knowledge-base/raw/other/2026-06-16_openclaw-releases-v2026.6.8.md

341 lines
21 KiB
Markdown
Raw Normal View History

---
type: other
source_url: "https://github.com/openclaw/openclaw/releases"
retrieved: 2026-06-16
title: "OpenClaw Releases — v2026.6.6 bis v2026.6.8 (Top 5 aktuell)"
tags: [openclaw, releases, github, changelog, model-routing, security]
scope: index
fetched_via: GitHub REST API (releases endpoint, per_page=6)
---
# OpenClaw Releases — Index Snapshot (2026-06-16)
> Roh-Dump der fünf aktuellsten OpenClaw-Releases via GitHub-REST-API.
> Quelle: <https://github.com/openclaw/openclaw/releases>
> Fetch: 2026-06-16 18:08 UTC
Dieser Dump ist die unveränderliche Quelle. Strukturell reduzierte Wiki-Aufbereitung
liegt unter `wiki/tools/openclaw.md` + Updates in `wiki/architecture/model-routing.md`,
`wiki/architecture/memory-system.md`, `wiki/concepts/llm/glm-5.2-zai-coding-model.md`.
---
## 1. v2026.6.8 (stable) — 2026-06-16 16:32 UTC
- **Tag:** `v2026.6.8` (Release-Branch: `release/2026.6.8`)
- **Release-SHA:** `844f405ac1be805d5c598922a37254f12ab6d765`
- **URL:** <https://github.com/openclaw/openclaw/releases/tag/v2026.6.8>
- **Author:** [@vincentkoc](https://github.com/vincentkoc)
- **Asset:** `OpenClaw-2026.6.8.dmg` (40.8 MB), `OpenClaw-2026.6.8.zip` (55.8 MB),
`OpenClawCompanion-Setup-arm64.exe`, `openclaw-2026.6.8-dependency-evidence.zip`
### Highlights
- **Telegram + WhatsApp Channel Delivery:** Structured rich text (tabellen, listen,
expandable blockquotes, intentional line breaks), prompt-preserving CLI backend
delivery, retired native draft migration, safer rich-media boundaries, WhatsApp
honoriert konfigurierte ACP-Bindings. (#92679, #93164, #84082, #89421, #92513)
- **Agent + Gateway Recovery:** Account-scoped DM sends, generated media completions,
auto-reply message-tool final replies, reset archive fallback reads, restart
shutdown aborts, yielded subagent pauses, trusted subagent thinking override
fallback, yielded cron media, heartbeat dedupe, session identity prompts,
unknown OpenAI agent selector rejection. (#92788, #91246, #92879, #91357, #92631, …)
- **Provider/Model Handling:** **GLM-5.2** Support + Claude Haiku 4.5 catalog rows,
OpenRouter und Google Vertex provider-prefix normalization, managed SecretRef
auth, OAuth image-default routing via Codex, bounded model browse discovery,
LM Studio binary thinking-off delivery, storeless OpenAI Responses replay gating,
invalid OpenAI reasoning-signature + genericized Anthropic thinking-signature
recovery, Claude 4.5 Copilot tool-streaming safety, OpenAI/Anthropic-family
payload quarantine für unreadable/post-hook tool schemas.
- **`/usage` und reply payload hooks:** Native full footer renderer, default
template, fixed-decimal formatting, credential-aware limits, partial-count
handling, warnings für broken templates.
- **UI/mobile:** Workspace files collapsible, WebChat backscroll survives streaming,
sidebar session picker interaktiv, iOS reconnects stale foreground gateways.
- **Memory/State/Diagnostics:** Oversized OpenAI embedding batches split vor 431s,
**QMD memory search stays available in transient mode**, SQLite avoids WAL on
NFS state volumes, stuck-session recovery no longer resets warning backoff,
full memory reindexes preserve rollback/cache recovery, **raw Memory Wiki source
pages stop looking malformed**, Infinity chunk limits stay genuinely unbounded.
### Changes
- Providers/models: GLM-5.2 support, Claude Haiku 4.5 catalog entries, provider-
qualified model IDs normalized across OpenRouter + Google Vertex.
- Web search: Key-free providers (Parallel Free, DuckDuckGo, Ollama, Codex
Hosted Search) als explicit opt-ins, nicht auto-selected wenn keine API-backed
Provider konfiguriert. (#93616)
- Channel plugins: Telegram rich-message delivery, WhatsApp ACP binding support,
preserved line breaks, rich prompt handoff to CLI backends, transport fixtures.
- Agent commands: `/btw` in CLI-backed sessions, CLI usage-error exits als
usage failures klassifiziert.
- Usage hooks: built-in full footer rendering, default footer templates,
per-turn usage state, credential-aware limits, fixed-decimal formatting.
- Docs/operator guidance: node config examples, before-install hook scope,
agent default concurrency comments, ZAI provider docs, channel/group docs.
### Fixes (Kernauswahl, plattformrelevant)
- **Channels:** Account-scoped DM policy, intentional line breaks in Telegram/status,
rich Telegram final replies + tables + lists, Feishu dynamic-agent routes nach
persisted binding reuse, Slack outbound `message_sent` hooks, same-channel
generated media completions, channel chunking around surrogate pairs + Infinity.
- **Discord:** Auto-thread titles: 60s timeout + 4,096-token reasoning budget
(clamped to model output cap).
- **Agent/cron/Gateway runtime:** Active main sessions marked before restart
shutdown aborts, yielded subagent runs paused at terminal abort, trusted
subagent thinking overrides clamped through provider/model fallback, yielded
media completions preserved, channel message-tool final replies via auto-reply
(internal hints hidden), reset archive fallback reads restored, heartbeat
events de-duplicated, session identity exposed in runtime prompts, unknown
OpenAI agent selectors rejected, **admin privileges required for HTTP
session/model override surfaces**.
- **Providers/model replay:** Storeless OpenAI Responses replay compatibility,
OpenAI reasoning-signature + Anthropic thinking-signature replay recovery,
OAuth image defaults routed through Codex, Claude 4.5 in Copilot avoids eager
tool streaming, **unreadable and post-hook OpenAI/Anthropic-family tool
schemas quarantined** (ohne broadening allowed tool choices), LM Studio
binary-thinking models erhalten explicit thinking-off requests, profile auth
honored for SecretRef model entries, bounded model browsing, provider prefixes
stripped wo runtimes bare IDs brauchen, nested embedding fetch failures surfaced.
- **Memory/State/Diagnostics/Config:** Header-too-large embedding batches split,
**QMD memory search enabled in transient mode**, **SQLite avoids WAL on NFS
volumes**, recovery scheduling preserved, full-reindex rollback/cache recovery,
**raw Memory Wiki source pages treated as source evidence**, shell environment
fallbacks contained in config write tests.
- **Plugins + updates:** Missing required platform packages during managed plugin
install/update repaired, including omitted Codex platform binaries.
- **Dependencies:** Hono updated to 4.12.25.
- **Release + test reliability:** Slow Gateway/full-suite watchdogs extended,
local full-suite shards split when throttled, plugin auth marker fixtures
stabilized, brittle provider-ref error text avoided, Telegram RTT sampling
folded into live QA evidence, QA scorecard mappings around canonical coverage
IDs simplified, QA Lab bootstrap aligned with flow-only scenarios, false
downgrade prompts für unresolved latest-tag updates vermieden.
### Verification
- npm: <https://www.npmjs.com/package/openclaw/v/2026.6.8>
- integrity: `sha512-iziR8fi69+ojrtX7FYYvTpkGcVnmyLpIhvchgt5LFkkdHVWw973XAAekKVZ3/xQJ5FG4NwgHkXL0LLTrgsNOSQ==`
- Release-CI-Report: <https://github.com/openclaw/releases/blob/main/evidence/2026.6.8/release-evidence.md>
- macOS signed/notarized preflight, Swift validation, asset promotion alle grün
- Windows Hub promotion: from `openclaw/openclaw-windows-node@v0.6.3`
---
## 2. v2026.6.8-beta.2 (prerelease) — 2026-06-16 01:50 UTC
- **Tag:** `v2026.6.8-beta.2` (Release-SHA: `b1736723d716b1abe1f8d324772371661146f3b8`)
- **URL:** <https://github.com/openclaw/openclaw/releases/tag/v2026.6.8-beta.2>
- **Inhalt:** Identisch zu v2026.6.8 (Highlights/Changes/Fixes), nur Verification-Block
verweist auf Beta-Build-Links und post-publish recovery (35 npm plugins + 35
ClawHub packages verifiziert nach Registry-Propagation).
---
## 3. v2026.6.8-beta.1 (prerelease) — 2026-06-14 22:45 UTC
- **Tag:** `v2026.6.8-beta.1` (Release-SHA: `43d00c7724b5b4856ad4055b2dcd21ce6ef61550`)
- **URL:** <https://github.com/openclaw/openclaw/releases/tag/v2026.6.8-beta.1>
- **Inhalt:** Gleiche Highlights/Changes/Fixes wie stable v2026.6.8; markiert als
`## 2026.6.8` im Body (nicht mit `v`-Prefix). Beta-1 CI: Release-Publish-
Orchestration fehlgeschlagen nach Plugin-Publish-Verification, dann direkter
OpenClaw-npm-Recovery. ClawHub Plugin-Publish fehlgeschlagen wegen
`setupEntry` Metadata in transport plugin (follow-up erforderlich).
---
## 4. v2026.6.7-beta.1 (prerelease) — 2024-06-13 09:42 UTC
- **Tag:** `v2026.6.7-beta.1`
- **URL:** <https://github.com/openclaw/openclaw/releases/tag/v2026.6.7-beta.1>
- **Body-Header:** `## 2026.6.7` (Note: kein 2026.6.7-stable; nur Beta)
### Highlights (Highlights zusammengefasst)
- **Channel delivery tighter:** Slack same-channel finals persist in transcripts,
top-level `image` message-tool sends attach media, Telegram expandable
blockquotes + spooled replay survive delivery, explicit silent replies stay
silent, progress draft startup failures reported, channel action result pages
fetchable incremental. (#92498, #92407, #92416, #92281, #92073, #92083, #88993)
- **Provider/Model resilient:** **Kimi K2.7 Code verfügbar**, Kimi native tool-call
ids + replayed `reasoning_content` repaired, Mistral skips unreadable tool
schemas, Fireworks catalog parameters from manifests, DeepSeek keeps configured
static transport, provider fallbacks resolve correctly, Anthropic thinking
replay repaired, Anthropic Vertex stops re-marking transport-budgeted cache
control. (#92554, #92396, #90242, #90326, #92265, #92293, #92286, #92387)
- **Context/Auth boundaries safer:** Feishu leakt keine prompt-preface runtime
context, WebSocket payload handling hardened, CLI-backed `/btw` fallback
fails closed, local setup trust hardened, Skill Workshop symlink writes
gated + validated before rollback metadata written. (#92589, #92593, #92226, #92175)
- **Agent/Memory/Codex/Cron/Update recovery:** Invalid plugin model catalogs
isolated, QMD startup failures survive fallback errors, Codex memory prompts
stay registered, source message tool replies stoppen agent progress nicht
mehr, structured unsupported-model errors classified, heartbeat/cron terminal
state preserved, Linux service updates handoff cleanly, cron status reports
SQLite store path. (#92564, #92218, #92618, #92350, #92343, #92280, #92231, #92225, #92144)
- **UI/Docs/QA/Docker/Release proof:** Accessibility contrast/focus/font fixes,
empty Workboard columns hideable, design-system docs, uptime monitors pointed
at `/health`, Windows Hub docs pin verified stable installer links, QA evidence
+ scorecard taxonomy artifacts, QA Lab bundled into Docker images, lifecycle
timeout cleanup survives leader exit. (#89822, #89615, #89827, #55768, #92608, #92605, #91484, #91500, #92087, #92566)
### Changes
- QA + release validation emit scorecard taxonomy + evidence artifacts, split
plugin ClawHub publishing paths, use trusted plugin npm publishing, keep
plugin publish checks authoritative, align root package, publishable plugin
manifests, generated baselines, native app versions für 2026.6.7 beta train.
- Docs + operator guidance: Gateway uptime monitoring, design-system guidance,
Windows Hub stable download pins, removed stale ClawHub navigation, WhatsApp
inbound compatibility, doctor/update progress behavior.
- Matrix plugin release metadata aligned with core beta train.
### Fixes
- Channels: Slack transcript mirrors, Telegram polling conflicts + transient
draft-preview failures, outbound image sends, explicit silent replies,
progress-draft startup errors, paged action results, WhatsApp inbound
aliases, local setup trust, heartbeat commitment delivery.
- Provider/model/tool replay: Mistral schemas, Fireworks manifest model
parameters, Kimi K2.7 Code/tool-call/reasoning replay, DeepSeek transport
inheritance, managed SecretRef auth, static model fallbacks, Anthropic
thinking replay, Anthropic Vertex cache control, OTLP trace correlation.
- Agent/runtime recovery: Invalid plugin model catalogs isolated, Codex memory
prompt registration preserved, source message tool replies continue,
structured unsupported-model errors classified, QMD startup failures reported
neben fallback errors, cron timeout/cancel state preserved, disabled heartbeat
one-shot retries working, Linux service auto-updates readable + handoff.
- Install/sandbox/doctor/security: CLI skill prompts from materialized paths,
CLI-backed `/btw` fails closed, doctor SecretRef previews, blocked external
channel plugins diagnosed, Skill Workshop symlink writes validated + gated,
Node package install failures stop processing, unsupported daemon service
status readable.
- Release/CI/E2E/Docker/dependency gates: lifecycle timeout cleanup, QA Lab
runtime in Docker images, esbuild audit pin updated, Docker process cleanup
hardened, plugin publish checks authoritative, noisy redundant proof scripts
entfernt.
---
## 5. v2026.6.6 (stable) — 2026-06-12 11:04 UTC
- **Tag:** `v2026.6.6` (Release-SHA: `8c802aa683510c7f7503597b54c3021733245e59`)
- **URL:** <https://github.com/openclaw/openclaw/releases/tag/v2026.6.6>
- **Integrity:** `sha512-oMYoQ8a7zummw1tD+AX98yYLzqoq0tQmYWHG65AA0ZivgzmOb2oD0cVdhcWP9IT3opkHdJ5vBdWywUe6xWQXtw==`
### Highlights (Security-Release — höchste Priorität für unser Setup)
- **Security boundaries substantially tighter** across: transcripts, sandbox
binds, host environment inheritance, MCP stdio, Codex HTTP access, native
search policy, elevated sender checks, deleted-agent ACP bypasses, loopback
tools, Discord moderation, Teams group actions. **Exec approvals now fail
closed on timeout.** (#91529, #91618, #91615, #91619, #91741, #91745, #91746,
#91748, #91749, #91750, #91751, #91752, #91763, #89938)
- **Telegram delivery safer + more coherent:** Account-scoped topics route to
correct agent, streamed text survives tool calls, `/compact` works on generic
ingress, callback handling uses concrete APIs, draft chunking shared, durable
dispatch dedupe moved into SDK, unauthorized DM text stays out of cache + prompt
context. (#91189, #88682, #89588, #90212, #91876, #91874, #91904, #91478, #91915)
- **iMessage recovery + delivery:** Always-on inbound restart, durable echo
markers, block streaming, idle approval discovery, hardened outbound
transport, actionable inbound startup diagnostics. (#91335, #91449, #88969, #88530, #91783, #91785)
- **Browser + MCP connectivity:** Existing-session CDP support, discovered
WebSocket validation, default-profile `cdpUrl` handling, safer browser-output
boundaries, Streamable HTTP loopback transport, corrected OAuth/SSE auth,
broader schema compatibility. (#91422, #89851, #91736, #91747, #91451, #80143)
- **Control UI startup + first-reply latency:** Cached model metadata, removal
of startup catalog wait, lazy slash-command loading, first-event tracing with
slow-reply diagnostics. (#91531, #91538, #91568, #91583, #91598)
- **Provider support expands:** OpenRouter OAuth onboarding, Claude Fable 5
adaptive thinking, Codex sessions keep correct compaction ownership, local
models skip guardian review, dynamic tool progress normalizes cleanly,
Gemma 4 reasoning replay preserved. (#91830, #91882, #91590, #88630, #88768, #91696)
### Changes (Auswahl)
- **CLI progress:** Emit Claude CLI commentary progress events, bridge inter-tool
commentary into channel progress without exposing internal protocol scaffolding.
- **Observability:** Trusted diagnostics channels capture tool input/output
content, first-assistant-event traces, warn on slow initial replies.
- **Plugins/ClawHub:** Dogfood reusable package publishing, dry runs skip
publish approval, declared installed trusted hooks, report managed plugin
version drift, warn instead of failing on retired Skill Workshop config.
- **Memory/providers:** Local llama.cpp runtime moved into its provider plugin,
batch embeddings across files, persist agent model catalog cache, QMD JSON
search one-shot + filtering stale REM recall previews.
- **Channels/mobile:** QQBot group mention toggle, iPad + iPhone control
surfaces, active connection host in TUI footer.
- **Performance:** Prewarm TUI runtime plugins, dedupe plugin auto-enable
fanout, stop `/models` derived-registry rescan storms, trim dense text-delta
snapshots, reuse prepared startup model metadata.
### Fixes (Auswahl, plattformrelevant)
- **Agent/session recovery:** Drop stale approval follow-ups after session
rebind, remove drained reply-queue items by identity, recover stale main +
visible replies, preserve Codex context-engine compaction ownership, project
thinking catalog compatibility through SDK sessions, retry same-model
assistant calls across short rate-limit windows, lower default compaction
timeout to 180s, keep provider-failure terminal lifecycle state correct.
- **User-visible content boundaries:** Suppress Codex/Harmony protocol artifacts,
neutralize browser + LanceDB memory media directives, redact transcript
images, preserve native `/compact` replies through source suppression.
- **Channel delivery:** WhatsApp captured replies attached to successor
controller after restart, Feishu rate limits retry, Mattermost thread replies
preserved, LINE webhook paths canonicalized, Discord reply hydration +
runtime timeout exports restored, OpenAI Realtime WebRTC assistant transcripts
shown.
- **Cron:** Cancel active task runs cleanly, preserve terminal timeout/cancel
state, recover no-deliver tool warnings statt silent loss.
- **Gateway/config/auth:** Share approval runtime socket token, replace arrays
explicitly in `config.patch`, keep indexed `replacePaths` consent from
widening to whole arrays, reject malformed Gateway RPC timeout inputs, skip
deleted-agent guard only for valid ACP harness sessions, surface headless
LaunchAgent state, verify SQLite auth migration before cleanup, arm QMD
startup maintenance.
- **Providers/Codex:** Clarify quota errors, restore Codex synthetic usage
line, canonicalize Codex protocol assets, require API-key auth for realtime
voice, normalize ACP model refs, preserve Gemma 4 `reasoning_content`, honor
Ollama's provider-declared thinking default in SDK sessions, avoid guardian
review for local models.
- **Updates/builds:** Recover package Gateway restarts after refresh failure,
expose plugin convergence repair, fall back to Corepack in PATH-less pnpm,
seed correct Docker store packages, keep ClawHub dry-run + publish paths
reusable, keep beta GitHub release pages draft bis OpenClaw npm + dependency
evidence + postpublish verification + required plugin publishes pass.
- **Android:** Avoid `dataSync` foreground-service type for persistent nodes.
- **Native hooks:** Bound relay lifetimes so abandoned native hook connections
cannot linger indefinitely.
### Verification
- npm: <https://www.npmjs.com/package/openclaw/v/2026.6.6>
- Full release CI report: <https://github.com/openclaw/releases/blob/main/evidence/2026.6.6/release-evidence.md>
---
## Cross-Release Patterns (plattformrelevant)
| Bereich | Trend seit 2026.6.6 | Direkter Impact für unser Setup |
|---|---|---|
| **Security boundaries** | Tightening: exec approvals fail closed, MCP stdio, ACP bypasses | High — wir laufen auf `ollama/minimax-m3` (local) + Telegram + Discord |
| **Memory** | QMD JSON search stabilisiert, batch embeddings, NFS-WAL vermieden | Medium — S2 (OpenClaw built-in) ist unsere primäre Memory |
| **Model routing** | OpenRouter/Vertex prefix normalization, GLM-5.2 Support, LM Studio binary thinking-off, OAuth image defaults via Codex | High — berührt unseren `openrouter/auto` Fallback + zukünftiges GLM-5.2 Routing |
| **Telegram** | Rich-message delivery, expandable blockquotes, account-scoped topics, intent-preserving line breaks | High — Hauptkanal |
| **Subagents** | Trusted subagent thinking override fallback, yielded subagent pauses bei abort, channel message-tool final replies hidden | High — wir spawnen regelmäßig Subagents |
| **Heartbeat** | De-duplication main-session events, snapshot of session identity in runtime prompts | Low — Heartbeats sind sideband |
| **Skill Workshop** | Symlink writes gated + validated, retired config wird warning statt failure | High — wir nutzen Skill Workshop aktiv |
| **Plugin updates** | Missing required platform packages repaired, Hono 4.12.25 | Medium — Codex platform binaries jetzt korrekt mitinstalliert |
| **Admin boundaries** | HTTP session/model override surfaces require admin | Medium — relevant falls wir HTTP-Override nutzen |
## Verwandte Wiki-Dateien
- `wiki/tools/openclaw.md` (neu erstellt 2026-06-16) — Übersicht + Versions-Timeline
- `wiki/architecture/model-routing.md` (Update 2026-06-16) — GLM-5.2 + Provider-Prefix
- `wiki/architecture/memory-system.md` (Update 2026-06-16) — QMD + SQLite-WAL
- `wiki/concepts/llm/glm-5.2-zai-coding-model.md` (Update 2026-06-16) — Offizielle
OpenClaw-Integration
- `wiki/concepts/llm/llm-knowledge-base.md` — OpenClaw native raw Memory Wiki
source pages support