OpenClaw Release Notes

Follow

373 release notes curated from 23 sources by the Releasebot Team. Last updated: Oct 5, 2026

Get this feed:
  • Oct 5, 2026
    • Date parsed from source:
      Oct 5, 2026
    • First seen by Releasebot:
      Oct 5, 2026
    OpenClaw logo

    OpenClaw

    v2026.10.1-beta.1

    OpenClaw ships v2026.10.1-beta.1.

    v2026.10.1-beta.1

    Original source
  • Oct 4, 2026
    • Date parsed from source:
      Oct 4, 2026
    • First seen by Releasebot:
      Oct 5, 2026
    OpenClaw logo

    OpenClaw

    release-publish/6bc3e8ae39ca-1791171552

    OpenClaw fixes release handling to keep lineage arguments nonempty.

    fix(release): keep lineage arguments nonempty (#165143)

    Original source
  • All of your release notes in one feed

    Join Releasebot and get updates from OpenClaw and hundreds of other software products.

    Create account
  • Oct 3, 2026
    • Date parsed from source:
      Oct 3, 2026
    • First seen by Releasebot:
      Oct 3, 2026
    OpenClaw logo

    OpenClaw

    openclaw 2026.9.8

    OpenClaw ships v2026.9.8 with a verified release and updated changelog and release notes, backed by CI checks and npm publication for the main package and plugin.

    OpenClaw v2026.9.8

    58 commits · 43 pull requests · 21 contributors

    Changes included in this release

    The release notes and changelog contain the same content, presented in two formats:
    Release notes — formatted for people, with expandable sections.
    Changelog — plain Markdown for AI agents and tools.

    Thanks

    @609NFT @aniketkrs @aniruddhaadak80 @EndeavorPioneer @ericcaiwx-star @fuller-stack-dev @hailongguo0530-alt @jasdeepohri-max @miguelpt2026 @NickM83 @obviyus @Patrick-Erichsen @PennyVibe @RomneyDa @scotthuang @steipete @VACInc @vincentkoc @WG-Mojo @xilopaint @yashas-13

    Release verification

    npm package: https://www.npmjs.com/package/openclaw/v/2026.9.8

    registry tarball: https://registry.npmjs.org/openclaw/-/openclaw-2026.9.8.tgz

    integrity: sha512-G+JkNUhtpDE3cXR4AEi2NyyG9fqI/T2WUSl8ZnR8AATH8Dh1kC3qYFL7wwPoZtgHiP/cszA86PEiE0PDysxb9Q==

    release SHA: fc23bc864e4553c2d215e479eeec47b67a0bf943

    full release CI report: https://github.com/openclaw/releases/blob/main/evidence/2026.9.8/release-evidence.md

    release publish: https://github.com/openclaw/openclaw/actions/runs/37089852299

    npm preflight: https://github.com/openclaw/openclaw/actions/runs/37046778498

    full release validation: https://github.com/openclaw/openclaw/actions/runs/37045896743

    plugin npm publish: https://github.com/openclaw/openclaw/actions/runs/37090141905

    plugin ClawHub submission: https://github.com/openclaw/openclaw/actions/runs/37090144556; public artifact verification follows successful release-parent completion

    plugin ClawHub bootstrap: not needed

    OpenClaw npm publish: https://github.com/openclaw/openclaw/actions/runs/37087759921/attempts/1

    Telegram integration checks: waived by the release owner for 2026.9.8 (source QA, Package Acceptance, published-package E2E); not run.

    Android APK: skipped — apps/android/version.json is 2026.8.2, release train is 2026.9.8; run pnpm android:version:pin -- --from-gateway before the next tag.

    Original source
  • Oct 2, 2026
    • Date parsed from source:
      Oct 2, 2026
    • First seen by Releasebot:
      Oct 4, 2026
    OpenClaw logo

    OpenClaw

    Tencent AIG joins ClawScan

    OpenClaw adds Tencent AIG to ClawScan, strengthening ClawHub security review for every uploaded skill and plugin. The update pairs AIG with SkillSpector in an ongoing benchmark-driven feedback loop to improve risk detection.

    Tencent’s AIG joins ClawScan to strengthen security review for every skill and plugin uploaded to ClawHub, backed by benchmark testing and an ongoing feedback loop.

    AIG is now part of ClawHub review

    We’ve integrated Tencent’s AI-Infra-Guard (AIG) into ClawScan, the open-source command-line tool that powers security review on ClawHub. Every skill and plugin uploaded to ClawHub now runs through AIG as part of its security review.

    How ClawScan works

    Our ClawHub Security Signals paper showed how differently scanners can read the same skill. Each brings its own view of risk, and preserving those differences gives us more evidence to work with.

    ClawScan runs AIG and NVIDIA’s SkillSpector security scanner independently on each skill or plugin. An AI judge then reviews both scanners’ findings alongside the uploaded files and makes a final security assessment.

    Contributors can test different scanners, AI models, and review instructions against the same benchmark to measure whether a change improves the results.

    What Tencent AIG adds

    Tencent describes AIG’s skill scanner as “an LLM-driven multi-stage code audit and vulnerability review pipeline.” It can follow the relationship between a skill’s instructions and the scripts, dependencies, and data flows behind them.

    AIG reviews nine categories of risk, from instruction hijacking and memory poisoning to remote payload execution, unauthorized access, persistence, and insecure dependencies.

    Benchmarking the combined system

    We worked with Tencent to evaluate ClawScan on a fixed 556-case subset of SkillTrustBench, the public benchmark developed by Tencent and the Chinese University of Hong Kong, Shenzhen.

    SkillTrustBench includes benign, suspicious, and malicious skills across nine risk categories. It tests whether scanners catch risky behavior, avoid flagging legitimate skills, and distinguish security flaws from malicious intent.

    The evaluation helped us validate the scanner settings and the combined review process. Tencent found that AIG and SkillSpector surfaced different risks even when using the same AI model.

    Across those 556 cases, ClawScan matched 86.9% of the benchmark’s labels and correctly classified 98.6% of malicious cases.

    Improving both projects together

    We now share anonymized cases where the scanners disagree, along with confirmed false positives, with Tencent. These examples feed into regression tests and improvements to AIG’s detection rules and review process. We evaluate those changes through ClawScan, creating a feedback loop that improves both projects.

    Keeping this work open lets contributors build on the integration and bring their own evidence to the next round of improvements.

    Acknowledgments

    We’re grateful to the Tencent team for contributing their scanner, benchmark, and time to this work, from reviewing individual results to resolving production issues.

    Original source
  • Oct 2, 2026
    • Date parsed from source:
      Oct 2, 2026
    • First seen by Releasebot:
      Oct 3, 2026
    OpenClaw logo

    OpenClaw

    release-publish/aa6008ad198e-1790984363

    OpenClaw improves self-upgrade aggregation by removing duplicate entries.

    improve(release): remove duplicate self-upgrade aggregate (#163676)

    Original source
  • Similar to OpenClaw with recent updates:

  • Oct 2, 2026
    • Date parsed from source:
      Oct 2, 2026
    • First seen by Releasebot:
      Oct 2, 2026
    OpenClaw logo

    OpenClaw

    openclaw 2026.8.35

    OpenClaw ships an extended-stable release with critical security updates, reliability and performance fixes, and new model support including GPT-6.1 Sol. It also improves update safety, agent completion, channel integrations, WebChat continuity, and runtime stability.

    This is a gateway-only extended-stable release, which is our current equivalent to LTS. This release is OpenClaw from the end of August 2026, plus critical security updates, reliability and performance fixes, and features like new model support. The latest version of OpenClaw at the time of this release is 2026.9.7

    2026.8.35

    Highlights

    • GPT-6.1 Sol support: add the current Sol model across OpenAI routing, discovery, reasoning, harness, and Reef guard-model boundaries. (#161400, #162955)
    • Safer updates and recovery: preserve plugin settings, prevent duplicate Gateways, handle pnpm package updates without terminal failures, and retain plugin inventory through migration. (#160344, #160193, #161920, #161485) Thanks @EndeavorPioneer, @grtninja, @alkor2000, @xilopaint, and @aniruddhaadak80.
    • Reliable agent completion: preserve complete delegated and CLI answers, release suspended child capacity, recover full cron output, and prevent failed requests from consuming steered questions. (#162843, #162368, #160520, #162439) Thanks @zyz619963502zyz, @holgergruenhagen, @armstrongsam25, @davidcittadini, @jayzhou2309, and @obviyus.
    • Security and ownership hardening: keep secret-store kinds stable during rotation, restore admitted secret-egress execution, and retain explicit cron tool allowlists while repairing stale automatic snapshots. (#160926, #160760, #162432) Thanks @zachisfine, @yetval, @VACInc, and @obviyus.
    • Channel and integration reliability: repair Gmail and IMAP watchers, Matrix direct mappings, Telegram progress, remote MCP startup, and managed llama.cpp startup on clean Windows hosts. (#161503, #160413, #161727, #161546, #162376, #163093) Thanks @obviyus, @kazuyuki-eguchi, @Ayushdevo, @addyCooks, @VACInc, @Patrick-Erichsen, and @RomneyDa.
    • Performance and UI continuity: bound model-catalog waits, reduce Codex fleet heap pressure, and keep saved WebChat replies visible across history refresh races. (#161132, #162912, #162763) Thanks @jayzhou2309, @Flakedict, @obviyus, @609NFT, and @VACInc.

    Changes

    • Extended-stable release preparation: align OpenClaw and every publishable official plugin to 2026.8.35 while preserving the 2026.8.34 publication contract.
    • Model compatibility: add GPT-6.1 Sol to the branch-native OpenAI and Reef compatibility owners. (#161400, #162955)

    Fixes

    • Update safety: preserve incompatible-plugin settings through recovery, keep retained plugin records during migration, avoid pnpm terminal failures, and carry the existing Gateway lock through container/direct startup. (#160344, #161485, #161920, #160193) Thanks @EndeavorPioneer, @aniruddhaadak80, @alkor2000, @xilopaint, and @grtninja.
    • Agent delivery: recover uncapped cron replies, preserve complete CLI subagent answers, honor skipped announcements, retain detached transcripts, release suspended child slots, and keep failed requests from replacing earlier questions with a steer. (#160520, #162843, #161542, #161091, #162368, #162439) Thanks @jayzhou2309, @zyz619963502zyz, @holgergruenhagen, @armstrongsam25, @davidcittadini, and @obviyus.
    • Cron and tools: bound thinking-catalog hydration, repair stale automatic tool snapshots without widening explicit allowlists, and deliver manual runs after their creating turn ends. (#161132, #162432, #162780) Thanks @jayzhou2309, @Flakedict, and @obviyus.
    • Sessions and tool results: reject malformed session targets, preserve spawned working directories, project deeply nested MCP results safely, and keep remote MCP bundles working in native sessions. (#161533, #162308, #160825, #162376) Thanks @wangmiao0668000666, @Takhoffman, @hpyhandsome, and @Patrick-Erichsen.
    • Channels: recover Gmail transient binds, bound IMAP backlog processing, restore Matrix direct mappings, and restore Telegram progress when hooks suppress previews. (#161503, #160413, #161727, #161546) Thanks @obviyus, @kazuyuki-eguchi, @Ayushdevo, @addyCooks, and @VACInc.
    • Runtime reliability: prevent redaction stalls, cancel stale thinking-catalog waits, pass the responding agent to TTS model selection, stop durable worker retries from freezing hosts, reduce Codex fleet heap use, and install the required Visual C++ runtime after a managed llama.cpp launch failure. (#161089, #161319, #161454, #160812, #162912, #163093) Thanks @Baumus, @drakeo338, @aounakram, @RileyJJY, @aniruddhaadak80, @obviyus, @609NFT, and @RomneyDa.
    • Secrets and sandboxing: retain secret entry kinds during value rotation and repair read-only copied skills without escaping their confined roots. (#160926, #162304, #162295) Thanks @zachisfine and @yetval.
    • WebChat: keep saved replies visible when stale history responses race with live messages. (#162763) Thanks @VACInc.

    Complete contribution record

    This audited record covers the complete v2026.8.34..741d94f history: 49 in-range PRs + 0 retained seed-only PRs = 49 unique PRs. The generation manifest also supplies direct commits as editorial input; the grouped notes above prioritize user impact.

    Pull requests

    • PR #160344 Related #159477. Thanks @EndeavorPioneer.
    • PR #160193 Related #159941. Thanks @grtninja.
    • PR #160825 Related #160418. Thanks @wangmiao0668000666 and @Takhoffman and @hpyhandsome.
    • PR #161400 Related #161397.
    • PR #161089
    • PR #161503 Related #161467. Thanks @obviyus and @kazuyuki-eguchi.
    • PR #161533
    • PR #161542
    • PR #161319 Related #161310. Thanks @Baumus.
    • PR #161270 Thanks @zachisfine.
    • PR #161454 Related #161431. Thanks @drakeo338 and @aounakram.
    • PR #160413 Related #160353. Thanks @Ayushdevo and @addyCooks.
    • PR #161132 Related #161112. Thanks @jayzhou2309 and @Flakedict.
    • PR #161727
    • PR #161091
    • PR #160812 Related #160735. Thanks @RileyJJY and @aniruddhaadak80.
    • PR #161485 Related #161329. Thanks @aniruddhaadak80.
    • PR #160760 Thanks @VACInc.
    • PR #160715 Thanks @VACInc.
    • PR #160843 Thanks @VACInc.
    • PR #162304
    • PR #160520 Thanks @jayzhou2309.
    • PR #161920 Related #161866. Thanks @alkor2000 and @xilopaint.
    • PR #162308
    • PR #162368 Related #162267. Thanks @armstrongsam25 and @davidcittadini.
    • PR #162295
    • PR #162439 Thanks @obviyus.
    • PR #149925 Thanks @obviyus.
    • PR #77023 Thanks @fuller-stack-dev.
    • PR #109709
    • PR #161069 Thanks @obviyus.
    • PR #161546 Thanks @VACInc.
    • PR #162763 Thanks @VACInc.
    • PR #162432 Thanks @obviyus.
    • PR #137832 Related #130753. Thanks @jalehman.
    • PR #147969 Thanks @obviyus.
    • PR #91499 Thanks @mmaps.
    • PR #112483 Thanks @joshavant.
    • PR #112661 Related #111809. Thanks @joshavant and @andersonjeccel.
    • PR #162780 Thanks @obviyus.
    • PR #104595
    • PR #115404 Related #115758. Thanks @RomneyDa.
    • PR #121113
    • PR #162912 Related #162802. Thanks @obviyus and @609NFT.
    • PR #162843 Related #162777. Thanks @zyz619963502zyz and @holgergruenhagen.
    • PR #162955
    • PR #162376 Thanks @Patrick-Erichsen.
    • PR #163093 Thanks @RomneyDa.
    • PR #160926 Related #158968. Thanks @zachisfine and @yetval.

    Release verification

    • npm package: https://www.npmjs.com/package/openclaw/v/2026.8.35
    • registry tarball: https://registry.npmjs.org/openclaw/-/openclaw-2026.8.35.tgz
    • integrity: sha512-7Bk/IeHTk04gfR4rW2SEVwwmGiXg2CcRxL3K1U2JzTgwbSSSlbX/yoLEbkiiSMOLtOuAi1ZfVbgmSsSlOA/E6g==
    • release SHA: 713ba5785d72d6ed1cec971e21307f16cc4234a6
    • npm preflight: https://github.com/openclaw/openclaw/actions/runs/36994752811
    • full release validation: https://github.com/openclaw/openclaw/actions/runs/36994246053
    • plugin npm publication: https://github.com/openclaw/openclaw/actions/runs/37008498463
    • OpenClaw npm publication: https://github.com/openclaw/openclaw/actions/runs/37010843200 — npm accepted publication; the workflow expired only during bounded registry readback.
    • Docker publication recovery: https://github.com/openclaw/openclaw/actions/runs/37013839190
    • Manual finalization: owner-approved after independent verification of npm signatures and provenance, the extended-stable selector, all 89 plugin packages, Docker digests and attestations, both requested upgrade paths, live model and channel paths, and public container smoke.
    Original source
  • Oct 2, 2026
    • Date parsed from source:
      Oct 2, 2026
    • First seen by Releasebot:
      Oct 2, 2026
    OpenClaw logo

    OpenClaw

    openclaw 2026.8.34

    OpenClaw ships an extended-stable release with critical security updates, reliability and performance fixes, and new model support. It strengthens upgrades, recovery, auth, sessions, plugins, gateways, and filesystem safety while improving correctness across the platform.

