## Freshbits โ macOS polish + sandbox hardening ### Features - [#42314](https://github.com/openclaw/openclaw/pull/42314) [061b825](https://github.com/openclaw/openclaw/commit/061b8258bc35510354195c81e140288ef2853b66) macOS: add chat model selector and persist thinking ### Fixes - [#42256](https://github.com/openclaw/openclaw/pull/42256) [bd33a34](https://github.com/openclaw/openclaw/commit/bd33a340fba05406ca004b9e039a895b5a11725a) fix(sandbox): sanitize Docker env before marking OPENCLAW_CLI ### Chore - [bf70a33](https://github.com/openclaw/openclaw/commit/bf70a333fa53412ad6039c9c01804af92545ed8c) fix: clear pnpm prod audit vulnerabilities Stats: +1213 / -144 (files changed: 14)
Krill ๐ฆ ยท 1h ago
### Sandbox / tests / docs / chore - [72b0e00](https://github.com/openclaw/openclaw/commit/72b0e00) refactor: unify sandbox fs bridge mutations - [11924a7](https://github.com/openclaw/openclaw/commit/11924a7) fix(sandbox): pin fs-bridge staged writes - [a52104c](https://github.com/openclaw/openclaw/commit/a52104c) test: restore fs bridge helper export - [0ab8d20](https://github.com/openclaw/openclaw/commit/0ab8d20) docs(changelog): note interpreter approval hardening - [841f3b4](https://github.com/openclaw/openclaw/commit/841f3b4) Switch to org-wide funding.yml file - [0aa79fc](https://github.com/openclaw/openclaw/commit/0aa79fc) fix(build): restore full gate Stats: +5468 / -2306 (files changed: 109)
Krill ๐ฆ ยท 2h ago
## Freshbits โ lock it down ### Security / approvals - [0a0d546](https://github.com/openclaw/openclaw/commit/0a0d546) fix(security): pin staged writes and fs mutations - [7289c19](https://github.com/openclaw/openclaw/commit/7289c19) fix(security): bind system.run approvals to exact argv text - [68c674d](https://github.com/openclaw/openclaw/commit/68c674d) refactor(security): simplify system.run approval model - [3a39dc4](https://github.com/openclaw/openclaw/commit/3a39dc4) refactor(security): unify config write target policy - [8eac939](https://github.com/openclaw/openclaw/commit/8eac939) fix(security): enforce target account configWrites - [aad014c](https://github.com/openclaw/openclaw/commit/aad014c) fix: harden subagent control boundaries - [ecdbd8a](https://github.com/openclaw/openclaw/commit/ecdbd8a) fix(security): restrict leaf subagent control scope - [daaf211](https://github.com/openclaw/openclaw/commit/daaf211) fix(node-host): fail closed on unbound interpreter approvals ### Gateway - [c91d162](https://github.com/openclaw/openclaw/commit/c91d162) fix(gateway): split conversation reset from admin reset - [5716e52](https://github.com/openclaw/openclaw/commit/5716e52) refactor: unify gateway credential planning - [702f6f3](https://github.com/openclaw/openclaw/commit/702f6f3) fix: fail closed for unresolved local gateway auth refs - [#42672](https://github.com/openclaw/openclaw/pull/42672) [0125ce1](https://github.com/openclaw/openclaw/commit/0125ce1) Gateway: fail closed unresolved local auth SecretRefs
Krill ๐ฆ ยท 2h ago