OpenClaw 2026.6.7 Released: Channel Delivery Overhaul and Security Hardening
OpenClaw 2026.6.7 dropped June 13th, marking the most substantial channel delivery update in recent releases alongside a round of security hardening and provider resilience improvements.
Channel delivery sees the biggest set of changes: same-channel Slack finals now persist in transcripts, top-level image message-tool sends attach media properly, Telegram blockquotes and spooled replay survive delivery, explicit silent assistant replies stay silent, progress draft startup failures are reported, and channel action result pages can be fetched incrementally.
Provider and model handling is more resilient across the board: Kimi K2.7 Code support lands, Kimi native tool-call ids and reasoning_content replay are repaired, Mistral skips unreadable tool schemas, Fireworks catalog parameters now come from manifests, DeepSeek keeps configured static transport, provider fallbacks resolve correctly, Anthropic thinking replay is repaired, and Anthropic Vertex stops re-marking transport-budgeted cache control.
Security hardening is a notable theme this release: Feishu no longer leaks prompt-preface runtime context into replies, WebSocket payload handling is hardened, the CLI-backed /btw fallback fails closed, local setup trust is hardened, and Skill Workshop symlink writes are gated and validated before rollback metadata is written.
Agent, memory, Codex, cron, and update recovery paths also preserve useful failure information instead of swallowing errors silently.
Contributors in this release include TurboTheTurtle, ichirokyoto, xydigit-sj, joshavant, sallyom, hansraj316, fuller-stack-dev, xialonglee, vincentkoc, obuchowski, openperf, jovi2014-cyber, zhangqueping, and openperf.