mirror of
https://github.com/openclaw/openclaw.git
synced 2026-08-12 21:53:00 -06:00
84c7d45f15
* refactor(qqbot): remove bundled extension source Mechanical deletion half of the #107295 squashed rebase; the catalog repoint and host integration land in the follow-up commit. Co-authored-by: sliverp <870080352@qq.com> * refactor(qqbot): install plugin from Tencent package Squashed rebase of #107295 onto current main. Repoints the official external channel catalog at @tencent-connect/openclaw-qqbot@2.0.1 and adapts onboarding, doctor migrations, secrets, build guards, and tests. Documents the known limitation that the external package does not support structured SecretRef clientSecret values; operators move those to QQBOT_CLIENT_SECRET or clientSecretFile before upgrading. Co-authored-by: sliverp <870080352@qq.com> * fix(doctor): reuse shared hasOwnKey record helper The rebased QQBot migration carried its own hasOwnKey export, colliding with the one main now ships in legacy-config-record-shared.ts. Co-authored-by: sliverp <870080352@qq.com> * fix(plugins): carry catalog integrity through the update bridge The externalized-bundled-plugin bridge dropped the official catalog's expectedIntegrity pin, so bundled-user updates installed the external npm package without integrity verification. The bridge now carries the pin for the catalog's exact npm spec and both bridge install calls pass it through; update-channel spec overrides intentionally skip the pin since it only covers the pinned version. Co-authored-by: sliverp <870080352@qq.com> * chore(plugin-sdk): refresh per-entrypoint API baselines The QQBot compat export and bundled-type removal shift 26 entrypoint closure hashes in the new split baseline layout. Co-authored-by: sliverp <870080352@qq.com> * refactor(qqbot): drop helper reintroduced during rebase Main's coercion consolidation added this file after the deletion commit's base; its only consumers were the removed qqbot sources. Co-authored-by: sliverp <870080352@qq.com> --------- Co-authored-by: Peter Steinberger <steipete@gmail.com>
55 lines
1.1 KiB
YAML
55 lines
1.1 KiB
YAML
name: openclaw-codeql-channel-runtime-boundary-critical-quality
|
|
|
|
disable-default-queries: true
|
|
|
|
queries:
|
|
- uses: security-and-quality
|
|
|
|
query-filters:
|
|
- include:
|
|
problem.severity:
|
|
- error
|
|
- exclude:
|
|
tags:
|
|
- security
|
|
|
|
paths:
|
|
- extensions/discord/src
|
|
- extensions/feishu/src
|
|
- extensions/googlechat/src
|
|
- extensions/imessage/src
|
|
- extensions/irc/src
|
|
- extensions/line/src
|
|
- extensions/matrix/src
|
|
- extensions/mattermost/src
|
|
- extensions/msteams/src
|
|
- extensions/nextcloud-talk/src
|
|
- extensions/nostr/src
|
|
- extensions/qa-channel/src
|
|
- extensions/signal/src
|
|
- extensions/slack/src
|
|
- extensions/synology-chat/src
|
|
- extensions/telegram/src
|
|
- extensions/tlon/src
|
|
- extensions/twitch/src
|
|
- extensions/whatsapp/src
|
|
- extensions/zalo/src
|
|
- extensions/zalouser/src
|
|
- src/channels
|
|
|
|
paths-ignore:
|
|
- "**/node_modules"
|
|
- "**/coverage"
|
|
- "**/*.generated.ts"
|
|
- "**/*.bundle.js"
|
|
- "**/*-runtime.js"
|
|
- "**/*.test.ts"
|
|
- "**/*.test.tsx"
|
|
- "**/*.e2e.test.ts"
|
|
- "**/*.e2e.test.tsx"
|
|
- "**/*test-support*"
|
|
- "**/*test-helper*"
|
|
- "**/*mock*"
|
|
- "**/*fixture*"
|
|
- "**/*bench*"
|