Skip to content

fix: harden plugin trust defaults#266

Merged
hopeatina merged 2 commits intomainfrom
release/v0.7.30
Mar 28, 2026
Merged

fix: harden plugin trust defaults#266
hopeatina merged 2 commits intomainfrom
release/v0.7.30

Conversation

@hopeatina
Copy link
Copy Markdown
Contributor

Summary

  • make agent suite provisioning opt-in by default
  • make MCP client autoconfig opt-in by default
  • remove legacy dev credential fallback from the shipped plugin
  • add explicit security and transparency docs for local writes, credentials, network calls, telemetry, and watchdog behavior
  • remove stale dashboard labels for the removed legacy key source

Test plan

  • npm run typecheck
  • npm run build

Rollout notes

  • npm publish for 0.7.30 is ready but still requires an npm OTP at publish time
  • ClawHub publish from the packed artifact no longer hits the 20 MB upload limit, but the CLI is still hanging after Preparing; package metadata has not updated yet

@hopeatina hopeatina merged commit 1557a55 into main Mar 28, 2026
0 of 3 checks passed
@hopeatina hopeatina deleted the release/v0.7.30 branch March 28, 2026 20:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant