fix(security): refresh MCP runtime audit locks - #8180
Conversation
Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughThe MCP tool discovery runtime now pins reviewed dependency versions, documents the security refresh, and adds contract coverage for the fail-closed production audit. The managed image registry proxy test now validates a successful proxied response. ChangesMCP runtime security refresh
Managed image registry proxy test
Estimated code review effort: 3 (Moderate) | ~20 minutes Sequence Diagram(s)sequenceDiagram
participant ContractTest
participant RuntimeArtifacts
participant Installer
participant npm
ContractTest->>RuntimeArtifacts: Load manifest, lockfile, and security review
ContractTest->>RuntimeArtifacts: Validate pinned dependency metadata
ContractTest->>Installer: Verify production audit command
Installer->>npm: Run low-severity production audit
npm-->>ContractTest: Return audit result
Possibly related PRs
Suggested labels: Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall coverage in commit 90b95be in the TypeScript / code-coverage/cliThe overall coverage in commit 90b95be in the Show a code coverage summary of the most impacted files.
Updated |
PR Review Advisor — No blocking findings reportedAdvisor assessment: No blocking advisor findings reported Model lanes
6 terminology differences from the second opinionAdvisory only. These are normalized differences from the primary terminology receipt.
2 additional E2E selections from the second opinionAdvisory only. The primary lane did not select these E2E jobs or targets.
Second-opinion terminology and E2E selections are advisory. They do not change the primary assessment or E2E / PR Gate. 3 semantic terminology decisionsTerminology decisions are advisory. They affect the assessment only when a separate finding identifies concrete semantic impact.
E2E guidanceAdvisory only. E2E / PR Gate selects and runs jobs independently. Recommended E2E: This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge. |
Signed-off-by: Carlos Villela <cvillela@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Replace the intermittently rejected @hono/node-server 2.0.11 package with the reviewed 2.0.12 patch release. Bind its registry identity in the lock and image contract. Record the upstream compatibility and provenance review. Signed-off-by: Carlos Villela <cvillela@nvidia.com>
Signed-off-by: Carlos Villela <cvillela@nvidia.com>
Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
Restore the ordinary HTTP forward-proxy fixture used by locked Undici 8.10.0. The client does not enable CONNECT tunneling for plain HTTP targets. Signed-off-by: Carlos Villela <cvillela@nvidia.com>
There was a problem hiding this comment.
Actionable comments posted: 1
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
tools/mcp-tool-discovery-runtime/dependency-review.md (1)
16-24: 🔒 Security & Privacy | 🟡 Minor | ⚡ Quick winStrengthen the image contract for the SDK pin and audit boundary.
The contract test does not bind the documented
@modelcontextprotocol/sdkintegrity. Its audit check also usestoContain, sonpm audit ... || truecould bypass the fail-closed boundary. Add the SDK metadata and assert the exact non-suppressed audit invocation.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@tools/mcp-tool-discovery-runtime/dependency-review.md` around lines 16 - 24, Strengthen the contract test for the documented `@modelcontextprotocol/sdk` pin by adding and validating its exact integrity metadata alongside the existing dependency overrides. Update the audit assertion to require the exact fail-closed npm audit invocation, including its intended arguments, rather than using toContain. Ensure the expected command cannot be satisfied when npm audit is followed by || true or otherwise suppresses failures.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/lib/onboard/managed-image-registry-fetch.test.ts`:
- Around line 58-60: Update the fetch test around session.fetchImpl to assert
response.status is 200 alongside the existing response body assertion, while
preserving the tunnel expectation and avoiding implementation-specific
assertions.
---
Outside diff comments:
In `@tools/mcp-tool-discovery-runtime/dependency-review.md`:
- Around line 16-24: Strengthen the contract test for the documented
`@modelcontextprotocol/sdk` pin by adding and validating its exact integrity
metadata alongside the existing dependency overrides. Update the audit assertion
to require the exact fail-closed npm audit invocation, including its intended
arguments, rather than using toContain. Ensure the expected command cannot be
satisfied when npm audit is followed by || true or otherwise suppresses
failures.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 19bd8713-0325-4255-9f22-73e03c49fc3e
📒 Files selected for processing (4)
ci/source-shape-test-budget.jsonsrc/lib/onboard/managed-image-registry-fetch.test.tstest/mcp-tool-discovery-image-contract.test.tstools/mcp-tool-discovery-runtime/dependency-review.md
🚧 Files skipped from review as they are similar to previous changes (2)
- test/mcp-tool-discovery-image-contract.test.ts
- ci/source-shape-test-budget.json
Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
Align the proxy fixture with locked Undici 8.10.0, which forwards plain HTTP requests. Bind the SDK lock identity, response status, and exact audit commands so drift fails closed. Signed-off-by: Carlos Villela <cvillela@nvidia.com>
Signed-off-by: Carlos Villela <cvillela@nvidia.com>
Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
apurvvkumaria
left a comment
There was a problem hiding this comment.
Reviewed exact head 8397801. Approve: the four overrides advance the exact locked production graph beyond the reported advisory ranges without weakening the low-severity audit, signature, integrity, or bundle allowlist boundaries. The contract now binds the SDK and override metadata and requires the two exact unsuppressed audit commands. The focused image-contract and bounded-proxy suites passed 9 of 9 tests locally, including the restored CONNECT fixture and HTTP status assertion. Current required CI is still rerunning after superseded jobs; the normal merge gate should remain authoritative.
|
Current head For the locked runtime in this checkout, Please preserve the CONNECT fixture while the current-head CI run completes; the ordinary forward-proxy handler has now reproduced the same timeout on |
Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
apurvvkumaria
left a comment
There was a problem hiding this comment.
Re-reviewed exact head 330b13d. The only new delta replaces the CONNECT fixture with the forward-proxy request shape used by the branch-locked Undici 8.10.0 while retaining the response-status, body, and exact destination assertions. With an exact npm ci for this revision, the focused transport suite passes 5 of 5 tests; the dependency, integrity, audit-command, and image-contract changes from the prior approved revision are unchanged. No blocking defect found; current CI remains the normal merge gate.
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
apurvvkumaria
left a comment
There was a problem hiding this comment.
Comment — reviewed exact head cb6f948. The production dependency remediation remains safe, but this latest test-only commit needs a narrow non-blocking correction: after an exact npm ci for this revision (Undici 8.10.0), the focused managed-image registry transport suite deterministically times out at the CONNECT fixture (1 failed, 4 passed). The immediately preceding forward-proxy fixture passed 5 of 5 with the same exact dependencies, showing that this EnvHttpProxyAgent path sends an ordinary absolute-form HTTP proxy request rather than CONNECT for the HTTP registry URL. Please restore that forward-request fixture and retain the status, body, and exact destination assertions. This is explicitly non-blocking review feedback because it does not change supported runtime behavior; the required CI merge gate should enforce the test correction before merge.
apurvvkumaria
left a comment
There was a problem hiding this comment.
Re-reviewed exact head 1058aa9. The prior non-blocking proxy-fixture failure is resolved: the fixture now handles both ordinary forward requests and CONNECT while still proving exactly one bounded proxy route, a 200 response, the expected body, and an exact allowed destination. With this revision’s exact Undici 8.10 dependency set, the focused transport suite passes 5 of 5 tests. The reviewed dependency, integrity, signature, audit, and image-contract boundaries are unchanged. Approve; no blocking defect found.
Assert the method, host, and full target URL for the plain HTTP request. Return HTTP 502 for CONNECT and record the Undici 8.10 default. Signed-off-by: Carlos Villela <cvillela@nvidia.com>
|
🌿 Preview your docs: https://nvidia-preview-pr-8180.docs.buildwithfern.com/nemoclaw |
## Summary Add deterministic regression coverage for cancelling an HTTPS registry request after its configured proxy has completed the CONNECT handshake. The independent MCP runtime audit fix is already merged on `main` through #8180. This branch now integrates that exact base and intentionally carries no dependency, lockfile, review-record, or production-code delta. ## Changes - Retain `main`'s plain HTTP forward-proxy coverage. - Add a loopback HTTPS CONNECT fixture that sends `200 Connection Established` before aborting the request signal. - Assert the public fetch boundary returns `AbortError`, the tunnel targets `registry.invalid:443`, and the accepted socket is cleaned up in `finally`. ## Type of Change - [x] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [ ] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [x] Tests added or updated for changed behavior - [ ] Existing tests cover changed behavior — justification: - [ ] Tests not applicable — justification: - [ ] Docs updated for user-facing behavior changes - [x] Docs not applicable — justification: The effective diff adds only test coverage and changes no production or user-visible contract. - [x] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [x] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: Independent exact-head nine-category security review passed with no findings at `ade9f9cfc588124d0ffac8ced6e594cc0b40aba7`. - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## Documentation Writer Review - [x] Documentation writer subagent reviewed the completed changes - Result: `no-docs-needed` - Evidence: Reviewed the complete effective diff from base `1ee723a3c` to head `ade9f9cfc`. It adds only a 32-line HTTPS proxy CONNECT cancellation regression test. No production or user-visible behavior changed. The test title follows the writing guide. Findings: none. `git diff --check` passed, and the focused Vitest file passed 6/6. - Agent: Codex Desktop <!-- docs-review-head-sha: ade9f9c --> <!-- docs-review-agents-blob-sha: 3dd7c24 --> ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed - [x] Targeted behavior tests pass for the current change set — the complete registry transport file passed 6/6, ten consecutive focused reruns passed, source-shape and test-size gates passed, and CLI build plus TypeScript checks passed - [ ] Applicable broad gate passed — exact-head CI is authoritative and is still running - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) - [ ] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) ## Security Review No findings at exact head `ade9f9cfc588124d0ffac8ced6e594cc0b40aba7`. The effective diff is one test file with 32 additions. The fixture is loopback-only, completes the CONNECT handshake before cancellation, asserts the abort-specific public error, and deterministically destroys the socket and closes the dispatcher in `finally`. No dependencies, production configuration, authentication, TLS trust, credentials, or runtime controls change. All nine review categories pass. --- Signed-off-by: Aaron Erickson <aerickson@nvidia.com> --------- Signed-off-by: Aaron Erickson <aerickson@nvidia.com> Signed-off-by: Julie Yaunches <jyaunches@nvidia.com> Co-authored-by: Carlos Villela <cvillela@nvidia.com> Co-authored-by: Julie Yaunches <jyaunches@nvidia.com>
Signed-off-by: Carlos Villela <cvillela@nvidia.com>
<!-- markdownlint-disable MD041 --> ## Summary Keep the reviewed npm-audit provenance tests fail-closed after #8156 merged the clean root, OpenClaw, and mcporter dependency graphs. Derive the expected mcporter audit status and advisory list from the parsed checked-in exception policy instead of hard-coding one policy state. Keep generic audit tests independent from that production file while separately asserting that the checked-in registry remains empty. ## Related Issue Post-remediation contract follow-up to #8156. The separate MCP discovery runtime remediation remains owned by #8177 and #8180. ## Changes - Derive mcporter base-provenance fixtures and mocked audit results from the checked-in exception policy. - Keep the generic empty-policy fixture immutable and independently assert that `ci/npm-audit-exceptions.json` contains no entries. - Remove all seven temporary transition exceptions and all duplicated MCP dependency changes from this PR now that #8156 is on `main` and #8180 owns the MCP fix. ## Type of Change - [x] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [ ] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [x] Tests added or updated for changed behavior - [ ] Existing tests cover changed behavior — justification: - [ ] Tests not applicable — justification: - [ ] Docs updated for user-facing behavior changes - [x] Docs not applicable — justification: the effective diff changes test fixtures and assertions only; no supported API, CLI, configuration, workflow, default, error, or user-facing behavior changes. - [x] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [x] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: the exact effective diff only derives expected audit provenance from the parsed checked-in policy and retains fail-closed mismatch coverage. The production policy remains empty and no exception or enforcement behavior changes. - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: no exception is requested; exact-head CI is authoritative. ## Documentation Writer Review - [x] Documentation writer subagent reviewed the completed changes - Result: `no-docs-needed` - Evidence: The independent writer reviewed the two-file effective diff and confirmed that it changes test fixtures and assertions only. The checked-in exception registry remains empty. The focused provenance and reviewed-audit suites pass 84/84, and `git diff --check` passes. - Agent: Codex Desktop, independent documentation-writer subagent <!-- docs-review-head-sha: 76ef46a --> <!-- docs-review-agents-blob-sha: 3dd7c24 --> ## DGX Station Hardware Evidence - [ ] Tested on DGX Station - Tested commit: Not applicable; DGX Station preparation is unchanged. - Station profile/scenario: Not applicable. - Result: Not applicable. - Supporting evidence: Not applicable. ## Verification - [x] PR description includes a `Signed-off-by:` line and every pushed commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run validate:pr` passed after refreshing `origin/main` when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set — 84/84 tests passed across the reviewed-audit and OpenClaw integrity-pin suites. - [ ] Applicable broad gate passed — `npm test` for broad runtime/test-harness changes; `npm run check` for repo-wide validation/coverage changes — not applicable to this two-test-file contract hardening; required CI remains authoritative. - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) — not applicable; no documentation changes remain in the effective diff. - [x] Doc pages follow the style guide (doc changes only) — not applicable. - [ ] New doc pages include SPDX header and frontmatter (new pages only) Additional evidence: - Current base: merged #8156 commit `15069f9262d52b74d8916b7a0d7969a9ae4d3ee1`. - Effective diff: `test/openclaw-integrity-pin-suite.ts` and `test/reviewed-npm-audit.test.ts` only. - Checked-in `ci/npm-audit-exceptions.json`: schema version 1 with an empty `exceptions` array. - No MCP manifest, lock, dependency-review, audit exception, or runtime file changes remain in this PR. --- Signed-off-by: Julie Yaunches <jyaunches@nvidia.com> Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com> --------- Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com> Signed-off-by: J. Yaunches <jmyaunch@gmail.com> Signed-off-by: Julie Yaunches <jyaunches@nvidia.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Julie Yaunches <jyaunches@nvidia.com>
<!-- markdownlint-disable MD041 --> ## Summary Prepares the canonical v0.0.102 release documentation from the current release-labeled scope. The change adds a dated changelog for all 38 user-facing shipping PRs and corrects the OpenClaw agent command reference for the behavior delivered by #8191. ## Changes - Add `docs/changelog/2026-08-04.mdx` with the v0.0.102 release summary, detailed behavior changes, support boundaries, security evidence links, and links to durable documentation. - Update `docs/reference/commands.mdx` to describe non-JSON OpenClaw output capture, its combined limit, marker handling, stream suppression, recovery guidance, and exit behavior. - [#8167](#8167) -> `docs/changelog/2026-08-04.mdx`: Records authenticated attachment of operator-managed llama.cpp servers. - [#8129](#8129) -> `docs/changelog/2026-08-04.mdx`: Records the Experimental managed vLLM profile for two DGX Spark systems. - [#7983](#7983) -> `docs/changelog/2026-08-04.mdx`: Records qualification of the May 2026 GB300WS factory image. - [#8207](#8207) -> `docs/changelog/2026-08-04.mdx`: Records the qualified DGX Station driver transaction. - [#8208](#8208) -> `docs/changelog/2026-08-04.mdx`: Records mode-bound Express resume state. - [#8158](#8158) -> `docs/changelog/2026-08-04.mdx`: Records recovery of host-global dual-Station runtime ownership. - [#8145](#8145) -> `docs/changelog/2026-08-04.mdx`: Records Windows-host Ollama validation from Docker Desktop's network context. - [#8190](#8190) -> `docs/changelog/2026-08-04.mdx`: Records HTTP model pulls when WSL has no local Ollama executable. - [#8195](#8195) -> `docs/changelog/2026-08-04.mdx`: Records reuse of a healthy installer-managed CLI. - [#8053](#8053) -> `docs/changelog/2026-08-04.mdx`: Records early rejection of incompatible OpenShell gateway versions. - [#8098](#8098) -> `docs/changelog/2026-08-04.mdx`: Records the bounded package-service-to-standalone gateway recovery transition. - [#8216](#8216) -> `docs/changelog/2026-08-04.mdx`: Records the final dashboard port selected during multi-sandbox onboarding. - [#8146](#8146) -> `docs/changelog/2026-08-04.mdx`: Records managed startup-state restoration for stopped sandboxes. - [#8092](#8092) -> `docs/changelog/2026-08-04.mdx`: Records gateway watchdog recovery for classified not-serving states. - [#8182](#8182) -> `docs/changelog/2026-08-04.mdx`: Records consistent managed-recovery wait configuration. - [#8040](#8040) -> `docs/changelog/2026-08-04.mdx`: Records Docker sandbox rollback authority through late validation. - [#8130](#8130) -> `docs/changelog/2026-08-04.mdx`: Records bounded Shields deadline recovery and durable containment. - [#8086](#8086) -> `docs/changelog/2026-08-04.mdx`: Records repair of narrowly validated permission-only configuration drift. - [#8122](#8122) -> `docs/changelog/2026-08-04.mdx`: Records prompt failure and guidance for corrupt transition locks. - [#8124](#8124) -> `docs/changelog/2026-08-04.mdx`: Records policy restoration flags, previews, and target revalidation. - [#7886](#7886) -> `docs/changelog/2026-08-04.mdx`: Records explicit destruction after pre-delete Shields hardening failures while preserving recovery authority. - [#7901](#7901) -> `docs/changelog/2026-08-04.mdx`: Records multi-port uninstall behavior and shared-resource preservation. - [#7984](#7984) -> `docs/changelog/2026-08-04.mdx`: Records one classified transient remote MCP startup retry. - [#7954](#7954) -> `docs/changelog/2026-08-04.mdx`: Records bounded hosted-inference probe replies. - [#7574](#7574) -> `docs/changelog/2026-08-04.mdx`: Records preservation of validated reasoning capabilities through onboarding. - [#8089](#8089) -> `docs/changelog/2026-08-04.mdx`: Records proxy routing for Hermes WhatsApp pairing and media traffic. - [#7682](#7682) -> `docs/changelog/2026-08-04.mdx`: Records native Hermes session deletion and identifier validation. - [#8150](#8150) -> `docs/changelog/2026-08-04.mdx`: Records corporate CA trust for LangChain Deep Agents Code image builds. - [#8156](#8156) -> `docs/changelog/2026-08-04.mdx`: Records reviewed managed runtime dependency remediation. - [#8180](#8180) -> `docs/changelog/2026-08-04.mdx`: Records reviewed MCP discovery runtime dependency updates. - [#8196](#8196) -> `docs/changelog/2026-08-04.mdx`: Records private npm dependency remediation across managed images. - [#8203](#8203) -> `docs/changelog/2026-08-04.mdx`: Records reviewed Hermes and LangChain Deep Agents Code Python dependency updates. - [#8125](#8125) -> `docs/changelog/2026-08-04.mdx`: Records bounded diagnostics for invalid enumerated CLI values. - [#8193](#8193) -> `docs/changelog/2026-08-04.mdx`: Records bounded diagnostics for unresolved sandbox base images. - [#8118](#8118) -> `docs/changelog/2026-08-04.mdx`: Records bounded diagnostics for changed gateway authority. - [#8191](#8191) -> `docs/changelog/2026-08-04.mdx`, `docs/reference/commands.mdx`: Records output capture, marker handling, recovery guidance, and exit behavior for non-JSON OpenClaw agent commands. - [#8187](#8187) -> `docs/changelog/2026-08-04.mdx`: Records the aligned interactive-installation start across supported agents. - [#8153](#8153) -> `docs/changelog/2026-08-04.mdx`: Records current product capabilities and support boundaries. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [x] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [ ] Tests added or updated for changed behavior - [ ] Existing tests cover changed behavior — justification: - [x] Tests not applicable — justification: This documentation-only release preparation does not change executable behavior. Existing changelog and published-route tests pass. - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## Documentation Writer Review - [x] Documentation writer subagent reviewed the completed changes - Result: `docs-updated` - Evidence: Independently reviewed `docs/changelog/2026-08-04.mdx` and `docs/reference/commands.mdx` at commit `b89913780`. All 38 user-facing v0.0.102 PRs are represented, #8191 behavior matches the implementation, and the writing rules, documentation style, controlled terminology, route structure, and skip policy pass review. Targeted tests pass 36/36 and the documentation build completes with 0 errors. - Agent: Codex Desktop independent documentation writer <!-- docs-review-head-sha: b899137 --> <!-- docs-review-agents-blob-sha: 3dd7c24 --> ## DGX Station Hardware Evidence - [ ] Tested on DGX Station - Tested commit: Not applicable - Station profile/scenario: Not applicable - Result: Not applicable - Supporting evidence: Not applicable ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run validate:pr` passed after refreshing `origin/main` when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — `npx vitest run --project integration test/changelog-docs.test.ts test/check-docs-published-routes.test.ts` passed 36/36. - [x] Applicable broad gate passed — not applicable to documentation-only changes; `npm run docs` completed successfully with 0 errors. - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) — completed with 0 errors and 2 existing Fern warnings. - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [x] New doc pages include SPDX header and frontmatter (new pages only) — the native dated changelog uses the required parser-safe MDX SPDX comment and intentionally has no frontmatter. --- Signed-off-by: Apurv Kumaria <akumaria@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Added release notes for v0.0.102, covering authentication, hardware setup, WSL, installer recovery, sandbox resilience, policy management, inference reliability, CLI improvements, and unified quickstarts. - Updated command documentation to explain how non-JSON agent output is collected, replayed, and reported. - **Bug Fixes** - Improved command-output recovery guidance when output exceeds limits or contains unsupported fallback markers. - Preserved accurate command exit-status reporting after output processing. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Summary
Updates the locked Model Context Protocol (MCP) tool-discovery runtime so sandbox image builds pass the unchanged production audit.
The reviewed dependency releases are outside the reported advisory ranges.
The final correction updates regression coverage and dependency-review text without changing production proxy behavior.
The proxy-test correction is included because the stale fixture prevented the CLI shard from validating the dependency update.
Related Issue
Fixes #8177
Changes
@hono/node-server@2.0.12,fast-uri@3.1.5,hono@4.12.34, andip-address@10.3.1.@modelcontextprotocol/sdk@1.30.0and the existingnpm audit --omit=dev --audit-level=lowrequirement.502on CONNECT so tunneling fails.tools/mcp-tool-discovery-runtime/dependency-review.mdanddocs/security/openclaw-2026.7.1-dependency-review.md.PR #8172 overlaps this dependency graph but also changes audit policy and remains a separate sequencing decision.
PR #8175 overlaps the advisory remediation but does not bind the reviewed graph and audit command in the image contract.
No work was transferred between these branches.
Type of Change
Quality Gates
90b95be3af1856d0d59cc34581dd6cb94571ee61returned PASS in every category. No security findings remain.Documentation Writer Review
docs-updated90b95be3af1856d0d59cc34581dd6cb94571ee61against base6a838ffc. Its tree39e3f5f8c74cee608e56e4fea82677b6663e07a4matches the previously reviewed tree. The security page accurately documents Undici 8.10 plain HTTP proxy forwarding and unchanged HTTPS CONNECT behavior. The runtime review records the four pinned dependencies, integrity values, licenses, provenance, advisory ranges, and unchanged audit commands. Tests bind those records and proxy behavior to observable assertions. No public API, CLI, configuration, or supported workflow changed. The changed documentation paths aredocs/security/openclaw-2026.7.1-dependency-review.mdandtools/mcp-tool-discovery-runtime/dependency-review.md.DGX Station Hardware Evidence
Verification
Signed-off-by:line and every commit appears asVerifiedin GitHub — All 15 commits are verified, and the DCO check passed for commit90b95be3af1856d0d59cc34581dd6cb94571ee61.pre-commit,commit-msg, andpre-pushhooks passed, ornpm run validate:prpassed after refreshingorigin/mainwhen hooks were skipped or unavailable — All normal hooks passed for the final correction.90b95be3af1856d0d59cc34581dd6cb94571ee61. All eight CLI shards passed, including the proxy regression, and the reviewed production audit passed. No duplicate local test suite was run after the final correction.npm testfor broad runtime/test-harness changes;npm run checkfor repo-wide validation/coverage changes — command/result: The requiredchecksresult and E2E gate passed on commit90b95be3af1856d0d59cc34581dd6cb94571ee61. GitHub CI is authoritative; no duplicate local suite was run for the final correction.npm run docsbuilds without warnings (doc changes only) — The GitHub Fern preview prepared and validated the documentation on commit90b95be3af1856d0d59cc34581dd6cb94571ee61.Security Review
Commit
90b95be3af1856d0d59cc34581dd6cb94571ee61has no security findings.@hono/node-server,hono, andip-addressuse MIT licenses.fast-uriuses BSD-3-Clause.502for an unexpected CONNECT request.Signed-off-by: Julie Yaunches jyaunches@nvidia.com
Signed-off-by: Prekshi Vyas prekshiv@nvidia.com
Signed-off-by: Carlos Villela cvillela@nvidia.com