102 Commits
Author SHA1 Message Date
Dallin Romney 348bd81b55 docs: keep release policy public and maintainer procedures in skills (#156946)
* docs: make the release guide readable and correct closeout policy

* docs: address release guide review feedback

* test: decouple release workflow checks from public guide prose

* docs: finish release procedure link migration

* docs: repair release procedure destinations and preserve packager steps

* docs: preserve release recovery procedures and legacy destinations
2026-09-26 00:18:17 +00:00
Josh Avant c2b84506a9 feat(ci): split security review into maintainer and SecOps tiers (#152415)
* feat(ci): split security review into two tiers

* refactor(ci): move security review paths into YAML

* fix(ci): require explicit maintainer approval commands

* feat(ci): integrate automatic security review with CI

* fix(ci): filter security review comment events

* test(ci): include security review workflow routes
2026-09-18 23:39:46 -05:00
Ayaan Zaidi 36a6a6f565 chore: remove secops CODEOWNERS review routing (#151624)
## What Problem This Solves

Remove the blanket CODEOWNERS review routing to openclaw-secops, as requested by steipete and relayed by the author.

## User Impact

Security-related paths no longer automatically request secops code-owner review. Dependency Guard and Security Sensitive Guard remain unchanged, including dependency detection, lockfile autoscrub, comments/labels, and their SHA-bound approval commands. This does not remove dependency checks or change guard authorization.

## Why This Change Was Made

Remove only the secops CODEOWNERS block, the matching contribution restriction and stale lockfile-owner documentation, and two tests that require the retired CODEOWNERS entries. Keep steipete's ownership of CODEOWNERS and release-manager routing. Security scanning, dependency audits, and release approvals are untouched.

The earlier revision removed the guards too broadly; this revision restores them completely.

## Evidence

- All four guard suites pass: 59 tests.
- Both workflows, all three guard scripts, test routing, and guard script tests match the original baseline byte-for-byte.
- Two obsolete CODEOWNERS assertions removed; all guard behavior coverage retained.
- Targeted formatting, lint, and `git diff --check` pass.
- [Hosted CI](https://github.com/openclaw/openclaw/actions/runs/35324860885) failed in Telegram QA tooling: TS2353 at `scripts/mantis/run-request-telegram.mts:446` and four recorder tests whose fixture rejects `reply_to`. The failing caller, lease helper, recorder, fixture, and test are byte-identical between the actual CI merge `e1f02ecfae2b450fb4363c5205abd97c979c5aaa` and its main parent `c616fb4852ef9d6904427914bd75d2ba170b8146`. The required CI check remains red; no bypass or merge attempted.

## Compatibility

No runtime, configuration, SDK, GitHub ruleset, or environment changes. Both `/allow-*` guard commands retain their existing behavior.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-09-18 14:51:31 +05:30
Peter Steinberger 5e33622cca docs: clarify authorization for internal repair decisions (#146462) 2026-09-12 14:14:56 -07:00
RoboClawandhannesrudolph d23730ee7c docs: make PR descriptions plain-language first (#146253)
Co-authored-by: hannesrudolph <49103247+hannesrudolph@users.noreply.github.com>
2026-09-12 13:29:17 -06:00
Hannes RudolphandPeter Steinberger 2227743f74 refactor: split release changelogs and synchronize docs mirrors (#145464)
* refactor: split release changelogs and synchronize docs mirrors

* fix: complete split changelog instructions and validation wiring

* fix: complete release changelog mirror integration

Regenerate existing docs mirrors within the docs-agent publication boundary, preserve one HTML release heading, and package links for oversized mirrors without changing frozen records. Update release publisher and test-routing fixtures for the shared changelog resolver.

* test: align docs agent Git ownership fixtures

Keep failure injection aligned with staged-index validation and mirror staging. Preserve native Git producer exit codes and verify both cached-index producers without weakening process-drain assertions.

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-11 21:19:18 -07:00
Peter Steinberger 62395281ff fix(tooling): prevent accidental shared dependency installs (#141719)
* fix(tooling): prevent accidental shared dependency installs

Stop creating implicit checkout-root dependency links during tool bootstrap.
Refuse default pnpm reconciliation through borrowed roots before linking,
while preserving explicit hydrated aliases, existing read-only borrows,
and configured-to-local toolchain fallback.

Include the early guard in package files and document its checkout-root
scope, lifecycle bypasses, and concurrent-path limits.

Validation: 127 focused Linux tests, seven real pnpm install cases,
packaged-root command proof, full checks plus final scoped loader checks,
and independent P0-P2 review.

* fix(tooling): audit install hook and align bootstrap coverage

Include the dependency ownership guard in the exact install lifecycle
contract and dependency fingerprint inputs so CI admits the hook and
invalidates cached dependencies when its implementation changes.

Update the existing wrapper expectation for the intentionally removed
implicit primary-checkout borrowing path while retaining hydration proof.

Validation: reproduced both failures, 517 workflow guards (2 existing
skips), 98 bootstrap/ownership tests, full scoped Linux checks, and
independent P0-P2 review.

* test(tooling): align isolated harness and routing contracts

Provision the copied Docker harness's TypeScript package explicitly and
update the preflight diagnostic and dedicated shim test routing expectations.

Validate compact tooling runner capacity from each resulting group's compiler
membership, preserving all file-policy and negative mutation checks without
freezing incidental compiler co-tenants onto a larger runner.

Validation: all 604 affected Linux tests, complete scoped checks, original
failure reproductions, planner inventory attribution and independent P0-P2
review. No production dependency or capacity policy changed in this follow-up.

* test(tooling): keep bootstrap cases in the runtime owner suite

Preserve all eight bootstrap cases and fixture logic in the existing local
runtime suite, with scoped environment cleanup and precise test routing.
The standalone filename fragmented the integrated GitHub compact plan into
81 jobs; the actual consolidated merge fits all three plans within80.

Keep the cap, estimates, compiler capacity, assertions and test coverage.
Validation: identical moved AST/token bodies, 571 local tests, 624 integrated
Linux tests and full scoped checks, exact merged planner proof, and clean
independent P0-P2 review.
2026-09-07 20:09:36 -07:00
Peter Steinberger ce0e84d073 fix(runtime): require Node builds with lossless SQLite reads (#140672)
* fix(runtime): require Node builds with lossless SQLite reads

* fix(runtime): preserve upgrades and guard sealed workers

Validate downloaded Node before switching the active runtime alias, reject unsupported sealed-worker runtimes, and keep the Gateway error fixture on a supported Node release. Document the approved ARMv7 and older macOS compatibility losses and decoder fix boundaries.

* test(runtime): use typed process exports in worker fixture

* test(runtime): align installer fixtures without growing test shards

* test(runtime): align release and guest runtime fixtures

* fix(test): canonicalize Windows temp roots for Node 24

Expand Windows short paths before creating test directories and owned child environments. Node 24 filesystem watchers otherwise abort when native long event paths differ from inherited short temporary paths. Preserve explicit custom-root spelling and existing cleanup ownership.

* test(ci): run Windows temp-root regressions in the native lane
2026-09-07 10:31:31 -07:00
Peter Steinberger 98bb2591c7 fix(tooling): preserve Git hook choices during install (#139461)
Read the effective hooks path before initializing an unset selection in worktree scope. Preserve inherited and empty settings; let Git refuse shared initialization instead of changing sibling checkout configuration.

Fixes #139449. Seven real-Git regression cases fail before the repair; the final 15-case suite and scoped checks pass. Tooling net -15 LOC.
2026-09-05 16:02:22 -07:00
Vincent KocandPeter Steinberger 8e5a3f3638 chore(test): migrate to stable Vitest 5 (#138264)
* build(test): migrate to stable Vitest 5

Co-authored-by: Peter Steinberger <steipete@gmail.com>

* docs(test): document Vitest 5 contracts

* test(test): prove Vitest cache invalidation

* test(test): stabilize report config load proof

* test(test): restore Vitest 5 compatibility

Co-authored-by: Peter Steinberger <steipete@gmail.com>

* test(test): isolate pnpm cache fixture registry

* fix(test): keep pnpm 12 env lock portable

* fix(test): preserve explicit Vitest project roots

* fix(test): preserve nested Vitest project identity

* test(test): expect captured Vitest name prefix

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-06 04:17:59 +09:00
Peter Steinberger 4675e3d6dc fix(deps): reduce source install filesystem churn with isolated linking (#135728)
* fix(deps): reduce source install filesystem churn with isolated linking

* fix(deps): preserve package ownership under isolated linking

* fix(deps): retain isolated package ownership in packaging and declarations

* fix(build): preserve Crabline dependency ownership with isolated linking

* fix(build): keep external plugin runtimes with their dependency owners
2026-09-01 19:56:06 -07:00
Peter Steinberger 1855fe0f4e docs: generate changelogs only at release time (#135136)
Align contributor guidance with the maintainer-requested release-only rule already recorded in AGENTS.md. Ordinary PRs and merges keep release-note context in PR bodies or commits; takeover permissions remain unchanged.
2026-09-01 04:37:00 -07:00
Peter Steinberger e7926e3002 docs: remove AI-assistance disclosure requirement for PRs (#132968) 2026-08-29 18:20:35 -07:00
Peter Steinberger 1879e4ea6b chore: block restricted literals in local commits (#132223)
* chore: block restricted literals in local commits

* fix: fully redact overlapping private literals
2026-08-28 20:00:36 -07:00
Martin Cleary 7f24f54214 docs: require discussion for material SQLite changes (#128876) 2026-08-24 23:53:14 +01:00
Vincent Koc 73ff2d2f45 fix(agents): distinguish review routing from enforcement (#126216) 2026-08-20 23:47:14 -07:00
Peter Steinberger c70aee247e refactor(scripts): migrate JavaScript tools to TypeScript (#121005)
* refactor(scripts): migrate JavaScript tools to TypeScript

* fix(ci): keep changed-scope preflight zero-install

* fix(ci): preserve zero-install script owners

* fix(ci): complete script migration follow-through

* fix(release): keep stable closeout zero-install

* fix(scripts): preserve standalone execution boundaries

* fix(scripts): repair standalone loader boundaries

* fix(scripts): normalize gateway observation ids

* fix(scripts): keep Docker packager standalone

* test(scripts): preserve rebase cleanup helpers

* test(sessions): use tracked temp directory
2026-08-09 07:21:35 -07:00
Peter Steinberger 00a5db443a refactor: remove obsolete commit helper 2026-08-06 18:10:10 -07:00
Peter Steinberger fd0fdcc458 chore(docs): audit external links without gating PRs (#114643)
* docs: repair audited external links

* ci(docs): add advisory external link audit
2026-07-27 14:02:09 -04:00
clawsweeper[bot]clawsweeper <274271284+clawsweeper[bot]@users.noreply.github.com>PollyBot13
2a2b2b830c docs: explain pull request automation workflow (#101748)
Co-authored-by: clawsweeper <274271284+clawsweeper[bot]@users.noreply.github.com>
Co-authored-by: PollyBot13 <261872620+PollyBot13@users.noreply.github.com>
2026-07-16 20:29:15 -07:00
Vincent Koc f33ab243cf fix(sqlite): reject runtimes vulnerable to WAL corruption (#106065)
* fix(sqlite): require WAL-reset-safe Node runtime

* docs(sqlite): document safe Node runtime floor

* fix(sqlite): defer runtime library validation until use

* fix(ci): align startup memory with Node 24.15
2026-07-13 13:59:00 +08:00
Josh Lehman 2367511310 docs: refresh contributing maintainer roster (#102998) 2026-07-09 10:02:23 -07:00
lin-hongkuanandlin-hongkuan 23527a456d docs: clarify source checkout Node floor (#97898)
* docs: clarify source checkout Node floor

* chore: refresh CI for PR #97898

---------

Co-authored-by: lin-hongkuan <lin-hongkuan@users.noreply.github.com>
2026-06-30 17:55:47 -07:00
Vincent Koc fa78cfbfb7 Reapply "docs: document agent issue and PR routing (#96714)"
This reverts commit c691872b9e.
2026-06-26 16:52:45 -07:00
Vincent Koc c691872b9e Revert "docs: document agent issue and PR routing (#96714)"
This reverts commit 43dd34262e.
2026-06-26 16:52:17 -07:00
43dd34262e docs: document agent issue and PR routing (#96714)
* docs: document agent issue and pr routing

* docs: link contribution routes from readme

* docs: point routing docs at github codeowners

* docs(contributing): keep routing guidance concise

---------

Co-authored-by: Eva <eva@100yen.org>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-06-27 00:34:58 +01:00
brokemac79 8972bff98d [codex] docs: clarify PR body evidence updates (#95076) 2026-06-19 14:49:05 -06:00
Hannes Rudolph 4a0f497f16 improve: simplify PR context and evidence (#94676)
* improve: simplify PR context and evidence

* improve: decouple PR context from proof labels

* fix: satisfy PR context lint
2026-06-19 14:00:38 -06:00
Vincent Koc 16a5d3b51a fix(scripts): make fast commits skip hooks 2026-06-17 16:12:47 +02:00
Jason (Json) f271f003d4 docs: require maintainer-editable PR branches
Require contributor and agent-created PR branches to stay maintainer-editable, with a GitHub Actions/secrets caveat for fork PRs.

Verification:
- pnpm docs:list
- git diff --check
- Real behavior proof: https://github.com/openclaw/openclaw/actions/runs/26409882732/job/77741796262
- check-docs: https://github.com/openclaw/openclaw/actions/runs/26409857961/job/77741751070

Changelog intentionally skipped per maintainer request.

Co-authored-by: FullerStackDev <263060202+fuller-stack-dev@users.noreply.github.com>
2026-05-25 17:19:40 +01:00
Peter Steinberger ee5b06f9fe docs: clarify contributor changelog ownership 2026-05-11 14:26:56 +01:00
Val Alexander 49cb2b97ae docs: update Val maintainer areas (#79680) 2026-05-09 01:39:31 -05:00
Momo 681042a897 Add Maurice Niu as maintainer (#79219) 2026-05-08 11:33:58 +08:00
Vincent Koc 91ed1604b0 docs(imessage): make imsg the supported setup path 2026-05-07 12:53:01 -07:00
Peter Steinberger 330ba1fa31 refactor: move canvas to plugin surfaces 2026-05-07 09:07:18 +01:00
pashpashpash d05415d603 docs: remind contributors to redact proof evidence (#78630) 2026-05-07 06:53:01 +09:00
Frank Yang 3e04755874 docs: add Frank Yang to maintainers 2026-05-06 16:19:19 +08:00
pashpashpashandPeter Steinberger 70f34bf177 Require real behavior proof for external PRs (#77622)
* ci: require real behavior proof for external PRs

* fix: tighten real behavior proof heuristics

* fix: reject test-only real behavior proof labels

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-05-05 05:45:30 +01:00
Tak Hoffman a8467c9fce docs(contributing): align PR cap 2026-05-03 19:44:06 -05:00
3120401f53 feat(channel) yuanbao (#72756)
* feat(channel) yuanbao

* feat(channel) yuanbao

* docs(changelog): note Yuanbao channel plugin (#72756) (thanks @loongfay)

---------

Co-authored-by: loongzhao <loongzhao@tencent.com>
Co-authored-by: sliverp <870080352@qq.com>
2026-04-27 23:04:33 +08:00
JonathanandJonathan Amponsah 9f5dc4045c docs: fix stale community links in README and CONTRIBUTING (#69945)
Co-authored-by: Jonathan Amponsah <amponsahjonathan442@gmail.com>
2026-04-21 22:47:16 -07:00
Josh Lehman dafc71c913 Update contributor details for Josh Lehman (#67824) 2026-04-16 14:05:56 -07:00
Shadow 32222812ea Revise contribution process for new features 2026-04-15 11:04:30 -05:00
Mason Huang 0aea99883c Add Mason Huang as maintainer (#66974) 2026-04-15 12:36:11 +08:00
Sliverp 5b92dbaeee docs:add maintainer info (#65762) 2026-04-13 14:46:37 +08:00
Vincent Koc 6133d248e2 docs(contributing): note committer fast mode 2026-04-12 05:11:55 +01:00
Vincent Koc b82fc1fdad docs(boundary): codify shared test helper plugin seams 2026-04-10 08:27:35 +01:00
Chinar Amrutkar e419989c34 docs: add PR limits to contribution guide (#60910)
Add PR limits section explaining:
- 10 open PRs per author cap
- r: too-many-prs label auto-close mechanism
- How to get exception via #clawtributors Discord

Fixes: #38283
2026-04-05 05:17:10 +09:00
Qkal 3a52b475ab Docs: clarify first-contribution fallback when no good-first-issue labels are open (#58530) 2026-03-31 21:09:10 -04:00
Peter Steinberger 09f2832670 test: split contract seams from unit lane 2026-03-27 16:28:23 +00:00