Skip to main content

Secure development

This guide covers the practices contributors follow while writing code. For reporting a vulnerability, the trust model and operator hardening, see the Security section of the docs site.

Secrets and placeholders

  • Never commit real phone numbers, API tokens, videos, or live config values. Use obviously fake placeholders.
  • Docs content must be generic. Do not include personal device names, hostnames, or paths. Use placeholders such as user@gateway-host.
  • Read the security policy before any security triage or advisory work.

Local credential files

  • Web provider credentials live in ~/.openclaw/credentials/. Rerun wednesdayai login if you are logged out.
  • Pi and agent sessions live in ~/.openclaw/agents/<agentId>/sessions/*.jsonl (newest by default).
Never copy these into the repository, a fixture, or a log entry.

Security scanning

The project uses detect-secrets for automated secret detection in CI. See .detect-secrets.cfg for configuration and .secrets.baseline for the baseline. Run it locally:

Dependency policy

  • Dependencies listed in pnpm.patchedDependencies must use exact versions (no ^ or ~). Patching a dependency requires explicit approval.
  • @sinclair/typebox is pinned to an exact version for the same reason.
  • Never update the Carbon dependency (@buape/carbon).
  • Never use npm link or pnpm link for local installs. Build with npm pack and install the tarball globally.