openclaw/clawsweeperPublic

ClawSweeper scans all issues and PRs and suggest what we can close, and why. It runs every PR / Issue once a week.

AI summary: A conservative GitHub maintenance bot that automates reviews and guarded repository cleanup.

Stars
2K
+1 today
Forks
311
Watchers
15
Open issues
6
Open PRs
5
Contributors
~59
Commits
7.1K
Branches
98

TypeScriptMITCreated Apr 23, 2026Last push 2d agoLatest release v0.3.0+5 stars this week+24 this month

Quick answers

What is clawsweeper?
A conservative GitHub maintenance bot that automates reviews and guarded repository cleanup.
What does clawsweeper do?
ClawSweeper is a highly conservative maintenance automation bot specifically tailored for the OpenClaw repository ecosystem. It systematically scans open issues and pull requests, generating durable markdown reports and public review comments based on a rigorous set of guardrails. Rather than aggressively auto-closing items, it relies on high-confidence, policy-allowed proposals (such as items already implemented on main) to suggest actions. It routes commands from maintainers to trigger bounded repair loops, automerging, or issue implementation, always requiring revalidation of the live GitHub state before executing any mutation.
Who is clawsweeper for?
ClawSweeper is designed for OpenClaw maintainers who need to manage massive repository backlogs efficiently without sacrificing review quality or repository safety.
How do I get started with clawsweeper?
Read CONTRIBUTING.md for local setup details.
How popular is clawsweeper on GitHub?
openclaw/clawsweeper has 1,994 stars and 311 forks on GitHub, and gained 5 stars in the last 7 days.
What license does clawsweeper use?
openclaw/clawsweeper is released under the MIT license.

Star history

since Jul 29, 2026
05001K1.5KJul 2026Aug 2026Sep 2026Oct 2026
2K stars as of Oct 3, 2026. Measured daily since Jul 29, 2026; GitHub no longer exposes earlier star timestamps.

Contribution activity

commits per day, last 52 weeks
OctNovDecJanFebMarAprMayJunJulAugSepMonWedFri2025-10-05: 0 commits2025-10-06: 0 commits2025-10-07: 0 commits2025-10-08: 0 commits2025-10-09: 0 commits2025-10-10: 0 commits2025-10-11: 0 commits2025-10-12: 0 commits2025-10-13: 0 commits2025-10-14: 0 commits2025-10-15: 0 commits2025-10-16: 0 commits2025-10-17: 0 commits2025-10-18: 0 commits2025-10-19: 0 commits2025-10-20: 0 commits2025-10-21: 0 commits2025-10-22: 0 commits2025-10-23: 0 commits2025-10-24: 0 commits2025-10-25: 0 commits2025-10-26: 0 commits2025-10-27: 0 commits2025-10-28: 0 commits2025-10-29: 0 commits2025-10-30: 0 commits2025-10-31: 0 commits2025-11-01: 0 commits2025-11-02: 0 commits2025-11-03: 0 commits2025-11-04: 0 commits2025-11-05: 0 commits2025-11-06: 0 commits2025-11-07: 0 commits2025-11-08: 0 commits2025-11-09: 0 commits2025-11-10: 0 commits2025-11-11: 0 commits2025-11-12: 0 commits2025-11-13: 0 commits2025-11-14: 0 commits2025-11-15: 0 commits2025-11-16: 0 commits2025-11-17: 0 commits2025-11-18: 0 commits2025-11-19: 0 commits2025-11-20: 0 commits2025-11-21: 0 commits2025-11-22: 0 commits2025-11-23: 0 commits2025-11-24: 0 commits2025-11-25: 0 commits2025-11-26: 0 commits2025-11-27: 0 commits2025-11-28: 0 commits2025-11-29: 0 commits2025-11-30: 0 commits2025-12-01: 0 commits2025-12-02: 0 commits2025-12-03: 0 commits2025-12-04: 0 commits2025-12-05: 0 commits2025-12-06: 0 commits2025-12-07: 0 commits2025-12-08: 0 commits2025-12-09: 0 commits2025-12-10: 0 commits2025-12-11: 0 commits2025-12-12: 0 commits2025-12-13: 0 commits2025-12-14: 0 commits2025-12-15: 0 commits2025-12-16: 0 commits2025-12-17: 0 commits2025-12-18: 0 commits2025-12-19: 0 commits2025-12-20: 0 commits2025-12-21: 0 commits2025-12-22: 0 commits2025-12-23: 0 commits2025-12-24: 0 commits2025-12-25: 0 commits2025-12-26: 0 commits2025-12-27: 0 commits2025-12-28: 0 commits2025-12-29: 0 commits2025-12-30: 0 commits2025-12-31: 0 commits2026-01-01: 0 commits2026-01-02: 0 commits2026-01-03: 0 commits2026-01-04: 0 commits2026-01-05: 0 commits2026-01-06: 0 commits2026-01-07: 0 commits2026-01-08: 0 commits2026-01-09: 0 commits2026-01-10: 0 commits2026-01-11: 0 commits2026-01-12: 0 commits2026-01-13: 0 commits2026-01-14: 0 commits2026-01-15: 0 commits2026-01-16: 0 commits2026-01-17: 0 commits2026-01-18: 0 commits2026-01-19: 0 commits2026-01-20: 0 commits2026-01-21: 0 commits2026-01-22: 0 commits2026-01-23: 0 commits2026-01-24: 0 commits2026-01-25: 0 commits2026-01-26: 0 commits2026-01-27: 0 commits2026-01-28: 0 commits2026-01-29: 0 commits2026-01-30: 0 commits2026-01-31: 0 commits2026-02-01: 0 commits2026-02-02: 0 commits2026-02-03: 0 commits2026-02-04: 0 commits2026-02-05: 0 commits2026-02-06: 0 commits2026-02-07: 0 commits2026-02-08: 0 commits2026-02-09: 0 commits2026-02-10: 0 commits2026-02-11: 0 commits2026-02-12: 0 commits2026-02-13: 0 commits2026-02-14: 0 commits2026-02-15: 0 commits2026-02-16: 0 commits2026-02-17: 0 commits2026-02-18: 0 commits2026-02-19: 0 commits2026-02-20: 0 commits2026-02-21: 0 commits2026-02-22: 0 commits2026-02-23: 0 commits2026-02-24: 0 commits2026-02-25: 0 commits2026-02-26: 0 commits2026-02-27: 0 commits2026-02-28: 0 commits2026-03-01: 0 commits2026-03-02: 0 commits2026-03-03: 0 commits2026-03-04: 0 commits2026-03-05: 0 commits2026-03-06: 0 commits2026-03-07: 0 commits2026-03-08: 0 commits2026-03-09: 0 commits2026-03-10: 0 commits2026-03-11: 0 commits2026-03-12: 0 commits2026-03-13: 0 commits2026-03-14: 0 commits2026-03-15: 0 commits2026-03-16: 0 commits2026-03-17: 0 commits2026-03-18: 0 commits2026-03-19: 0 commits2026-03-20: 0 commits2026-03-21: 0 commits2026-03-22: 0 commits2026-03-23: 0 commits2026-03-24: 0 commits2026-03-25: 0 commits2026-03-26: 0 commits2026-03-27: 0 commits2026-03-28: 0 commits2026-03-29: 0 commits2026-03-30: 0 commits2026-03-31: 0 commits2026-04-01: 0 commits2026-04-02: 0 commits2026-04-03: 0 commits2026-04-04: 0 commits2026-04-05: 0 commits2026-04-06: 0 commits2026-04-07: 0 commits2026-04-08: 0 commits2026-04-09: 0 commits2026-04-10: 0 commits2026-04-11: 0 commits2026-04-12: 0 commits2026-04-13: 0 commits2026-04-14: 0 commits2026-04-15: 0 commits2026-04-16: 0 commits2026-04-17: 0 commits2026-04-18: 0 commits2026-04-19: 0 commits2026-04-20: 0 commits2026-04-21: 0 commits2026-04-22: 0 commits2026-04-23: 14 commits2026-04-24: 152 commits2026-04-25: 391 commits2026-04-26: 892 commits2026-04-27: 257 commits2026-04-28: 986 commits2026-04-29: 957 commits2026-04-30: 660 commits2026-05-01: 223 commits2026-05-02: 61 commits2026-05-03: 42 commits2026-05-04: 15 commits2026-05-05: 28 commits2026-05-06: 9 commits2026-05-07: 1 commit2026-05-08: 0 commits2026-05-09: 13 commits2026-05-10: 14 commits2026-05-11: 44 commits2026-05-12: 4 commits2026-05-13: 3 commits2026-05-14: 6 commits2026-05-15: 7 commits2026-05-16: 19 commits2026-05-17: 38 commits2026-05-18: 23 commits2026-05-19: 18 commits2026-05-20: 2 commits2026-05-21: 16 commits2026-05-22: 20 commits2026-05-23: 5 commits2026-05-24: 13 commits2026-05-25: 11 commits2026-05-26: 3 commits2026-05-27: 9 commits2026-05-28: 10 commits2026-05-29: 5 commits2026-05-30: 5 commits2026-05-31: 4 commits2026-06-01: 0 commits2026-06-02: 18 commits2026-06-03: 1 commit2026-06-04: 1 commit2026-06-05: 12 commits2026-06-06: 0 commits2026-06-07: 0 commits2026-06-08: 2 commits2026-06-09: 1 commit2026-06-10: 8 commits2026-06-11: 31 commits2026-06-12: 2 commits2026-06-13: 17 commits2026-06-14: 9 commits2026-06-15: 23 commits2026-06-16: 2 commits2026-06-17: 4 commits2026-06-18: 10 commits2026-06-19: 12 commits2026-06-20: 0 commits2026-06-21: 3 commits2026-06-22: 4 commits2026-06-23: 5 commits2026-06-24: 12 commits2026-06-25: 0 commits2026-06-26: 3 commits2026-06-27: 0 commits2026-06-28: 0 commits2026-06-29: 0 commits2026-06-30: 1 commit2026-07-01: 5 commits2026-07-02: 1 commit2026-07-03: 5 commits2026-07-04: 24 commits2026-07-05: 14 commits2026-07-06: 5 commits2026-07-07: 0 commits2026-07-08: 1 commit2026-07-09: 19 commits2026-07-10: 31 commits2026-07-11: 10 commits2026-07-12: 318 commits2026-07-13: 266 commits2026-07-14: 265 commits2026-07-15: 15 commits2026-07-16: 24 commits2026-07-17: 18 commits2026-07-18: 20 commits2026-07-19: 31 commits2026-07-20: 22 commits2026-07-21: 26 commits2026-07-22: 39 commits2026-07-23: 20 commits2026-07-24: 20 commits2026-07-25: 24 commits2026-07-26: 16 commits2026-07-27: 23 commits2026-07-28: 17 commits2026-07-29: 18 commits2026-07-30: 18 commits2026-07-31: 15 commits2026-08-01: 18 commits2026-08-02: 9 commits2026-08-03: 7 commits2026-08-04: 3 commits2026-08-05: 7 commits2026-08-06: 7 commits2026-08-07: 10 commits2026-08-08: 8 commits2026-08-09: 8 commits2026-08-10: 26 commits2026-08-11: 14 commits2026-08-12: 13 commits2026-08-13: 11 commits2026-08-14: 6 commits2026-08-15: 2 commits2026-08-16: 6 commits2026-08-17: 26 commits2026-08-18: 4 commits2026-08-19: 0 commits2026-08-20: 7 commits2026-08-21: 4 commits2026-08-22: 1 commit2026-08-23: 4 commits2026-08-24: 2 commits2026-08-25: 4 commits2026-08-26: 7 commits2026-08-27: 18 commits2026-08-28: 18 commits2026-08-29: 5 commits2026-08-30: 14 commits2026-08-31: 18 commits2026-09-01: 21 commits2026-09-02: 21 commits2026-09-03: 34 commits2026-09-04: 21 commits2026-09-05: 26 commits2026-09-06: 7 commits2026-09-07: 16 commits2026-09-08: 21 commits2026-09-09: 18 commits2026-09-10: 5 commits2026-09-11: 13 commits2026-09-12: 19 commits2026-09-13: 12 commits2026-09-14: 8 commits2026-09-15: 2 commits2026-09-16: 3 commits2026-09-17: 8 commits2026-09-18: 5 commits2026-09-19: 1 commit2026-09-20: 6 commits2026-09-21: 19 commits2026-09-22: 12 commits2026-09-23: 9 commits2026-09-24: 8 commits2026-09-25: 13 commits2026-09-26: 3 commits2026-09-27: 0 commits2026-09-28: 0 commits2026-09-29: 0 commits2026-09-30: 0 commits2026-10-01: 0 commits2026-10-02: 0 commits2026-10-03: 0 commits
7,109 commits in the last yearLessMore

Signals and awards

derived from tracked data
  • Very active

    7,109 commits in 52 weeks

  • Permissive license

    MIT

  • Continuous integration

    Automated checks passing

What clawsweeper does

ClawSweeper is a highly conservative maintenance automation bot specifically tailored for the OpenClaw repository ecosystem. It systematically scans open issues and pull requests, generating durable markdown reports and public review comments based on a rigorous set of guardrails. Rather than aggressively auto-closing items, it relies on high-confidence, policy-allowed proposals (such as items already implemented on main) to suggest actions. It routes commands from maintainers to trigger bounded repair loops, automerging, or issue implementation, always requiring revalidation of the live GitHub state before executing any mutation.

ClawSweeper is designed for OpenClaw maintainers who need to manage massive repository backlogs efficiently without sacrificing review quality or repository safety.

  • Conservative review process: Generates proposal-only markdown reports and updates marker-backed public comments without immediately altering issue state.
  • Guarded mutation: Ensures any automated closing or merging is backed by high-confidence evidence, such as verification against the current main branch.
  • Maintainer command routing: Responds to specific comments (like @clawsweeper autofix) to initiate targeted, bounded repair and merge loops.
  • Automated repair: Utilizes a Codex-driven loop to attempt automated fixes for opted-in PRs, including rebasing and addressing CI failures.
  • Strict safety boundaries: Operates primarily in read-only mode for reviews, generating write credentials only after the AI evaluation phase is complete.

Where teams use it

Repository Backlog Management

Automatically scans and proposes closures for stale issues or PRs that have already been resolved on the main branch.

Automated Pull Request Repair

Responds to maintainer commands to automatically attempt fixes on failing CI checks or address review comments before merging.

Issue Triage and Labeling

Applies advisory labels to open issues to categorize reproduction status, linked PRs, and missing information for human maintainers.

Guarded Automerging

Safely automerges approved pull requests only after ensuring all checks, policies, and re-reviews pass.

Getting started: Read CONTRIBUTING.md for local setup details.

README

main branch

🦞🧹 ClawSweeper

ClawSweeper banner

ClawSweeper is the conservative maintenance bot for OpenClaw repositories. It keeps the backlog reviewed, keeps maintainer-visible GitHub comments tidy, and turns narrow trusted findings into guarded repair or automerge work.

The dashboard Worker's explicit production targets are openclaw/openclaw, openclaw/clawhub, openclaw/clawsweeper, and openclaw/fs-safe. Additional public openclaw/* and steipete/* repositories can use configured profiles or conservative generic fallback review through event dispatch and scheduled fanout.

Project vision and boundaries: VISION.md

Documentation by task and audience: docs/README.md

Contributing

For local setup, PR scope, main-body proof, and the author-owned review loop, read CONTRIBUTING.md before opening or updating a pull request. Use the documentation index to reach architecture, configuration, dashboard, policy, and operator references without scanning this entire README. The contributing guide explains when to use @clawsweeper re-review, why a changed head or PR body needs fresh evidence, and why readiness is not merge authority.

The OpenClaw-hosted ClawSweeper instance is not a public review service and does not provide free reviews for third-party repositories. If you want ClawSweeper for your own project, fork this repository, deploy it in your own organization, and configure that self-hosted instance for your repositories.

At a high level ClawSweeper:

  • reviews open issues and pull requests on a schedule and on exact GitHub events
  • writes one durable markdown report per item in generated state
  • syncs one marker-backed public review comment per issue or PR, edited in place
  • can request relevant Web UI or Telegram proof within an eligible OpenClaw PR review and evaluate results in that same turn; see live proof
  • preserves validation, rendering, media publication, and retraction for historical post-review live-proof artifacts
  • closes only unchanged, high-confidence, policy-allowed proposals
  • routes maintainer commands such as @clawsweeper review, @clawsweeper fix, @clawsweeper autofix, and @clawsweeper automerge
  • can acknowledge maintainer comment commands through an optional GitHub App webhook before the GitHub Actions fallback starts
  • repairs opted-in PRs through a bounded Codex review/fix loop before merge
  • automatically opens guarded implementation PRs for viable reviewed issues in eligible public openclaw/* and steipete/* projects outside openclaw/openclaw and openclaw/clawhub
  • can review local branch ranges with repository and GitHub access kept local while Codex connects to the configured model service
  • publishes canonical review records to the Cloudflare Worker, action ledgers and assets to R2, and the remaining operational state to openclaw/clawsweeper-state

For the complete architecture and operator guide covering issue-to-PR work, PR repair, GitCrawl intake, durable Codex threads, CrabFleet steering, completion gates, quotas, dashboards, and recovery, see docs/steerable-repair-automation.md.

The oversized PR close lane proposes closing pull requests above 50,000 changed lines before hydration, scanning, or model review, with a maintainer size: accepted-large exemption. See the close-policy index for the guarded close lanes.

ClawSweeper is not a generic auto-close bot. Review is proposal-only, apply is guarded, Codex never gets write credentials during review, and every GitHub mutation is rechecked against live target state immediately before it happens.

Capabilities

Issue and PR Reviews

Scheduled runs scan open issues and pull requests, while target repositories can forward exact issue/PR events with repository_dispatch for low-latency one-item reviews. Each review writes records/<repo-slug>/items/<number>.md with the decision, evidence, proposed maintainer-facing comment, runtime metadata, and GitHub snapshot hash.

PR checkout preparation captures only the recursive tree's entry types, object IDs, sizes, and truncation flag from the GitHub CLI. This keeps path and URL metadata from exhausting the response buffer while preserving the existing checkout size limits and rejection of incomplete or malformed trees.

Media proof preparation recognizes image/video filename extensions and GitHub attachment URLs, including legacy repository asset links. Attachments are fetched with GET and classified by the response content type; images are saved locally and videos are probed and converted to contact sheets. PR patches and supplemental body excerpts never supply host download URLs.

ClawSweeper syncs one marker-backed public review comment per item and edits it in place instead of posting repeated completed reviews. Scheduled review workers use a separate temporary status comment for lease coordination. Command-triggered exact reviews instead rewrite their existing acknowledgement and use the durable queue claim as their coordination lease, so they do not add a second visible status comment. Exact-review workers verify queue ownership before generation and during finalization. Temporary lease comments are removed after publication. Pull request comments include hidden verdict/action markers so trusted repair and automerge flows can continue without scraping visible prose. See docs/pr-review-comments.md.

Review prompts include compact related issue and PR context from explicit links, linked closing PRs, existing local ClawSweeper reports, optional gitcrawl clusters, and opt-in live GitHub issue search for exact event reviews. This is advisory context for duplicate/superseded reasoning, not a standalone close decision. Reviews also persist a typed, proposal-only root-cause assessment with same-repository URLs and at most one evidence-backed canonical item; it does not dispatch repair, suppress jobs, mutate siblings, close, or merge. See docs/related-issue-discovery.md.

For open issues with complete, current kept-open reviews, ClawSweeper also projects selected structured review conclusions into advisory GitHub labels for maintainer filtering and project views. These labels expose states such as current-main reproduction, source reproduction, linked open PRs, queueable fixes, verified small bugs suitable for good first issue, missing info, and product/security review needs. They are advisory only and do not trigger repair, merge, or close behavior. Label-only syncs record labels_synced_at in the durable report so GitHub updated_at changes caused by ClawSweeper-owned label writes do not look like fresh target-side activity to the scheduler. See docs/work-lane.md.

Apply and State

Apply mode re-fetches live GitHub state, checks labels, maintainer authorship, paired issue/PR state, snapshot drift, and repository profile rules before commenting or closing anything. Closed or already-closed reports move to records/<repo-slug>/closed/<number>.md; reopened archived items move back to items/ as stale work.

Apply and artifact replay also maintain Codex-authored decision packet JSON at records/<repo-slug>/decision-packets/<number>.json for reports that need a maintainer ruling. Codex supplies the exact question, rationale, options, recommendation, and likely owner as structured review output. Deterministic code validates that intent, persists it, refreshes item state, and removes stale packets; labels and report prose do not reconstruct the decision. Pass --decision-packets-dir to write those packet files somewhere other than the profile's default records directory.

Canonical review records live in the Cloudflare Durable Object store and are snapshotted to R2. Immutable ledger/v1/ action events, published assets/, and the bounded content-addressed artifacts/exact-review/v1/ retry cache also live in R2. The state branch of openclaw/clawsweeper-state now retains only jobs/, results/, notifications/, apply-report.json, and repair-apply-report.json; its main branch remains the dashboard renderer source. scripts/hydrate-state.ts combines those sources for local commands. See docs/state-storage.md for the ownership table.

Repair and Automerge

Maintainer commands can opt PRs into autofix or automerge, dispatch a fresh exact-head review, and run a bounded Codex review/fix loop. Codex handles the code repair and local validation loop; deterministic executor steps own every GitHub mutation, branch push, label update, and final merge gate.

Operators can create repair-only jobs for one author's blocked pull requests in one repository with pnpm repair:pr-intake -- --repo owner/name --author login, or across all configured public repositories with pnpm repair:pr-intake -- --author login --all-open. Author-wide discovery skips private, unsupported, and unverifiable repositories without persisting their names. Generated jobs cannot close or merge their source pull requests.

Automerge waits for exact-head review, required checks, mergeability, and policy gates. If repair was needed, the mutable status comment records each review, repair, re-review, and merge step with timing and links. The final merge result summarizes both the original PR change and any ClawSweeper fixups.

For issues, high-confidence bug reviews that identify a reproduced or small, source-proven fix, do not already have a linked PR, and do not require feature/config expansion automatically dispatch Codex to open one guarded implementation PR labeled clawsweeper:autogenerated whenever CLAWSWEEPER_AUTO_IMPLEMENT_ISSUES=1. An exact issue review dispatches its fix as soon as that review is published; scheduled sweeps also backfill eligible existing reports. The worker reproduces or establishes a failing regression before opening the PR. When the separate vision-fit lane is enabled, reviewed issues that clearly fit the target repository VISION.md, are small enough for one focused PR, and have clear repair shape can use the same PR-only implementation path without weakening the strict bug gate.

Commit Reviews (retired)

The push/manual commit-review lane was retired in July 2026. Use pnpm local-review for GitHub-isolated local branch reviews.

Operations

Repository-specific rules live in src/repository-profiles.ts, so OpenClaw, ClawHub, and ClawSweeper can share the same engine while keeping different apply limits. Both review and repair lanes support manual workflow dispatch, reruns, and backfills.

Guardrails

ClawSweeper may propose a close only when the item is clearly one of these:

  • implemented on current main
  • not reproducible on current main
  • better suited for ClawHub skill/plugin work than core
  • duplicate or superseded by a canonical issue/PR
  • low-signal pull request whose branch is mostly unrelated or unmergeable churn
  • external low-rated pull request whose requested real-behavior proof never arrived and whose branch has been idle for 14+ days
  • external pull request abandoned for 30+ days as a draft, waiting on its author, or failing checks on its live head
  • concrete but not actionable in this source repo
  • incoherent enough that no action can be taken
  • stale issue older than 60 days with too little data to verify

Maintainer-authored items stay open unless ClawSweeper can verify that the request is already implemented on current main. Everything else stays open. Issues with an open PR that references them using GitHub closing syntax such as Fixes #123 stay open until that PR merges, is closed, or ClawSweeper closes that high-confidence PR candidate earlier in the same apply run. Open issue/PR pairs from the same author stay open together unless the paired item is already resolved or a maintainer explicitly asks to close one side. Related PR links do not promote a completed keep-open review into a close proposal. Codex owns that supersession decision; comment publication preserves the verdict. Independent no-diff, stale-PR, and author-budget policies still apply.

PR-to-PR duplicate/superseded closes also require a safe canonical target: ClawSweeper refuses to close one PR as replaced by another PR that is closed unmerged, missing positive real behavior proof, F-rated, already proposed for close, not cleanly mergeable, or otherwise not a viable landing path.

Repository profiles can further narrow apply. ClawHub and ClawSweeper self-review are intentionally stricter: they review issues and PRs, but apply may close only PRs where current main already implements the proposed change with source-backed evidence.

Maintainer Commands

Maintainers can steer ClawSweeper from target-repo issue and PR comments. The preferred form is @clawsweeper .... The router also accepts @clawsweeper[bot] ..., @openclaw-clawsweeper ..., @openclaw-clawsweeper[bot] ..., and legacy slash aliases such as /clawsweeper ..., /review, /automerge, /auto merge, and /autoclose <reason>.

Common commands:

@clawsweeper status
@clawsweeper re-review
@clawsweeper re-run
@clawsweeper review
@clawsweeper fix ci
@clawsweeper address review
@clawsweeper rebase
@clawsweeper autofix
@clawsweeper automerge
@clawsweeper approve
@clawsweeper explain
@clawsweeper ask is this blocked by flaky CI?
@clawsweeper visualize state
@clawsweeper stop
@clawsweeper why did automerge stop here?
  • status and explain post a short target summary.
  • review, re-review, and re-run dispatch a fresh ClawSweeper issue/PR review without starting repair.
  • Command status replies are marker-backed and edited in place per issue/PR, intent, and head SHA. The visible badge is one lobster plus the current state: 👀 for acknowledgement, 🧹 for review, 🔧 for repair, and ✅ for completed/paused work.
  • Freeform @clawsweeper ... mentions and explicit ask ... questions dispatch the maintainer-only assist lane. Assist runs the internal model with high reasoning, a 120-second per-item timeout, and its own five-job cap. It posts a separate non-durable answer comment and never edits the durable ClawSweeper review comment, closes, merges, labels, pushes, repairs, or emits review/apply markers. The model job has read-only GitHub access and emits a bounded artifact; a fresh trusted publisher validates its workflow request, target revision, PR head, and source comment before minting a narrow comment-write token.
  • visualize [lens] dispatches the read-only visual assist lane and posts or updates a marker-backed visual brief comment for the requested lens.
  • fix ci, address review, and rebase dispatch the repair worker only for ClawSweeper PRs or PRs already opted into clawsweeper:autofix or clawsweeper:automerge.
  • autofix labels an open PR, creates or reuses the adopted job, dispatches review, and enters the bounded review/fix loop without merging.
  • automerge labels an open PR, creates or reuses the adopted job, dispatches review, and enters the bounded review/fix/merge loop. Draft PRs are fix-only until GitHub marks them ready for review.
  • Scheduled router runs (CLAWSWEEPER_COMMENT_ROUTER_EXECUTE=1) also dispatch the router for openclaw/endor-clawsweeper-e2e. Execute-enabled scheduled or manual runs for that test repository enrol eligible Endor Pro PRs with clawsweeper:automerge: review, repair if needed, then merge only after the existing exact-head review and merge gates pass. Intake checks bot identity, PR state and same-repository/default-branch targeting. Current or historical control labels block enrolment; a maintainer must resume it. Other repositories, including openclaw/openclaw, are excluded from Endor enrolment. Endor policy owns reachability. Intake failures do not stop the router. Existing autofix PRs and human-review holds are not automatically upgraded or cleared by this change. Read-only preview: node dist/repair/endor-automerge-intake.js --repo openclaw/endor-clawsweeper-e2e. The controlled intake/router proof is node scripts/e2e/endor-automerge.mjs after pnpm run build:node; it uses synthetic GitHub state and verifies review dispatch, automatic merge, human-review pause, stale-review rejection, all late automerge-blocking labels, and replay without duplicate merge calls.
  • implement issue on an open issue creates or reuses one issue implementation job and dispatches the issue-to-PR lane. OpenClaw organization members may request this explicitly even without repository write permission.
  • With automatic issue implementation enabled, newly reviewed issues and existing eligible open issue reports enter the enabled bounded lanes. Codex inspects the issue and repository, chooses the implementation, discovers validation, and stops without a PR when the request is no longer viable. Generated PRs receive clawsweeper:autogenerated and clawsweeper:autofix, then repeat exact-head review and repair until no actionable findings remain, required checks appear and settle green, and GitHub reports merge-state readiness. ClawSweeper removes the repair-loop label and leaves the PR open; generated issue PRs never automerge.
  • User-facing OpenClaw fix, feat, and perf automerge PRs preserve release-note context in PR bodies and commit messages before merge; contributors are not asked to edit CHANGELOG.md.
  • Security-sensitive findings can be repaired only after explicit autofix/automerge opt-in; ClawSweeper still will not merge until a later exact-head review is clean.
  • approve lets a maintainer clear a ClawSweeper human-review pause and merge only after the normal exact-head, checks, mergeability, and gate checks pass.
  • stop removes repair-loop labels, adds clawsweeper:human-review, and makes older automerge/autofix comments ineligible to continue. /autoclose <reason> closes the item and any open same-repo targets explicitly referenced in the command text.
  • clawsweeper:human-review and clawsweeper:manual-only stop automatic PR repair and issue-to-PR mutation. Issue implementation rechecks the live issue immediately before every branch push and before PR creation.

Only maintainers are accepted for write actions. The router checks repository collaborator permission (admin, maintain, or write) and falls back to trusted author_association values when permission lookup is unavailable. Users with repository write access and issue/PR authors may ask @clawsweeper re-review or @clawsweeper re-run for a fresh read-only review. Other contributor commands are ignored without a reply. Scheduled comment routing is dry unless CLAWSWEEPER_COMMENT_ROUTER_EXECUTE=1; workflow dispatch with execute=true can be used for one-off live routing. For fast intake, the ClawSweeper GitHub App webhook durably records eligible review and re-review comment versions before it acknowledges them. Other commands still enqueue exact clawsweeper_comment work, and item events enqueue clawsweeper_item work, from eligible public openclaw/* and steipete/* repositories. Exact item work is coalesced and leased by the dashboard Worker before it dispatches an executor, so webhook bursts do not create capacity-waiting Actions runners. The target-side dispatcher remains a scheduled-intake fallback until it adopts the queue lease contract. Legacy target dispatches are bridged into that queue before any Codex executor starts.

Dashboard

Live dashboard and generated state: https://github.com/openclaw/clawsweeper-state

Live pipeline dashboard: https://clawsweeper.openclaw.ai/

The Cloudflare dashboard is observability-only: it shows the system flow, live worker capacity, per-worker current steps and drill-down timelines, separate issue-to-PR and PR-repair worker views, automatic issue-build cards with lifecycle drill-down, repair/automerge pipeline rows, CI state, recent failures, exact-review failure repetition and exhaustion, and automerge timing without owning GitHub mutations. Its Live terminals link opens CrabFleet for browser steering of registered GitHub Actions sessions. See docs/live-dashboard.md. The end-to-end session lifecycle is documented in docs/steerable-repair-automation.md.

The optional triage dashboard page at /triage exposes ClawSweeper advisory issue labels as read-only maintainer views, including local routing groups derived from existing impact:* labels. It is backed by GitHub Search snapshots instead of GitHub Project writes. See docs/triage-dashboard.md.

The optional PR proof triage page at /pr-proof-triage exposes open pull requests that are blocked on real behavior proof labels, including missing proof, supplied-but-not-sufficient proof, mock-only proof, and proof label mismatches. See docs/pr-proof-triage-dashboard.md.

OpenClaw Bay at /bay is a public, indexable ClawSweeper dashboard destination that renders the same read-only operational status as an animated shoreline. It is linked from the Overview, issue-triage, and PR-proof headers, and adds no browser-to-GitHub requests or new GitHub query path. See docs/openclaw-bay-demo.md.

The default-off unconfirmed product-direction policy can propose closure for a strictly bounded class of technically correct, well-proven external feature PRs that still lack maintainer-confirmed direction. Live maintainer signals and automation opt-ins veto apply. See docs/product-direction-close-policy.md.

The default-off per-author PR-budget policy gradually trims an external author's oldest lowest-signal PRs only after apply verifies the live repository count, seven-day inactivity, rating/proof eligibility, protected labels, and maintainer engagement. See docs/author-pr-budget-close-policy.md.

How It Works

ClawSweeper is split into three operational lanes:

  • review lane: scheduled and event-driven issue/PR reviews, durable reports, and public review comment sync
  • apply lane: guarded close/comment mutations, audit, reconcile, and state publishing
  • repair lane: maintainer-command routing, autofix, automerge, issue implementation PRs, and repair result publishing

Scheduler

The issue/PR scheduler decides what to scan and how often. New and active items get more attention; older quiet items fall back to a slower cadence. Detailed scheduling, capacity, and monitoring behavior is documented in docs/scheduler.md.

  • hot/new and recently active items are checked hourly, with a 5-minute intake schedule for the newest queue edge
  • target repositories can forward issue and PR events with repository_dispatch; those exact item runs use a dedicated single job to review one item, sync the durable comment, and apply only safe close proposals for that same item
  • pull requests and issues younger than 30 days are checked daily once they leave the hot window
  • older inactive issues are checked weekly
  • apply wakes every 15 minutes and exits quickly when there are no unchanged high-confidence close proposals

Review Lane

Review is proposal-only. It never closes items.

  • A planner scans open issues and PRs, then assigns exact item numbers to shards.
  • Manual runs can pass item_number or comma-separated item_numbers to review exact Audit Health findings without scanning for a normal batch. Batch dispatchers can use shard_count to bound parallel shards and batch_size to set the number of items assigned to each worker.
  • Each shard checks out the selected target repository at main.
  • Codex reviews use GPT-6 Sol. OWNER, MEMBER, and COLLABORATOR-authored issues and pull requests use high reasoning with fast service; other items use medium reasoning with standard service. Sweep planning, assist answers, and close-coverage proofs use the configured ordinary-item defaults. Reviews have a 10-minute per-item timeout.
  • Each item becomes a flat report under records/<repo-slug>/items/<number>.md with the decision, evidence, Codex /review-style PR findings, suggested comment, runtime metadata, and GitHub snapshot hash. When GitHub exposes a merged closing PR for an issue, the report records that PR and the close comment links it as fix provenance.
  • High-confidence allowed close decisions become proposed_close.
  • After publish, the lane checks the selected items' single marker-backed Codex review comment. Missing comments and missing metadata are synced immediately; existing comments are refreshed only when stale, currently weekly.
  • PR review comments keep the top-level note concise, put source links and full evidence in collapsed details, and use hidden verdict/action markers for the trusted ClawSweeper repair loop; see docs/pr-review-comments.md.

Apply Lane

Apply reads existing reports and mutates GitHub only when the stored review is still valid.

  • Updates the single marker-backed Codex automated review comment in place.
  • Closes only unchanged high-confidence proposals.
  • Keeps the durable review comment. Applied PR closes also post one idempotent, marker-backed close receipt; issue closes currently leave the durable review as ClawSweeper's sole comment.
  • Moves closed or already-closed reports to records/<repo-slug>/closed/<number>.md.
  • Moves reopened archived reports back to the repo’s items/ folder as stale.
  • Commits checkpoints and machine-readable status during long runs.

Apply wakes every 15 minutes, no-ops when there are no unchanged high-confidence close proposals, and narrows scheduled runs to the currently eligible proposal list so idle runs do not scan unrelated keep-open records. It defaults to all item kinds, no age floor, a 2-second close delay, and 40 fresh closes per checkpoint, with a hard cap of 40 to keep each GitHub App token within its lifetime. After a checkpoint closes at least one item, it queues another apply run with a fresh token; a saturated scan that closes nothing stops and waits for the next scheduled tick instead of self-dispatching indefinitely.

Apply health keeps the scheduler-admitted apply_ready_count separate from the full promotion backlog, cooldown-eligible probes, proof-required work, guarded retries, and inconsistent records. Its cycle estimate covers work actionable in the current scheduler window rather than presenting every probe as immediately closable.

Exact event runs skip the bulk planner and shard matrix. The read-only reviewer handles only the selected item, uploads a hash-bound GitHub Actions artifact, enqueues a separate durable publication lease, and then releases its review lease without checking out or pushing the state repository. The queue retries publication independently, so a cancelled publisher does not rerun Codex. The source fallback uses adaptive minimum/base/maximum values of 4/24/48; production overrides them with 8/32/32 and enables direct publication plus up to 8 concurrent size-8 batches, with two isolated preparation workers per batch. The Durable Object validates each artifact's workflow run, queue tuple, target, decision digest, file inventory, sizes, and SHA-256 hashes before a publisher receives write tokens. Publication leases reserve the bounded publisher lane's maximum queue wait; terminal-run reconciliation releases dead dispatches early. The publisher then uses the same review and apply paths with only the immediate-safe reasons enabled by default: implemented_on_main, duplicate_or_superseded, and low_signal_unmergeable_pr. A stale tuple now terminates as superseded instead of retrying, while permanent failures enter a bounded dead-letter store after their confirmation retries. Artifacts remain available for 90 days; three confirmed unavailable-artifact attempts queue one fresh exact review instead of waiting for the retention deadline.

Deterministic terminal and remain-open outcomes flow through the same publisher. Ordinary synced verdicts publish their exact durable comment, then queue an executing target-wide comment-router scan. Exact publishers use the bounded Durable Object lane while batch publishers remain per-target serialized. Direct exact-event viable-issue implementation dispatch stays disabled; the bounded broad publish/backfill lane owns that separately revalidated intake. Publication still does not claim an atomic state-publish-and-route boundary. stale_insufficient_info issue reports and mostly_implemented_on_main PR reports are never applied to young items; apply requires those reports to be at least 60 days old unless a manual run explicitly changes the threshold. A stale issue also stays open when a non-bot comment was posted in the last 60 days.

The external state dashboard is fleet-scoped. Each configured repository gets its own canonical record collection, status JSON, audit state, cadence counts, and recent activity section, so event runs from one repo do not hide the state of another.

There is still one deterministic apply path for writes. Review can propose and sync stale public review comments, but closing remains guarded by apply so a fresh GitHub snapshot, labels, maintainer-authorship, and unchanged item state are checked immediately before mutation. Maintainer-authored or maintainer-labeled items can still close when the only protected state is maintainer ownership and the close reason is verified implemented_on_main. Configured OpenClaw targets may close issues as implemented_on_main when the fix is proven on current main, even before the next release ships.

Repair Lane

Repair starts from maintainer intent or trusted ClawSweeper review metadata. The comment router accepts commands from target repositories, validates maintainer permissions, updates one mutable command/status comment, and dispatches the appropriate repair job.

  • autofix and automerge adopt the PR branch and run exact-head review before making changes.
  • If review or CI finds actionable issues, Codex rebases, addresses PR review comments, fixes CI, runs the requested validation, and returns a structured repair artifact.
  • The deterministic executor applies the artifact, pushes only after validation, re-dispatches exact-head review, and waits for required checks.
  • autofix completes by removing its repair-loop label after a clean exact-head review and green required checks, then leaves the PR open for maintainer review and merge.
  • automerge merges only after review verdict, checks, mergeability, security, maintainer stop/approve state, and repository policy gates pass.
  • Repair workers coalesce pending runs for the same durable job while allowing an active execute run to finish its gate cleanup. Stale-head retries use a dedicated run-scoped lane so they can start during that temporary gate window. Before a contributor branch push, ClawSweeper waits 90 seconds by default, fetches the live PR head again, and requeues instead of pushing when that head changed. It also refuses to push when the PR closed during the wait. Override the window with CLAWSWEEPER_BRANCH_PUSH_SETTLE_SECONDS (bounded to 0-120 seconds) when a manual backfill is already settled.
  • An OpenClaw organization member can comment @clawsweeper implement issue; ClawSweeper refuses when an open PR already mentions the issue, a generated branch PR is already open, the issue is paused, or security blockers remain.
  • CLAWSWEEPER_AUTO_IMPLEMENT_ISSUES=1 enables newly reviewed issues and bounded backfill from existing eligible open issue reports. General viable implementation remains limited to public sibling repositories; openclaw/openclaw uses its separately gated strict-bug and vision-fit lanes, and openclaw/clawhub remains excluded.
  • Issue intake and dispatch use ubuntu-latest by default, independently of the Blacksmith runner selected for Codex planning and repair execution.

Repair internals are documented in docs/repair/README.md, and the automerge state machine is documented in docs/repair/automerge-flow.md. The production automerge command chain can be validated before merge with the local-container, CI, and Crabbox harness in docs/repair/automerge-e2e.md.

Commit Review Lane (retired)

The hosted commit-review lane was retired in July 2026 (zero successful runs in its final month). The local, GitHub-isolated review engine survives as pnpm local-review; see docs/commit-sweeper.md.

Safety Model

Native reviews require host-owned TruffleHog admission before any model-backed checkout inspection or review. The host scans the explicit initial prompt and schema plus complete raw before/after blobs and the full introduced diff. Scan coverage is independent of the 80-path/24K-character display evidence limits. Repair reviews scan the committed, staged, unstaged, and applicable untracked bytes of the validated checkout. Clean text-converted checkouts retain both canonical Git and raw working bytes in scan coverage. The host never starts a target-bundled autoreview helper or second reviewer.

Hosted Codex and OpenClaw setup share the checksum-pinned TruffleHog 3.97.4 installer in .github/actions/setup-review-tools/install.sh. For local review, ClawSweeper first qualifies a trusted host executable outside both checkouts; when it is absent or reports a different TruffleHog release, it bootstraps the exact checksum-pinned release asset into a user-owned cache outside both checkouts. The local bootstrap accepts no URL or version override, verifies the download and cached executable, and runs a clean environment version check before scanning. Missing tools, unclassified findings, scan errors, source drift, incomplete ancestry/objects, changed gitlinks, and LFS pointers refuse the review. The scan stages at most 256 MiB in private external temporary files and uses the remaining review deadline; it never silently truncates or bypasses. Diagnostics omit scanner output and source values. Restore prerequisites or remove sensitive input before retrying a refusal. Exact-review failure manifests distinguish a native output/scan-contract failure from an unclassified finding. The latter records the first blocking finding's bounded detector metadata and host-staged material identity: prompt, schema, additional input, raw diff, patch, raw working bytes, or Git blob. Source references contain Git revisions and hashed paths, with at most four references and their total count. No raw paths, matched values, literal digests, or verification messages are retained; this provenance does not authorize a finding.

The host classifies the reviewed synthetic malformed-configuration URI in test/action-ledger-runtime.test.ts and the explicitly approved autoreview negative-test URI in the canonical autoreview test or its vendored OpenClaw copy as non-sensitive after a complete scan. The same exact-fixture policy covers the reviewed OpenClaw Browser CDP authentication and credential-redaction fixtures in chrome.test.ts, the remote-CDP coverage, the server-context redaction test, the profile-status redaction fixture, the remote-CDP documentation example, the credentialed-page rejection fixtures, the guarded CDP authentication fixtures, the MCP endpoint-redaction fixture, the Crabbox fleet audit sanitization fixture, the Mac dashboard credentialed-subframe rejection fixture, the Mattermost slash-error sanitization fixtures, the MCP Apps sandbox-origin rejection fixture, the Gateway config CDP-redaction fixture, the mocked marketplace telemetry-redaction fixture, the Signal URL-rejection fixtures in client tests and container tests, and the OpenClaw config URL-redaction and restoration fixtures after a complete scan. Static host policy associates each exact detector-matched URI SHA-256 with only its approved source paths and exact scanner Raw digest, including when Raw omits a path retained by RawV2. The matched value must be a literal in a host-staged Git blob from mode 100644. The three guarded-CDP/MCP entries, Crabbox fixture, Mac dashboard entry, MCP Apps entry, marketplace telemetry entry, Gateway config entry, two Signal entries, and four Mattermost entries also bind complete reviewed source lines, including surrounding query text that TruffleHog's URI detector does not match. Changes to those lines or additional literal occurrences refuse classification. These witnesses do not expand native query detection. The table binds exact values and paths across revisions, not particular commits. The host locates that exact literal independently in the staged blob. Decoder coordinates can shift, and TruffleHog can omit a companion plain-text finding, so admission does not depend on another finding or a reported line matching the original source. Repeated literals remain eligible unless an entry is bound to an approved complete-line digest; those entries require exactly one occurrence in the staged blob. Finding order and duplicate records do not change the exact value, path, and mode checks. Findings must use PLAIN or HTML, except the Mac dashboard, MCP Apps, marketplace telemetry, and Gateway config entries permit only their observed PLAIN decoder and the two guarded-CDP fixtures also permit BASE64. The pinned Base64 decoder preserves the rest of a chunk after decoding another token, so an unchanged literal can acquire that decoder label and win cross-decoder deduplication. Those entries still require the literal in its exact original source line; encoded-only content remains blocking.

The OpenClaw logging redaction fixtures and the reviewed Crabbox PostgreSQL operations example use a separate flat attribution table without changing the legacy URI policy above. Each row binds the exact detector ID and name, observed native decoder, Raw, RawV2, and complete source-line SHA-256 digests, path, and mode. The logging rows permit only their observed PLAIN or ESCAPED_UNICODE variants; the Crabbox documentation row permits only its observed PLAIN or HTML variants. These exact attribution rows are role-neutral; every logical staged reference must independently match the row and have a committed base or head role. URI findings require one literal RawV2 witness unless the row declares an exact ordered sequence of complete source-line digests. A declared sequence must match every occurrence exactly; missing, extra, reordered, or changed lines refuse admission. Derived host, username, and password fields must match native metadata; the host preserves explicit default ports and original spelling, as TruffleHog does. MongoDB and Postgres findings bind the scanner-reported line and their exact native metadata shape. Any emitted subset and order may qualify; duplicate exact findings, unknown variants, lossy decoder buckets, or an unqualified deduplicated blob reference refuse admission.

The same table qualifies the exact embedded-credential rejection fixture in OpenClaw's extensions/matrix/src/matrix/client.test.ts for URI detector 17, only with PLAIN or HTML attribution. Both raw-value digests, the complete source line, path, regular-file mode, and committed base/head references must match. Retained source-only native scans observed PLAIN findings; the original hosted refusal identified HTML for its first finding but did not retain the second finding's details. Constructed HTML regression records are not recovered hosted evidence. Qualification does not waive that unknown finding or replace fresh whole-input admission and a completed review.

The same table qualifies the existing OpenClaw browser URL-port precedence fixtures. The HTTPS input and assertion require their exact two-line sequence; the two loopback fixtures each require one complete source line. Only URI detector 17, PLAIN/HTML, the pinned raw-value identities, regular-file mode, and committed base/head references qualify. The native proof for PR #149651 observed PLAIN findings; HTML is separately covered by constructed classifier records.

The marketplace entries telemetry test uses the same reviewed feed URI twice, in live and snapshot metadata. Its exact attribution binds both complete source lines in order, URI detector 17, observed PLAIN or HTML decoding, regular-file mode, and committed base/head roles. The refresh test keeps its existing legacy approval and repair roles. Policy selection follows the staged source references, including each patch witness, so a shared URI does not transfer changed-line approval or duplicate-record rules between these sources. See the native proof.

Six existing Crabbox scope-normalization and redaction fixtures use the same exact attribution table, limited to their observed URI detector 17 / PLAIN results. Both raw digests, each complete source line (including the ordered pair for the repeated fixture), the three original test paths, regular-file mode, and every committed base/head reference must match. No test file is exempt from scanning. See the qualification contract and native proof.

The Gateway readiness error-privacy fixture in OpenClaw's readiness test is also qualified by this table. The exact URI detector 17 identities, complete source line (including the surrounding synthetic payload expression), regular-file mode, and committed base/head references must match. Native 3.97.4 scans observed PLAIN and HTML; only those two variants qualify. See the native proof.

The browser CDP discovery fixture in extensions/browser/src/browser/pw-session.connections.test.ts uses the same exact table for its observed URI detector 17 PLAIN and HTML findings. Both raw-value digests, the complete source line, original path, regular-file mode, and committed base/head references must match. See the native proof.

The TypeSafe local-transport URL-rejection fixture in extensions/typesafe/src/local.transport.test.ts binds its exact URI detector 17 identities, full source line, regular-file mode, and committed base/head references. Native 3.97.4 scans observed PLAIN and HTML; only those variants qualify. See the native proof.

The native-worker endpoint and startup-config rejection fixtures in transport tests and startup tests qualify only through their exact URI-17 PLAIN/HTML attribution, both value digests, complete source lines, regular-file mode and committed source references. No whole test file is exempt. See the native source-admission proof.

One source path may contain multiple independently reviewed fixtures; each digest/path/mode tuple must match exactly, so source membership alone never qualifies a finding. The model-egress fixtures in OpenClaw's Crabbox model runner and configured model egress tests qualify three synthetic URI identities using their complete source lines and committed regular-file references. Native TruffleHog 3.97.4 observed PLAIN and HTML for each identity; only those variants qualify. See the native proof. Deduplicated blobs retain every scanned logical endpoint's role, path, and Git mode, including mode-only transitions and shared-path aliases. Every captured reference must qualify under the same exact attribution policy before any source is eligible for classification or an audit notice. The policy does not trust checkout ignore rules, domain patterns, fixture words, test names, or unchanged-line inference; no nearby fixture is implicitly approved. When review evidence quotes an exact reviewed synthetic URI, prompt preparation replaces the URI with a visible reference to its source file, preserving closing Markdown and sentence punctuation. The original context is preserved, and changed paths, credentials, or additional query text remain untouched. This omission does not classify a native finding or prove its verification status. Source blobs, introduced patches, and scanner admission retain their existing checks. The create-profile response-redaction fixture in OpenClaw's extensions/browser/src/browser/profiles-service.test.ts also binds its exact URI identity, complete source line, regular-file mode, and committed base/head references. Native 3.97.4 scans observed only PLAIN and HTML attribution; the policy accepts those two variants.

The plugin settings redaction fixtures in OpenClaw's ui/src/pages/custodian/custodian-session-store.test.ts and ui/src/e2e/plugins-help.e2e.test.ts bind their exact synthetic URI, ordered complete source lines, regular-file mode, and committed base/head references. Native 3.97.4 scans observed PLAIN and HTML attribution for these fixtures; only those exact tuples qualify.

The autoreview hardening negative-test fixtures in skills/autoreview/tests/test_autoreview_hardening.py and its OpenClaw mirror at .agents/skills/autoreview/tests/test_autoreview_hardening.py use the same exact attribution table. URI detector 17, each row's qualified PLAIN or HTML decoder, both pinned raw-value digests, every complete source line in order, regular-file mode, and committed base/head references qualify. The existing legacy value-only row stays available for review-context omission; changed patch lines require these exact tuples. No other literal or source line in either test file is implicitly approved. The additional empty-username and encoded-NUL identities permit only their observed PLAIN decoding. See the repeated native proof.

The full generated patch remains scanned. Every literal occurrence of an eligible URI must bind to committed regular-file bytes through canonical same-path headers, full Git object IDs, hunk coordinates, counts, and newline markers. Unchanged context requires the identical full line in both blobs. Added lines require the head blob; removed lines require the base blob, and both require exact ordered full-line attribution policy. Legacy value/path-only rows remain context-only. Every retained blob reference must independently pass the existing fixture policy. New and deleted files additionally require one matching host-captured raw Git diff record proving the absent endpoint, correct zero object ID and mode, and the complete present-file hunk. A textual /dev/null header or missing blob is not absence proof; contradictory captured references refuse admission. Headers containing the URI, binary patches, ambiguous paths, mode changes, uncommitted endpoints, and encoded-only matches remain blocking. Decoder line coordinates are diagnostic only; source matching does not rely on them. Patch notices retain the original material ID, scanner line, decoder, and literal line, with patch provenance recording both revisions and each source blob/line. The prompt omission helper is never applied to scan input. See the reproducible admission proof.

CloudflareGlobalApiKey detector 58 can pair Git's generated 40-character blob IDs with nearby email context. An unverified PLAIN/HTML finding in a patch or raw diff requires a separate provenance scan only when every literal occurrence is an exact object-ID field in canonical same-path regular-file patch/raw-diff headers. Modified executable files also qualify when both endpoint modes remain 100755; their raw records, patch headers, and blob references must agree on that mode. Executable additions/deletions, mode changes, and symlinks remain unsupported. The two endpoint revisions, paths, modes, and full staged blobs must agree; the host independently rehashes each present blob. Added and deleted files require matching zero endpoints, mode/status fields, patch headers, and absence of source references at the missing endpoint. Raw records and matching patch sections must be unambiguous; malformed, duplicate, or unmatched records refuse. The matched bytes must be absent from every staged prompt, schema, additional input, raw working file, and full blob, preventing detector deduplication from hiding a content occurrence. Missing retained bytes, unsupported metadata, malformed native fields, verified findings, and scanner errors still refuse. The complete patch, raw diff, and blobs remain scanned unchanged. Metadata notices identify their classification and use a SHA-256 digest in the existing notice identity field; matched object IDs and verification values are never emitted. OpenClaw Bay is unaffected.

Those witnesses alone never admit a review: HTML decoding can create another matching value from source content while its reported line differs from the original bytes. The host scans a second complete copy of each affected patch or raw diff with only the proven object-ID fields masked at their original lengths. All filename context and content bytes remain unchanged, and the staged bytes record that actual masked copy. The same pinned scanner, verification flags, completion checks, and shared deadline apply. Any remaining unclassified finding or request for metadata proof refuses admission; success notices are emitted only after this replay and the final source fences. Raw-diff replay has no fixture-admission route: any remaining finding refuses. Existing URI-only reviews retain their original single scan.

Findings attributed to prompt, schema, additional-input, other-path, or unqualified patch material remain blocking, as do other findings, verified findings, and incomplete scans. Unverified findings alone never qualify: every finding must match the exact bytes, source association, and strict detector contract. This classification does not expand TruffleHog's detection coverage. The classification is pinned to TruffleHog 3.97.4's output contract; scanner upgrades require requalification. See src/agent-input-scan-fixtures.ts. After successful cleanup and final source fences, each accepted fixture/source pair emits a host-side structured stderr notice with event, fixtureSha256, source, detector, and findings entries containing blob, decoder, and occurrences; role-bound findings also include role. Each finding retains its reported scannerLine and a literalLine for the first exact literal in the staged blob. This bounded witness establishes literal presence; it does not identify which occurrence produced a decoded hit. Counts are per source: a shared blob can appear in both source notices and those counts must not be summed across sources. A refused or drifted scan emits no success notice. Raw values and verification diagnostics never appear in that audit notice.

Generated review and repair prompt diagnostics retire the previous attempt's copy before admission and persist only successfully scanned exact prompt bytes with owner-only access. Commit review, assist, and close-coverage proof do not retain unused prompt copies. Original inputs and explicitly requested prompt exports (repair:render or worker --dry-run) remain operator-owned outputs.

This admission boundary is not universal provider-egress scanning. Automatically loaded project docs, resumed/steered history, later tool results, and unchanged repository history are outside its scope. Planning, assist, and close-coverage calls scan their explicit prompt/schema; they do not attest a source review. No dashboard projection or observer API changes; OpenClaw Bay is unaffected.

Maintainers can run the dispatch-only Hosted native review scan smoke job in ci.yml. It uses the existing OPENAI_API_KEY and CLAWSWEEPER_MODEL secrets only during host setup, with no App mutation token. The proof artifact records zero Codex launches on refusal, then proves the production review path completed a read-only command over a synthetic committed diff before returning a schema-valid decision and terminal turn. Raw commands, output, prompts, transcripts, fixture values, runner identities, and model identities stay in ephemeral private files; the uploaded artifact contains only booleans and counts, including explicit false coverage flags for external repositories, review publication, and queue lifecycle.

  • Review and repair base fetches use fully qualified branch refspecs so inherited fetch.prune or remote.origin.prune settings do not delete the requested tracking ref. Validation uses the same repair fetch helper; no host Git configuration changes are required.
  • Maintainer-authored items are excluded from automated closes unless the close reason is verified implemented_on_main.
  • Protected labels block close proposals.
  • Apply rechecks older skipped fixed-close reports and archives skipped item records when GitHub already shows the item closed.
  • Apply can retry older kept_open close reports and clear linked-PR issue blockers after ClawSweeper closes the PR earlier in the same apply run.
  • Open PRs with GitHub closing references block issue closes until the PR is resolved or closed earlier in the same apply run.
  • Open same-author issue/PR pairs block one-sided closes.
  • Codex runs without GitHub write tokens.
  • Issue/PR event jobs create target write and report-push credentials only after Codex exits.
  • The retired hosted commit-review lane no longer mints target credentials; pnpm local-review operates on the local branch range without GitHub writes.
  • CI keeps the target checkout read-only and gives Codex issue/PR reviewers a managed network proxy restricted to the hosts in the review permission profile: GitHub, npm, Node, MDN, and OpenClaw documentation. Limited mode inspects HTTPS and permits only GET/HEAD/OPTIONS; other hosts are blocked. When supplied by the review job, Codex tools receive the target repository's read-only GitHub App token only as GH_TOKEN (contents, issues, and pull requests read; expires within the hour). Use authenticated GitHub reads to avoid public rate limits; never put the token in a URL, log it, or send it to a non-GitHub host. Without a token, use public endpoints and pre-fetched context. Read downloaded media through the local proof manifest. A blocked request is not evidence against a PR. Setup must prove allowed HTTPS, denied unlisted HTTPS, and denied checkout writes before reviews can publish. Offline local reviews retain their existing network restriction. The review-network-smoke PR CI job proves the same enforcement on Ubuntu without secrets. Capability text follows the active runner: OpenClaw uses gateway network execution without the Codex proxy or filesystem sandbox, strips GitHub tokens through its final child environment allowlist, and must keep the checkout read-only by instruction.
  • Reviews fail if Codex leaves tracked or untracked changes behind.
  • Snapshot changes block apply unless the only change is the bot’s own review comment.
  • The retired hosted commit-review lane no longer publishes Commit Check Runs.

Audit

pnpm run audit compares live GitHub state with generated records without moving files. It reports missing open records, archived open records, stale records, duplicates, protected-label proposed closes, and stale review-status records. Protected proposed closes are reported only for active repo items/ records because archived repo closed/ records are historical and cannot be applied. Missing open records are classified as eligible, maintainer-authored, protected, or recently created so strict audit mode can flag actionable drift without treating expected queue lag or excluded items as failures. Use --update-dashboard to publish the latest audit state under results/audit/ in openclaw/clawsweeper-state without making every normal status update scan all open GitHub items. The state repo renders reviewable findings such as missing eligible records, reopened archived records, and stale reviews from that state. The workflow refreshes audit state on a separate six-hour schedule, and it can be run manually with audit_dashboard=true. The read-only audit lane covers openclaw/openclaw, openclaw/clawhub, and openclaw/clawsweeper; it falls back to public workflow-token reads when the ClawSweeper App token is not available for a target.

Local Run

Requires Node 24.

Issue/PR sweeper:

source ~/.profile
corepack enable
pnpm install
pnpm run build
pnpm run plan -- --target-repo openclaw/openclaw --batch-size 5 --shard-count 89 --max-pages 250 --codex-model internal
pnpm run review -- --target-repo openclaw/openclaw --target-dir ../openclaw --batch-size 5 --max-pages 250 --artifact-dir artifacts/reviews --output-retention debug --codex-model internal --codex-timeout-ms 600000
pnpm run apply-artifacts -- --target-repo openclaw/openclaw --artifact-dir artifacts/reviews --skip-dashboard
pnpm run audit -- --target-repo openclaw/openclaw --max-pages 250 --sample-limit 25 --update-dashboard
pnpm run reconcile -- --target-repo openclaw/openclaw --dry-run

Advisory exact local issue/PR review:

For Codex users, the repo-local skill $local-clawsweeper-review wraps this workflow with setup checks, target checkout hygiene, and artifact readout. Skill usage is documented in docs/local-clawsweeper-skill.md.

codex login --device-auth -c 'service_tier="fast"'
pnpm run codex:local:check
pnpm run review -- --local-only --target-repo owner/name --item-number 123

review is the single issue/PR review command. --local-only makes it an advisory local run: it skips the review-start placeholder comment, defaults the Codex service tier to fast for local CLI compatibility, and preserves local Codex auth. Persistent output is opt-in. The default --output-retention none uses private run-owned scratch, prints the result, and removes scratch after ordinary completion or a caught failure. Operating-system termination keeps its default behavior so cancellation is not delayed by synchronous review work; an unhandled signal or SIGKILL can leave the bounded private scratch behind. Use --output-retention summary for the report without raw prompt/stream files, or --output-retention debug for the existing artifact tree. An explicit legacy --artifact-dir still selects debug retention. Summary destinations are created exclusively for one invocation. Managed transient output is capped at 96 MiB/256 files; managed debug output is capped at 1 GiB/4,096 files with per-item allocations and at most 128 selected items per invocation. Existing destination files count toward these limits. Metadata, cached and fresh reports, and model output use the same run admission checks. None and summary batches hash each item's report and stream evidence into the canonical ledger before pruning that item's run-owned engine files; summary retains only the reports. Required pull-request checkouts use a separate private run workspace: tracked paths and Git blob sizes are admitted before materialization, with a 2x allowance for bounded EOL expansion. Active filters, working-tree encodings, and ident expansion are refused through a bounded private Git index compatible with Git 2.39. That index reserves at most two files/128 MiB plus the workspace disk reserve before creation and is removed after inspection. Checkout hooks are disabled. Projected and actual checkout usage is capped at 200,000 files/2 GiB, and 1 GiB remains reserved on each filesystem used for checkout materialization or missing Git object acquisition; a shared filesystem is charged once. Media proof downloads use at most 64 MiB per debug item and derived metadata/contact sheets at most 16 MiB, subject to the remaining run byte and file allowances. Non-debug items use at most 32 MiB and 8 MiB respectively. Media admission reserves the non-media output pools before starting another download or transcode. These are producer admission and retained-output limits, not a peak disk quota: curl and ffmpeg can temporarily exceed their requested limits, and arbitrary model-written files are not quota-controlled. Oversized managed media output is discarded. Existing or unrelated retained runs are never pruned automatically. --result-format json returns the same result as valid JSON.

pnpm run review -- --local-only \
  --target-repo owner/name \
  --item-number 123 \
  --target-dir ../target-checkout \
  --output-retention summary

Pre-submission committed-range review uses the same full proof-aware review without requiring an open GitHub item. From the clean checkout containing the branch to review:

pnpm run review -- --local-range \
  --target-repo openclaw/clawsweeper \
  --base origin/main

Without --target-dir, --local-range reviews the checkout where the command was invoked. Pass --target-dir <path> when invoking ClawSweeper from a different checkout. The range is merge-base(<base>, HEAD)..HEAD, includes committed work only, and refuses a dirty working tree. --body-file can supply the proposed PR body and --additional-policy can layer an extra local policy.

This mode withholds GitHub token variables, points gh at an empty config directory inside private run scratch, disables Codex web search, skips host-side URL/media preprocessing, and makes no GitHub reads or writes. It is not air-gapped: the Codex model invocation still uses its configured network service. Debug local reviews preserve the latest local result in the same bounded review-history format used by hosted review. The next debug run receives the previous findings and dispositions so it can verify fixes and avoid re-raising resolved findings. Summary retention keeps only the current reports. In debug mode, exact-item history stays in the selected artifact directory. Committed-range debug history stays under .git/clawsweeper/reviews/ and is reused only for the same target repository and resolved base when its reviewed commit is an ancestor of the current HEAD; changing the base or switching to an unrelated branch starts a fresh history.

Summary/debug reports use a unique .git/clawsweeper/reviews/local-range-<time>-<pid>/ directory unless --artifact-dir overrides it. Default no-retention runs leave no persistent ClawSweeper review directory.

When output is retained at the default local artifact destination, read the report at artifacts/local-review-<number>/<number>.md. Key fields are review_status, main_sha, pull_head_sha, decision, confidence, and Review Findings. Do not run apply-artifacts or apply-decisions unless you intentionally want to move reports into durable state or sync GitHub comments. Add --verbose when you need the underlying [review] diagnostic logs.

If you prefer API-key auth, keep the key out of the repository and shell history. For POSIX shells:

printf '%s' "$OPENAI_API_KEY" | codex login --with-api-key -c 'service_tier="fast"'
unset OPENAI_API_KEY

For PowerShell:

$env:OPENAI_API_KEY = Read-Host "OpenAI API key"
$env:OPENAI_API_KEY | codex login --with-api-key -c 'service_tier="fast"'
Remove-Item Env:OPENAI_API_KEY

--local-only preserves local Codex auth environment variables only for that advisory local run. Normal production review workers still strip Codex, OpenAI, and GitHub write credentials before invoking the model. Set CODEX_BIN to an absolute executable path if the desired Codex CLI is not the first spawnable binary on PATH.

Apply unchanged proposals later:

source ~/.profile
corepack enable
pnpm run apply-decisions -- --target-repo openclaw/openclaw --limit 40 --apply-kind all --skip-dashboard

Sync durable review comments without closing:

source ~/.profile
corepack enable
pnpm run apply-decisions -- --target-repo openclaw/openclaw --sync-comments-only --comment-sync-min-age-days 7 --processed-limit 1000 --limit 0 --skip-dashboard

Manual review runs are proposal-only. Use apply_existing=true to apply unchanged proposals later. Scheduled apply runs process both issues and pull requests by default, subject to the selected repository profile; pass target_repo, apply_kind=issue, or apply_kind=pull_request to narrow a manual run.

Scheduled runs cover the configured product profiles. openclaw/openclaw runs normal backfill hourly; scheduled hot intake and normal backfill share a 32-worker cap in the durable review queue. openclaw/clawhub runs on offset review/apply/audit crons so its reports live under records/openclaw-clawhub/ without colliding with default repo records. openclaw/clawsweeper has a scheduled read-only audit row and is available for manual and event self-review smoke tests. Broad hot-intake sweeps use the queue's scheduled admission budget; manual normal and hot-intake matrices have at most 89 and 44 slots when quiet, while exact event reviews still use one shard. Normal review and hot intake are background lanes, so they shrink automatically while repair or exact-item work is active. Throughput defaults live in docs/limits.md and config/automation-limits.json.

Worker Budget

ClawSweeper has one main capacity knob: config/automation-limits.json -> workers.max. The current value is 128. This is a Codex worker budget, not a GitHub Actions runner limit. Deterministic exact-review publishers, comment routers, and lease reconcilers are control-plane workflows and do not consume these 128 slots. Lane limits are derived from that number: manual normal review defaults to 89 requested shards and hot intake to 44; the interactive and expansion reserves leave 104 background slots when quiet. Scheduled work has a separate 32-slot admission cap and a 60-review/hour target with a six-item burst. The existing repair/issue implementation lanes use 40% of workers.max, currently 51 live workers. Imported gitcrawl cluster repair allows 2 live workers by default. Exact-item review, repair, and issue implementation are priority work; normal review and hot intake are background work and automatically yield when priority work is active. Exact-item runs use a durable Worker queue that coalesces item deliveries, leases at most 80 concurrent reviews, and admits up to 64 active exact reviews per target repository. Other lanes use the checked-in 128-worker scheduling model. A separate 194-slot exact-review Actions budget supports the production maximum of 32 legacy publisher slots, the enforced 16-slot control-plane reserve, and additional Actions headroom without raising the Codex review ceiling. Use workers.max first when turning total Codex usage up or down; use lanes.repair.cluster_max_live_runs to tune the imported legacy cluster-repair lane separately, and individual environment overrides only for temporary lane-specific exceptions.

Target repositories can opt into event-level latency by installing the dispatcher workflow in docs/target-dispatcher.md. The dispatcher sends repository_dispatch events to this repository with the target repo and exact item number; ClawSweeper then runs one event job that reviews, comments, and checks immediate safe apply instead of waiting for the next hot-intake cron or bulk publish lane.

Checks

pnpm run check
pnpm run oxformat

oxformat is an alias for oxfmt; there is no separate oxformat pnpm package. The CI GitHub Actions workflow uses the latest Node 24 release and runs pnpm run check on pushes, pull requests, and manual dispatches. The check gate includes the full test suite, a strict changed-surface coverage threshold, and a full compiled-repo coverage ratchet. It builds once, runs independent static and lint checks with bounded phase-level parallelism, and uses the full coverage run as the single source of complete test results. Standalone test, test:repair, and coverage commands still build their required outputs; their internal *:no-build variants are for the composed gate after build:all.

Node test files are expanded by scripts/run-node-tests.mjs instead of the shell, so the same targets work on Linux, macOS, and Windows. The runner defaults to the smaller of the machine's available parallelism and 16, prints the chosen value, and accepts an explicit --test-concurrency override for diagnostics. CLAWSWEEPER_TEST_CONCURRENCY sets the default for CLI runs when that flag is absent, allowing controlled concurrency experiments through package scripts. CI retains the adaptive default. Crabbox diagnostic bundles under .crabbox/ are generated scratch and are ignored by Git.

On Linux and macOS, the shared synthetic GitHub CLI fixtures clear NODE_V8_COVERAGE before starting their Node stand-ins. Those fixtures do not execute ClawSweeper source; interrupting their profile writes must not break the real coverage report. Production subprocesses keep inherited coverage. Other fixture launchers and Windows retain their existing behavior.

GitHub Actions Setup

Required secrets:

  • OPENAI_API_KEY: OpenAI API key used by the per-job local Codex Responses proxy. Codex subprocesses inherit only the proxy-backed CODEX_HOME, not the raw API key.
  • CLAWSWEEPER_APP_CLIENT_ID: public GitHub App client ID for clawsweeper. Currently Iv23liOECG0slfuhz093.
  • CLAWSWEEPER_APP_PRIVATE_KEY: private key for clawsweeper; plan/review jobs use a short-lived GitHub App installation token for read-heavy target API calls, and apply/comment-sync/check jobs use the

    (README truncated)

View on GitHub

Recent activity

commits and pull requests

Recent open issues

view all

Releases and announcements

3 total
  1. ClawSweeper 0.2.0v0.2.0May 3, 2026

    ### Added - Accepted `@clawsweeper fix` as a short issue implementation command that creates or updates one guarded ClawSweeper PR for an open issue. - Added an `openclaw/openclaw` active review-shard floor so scheduled normal review keeps capacity warm around the clock even when the due backlog is temporarily below full shard capacity. - Added coarse automerge repair progress updates to the existing mutable status timeline for validation, Codex edit, review, base-sync, and wait phases. ### Changed - Switched the shared Codex setup action to a per-run `CODEX_HOME` with a local Responses proxy so Codex subprocesses no longer inherit raw OpenAI/Codex API key environment variables. - Replaced duplicate-lobster command status badges with one lobster plus a state emoji for acknowledgement, review, repair, and completed/paused work. - Kept broad review continuations warm and faster by preserving the `openclaw/openclaw` active shard floor, stopping saturated planning once capacity is full, capping optional pre-shard dashboard publishes, and moving broad continuation comment sync into the separate comment-sync lane. - Removed the expensive record reconciler from pre-shard planning stat

  2. ClawSweeper 0.1.0v0.1.0May 3, 2026

    ### Added - Scaffolded ClawSweeper as a conservative OpenClaw maintainer bot that writes one markdown review record per open issue or pull request. - Added proposal-only review flow plus an explicit apply mode for unchanged, high-confidence close proposals. - Added targeted single-item review support. - Added README dashboard links to generated item reports, fixed evidence, issue and PR close-rate metrics, cadence coverage, workflow status, and apply status. - Added archived `closed/` records so `items/` can stay focused on open tracked items. - Added a read-only audit command for checking live GitHub state against generated `items/` and `closed/` records. Thanks @stainlu. - Added review runtime metadata to detail reports, including model and reasoning effort. - Added MIT licensing. - Added durable Codex automated review comments that are updated in place before any close action. - Added a separate hourly apply/comment-sync workflow lane that can run alongside review work. - Added a five-minute hot-intake review lane for new and recently active issues or pull requests, fanning out single-item review shards. - Added targeted comment-sync mode so hot-intake review

  3. ClawSweeper 0.3.0v0.3.0Jun 15, 2026

    Verification: [CI](https://github.com/openclaw/clawsweeper/actions/runs/27581772359) and [CodeQL](https://github.com/openclaw/clawsweeper/actions/runs/27581772288) passed on the release commit. ### Added - Added typed, durable, proposal-only root-cause cluster assessments to reviews, with strict same-repository canonical-item validation and no repair dispatch, job suppression, sibling mutation, close, or merge behavior. - Added a fail-closed `CLAWSWEEPER_CODEX_LOGIN_METHOD=chatgpt` override for local Codex OAuth runs while retaining API authentication by default. Thanks @anagnorisis2peripeteia. - Added repair-only PR intake that scans an author's open pull requests for actionable failures and creates durable PR-repair jobs. Thanks @Jhacarreiro. - Added automatic issue-build lifecycle comments and dashboard cards with issue titles, queued/planning/building/completed/blocked history, live worker links, Actions runs, and generated PR drill-down. - Show issue and pull request titles alongside target numbers on active dashboard worker cards and worker detail links. - Added comprehensive documentation for steerable repair automation, covering issue-to-PR and PR-repair intake, GitCrawl

Code frequency

additions and deletions
+227.6K-227.6KWeek of 2026-04-19: +14,621 linesWeek of 2026-04-19: -9,805 linesWeek of 2026-04-26: +190,797 linesWeek of 2026-04-26: -142,635 linesWeek of 2026-05-03: +10,194 linesWeek of 2026-05-03: -1,656 linesWeek of 2026-05-10: +10,769 linesWeek of 2026-05-10: -1,192 linesWeek of 2026-05-17: +29,591 linesWeek of 2026-05-17: -6,341 linesWeek of 2026-05-24: +12,885 linesWeek of 2026-05-24: -5,027 linesWeek of 2026-05-31: +14,086 linesWeek of 2026-05-31: -1,306 linesWeek of 2026-06-07: +27,582 linesWeek of 2026-06-07: -18,408 linesWeek of 2026-06-14: +17,644 linesWeek of 2026-06-14: -8,387 linesWeek of 2026-06-21: +18,319 linesWeek of 2026-06-21: -14,479 linesWeek of 2026-06-28: +14,175 linesWeek of 2026-06-28: -2,073 linesWeek of 2026-07-05: +32,316 linesWeek of 2026-07-05: -3,298 linesWeek of 2026-07-12: +227,649 linesWeek of 2026-07-12: -132,729 linesWeek of 2026-07-19: +56,071 linesWeek of 2026-07-19: -5,668 linesWeek of 2026-07-26: +120,995 linesWeek of 2026-07-26: -95,377 linesWeek of 2026-08-02: +45,246 linesWeek of 2026-08-02: -20,128 linesWeek of 2026-08-09: +149,561 linesWeek of 2026-08-09: -45,469 linesWeek of 2026-08-16: +29,475 linesWeek of 2026-08-16: -5,440 linesApr 19, 2026Aug 16, 2026
+1M lines added, -519.4K removed over the last year.

Commits per week

last 52 weeks
40360Week of 2025-10-05: 0 commitsWeek of 2025-10-12: 0 commitsWeek of 2025-10-19: 0 commitsWeek of 2025-10-26: 0 commitsWeek of 2025-11-02: 0 commitsWeek of 2025-11-09: 0 commitsWeek of 2025-11-16: 0 commitsWeek of 2025-11-23: 0 commitsWeek of 2025-11-30: 0 commitsWeek of 2025-12-07: 0 commitsWeek of 2025-12-14: 0 commitsWeek of 2025-12-21: 0 commitsWeek of 2025-12-28: 0 commitsWeek of 2026-01-04: 0 commitsWeek of 2026-01-11: 0 commitsWeek of 2026-01-18: 0 commitsWeek of 2026-01-25: 0 commitsWeek of 2026-02-01: 0 commitsWeek of 2026-02-08: 0 commitsWeek of 2026-02-15: 0 commitsWeek of 2026-02-22: 0 commitsWeek of 2026-03-01: 0 commitsWeek of 2026-03-08: 0 commitsWeek of 2026-03-15: 0 commitsWeek of 2026-03-22: 0 commitsWeek of 2026-03-29: 0 commitsWeek of 2026-04-05: 0 commitsWeek of 2026-04-12: 0 commitsWeek of 2026-04-19: 557 commitsWeek of 2026-04-26: 4036 commitsWeek of 2026-05-03: 108 commitsWeek of 2026-05-10: 97 commitsWeek of 2026-05-17: 122 commitsWeek of 2026-05-24: 56 commitsWeek of 2026-05-31: 36 commitsWeek of 2026-06-07: 61 commitsWeek of 2026-06-14: 60 commitsWeek of 2026-06-21: 27 commitsWeek of 2026-06-28: 36 commitsWeek of 2026-07-05: 80 commitsWeek of 2026-07-12: 926 commitsWeek of 2026-07-19: 182 commitsWeek of 2026-07-26: 125 commitsWeek of 2026-08-02: 51 commitsWeek of 2026-08-09: 80 commitsWeek of 2026-08-16: 48 commitsWeek of 2026-08-23: 58 commitsWeek of 2026-08-30: 155 commitsWeek of 2026-09-06: 99 commitsWeek of 2026-09-13: 39 commitsWeek of 2026-09-20: 70 commitsWeek of 2026-09-27: 0 commitsOct 5, 2025Sep 27, 2026
7.1K commits in the last 52 weeks.

When work happens

weekday and hour
SunMonTueWedThuFriSat036912151821Sun 0:00 — 42 commitsSun 1:00 — 45 commitsSun 2:00 — 76 commitsSun 3:00 — 99 commitsSun 4:00 — 100 commitsSun 5:00 — 62 commitsSun 6:00 — 77 commitsSun 7:00 — 60 commitsSun 8:00 — 93 commitsSun 9:00 — 71 commitsSun 10:00 — 88 commitsSun 11:00 — 53 commitsSun 12:00 — 57 commitsSun 13:00 — 46 commitsSun 14:00 — 55 commitsSun 15:00 — 51 commitsSun 16:00 — 56 commitsSun 17:00 — 44 commitsSun 18:00 — 52 commitsSun 19:00 — 44 commitsSun 20:00 — 38 commitsSun 21:00 — 52 commitsSun 22:00 — 45 commitsSun 23:00 — 54 commitsMon 0:00 — 36 commitsMon 1:00 — 39 commitsMon 2:00 — 45 commitsMon 3:00 — 39 commitsMon 4:00 — 40 commitsMon 5:00 — 57 commitsMon 6:00 — 31 commitsMon 7:00 — 33 commitsMon 8:00 — 41 commitsMon 9:00 — 43 commitsMon 10:00 — 45 commitsMon 11:00 — 22 commitsMon 12:00 — 28 commitsMon 13:00 — 25 commitsMon 14:00 — 38 commitsMon 15:00 — 31 commitsMon 16:00 — 20 commitsMon 17:00 — 17 commitsMon 18:00 — 21 commitsMon 19:00 — 35 commitsMon 20:00 — 25 commitsMon 21:00 — 30 commitsMon 22:00 — 40 commitsMon 23:00 — 36 commitsTue 0:00 — 28 commitsTue 1:00 — 36 commitsTue 2:00 — 57 commitsTue 3:00 — 41 commitsTue 4:00 — 40 commitsTue 5:00 — 23 commitsTue 6:00 — 130 commitsTue 7:00 — 150 commitsTue 8:00 — 84 commitsTue 9:00 — 70 commitsTue 10:00 — 55 commitsTue 11:00 — 46 commitsTue 12:00 — 78 commitsTue 13:00 — 41 commitsTue 14:00 — 65 commitsTue 15:00 — 63 commitsTue 16:00 — 61 commitsTue 17:00 — 72 commitsTue 18:00 — 57 commitsTue 19:00 — 39 commitsTue 20:00 — 39 commitsTue 21:00 — 50 commitsTue 22:00 — 64 commitsTue 23:00 — 66 commitsWed 0:00 — 39 commitsWed 1:00 — 35 commitsWed 2:00 — 33 commitsWed 3:00 — 46 commitsWed 4:00 — 24 commitsWed 5:00 — 30 commitsWed 6:00 — 30 commitsWed 7:00 — 48 commitsWed 8:00 — 45 commitsWed 9:00 — 85 commitsWed 10:00 — 96 commitsWed 11:00 — 62 commitsWed 12:00 — 54 commitsWed 13:00 — 49 commitsWed 14:00 — 59 commitsWed 15:00 — 58 commitsWed 16:00 — 48 commitsWed 17:00 — 52 commitsWed 18:00 — 49 commitsWed 19:00 — 49 commitsWed 20:00 — 48 commitsWed 21:00 — 44 commitsWed 22:00 — 31 commitsWed 23:00 — 47 commitsThu 0:00 — 33 commitsThu 1:00 — 35 commitsThu 2:00 — 52 commitsThu 3:00 — 39 commitsThu 4:00 — 32 commitsThu 5:00 — 34 commitsThu 6:00 — 21 commitsThu 7:00 — 27 commitsThu 8:00 — 29 commitsThu 9:00 — 34 commitsThu 10:00 — 26 commitsThu 11:00 — 40 commitsThu 12:00 — 29 commitsThu 13:00 — 28 commitsThu 14:00 — 49 commitsThu 15:00 — 64 commitsThu 16:00 — 40 commitsThu 17:00 — 41 commitsThu 18:00 — 49 commitsThu 19:00 — 51 commitsThu 20:00 — 42 commitsThu 21:00 — 38 commitsThu 22:00 — 45 commitsThu 23:00 — 51 commitsFri 0:00 — 52 commitsFri 1:00 — 59 commitsFri 2:00 — 45 commitsFri 3:00 — 40 commitsFri 4:00 — 38 commitsFri 5:00 — 31 commitsFri 6:00 — 36 commitsFri 7:00 — 20 commitsFri 8:00 — 18 commitsFri 9:00 — 23 commitsFri 10:00 — 17 commitsFri 11:00 — 18 commitsFri 12:00 — 22 commitsFri 13:00 — 17 commitsFri 14:00 — 18 commitsFri 15:00 — 10 commitsFri 16:00 — 22 commitsFri 17:00 — 31 commitsFri 18:00 — 24 commitsFri 19:00 — 25 commitsFri 20:00 — 19 commitsFri 21:00 — 9 commitsFri 22:00 — 9 commitsFri 23:00 — 12 commitsSat 0:00 — 11 commitsSat 1:00 — 21 commitsSat 2:00 — 32 commitsSat 3:00 — 28 commitsSat 4:00 — 34 commitsSat 5:00 — 36 commitsSat 6:00 — 32 commitsSat 7:00 — 30 commitsSat 8:00 — 41 commitsSat 9:00 — 29 commitsSat 10:00 — 33 commitsSat 11:00 — 31 commitsSat 12:00 — 25 commitsSat 13:00 — 35 commitsSat 14:00 — 33 commitsSat 15:00 — 19 commitsSat 16:00 — 24 commitsSat 17:00 — 24 commitsSat 18:00 — 36 commitsSat 19:00 — 25 commitsSat 20:00 — 32 commitsSat 21:00 — 26 commitsSat 22:00 — 14 commitsSat 23:00 — 21 commits
Commit volume by weekday and hour (UTC). Larger dots mean more commits.
DateListRankStars gained
Apr 25, 2026daily#22+140
  • freeCodeCamp/freeCodeCamp

    freeCodeCamp.org's open-source codebase and curriculum. Learn math, programming, and computer science for free.

    456.7K stars · TypeScript

  • openclaw/openclaw

    The AI that really does things. Any OS. Any Platform. The lobster way. 🦞

    391.3K stars · TypeScript

  • obra/superpowers

    An agentic skills framework & software development methodology that works.

    295.2K stars · Shell

  • NousResearch/hermes-agent

    The agent that grows with you

    251.2K stars · Python

  • anomalyco/opencode

    The open source coding agent.

    211.7K stars · TypeScript

  • n8n-io/n8n

    Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.

    206.7K stars · TypeScript