Repository navigation
Conversation
Signed-off-by: Rebecca Sliter <571084+rsliter@users.noreply.github.com>
Signed-off-by: Rebecca Sliter <571084+rsliter@users.noreply.github.com>
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: true
Comment |
|
🌿 Preview your docs: https://nvidia-preview-pr-12513.docs.buildwithfern.com/nemoclaw |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall line coverage in commit 1dc162e in the Show a line coverage summary of the most impacted files.
TypeScript / code-coverage/cliThe overall line coverage in commit 1dc162e in the Show a line coverage summary of the most impacted files.
Updated |
Signed-off-by: Rebecca Sliter <571084+rsliter@users.noreply.github.com>
Signed-off-by: Rebecca Sliter <571084+rsliter@users.noreply.github.com>
|
Maintainer context: This remains a valid focused Undici remediation. It updates the root OpenClaw runtime and the bundled Slack and Discord plugin paths, including offline and installed-plugin remediation. It is not a complete repository-wide dependency or CI unblocker. It does not repair the separate Maintainer intent is to preserve and merge this focused fix if exact-head evidence shows that it does not regress unrelated behavior and the required independent trust and CI gates are satisfied. Do not bypass red required checks. If #12507 lands first, re-evaluate this PR against |
|
Closing in favor of continuing the broader repair in #12507. #12513 remains a valid focused Undici remediation. Its candidate-owned tests, all twelve CLI shards, type checks, installer tests, plugin tests, CodeQL, and CodeRabbit passed on #12507 is the more complete candidate because it also addresses Reopen #12513 if #12507 stalls, cannot restore the trusted audit boundary, or the broader OpenClaw upgrade is declined and the focused 2026.9.1 remediation is needed as the fallback. |
Outcome
NemoClaw now remediates the reviewed Undici advisories in the root OpenClaw 2026.9.1 archive and its Discord and Slack plugin bundles. Managed image builds cache the reviewed replacement archives for offline installation.
Reason
Updating the root dependency alone leaves vulnerable Undici copies inside signed OpenClaw plugin archives. The build and installed-plugin paths must replace those copies without weakening package provenance checks.
Changes
Verification
npx vitest run --project integration test/agents/openclaw/openclaw-2026-9-undici-remediation.test.ts test/runtime/messaging/messaging-build-applier.test.ts- 41 tests passed.npx vitest run --project integration test/runtime/messaging/messaging-build-applier-integrity.test.ts- 6 tests passed.npx vitest run --project integration test/agents/openclaw/openclaw-managed-messaging-offline-build.test.ts- 4 tests passed.npx vitest run --project integration test/automation/pull-requests/growth-guardrails.test.ts test/agents/openclaw/openclaw-2026-9-undici-remediation.test.ts- 15 tests passed.npx vitest run --project package-contract test/package-contract/managed-image-registry-transport.test.ts- passed.npm run source-shape:check- passed with no new source-shape cases.npm run build:cli- passed.npm --prefix nemoclaw run build- passed.NODE_OPTIONS=--max-old-space-size=8192 npm run typecheck:cli- passed.git diff --check origin/main...HEAD- passed.Review notes
This draft is the approved Pi qualification seed. The changed image inputs require Linux AMD64 and ARM64 candidate receipts from this PR commit and one workflow run. The PR must remain draft until those receipts are committed and the normal publication gate passes without the seed exception.
The local seed publication skipped the Pi receipt refresh check and inherited Hadolint findings. All other selected repository checks passed. CI will provide the candidate image evidence needed to remove the Pi exception.
Signed-off-by: Rebecca Sliter 571084+rsliter@users.noreply.github.com