The OpenClaw
repository tracker.
A timestamped view of release state, repository velocity and security signals. Metrics are evidence for editorial judgement—not proof that every change deserves a story.
openclaw 2026.7.2-beta.3
This is a pre-release signal. Operators should test it in a disposable or non-critical environment before considering production deployment.
Release analysis →GHSA-4pqj-3c56-5fqq
Workspace dotenv files could override provider credentials
An advisory appearing here does not establish that every deployment is exposed. Check affected versions, enabled integrations and the official remediation before acting.
Security desk →Collection map
Primary sources in. Editorial consequences out.
The collector deduplicates source events in SQLite, uses conditional HTTP requests, and leaves evidence pending until an editorial run judges it. Social posts and third-party coverage may surface leads, but they do not replace primary evidence.
Counts come from the official GitHub API for the stated rolling 24-hour window. The merged pull-request count uses GitHub issue search and can shift as pull requests or metadata are updated. The docs count uses the commits endpoint filtered to the docs path; GitHub returns at most 100 commits on this request.
From to the snapshot timestamp.
OpenClaw Academy is a community publication and is not officially affiliated with the OpenClaw project.