Skip to content

fix(deps): remediate Dependabot alerts#93857

Merged
vincentkoc merged 3 commits into
mainfrom
fix/security-deps-openclaw
Jun 17, 2026
Merged

fix(deps): remediate Dependabot alerts#93857
vincentkoc merged 3 commits into
mainfrom
fix/security-deps-openclaw

Conversation

@vincentkoc

@vincentkoc vincentkoc commented Jun 17, 2026

Copy link
Copy Markdown
Member

Summary

  • Updates the tar, protobufjs, DOMPurify, and OpenTelemetry dependency families that back the active OpenClaw Dependabot alerts.
  • Regenerates the root and affected bundled-plugin npm shrinkwraps from the canonical pnpm lockfile.

Verification

  • autoreview --mode branch --base origin/main: clean.
  • Blacksmith Testbox tbx_01kv9r9am5wparpj1j905zwe3v: full changed gate passed, including lockfile policy, dependency pins, all 36 npm shrinkwrap checks, typecheck, lint, and runtime import cycles.
  • Repository CI is running against the exact PR head.

@vincentkoc
vincentkoc requested a review from a team as a code owner June 17, 2026 02:09
@openclaw-barnacle openclaw-barnacle Bot added channel: whatsapp-web Channel integration: whatsapp-web app: web-ui App: web-ui extensions: diagnostics-otel Extension: diagnostics-otel channel: feishu Channel integration: feishu extensions: llama-cpp size: XS maintainer Maintainer-authored PR labels Jun 17, 2026
@github-actions github-actions Bot added the dependencies-changed PR changes dependency-related files label Jun 17, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Dependency Guard

This PR changes dependency-related files. Maintainers should confirm these changes are intentional.

Changed files:

  • extensions/diagnostics-otel/npm-shrinkwrap.json
  • extensions/diagnostics-otel/package.json
  • extensions/feishu/npm-shrinkwrap.json
  • extensions/llama-cpp/npm-shrinkwrap.json
  • extensions/whatsapp/npm-shrinkwrap.json
  • npm-shrinkwrap.json
  • package.json
  • pnpm-lock.yaml
  • pnpm-workspace.yaml
  • ui/package.json

Maintainer follow-up:

  • Review whether the dependency changes are intentional.
  • Inspect resolved package deltas when lockfile, shrinkwrap, or workspace dependency policy changes are present.
  • Treat package-lock.json and npm-shrinkwrap.json diffs as security-review surfaces.
  • Run pnpm deps:changes:report -- --base-ref origin/main --markdown /tmp/dependency-changes.md --json /tmp/dependency-changes.json locally for detailed release-style evidence.

@github-actions

github-actions Bot commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

Dependency graph changes noted

This PR includes dependency graph changes. The dependency guard is informational because the PR author is a repository admin or a member of @openclaw/openclaw-secops.

  • Current SHA: 51ece24eef2cb0af3966c3a436d1c2cc42cc8067
  • Trusted actor: @vincentkoc
  • Trusted role: pull request author; openclaw-secops

Security review is still recommended before merge when the dependency graph change is intentional.

@vincentkoc
vincentkoc force-pushed the fix/security-deps-openclaw branch 3 times, most recently from 62aa4f5 to ea68e0a Compare June 17, 2026 03:13
@openclaw-barnacle openclaw-barnacle Bot added the gateway Gateway runtime label Jun 17, 2026
@vincentkoc
vincentkoc force-pushed the fix/security-deps-openclaw branch from 1e45cd9 to 51ece24 Compare June 17, 2026 03:15
@openclaw-barnacle openclaw-barnacle Bot removed the gateway Gateway runtime label Jun 17, 2026
@vincentkoc
vincentkoc merged commit d79d548 into main Jun 17, 2026
15 of 17 checks passed
@vincentkoc
vincentkoc deleted the fix/security-deps-openclaw branch June 17, 2026 03:15
@vincentkoc

Copy link
Copy Markdown
Member Author

Merged via squash.

Thanks @vincentkoc!

karmafeast added a commit to karmaterminal/openclaw that referenced this pull request Jun 17, 2026
…5651) (#1038)

* refactor(agents): hide update plan gating helper

* fix(e2e): keep live plugin pack paths local

* refactor(agents): drop mcp fetch type re-export

* refactor(agents): hide mcp oauth redirect classifier

* refactor(agents): remove catalog browse timer test hooks

* refactor(agents): hide execution contract resolver

* fix(e2e): reject unsafe Docker pack names

* clawdbot-d02.1.9.1.31: add sessions.create lifecycle seam (openclaw#93691)

* refactor(agents): hide assistant stream delivery types

* refactor(agents): hide message handler helpers

* fix: clean agent lint failures

* refactor(agents): hide compaction reconcile wrapper

* refactor(agents): hide context cache reset helper

* refactor(agents): hide copilot routing constants

* refactor(agents): hide subagent outcome helpers

* refactor(agents): hide tool mutation helpers

* refactor(agents): hide transport error extractor

* refactor(agents): remove video task status wrappers

* refactor(agents): hide custom api source id helper

* refactor(agents): hide docs path helpers

* fix(codex): sync app-server dynamic tool protocol

* refactor(agents): hide timeout seconds helper

* fix(gemini): bridge OAuth profiles into CLI runtime

* fix: persist Gemini CLI auth homes

* fix: preserve Gemini CLI project binding

* fix: scope CLI auth epochs to agent stores

* fix: fail closed on unstaged Gemini profiles

* fix: preserve runtime auth alias scope

* fix: keep CLI auth fallback scoped

* fix: accept Google API keys for Gemini CLI

* fix: honor Google auth order for Gemini CLI

* test: type Gemini CLI auth refresh mock

* fix: forward pinned Gemini CLI auth for validation

* fix: bind Gemini CLI epochs to profile homes

* fix: keep CLI prepare credentials private

* fix: ignore stale auto auth for Gemini CLI

* fix: stage resolved Gemini OAuth profiles

* fix: clear ambient Google ADC for Gemini CLI

* fix: stage adopted Gemini OAuth credentials

* fix: isolate Gemini CLI system auth settings

* fix: enforce Gemini CLI profile auth precedence

* fix: keep Gemini CLI system settings per run

* fix: clean Gemini bundle settings on prepare failure

* fix: preserve ambient Gemini system auth

* fix: honor inherited Gemini auth policy

* test: fix Gemini CLI auth test types

* test: narrow Gemini CLI setup agent dir

* fix: pass prepared CLI env to spawned process

* fix: expose CLI runtime env diagnostics

* fix: load staged Gemini CLI auth profiles

* fix: log Gemini CLI runtime env activation

* fix: select CLI auth profile for runtime prep

* fix: keep CLI env diagnostics opt-in

* fix: align Gemini CLI home path

* fix: add CLI empty response diagnostics

* fix: parse Gemini CLI stream output

* fix: allow Gemini CLI file edits

* docs: update Gemini CLI backend defaults

* fix: use OpenClaw temp root for Gemini CLI settings

* fix: clean up Gemini CLI backend checks

* fix: keep Gemini CLI auth out of warmup

* refactor(agents): hide cleanup timeout helpers

* refactor(agents): hide stale run cutoff

* refactor(agents): hide compaction timeout internals

* refactor(agents): remove stale compaction grace helper

* refactor(agents): hide idle timeout default

* refactor(plugins): hide cleanup timeout internals

* refactor(qqbot): hide response timeout default

* refactor(feishu): hide timeout config type

* refactor(browser): hide cdp reachability defaults

* docs: add Gemini CLI auth changelog entry

* refactor(agents): hide context window thresholds

* refactor(agents): hide fallback skip cache internals

* fix(agents): tolerate uncloneable adjusted tool params

* refactor(cli): hide compile cache and media internals

* fix(slack): preserve completed native progress titles

* refactor(acp): hide test helper internals

* refactor(tests): hide helper-only types

* refactor(tests): hide gateway state helper types

* fix(deps): remediate Dependabot alerts (openclaw#93857)

Merged via squash.

Prepared head SHA: 51ece24
Co-authored-by: vincentkoc <[email protected]>
Co-authored-by: vincentkoc <[email protected]>
Reviewed-by: @vincentkoc

* refactor(commands): hide doctor harness mocks

* refactor(commands): hide doctor e2e mock internals

* refactor(commands): hide doctor service install mock

* refactor(commands): hide gateway readiness types

* refactor(commands): hide health summary internals

* refactor(commands): trim health type reexports

* refactor(commands): trim migrate option reexports

* refactor(commands): trim backup type exports

* test(codex): refresh dynamic tool snapshots

* refactor(commands): hide onboarding install result

* fix(ui): harden chromium test runner

* refactor(commands): hide status task helper types

* refactor(commands): trim setup type reexports

* fix(slack): recognize MiniMax mm: namespaced reasoning tags in monitor preview (openclaw#93874)

* refactor(commands): hide doctor repair helper types

* feat(providers): add ClawRouter managed proxy

* docs(providers): document ClawRouter integration

* chore(providers): align ClawRouter package version

* fix(providers): preserve ClawRouter native replay policies

* chore(deps): register ClawRouter workspace

* fix(providers): consume canonical ClawRouter catalog field

* fix(providers): restore ClawRouter native runtime routes

* fix(providers): isolate ClawRouter runtime credentials

* fix(providers): cover ClawRouter runtime auth paths

* fix(providers): preserve ClawRouter catalog model ids

* fix(providers): require runnable ClawRouter Gemini routes

* fix(providers): route ClawRouter direct streams

* fix(providers): apply wrappers to direct streams

* fix(providers): wrap direct fallback streams

* fix(providers): compose ClawRouter native auth

* fix(providers): align ClawRouter package boundary

* fix(sdk): refresh plugin api baseline

* refactor(commands): hide doctor utility types

* refactor(commands): hide doctor state helper types

* refactor(commands): trim doctor probe type exports

* refactor(commands): trim setup barrel type exports

* fix(macos): preserve approvals migration data (openclaw#93880)

Merged via squash.

Prepared head SHA: a8a0dd0
Co-authored-by: vincentkoc <[email protected]>
Co-authored-by: vincentkoc <[email protected]>
Reviewed-by: @vincentkoc

* refactor(flows): hide setup helper types

* refactor(commands): trim custom provider type reexports

* fix(cron): reject invalid absolute timestamps (openclaw#93903)

* fix(cron): reject invalid absolute timestamps

* fix(cron): preserve ISO end of day

---------

Co-authored-by: Vincent Koc <[email protected]>

* refactor(commands): hide custom provider helper types

* fix(update): use configured npm registry for update metadata (openclaw#93879)

Merged via squash.

Prepared head SHA: ae8bbb0
Co-authored-by: vincentkoc <[email protected]>
Co-authored-by: vincentkoc <[email protected]>
Reviewed-by: @vincentkoc

* refactor(commands): trim status type exports

* refactor(commands): hide doctor helper types

* refactor(commands): hide migrate helper types

* refactor(config): hide local helper types

* revert(providers): remove ClawRouter provider

* refactor(config): hide session helper types

* refactor(gateway): hide local helper types

* refactor(gateway): hide websocket helper types

* refactor(infra): hide local helper types

---------

Co-authored-by: Vincent Koc <[email protected]>
Co-authored-by: Josh Lehman <[email protected]>
Co-authored-by: Shakker <[email protected]>
Co-authored-by: Jason O'Neal <[email protected]>
Co-authored-by: Vincent Koc <[email protected]>
Co-authored-by: Alix-007 <[email protected]>
Co-authored-by: ronan-dandelion-cult <[email protected]>
Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]>
github-actions Bot pushed a commit to Desicool/openclaw that referenced this pull request Jun 17, 2026
Merged via squash.

Prepared head SHA: 51ece24
Co-authored-by: vincentkoc <[email protected]>
Co-authored-by: vincentkoc <[email protected]>
Reviewed-by: @vincentkoc
crh-code pushed a commit to crh-code/openclaw that referenced this pull request Jun 18, 2026
Merged via squash.

Prepared head SHA: 51ece24
Co-authored-by: vincentkoc <[email protected]>
Co-authored-by: vincentkoc <[email protected]>
Reviewed-by: @vincentkoc
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

app: web-ui App: web-ui channel: feishu Channel integration: feishu channel: whatsapp-web Channel integration: whatsapp-web dependencies-changed PR changes dependency-related files extensions: diagnostics-otel Extension: diagnostics-otel extensions: llama-cpp maintainer Maintainer-authored PR size: XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant