Skip to content

Jan 30 upstream update#4

Merged
centminmod merged 8 commits intocentminmod:mainfrom
openclaw:main
Jan 29, 2026
Merged

Jan 30 upstream update#4
centminmod merged 8 commits intocentminmod:mainfrom
openclaw:main

Conversation

@centminmod
Copy link
Owner

Jan 30 upstream update

@centminmod centminmod merged commit dfd811a into centminmod:main Jan 29, 2026
centminmod added a commit that referenced this pull request Feb 9, 2026
centminmod pushed a commit that referenced this pull request Feb 13, 2026
…13184)

* fix(security): default standalone servers to loopback bind (#4)

Change canvas host and telegram webhook default bind from 0.0.0.0
(all interfaces) to 127.0.0.1 (loopback only) to prevent unintended
network exposure when no explicit host is configured.

* fix: restore telegram webhook host override while keeping loopback defaults (openclaw#13184) thanks @davidrudduck

* style: format telegram docs after rebase (openclaw#13184) thanks @davidrudduck

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
centminmod added a commit that referenced this pull request Feb 22, 2026
- Add sync-7 entry: 4 security commits (model allowlist, QMD mcporter, sandbox tmpdir/symlink)
- Update 26 stale refs across 20 doc files (device-pairing +72-85 lines, zod-schema +9-11 lines, qmd-manager +279 lines, timer.ts armTimer refactor, gateway-lock.ts, embeddings.ts, sandbox-paths.ts, operator-scope-compat.ts)
- Update post-merge-hardening.md TOC + Gap #4 qmd-manager ref
- Audit 2 Claim 5 (RBAC), Claim 1 (setupCommand mcporter), Claim 3 (outPath/sandbox) strengthened
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants