From 6276bc67296e2fe9224836225c08ce21061a3c9c Mon Sep 17 00:00:00 2001 From: "dylan.wang" Date: Fri, 25 Sep 2026 23:36:00 +0800 Subject: [PATCH] docs: record ClawHub's Pass for v1.0.2 ClawHub's audit of v1.0.2 reads clean, shown as Pass. v1.0.0 and v1.0.1 read Review for the download override that v1.0.2 removed (ADR-027). Step 4 says so and calls the audit page the latest version's. Step 3 adds how the hidden v1.0.2 upload looked in inspect ("Version not found", latest still 1.0.1) and that it was public within seven minutes, replacing the note that publication time was not verified. Co-Authored-By: Claude Opus 5.5 --- docs/publishing.md | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/docs/publishing.md b/docs/publishing.md index d03655d..9da78ef 100644 --- a/docs/publishing.md +++ b/docs/publishing.md @@ -283,9 +283,10 @@ To publish: For a later release, change the tag (in `git checkout` and `--source-ref`), `--version` and `--changelog`. The upload stays hidden while ClawHub - reviews it (`clawhub inspect` shows `pending.publication`). v1.0.0's scan - came back clean within a minute; how long publication takes after that was - not verified. + reviews it: for v1.0.0, `clawhub inspect` gave the moderation reason as + `pending.publication`; for v1.0.2, `inspect --version 1.0.2` answered + "Version not found" and `latest` stayed at 1.0.1. v1.0.2 was audited and + public within seven minutes of the upload. 4. Check the listing, then the version's security audit. They are separate verdicts: moderation decides whether the listing is public, and it can be @@ -301,8 +302,9 @@ To publish: ``` The audit is `version.security`. v1.0.0 and v1.0.1 read `suspicious`, - shown as Review, for the download override that ADR-027 removed. The - findings are on + shown as Review, for the download override that ADR-027 removed; v1.0.2 + reads `clean`, shown as Pass. The latest version's audit, with any + findings, is on . ```bash