Skip to content

Releases: KCNyu/clawock

clawock v0.3.1

Choose a tag to compare

@github-actions github-actions released this 07 Oct 08:51
9916faf

Install from PyPI:

python -m pip install clawock==0.3.1

A maintenance release for the Python package and clawock-dsh, with corrected
session accounting, clearer evidence and delivery readouts, and task-panel
improvements. Restart DeepSeek Harness after upgrading clawock-dsh so its
host methods and client bundle come from the same version.

Added

  • clawock-dsh: /dispatch-list for OpenClaw, sharing the sidebar's
    provider balances, task queue, recent completions and patrol view (#2168).
  • clawock-dsh: task timelines, append history and patrol coverage, with
    readable findings, links to full task logs and Markdown chat layouts
    (#2425, #2426, #2443, #2518, #2529).

Changed

  • Dependency updates: Python now requires requests>=2.32.4 to include
    the credential-leak fix; the DSH protocol, client store and UI slots move
    to the 0.2.0-rc.2 line (#2165, #2578).
  • The README and its diagrams explain the complete workflow before setup,
    with separate US/HK return curves, evidence and judgment feedback loops,
    and consistent icons and flow types (#2664, #2735, #2736, #2740, #2749).

Fixed

  • Portfolio accounting follows each market's trading session. Per-lot
    daily P&L handles same-session buys; malformed ledger rows are reported;
    unknown sessions fail the integrity check without crashing; quote refreshes
    preserve concurrent ledger edits and previous closes (#2355, #2400, #2408,
    #2505, #2650). Leveraged bars are checked against their underlying where
    evidence is available, and suspect settlement marks carry refusal reasons
    (#2357, #2601).
  • Lifecycle CLI flags match the selected phase and report mode, optional
    dependency errors name the required extra, and brief fallback honors the
    selected workspace (#2554, #2619, #2651, #2734).
  • Brief and intraday evidence checks use complete, dated sources. News
    windows follow publication time, stale-news checks cover all reference
    families, trigger text and currency totals are grounded in source data,
    and scorecard provenance detects rewritten rows (#2236, #2257, #2357,
    #2475, #2584, #2598).
  • Delivery and health checks preserve failures and recovery evidence.
    Watchdogs wait for an in-flight attempt, WeChat backstops deduplicate across
    checkouts, due slots with no record are counted, and rollups retain actual
    delivery timestamps and degradation reasons (#2237, #2314, #2483, #2487,
    #2602, #2648, #2649, #2718).
  • Dashboard tabs and financial readouts are reliable on first use.
    Inactive panels are inert; tab switching no longer waits on a failed load;
    negative amounts keep their sign; return windows, exposure bases, sample
    counts, source dates and holding sessions are labelled consistently
    (#2511, #2513, #2555, #2581, #2582, #2583, #2600, #2611, #2697, #2719).
  • clawock-dsh reports unreadable balances and queues as unavailable,
    expires trace caches, and re-renders changed FX provenance instead of
    retaining stale labels (#2184, #2319, #2360, #2586, #2659, #2696).
  • Published Markdown rejects unsafe link targets and escapes model HTML;
    public workflow records redact host paths (#2192, #2235, #2314, #2356).
  • Release npm verification tolerates registry propagation and compares
    the served package with a fresh build in a separate readback job, allowing
    the GitHub Release after both registries accept publication (#2156, #2319).

npm

clawock-dsh@0.3.1 published to npm.

clawock v0.3.0

Choose a tag to compare

@KCNyu KCNyu released this 29 Sep 01:16
ff7531a

Install from PyPI:

python -m pip install clawock==0.3.0

A minor bump: a new public command, new intraday harness surfaces and a new
DSH plugin panel. Nothing was removed and no dependency changed. The DSH plugin
ships on the same version. Restart DeepSeek Harness after upgrading
clawock-dsh
: the panel adds host methods, and the host half of a plugin
loads only at start, so a new client stays paired with the old host until then.

Added

  • clawock live-sources (#1935). Free live news and disclosures
    (HKEXnews, EDGAR full-text search, Google News, Yahoo RSS, 同花顺 and 东财
    7×24) for any harness. It is budgeted and timed, and each item is labelled
    with its publication time.
  • Intraday harness: a core packet plus an addressable reference layer
    (#1882).
    intraday preflight --judgment-packet prints only the
    judgment-relevant fields; the rest is fetched on demand with
    clawock tool intraday_reference. There is also an information lane with
    timestamped items (#1885) and one web search per mover per session
    (#1887).
  • Add-side reads (#1872, #1888, #1953). The brief and the intraday
    card share one implementation. Evidence is graded, pullback candidates are
    allowed, and discipline downgrades a read. Left-side scale-in runs in
    observe mode: its rows carry no size (#2040).
  • clawock-dsh: one provider panel (#2037). Claude and Codex quota
    windows, the DeepSeek and MiniMax balances and the OpenCode free pool sit in
    one sidebar cell. On a host that runs clawock's agent-dispatch, the panel
    also shows the task queue, which can be steered from the chip (#1951).
    Each row opens a detail layer (#1775, #2136), and every row shares one
    grid with role-coloured status chips (#2129).
  • clawock-dsh: localized client (#1660), with LICENSE and
    SECURITY.md shipped in the package (#1524).

Changed

  • clawock-dsh: the balance lives in the sidebar foot and opens as a
    popover (#1529, #1533)
    , instead of replacing the main column.
  • Every intraday slot sends a card (#1865). A slot with no change says
    so in one line, rather than staying silent.
  • The README (the PyPI project page) was rebuilt around what a first-time
    reader needs (#2150).
    It adds a two-line install at the top, a linked
    logo wall of the supported harnesses, real OpenClaw and DSH captures, and a
    plugin section.

Fixed

  • The Finnhub key is sent as a header (#1845), so a provider error
    message can no longer echo it into a published artifact.
  • Model prose is escaped in the published brief (#2111).
  • HK quote timestamps are parsed for the staleness gate (#2117).
  • Writes to the decision ledger can be read back by a strict parser
    (#1739)
    , and portfolio reconciliation is serialized against quote
    writes (#1812).
  • clawock-dsh loads on hosts that ship React 18 (#1655). It also keeps
    malformed share counts out of the traces wire (#1824), and state chips in
    the sidebar are no longer clipped (#2138).

npm

clawock-dsh@0.3.0 published to npm.

clawock v0.2.0

Choose a tag to compare

@github-actions github-actions released this 14 Sep 16:08
84f541a

Install from PyPI:

python -m pip install clawock==0.2.0

A minor bump rather than 0.1.10: numpy and scipy became required
dependencies and the compute extra is gone. The DSH plugin ships on the same
version.

Changed

  • numpy and scipy are required (#1202). portfolio/risk.py, the
    module behind the packaged portfolio-risk command, imported numpy at the top
    level while numpy sat in an optional extra, so on a clean install that command
    failed on its first line. scipy joins it for the covariance, allocation and
    stress work that landed in the same change.
  • The empty compute extra is removed; clawock[market] installs the
    yfinance quote fallback (#1321, #1325).
    yfinance is the last hop of
    the HK quote chain and the fifth of seven US providers. It was declared
    nowhere, so an install that followed the metadata silently lost that hop.
  • The pre-open brief is rendered by the harness, not written by the model
    (#1232, #1234).
    The model supplies the judgment (schema v3) and
    clawock.harness.brief_render produces the report and the WeChat card;
    clawock brief render runs that step on its own, with --dry-run and
    --date.
  • Report and intraday postflights accept only the prose form (#1279). The
    legacy input, where the model handed back a whole report including its own
    copy of the data block, is removed together with
    validation.check_raw_tables_verbatim.
  • Run cards use schema 2 (#1203). Reproduction keys now cover registered
    seeds, library versions and configuration contents; old keys no longer match
    reruns. clawock run-card --diff and --verify explain changes and check the
    recorded environment, with a separate digest for the resulting metrics.
  • Module workspace defaults no longer follow the process's current directory
    (#1254).
    They resolve from the package tree; CLAWOCK_WORKSPACE still
    overrides that default for an external book.
  • The packaged automation LLM client uses MiniMax only (#1488). The
    OpenCode fallback and its fallback_* arguments are removed. Influence-feed
    filtering failures retain only fresh, previously scored entries instead of
    publishing unscored candidates.
  • Automation validates model output before publishing (#1267). Empty,
    stub-length or incomplete reports are refused; structured influence-feed
    scores are checked before use.
  • Delivered postflights with advisory warnings exit 0; failed products exit
    2 (#1433).
    Report, intraday and brief now share this exit-code contract.

Added

  • clawock calendar <market> --status (#1429) prints OPEN / CLOSED
    and always exits 0, for callers that read the output rather than the exit
    code. The bare command still exits 1 on a closed session.
  • Covariance, allocation and stress modules for portfolio risk (#1162,
    #1165, #1186).
  • clawock signal-panel evaluates registered signals on the cross-section
    (#1131, #1199, #1201, #1236).
    It reports rank IC, quantile returns,
    turnover and persistence, fixed-horizon and triple-barrier outcomes, placebo
    tests and leave-one-ticker-out checks.
  • Evaluation modules for selection uncertainty, drift and attribution
    (#1128, #1197, #1204, #1205).
    These add purged CSCV/PBO, block
    bootstrap intervals, deflated Sharpe, distribution-drift diagnostics, factor
    attribution and a combined evaluation grade.
  • clawock validate-regime-hmm and clawock evaluate-add-shapes
    (#1208, #1341)
    compare probabilistic regimes and entry shapes against
    baselines. They measure alternatives without changing live decision rules.
  • Daily-bar liquidity and volatility estimators (#1200) include spread
    and illiquidity estimates, EWMA and GARCH volatility, with explicit missing
    values when the data cannot support an estimate.
  • Scorecard provenance and net shadow returns (#1127, #1218).
    clawock scorecard-provenance --check --recompute traces metrics to ledger
    rows. Shadow results retain the gross curve and add a net curve under stated
    commission and spread assumptions.
  • Optional decision debate and magnitude forecasts (#1129, #1239).
    Decisions can retain their supporting/opposing cases and expected_move_pct;
    coverage and forecast-magnitude errors are reported separately.
  • Decision-packet section queries accept thesis, execution, history,
    information and status (#1374)
    as well as the original seven sections.
  • clawock decision-map (#1206) joins decisions to the signal snapshots
    available when they were made, with explicit payload-size degradation.
  • clawock cron-trigger --job-name ... (#1443, #1498) queues an
    OpenClaw job from a host scheduler after checking ownership and current job
    state; --check validates without triggering a run.
  • clawock-dsh shows Codex quota (#1480). Codex is a fourth balance
    provider, read through the official codex app-server rate-limit call, with
    the 5-hour and weekly windows. Codex OAuth tokens are never read or
    forwarded. A quota warning now names the window that crossed the line
    (#1486).

Fixed

  • clawock-dsh loads on DeepSeek Harness 0.1.2 (#1310). 0.1.2 retired
    @deepseek-ai/dsh-client-runtime, which the plugin still required, and that
    one stale module id took the whole dsh UI down with "Failed to load plugins".
    The plugin now imports defineStore from @deepseek-ai/dsh-client-store.
  • The published profile schema matches the loader (#1308). It no longer
    requires the retired templates field or accepts workflows.*.template.
  • Decision IDs and ledger writes preserve episode identity and concurrent
    updates (#1433, #1483).
    Harness-owned IDs are normalized rather than
    trusting model-supplied episode IDs, and read/modify/write operations hold a
    cross-process ledger lock.
  • Artifact reads and interrupted writes preserve complete data
    (#1499, #1500, #1506).
    Git artifact reads stay on one fetched commit;
    canonical bars and fallback brief files use atomic writes.
  • Market-data failures remain distinguishable from valid data
    (#1124, #1130, #1397, #1505).
    Degraded quotes retain quality labels,
    HK peer discovery uses the working industry endpoint, benchmark fetch errors
    are reported, and non-positive closes no longer crash regime calculations.

npm

clawock-dsh@0.2.0 published to npm.

clawock v0.1.9

Choose a tag to compare

@github-actions github-actions released this 27 Aug 14:42
1e81cc6

Install from PyPI:

python -m pip install clawock==0.1.9

Refresh release: same version train for the Python package and the DSH
plugin; the plugin's published tree is unchanged from 0.1.8 (the desk's
Decision Mind UI work landed in the data plane, not the npm package).

Changed

  • Breakout is now a third evidence family for add authority ([#1086]). A
    confirmed, un-overheated 20-day breakout counts as an independent family;
    any two families authorise a capped exploration slice, while validated
    tranches still require decision-usable evidence on both the price and the
    information side. The README wording was aligned with the shipped behaviour.
  • Earnings quality requires at least four comparable periods on every
    cadence ([#1097]),
    matching the documented contract (annual filers now need
    four fiscal years).
  • The thesis registry is a pure kill-switch ([#1085]): an intact thesis
    sizes exactly like an undocumented one, and only broken / damaged /
    weakening states reduce tranches. The empty min(x, x) identity was
    removed and a test pins the subtract-only semantics.

Added

  • add_alpha_walkforward now splits fills by price structure and volatility
    regime ([#1107])
    — measurement only, no behaviour change.

npm

clawock-dsh@0.1.9 published to npm.

clawock v0.1.8

Choose a tag to compare

@github-actions github-actions released this 17 Aug 10:00
1c1915d

Install from PyPI:

python -m pip install clawock==0.1.8

The Python package's code is identical to 0.1.7. This version exists to ship the
plugin: clawock-dsh is the release.

Fixed

  • The Decision Mind plugin rendered the same four copy/verdict
    misrepresentations the dashboard card fixed in #742 — written by hand on that
    side, so fixing one side never fixed the other ([#741]).
    execution.status
    is the plan's self-report, not the fill's outcome, yet it headed the fill's
    timeline node as 执行/未执行 —「未执行」on a completed buy read as a flat
    contradiction. The 盈亏 label loaded two different quantities (this fill's
    realized money and the whole position's floating percent) into one word. The
    pairing was called 挂接决策, jargon that implied evidence the data did not
    carry. The T+1 chip only showed a verdict for action === 'sell', silently
    dropping cut/trim/trim_on_rebound. Now the fill node is 真实成交 with the
    plan-vs-fill relation stated as 与计划同向/反向 (alignment, host-computed;
    live data is 22/40 reversals), execution.status survives only as a labelled
    账本自评 chip, the P&L node splits into 本笔已实现 vs 该持仓当前浮动(非本笔),
    pairing reads 有当日计划/无当日计划, every header stat shows the denominator
    it is a fraction of (判出 X/Y 笔卖出, not a buy-and-sell-mixed total), and
    unjudged fills say T+1 未判 instead of lying by omission. The browser bundle
    keeps no second copy of the action set — side is computed host-side — and
    the alignment/action-set/breach-strip rules are now pinned against the
    dashboard half in tests/test_decision_trace_parity.py, which previously
    claimed to pin them without doing so. ([#744])

npm

clawock-dsh@0.1.8 published to npm.

clawock v0.1.7

Choose a tag to compare

@github-actions github-actions released this 17 Aug 07:06
6e52cfc

Install from PyPI:

python -m pip install clawock==0.1.7

The Python package's code is identical to 0.1.6. This version exists to ship the
plugin: clawock-dsh is the release.

Fixed

  • clawock-dsh on npm was a different build than its version number
    claimed.
    npm's latest was 0.1.5 for a day, whose
    tarball is the pre-#708 layout — client.js at the root, no
    lib/typert.*, no ./typert or ./remote export, no zod dependency —
    so dsh plugin add clawock-dsh installed a plugin that registers and then
    shows no data. The two tag-triggered 0.1.6 publishes died inside
    npm itself (Exit handler never called!): the plugin's package-lock.json had been
    regenerated on a machine behind a mirror registry, so all 169 resolved
    URLs pointed at a host the GitHub runner cannot reach and every fetch
    stalled through npm's retry ladder. The lockfile is back on
    registry.npmjs.org and the publish job pins the npm that does the publishing
    and records which registry it used; with those in place a manual npm-only run
    did land 0.1.6 on 2026-08-17 at 06:16Z, so the registry was already correct
    before this version. What 0.1.7 adds is the part that makes that claim
    checkable rather than assumed: because "publish exited 0" was never evidence,
    publishing now downloads the registry copy back and asserts file-for-file,
    export-for-export and dependency-for-dependency that it is what was packed.
    (#732, #728)

Changed

  • The DSH plugin follows the official Harness client rules instead of a
    reverse-engineered shape.
    Styles ship as CSS Modules whose
    <style data-plugin="clawock-dsh"> tag the module loader owns and removes on
    unload, so nothing touches document while the bundle is loading; the UI
    store is a createDecisionMindStore() factory called inside apply rather
    than a module-level singleton shared across plugin reloads; the trace cache
    lives in the plugin instance and reaches the view through its props; the
    scroll container comes from an element ref instead of a global selector; and
    the browser bundle carries no business any — it consumes the same wire
    types the host declares. The generated Typert reflection is now emitted by
    the official generator running in place over the real source tree (the
    package moved to examples/dsh/packages/clawock-dsh because rc.6 discovers
    packages only under a workspace root's packages/), the build is
    reproducible, and CI rebuilds lib/ on every plugin change and fails if the
    committed artifacts differ. (#729, #730, #731)
  • Installing the plugin from a checkout goes through the official
    installer.
    ops/host/install_dsh_plugin.sh packs the package and hands the
    tarball to dsh plugin --profile web add, which installs it the way a
    registry package is installed and reconciles the profile's bundle rows
    itself. It no longer hand-copies a source directory and hand-edits the
    profile manifest — a directory spec is only linked, which is how a plugin
    dependency went uninstalled and crash-looped dsh in the first place. The
    tarball's file name carries a content hash, because pnpm keys a file:
    tarball by path and would otherwise serve the previous build from its store
    while every step reported success. (#731)

npm

clawock-dsh@0.1.7 published to npm.

clawock v0.1.5

Choose a tag to compare

@github-actions github-actions released this 16 Aug 13:12
d20427d

Install from PyPI:

python -m pip install clawock==0.1.5

Fixed

  • The clawock-dsh DSH plugin's T+1 result color was inverted for sell
    actions.
    It applied one sign rule to every action, so a rising price after
    a sell (a loss for the seller — 卖飞) rendered green, and a falling price
    after a buy rendered green too. The color is now action-aware: rising is
    good (green) for a buyer, bad (red) for a seller, and vice versa. (#665)

Added

  • clawock record --source <harness> is now the single write path for the
    decision-mind ledger (memory/decisions.jsonl); every harness (OpenClaw,
    Claude, Codex, DSH, CLI) tags its own conversational judgments through it
    instead of hand-writing JSONL, and validate_decision accepts the resulting
    schema-version-0 records from any of them. (#661, #662)
  • The DSH plugin's Decision Studio tab is now a single "决策轨迹" (decision
    trace) timeline
    built from real trade fills, not a separate, disconnected
    ledger view: each row pairs an actual execution with its T+1 result chip and
    expands into the plan → execution → outcome sequence. It renders only the
    most recent activity by default, with a "show all" control for the rest.
    (#676, #684)

npm

clawock-dsh@0.1.5 published to npm.

clawock v0.1.4

Choose a tag to compare

@github-actions github-actions released this 15 Aug 17:39
44ae6be

Install from PyPI:

python -m pip install clawock==0.1.4

Fixed

  • Harness-agnostic examples and the clawock-dsh skill now match the real
    validator.
    The tutorial taught --artifact decision=..., a six-field
    decision shape and a fixed .clawock/work/request.json path; the validator
    requires the artifact to be named decision.json, nine top-level fields
    (schema_version / workflow / decision_id / as_of / subject / evidence /
    debate / thesis / decision) and the <run_id>-scoped request file
    prepare actually writes. The examples were rewritten against the pack's
    decision.example.json and the whole prepare → decision.json → publish
    loop is verified end-to-end. (clawock-dsh npm package bumped to 0.1.4.)
  • No more double-writer races on a missing brief. The 09:05 watchdog no
    longer queues a local re-run and the off-host fallback at the same time —
    two LLMs writing the same artifacts produced duplicate WeChat/Telegram
    pushes. The re-run is now evidence-gated (a run that ended OK today does not
    stack another queue entry).
  • Report delivery gaps are now named. When a postflight sender dies
    mid-send (claim present, no completion marker), the watchdog says "WeChat
    delivery unconfirmed" out loud instead of silently only mirroring Telegram.
  • User risk overrides settle the ledger. An overridden risk_rule cut is
    settled (execution.status=overridden_by_user) instead of accumulating as
    unknown forever and flooding the open queue when the override TTL expires.
  • The 30-bar data-quality gate is restored. The short-history fallback now
    requires a registry listing_date within 45 days, so a mature name with a
    partial feed can no longer enter the universe with half a signal set.

Changed

  • The AI watch list (智谱 / 迅策) now rides the brief's market bundle — the
    model boundary can actually read it — and its thresholds
    (opportunity_near_pct, early_no_chase_zscore) moved into
    add-alpha-policy.json as a single source shared with the intraday radar.
  • Intraday slots fetch each code once per slot instead of three times
    (~540 → ~180 requests/day).
  • Intraday push gating: opportunity/early-trend sub-state flips around a price
    threshold no longer retrigger a full push every slot.

npm

clawock-dsh@0.1.4 published to npm.

clawock v0.1.3

Choose a tag to compare

@github-actions github-actions released this 15 Aug 16:08
e6e773c

Install from PyPI:

python -m pip install clawock==0.1.3

Added

  • Harness-agnostic decision contract. The workflow is files + CLI, so the
    same decision run works from a pure CLI, an OpenClaw skill, a Claude Code
    instruction, a Codex AGENTS.md, or a DeepSeek Harness agent — see
    examples/harness-agnostic/ (each runnable, executed by release.yml).
  • clawock-dsh skill package on npm. DSH users install one command:
    dsh plugin --profile web add clawock-dsh. A pure dsh.skills package (no
    Node code) that walks the agent through prepare → decision.json → publish.
  • README rewritten around the live record. First-line hook (90 days live,
    −15.95%, every loss on the page), four-line scorecard reconciliation
    (ledger / directional hit / shadow portfolio / real account), reproducible
    auditing (clawock audit-resettle), and the influencer radar (Trump /
    Musk) now documented in both languages. Live numbers are maintained by
    ops/growth/refresh_readme_metrics.py placeholders, refreshed weekly by CI.
  • ops/publish/publish_dsh_plugin.sh — single entry point for publishing the
    npm side of a release, shared by release.yml and manual bumps.

Changed

  • README.zh.md and README.md now share a locked 12-section structure (CI
    parity tests); the information-layer tables are checked against
    config/information-layers.json and the per-run block counts against the
    preflights themselves.

npm

clawock-dsh@0.1.3 published to npm.

clawock v0.1.2

Choose a tag to compare

@github-actions github-actions released this 11 Aug 05:58
d68b278

Install from PyPI:

python -m pip install clawock==0.1.2

Mostly documentation and repository policy. It is a release because README.md
is shipped verbatim as the PyPI long_description, and a published page cannot
be re-rendered — the same reason 0.1.1 existed.

Fixed

  • The numeric provenance advisory now recognises %, pp, x/× and σ, and
    matches context per unit rather than against one flat set of numbers, so a
    figure like 2.3x is no longer waved through by a match on an unrelated
    quantity. The intraday insights sidecar is normalised before publication:
    model-owned narrative is kept, the generated_at stamp is the harness's own
    UTC clock, and a missing or malformed sidecar stays warn-only so report
    delivery is not held hostage to it. (#485)
  • The README's widest claim about the system — "26 fetch and compute modules
    across 8 layers" — had no artifact behind it and had survived #429, which
    moved every module it counted. The catalog is now
    config/information-layers.json: every packaged command sits in exactly one
    layer or on an exclusion list with the reason it is not information
    collection, and the tables in both READMEs are checked against it. The
    partition covers both distributions' command registries, so nothing counted
    can be typed by hand. Re-derived, the count is 39, and two layer names that no
    longer described their members were corrected. (#476)

Added

  • SECURITY.md naming GitHub private vulnerability reporting — now enabled on
    the repository, so the channel it points at exists — a
    CONTRIBUTING.md stating which parts of the repository can accept a patch
    (the package can; the live book cannot), and a bug-report issue template.
    Installable packages need a disclosure channel; a repository someone only
    reads does not. (#477)
  • The runtime-coupling ratchet now also enumerates shell entry points naming the
    live host, against a per-file allowlist with a reason each. Its Python count
    stays 0, and the claim now states what it covers. (#478)