RepoJournal

$ cat openclaw/week/2026-09-28.log

OpenClaw

OpenClaw

the week in review · Sep 28 – Oct 4, 2026

Openclaw 2026.8.35 extended-stable ships critical security fixes

By RepoJournal · composed from the cited sources · human-reviewed weekly · methodology

♥

fs-safe 0.21.1 also lands as a breaking change, and the deslop sweep has cut more than 1,000 production lines.

761 commits 404 PRs merged 13 releases 7 briefings covered

all openclaw reviews →

openclaw 2026.8.35 openclaw/openclaw

by RomneyDa

This is a gateway-only extended-stable release, the project's current equivalent to LTS: OpenClaw from the end of August 2026 plus critical security updates and reliability fixes. If you pin an LTS-style track, this is the version that carries the fixes.

fs-safe 0.21.1 openclaw/fs-safe

by github-actions[bot]

On Linux kernels without openat2, native opens now follow in-root relative symlinks exactly as RESOLVE_BENEATH does, rejecting absolute links, `..` escapes, procfs and nosymfollow links, and chains longer than 40. Denial and symlink policies report the same errors as the openat2 path, so code that previously depended on the looser behavior needs to be rechecked.

openclaw 2026.9.7 openclaw/openclaw

by github-actions[bot]

Updates now back up every state and agent database before migrations and restore them on rollback, and stop before schema changes when snapshot cleanup fails. Snapshots are taken consistently while the Gateway keeps writing, so a failed upgrade no longer means a lost database.

perf(sqlite): checkpoint WAL from maintenance ticks instead of commits (#160818) openclaw/openclaw

by Peter Steinberger

Inline autocheckpoints previously ran on every committing connection, including the Gateway main thread, and readers kept the log from resetting. Checkpointing moves to maintenance ticks, taking that work off the commit path.

fix(acpx): recover adapter launches after plugin capture cleanup (#160156) openclaw/openclaw

by Bruce-Yii

Codex and Claude ACP launches failed with MODULE_NOT_FOUND when cleanup reclaimed the plugin capture referenced by their durable wrappers. Adapter launches now recover after plugin capture cleanup.

fix(viewer): retain live state during atomic replacement openclaw/acpx

by steipete

Polling could overlap an atomic replacement of a live run projection: the filesystem identity check reported path-mismatch, and optional-read fallbacks treated that transient error as missing data, publishing the older saved projection instead.

refactor(channels): deslop Telegram, Matrix and Feishu fourth pass (#160032) openclaw/openclaw

by Peter Steinberger

The fourth pass over Telegram, Matrix and Feishu shares canonical types and parameter/result owners, removes unused forwarding layers and callback projections, and drops 629 net production lines. Channel wire formats and policy contracts are unchanged.

refactor(codex): deslop Codex plugin sixth pass (#160912) openclaw/openclaw

by Peter Steinberger

The sixth pass over the Codex plugin consolidates shell projections, native binding and recovery plumbing, policy fingerprints, catalog adapters, and command/auth forwarding. Wire and transcript contracts hold.

$ ls openclaw/week/ # the briefings behind this review

Keep up with OpenClaw in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

all openclaw reviews →