Skip to content

Bump openclaw/clawhub/.github/workflows/package-publish.yml from 0.12.0 to 0.22.0#2

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/openclaw/clawhub/dot-github/workflows/package-publish.yml-0.22.0
Open

Bump openclaw/clawhub/.github/workflows/package-publish.yml from 0.12.0 to 0.22.0#2
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/openclaw/clawhub/dot-github/workflows/package-publish.yml-0.22.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 17, 2026

Copy link
Copy Markdown

Bumps openclaw/clawhub/.github/workflows/package-publish.yml from 0.12.0 to 0.22.0.

Release notes

Sourced from openclaw/clawhub/.github/workflows/package-publish.yml's releases.

clawhub 0.22.0

0.22.0 - 2026-06-15

Changes

  • CLI: remove the clawhub sync command. clawhub skill publish <path> now skips unchanged content, defaults new skills to 1.0.0, defaults changed skills to the next patch version, and supports dry-run/JSON output.
  • GitHub Actions: preserve catalog publishing through the reusable skill-publish.yml workflow, which invokes ordinary skill publish once per skill folder.

Release Proof

clawhub 0.21.0

0.21.0 - 2026-06-11

Changes

  • CLI/API: add public clawhub package trusted-publisher set and clawhub package trusted-publisher delete commands so package managers can configure or remove GitHub Actions OIDC trusted publishing for existing packages.

Release Proof

clawhub 0.20.2

0.20.2 - 2026-06-11

Changes

  • CLI packages now require Node.js 22 or newer, dropping the EOL Node 20 runtime floor.
  • CLI: add clawhub package validate <source> for local plugin validation with author-facing Plugin Inspector findings, remediation text, and report artifacts.

Release Proof

clawhub 0.20.0

0.20.0 - 2026-06-06

... (truncated)

Changelog

Sourced from openclaw/clawhub/.github/workflows/package-publish.yml's changelog.

0.22.0 - 2026-06-15

Changes

  • CLI: remove the clawhub sync command. clawhub skill publish <path> now skips unchanged content, defaults new skills to 1.0.0, defaults changed skills to the next patch version, and supports dry-run/JSON output.
  • GitHub Actions: preserve catalog publishing through the reusable skill-publish.yml workflow, which invokes ordinary skill publish once per skill folder.

0.21.0 - 2026-06-11

Changes

  • CLI/API: add public clawhub package trusted-publisher set and clawhub package trusted-publisher delete commands so package managers can configure or remove GitHub Actions OIDC trusted publishing for existing packages.

0.20.2 - 2026-06-11

Changes

  • CLI packages now require Node.js 22 or newer, dropping the EOL Node 20 runtime floor.
  • CLI: add clawhub package validate <source> for local plugin validation with author-facing Plugin Inspector findings, remediation text, and report artifacts.

0.20.0 - 2026-06-06

Changes

  • CLI/API: replace local clawhub scan uploads with stored submitted-version scan report downloads, including owner-authorized clawhub scan download <name> --version <version> support for blocked skill and plugin submissions.

0.19.2 - 2026-06-05

Fixes

  • CLI: accept the legacy clawhub skill verify --json flag as a hidden compatibility no-op while continuing to print JSON by default.

0.19.1 - 2026-06-05

Fixes

  • CLI: install source-backed GitHub skills from the deployed /api/v1/skills/:slug/install resolver so clawhub install works for skills without hosted ClawHub versions.

0.19.0 - 2026-06-03

Changes

  • CLI/API: add authenticated clawhub scan submit/poll support for ephemeral local skill bundles and owner-authorized published skill scans, including JSON output and report ZIP downloads (#2479).

Fixes

  • Auth/Ops: keep GitHub account-age lookups on immutable numeric IDs, retry without auth when a configured GitHub token is rejected, and add an operator backfill for missing cached account ages.
  • API/CLI: report Skill Card verification with flattened skill/version metadata, ClawScan verdict fields at security.*, and supporting scanner evidence under security.signals.

0.18.0 - 2026-05-25

... (truncated)

Commits
  • e3e5705 feat(cli)!: remove sync command (#2669)
  • 69dd3b5 Polish content rights email workflow (#2670)
  • 44f4ab0 fix: set GitHub scan upload content type
  • 4efbf01 fix: floor skill stat drain batch size
  • f366269 feat: add owner version deletion
  • 1622a74 fix: recover forced GitHub scan requests
  • 455f4ea fix: serialize skill stat event drain
  • 5256b9e fix(agents): sync autoreview scope guard
  • 76638de feat: run full ClawScan for GitHub skills
  • 89bb8fe feat: add content rights case tooling (#2657)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [openclaw/clawhub/.github/workflows/package-publish.yml](https://github.com/openclaw/clawhub) from 0.12.0 to 0.22.0.
- [Release notes](https://github.com/openclaw/clawhub/releases)
- [Changelog](https://github.com/openclaw/clawhub/blob/main/CHANGELOG.md)
- [Commits](openclaw/clawhub@v0.12.0...v0.22.0)

---
updated-dependencies:
- dependency-name: openclaw/clawhub/.github/workflows/package-publish.yml
  dependency-version: 0.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jun 17, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies, github-actions. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants