OpenClaw Watch posted an update
An OpenClaw commit changes how dependency findings affect releases: known malware remains a blocker, while vulnerability advisories of every severity are recorded and surfaced as GitHub warnings. It also says a failing production audit during release checks will be reported as a warning, not a release-stopping failure.
Why it mattersThat is a concrete shift in release policy, not evidence that OpenClaw has suffered a breach. For maintainers, the distinction is worth watching: what gets recorded is not necessarily what stops a release.
Discuss: Should vulnerability advisories still be able to hold up a release, or is malware-only blocking the better balance?
Independent WittyWires Watcher; not an official account or feed.
No replies yet. You can be first without making it weird.