fix(deps): remediate Dependabot alerts#93857
Merged
Merged
Conversation
Contributor
Dependency GuardThis PR changes dependency-related files. Maintainers should confirm these changes are intentional. Changed files:
Maintainer follow-up:
|
Contributor
Dependency graph changes notedThis PR includes dependency graph changes. The dependency guard is informational because the PR author is a repository admin or a member of
Security review is still recommended before merge when the dependency graph change is intentional. |
vincentkoc
force-pushed
the
fix/security-deps-openclaw
branch
3 times, most recently
from
June 17, 2026 03:13
62aa4f5 to
ea68e0a
Compare
vincentkoc
force-pushed
the
fix/security-deps-openclaw
branch
from
June 17, 2026 03:15
1e45cd9 to
51ece24
Compare
Member
Author
|
Merged via squash.
Thanks @vincentkoc! |
karmafeast
added a commit
to karmaterminal/openclaw
that referenced
this pull request
Jun 17, 2026
…5651) (#1038) * refactor(agents): hide update plan gating helper * fix(e2e): keep live plugin pack paths local * refactor(agents): drop mcp fetch type re-export * refactor(agents): hide mcp oauth redirect classifier * refactor(agents): remove catalog browse timer test hooks * refactor(agents): hide execution contract resolver * fix(e2e): reject unsafe Docker pack names * clawdbot-d02.1.9.1.31: add sessions.create lifecycle seam (openclaw#93691) * refactor(agents): hide assistant stream delivery types * refactor(agents): hide message handler helpers * fix: clean agent lint failures * refactor(agents): hide compaction reconcile wrapper * refactor(agents): hide context cache reset helper * refactor(agents): hide copilot routing constants * refactor(agents): hide subagent outcome helpers * refactor(agents): hide tool mutation helpers * refactor(agents): hide transport error extractor * refactor(agents): remove video task status wrappers * refactor(agents): hide custom api source id helper * refactor(agents): hide docs path helpers * fix(codex): sync app-server dynamic tool protocol * refactor(agents): hide timeout seconds helper * fix(gemini): bridge OAuth profiles into CLI runtime * fix: persist Gemini CLI auth homes * fix: preserve Gemini CLI project binding * fix: scope CLI auth epochs to agent stores * fix: fail closed on unstaged Gemini profiles * fix: preserve runtime auth alias scope * fix: keep CLI auth fallback scoped * fix: accept Google API keys for Gemini CLI * fix: honor Google auth order for Gemini CLI * test: type Gemini CLI auth refresh mock * fix: forward pinned Gemini CLI auth for validation * fix: bind Gemini CLI epochs to profile homes * fix: keep CLI prepare credentials private * fix: ignore stale auto auth for Gemini CLI * fix: stage resolved Gemini OAuth profiles * fix: clear ambient Google ADC for Gemini CLI * fix: stage adopted Gemini OAuth credentials * fix: isolate Gemini CLI system auth settings * fix: enforce Gemini CLI profile auth precedence * fix: keep Gemini CLI system settings per run * fix: clean Gemini bundle settings on prepare failure * fix: preserve ambient Gemini system auth * fix: honor inherited Gemini auth policy * test: fix Gemini CLI auth test types * test: narrow Gemini CLI setup agent dir * fix: pass prepared CLI env to spawned process * fix: expose CLI runtime env diagnostics * fix: load staged Gemini CLI auth profiles * fix: log Gemini CLI runtime env activation * fix: select CLI auth profile for runtime prep * fix: keep CLI env diagnostics opt-in * fix: align Gemini CLI home path * fix: add CLI empty response diagnostics * fix: parse Gemini CLI stream output * fix: allow Gemini CLI file edits * docs: update Gemini CLI backend defaults * fix: use OpenClaw temp root for Gemini CLI settings * fix: clean up Gemini CLI backend checks * fix: keep Gemini CLI auth out of warmup * refactor(agents): hide cleanup timeout helpers * refactor(agents): hide stale run cutoff * refactor(agents): hide compaction timeout internals * refactor(agents): remove stale compaction grace helper * refactor(agents): hide idle timeout default * refactor(plugins): hide cleanup timeout internals * refactor(qqbot): hide response timeout default * refactor(feishu): hide timeout config type * refactor(browser): hide cdp reachability defaults * docs: add Gemini CLI auth changelog entry * refactor(agents): hide context window thresholds * refactor(agents): hide fallback skip cache internals * fix(agents): tolerate uncloneable adjusted tool params * refactor(cli): hide compile cache and media internals * fix(slack): preserve completed native progress titles * refactor(acp): hide test helper internals * refactor(tests): hide helper-only types * refactor(tests): hide gateway state helper types * fix(deps): remediate Dependabot alerts (openclaw#93857) Merged via squash. Prepared head SHA: 51ece24 Co-authored-by: vincentkoc <[email protected]> Co-authored-by: vincentkoc <[email protected]> Reviewed-by: @vincentkoc * refactor(commands): hide doctor harness mocks * refactor(commands): hide doctor e2e mock internals * refactor(commands): hide doctor service install mock * refactor(commands): hide gateway readiness types * refactor(commands): hide health summary internals * refactor(commands): trim health type reexports * refactor(commands): trim migrate option reexports * refactor(commands): trim backup type exports * test(codex): refresh dynamic tool snapshots * refactor(commands): hide onboarding install result * fix(ui): harden chromium test runner * refactor(commands): hide status task helper types * refactor(commands): trim setup type reexports * fix(slack): recognize MiniMax mm: namespaced reasoning tags in monitor preview (openclaw#93874) * refactor(commands): hide doctor repair helper types * feat(providers): add ClawRouter managed proxy * docs(providers): document ClawRouter integration * chore(providers): align ClawRouter package version * fix(providers): preserve ClawRouter native replay policies * chore(deps): register ClawRouter workspace * fix(providers): consume canonical ClawRouter catalog field * fix(providers): restore ClawRouter native runtime routes * fix(providers): isolate ClawRouter runtime credentials * fix(providers): cover ClawRouter runtime auth paths * fix(providers): preserve ClawRouter catalog model ids * fix(providers): require runnable ClawRouter Gemini routes * fix(providers): route ClawRouter direct streams * fix(providers): apply wrappers to direct streams * fix(providers): wrap direct fallback streams * fix(providers): compose ClawRouter native auth * fix(providers): align ClawRouter package boundary * fix(sdk): refresh plugin api baseline * refactor(commands): hide doctor utility types * refactor(commands): hide doctor state helper types * refactor(commands): trim doctor probe type exports * refactor(commands): trim setup barrel type exports * fix(macos): preserve approvals migration data (openclaw#93880) Merged via squash. Prepared head SHA: a8a0dd0 Co-authored-by: vincentkoc <[email protected]> Co-authored-by: vincentkoc <[email protected]> Reviewed-by: @vincentkoc * refactor(flows): hide setup helper types * refactor(commands): trim custom provider type reexports * fix(cron): reject invalid absolute timestamps (openclaw#93903) * fix(cron): reject invalid absolute timestamps * fix(cron): preserve ISO end of day --------- Co-authored-by: Vincent Koc <[email protected]> * refactor(commands): hide custom provider helper types * fix(update): use configured npm registry for update metadata (openclaw#93879) Merged via squash. Prepared head SHA: ae8bbb0 Co-authored-by: vincentkoc <[email protected]> Co-authored-by: vincentkoc <[email protected]> Reviewed-by: @vincentkoc * refactor(commands): trim status type exports * refactor(commands): hide doctor helper types * refactor(commands): hide migrate helper types * refactor(config): hide local helper types * revert(providers): remove ClawRouter provider * refactor(config): hide session helper types * refactor(gateway): hide local helper types * refactor(gateway): hide websocket helper types * refactor(infra): hide local helper types --------- Co-authored-by: Vincent Koc <[email protected]> Co-authored-by: Josh Lehman <[email protected]> Co-authored-by: Shakker <[email protected]> Co-authored-by: Jason O'Neal <[email protected]> Co-authored-by: Vincent Koc <[email protected]> Co-authored-by: Alix-007 <[email protected]> Co-authored-by: ronan-dandelion-cult <[email protected]> Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]>
github-actions Bot
pushed a commit
to Desicool/openclaw
that referenced
this pull request
Jun 17, 2026
Merged via squash. Prepared head SHA: 51ece24 Co-authored-by: vincentkoc <[email protected]> Co-authored-by: vincentkoc <[email protected]> Reviewed-by: @vincentkoc
crh-code
pushed a commit
to crh-code/openclaw
that referenced
this pull request
Jun 18, 2026
Merged via squash. Prepared head SHA: 51ece24 Co-authored-by: vincentkoc <[email protected]> Co-authored-by: vincentkoc <[email protected]> Reviewed-by: @vincentkoc
This was referenced Jun 20, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Verification