Verified change intelligence for developers and founders who run agents. We track consequential releases, pricing, limits, reliability, security, and compatibility—then explain what changed, what could break, and what to do next.
Registry stats loading…
We separate release-note language from the behavior, policy, price, limit, or compatibility change that matters in practice.
We look for pricing changes, migration risk, reliability regressions, security exposure, and hidden operational limits before recommending an update.
Each report ends with a practical verdict: update, wait, test first, pin a version, change configuration, or ignore the announcement.
OpenClaw v2026.7.33 (2026-09-18 05:33 UTC) is the July 2026 Extended Stable release, moving only the extended-stable* aliases. 126 merged PRs in one tag across five buckets: security and credential safety (PR #114134 escaped-newline shell words; PR #102398 Git option-argument injection via plugin git: specs; PR #101739 inherited exec response ids; PR #38290 browser origin allowlist; PR #102426 diagnostic config redaction; PR #102403 backup archives written owner-only 0o600; PR #102089 Twilio turnToken redaction); message and session integrity (PR #113700 retry-delay accuracy; PR #113703 distinct imported CLI session messages; PR #113697 plugin-blocked tool-call transcripts); Gateway reliability (PR #102125 plugin HTTP responses finished after post-header failures; PR #102013 bounded sessions.usage discovery concurrency; PR #102451 / #104811 shutdown work settled before completion); channel delivery (Discord silent message loss #103562; UTF-16 truncation fixes across Discord / Matrix / Telegram / Slack / WhatsApp / LINE / Feishu / Zalo / Mattermost / Google Meet / ACP); provider and media robustness (PR #104734 synthetic auth credential redaction in models status --json). Documentation comparison; no firsthand test.
We do not rewrite launch posts. We connect primary sources, reproducible tests, scanner evidence, Registry records, and technical guides to the decision in front of you.
Pricing, policy, security, compatibility, and incident claims start with official documentation, repositories, advisories, or status pages. Community reports are labeled as experience, not proof.
Field reports name the version, environment, method, inputs, and limitations. If we only compared documentation, we say so.
The skills and MCP Registry remains free. Its source links, scan states, provenance, and explicit evidence gaps help test whether an ecosystem claim survives contact with real artifacts.
Durable technical guides and inspectable workflow manifests turn a news event into implementation work you can adapt and validate in your own environment.
A guide to dependency review, supply-chain risk triage, and remediation workflows.
A practical walkthrough of Model Context Protocol server structure, authentication, and tool registration.
A technical guide to turning SEO findings into concrete implementation work.
Codex, Claude Code, Gemini CLI, Cursor, OpenClaw, Hermes, MCP, models, memory, orchestration, and agent infrastructure—prioritized by cost, limits, reliability, security, compatibility, and practical capability.
Weekday impact reports, a weekly Before You Update brief, and tested comparisons when the evidence supports them. No quota filler.
The intelligence index is the canonical feed. Existing articles and payload URLs remain available while new coverage follows the evidence-first format.
Open the intelligence index