26bd8dachangelog v2.16.1 is 6 commits behind this build โ last written 8d ago, so 6 changes to what the site shows are unrecorded
obotclaw,
the broader permission set (Contents/Issues/PRs RW + Workflows RW + Actions read โ
anticipating the @claude PR-responder follow-on; Discussions RW added at registration),
Keychain + Actions-secrets key management, script + skill in safety.agent. Doc updated
and merged in PR #14; resolutions
recorded on #3.obotclaw GitHub App (App ID 4215246) under @jwildfire โ form driven
via browser automation, sudo-auth and key generation by Jeremy โ and installed it on the
five whitelisted repos (installation 144370633; bot user ID 299836032).obot-github-app; raw multiline values don't survive security -w round-trips),
OBOT_APP_ID/OBOT_APP_PRIVATE_KEY Actions secrets set on obot.roadmap, downloaded PEM
deleted. Token minting verified end-to-end: 1-hour token scoped to exactly the five repos.scripts/obot-app-token + the
obot-identity skill (safety.agent PR #9,
merged) posted the first obotclaw[bot] comment on #3.
GHA flow: app-smoke-test.yml + identity-selection docs merged in
PR #20, then dispatched from main โ
run succeeded and posted its own bot comment on #3.@claude
responder, background dev lane), each with a declared trigger, write scope, and human
gate; depends on #3, companion to #17. Both filed with milestone 2026q3.site/roadmap-changelog.json; AGENTS.md now requires a semver-bumped changelog entry
for any change that alters what roadmap.html shows.gh auth audit and old-config
scan pending. Until then the retired identity's credentials coexist with the App.gh auth audit, old-config scan โ then decide whether
#3 closes.read:project" note is stale (scope refreshed
2026-07-03).obot-app-token pruned. Only safety.agent p004-requirements-testing-framework
(merged PR #4, not on the approved list) remains.obot-claw.github.io-worktrees/
(design-html, fix-53, hub-refactor) and the wider stale-reference sweep โ fold into
#17's cleanup scope.close-session โ automate what tonight's wrap-up did by hand
(consolidate the day's diary across sessions, prune merged branches/worktrees, sweep
open PRs/issues for loose ends, publish). The
session-orchestration proposal
already scopes this as its wrap-up step โ resolve its D1โD4 rather than building the
skill separately.