    This is a gateway-only extended-stable release, which is our current equivalent to LTS. This release is OpenClaw from the end of August 2026, plus critical security updates, reliability and performance fixes, and features like new model support. The latest version of OpenClaw at the time of this release is 2026.9.7

    2026.8.34

    Highlights

    Extended-stable correctness rollup: backport 113 audit-selected fix units across upgrades, Doctor, authentication, sessions, channels, plugins, sandboxing, filesystem safety, model runtimes, and release packaging.

    Complete rescan: re-evaluate the full 2026.8.33 discovery range, large mixed-purpose pull requests, and the 2026.7.35 lineage instead of advancing only from the previous backport cursor.

    Upgrade and recovery hardening: preserve credentials, agent state, plugin inventory, transcripts, schedules, service ownership, and runtime links through upgrades, restarts, and Doctor repair.

    Boundary fixes: tighten remote filesystem mutation, plugin and skill scanning, browser authentication, channel reply identity, private skill ingress, and scoped runtime ownership.

    Changes

    Extended-stable release preparation: align OpenClaw, publishable plugins, native version metadata, generated channel catalogs, and npm package inventories to 2026.8.34.

    Fixes

    Plugins: Recover orphan installs without weakening ownership.

    Doctor: Repair keyed multi-agent rosters without ownership (#134706)

    Prevent device pairing migration crash on contaminated records.

    Doctor: Preserve per-agent memory search during upgrades.

    Doctor: Detect shared auth migration by provenance (#134808)

    Cron: Refuse stale doctor store rewrites.

    Gateway: Refresh model catalog after auth changes (#134361)

    Openai: Repair stale doctor route pins.

    Auth: Verify shared credential migration receipts (#134952)

    Cron: Keep model aliases scoped to the selected owner (#135069)

    Memory: Resolve profile auth for compatible embeddings (#134744)

    Auth: Recover credentials stranded by completed migrations (#135346)

    Auth: Relogin repairs stale profile order after upgrade.

    Auth: Preserve custom provider SecretRefs in Doctor.

    Docker: Install libgomp1 in the runtime image for managed llama.cpp (#134532)

    Devices: Allow authorized scoped node token management (#135617)

    Msteams: Thread context is dropped when a channel reply has no replyToId (#129345)

    Ui: Ignore tool-only model auth rows (#134218)

    Cron: Kind change fails with "command env must be an object" when env is omitted (#134639)

    Backup: Exclude workspaces before traversal.

    Infra: Drop empty PATHEXT entries from Windows extension lookup (#135807)

    Anthropic: Context usage is lost when a proxy omits message_delta usage (#135467)

    Systemd: Protect credentials in managed backups (#131786)

    Agents: Preserve requester MCP runtime ownership (#134819)

    Plugins: Refresh persisted registry when source mounts change (#136517)

    Gateway restart hangs while followup drain retries a draining error (#136713)

    Auth: Preserve OAuth metadata during session SDK refresh (#127988)

    Doctor: Recognize configured memory provider secret references (#137782)

    Sessions: Preserve logical shared-store ownership (#138380)

    Full-access tasks lose tools after Gateway restart (#138701)

    Keep unchanged files out of session diffs (#138877)

    Auth: Recover billing-disabled profiles in minutes instead of hours (#136364)

    Auth: Keep an unset default model unchanged during login (#139218)

    Gateway: Avoid crashes when an upgrading client disconnects (#139061)

    Shell-env: Preserve CLI terminal ownership during login imports (#139308)

    Auto-reply: Fold trailing transcript growth into memory-flush fresh totals (#138928)

    Cron: Preserve pending paced checks across restart (#140083)

    Daemon: Systemd install no longer aborts on "ownership could not be verified" after a clock step (#137253)

    Config: Apply environment changes after in-process restart (#141296)

    Pasted text is missing in model-locked Codex sessions (#142021)

    Docker: Restore source builds after dependency ownership guard (#142073)

    Security: Preserve existing WhatsApp group allowlists (#142589)

    Doctor: Avoid installing unselected search providers (#142640)

    Doctor: Migrate legacy Codex music model selectors (#143235)

    Doctor: Preserve selected model metadata in diagnostics (#144332)

    Discord: Report parent channel denies for thread permissions (#121144)

    Config: Avoid false model changes when saving settings (#144807)

    Doctor: Preserve legacy registry files when quarantine fails (#144787)

    Retain route ownership while discovering conversations (#146927)

    Install: Preserve runtime links when Node validation fails (#147221)

    Doctor reports missing OAuth dir for channel config with no installed plugin (#147888)

    Doctor: Stop private pending inputs replaying after session repair (#148625)

    Channels: Settle task-scoped context leases once (#148922)

    Push: Normalize malformed proxy auth errors (#149112)

    Cron: Reject invalid stagger before silent schedule changes (#151740)

    Cli: Keep model validation out of session execution (#154763)

    Agents: Treat empty credential environment variables as unresolved (#155558)

    Doctor: Apply ambient-owner fallback to dream diary and all memory target handlers (#156437)

    Sandbox: Unblock scoped recreation across runtime targets (#157808)

    Security: Parse gpt generation numbers in the audit tier check (#140012)

    Doctor: Report shared auth health without a default agent (#134902)

    Doctor: Converge redundant shared auth relocation subsets (#135096)

    Doctor: Report retained device-auth files (#133978)

    Update: Stop detached updates after chat ownership is revoked (#137312)

    Doctor: Inspect source auth stores during full lint (#137610)

    Gateway: Recover queued RPC replies across restart (#138565)

    Doctor: Preserve legacy ownership during config repair (#138837)

    Prevent browser profile permission hangs in Doctor (#139612)

    Gateway: Prevent systemd restarts from hanging (#140914)

    Doctor: Recover legacy node tokens with invalid scopes (#143599)

    Skills: Refresh session snapshots on gateway restart (#122110)

    Doctor: Session SQLite import drops Codex assistant messages from legacy transcripts (#140296)

    Cron: Forward claude-cli auth profile on scheduled runs to prevent OAuth expiration (#144266)

    Discord: Preserve sender-owned line limits and reply scope (#137969)

    Install: Never replace or break an existing nvm during installation (#145317)

    Sessions: Recover omitted historical transcripts in Doctor (#120781)

    Update: Recognize custom npm prefix installations (#146091)

    Context: Preserve provider-scoped prompt budgets before reply maintenance (#141052)

    Sessions: Prevent Doctor and startup memory exhaustion (#149704)

    Daemon: Preserve inline auth through service upgrades (#149686)

    Update: Verify paired trusted-proxy gateways with service credentials (#153540)

    Background continuations lose session access and GitHub tools (#141865)

    Doctor: Decode session headers across read chunk boundaries (#154034)

    Faulty compaction probe wedges run steering and restart aborts (#154868)

    Ui: Publish rejected goal operations (#156363)

    Commands: Deduplicate session lifecycle keys (#158487)

    Plugins: Preserve runtime artifact preference (#158487)

    Agents: Strip private skill authoring from public ingress (#159220)

    Plugins: Preserve include ownership during uninstall (#159945)

    Channels: Restore system-agent approval reactions (#159132)

    Moonshot: Reject inherited thinking-model keys (#158437)

    Tencent: Ignore inherited effort-map keys (#158437)

    Workers: Observe already-aborted operation promises (#158228)

    Gateway: Reject non-object Claude history rows (#158228)

    Copilot: Recover pool after synchronous factory failures (#157819)

    Tlon: Preserve IPv6 ship origins (#157825)

    Sms: Clean revoked inbound media (#157825)

    Slack: Preserve replacement webhook registrations (#158085)

    Matrix: Accept system-agent approval reactions (#158164)

    Channels: Retain typing tick exclusivity across restart (#158830)

    Acp: Format unset optional tool arguments (#159417)

    Meeting: Clean up partial audio startup (#157982)

    Exec: Retain prepared plugin environment (#158378)

    Mxc: Clean temp directory after bridge failure (#158532)

    Discord: Preserve batched native reply identities (#158886)

    Skills: Count omitted dangerous exec aliases once (#158906)

    Sandbox: Preserve remote mutation path bytes (#159346)

    Browser: Accept standard CDP header containers (#159430)

    Plugins: Preserve sparse catalog preferences (#159945)

    Doctor: Preserve complete plugin inventory (#153901)

    Fs: Preserve bounded filesystem correctness (#157524)

    Complete contribution record

    This release represents 113 approved units: 60 exact source commits, 25 material adaptations, 27 narrow slices extracted from large or mixed-purpose pull requests, and one 2026.7.35 plugin-inventory parity repair. Units already covered by the 2026.8.33 architecture, or whose newer storage contract does not exist on this release line, are recorded as evidence-backed inclusions rather than duplicate or speculative code.

    Release verification

    npm package: https://www.npmjs.com/package/openclaw/v/2026.8.34

    registry tarball: https://registry.npmjs.org/openclaw/-/openclaw-2026.8.34.tgz

    integrity: sha512-wr/4SIbHkX2sSCi5etvIevjYK4IWfKsQmPf3Yhhrix4Eg94CALkdBr8VPAQsbMXyiILGQpW6syjXsmFs+aCvzg==

    release SHA: d21cb744af45bc4d29352750c5e1e7f1cf7f066a

    full release CI report: https://github.com/openclaw/releases/blob/main/evidence/2026.8.34/release-evidence.md

    release publish: https://github.com/openclaw/openclaw/actions/runs/36941737739

    npm preflight: https://github.com/openclaw/openclaw/actions/runs/36819226831

    full release validation: https://github.com/openclaw/openclaw/actions/runs/36818791392

    plugin npm publish: https://github.com/openclaw/openclaw/actions/runs/36942133414

    plugin ClawHub publish: no normal OIDC candidates

    plugin ClawHub bootstrap: not needed

    OpenClaw npm publish: https://github.com/openclaw/openclaw/actions/runs/36919657824/attempts/1

    npm Telegram beta E2E: not supplied

    Original source
  • Oct 1, 2026
    • Date parsed from source:
      Oct 1, 2026
    • First seen by Releasebot:
      Oct 2, 2026
    OpenClaw logo

    OpenClaw

    release-publish/bd058c2d9999-1790897806

    OpenClaw fixes release to retain admitted npm resume publisher.

    fix(release): retain admitted npm resume publisher (#163082)

    Original source
  • Oct 1, 2026
    • Date parsed from source:
      Oct 1, 2026
    • First seen by Releasebot:
      Oct 2, 2026
    OpenClaw logo

    OpenClaw

    release-publish/a01081aac382-1790893897

    OpenClaw fixes legacy published chunk ownership verification.

    fix(release): verify legacy published chunk ownership (#163019)

    Original source
  • Oct 1, 2026
    • Date parsed from source:
      Oct 1, 2026
    • First seen by Releasebot:
      Oct 2, 2026
    OpenClaw logo

    OpenClaw

    release-publish/004549970362-1790888386

    OpenClaw fixes delayed npm readback resume in a release update.

    fix(release): resume delayed npm readback (#162990)

    Original source
  • Sep 30, 2026
    • Date parsed from source:
      Sep 30, 2026
    • First seen by Releasebot:
      Oct 2, 2026
    OpenClaw logo

    OpenClaw

    release-publish/7a438dc93ec0-1790883042: fix: validate extended-stable package upgrades (#161450)

    OpenClaw fixes release package upgrades with extended-stable validation, channel routing, registry pinning, and candidate binding.

    fix(release): validate extended-stable package upgrades

    fix(release): route upgrades by baseline channel

    fix(release): pin extended-stable registry upgrades

    fix(release): bind extended-stable registry candidate

    Original source
  • Sep 30, 2026
    • Date parsed from source:
      Sep 30, 2026
    • First seen by Releasebot:
      Sep 30, 2026
    • Modified by Releasebot:
      Oct 1, 2026
    OpenClaw logo

    OpenClaw

    openclaw 2026.9.7

    OpenClaw ships the 2026.9.7 release with verified npm and plugin publishes, backed by a large set of direct commits, pull requests, and contributors. The release notes and changelog are published in both human-friendly and plain Markdown formats.

    OpenClaw v2026.9.7

    518 direct commits · 2,818 pull requests · 334 contributors

    Changes included in this release

    The release notes and changelog contain the same content, presented in two formats:
    Release notes — formatted for people, with expandable sections.
    Changelog — plain Markdown for AI agents and tools.

    Thanks

    @609NFT @Aalmann @aatreya @abacha @abuegab1-spec @ada-KVR @AgentSolomon @aicyberg @ajmtrz @Alekstodo @aleps001 @alexph-dev @alibux @Alix-007 @altaywtf @amarsmission @AmesGit @anarchia-99 @andersonjeccel @aniruddhaadak80 @anyech @apple2345-pixel @areslp @AS76 @aspalagin @auriga-agents @avirtudazo-officeconnect @AXEG0 @axiom-ncis @Ayushdevo @azakharko @baiwei0427 @bappamp4 @Baumus @bdjben @benlaube @bill-starfoundry @BillVerhelle @bitkylin @blackdiamondcyber-png @blackeyes-boy @blyszcz @BoatAngle @bogdandragosvasile @boycez @brokemac79 @Bruce-Yii @brucemccurdy @canvrno-oai @Captain69G @CarotaWealth @caseyjustus @cbhawthorne84 @ceckert @chac4l @chaolawo-byte @charlie-morrison @chelsealong @chopin-op60 @choury @cipp-ashe @cjn119-ui @Colton-Harris @Conan-Scott @context-down @coygeek @cp7553479 @Cyb3rb1ade @dankarization @DarkJuanFra @DasX @davidcittadini @desksk @destinedenergy @dh-js @dimonnld @dmmc12 @dmwtech @DonnieFi @dots-oai @dragomirdimitrov-mmrndm @Dreamer-HIT @DrToNy1 @dwalthour @dwonshin @dynamite-bud @eddiekk @EduHerranz @ekinnee @eleqtrizit @EndeavorPioneer @eric-basketbot @ericcaiwx-star @etzelm @fchaudhryspear @fduch-stranger @Flakedict @flyto168 @fourestfire @fransqaas @freeqaz-openai @fulgerulnegru @fuller-stack-dev @Fuma2013 @funklawfirm-dotcom @galiniliev @gaoanze888 @Geokec @giangthb @giodl73 @giodl73-repo @gisk0 @gokay-ai @goslingmanagment @Gr33n93 @grape404 @Grynn @h94916 @haldana88 @hannesrudolph @hartmark @he-yufeng @Hensarj @highfly-hi @Hmache @holny @hpyhandsome @htuyer121 @hugenshen @hurtlovewow @hxy91819 @ion-developing @Irish-Joseph @islandpreneur007 @ivankuznetsov @IWhatsskill @Jackten @jalehman @jb168 @jb510 @JefRH1 @jiangzhao2121-debug @jihoon-ernesto @jjjhenriksen @johnfink8 @johnnyjrizzo @JordanNewell @joshavant @joshbunker @joshpetras @Journey417 @jscd98 @jtatum @JUMPUNDER @kai0126-claw @Kaspnov @kassol @kchuang1015 @kevinlin-openai @keysersozeh @Kiiatkin @Kimiyu-186 @kirylh @kybrcore @laisonamarante @laurencebrown @laurentschwartz @leilei3167 @lennartack @Leon-SK668 @liemnhoang @LinzeShi @lisheguo @liunan12345678-spec @LiuwqGit @liuxb553-panda @liyoulu @Loganwoooof @lovelefeng-glitch @lucarinaorg @Ludwigtheo0815 @lukewd @ly85206559 @marinabotobs @mariorivas1 @markmcd @markomiric @martinxomag @Marvinthebored @masatohoshino @MasterSwords1 @Matuno @mcaxtr @MertBasar0 @meska @MikyWang @mmartoccia @MoerAI @mohit @mrclawfield @mrzeepek @msobrosa @myagizmaktav @Nakagawa-master @name5566 @Navras98 @ndakota79 @neyudo @NianJiuZst @Nickfost @NicolasDerito @Niriakot @nkeil @NobleVision @noelillinger @nomiSFI @NovaUnboundAi @nz365guy @obviyus @Oldrich333 @oleagui @Olli0103 @olyapop @omarshahine @OpenClawKobian99 @Orionation @oxen-horse @ozp @pash-openai @Patrick-Erichsen @paweldrozd @Peetiegonzalez @Pegorim @pengzh1 @PennyVibe @pgondhi987 @Pluviobyte @pmika @podulator @polaris-arch @PollyBot13 @potterdigital @prashantkamani @QuinsZouls @rboy1 @redxzeta @revision-co-ltd @ReyesAdrian @RileyJJY @rmyers64 @rogeriochaves @RomneyDa @ruel225 @ryan-dyer-sp @ryanjkelly @S1gv4rd @s93101179 @saariuslystoned @sahilsatralkar @sallyom @salmunclaw @sandra-peach @Sanjays2402 @sarahliyanage @ScientificProgrammer @seaurching @SebTardif @SecureCloudProjO @serg0x @shadesurgeon @shakkernerd @shootingsyh @sidboswell @siri1410 @SiskoYU @sjf @sjf-oa @Solvely-Colin @sonofakel @spikewillcocks @steipete @stevenlee-oai @SummitOperations26 @SundayDriver @sunlit-deng @SunnyShu0925 @superandylin @superdiaodiao @sxh313 @Takhoffman @TeaCup404 @team-contractorscale @texasaggie1 @thoth-ctl @timothyfs @todddickerson @tomdailey55 @tomm789 @Torsie @TreyLawrence @tsw-uop @VACInc @VasuBansal7576 @villemac @vincentkoc @vishubh043-dev @vyctorbrzezowski @wangmiao0668000666 @WanweiInMod @WG-Mojo @wlassalle724 @wzkagms @xiaov1024 @xiaozishan @xilopaint @xx77yy @YangManBOBO @yashas-13 @ycmjason @yetval @Yigtwxx @yihan331313 @yoyo837 @Yun-0000 @yunligou711-commits @Yuxin-Qiao @yyds-xxxx @zachisfine @ZengWen-DT @zeroaltitude @zhiyuan82-tech @zl0nline @zsh20000414 @zyz619963502zyz

    Release verification

    npm package: https://www.npmjs.com/package/openclaw/v/2026.9.7

    registry tarball: https://registry.npmjs.org/openclaw/-/openclaw-2026.9.7.tgz

    integrity: sha512-/8N2LnfTFQPvnZizi8qKSFfnLQaPvSG3Cb4xo1YV7b4JhYiUc43ZNRpXJ01bWghLK0Ezk3HVeo/DGHcIRQwRWA==

    release SHA: c074824a27c96d3983043f9eeb33823cd1772d8c

    full release CI report: https://github.com/openclaw/releases/blob/main/evidence/2026.9.7/release-evidence.md

    release publish: https://github.com/openclaw/openclaw/actions/runs/36667642121

    npm preflight: https://github.com/openclaw/openclaw/actions/runs/36645703509

    full release validation: https://github.com/openclaw/openclaw/actions/runs/36644909314

    plugin npm publish: https://github.com/openclaw/openclaw/actions/runs/36668111716

    plugin ClawHub submission: https://github.com/openclaw/openclaw/actions/runs/36668119179; public artifact verification follows successful release-parent completion

    plugin ClawHub bootstrap: dispatched separately, not awaited by this proof: https://github.com/openclaw/openclaw/actions/runs/36668126283

    OpenClaw npm publish: https://github.com/openclaw/openclaw/actions/runs/36664180615/attempts/1

    Telegram integration checks: waived by the release owner for 2026.9.7 (source QA, Package Acceptance, published-package E2E); not run.

    Android APK: skipped — apps/android/version.json is 2026.8.2, release train is 2026.9.7; run pnpm android:version:pin -- --from-gateway before the next tag.

    Original source
  • Sep 29, 2026
    • Date parsed from source:
      Sep 29, 2026
    • First seen by Releasebot:
      Sep 30, 2026
    OpenClaw logo

    OpenClaw

    release-publish/2b4055f8dd70-1790734526

    OpenClaw fixes Vercel CLI tooling by bumping the undici override to 6.28.1.

    fix(release): bump the Vercel CLI tooling undici override to 6.28.1 (…

    Original source
  • Sep 29, 2026
    • Date parsed from source:
      Sep 29, 2026
    • First seen by Releasebot:
      Sep 30, 2026
    OpenClaw logo

    OpenClaw

    OpenClaw Enterprise - The Open Agent Platform

    OpenClaw introduces OpenClaw Enterprise, an open source control plane for persistent agents in sensitive environments. It adds multi-tenancy, hard security boundaries, governance, auditability, and support for swapping core primitives with third-party or internal tools.

    Today, we are excited to announce OpenClaw Enterprise (OCE), an open source, vendor neutral platform for managing persistent agents in sensitive environments.

    When OpenClaw first launched, it showed the world the capabilities of a good model paired with a harness optimized for agentic work. Now almost a year later, the actual deployment of persistent agents remains limited. The main feedback we hear from organizations is that a stronger common security, safety, and governance standard is needed before agents can be fully adopted. As a consequence, the default stance of IT in most organizations is to ban agentic platforms like OpenClaw altogether.

    This is the problem we are trying to solve with OCE: how do we safely deploy powerful agents without nerfing their capabilities in enterprise environments?

    OpenClaw Enterprise — currently being developed in the open before its 1.0 release — introduces an enterprise grade control plane for agents and builds upon the foundation set by OpenClaw with support for multi-tenancy, hard security boundaries, and standardized agentic primitives. OCE adds governance and auditability across the agent lifecycle while making sure that core primitives like the harness, model, and sandbox can be swapped out with third party solutions as well as internal implementations.

    Today, we consider OCE something that organizations can use for internal pilot workloads. We prioritized open sourcing this work early in development in order to build in the open and co-develop with the wider community ahead of the 1.0 release later this year. You can self host OCE today by cloning the repo and following the getting started guide. You can run OCE using docker-compose for local development and deploy internally via kubernetes.

    The development of OCE has been a joint effort of multiple organizations. It originally started at OpenAI and then was donated to the OpenClaw Foundation, where it is now an independent project and has been further developed in collaboration with Red Hat and NVIDIA. OCE is built to run on your own infrastructure and will always be free for any organization to use.

    OCE is being piloted internally at companies like Red Hat and OpenAI. OpenAI is already running OpenClaw agents with full access to codebases and plugins.

    Our internal enterprise agent Androidclaw has really been well-adopted by our team. Having it help triage in channels is just epic. It’s got all our context, git, github, logging, etc. Alert about a broken build? Androidclaw finds the PR and can quickly fix it. Someone gives feedback that the work tab disappeared? Androidclaw responds in like 30 seconds with the link to the SEV. Even for hilarious, obscure things like "the streaming seems glitchy,” it can trace, find a fix for, publish a PR with video evidence and merge it. Kinda game changing. It’s smart.
    -RJ Marsan, Member of the Technical Staff at OpenAI

    Security is the primary focus of OpenClaw Enterprise. OCE combines hard boundaries between trusted and untrusted workloads with sandboxing, LLM-based reviews, and fine-grained permissions. In the coming weeks, we’ll share a reference architecture showing how these protections work together in practice.

    The OpenClaw Foundation exists to make powerful AI agents open and accessible. OpenClaw Enterprise carries that mission into the workplace, giving organizations the security, governance and deployment controls they need to run agents on their own terms. We are early, and there is much more work ahead. As we continue building, we invite developers, operators, security teams and organizations to help shape the open foundation for enterprise agents.

    Original source
  • Sep 29, 2026
    • Date parsed from source:
      Sep 29, 2026
    • First seen by Releasebot:
      Sep 29, 2026
    OpenClaw logo

    OpenClaw

    openclaw 2026.8.33

    OpenClaw ships an extended-stable LTS-style release with critical security updates, reliability and performance fixes, and new model support including Meta Muse Spark 1.3, Anthropic Fable 5.1, OpenAI GPT-6 Astra, and GPT Image 2.5.

    This is a gateway-only extended-stable release, which is our current equivalent to LTS. This release is OpenClaw from the end of August 2026, plus critical security updates, reliability and performance fixes, and features like new model support. The current latest version of OpenClaw is 2026.9.6

    2026.8.33

    Highlights

    Current flagship models: add Meta Muse Spark 1.3, Anthropic Fable 5.1, OpenAI GPT-6 Astra, and OpenAI/fal GPT Image 2.5 support to the extended-stable line. (#135638, #136553, #137550, #143068, #143069)

    Complete GPT-5.6 family support: preserve Sol, Terra, and Luna catalog, routing, migration, image, vision, and thinking behavior, including Ultra reasoning across model-runtime boundaries and Bedrock tool-result images. (#135397, #149336)

    Extended-stable security rollup: reconcile all repository advisories that affect 2026.8.2, harden Prometheus metrics authorization and Discord asset/voice ownership, and clear the production Nodemailer advisory gate. (#136700, #137433, #140334, #140903)

    Changes

    Extended-stable release preparation: normalize OpenClaw, all publishable plugins, and native version metadata to 2026.8.33 while retaining the release-line-compatible publication workflows from 2026.8.2.

    Fixes

    Anthropic reasoning continuity: preserve Fable 5.1 reasoning through model switches and runtime events. (#136782)

    OpenAI discovery: require successful model discovery before offering GPT-6 Astra through OAuth. (#137561)

    Doctor skill state: preserve explicitly enabled skills during automatic updates. (#138730)

    Generated media: retain generated images when a later tool call fails. (#131226)

    Matrix verification: refresh verification state before reporting device trust. (#136226)

    Prometheus authorization: reject metric scrapes that lack the configured operator-read scope. (#140903)

    Discord media policy: enforce sender media policy for guild asset uploads. (#140334)

    Discord realtime ownership: preserve speaker and playback ownership across voice lifecycle transitions. (#137433)

    Discord consult cancellation: record host-cancelled realtime consults as cancellation, suppress the generic error fallback, and keep the voice session ready for the next request. (#134924, #135380)

    Dependency security: override the IMAP dependency graph to Nodemailer 9.1.1, clearing the address-parser denial-of-service and related domain/content-access advisories. (#136700)

    iOS release validation: update the WebRTC binary dependency to 152.0.0 after the 151.0.0 artifact was withdrawn. (#134942)

    Original source
Releasebot

Curated by the Releasebot team

Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.

Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.