Skip to content

Bump openclaw/clawhub/.github/workflows/skill-publish.yml from 0.23.3 to 0.24.0 - #38

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/openclaw/clawhub/dot-github/workflows/skill-publish.yml-0.24.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/openclaw/clawhub/dot-github/workflows/skill-publish.yml-0.24.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Bumps openclaw/clawhub/.github/workflows/skill-publish.yml from 0.23.3 to 0.24.0.

Changelog

Sourced from openclaw/clawhub/.github/workflows/skill-publish.yml's changelog.

0.24.0 - 2026-09-30

Changes

  • CLI/API: publish experimental Claw packages from already-built npm tarballs, bind staged uploads to their SHA-256 digest, and preserve the exact artifact bytes through scanning and download.
  • API: expose public exact-version package publication state to distinguish staged, failed, absent, and published releases with advisory recovery eligibility.
  • CI: record dependency advisories from bun audit as warning annotations instead of failing static and blocking Deploy Test; known-malware findings still fail.
  • Workers: default Skill Cards to GPT-6 Sol with medium reasoning and fast service, and prepare semantic input reuse with stale-result fencing for separate activation after backend deployment.
  • Workers: preserve optional scanner model and reasoning settings in restricted subprocess environments without changing workflow defaults.
  • Web: organization publishers can upload durable PNG, JPEG, or WebP logos from settings instead of relying on hotlinked image URLs.
  • Web/API: make default skill and plugin discovery freshness-aware, add seven-day trending views for both catalogs, and use verified status plus usage as search tie-breakers within direct matches.

Fixes

  • Publishing: load only the text decoder, not the whole clawhub-schema barrel, in the static publish scan Node action, cutting ~140 MB from its peak so large bundled plugins such as WhatsApp no longer run it out of memory.

  • Publishing: settle retries of an exact staged package artifact before scans and Plugin Inspector run again, returning the pending or published result, and name a failed attempt with its recovery command instead of a bare "already exists".

  • CLI: read Retry-After and rate-limit headers from curl responses under Bun, so publishes back off for the time the server asks instead of retrying blind.

  • CLI: keep completed skill installs and updates when deleting an old backup fails, without rolling back the new files (thanks @​SebTardif).

  • Publishing: prepare the Plugin Inspector OpenClaw target by streaming and verifying only its public declaration surface, so plugin publishes no longer run the Node action out of memory or fill /tmp with the full OpenClaw package.

  • Deploy: coalesce pending skills.sh syncs per ref before they enter the production deployment queue, while preserving active sync cleanup and queued manual deploys.

  • Dependencies: align brace-expansion and fast-uri overrides with their patched lockfile versions so dependency resolution cannot restore the vulnerable pins.

  • Workers: reserve Skill Card capacity by lease slot to avoid global queue contention, continue after partial batches, and release undelivered leases when input hydration fails.

  • Workers: redact quoted credentials completely in serialized JSON diagnostics while preserving adjacent non-secret context.

  • Deploy: queue production deployments and hourly skills.sh synchronization together so rollout pauses cannot interrupt synchronization or rollback; retain bounded, redacted failure receipts when synchronization fails.

  • Tests: shorten local Convex scratch paths when a deeply nested TMPDIR shares the workspace filesystem, while retaining short overrides and avoiding Unix socket path failures.

  • API/CLI: preserve owner-qualified skill identities in catalog listings and accept explicit null public versions consistently across API and CLI schemas (thanks @​HwangBae for the report and @​goutamadwant for the fix).

  • Workers: delete a newly generated Skill Card blob when attachment fails, while preserving successfully attached cards and historical bundle fingerprints (thanks @​SebTardif).

  • Publishing: fall back to local changelog notes when the provider stalls for ten seconds, including while reading the response body (thanks @​SebTardif).

  • Web: bound Agent Skills discovery proxy requests to ten seconds, including stalled response bodies, so installers can recover from an unresponsive upstream (thanks @​SebTardif).

  • CLI: preserve literal multipart text when publishing with Bun, including semicolons in JSON metadata and values beginning with @ or <, without changing uploaded file bytes.

