154 wires and counting

$ follow OpenClaw

Keep up with OpenClaw in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-10-04
stories 199

© 2026 RepoJournal Home Showcase How it works Privacy

$ the-wire · showcase

OpenClaw's deslop sweep removes 1,000+ production lines

By RepoJournal · Filed · About OpenClaw · Composed from the cited sources · methodology

A coordinated refactor across core, gateway, plugins, and the control UI strips duplicate adapters and plumbing while holding public contracts fixed, and the enterprise and Peekaboo desks spend the day tightening test fixtures and identity checks.

refactor(core): deslop small core subsystems (#164708) openclaw/openclaw

by Peter Steinberger

Credential selection duplication, one-use forwarding layers, and fixed-option plumbing are gone across core subsystems, a net reduction of 1,000 production lines. Configuration, persisted data, protocol shapes, SDK contracts, security checks, and lifecycle fencing are all explicitly preserved, so the change should be invisible to callers.

refactor(plugins): deslop plugins (#164617) openclaw/openclaw

by Peter Steinberger

Private plugin activation, auth-receipt settlement, callback binding, and SDK forwarding are simplified for a net 565 production lines and 62 test lines removed. Windows startup checks, receiver-free recovery callbacks, and protected metadata/scan contracts survive, and the assertion ratchet drops from 3 to 2.

fix(channels): preserve lazy pairing reads for Doctor openclaw/openclaw

by Peter Steinberger

The dynamic import is restored at the default ingress allowlist reader, after a static import pulled memory-wiki's Doctor contract into Kysely through security-runtime and the shared-state reader. Doctor should load without that database graph until an actual store read.

fix(audit): redact and cap route denial explanations openclaw/openclaw-enterprise

by freeqaz

The controller's denial() helper was spreading route explanations on top of the audit event, so decisionReason skipped the factory's redaction and its 120-character cap, and details reached the Postgres sink unredacted. The Agent service principal denial records a 220-character reason today; the route denial explanations are now redacted and capped.

fix(paste): fence exact-window clipboard delivery openclaw/Peekaboo

by steipete

Temporary rich and binary paste is now fenced to an exact background window using the native clipboard generation retained by the write transaction, and the input host checks a content-free claim before every new key-down. A competing copy stops new paste input without suppressing releases owed to the original process generation.

test(auth): pin the shared ID-token verifier once openclaw/openclaw-enterprise

by freeqaz

The generic ID-token cases that google-id-token.test.mjs re-ran against verifyIdToken are now pinned once in oidc-id-token.test.mjs, ending two copies that had drifted and killed different verifier mutants.

Quick answers

What shipped in OpenClaw on October 4, 2026?
A coordinated refactor across core, gateway, plugins, and the control UI strips duplicate adapters and plumbing while holding public contracts fixed, and the enterprise and Peekaboo desks spend the day tightening test fixtures and identity checks. In total, 126 commits, 72 pull requests, and 1 releases landed.
Who contributed to OpenClaw on October 4, 2026?
3 developers shipped this update, including Peter Steinberger, stevenlee-oai, and freeqaz.
What were the notable OpenClaw updates?
refactor(core): deslop small core subsystems (#164708), refactor(plugins): deslop plugins (#164617), and fix(channels): preserve lazy pairing reads for Doctor.