Skip to content

chore(deps): bump the npm-minor-patch group across 1 directory with 3 updates - #27

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/npm-minor-patch-0b949b1b33
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/npm-minor-patch-0b949b1b33

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 18, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm-minor-patch group with 3 updates in the / directory: yaml, @types/node and openclaw.

Updates yaml from 2.9.0 to 2.9.1

Release notes

Sourced from yaml's releases.

v2.9.1

  • Limit recursive merge aliases (#685, #713)
  • Simplify line unfolding during quoted string parsing (#714)
Commits

Updates @types/node from 22.20.1 to 22.20.3

Commits

Updates openclaw from 2026.7.1-2 to 2026.9.4

Release notes

Sourced from openclaw's releases.

openclaw 2026.9.4

OpenClaw v2026.9.4

20 direct commits · 1,558 pull requests · 294 contributors

Changes included in this release

The release notes and changelog contain the same content, presented in two formats:

  • Release notes — formatted for people, with expandable sections.
  • Changelog — plain Markdown for AI agents and tools.

Thanks

@​0xcyda @​100yenadmin @​1vision365-petertijsma @​609nft @​84dnnvbdvp-debug @​aaajiao @​aatreya @​abacha @​adinballew @​aeoess @​aevgeniou @​ai-hpc @​aim9sour @​akagifreeez @​aleps001 @​alexjpanagis @​alexph-dev @​alix-007 @​aminekhettat @​andrea-kingautomation @​anguslogan01 @​aniruddhaadak80 @​ansxor @​anyech @​arcabotai @​artemeey @​ashawwal @​aspalagin @​avcarp @​avp717 @​ayaangazali @​azuretek @​barbarhan @​baumus @​benjaml4 @​bottanicals @​brainatworkharris @​bricelb @​bsniznd @​c0ncatenate @​cai-ops @​ccaprani @​ceckert @​chegherian @​chelsealong @​chl-0537 @​chriscantwell @​chrislro @​cjn119-ui @​ck-xyz @​cobblestone-digital1 @​colton-harris @​conan-scott @​cp1369 @​crash2kx @​dasx @​dbarbatti @​developercrocodiles @​devin-linux @​dh-js @​dilapidateddolphin98 @​dillona @​dimonnld @​donniefi @​dreamer-hit @​drobison00 @​dw1161 @​ejc3 @​ekinnee @​elbourne12345 @​eleqtrizit @​elikampf @​elvisio7 @​enominera @​ericcaiwx-star @​fabiolr @​fahrenhe1t @​fanyangcs @​fanyuantaier @​fede-kamel @​finn763 @​flagshipclaw @​fulgerulnegru @​fuller-stack-dev @​galiniliev @​gdxbsv @​geekforlife @​githoubi @​glenn-agent @​glucksberg @​goutamadwant @​gozu @​grynn @​guarismo @​guojiongming @​gwiltschek @​hannesrudolph @​happyfaptain @​harjothkhara @​harshitgupta31415 @​hawk5150 @​hayden-cc @​he-yufeng @​hekzory @​hermanzeng @​hugenshen @​husodrn46 @​hxy91819 @​igs-rogenlo @​ikenraf @​infocus13 @​islandpreneur007 @​itanyplus @​iwhatsskill @​jackatagenticforce @​jackten @​jai-assistant @​jailbirt @​jalehman @​jarvismazz @​jason-allen-oneal @​jerabinovich @​jesse-merhi @​jialele @​jinngimk-lang @​jjjhenriksen @​jkamgang @​jlacroix82 @​jlapenna @​jmissig @​jodok @​junfxiao @​kashivreddy @​kaspnov @​kesslerio @​kiagentkronos-cell @​kimiyu-186 @​kingakrej @​kingkong9817 @​kirde @​kopl-blip @​kvnloo @​laisonamarante @​laurencebrown @​laurenceputra @​leapdragon @​legupsystems @​lei-happy @​leilei3167 @​lendersmark @​leon-sk668 @​lightningwarellc @​linhongyu510 @​lisheguo @​liuwqgit @​lizhengwu @​lonexreb @​louisfy @​lraesly @​ly85206559 @​mag-linares-andalucia @​manumadrigal09 @​markthebest12 @​martins-oss @​marvinthebored @​masatohoshino @​masterswords1 @​matthewmoroz @​maxvidkrytaklishnya @​mgabor3141 @​miguelbranco80 @​mikronn2 @​moerai @​morrow-bluedot @​mrnozz @​najef1979-code @​narbs @​newsstand @​nianjiuzst @​nissl24 @​nkdmike @​nocodet888-arch @​noelillinger @​north-echo @​novaunboundai @​nullarbitrage @​obviyus @​oliverbot26 @​omarshahine @​ooiuuii @​orangejon @​ouioui33 @​oywino @​pash-openai @​patrick-erichsen @​pbergeot @​pcpilot-dev @​peetiegonzalez @​pengzh1 @​peterhodl @​peterkaynie @​pfrederiksen @​pgondhi987 @​pick-cat @​piotx @​pollybot13 @​postoso @​qingminglong @​razvangirgiz @​rboy1 @​rgregg @​richard355168 @​rico007 @​rileyjjy @​rjamoul @​rlosito @​romneyda @​rondavis007 @​rqlangley @​ruel225 @​ruicatalao7 @​russellweiss @​safzanpirani @​sallyom @​samrrr @​sappkevin @​schjonhaug @​schwanncells @​scotthuang @​sedrak-hovhannisyan @​sercada @​seven7763 @​shakkernerd @​shaozhengkun123 @​shojikumaru @​skaneta @​sloptop-the-terrible @​soroyue @​spectrl @​srikolagani @​steipete @​stephane-fci @​stevenlee-oai @​sunlit-deng @​sunnyandtec-ak @​sunnyiren-max @​sunnyshu0925 @​syfvb @​synthalorian @​szqub @​takhoffman @​teddytennant @​theangrypit @​thecrazylex @​thien-ngn @​thomasmoenco @​tilor @​timetrvlr @​todddickerson @​tomdailey55 @​toneloke @​toraiwa @​tskerpnext @​unknowbug @​vacinc @​vincentkoc @​von8794 @​vyctorbrzezowski @​wangmiao0668000666 @​wenbiyou @​wolikimcheng @​wpu911 @​xialonglee @​xiaoguomeiyitian @​xueqingli1 @​xuxyyy @​xx441 @​xydigitlybnnnn @​xydt-juyaohui @​xydt-tanshanshan @​yangxiansheng @​yanhe1169 @​yetval @​yigtwxx @​ylcn91 @​yncubys @​youens @​yxloveql @​zachisfine @​zenglingbiao @​zhangguiping-xydt @​zhuyankarl @​zwyhmcn @​zyw02

Release verification

  • Signed source: 3a9d69db306cd7f081e06254cb89c4bcc14a7107.
  • Full stable validation: passed, attempt 2. Qualification also verified 15 performance measurements and 20 real OpenAI completions across 10 upgrade baselines.
  • Core npm publication: passed; exact qualified bytes, registry signatures, provenance and fresh install verified.
  • 90 npm plugins and 3 core companion packages: published at latest, exact bytes verified.
  • Docker publication: passed; public GHCR and Docker Hub manifests and attestations match qualified artifacts.
  • Original publisher: failed during npm propagation readback. GitHub finalized through manual recovery; no package republish.
  • Telegram and Parallels checks: explicitly waived by the release owner, not passed.
  • macOS DMG, ZIP, and debug symbols are public and byte-verified against the signed/notarized artifacts; the stable update feed is live and verified.
  • Pending: ClawHub recovery, npm beta-selector synchronization, remaining native app distribution, and stable main closeout. Android native qualification failed. Windows historical-upgrade and Vercel mirror advisory failures remain recorded.
  • The repaired split-publication verifier passed live npm/Docker verification. Full beta-selector verification and the immutable main-closeout record remain pending. The attached postpublish evidence preserves the earlier recovery snapshot; these follow-ups are not marked complete.
  • Linux desktop AppImage and Debian package: published from v2026.9.4 source 3a9d69db306cd7f081e06254cb89c4bcc14a7107. Build, packaged runtime smoke, and signing passed; GitHub asset upload was recovered using the exact successful CI artifacts. Public downloads match the checksums, and the AppImage signature was independently verified. The Linux updater manifest is published, and the stable update endpoint was verified at 2026.9.4.

openclaw 2026.9.3

2026.9.3

Highlights

  • Safer updates: rehearse core and plugin changes in isolated candidate state before activation, support eligible 2026.9.2 migrations, and recover abandoned update records without stopping a healthy matching Gateway. Related #136997. (#138839, #141109, #141175, #141562)
  • Performance: preserve warm prompt caches, reduce unnecessary work during cold session updates and memory search, and reuse worker builds between sessions. Related #140681. (#140449, #140730, #140799, #140840, #141141) Thanks @​justinkirklin-gif, @​NianJiuZst, and @​obviyus.
  • Skill Workshop: keep skills in one persistent agent-owned collection across workspaces, compare complete skill instructions, and retire missing-draft suggestions safely through Doctor. Related #135291. (#135528, #139248, #140300, #141009) Thanks @​khaisis and @​obviyus.
  • Browser tabs, live and native: watch agent pages repaint and open external links in native Mac tabs that remain with their window across chat switches. (#140988, #141031)
  • Your provider accounts, together: manage connected accounts and supported account priority directly in Models settings. (#132451) Thanks @​jesse-merhi.
  • Share selected conversations: explicitly publish a revocable read-only view of a session’s existing and future conversation text, accessible to anyone with its public link. (#139489)
  • A searchable meeting library: browse saved notes, search full transcripts, download complete Markdown or JSONL archives, and manage capture sources from the Control UI. (#139875, #140084)
  • Optional team activity reports: install and enable Team Reports to browse authenticated GitHub activity and explicitly configured Discord discussion, with stored history and optional model summaries. (#139850, #141327)

Changes

  • Breaking — Node runtime: require Node 24.16.0 or newer on 24.x, or Node 26.1.0 or newer; Node 26 is recommended. Upgrade Node before OpenClaw to prevent SQLite text truncation: Node 22, Node 25, and earlier 24.x/26.x builds are no longer supported. Node-based CLI/Gateway installs on macOS 11–13.4 or official Linux ARMv7 provisioning need a supported host; see Node requirements. (#140672)
  • Breaking — execution-policy SDK: move the retired exec-mode and comparator helpers from infra-runtime to execPolicy on openclaw/plugin-sdk/agent-harness-runtime; use resolveExecModePolicy and select the returned fields needed by the caller. See runtime utility migration.

... (truncated)

Changelog

Sourced from openclaw's changelog.

Changelog

Release notes: https://docs.openclaw.ai/releases

Each release has its complete changelog below. Audited contribution records are retained separately when available.

... (truncated)

Commits
  • 3a9d69d docs(changelog): finalize 2026.9.4 release notes (#144440)
  • 0b7ddbd fix(release): repair update safety and CLI continuity (#144402)
  • 685ae1b docs(changelog): refresh 2026.9.4 release notes
  • 2a4d6a1 test(gateway): use the shared deferred fixture
  • f212072 fix(release): repair Doctor finalization and validation boundaries
  • dd178db docs(changelog): finalize 2026.9.4 release notes
  • 86ef455 chore(release): prepare 2026.9.4 stable metadata
  • 7af9cef refactor(compaction): project setup selections once (#144121)
  • 938b854 fix(zalouser): restore Doctor policy promotion (#143860)
  • a5868c1 test: consolidate Quick Chat canvas message inputs (#144135)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

… updates

Bumps the npm-minor-patch group with 3 updates in the / directory: [yaml](https://github.com/eemeli/yaml), [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) and [openclaw](https://github.com/openclaw/openclaw).


Updates `yaml` from 2.9.0 to 2.9.1
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v2.9.0...v2.9.1)

Updates `@types/node` from 22.20.1 to 22.20.3
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `openclaw` from 2026.7.1-2 to 2026.9.4
- [Release notes](https://github.com/openclaw/openclaw/releases)
- [Changelog](https://github.com/openclaw/openclaw/blob/main/CHANGELOG.md)
- [Commits](openclaw/openclaw@v2026.7.1-2...v2026.9.4)

---
updated-dependencies:
- dependency-name: yaml
  dependency-version: 2.9.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@types/node"
  dependency-version: 22.20.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: openclaw
  dependency-version: 2026.9.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 18, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) September 18, 2026 22:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants