Skip to content

v0.2.0

Choose a tag to compare

@github-actions github-actions released this 10 Sep 01:04
1d35181

OpenClaw.NET v0.2.0 improves operator security, goal durability, recovery, and runtime verification.

Highlights

  • Existing browser sessions are invalidated when a local operator account is disabled, deleted, demoted, or has its password changed.
  • Goals can complete after successful tools, resume after automatic pause, and retain their state and token usage across gateway restarts. Model blocking requires three matching observations.
  • Startup recovery processes every eligible background session, including those beyond the first page, with both file and SQLite storage.
  • Dashboard account-token and bootstrap login use the gateway contract; failed API requests surface errors.
  • The native runtime now uses its extracted checkpoint, tool, model, context, and accounting components. Runtime scenarios evaluate actual execution evidence.
  • Companion supports isolated profiles through OPENCLAW_COMPANION_STATE_DIR and reliably stops its owned gateway when the desktop app closes.
  • The WhatsApp Go worker uses patched cryptography and Go 1.26.6. The Baileys worker has a reproducible dependency lockfile.
  • Release binaries carry the release version, and POSIX archives preserve executable permissions.

Downloads

Choose the desktop bundle for Windows x64, Linux x64, or Apple Silicon macOS. Each includes Companion, the NativeAOT gateway, and the CLI. Standalone gateway and CLI archives are also available. Every archive has a SHA-256 checksum.

Compatibility

Custom implementations of IGoalService must implement BeginTurn and UpdateModelStatus. Custom IBackgroundSessionStore implementations must implement ListBackgroundRecoveryPageAsync. Built-in implementations are updated.

Goal files are stored beneath Memory.StoragePath/goals and require a single writer. They do not provide exactly-once external actions or a full-instance backup. Action reconciliation, automatic run capture/replay, full-instance backup/restore, and richer operator recovery explanations remain roadmap work.

Validation

  • Full CI and release builds passed on commit 1d35181de37c2b059d363aecc18aa612bd26b409, including Windows x64, Linux x64, macOS arm64, NativeAOT, and Docker checks.

  • All nine release archive checksums match the uploaded asset digests. Final macOS downloads passed local checksum verification and the CLI reports version 0.2.0.0.

  • Final macOS desktop binaries passed first-run setup, gateway start/stop/restart, missing-configuration recovery, and clean desktop/gateway shutdown. UI automation used a temporary app wrapper around the unchanged packaged binaries and an isolated profile; external model inference was not exercised.

  • 2,503 standard tests and 2,516 tests with OpenSandbox and MemPalace enabled passed in CI; the optional-enabled suite also passed locally.

  • No vulnerable dependencies were reported by the .NET test-project dependency scan or the Node worker audit; Go govulncheck found no affected code paths.

See release guidance for setup and platform signing details.

What's Changed

  • Patch newly disclosed Go vulnerabilities by @Telli in #204
  • build(deps): bump google.golang.org/protobuf from 1.36.11 to 1.36.12 in /src/whatsapp-whatsmeow-worker by @dependabot[bot] in #205
  • build(deps): bump github.com/mattn/go-sqlite3 from 1.14.49 to 1.14.50 in /src/whatsapp-whatsmeow-worker by @dependabot[bot] in #206
  • build(deps): bump docker/setup-buildx-action from 4.2.0 to 4.3.0 by @dependabot[bot] in #207
  • Fix YAML parsing and gateway content includes by @geffzhang in #208
  • build(deps): bump github.com/mattn/go-sqlite3 from 1.14.50 to 1.14.52 in /src/whatsapp-whatsmeow-worker by @dependabot[bot] in #209
  • Fix operator authorization and durable task lifecycle for the next release by @Telli in #210
  • fix(release): preserve Unix executable permissions in downloads by @Telli in #211
  • fix(companion): stop owned gateway during desktop exit by @Telli in #212

Full Changelog: v0.1.4...v0.2.0