惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

美团技术团队
T
The Blog of Author Tim Ferriss
月光博客
月光博客
阮一峰的网络日志
阮一峰的网络日志
Engineering at Meta
Engineering at Meta
量子位
I
InfoQ
Jina AI
Jina AI
Microsoft Security Blog
Microsoft Security Blog
H
Help Net Security
H
Hackread – Cybersecurity News, Data Breaches, AI and More
G
Google Developers Blog
J
Java Code Geeks
Recent Announcements
Recent Announcements
aimingoo的专栏
aimingoo的专栏
小众软件
小众软件
V
V2EX
腾讯CDC
P
Proofpoint News Feed
A
About on SuperTechFans
爱范儿
爱范儿
U
Unit 42
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Last Week in AI
Last Week in AI

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4
ci: schedule android codeql shard (#73430) · openclaw/ope...
vincentkoc · 2026-04-28 · via Recent Commits to openclaw:main

@@ -230,18 +230,22 @@ or overlapping changed hunks.

230230

The `CodeQL` workflow is intentionally a narrow first-pass security scanner,

231231

not the full repository sweep. Daily and manual runs scan Actions workflow code

232232

plus the highest-risk JavaScript/TypeScript auth, secrets, sandbox, cron, and

233-

gateway surfaces with high-precision security queries. Android and macOS remain

234-

manual security shards so their runtime and alert quality can be tracked

235-

separately.

233+

gateway surfaces with high-precision security queries. macOS remains a manual

234+

security shard so its runtime and alert quality can be tracked separately.

235+236+

The `CodeQL Android Critical Security` workflow is the scheduled Android

237+

security shard. It builds the Android app manually for CodeQL on the smallest

238+

Blacksmith Linux runner label accepted by workflow sanity and uploads results

239+

under the `/codeql-critical-security/android` category.

236240237241

The `CodeQL Critical Quality` workflow is the matching non-security shard. It

238242

runs only error-severity, non-security JavaScript/TypeScript quality queries

239243

over the same narrow auth, secrets, sandbox, cron, and gateway surface. Keep it

240244

separate from the security workflow so quality findings can be scheduled,

241245

measured, disabled, or expanded without obscuring security signal. Swift,

242-

Android, Python, UI, and bundled-plugin CodeQL expansion should be added back as

243-

scoped or sharded follow-up work only after the narrow profiles have stable

244-

runtime and signal.

246+

Python, UI, and bundled-plugin CodeQL expansion should be added back as scoped

247+

or sharded follow-up work only after the narrow profiles have stable runtime and

248+

signal.

245249246250

The `Docs Agent` workflow is an event-driven Codex maintenance lane for keeping

247251

existing docs aligned with recently landed changes. It has no pure schedule: a