Vignesh
1295b67057
fix(lobster): block arbitrary exec via lobsterPath/cwd (GHSA-4mhr-g7xj-cg8j) ( #5335 )
...
* fix(lobster): prevent arbitrary exec via lobsterPath/cwd
* fix(lobster): harden lobsterPath errors + normalize cwd sandboxing
* fix(lobster): ignore tool-provided lobsterPath; validate + use plugin config
* fix(lobster): use plugin config lobsterPath + add tests (#5335 ) (thanks @vignesh07)
* fix(lobster): make Windows spawn fallback handle ENOENT (#5335 ) (thanks @vignesh07)
---------
Co-authored-by: Tyler Yust <TYTYYUST@YAHOO.COM>
2026-01-31 12:46:20 -08:00
Ayaan Zaidi
f1de88c198
fix: restore telegram draft streaming partials ( #5543 ) (thanks @obviyus)
2026-01-31 22:46:19 +05:30
Tak Hoffman
9c29853014
Gateway: inject timestamps into agent/chat.send ( #3705 ) (thanks @conroywhitney, @CashWilliams)
2026-01-31 09:47:27 -06:00
Peter Steinberger
83e64c1ac9
docs: start 2026.1.31 changelog
2026-01-31 16:28:19 +01:00
Peter Steinberger
7d89855c55
fix: align npm publish metadata
2026-01-31 14:21:21 +01:00
cpojer
8cab78abbc
chore: Run pnpm format:fix.
2026-01-31 21:13:13 +09:00
Peter Steinberger
1287328b6f
feat: add MiniMax OAuth plugin ( #4521 ) (thanks @Maosghoul)
2026-01-31 12:42:45 +01:00
Peter Steinberger
b9b94715fa
fix: avoid stderr backpressure in macOS discovery ( #3304 ) (thanks @abhijeet117)
2026-01-31 12:03:30 +01:00
Peter Steinberger
247fab47ca
chore: bump version to 2026.1.30
2026-01-31 11:37:36 +01:00
Ayaan Zaidi
310eed825e
fix: preserve delivery thread fallback ( #4911 ) (thanks @yevhen)
2026-01-31 09:31:40 +05:30
Ayaan Zaidi
e849df64dc
fix: normalize telegram account token lookup ( #5055 ) (thanks @jasonsschin)
2026-01-31 08:58:04 +05:30
Tyler Yust
0b7aa8cf1d
feat(ui): refresh session list after chat commands in Web UI
2026-01-30 14:29:04 -08:00
Gustavo Madeira Santana
34bdbdb405
fix: resolve Control UI assets for global installs ( #4909 ) (thanks @YuriNachos)
...
Co-authored-by: YuriNachos <YuriNachos@users.noreply.github.com>
2026-01-30 17:08:40 -05:00
Gustavo Madeira Santana
39eb0b7bc0
fix: prevent undefined gateway token defaults ( #4873 ) (thanks @Hisleren)
...
Co-authored-by: Hisleren <Hisleren@users.noreply.github.com>
2026-01-30 16:16:35 -05:00
Gustavo Madeira Santana
daf27dd37e
fix: add per-agent models status ( #4780 ) (thanks @jlowin)
2026-01-30 15:47:05 -05:00
Peter Steinberger
fd00d5688a
chore: update openclaw naming
2026-01-30 21:03:11 +01:00
Ayaan Zaidi
da71eaebd2
fix: correct telegram html nesting ( #4578 ) (thanks @ThanhNguyxn)
2026-01-30 16:53:39 +05:30
Ayaan Zaidi
fa9ec6e854
fix: add docker ui install changelog entry ( #4584 ) (thanks @obviyus)
2026-01-30 16:25:24 +05:30
Ayaan Zaidi
bc432d8435
fix: accept numeric Telegram react ids ( #4533 ) (thanks @Ayush10)
2026-01-30 15:01:18 +05:30
Ayaan Zaidi
3a85cb1833
fix: honor Telegram proxy dispatcher ( #4456 ) (thanks @spiceoogway)
2026-01-30 14:38:39 +05:30
Ayaan Zaidi
9025da2296
fix: scope telegram skill commands per bot ( #4360 ) (thanks @robhparker)
2026-01-30 12:00:29 +05:30
Manik Vahsith
5e635c9656
feat: add Kimi K2.5 model to synthetic catalog ( #4407 )
...
* feat: add Kimi K2.5 model to synthetic catalog
Add hf:moonshotai/Kimi-K2.5 to the synthetic model catalog.
This model is available via dev.synthetic.new API.
- 256k context window
- 8192 max tokens
- Supports reasoning
* chore: fix formatting in onboard-helpers.ts
* fix: update config candidate ordering test (#4407 ) (thanks @manikv12)
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-01-30 07:17:42 +01:00
Peter Steinberger
23c424899c
docs: reorder 2026.1.29 changelog
2026-01-30 06:25:21 +01:00
Peter Steinberger
9a7160786a
refactor: rename to openclaw
2026-01-30 03:16:21 +01:00
Shakker
4583f88626
fix: preserve reasoning tags inside code blocks ( #4118 ) (thanks @vinaygit18)
2026-01-29 18:53:05 +00:00
Peter Steinberger
78b9876641
feat: add Xiaomi MiMo provider onboarding ( #3454 )
...
Thanks @WqyJh.
Co-authored-by: Qiying Wang <15232241+WqyJh@users.noreply.github.com>
2026-01-29 17:29:58 +00:00
Peter Steinberger
5152060121
docs(changelog): rewrite 2026.1.29 notes
2026-01-29 16:48:05 +00:00
Peter Steinberger
06289b36da
fix(security): harden SSH target handling ( #4001 )
...
Thanks @YLChen-007.
Co-authored-by: Edward-x <YLChen-007@users.noreply.github.com>
2026-01-29 16:33:36 +00:00
Ayaan Zaidi
718bc3f9c8
fix: avoid silent telegram empty replies ( #3796 ) ( #3796 )
2026-01-29 11:34:47 +05:30
Ayaan Zaidi
16a5549ec0
docs: update changelog for mention patterns ( #3303 ) (thanks @HirokiKobayashi-R)
2026-01-29 10:31:47 +05:30
Ayaan Zaidi
fcc53bcf1b
fix: include AccountId in telegram native command context ( #2942 ) (thanks @Chloe-VP)
2026-01-29 10:17:25 +05:30
Ayaan Zaidi
4ac7aa4a48
fix: handle telegram video notes ( #2905 ) (thanks @mylukin)
2026-01-29 10:07:21 +05:30
Gustavo Madeira Santana
a44da67069
fix: local updates for PR #3600
...
Co-authored-by: kira-ariaki <kira-ariaki@users.noreply.github.com>
2026-01-28 22:00:11 -05:00
Shakker
b717724275
fix: add security hardening for media text attachments ( #3700 )
...
* fix: Prevent XML attribute injection by escaping special characters in file name and MIME type attributes.
* fix: text attachment MIME misclassification with security hardening (#3628 )
- Fix CSV/TSV inference from content heuristics
- Add UTF-16 detection and BOM handling
- Add XML attribute escaping for file output (security)
- Add MIME override logging for auditability
- Add comprehensive test coverage for edge cases
Thanks @frankekn
2026-01-29 02:39:01 +00:00
Shakker
67f1402703
fix: tts base url runtime read ( #3341 ) (thanks @hclsys)
2026-01-28 23:30:29 +00:00
Shadow
6044bf3637
Discord: fix resolveDiscordTarget parse options
2026-01-28 00:37:21 -06:00
Ayaan Zaidi
b6a3a91edf
fix: wire per-account dm scope guidance ( #3095 ) (thanks @jarvis-sam)
2026-01-28 11:42:33 +05:30
Ayaan Zaidi
93c2d65398
fix: restore discord username lookup and align minimax test ( #3131 ) (thanks @bonald)
2026-01-28 11:04:07 +05:30
Shadow
61ab348dd3
Discord: fix target type imports
2026-01-27 22:56:12 -06:00
Shadow
b01612c262
Discord: gate username lookups
2026-01-27 22:48:18 -06:00
Ayaan Zaidi
14e4b88bf0
fix: keep telegram dm thread sessions ( #2731 ) (thanks @dylanneve1)
2026-01-28 09:32:20 +05:30
Shadow
d0ef4d3b85
fix: update Moonshot Kimi model references ( #2762 ) (thanks @MarvinCui)
2026-01-27 21:10:59 -06:00
Shadow
7bfe6ab2d6
fix: resolve Discord usernames for outbound sends ( #2649 ) (thanks @nonggialiang)
2026-01-27 21:05:37 -06:00
Shadow
57d9c09f6e
fix: expand Telegram polling network recovery ( #3013 ) (thanks @ryancontent)
2026-01-27 19:56:24 -06:00
Shadow
eb50314d7d
fix: update MiniMax provider config ( #3064 ) (thanks @hlbbbbbbb)
2026-01-27 19:48:38 -06:00
Shadow
34653e4baf
fix: guard channel tool listActions ( #2859 ) (thanks @mbelinky)
2026-01-27 19:25:50 -06:00
Shadow
4647309c4c
fix: update exe.dev install docs (# https://github.com/moltbot/moltbot/pull/3047 ) (thanks @zackerthescar)
2026-01-27 18:54:46 -06:00
Peter Steinberger
7eb57b691c
chore: prep 2026.1.27-beta.1 release
2026-01-28 01:35:58 +01:00
Peter Steinberger
e2c437e81e
fix: migrate legacy state/config paths
2026-01-28 00:16:00 +00:00
elliotsecops
3b879fe524
fix(infra): prevent gateway crashes on transient network errors
2026-01-27 18:11:04 -06:00