$ ls openclaw/reviews/ # the step-back reads
OpenClaw in review
One review per week (and month): what shipped, what broke, what to act on.
Sep 14–20, 2026 weekly [act] 8 stories
fs-safe 0.14.0 sets new guest listing rules
The period's security work ran alongside startup-cost and session-write performance fixes across openclaw and clowfish.
Sep 7–13, 2026 weekly [act] 8 stories
Three auth bypass bugs fixed, 2026.9.4 ships rollback recovery
Slack file downloads, OpenAI-compatible transport, and outbound attachments all leaked credentials or data before this week's patches.
Aug 31–Sep 6, 2026 weekly [act] 8 stories
OpenClaw 2026.8.1 breaks cross-agent session defaults
Cross-agent session access is now the default, while shared ownership fixes land across Crabbox and OCM.
Aug 1–31, 2026 monthly [act] 8 stories
2026.8.1-beta.2 binds secrets to exact HTTPS hosts
Crabbox reaches v0.44.0 with credential-free provider discovery, while the beta release hardens secret egress.
Keep up with OpenClaw in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.
fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.
Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.