Skip to content

chore(deps): bump openclaw/clawhub/.github/workflows/package-publish.yml from 0.12.0 to 0.20.0#2561

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/openclaw/clawhub/dot-github/workflows/package-publish.yml-0.20.0
Open

chore(deps): bump openclaw/clawhub/.github/workflows/package-publish.yml from 0.12.0 to 0.20.0#2561
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/openclaw/clawhub/dot-github/workflows/package-publish.yml-0.20.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 11, 2026

Copy link
Copy Markdown
Contributor

Bumps openclaw/clawhub/.github/workflows/package-publish.yml from 0.12.0 to 0.20.0.

Release notes

Sourced from openclaw/clawhub/.github/workflows/package-publish.yml's releases.

clawhub 0.20.0

0.20.0 - 2026-06-06

Changes

  • CLI/API: replace local clawhub scan uploads with stored submitted-version scan report downloads, including owner-authorized clawhub scan download <name> --version <version> support for blocked skill and plugin submissions.

Release Proof

clawhub 0.19.2

0.19.2 - 2026-06-05

Fixes

  • CLI: accept the legacy clawhub skill verify --json flag as a hidden compatibility no-op while continuing to print JSON by default.

Release Proof

clawhub 0.19.1

0.19.1 - 2026-06-05

Fixes

  • CLI: install source-backed GitHub skills from the deployed /api/v1/skills/:slug/install resolver so clawhub install works for skills without hosted ClawHub versions.

Release Proof

clawhub 0.19.0

0.19.0 - 2026-06-03

Changes

... (truncated)

Changelog

Sourced from openclaw/clawhub/.github/workflows/package-publish.yml's changelog.

0.20.0 - 2026-06-06

Changes

  • CLI/API: replace local clawhub scan uploads with stored submitted-version scan report downloads, including owner-authorized clawhub scan download <name> --version <version> support for blocked skill and plugin submissions.

0.19.2 - 2026-06-05

Fixes

  • CLI: accept the legacy clawhub skill verify --json flag as a hidden compatibility no-op while continuing to print JSON by default.

0.19.1 - 2026-06-05

Fixes

  • CLI: install source-backed GitHub skills from the deployed /api/v1/skills/:slug/install resolver so clawhub install works for skills without hosted ClawHub versions.

0.19.0 - 2026-06-03

Changes

  • CLI/API: add authenticated clawhub scan submit/poll support for ephemeral local skill bundles and owner-authorized published skill scans, including JSON output and report ZIP downloads (#2479).

Fixes

  • Auth/Ops: keep GitHub account-age lookups on immutable numeric IDs, retry without auth when a configured GitHub token is rejected, and add an operator backfill for missing cached account ages.
  • API/CLI: report Skill Card verification with flattened skill/version metadata, ClawScan verdict fields at security.*, and supporting scanner evidence under security.signals.

0.18.0 - 2026-05-25

Changes

  • CLI/API: add Skill Card verification surfaces, including clawhub skill verify <slug> JSON output and --card Markdown retrieval (#2382).
  • Web/API: surface an "API key required" attribute on skills so listings, cards, and detail views show whether a skill needs an LLM API key, with publish-time inference from skill prompts and metadata (#2353) (thanks @​momothemage).

Fixes

  • API: fix GET /api/v1/skills pagination so cursor advances to the next page instead of repeating the first page for supported non-trending sorts (#2275) (thanks @​vyctorbrzezowski, @​enerj).
  • Web: block collaborative membership on personal publishers while allowing the linked owner to clean up stale extra membership rows (thanks @​vyctorbrzezowski).
  • Security/API: hide owned package/plugin catalog entries, revoke package publish tokens, and restore only matching ban-hidden packages on user unban (thanks @​vyctorbrzezowski).
  • API: block public raw skill files when moderation already blocks downloads and reject skill tags that point at another skill's version (thanks @​vyctorbrzezowski).
  • Web: stop stale unban restore batches from reactivating skills after the owner is banned again or deactivated (thanks @​vyctorbrzezowski).
  • Security/API: reject direct skill owner transfers when the skill is hidden, suspicious, or malicious (thanks @​vyctorbrzezowski).
  • Security/API: revalidate package publish actor, owner, and owner publisher active state in the final release insert (thanks @​vyctorbrzezowski).

0.17.0 - 2026-05-19

  • CLI/API: add self-serve org publisher creation with clawhub publisher create <handle> and scoped package publish errors that point to the command.

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [openclaw/clawhub/.github/workflows/package-publish.yml](https://github.com/openclaw/clawhub) from 0.12.0 to 0.20.0.
- [Release notes](https://github.com/openclaw/clawhub/releases)
- [Changelog](https://github.com/openclaw/clawhub/blob/main/CHANGELOG.md)
- [Commits](openclaw/clawhub@v0.12.0...v0.20.0)

---
updated-dependencies:
- dependency-name: openclaw/clawhub/.github/workflows/package-publish.yml
  dependency-version: 0.20.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jun 11, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jun 11, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: github-actions. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

Status: Backlog

Development

Successfully merging this pull request may close these issues.

0 participants