docs(changelog): clarify hooks transform dir restriction

This commit is contained in:
Peter Steinberger
2026-02-14 14:02:05 +01:00
parent d73b48b32c
commit d69b32a073

View File

@@ -6,7 +6,7 @@ Docs: https://docs.openclaw.ai
### Fixes
- Security/Hooks: restrict hook transform modules to `~/.openclaw/hooks/transforms` (prevents path traversal/escape module loads via config). Thanks @akhmittra.
- Security/Hooks: restrict hook transform modules to `~/.openclaw/hooks/transforms` (prevents path traversal/escape module loads via config). Config note: `hooks.transformsDir` must now be within that directory. Thanks @akhmittra.
- Security/Hooks: ignore hook package manifest entries that point outside the package directory (prevents out-of-tree handler loads during hook discovery).
## 2026.2.13