Signals

2026-09-21 / OpenClaw

The approved-exec fix finally shipped, and the long-term line moved to a build without it

Edited by Michael Ruescher

Merge ab5611f0 (binding exec approvals to the bytes that run), unreleased at the last two issues, is an ancestor of stable v2026.8.1 (2026-08-31) and of every later main-line tag; npm latest and beta are 2026.9.5. The npm extended-stable tag moved to 2026.7.35 on 2026-09-21, a July line that diverges from ab5611f0 and lacks the workspace-boundary and sandbox-stop fixes too. On 2026-09-11 the project published 75 advisories, 30 high, the exec-approval group patched in 2026.8.1.

What this changes for operators

  • Run 2026.8.1 or later on the latest channel if you rely on the exec approval prompt. Do not read extended-stable as the safer choice; it is the unfixed one.
  • Allow Always saved path-only grants before 2026.8.1 (GHSA-74gc); review persisted grants after upgrading.
  • Evidence that would settle residual: an extended-stable build containing ab5611f0.

Primary sources

Signal metadata

Source findings

Featured in

Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0

Schema: bitter.frontier_signals.v0 / ID: 2026-09-21-openclaw-exec-fix-shipped-extended-stable-did-not

Research evidence and publication history are open in the repository.