Releases: openclaw/openclaw
Release list
openclaw 2026.9.8
OpenClaw v2026.9.8
58 commits · 43 pull requests · 21 contributors
Changes included in this release
The release notes and changelog contain the same content, presented in two formats:
- Release notes — formatted for people, with expandable sections.
- Changelog — plain Markdown for AI agents and tools.
Thanks
@609NFT @aniketkrs @aniruddhaadak80 @EndeavorPioneer @ericcaiwx-star @fuller-stack-dev @hailongguo0530-alt @jasdeepohri-max @miguelpt2026 @NickM83 @obviyus @Patrick-Erichsen @PennyVibe @RomneyDa @scotthuang @steipete @VACInc @vincentkoc @WG-Mojo @xilopaint @yashas-13
Release verification
- npm package: https://www.npmjs.com/package/openclaw/v/2026.9.8
- registry tarball: https://registry.npmjs.org/openclaw/-/openclaw-2026.9.8.tgz
- integrity:
sha512-G+JkNUhtpDE3cXR4AEi2NyyG9fqI/T2WUSl8ZnR8AATH8Dh1kC3qYFL7wwPoZtgHiP/cszA86PEiE0PDysxb9Q== - release SHA:
fc23bc864e4553c2d215e479eeec47b67a0bf943 - full release CI report: https://github.com/openclaw/releases/blob/main/evidence/2026.9.8/release-evidence.md
- release publish: https://github.com/openclaw/openclaw/actions/runs/37089852299
- npm preflight: https://github.com/openclaw/openclaw/actions/runs/37046778498
- full release validation: https://github.com/openclaw/openclaw/actions/runs/37045896743
- plugin npm publish: https://github.com/openclaw/openclaw/actions/runs/37090141905
- plugin ClawHub submission: https://github.com/openclaw/openclaw/actions/runs/37090144556; public artifact verification follows successful release-parent completion
- plugin ClawHub bootstrap: not needed
- OpenClaw npm publish: https://github.com/openclaw/openclaw/actions/runs/37087759921/attempts/1
- Telegram integration checks: waived by the release owner for 2026.9.8 (source QA, Package Acceptance, published-package E2E); not run.
- Android APK: skipped — apps/android/version.json is 2026.8.2, release train is 2026.9.8; run pnpm android:version:pin -- --from-gateway before the next tag.
openclaw 2026.8.35
This is a gateway-only extended-stable release, which is our current equivalent to LTS. This release is OpenClaw from the end of August 2026, plus critical security updates, reliability and performance fixes, and features like new model support. The latest version of OpenClaw at the time of this release is 2026.9.7
2026.8.35
Highlights
- GPT-6.1 Sol support: add the current Sol model across OpenAI routing, discovery, reasoning, harness, and Reef guard-model boundaries. (#161400, #162955)
- Safer updates and recovery: preserve plugin settings, prevent duplicate Gateways, handle pnpm package updates without terminal failures, and retain plugin inventory through migration. (#160344, #160193, #161920, #161485) Thanks @EndeavorPioneer, @grtninja, @alkor2000, @xilopaint, and @aniruddhaadak80.
- Reliable agent completion: preserve complete delegated and CLI answers, release suspended child capacity, recover full cron output, and prevent failed requests from consuming steered questions. (#162843, #162368, #160520, #162439) Thanks @zyz619963502zyz, @holgergruenhagen, @armstrongsam25, @davidcittadini, @jayzhou2309, and @obviyus.
- Security and ownership hardening: keep secret-store kinds stable during rotation, restore admitted secret-egress execution, and retain explicit cron tool allowlists while repairing stale automatic snapshots. (#160926, #160760, #162432) Thanks @zachisfine, @yetval, @VACInc, and @obviyus.
- Channel and integration reliability: repair Gmail and IMAP watchers, Matrix direct mappings, Telegram progress, remote MCP startup, and managed llama.cpp startup on clean Windows hosts. (#161503, #160413, #161727, #161546, #162376, #163093) Thanks @obviyus, @kazuyuki-eguchi, @Ayushdevo, @addyCooks, @VACInc, @Patrick-Erichsen, and @RomneyDa.
- Performance and UI continuity: bound model-catalog waits, reduce Codex fleet heap pressure, and keep saved WebChat replies visible across history refresh races. (#161132, #162912, #162763) Thanks @jayzhou2309, @Flakedict, @obviyus, @609NFT, and @VACInc.
Changes
- Extended-stable release preparation: align OpenClaw and every publishable official plugin to 2026.8.35 while preserving the 2026.8.34 publication contract.
- Model compatibility: add GPT-6.1 Sol to the branch-native OpenAI and Reef compatibility owners. (#161400, #162955)
Fixes
- Update safety: preserve incompatible-plugin settings through recovery, keep retained plugin records during migration, avoid pnpm terminal failures, and carry the existing Gateway lock through container/direct startup. (#160344, #161485, #161920, #160193) Thanks @EndeavorPioneer, @aniruddhaadak80, @alkor2000, @xilopaint, and @grtninja.
- Agent delivery: recover uncapped cron replies, preserve complete CLI subagent answers, honor skipped announcements, retain detached transcripts, release suspended child slots, and keep failed requests from replacing earlier questions with a steer. (#160520, #162843, #161542, #161091, #162368, #162439) Thanks @jayzhou2309, @zyz619963502zyz, @holgergruenhagen, @armstrongsam25, @davidcittadini, and @obviyus.
- Cron and tools: bound thinking-catalog hydration, repair stale automatic tool snapshots without widening explicit allowlists, and deliver manual runs after their creating turn ends. (#161132, #162432, #162780) Thanks @jayzhou2309, @Flakedict, and @obviyus.
- Sessions and tool results: reject malformed session targets, preserve spawned working directories, project deeply nested MCP results safely, and keep remote MCP bundles working in native sessions. (#161533, #162308, #160825, #162376) Thanks @wangmiao0668000666, @Takhoffman, @hpyhandsome, and @Patrick-Erichsen.
- Channels: recover Gmail transient binds, bound IMAP backlog processing, restore Matrix direct mappings, and restore Telegram progress when hooks suppress previews. (#161503, #160413, #161727, #161546) Thanks @obviyus, @kazuyuki-eguchi, @Ayushdevo, @addyCooks, and @VACInc.
- Runtime reliability: prevent redaction stalls, cancel stale thinking-catalog waits, pass the responding agent to TTS model selection, stop durable worker retries from freezing hosts, reduce Codex fleet heap use, and install the required Visual C++ runtime after a managed llama.cpp launch failure. (#161089, #161319, #161454, #160812, #162912, #163093) Thanks @Baumus, @drakeo338, @aounakram, @RileyJJY, @aniruddhaadak80, @obviyus, @609NFT, and @RomneyDa.
- Secrets and sandboxing: retain secret entry kinds during value rotation and repair read-only copied skills without escaping their confined roots. (#160926, #162304, #162295) Thanks @zachisfine and @yetval.
- WebChat: keep saved replies visible when stale history responses race with live messages. (#162763) Thanks @VACInc.
Complete contribution record
This audited record covers the complete v2026.8.34..741d94f history: 49 in-range PRs + 0 retained seed-only PRs = 49 unique PRs. The generation manifest also supplies direct commits as editorial input; the grouped notes above prioritize user impact.
Pull requests
- PR #160344 Related #159477. Thanks @EndeavorPioneer.
- PR #160193 Related #159941. Thanks @grtninja.
- PR #160825 Related #160418. Thanks @wangmiao0668000666 and @Takhoffman and @hpyhandsome.
- PR #161400 Related #161397.
- PR #161089
- PR #161503 Related #161467. Thanks @obviyus and @kazuyuki-eguchi.
- PR #161533
- PR #161542
- PR #161319 Related #161310. Thanks @Baumus.
- PR #161270 Thanks @zachisfine.
- PR #161454 Related #161431. Thanks @drakeo338 and @aounakram.
- PR #160413 Related #160353. Thanks @Ayushdevo and @addyCooks.
- PR #161132 Related #161112. Thanks @jayzhou2309 and @Flakedict.
- PR #161727
- PR #161091
- PR #160812 Related #160735. Thanks @RileyJJY and @aniruddhaadak80.
- PR #161485 Related #161329. Thanks @aniruddhaadak80.
- PR #160760 Thanks @VACInc.
- PR #160715 Thanks @VACInc.
- PR #160843 Thanks @VACInc.
- PR #162304
- PR #160520 Thanks @jayzhou2309.
- PR #161920 Related #161866. Thanks @alkor2000 and @xilopaint.
- PR #162308
- PR #162368 Related #162267. Thanks @armstrongsam25 and @davidcittadini.
- PR #162295
- PR #162439 Thanks @obviyus.
- PR #149925 Thanks @obviyus.
- PR #77023 Thanks @fuller-stack-dev.
- PR #109709
- PR #161069 Thanks @obviyus.
- PR #161546 Thanks @VACInc.
- PR #162763 Thanks @VACInc.
- PR #162432 Thanks @obviyus.
- PR #137832 Related #130753. Thanks @jalehman.
- PR #147969 Thanks @obviyus.
- PR #91499 Thanks @mmaps.
- PR #112483 Thanks @joshavant.
- PR #112661 Related #111809. Thanks @joshavant and @andersonjeccel.
- PR #162780 Thanks @obviyus.
- PR #104595
- PR #115404 Related #115758. Thanks @RomneyDa.
- PR #121113
- PR #162912 Related #162802. Thanks @obviyus and @609NFT.
- PR #162843 Related #162777. Thanks @zyz619963502zyz and @holgergruenhagen.
- PR #162955
- PR #162376 Thanks @Patrick-Erichsen.
- PR #163093 Thanks @RomneyDa.
- PR #160926 Related #158968. Thanks @zachisfine and @yetval.
Release verification
- npm package: https://www.npmjs.com/package/openclaw/v/2026.8.35
- registry tarball: https://registry.npmjs.org/openclaw/-/openclaw-2026.8.35.tgz
- integrity:
sha512-7Bk/IeHTk04gfR4rW2SEVwwmGiXg2CcRxL3K1U2JzTgwbSSSlbX/yoLEbkiiSMOLtOuAi1ZfVbgmSsSlOA/E6g== - release SHA:
713ba5785d72d6ed1cec971e21307f16cc4234a6 - npm preflight: https://github.com/openclaw/openclaw/actions/runs/36994752811
- full release validation: https://github.com/openclaw/openclaw/actions/runs/36994246053
- plugin npm publication: https://github.com/openclaw/openclaw/actions/runs/37008498463
- OpenClaw npm publication: https://github.com/openclaw/openclaw/actions/runs/37010843200 — npm accepted publication; the workflow expired only during bounded registry readback.
- Docker publication recovery: https://github.com/openclaw/openclaw/actions/runs/37013839190
- Manual finalization: owner-approved after independent verification of npm signatures and provenance, the
extended-stableselector, all 89 plugin packages, Docker digests and attestations, both requested upgrade paths, live model and channel paths, and public container smoke.
openclaw 2026.8.34
This is a gateway-only extended-stable release, which is our current equivalent to LTS. This release is OpenClaw from the end of August 2026, plus critical security updates, reliability and performance fixes, and features like new model support. The latest version of OpenClaw at the time of this release is 2026.9.7
2026.8.34
Highlights
- Extended-stable correctness rollup: backport 113 audit-selected fix units across upgrades, Doctor, authentication, sessions, channels, plugins, sandboxing, filesystem safety, model runtimes, and release packaging.
- Complete rescan: re-evaluate the full 2026.8.33 discovery range, large mixed-purpose pull requests, and the 2026.7.35 lineage instead of advancing only from the previous backport cursor.
- Upgrade and recovery hardening: preserve credentials, agent state, plugin inventory, transcripts, schedules, service ownership, and runtime links through upgrades, restarts, and Doctor repair.
- Boundary fixes: tighten remote filesystem mutation, plugin and skill scanning, browser authentication, channel reply identity, private skill ingress, and scoped runtime ownership.
Changes
- Extended-stable release preparation: align OpenClaw, publishable plugins, native version metadata, generated channel catalogs, and npm package inventories to 2026.8.34.
Fixes
- Plugins: Recover orphan installs without weakening ownership.
- Doctor: Repair keyed multi-agent rosters without ownership (#134706)
- Prevent device pairing migration crash on contaminated records.
- Doctor: Preserve per-agent memory search during upgrades.
- Doctor: Detect shared auth migration by provenance (#134808)
- Cron: Refuse stale doctor store rewrites.
- Gateway: Refresh model catalog after auth changes (#134361)
- Openai: Repair stale doctor route pins.
- Auth: Verify shared credential migration receipts (#134952)
- Cron: Keep model aliases scoped to the selected owner (#135069)
- Memory: Resolve profile auth for compatible embeddings (#134744)
- Auth: Recover credentials stranded by completed migrations (#135346)
- Auth: Relogin repairs stale profile order after upgrade.
- Auth: Preserve custom provider SecretRefs in Doctor.
- Docker: Install libgomp1 in the runtime image for managed llama.cpp (#134532)
- Devices: Allow authorized scoped node token management (#135617)
- Msteams: Thread context is dropped when a channel reply has no replyToId (#129345)
- Ui: Ignore tool-only model auth rows (#134218)
- Cron: Kind change fails with "command env must be an object" when env is omitted (#134639)
- Backup: Exclude workspaces before traversal.
- Infra: Drop empty PATHEXT entries from Windows extension lookup (#135807)
- Anthropic: Context usage is lost when a proxy omits message_delta usage (#135467)
- Systemd: Protect credentials in managed backups (#131786)
- Agents: Preserve requester MCP runtime ownership (#134819)
- Plugins: Refresh persisted registry when source mounts change (#136517)
- Gateway restart hangs while followup drain retries a draining error (#136713)
- Auth: Preserve OAuth metadata during session SDK refresh (#127988)
- Doctor: Recognize configured memory provider secret references (#137782)
- Sessions: Preserve logical shared-store ownership (#138380)
- Full-access tasks lose tools after Gateway restart (#138701)
- Keep unchanged files out of session diffs (#138877)
- Auth: Recover billing-disabled profiles in minutes instead of hours (#136364)
- Auth: Keep an unset default model unchanged during login (#139218)
- Gateway: Avoid crashes when an upgrading client disconnects (#139061)
- Shell-env: Preserve CLI terminal ownership during login imports (#139308)
- Auto-reply: Fold trailing transcript growth into memory-flush fresh totals (#138928)
- Cron: Preserve pending paced checks across restart (#140083)
- Daemon: Systemd install no longer aborts on "ownership could not be verified" after a clock step (#137253)
- Config: Apply environment changes after in-process restart (#141296)
- Pasted text is missing in model-locked Codex sessions (#142021)
- Docker: Restore source builds after dependency ownership guard (#142073)
- Security: Preserve existing WhatsApp group allowlists (#142589)
- Doctor: Avoid installing unselected search providers (#142640)
- Doctor: Migrate legacy Codex music model selectors (#143235)
- Doctor: Preserve selected model metadata in diagnostics (#144332)
- Discord: Report parent channel denies for thread permissions (#121144)
- Config: Avoid false model changes when saving settings (#144807)
- Doctor: Preserve legacy registry files when quarantine fails (#144787)
- Retain route ownership while discovering conversations (#146927)
- Install: Preserve runtime links when Node validation fails (#147221)
- Doctor reports missing OAuth dir for channel config with no installed plugin (#147888)
- Doctor: Stop private pending inputs replaying after session repair (#148625)
- Channels: Settle task-scoped context leases once (#148922)
- Push: Normalize malformed proxy auth errors (#149112)
- Cron: Reject invalid stagger before silent schedule changes (#151740)
- Cli: Keep model validation out of session execution (#154763)
- Agents: Treat empty credential environment variables as unresolved (#155558)
- Doctor: Apply ambient-owner fallback to dream diary and all memory target handlers (#156437)
- Sandbox: Unblock scoped recreation across runtime targets (#157808)
- Security: Parse gpt generation numbers in the audit tier check (#140012)
- Doctor: Report shared auth health without a default agent (#134902)
- Doctor: Converge redundant shared auth relocation subsets (#135096)
- Doctor: Report retained device-auth files (#133978)
- Update: Stop detached updates after chat ownership is revoked (#137312)
- Doctor: Inspect source auth stores during full lint (#137610)
- Gateway: Recover queued RPC replies across restart (#138565)
- Doctor: Preserve legacy ownership during config repair (#138837)
- Prevent browser profile permission hangs in Doctor (#139612)
- Gateway: Prevent systemd restarts from hanging (#140914)
- Doctor: Recover legacy node tokens with invalid scopes (#143599)
- Skills: Refresh session snapshots on gateway restart (#122110)
- Doctor: Session SQLite import drops Codex assistant messages from legacy transcripts (#140296)
- Cron: Forward claude-cli auth profile on scheduled runs to prevent OAuth expiration (#144266)
- Discord: Preserve sender-owned line limits and reply scope (#137969)
- Install: Never replace or break an existing nvm during installation (#145317)
- Sessions: Recover omitted historical transcripts in Doctor (#120781)
- Update: Recognize custom npm prefix installations (#146091)
- Context: Preserve provider-scoped prompt budgets before reply maintenance (#141052)
- Sessions: Prevent Doctor and startup memory exhaustion (#149704)
- Daemon: Preserve inline auth through service upgrades (#149686)
- Update: Verify paired trusted-proxy gateways with service credentials (#153540)
- Background continuations lose session access and GitHub tools (#141865)
- Doctor: Decode session headers across read chunk boundaries (#154034)
- Faulty compaction probe wedges run steering and restart aborts (#154868)
- Ui: Publish rejected goal operations (#156363)
- Commands: Deduplicate session lifecycle keys (#158487)
- Plugins: Preserve runtime artifact preference (#158487)
- Agents: Strip private skill authoring from public ingress (#159220)
- Plugins: Preserve include ownership during uninstall (#159945)
- Channels: Restore system-agent approval reactions (#159132)
- Moonshot: Reject inherited thinking-model keys (#158437)
- Tencent: Ignore inherited effort-map keys (#158437)
- Workers: Observe already-aborted operation promises (#158228)
- Gateway: Reject non-object Claude history rows (#158228)
- Copilot: Recover pool after synchronous factory failures (#157819)
- Tlon: Preserve IPv6 ship origins (#157825)
- Sms: Clean revoked inbound media (#157825)
- Slack: Preserve replacement webhook registrations (#158085)
- Matrix: Accept system-agent approval reactions (#158164)
- Channels: Retain typing tick exclusivity across restart (#158830)
- Acp: Format unset optional tool arguments (#159417)
- Meeting: Clean up partial audio startup (#157982)
- Exec: Retain prepared plugin environment (#158378)
- Mxc: Clean temp directory after bridge failure (#158532)
- Discord: Preserve batched native reply identities (#158886)
- Skills: Count omitted dangerous exec aliases once (#158906)
- Sandbox: Preserve remote mutation path bytes (#159346)
- Browser: Accept standard CDP header containers (#159430)
- Plugins: Preserve sparse catalog preferences (#159945)
- Doctor: Preserve complete plugin inventory (#153901)
- Fs: Preserve bounded filesystem correctness (#157524)
Complete contribution record
This release represents 113 approved units: 60 exact source commits, 25 material adaptations, 27 narrow slices extracted from large or mixed-purpose pull requests, and one 2026.7.35 plugin-inventory parity repair. Units already covered by the 2026.8.33 architecture, or whose newer storage contract does not exist on this release line, are recorded as evidence-backed inclusions rather than duplicate or speculative code.
Release verification
- npm package: https://www.npmjs.com/package/openclaw/v/2026.8.34
- registry tarball: https://registry.npmjs.org/openclaw/-/openclaw-2026.8.34.tgz
- integrity: `sha512-wr/4SIbHkX2sSCi5etvIevjYK4IWfKsQmPf3Yhhrix4Eg94CALkdBr8VPAQsbMXyiILGQpW6syjXsmFs+aCvzg=...
openclaw 2026.9.7
OpenClaw v2026.9.7
518 direct commits · 2,818 pull requests · 334 contributors
Changes included in this release
The release notes and changelog contain the same content, presented in two formats:
- Release notes — formatted for people, with expandable sections.
- Changelog — plain Markdown for AI agents and tools.
Thanks
@609NFT @Aalmann @aatreya @abacha @abuegab1-spec @ada-KVR @AgentSolomon @aicyberg @ajmtrz @Alekstodo @aleps001 @alexph-dev @alibux @Alix-007 @altaywtf @amarsmission @AmesGit @anarchia-99 @andersonjeccel @aniruddhaadak80 @anyech @apple2345-pixel @areslp @AS76 @aspalagin @auriga-agents @avirtudazo-officeconnect @AXEG0 @axiom-ncis @Ayushdevo @azakharko @baiwei0427 @bappamp4 @Baumus @bdjben @benlaube @bill-starfoundry @BillVerhelle @bitkylin @blackdiamondcyber-png @blackeyes-boy @blyszcz @BoatAngle @bogdandragosvasile @boycez @brokemac79 @Bruce-Yii @brucemccurdy @canvrno-oai @Captain69G @CarotaWealth @caseyjustus @cbhawthorne84 @ceckert @chac4l @chaolawo-byte @charlie-morrison @chelsealong @chopin-op60 @choury @cipp-ashe @cjn119-ui @Colton-Harris @Conan-Scott @context-down @coygeek @cp7553479 @Cyb3rb1ade @dankarization @DarkJuanFra @DasX @davidcittadini @desksk @destinedenergy @dh-js @dimonnld @dmmc12 @dmwtech @DonnieFi @dots-oai @dragomirdimitrov-mmrndm @Dreamer-HIT @DrToNy1 @dwalthour @dwonshin @dynamite-bud @eddiekk @EduHerranz @ekinnee @eleqtrizit @EndeavorPioneer @eric-basketbot @ericcaiwx-star @etzelm @fchaudhryspear @fduch-stranger @Flakedict @flyto168 @fourestfire @fransqaas @freeqaz-openai @fulgerulnegru @fuller-stack-dev @Fuma2013 @funklawfirm-dotcom @galiniliev @gaoanze888 @Geokec @giangthb @giodl73 @giodl73-repo @gisk0 @gokay-ai @goslingmanagment @Gr33n93 @grape404 @Grynn @h94916 @haldana88 @hannesrudolph @hartmark @he-yufeng @Hensarj @highfly-hi @Hmache @holny @hpyhandsome @htuyer121 @hugenshen @hurtlovewow @hxy91819 @ion-developing @Irish-Joseph @islandpreneur007 @ivankuznetsov @IWhatsskill @Jackten @jalehman @jb168 @jb510 @JefRH1 @jiangzhao2121-debug @jihoon-ernesto @jjjhenriksen @johnfink8 @johnnyjrizzo @JordanNewell @joshavant @joshbunker @joshpetras @Journey417 @jscd98 @jtatum @JUMPUNDER @kai0126-claw @Kaspnov @kassol @kchuang1015 @kevinlin-openai @keysersozeh @Kiiatkin @Kimiyu-186 @kirylh @kybrcore @laisonamarante @laurencebrown @laurentschwartz @leilei3167 @lennartack @Leon-SK668 @liemnhoang @LinzeShi @lisheguo @liunan12345678-spec @LiuwqGit @liuxb553-panda @liyoulu @Loganwoooof @lovelefeng-glitch @lucarinaorg @Ludwigtheo0815 @lukewd @ly85206559 @marinabotobs @mariorivas1 @markmcd @markomiric @martinxomag @Marvinthebored @masatohoshino @MasterSwords1 @Matuno @mcaxtr @MertBasar0 @meska @MikyWang @mmartoccia @MoerAI @mohit @mrclawfield @mrzeepek @msobrosa @myagizmaktav @Nakagawa-master @name5566 @Navras98 @ndakota79 @neyudo @NianJiuZst @Nickfost @NicolasDerito [@Niriakot](h...
openclaw 2026.8.33
This is a gateway-only extended-stable release, which is our current equivalent to LTS. This release is OpenClaw from the end of August 2026, plus critical security updates, reliability and performance fixes, and features like new model support. The latest version of OpenClaw at the time of this release is 2026.9.6
2026.8.33
Highlights
- Current flagship models: add Meta Muse Spark 1.3, Anthropic Fable 5.1, OpenAI GPT-6 Astra, and OpenAI/fal GPT Image 2.5 support to the extended-stable line. (#135638, #136553, #137550, #143068, #143069)
- Complete GPT-5.6 family support: preserve Sol, Terra, and Luna catalog, routing, migration, image, vision, and thinking behavior, including Ultra reasoning across model-runtime boundaries and Bedrock tool-result images. (#135397, #149336)
- Extended-stable security rollup: reconcile all repository advisories that affect 2026.8.2, harden Prometheus metrics authorization and Discord asset/voice ownership, and clear the production Nodemailer advisory gate. (#136700, #137433, #140334, #140903)
Changes
- Extended-stable release preparation: normalize OpenClaw, all publishable plugins, and native version metadata to 2026.8.33 while retaining the release-line-compatible publication workflows from 2026.8.2.
Fixes
- Anthropic reasoning continuity: preserve Fable 5.1 reasoning through model switches and runtime events. (#136782)
- OpenAI discovery: require successful model discovery before offering GPT-6 Astra through OAuth. (#137561)
- Doctor skill state: preserve explicitly enabled skills during automatic updates. (#138730)
- Generated media: retain generated images when a later tool call fails. (#131226)
- Matrix verification: refresh verification state before reporting device trust. (#136226)
- Prometheus authorization: reject metric scrapes that lack the configured operator-read scope. (#140903)
- Discord media policy: enforce sender media policy for guild asset uploads. (#140334)
- Discord realtime ownership: preserve speaker and playback ownership across voice lifecycle transitions. (#137433)
- Discord consult cancellation: record host-cancelled realtime consults as cancellation, suppress the generic error fallback, and keep the voice session ready for the next request. (#134924, #135380)
- Dependency security: override the IMAP dependency graph to Nodemailer 9.1.1, clearing the address-parser denial-of-service and related domain/content-access advisories. (#136700)
- iOS release validation: update the WebRTC binary dependency to 152.0.0 after the 151.0.0 artifact was withdrawn. (#134942)
openclaw 2026.9.6
macOS app rebuilt 2026-09-24: the original 2026.9.6 macOS build crashed at launch (#156861) and was replaced at 09:52 UTC by a rebuilt, notarized 2026.9.6 build with the fix (#156881). Download the DMG below or update from 2026.9.5 in the app. If you installed the earlier 2026.9.6 build and it does not launch, install the DMG once. The npm package is unchanged.
OpenClaw v2026.9.6
178 direct commits · 2,614 pull requests · 351 contributors
Changes included in this release
The release notes and changelog contain the same content, presented in two formats:
- Release notes — formatted for people, with expandable sections.
- Changelog — plain Markdown for AI agents and tools.
Thanks
@0-danielviktorovich-0 @1Vision365-PeterTijsma @609NFT @aatreya @abacha @AbuSido82 @agebreak0083 @agent-axos @AgentSolomon @ago1776 @Albertyn87 @alex-brave @alexey-pelykh @Alix-007 @allen0373 @altaywtf @alvelda @amittell @Andapeng @aniketkrs @aniruddhaadak80 @anyech @ayoakouh @azuretek @baiwei0427 @baovo15 @Bartok9 @Baumus @bdjben @beeven @beings1988-lab @bek91 @benediktweber @berklingtools @bharatvasan @BinChenUtrecht @bipolar84 @bitbalancer @blackeyes-boy @bobbygaerd @BodegaClaw @BorClaw @BottaniCals @britrik @brokemac79 @Bruce-Yii @brunorapido @BsnizND @camerono @Carme99 @ceckert @CHE10X @chelsealong @cipp-ashe @cjn119-ui @ckupferschmid @cloudgg82-blip @cnflwzh @cognos2013 @colehammond65 @Colton-Harris @ComfyChloe @Conan-Scott @cookywook @cortanapham @cpsleepy @ctbritt @Cyb3rb1ade @dale-goes-fast @damiansmazurek @dankarization @DasX @davidchyi-beep @davidcittadini @Davidofflol12 @Dazlarus @ddupg @Deregtx @desksk @destinedenergy @dh-js @dimonnld @dltlaos11 @dmlau76 @dmnksss @dom521 @DonnieFi @droidyouwerelookingfor @DrToNy1 @dustytext-bot @duybaovin @easyteacher @edenfunf @edgarstool @edrwalker @eefreenyc @Eragim @ericcaiwx-star @ericcurtin @ericpearson @ERMALTA @etzelm @ezimerman @Fatal0607 @fduch-stranger @fede-kamel @flynnmcpoc @flyto168 @fozzels-assistant @fray-ai @freshxiaoyao @fulgerulnegru @fuller-stack-dev @Gabrielnkl @galiniliev @ge0el @gennadyclaw @giodl73-repo @GoldenrodScript @gorkem2020 @goutamadwant @Grynn @guarismo @guerilla47 @gwjr @Haderach-Ram @hannesrudolph @hannnnn-l @harjothkhara @harshitgupta31415 @hartmark @HaukeSchnau @hhkwoong @holny @hpyhandsome @hxy8241 @hxy91819 @HypocritePro @imHw @isinghmitesh @islandpreneur007 @itanyplus @iuiu-py @ivankuznetsov @IWhatsskill @iXandru @Jackten @jacobtomlinson @jalehman @jammyclaw @jarvis-stephens-bot @jason-allen-oneal @jaxonparrott @jb510 @jesse-merhi @Jey2311 @jhgaylor @jiangwanxin1982-ctrl @jjgao @jjjhenriksen @jnikolaidis @johnnyjrizzo @joncursi @JoPaMu @joshavant @joshpetras @jplavoiemtl @jzakirov @KarleeTDM @keithce @kevinlin-openai @Kiiatkin @Kimiyu-186 @kip-claw @kiranvk-2011 @kittitys @kpwillis @KrasimirKralev @KrauseFx @KrisWuli006 @L497c @lakemike @LandonSchropp @laurencebrown @laurenceputra @Lendersmark @Leon-SK668 @Lidashi1025 @lishewen @LiuwqGit @lojasarah @lraesly @lucarinaorg @ludovicfourrage @ly85206559 @marcio-absmartly @markGenhealth @markun-japan @Marvinthebored @masatohoshino @massad1977 @MasterSwords1 [@MattKan...
openclaw 2026.7.35
This is a gateway-only extended-stable release, which is our current equivalent to LTS. This release is OpenClaw from the end of July 2026, plus critical security updates, reliability and performance fixes, and features like new model support. The latest version of OpenClaw at the time of this release is 2026.9.5
2026.7.35
Fixes
- Doctor plugin registry: preserve the complete bundled plugin inventory when Doctor creates or repairs registry state, so default Browser, Canvas, pairing, file-transfer, phone-control, Talk voice, and Bonjour plugins remain available after restart. State-migration discovery now also recovers from the partial registry written by 2026.7.34 while retaining external plugin install records. Backported from #136045. Thanks @wangmiao0668000666.
Complete contribution record
This extended-stable follow-up was selected from a complete 1,418-commit audit after the prior 2026.7.34 audit cursor. No other defect observed during clean install or the 2026.6.35 upgrade required a July-line backport.
Cumulative July extended-stable notes
OpenClaw 2026.7.33 and 2026.7.34 were unstable extended-stable builds and were intentionally not published as GitHub Releases. Because 2026.7.35 is the first GitHub Release for the July maintenance line, it includes their complete changelogs below.
2026.7.33
Highlights
- Security and credential safety: harden command parsing, browser origin checks, plugin Git installs, diagnostics, service credentials, and webhook logging across Gateway and official plugins.
- Message and session integrity: preserve queued, imported, streamed, and tool-result messages across retries, hooks, recovery, and channel lifecycle transitions.
- Gateway reliability: close failed HTTP and Responses streams, bound expensive reads and history queries, and settle shutdown work before reporting completion. Thanks @RomneyDa.
- Channel delivery: repair Discord, Matrix, Telegram, Slack, WhatsApp, LINE, Feishu, Zalo, and meeting-plugin edge cases that could lose, corrupt, or stall messages.
- Provider and media robustness: bound provider requests and diagnostics, reject malformed payloads, and preserve valid tool schemas and response lifecycles. Thanks @RomneyDa.
Changes
- Extended-stable release tooling: carry the current Docker channel classifier, promoter, verification policy, and tests so
v2026.7.33can move only theextended-stable*aliases. Thanks @RomneyDa.
Fixes
- Security boundaries: reject escaped-newline command words, exact-origin mismatches, injected Git option arguments, inherited secret-response identifiers, unsafe browser mutations, and malformed or oversized node payloads.
- Delivery and transcript recovery: keep retry delays accurate, preserve imported messages and plugin-blocked tool results, retain detached admissions, and avoid silently dropping channel actions or recovery work. Thanks @RomneyDa.
- Resource and lifecycle safety: bound catalog, history, media, stderr, API, and provider waits; stop canceled parallel tools; drain channel shutdown; and reject queued worker requests after close. Thanks @RomneyDa.
- Text and schema correctness: preserve UTF-16 boundaries across user-visible truncation paths, keep root tool-schema properties, reject non-finite schema values, and report exact UTF-8 write sizes.
- Official plugins: repair message parsing, proxy paths, request timeouts, media handling, privacy-safe logging, and runtime aliases across the npm-published plugin inventory.
Complete contribution record
This audited record covers the complete v2026.7.1-2..4262532 history: 126 merged PRs. The generation manifest also supplies direct commits as editorial input; the grouped notes above prioritize user impact.
Pull requests
- PR #102438 fix: auth bookkeeping no longer reverts rotated OpenAI OAuth credentials. Related #102430. Thanks @obviyus.
- PR #102125 fix(gateway): finish plugin HTTP responses after post-header failures. Thanks @mushuiyu886.
- PR #102451 fix(memory-host): reject queued worker requests on shutdown. Thanks @QiuYuang.
- PR #102276 fix(agent-core): stop canceled parallel tools from starting. Related #102252. Thanks @harjothkhara and @yetval.
- PR #101739 fix(secrets): reject inherited exec response ids. Thanks @Alix-007.
- PR #102089 fix(twilio): redact webhook turnToken diagnostics. Thanks @Alix-007.
- PR #102403 fix(backup): write backup archive with owner-only 0o600 permissions. Thanks @yetval.
- PR #102398 fix(plugins): terminate git clone args so git: specs cannot inject options. Thanks @yetval.
- PR #38290 Gateway: allow extension origins in browser allowlist. Related #46520. Thanks @brunowowk and @mosidevv.
- PR #102013 fix(gateway): bound sessions.usage all-agent session discovery concurrency. Thanks @masatohoshino.
- PR #102825 fix(gateway): parse image data URLs linearly. Related #102393. Thanks @wangyan2026 and @yetval.
- PR #102426 fix: redact diagnostic config fields with schema hints [AI]. Thanks @pgondhi987.
- PR #101000 fix(plugins): bound hosted catalog feed reads on non-streaming responses. Thanks @hugenshen and @cursoragent.
- PR #104625 fix(gateway): demote startup close transport races.
- PR #104540 fix(sessions): prevent corrupted Unicode in persisted tool details. Thanks @zhangguiping-xydt.
- PR #104734 fix(models): redact synthetic auth credentials from models status --json. Related #104713. Thanks @ObliviateRickLin and @davefano.
- PR #104811 fix(gateway): keep channels stopped during shutdown and reload. Thanks @ShiroKSH.
- PR #102881 fix(gateway): reject disallowed browser Origin before accepting auth.mode=none on HTTP (#102834). Thanks @wangyan2026 and @yetval.
- PR #101469 fix(hooks): bound HOOK.md reads during hook install validation. Thanks @cxbAsDev.
- PR #103562 fix(discord): retry reply session init conflicts to prevent silent message loss. Related #102381. Thanks @cxbAsDev and @zuofengboss.
- PR #113700 fix: recover outbound messages after the correct retry delay.
- PR #113703 fix: preserve distinct imported CLI session messages.
- PR #113697 fix: repair tool-call transcripts when plugins block results.
- PR #114134 fix: require approval for escaped newline shell words [AI]. Thanks @pgondhi987.
- PR #102331 fix(google-meet): keep Meet sessions on the agent that joined them. Thanks @steipete-oai.
- PR #101630 fix(mattermost): truncate inbound preview on code-point boundary. Thanks @hugenshen and @cursoragent.
- PR #101736 fix(agents): keep steering metadata truncation UTF-16 safe. Thanks @chengzhichao-xydt and @Alix-007.
- PR #101617 fix(discord): prevent stale gateway error listeners after restart. Thanks @zhangguiping-xydt.
- PR #102246 fix(discord): keep gateway close reasons UTF-16 safe. Thanks @mushuiyu886.
- PR #102332 fix(agents): keep truncation surrogate-safe. Thanks @QiuYuang.
- PR #101815 fix(discord): split encoded video URLs from captions. Thanks @VectorPeak.
- PR #102090 fix(gateway): keep session title and preview text truncation UTF-16 safe. Thanks @wm0018.
- PR #101976 fix(acp): keep background-task summaries UTF-16 safe at truncation boundaries. Thanks @MoerAI.
- PR #102378 fix(acp): keep session update text truncation surrogate-safe. Thanks @zw-xysk.
- PR #102085 fix(agents): keep chunkString and buildResumeMessage truncation UTF-16 safe. Thanks @wm0018.
- PR #102105 fix(google-meet): handle stdout/stderr stream errors in node host. Thanks @wangmiao0668000666.
- PR #102157 fix(google-meet): bound Calendar v3 events.list request deadline. Thanks @wangmiao0668000666.
- PR #102395 fix(matrix): keep HTTP error and tool-progress truncations UTF-16 safe. Thanks @wangmiao0668000666.
- PR #102266 fix(security): keep channel-metadata and install-policy truncation surrogate-safe. Thanks @zw-xysk.
- PR #101781 fix(telegram): keep DM topic auto-rename user message UTF-16 safe. Thanks @hugenshen and @cursoragent.
- PR #101934 fix: keep task title truncation UTF-16 safe in restart/diagnostic output. Thanks @wm0018.
- PR #102407 fix(channels): keep inbound log previews UTF-16 safe. Thanks @miorbnli.
- PR #102466 fix(agents): keep tool-result context guard truncation UTF-16 safe. Thanks @chengzhichao-xydt.
- PR #102464 fix(tool-policy-audit): use truncateUtf16Safe for audit field truncation. Thanks @lsr911.
- PR #102467 fix(native-hook-relay): use truncateUtf16Safe for hook display text truncation. Thanks @lsr911.
- PR #102470 fix(gateway): keep chat history display text truncation surrogate-safe. Thanks @zw-xysk.
- PR #102483 fix(auto-reply,infra): keep startup context and heartbeat event text UTF-16 safe. Thanks @wings1029.
- PR #102478 fix(memory): snippets split emoji when truncated. Thanks @qingminglong.
- PR #101649 fix(zalouser): clear probe timeout after auth resolves. Thanks @Alix-007.
- PR #101506 fix(browser): bound Chrome launch stderr diagnostics. Thanks @mikasa0818.
- PR #102484 fix(gateway): keep live chat assistant buffer tail truncation UTF-16 safe. Thanks @wings1029.
- PR #102477 fix(talk): use truncateUtf16Safe for LLM-prompt-facing text truncation. Thanks @xydt-tanshanshan.
- PR #102496 fix(agents): keep provider error detail truncation UTF-16 safe. Thanks @chengzhichao-xydt.
- PR #102500 fix(mcp-runtime): use truncateUtf16Safe for MCP metadata text truncation. Thanks @lsr911.
- PR #102515 fix(compaction): use truncateUtf16Safe for post-compaction context text. Thanks @lsr911.
- PR #102525 fix(discord): use truncateUtf16Safe for deploy error body truncation. Thanks @lsr911.
- PR #102527 fix(oc-path): use truncateUtf16Safe for error message path truncation. Thanks @lsr911.
- **PR...
openclaw 2026.9.5
OpenClaw v2026.9.5
64 direct commits · 4,179 pull requests · 503 contributors
Changes included in this release
The release notes and changelog contain the same content, presented in two formats:
- Release notes — formatted for people, with expandable sections.
- Changelog — plain Markdown for AI agents and tools.
Thanks
@0xalydev @0xghost42 @100yenadmin @1052 @373246784-design @609nft @849261680 @aaajiao @aadi-joshi @aanalog-crow @aaronqianaa @aaronwander @aatreya @abacha @abhishek17n @adamamzalag @adele-with-a-b @adembektas @agebreak0083 @akagifreeez @akarshghale @aleps001 @alex-govorov @alexph-dev @alexscfraser @alix-007 @altaywtf @alvinveroy @amadeubordaneto @amittell @amknight @amtls-bbq @andersonjeccel @angeliti999 @aniruddhaadak80 @ansxor @anusha0501 @anyech @arnehorn @aron-intframe @arong-me @arrobapontocom-ui @as76 @aspalagin @ataraxiat @atlas-crete @aurorabotticus-svg @axeg0 @ayaangazali @azuretek @baeut @bartok9 @batmanscode @baumus @bdjben @blackhu @blaekmajik @bodegaclaw @bravostation @bronyazaychik0328 @bruce-cham @bruce-yii @bsg2000 @caiming0331 @carme99 @cassiemei @cbruney @celthi @chac4l @chachi-max @chazgo @cheddaran @chelsealong @chengyouj @chilango74 @cjn119-ui @ckai49500-source @clawli-coder @clawputerlabs @clode2026 @compoodment @conan-scott @cookywook @corvid-reads @countermarch @cqforest123-wq @ctbritt @cubefarm-valkyrie @dakshk-02 @danhayman @darkamenosa @dasx @datrab @davidbennett1979 @davidchpl @davidcittadini @dbarbatti @dbostik @dbraendle @dclosefuturex @decent9967 @delicate-xqy @deltaecho3 @dembe-agent @dennyjoe @deregtx @desksk @deyangar @dg-thinkgoode @dgmoon1994 @dh-js @dioubernardo @djskinner @dolencluka @dom521 @donniefi @doomclaw @drobison00 @eason-mars @eatmoreduck @edenfunf @ekinnee @eleqtrizit @elharonyclaw @eliasbogordos @emes @emi-ercel @emilywinslow-source @emmyallears @emoriwan @enominera @enotionz @ericcaiwx-star @erulkey @etzelm @familievantuyll-max @fatihfulness @fazedors @fede-kamel @finn763 @flowzito @flyintothesky @foxrainhy @foxsky @frankekn @fray-ai @freeqaz-openai @freshxiaoyao @fszcd @fuller-stack-dev @fuma2013 @fused-id @gabrielnkl @galshir @gaodaabao @gbates19-jpg @geekforlife @ggfp2dhtht-wq @ghank @giangthb @giodl73-repo @gisk0 @githoubi @glucksberg @gluo88 @gokay-ai @good-warning @gorkem2020 @gracy769 @gregbond @gryffindorhammer @grynn @guarismo @guxiangya @hanamizuki @hannesrudolph @harjothkhara @harshitgupta31415 @hartmark @haruaiclone-droid @he-yufeng @hermannmetzker-ai @hermanzeng @highsensor @hk31584-alt @holny @honki12345 @hugenshen @hustfreefly @hyspacex @igs-rogenlo @iloveleon19 @injinj @isinghmitesh @itanyplus @itilys @iwhatsskill @jackpothan @jacks1237 @jackten @jacobtomlinson @jakuboleksy @jalehman @jalfaro2876 @jamesy023 @jared-oberhaus @jason-allen-oneal @jaysonsolis @jb-lopez @jerabinovich @jesse-merhi @jh-pm [@jhvics1](https:...
OpenClaw Linux update channel
Latest published Linux companion: v2026.9.5
openclaw 2026.9.4
OpenClaw v2026.9.4
20 direct commits · 1,558 pull requests · 294 contributors
Changes included in this release
The release notes and changelog contain the same content, presented in two formats:
- Release notes — formatted for people, with expandable sections.
- Changelog — plain Markdown for AI agents and tools.
Thanks
@0xcyda @100yenadmin @1vision365-petertijsma @609nft @84dnnvbdvp-debug @aaajiao @aatreya @abacha @adinballew @aeoess @aevgeniou @ai-hpc @aimansour @akagifreeez @aleps001 @alexjpanagis @alexph-dev @alix-007 @aminekhettat @andrea-kingautomation @anguslogan01 @aniruddhaadak80 @ansxor @anyech @arcabotai @artemeey @ashawwal @aspalagin @avcarp @avp717 @ayaangazali @azuretek @barbarhan @baumus @benjaml4 @bottanicals @brainatworkharris @bricelb @bsniznd @c0ncatenate @cai-ops @ccaprani @ceckert @chegherian @chelsealong @chl-0537 @chriscantwell @chrislro @cjn119-ui @ck-xyz @cobblestone-digital1 @colton-harris @conan-scott @cp1369 @crash2kx @dasx @dbarbatti @developercrocodiles @devin-linux @dh-js @dilapidateddolphin98 @dillona @dimonnld @donniefi @dreamer-hit @drobison00 @dw1161 @ejc3 @ekinnee @elbourne12345 @eleqtrizit @elikampf @elvisio7 @enominera @ericcaiwx-star @fabiolr @fahrenhe1t @fanyangcs @fanyuantaier @fede-kamel @finn763 @flagshipclaw @fulgerulnegru @fuller-stack-dev @galiniliev @gdxbsv @geekforlife @githoubi @glenn-agent @glucksberg @goutamadwant @gozu @grynn @guarismo @guojiongming @gwiltschek @hannesrudolph @happyfaptain @harjothkhara @harshitgupta31415 @hawk5150 @hayden-cc @he-yufeng @hekzory @hermanzeng @hugenshen @husodrn46 @hxy91819 @igs-rogenlo @ikenraf @infocus13 @islandpreneur007 @itanyplus @iwhatsskill @jackatagenticforce @jackten @jai-assistant @jailbirt @jalehman @jarvismazz @jason-allen-oneal @jerabinovich @jesse-merhi @jialele @jinngimk-lang @jjjhenriksen @jkamgang @jlacroix82 @jlapenna @jmissig @jodok @junfxiao @kashivreddy @kaspnov @kesslerio @kiagentkronos-cell @kimiyu-186 @kingakrej @kingkong9817 @kirde @kopl-blip @kvnloo @laisonamarante @laurencebrown @laurenceputra @leapdragon @legupsystems @lei-happy @leilei3167 @lendersmark @leon-sk668 @lightningwarellc @linhongyu510 @lisheguo @liuwqgit @lizhengwu @lonexreb @louisfy @lraesly @ly85206559 @mag-linares-andalucia @manumadrigal09 @markthebest12 @martins-oss @marvinthebored @masatohoshino @masterswords1 @matthewmoroz @maxvidkrytaklishnya @mgabor3141 @miguelbranco80 @mikronn2 @moerai @morrow-bluedot @mrnozz @najef1979-code @narbs @newsstand @nianjiuzst @nissl24 @nkdmike @nocodet888-arch @noelillinger @north-echo @novaunboundai @nullarbitrage @obviyus @oliverbot26 @omarshahine @ooiuuii @orangejon @ouioui33 @oywino @pash-openai @patrick-erichsen @pbergeot @pcpilot-dev @peetiegonzalez @pengzh1 @peterhodl @peterkaynie @pfrederiksen @pgondhi987 @pick-cat @piotx @pollybot13 @postoso @qingminglong @razvangirgiz @rboy1 [@rgregg](https://github.co...