OpenClaw 2026.6.34: extended-stable security release, Plugin SDK removals announced
Maintenance release on the extended-stable line — targeted security and reliability repairs, no new features. Notable for plugin authors: before_agent_start, root openclaw/plugin-sdk imports, providerAuthEnvVars, and channelEnvVars are scheduled for removal. OpenCode Go users get the corrected hy3 model identifier in place of the failing hy3-preview alias.
PUBLISHED2026-08-08
OBSERVED2026-08-11
AGE3d
SOURCES1
Highlights
- Sandboxed browser routes, trusted DNS targets, custom browser origins, and loopback provider endpoints reject unsafe access paths
- Retained session writes, provider fallbacks, stream progress handling, and stdio failures recover without silently ending active work
- Pending channel work resumes after recovery, acknowledgements are idempotent, sustained Discord gateway bursts stay bounded
- Command and status surfaces keep owner-only actions protected; credentials kept out of account URLs and summaries
- SQLite checkpoints, workspace reads, gateway process signalling, plugin HTTP responses, and dependency handling tolerate transient host conditions
Fixes
- OpenCode Go: use documented
hy3model identifier instead of the failinghy3-previewalias - Codex native subagents: retain parent app-server subscription; recognize multi-agent V2 child activity until a yielded child completion reaches its requester
- Dependency resolutions updated for patched
brace-expansion, PostCSS,fast-uri,ip-address, Undici (#113428, #118804)
Upcoming deprecations
before_agent_start, rootopenclaw/plugin-sdkimports,providerAuthEnvVars, andchannelEnvVarsscheduled for removal after July 24 — migrate to modern hook stages, focused SDK subpath imports, and manifest setup descriptors
Release notes
- Extended-stable Gateway release: npm and container images only; the GitHub release is intentionally not flagged Latest
extended-stableselectors on npm and containers resolve to 2026.6.34- 25 merged PRs plus release-validation backports since 2026.6.33
COMMUNITY
No curated reactions recorded for this event. Facts and takes are kept in separate layers — community context is added by hand, never blended into the record above.