Evidence record / openclaw

A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.

2026-07-01-openclaw-security-hardening-commit-on-main-not-yet-tagged-bound-o

Security-hardening commit on main (not yet tagged): bound OAuth token endpoint response reads in the Anthropic OAuth path (channel: main-unreleased, 2026-07-01). Operator consequence: Watch item, not yet actionable via a release. It bounds how much the client reads from the OAuth token endpoint (DoS/abuse hardening on the Anthropic auth flow). Track for the next tag; no operator action until it ships in a stable release. Full receipted detail lives in harvest/watchlist.md.

Receipt

Finding metadata

Run: 2026-07-01-weekly-digest-2026-06-24_2026-07-01-frontier-v0

Finding ID: 2026-07-01-openclaw-security-hardening-commit-on-main-not-yet-tagged-bound-o

Source links

Primary links, including exact changelog lines when available.

Versioned source: run artifact