  • Workers: scan plugin packages containing both skill and plugin manifests without ambiguous-target failures, preserving full-package scanning and bundled-skill paths.

  • CLI/API: recover failed staged plugin publications from their retained artifacts with clawhub package recover, fresh security checks, current publisher authorization, and preserved attempt history.

  • Tests: keep the Vitest localStorage shim working on Node 26, whose native Storage global has a non-configurable length, so bun run ci:unit passes on Node 24 and 26.

  • API/GitHub Actions: authorize human release recovery through v2 approval and the original child-bound parent receipt, fail automated attempts when their exact parent fails, and let admins preview or discard orphaned package publish attempts with a publisher-visible reason.

  • CI: warm and cache the npm packages for local Convex "use node" dependencies and raise the isolated backend's push transport timeout so local-auth browser lanes no longer race a 408-retried external-deps build into a deleted build directory.

  • CI: make the UI proof process-tree reaping test exercise KILL escalation deterministically and assert the reaper's signal sequence, so a TERM that lands before the grandchild ignores it can no longer mask a missing KILL.

  • CI: run the pinned Agent Skills CLI from the Bun lockfile without runtime npm access, retain subprocess failure output, and run first-party CLI coverage before third-party compatibility checks.

  • Docs: repair plugin validation remediation links to the published manifest metadata and runtime session helper sections while preserving valid CLI workflow anchors.

  • Dependencies: pin fast-uri to 3.1.6 to fix host confusion and server-side request forgery advisories in URI normalization.

  • GitHub Actions: accept complete release inventories in parent authorization receipts up to the backend's 64 KiB limit while retaining 8 KiB identity and recovery limits.

  • API: preserve inspector findings when workspace cleanup fails, report the failing stage, and keep cleanup failures publication-blocking.

  • API: bound runtime-identity checks to the owning publisher, reject collisions during personal-principal recovery, and prevent malicious-release quarantine from restoring a historical runtime identity that was administratively replaced.

  • Browser tests: use a supported manifest warning fixture and prepare local Convex fully with short scratch paths on the backend's volume before starting authenticated flows.

  • API: scope code-plugin runtime identity claims to the owning publisher so community and official packages can retain their manifest ids under distinct scoped names, while rejecting same-owner collisions during publication, transfer, restore, and administrative repair.

  • UI proof: supervise isolated loopback backend and browser proof together without writing project dotenv, preserving diagnostics and private-state cleanup on failure.

  • CI: authenticate weekly design-audit pull request mutations with the Barnacle GitHub App while retaining the workflow token for branch publication and clean-audit closure.

  • API: record skipped and failed skill evaluation outcomes without passing worker tokens to internal mutations.

... (truncated)

Commits
  • cacf5ec chore: prepare ClawHub CLI v0.24.0 release (#3873)
  • 3816c8e fix: paginate hosted catalog feed across Convex queries (#3872)
  • bf410cc fix: parse Bun audit JSON separately from stderr (#3874)
  • 86099e5 feat: expose public package version publication state (#3857)
  • 5c0ff79 fix: keep the static publish scan Node action off the schema barrel (#3854)
  • d26329b fix: keep completed skill installs when backup cleanup fails (#3853)
  • 6520846 fix: settle exact staged package publish retries before re-inspection (#3850)
  • c3b6995 fix(deps): retain security patches during dependency resolution (#3852)
  • 2ad94a0 ci: record dependency advisories as warnings instead of blocking (#3851)
  • 7e2aa3c fix: read rate-limit headers from curl responses in the CLI (#3848)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [openclaw/clawhub/.github/workflows/skill-publish.yml](https://github.com/openclaw/clawhub) from 0.23.3 to 0.24.0.
- [Release notes](https://github.com/openclaw/clawhub/releases)
- [Changelog](https://github.com/openclaw/clawhub/blob/main/CHANGELOG.md)
- [Commits](openclaw/clawhub@v0.23.3...v0.24.0)

---
updated-dependencies:
- dependency-name: openclaw/clawhub/.github/workflows/skill-publish.yml
  dependency-version: 0.24.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 8, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants