This release keeps dependencies and maintenance posture current for teams operating this tool.
✓ No known CVEs patched in this version
Topics
+4 more
Affected surfaces
Summary
AI summaryUpdates span build, bos_build, patches, browserclaw docs, and chromium handling.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Low |
Remove welcome page and separate BrowserClaw ports. Remove welcome page and separate BrowserClaw ports. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Redact signing credentials from logs in build process. Redact signing credentials from logs in build process. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Make CodeSignTool invocation argv‑safe with redacted logging. Make CodeSignTool invocation argv‑safe with redacted logging. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Clear browserclaw legacy command execute clsid in patches. Clear browserclaw legacy command execute clsid in patches. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Stage bundled extensions in debug plans during build. Stage bundled extensions in debug plans during build. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Stage exact product extension sets during build. Stage exact product extension sets during build. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Sign chrome.exe before installer packaging and rename the product executable at the end on Windows. Sign chrome.exe before installer packaging and rename the product executable at the end on Windows. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Package bundled extensions in AppImage and DEB for Linux builds. Package bundled extensions in AppImage and DEB for Linux builds. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Package BrowserClaw payloads and executable identity. Package BrowserClaw payloads and executable identity. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Isolate BrowserClaw Windows install identity in Chromium component. Isolate BrowserClaw Windows install identity in Chromium component. Source: llm_adapter@2026-07-16 Confidence: high |
— |
Full changelog
- fix(build): redact signing credentials from logs (#1759) (6b6171df9)
- chore: bump version for releasee (1ccee6936)
- fix(bos_build): argv-safe CodeSignTool invocation with redacted logging (bfa7757a5)
- chore: disable weekly eval workflow (242f1a267)
- fix(patches): clear browserclaw legacy command execute clsid (#1756) (3b5027ea1)
- fix(build): stage bundled extensions in debug plans (#1755) (a3ba4fcbd)
- feat: remove welcome page and separate BrowserClaw ports (#1754) (230fea046)
- fix(build): stage exact product extension sets (#1752) (277b296f1)
- fix(windows): sign chrome.exe before installer packaging; rename product exe at the end (#1753) (7b483743f)
- fix(linux): package bundled extensions in appimage and deb (#1751) (31d5a94e7)
- fix: package BrowserClaw payloads and executable identity (#1750) (60140a02f)
- fix(chromium): isolate browserclaw windows install identity (#1749) (d75d392d9)
- fix(bpatch): stop treating annotate commits as drift (#1748) (f4047097b)
- fix(patches): launch Windows server without console (#1747) (c07066a0e)
- chore: update claw docs link (97144d607)
- chore: version claw-app (72acbc199)
- fix(patches): suppress upstream first run (#1745) (922f2ca8f)
- fix(patches): disable onboarding for BrowserOS (#1744) (ceff90d59)
- chore(bos_build): seed browserclaw appcast staging placeholders (d89f7e15a)
- docs(browserclaw): Connect page with one-click board + four manual setup guides (#1741) (b04785734)
- docs(bos_build): rewrite README as an operator entry point (#1740) (1bc76c063)
- docs(browserclaw): retire first-run stub, redirect to how-it-works (#1738) (1f0aef2c7)
- docs(browserclaw): rewrite how-it-works as a six-step walkthrough with screenshots (#1735) (8790b21bc)
- chore(claw-server): standardize mcp middleware headers (#1736) (f787e3cf9)
- docs(browserclaw): rewrite intro page in everyday-user voice (#1733) (d97a421ef)
- docs(browserclaw): position BrowserClaw as a standalone product, stub install (#1731) (a79b04c46)
- fix(docs): break /browserclaw redirect loop, use Mintlify no-slash canonical (#1730) (721ddceb4)
- docs(browserclaw): scaffold section + Overview + Install, deep-link cockpit footer (#1728) (744cf3a65)
- chore: sync internal-docs submodule (#1727) (58d895582)
- chore(release): build v0.47.9 [skip ci] (a2c34ae99)
- chore: bump version (62f9d4b0a)
- chore: sync internal-docs submodule (#1725) (616c2248e)
- chore: bump claw server version to 0.0.6 (#1724) (af27a9fb8)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About BrowserOS
The open-source Agentic browser; alternative to ChatGPT Atlas, Perplexity Comet, Dia.
Related context
Related tools
Beta — feedback welcome: [email protected]