Skip to content

docs(changelog): add v0.0.90 security remediation#7326

Merged
jyaunches merged 1 commit into
mainfrom
codex/docs-v0.0.90-security-followup
Jul 21, 2026
Merged

docs(changelog): add v0.0.90 security remediation#7326
jyaunches merged 1 commit into
mainfrom
codex/docs-v0.0.90-security-followup

Conversation

@jyaunches

@jyaunches jyaunches commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Summary

Complete the planned v0.0.90 changelog after the security remediation in #7286 merged.
The release entry now records the remediated OpenClaw dependency boundary and links to the detailed dependency review.

Related Issue

Related to #5591 and follows #7286.

Changes

Type of Change

  • Code change (feature, bug fix, or refactor)
  • Code change with doc updates
  • Doc only (prose changes, no code sample modifications)
  • Doc only (includes code sample changes)

Quality Gates

  • Tests added or updated for changed behavior
  • Existing tests cover changed behavior — justification: test/changelog-docs.test.ts validates changelog structure and links, and the full docs build validates generated content and routes.
  • Tests not applicable — justification:
  • Docs updated for user-facing behavior changes
  • Docs not applicable — justification:
  • Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging)
  • Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification:
  • Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue:

DGX Station Hardware Evidence

  • Tested on DGX Station
  • Tested commit: not applicable
  • Station profile/scenario: not applicable
  • Result: not applicable
  • Supporting evidence: not applicable

Verification

  • PR description includes a Signed-off-by: line and every commit appears as Verified in GitHub
  • Normal pre-commit, commit-msg, and pre-push hooks passed, or npm run check:diff passed when hooks were skipped or unavailable
  • Targeted behavior tests pass for the current change set, or tests are marked not applicable above — npx vitest run test/changelog-docs.test.ts: 6/6 passed
  • Applicable broad gate passed — npm run docs: 0 errors; the two repository-wide pre-existing Fern warnings remain
  • Quality Gates section completed with required justifications or waivers
  • No secrets, API keys, or credentials committed
  • npm run docs builds without warnings (doc changes only) — 0 errors; the two repository-wide pre-existing Fern warnings remain
  • Doc pages follow the style guide (doc changes only)
  • New doc pages include SPDX header and frontmatter (new pages only)

Signed-off-by: Julie Yaunches jyaunches@nvidia.com

Summary by CodeRabbit

  • Documentation
    • Clarified inference provider routing and credential handling for managed agent images.
    • Added migration guidance ahead of the upcoming fallback removal.
    • Documented security updates for OpenClaw, Slack, and Microsoft Teams installations, including verified package remediation and archive validation.

Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
@jyaunches jyaunches added area: docs Documentation, examples, guides, or docs build v0.0.90 labels Jul 21, 2026
@coderabbitai

coderabbitai Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 90c2b95d-3457-4f03-a846-c7940cbb8329

📥 Commits

Reviewing files that changed from the base of the PR and between 2ad613d and f2d9f15.

📒 Files selected for processing (1)
  • docs/changelog/2026-07-20.mdx

📝 Walkthrough

Walkthrough

The v0.0.90 changelog now documents managed-image inference routing through NEMOCLAW_INFERENCE_PROVIDER_ID, migration guidance, and reviewed vulnerability remediation for OpenClaw integrations.

Changes

Release notes

Layer / File(s) Summary
Document v0.0.90 changes
docs/changelog/2026-07-20.mdx
Adds inference selector and credential-handling details, migration guidance, and dependency remediation notes for OpenClaw, Slack, and Microsoft Teams.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Possibly related PRs

Suggested labels: integration: openclaw, integration: hermes

Suggested reviewers: cv

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly matches the documentation-only changelog update and highlights the v0.0.90 security remediation.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/docs-v0.0.90-security-followup

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

@github-actions

github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

PR Review Advisor — Informational

Advisor assessment: Informational / high confidence
Next action: No advisor follow-up needed.
Findings: 0 blockers · 0 warnings · 0 suggestions
Status: No actionable findings remain in the canonical review ledger.

Model lanes

  • GPT-5.6 Terra (primary): Completed · high confidence · 0 blockers · 0 warnings · 0 suggestions
  • Nemotron 3 Ultra (second opinion): Completed · high confidence · 0 blockers · 0 warnings · 0 suggestions
  • Model comparison: normalized findings match; normalized E2E selections differ; severity counts match.

Nemotron output stays in workflow artifacts and does not change the assessment above.

E2E guidance

Advisory only. E2E / PR Gate selects and runs jobs independently.

Recommended E2E: None

1 optional E2E recommendation
  • docs-validation

Workflow run details

This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge.

@jyaunches
jyaunches merged commit 5814d19 into main Jul 21, 2026
70 checks passed
@jyaunches
jyaunches deleted the codex/docs-v0.0.90-security-followup branch July 21, 2026 17:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: docs Documentation, examples, guides, or docs build

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant