Skip to content

chore(deps): bump @tencent-weixin/openclaw-weixin from 2.4.6 to 2.4.8 in /plugins/openclaw-weixin - #296

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/plugins/openclaw-weixin/tencent-weixin/openclaw-weixin-2.4.8
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/plugins/openclaw-weixin/tencent-weixin/openclaw-weixin-2.4.8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 4, 2026

Copy link
Copy Markdown
Contributor

Bumps @tencent-weixin/openclaw-weixin from 2.4.6 to 2.4.8.

Maintainer changes

This version was pushed to npm by zengyi1001, a new releaser for @​tencent-weixin/openclaw-weixin since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps @tencent-weixin/openclaw-weixin from 2.4.6 to 2.4.8.

---
updated-dependencies:
- dependency-name: "@tencent-weixin/openclaw-weixin"
  dependency-version: 2.4.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 4, 2026
@clawsweeper

clawsweeper Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​@​tencent-weixin/​openclaw-weixin@​2.4.6 ⏵ 2.4.893 +1710010096 -1100

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Publisher changed: npm @tencent-weixin/openclaw-weixin is now published by zengyi1001

Author: zengyi1001

From: plugins/openclaw-weixin/package-lock.jsonnpm/@tencent-weixin/openclaw-weixin@2.4.8

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@tencent-weixin/openclaw-weixin@2.4.8. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@clawsweeper clawsweeper Bot added P1 Urgent regression or broken agent/channel workflow affecting real users now. merge-risk: 🚨 automation 🚨 Merging this PR could break CI, automerge, proof capture, label sync, or automation. merge-risk: 🚨 security-boundary 🚨 Merging this PR could weaken sandboxing, authorization, credentials, or sensitive data. rating: 🧂 unranked krab Not merge-ready due to missing proof or serious correctness/safety concerns. status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action. labels Sep 4, 2026
@clawsweeper

clawsweeper Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

Codex review: blocked before merge. Reviewed September 4, 2026, 5:42 AM ET / 09:42 UTC.

ClawSweeper review

What this changes

Updates the npm-pinned OpenClaw Weixin fixture from @tencent-weixin/openclaw-weixin 2.4.6 to 2.4.8 and refreshes its lockfile.

Merge readiness

Blocked before merge - 10 items remain

Keep open: the intended patch upgrade is accompanied by an unexplained 364-package lock expansion, leaves the checked-in inspector report on 2.4.6, and needs maintainer acceptance of the changed npm publisher.

Priority: P1
Reviewed head: faf504ac9b73abba2630b7f094e701bc3d649c87
Owner decision: Required. See Decision needed.

Review scores

Measure Result What it means
Overall readiness 🧂 unranked krab (1/6) PR readiness rating was derived from proof quality, review findings, security review, and reviewer confidence.
Proof confidence 🌊 off-meta tidepool Not applicable: Real behavior proof is not required for maintainer- or bot-authored pull requests.
Patch quality 🧂 unranked krab (1/6) Security review found an item that needs attention.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: Real behavior proof is not required for maintainer- or bot-authored pull requests.
Evidence reviewed 6 items Introduced dependency update: The PR changes the fixture's direct package pin to 2.4.8 and adds 4,943 lockfile lines across its two introduced files.
Unrelated peer graph expansion: The old lock had 4 package entries and the new lock has 365. Both locked plugin versions declare the same direct dependencies and openclaw >=2026.5.12 peer range, but the proposed lock newly resolves openclaw 2026.8.1 and its large dependency graph, including install-script packages.
Generated evidence remains stale: The committed report still identifies the inspected Weixin package and plugin manifest as 2.4.6, while the introduced diff changes only the manifest and lockfile. It would therefore misdescribe the pinned fixture after merge.
Findings 2 actionable findings [P1] Avoid resolving a full OpenClaw graph in this fixture lock
[P2] Refresh the generated fixture evidence for 2.4.8
Security Needs attention Review the changed npm publisher: Socket's PR alert identifies a new publisher for the exact 2.4.8 package being pinned. This is not evidence of malicious code, but it requires an explicit provenance and contents review before accepting the release.
Avoid unrelated install-script dependencies: The lock newly resolves OpenClaw and 364 packages, including packages marked with install scripts. Those packages become part of this fixture's committed install surface despite not being named by the fixture manifest.

How this fits together

Crabpot uses npm fixture shims to inspect third-party OpenClaw plugins. The fixture manifest and lockfile feed package materialization, generated compatibility reports, and the fixture-lock security check.

flowchart LR
  A[Fixture manifest] --> B[NPM fixture shim]
  B --> C[Committed package lock]
  C --> D[Package materialization]
  D --> E[Inspector compatibility report]
  C --> F[Fixture lock security check]
Loading

Decision needed

Question Recommendation
Should Crabpot accept the 2.4.8 release from the newly reported npm publisher after reviewing its contents and the expanded lock graph? Verify and accept the release: Review the publisher transition and package contents, then require an intentional lock and refreshed fixture evidence before merge.

Why: The repository can mechanically refresh fixture artifacts, but accepting a new package publisher and the newly introduced install-time dependency surface is a supply-chain trust decision.

Before merge

  • Avoid resolving a full OpenClaw graph in this fixture lock (P1) - The plugin's direct dependencies and OpenClaw peer range are unchanged from the previous lock, but this update newly locks openclaw and 364 packages, including install-script packages. That moves an unrelated release graph into fixture installation and security scanning; regenerate a minimal lock or deliberately review and justify this graph before merging.
  • Refresh the generated fixture evidence for 2.4.8 (P2) - The introduced delta changes only the shim manifest and lock, while reports/crabpot-report.json still records the Weixin package and manifest as 2.4.6. This leaves Crabpot's checked-in inspection result inconsistent with its pin and conflicts with the repository fixture policy; refresh the package source/report and any affected expectations.
  • Resolve security concern: Review the changed npm publisher - Socket's PR alert identifies a new publisher for the exact 2.4.8 package being pinned. This is not evidence of malicious code, but it requires an explicit provenance and contents review before accepting the release.
  • Resolve security concern: Avoid unrelated install-script dependencies - The lock newly resolves OpenClaw and 364 packages, including packages marked with install scripts. Those packages become part of this fixture's committed install surface despite not being named by the fixture manifest.
  • Resolve merge risk (P1) - The lock now admits a full OpenClaw dependency graph and four install-script packages into a fixture that previously resolved four packages, expanding the install and audit attack surface beyond the stated plugin patch update.
  • Resolve merge risk (P1) - The upstream release has a newly reported npm publisher, and no maintainer acceptance or package-mode evidence establishes that this release is trusted and compatible.
  • Complete next step (P2) - Before merge, review the publisher transition, regenerate and review the lock and fixture report for 2.4.8, and provide a redacted package-mode smoke result.
  • Improve patch quality - Resolve the security review concern or explain why the changed path is safe.
  • Improve patch quality - Address the highest-priority review finding and re-run the changed-surface validation.
  • Resolve maintainer decision - Resolve the maintainer decision shown above before merge.

Findings

  • [P1] Avoid resolving a full OpenClaw graph in this fixture lock — plugins/openclaw-weixin/package-lock.json:3499-3500
  • [P2] Refresh the generated fixture evidence for 2.4.8 — plugins/openclaw-weixin/package.json:7
  • [high] Review the changed npm publisher — plugins/openclaw-weixin/package-lock.json:893
  • [medium] Avoid unrelated install-script dependencies — plugins/openclaw-weixin/package-lock.json:3499
Agent review details

Security

Needs attention: The patch introduces an unreviewed publisher transition and a much larger installable dependency graph into a security-scanned fixture lock.

Review metrics

Metric Value Why it matters
Resolved package graph 364 packages added; 4 install-script packages The lockfile expansion is far larger than the one-package version update stated by the PR.
Generated fixture evidence 2 files changed; 0 report/test files changed The committed report still describes version 2.4.6.

Merge-risk options

Maintainer options:

  1. Regenerate and verify the fixture update (recommended)
    Refresh the source/report expectations, reduce or explicitly approve the added lock graph, and attach a redacted package-mode smoke result before merging.
  2. Pause for publisher verification
    Do not merge the dependency bump until an owner has reviewed and accepted the new npm publisher and its release provenance.

Technical review

Best possible solution:

Land a reviewed, intentional fixture update that refreshes the package source/report evidence, limits or explicitly validates the lock graph, and records successful package-mode inspection after maintainer approval of the publisher change.

Do we have a high-confidence way to reproduce the issue?

Yes—source inspection directly reproduces the inconsistency: the pin is 2.4.8 while the committed generated report remains at 2.4.6, and the lock expands from 4 to 365 package entries.

Is this the best way to solve the issue?

No—the direct pin bump is incomplete because it does not refresh the fixture evidence and introduces an unreviewed peer dependency graph; a constrained, reviewed refresh is safer.

Full review comments:

  • [P1] Avoid resolving a full OpenClaw graph in this fixture lock — plugins/openclaw-weixin/package-lock.json:3499-3500
    The plugin's direct dependencies and OpenClaw peer range are unchanged from the previous lock, but this update newly locks openclaw and 364 packages, including install-script packages. That moves an unrelated release graph into fixture installation and security scanning; regenerate a minimal lock or deliberately review and justify this graph before merging.
    Confidence: 0.96
  • [P2] Refresh the generated fixture evidence for 2.4.8 — plugins/openclaw-weixin/package.json:7
    The introduced delta changes only the shim manifest and lock, while reports/crabpot-report.json still records the Weixin package and manifest as 2.4.6. This leaves Crabpot's checked-in inspection result inconsistent with its pin and conflicts with the repository fixture policy; refresh the package source/report and any affected expectations.
    Confidence: 0.98

Overall correctness: patch is incorrect
Overall confidence: 0.96

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning high; reviewed against 9e031f875ad8.

Labels

Label changes:

  • add P1: This proposed merge materially expands a fixture's installed supply-chain graph while its publisher transition remains unapproved.
  • add merge-risk: 🚨 security-boundary: A newly reported npm publisher and newly locked install-script packages require explicit supply-chain review.
  • add merge-risk: 🚨 automation: The fixture-lock security workflow will audit a graph expanded from 4 to 365 locked packages.
  • add rating: 🧂 unranked krab: Overall readiness is 🧂 unranked krab; proof is 🌊 off-meta tidepool and patch quality is 🧂 unranked krab.
  • add status: ⏳ waiting on author: ClawSweeper has contributor-facing work open and is waiting for author action. Not applicable: Real behavior proof is not required for maintainer- or bot-authored pull requests.

Label justifications:

  • P1: This proposed merge materially expands a fixture's installed supply-chain graph while its publisher transition remains unapproved.
  • merge-risk: 🚨 security-boundary: A newly reported npm publisher and newly locked install-script packages require explicit supply-chain review.
  • merge-risk: 🚨 automation: The fixture-lock security workflow will audit a graph expanded from 4 to 365 locked packages.
  • rating: 🧂 unranked krab: Overall readiness is 🧂 unranked krab; proof is 🌊 off-meta tidepool and patch quality is 🧂 unranked krab.
  • status: ⏳ waiting on author: ClawSweeper has contributor-facing work open and is waiting for author action. Not applicable: Real behavior proof is not required for maintainer- or bot-authored pull requests.

Evidence

Security concerns:

  • [high] Review the changed npm publisher — plugins/openclaw-weixin/package-lock.json:893
    Socket's PR alert identifies a new publisher for the exact 2.4.8 package being pinned. This is not evidence of malicious code, but it requires an explicit provenance and contents review before accepting the release.
    Confidence: 0.92
  • [medium] Avoid unrelated install-script dependencies — plugins/openclaw-weixin/package-lock.json:3499
    The lock newly resolves OpenClaw and 364 packages, including packages marked with install scripts. Those packages become part of this fixture's committed install surface despite not being named by the fixture manifest.
    Confidence: 0.96

What I checked:

  • Introduced dependency update: The PR changes the fixture's direct package pin to 2.4.8 and adds 4,943 lockfile lines across its two introduced files. (plugins/openclaw-weixin/package.json:7, faf504ac9b73)
  • Unrelated peer graph expansion: The old lock had 4 package entries and the new lock has 365. Both locked plugin versions declare the same direct dependencies and openclaw >=2026.5.12 peer range, but the proposed lock newly resolves openclaw 2026.8.1 and its large dependency graph, including install-script packages. (plugins/openclaw-weixin/package-lock.json:3499, faf504ac9b73)
  • Generated evidence remains stale: The committed report still identifies the inspected Weixin package and plugin manifest as 2.4.6, while the introduced diff changes only the manifest and lockfile. It would therefore misdescribe the pinned fixture after merge. (reports/crabpot-report.json:30852, faf504ac9b73)
  • Fixture policy: Repository policy requires package-version changes to update the source reference and generated report/test expectations, and calls for source-mode and package-mode smoke checks after a publish. (AGENTS.md:9, faf504ac9b73)
  • Publisher provenance warning: The PR discussion's Socket report flags that version 2.4.8 was published by a new releaser, so accepting this package release is a maintainer-owned supply-chain decision.
  • Relevant fixture history: Recent fixture updates were made by Peter Steinberger, with earlier lock-security and fixture dependency work by Vincent Koc. (plugins/openclaw-weixin/package.json:7, e1cacde98732)

Likely related people:

  • Peter Steinberger: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • Vincent Koc: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

@dependabot @github

dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #318.

@dependabot dependabot Bot closed this Sep 21, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/plugins/openclaw-weixin/tencent-weixin/openclaw-weixin-2.4.8 branch September 21, 2026 09:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code merge-risk: 🚨 automation 🚨 Merging this PR could break CI, automerge, proof capture, label sync, or automation. merge-risk: 🚨 security-boundary 🚨 Merging this PR could weaken sandboxing, authorization, credentials, or sensitive data. P1 Urgent regression or broken agent/channel workflow affecting real users now. rating: 🧂 unranked krab Not merge-ready due to missing proof or serious correctness/safety concerns. status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants