* refactor(openclaw)!: read config from plugin config instead of process.env The plugin loaded credentials and runtime settings from environment variables (HINDSIGHT_API_LLM_*, HINDSIGHT_EMBED_API_*, HINDSIGHT_BANK_ID) plus auto-detection of OPENAI_API_KEY / ANTHROPIC_API_KEY / GEMINI_API_KEY / GROQ_API_KEY. That tripped OpenClaw's install-scanner env-harvesting rule and bypassed the framework's first-class SecretRef resolution. Switch to reading from the plugin config exclusively, with secrets configured via 'openclaw config set ... --ref-source env|file|exec'. Combined with the daemon lifecycle extraction in #949, this closes the remaining install-scanner findings the 0.5.x plugin was hitting. The plugin source now contains neither process.env nor child_process; the former moved to plugin config (resolved by OpenClaw before the plugin loads), and the latter lives in @vectorize-io/hindsight-all under node_modules where the scanner's directory walker skips it. The plugin can be installed without --dangerously-force-unsafe-install. BREAKING CHANGE: drops the llmApiKeyEnv plugin config field along with the HINDSIGHT_API_LLM_*, HINDSIGHT_EMBED_API_*, and HINDSIGHT_BANK_ID environment variables. Users must now configure llmProvider and llmApiKey explicitly via 'openclaw config set'. Migration guide is in hindsight-docs/docs-integrations/openclaw.md and the integration changelog. * chore(openclaw): pin published versions of hindsight-all and hindsight-client Phase 2 (#949) introduced @vectorize-io/hindsight-all and @vectorize-io/hindsight-client as plugin dependencies using 'file:' workspace paths. Those paths resolve inside the monorepo but break when the published tarball is installed outside it — 'openclaw plugins install @vectorize-io/hindsight-openclaw' failed with 'Cannot find module @vectorize-io/hindsight-all' because npm could not resolve the file: path from the extracted extension directory. Replace both with semver ranges targeting the published versions: @vectorize-io/hindsight-all ^0.1.0 @vectorize-io/hindsight-client ^0.5.0 Verified end-to-end: 'openclaw plugins install <local-tarball>' now succeeds without --dangerously-force-unsafe-install and without the workspace-symlink hack. npm pulls both dependencies from the registry into the extracted extension's node_modules, the plugin loads cleanly, and 'openclaw plugins doctor' reports no issues.
64 lines
1.5 KiB
JSON
64 lines
1.5 KiB
JSON
{
|
|
"name": "@vectorize-io/hindsight-openclaw",
|
|
"version": "0.5.1",
|
|
"description": "Hindsight memory plugin for OpenClaw - biomimetic long-term memory with fact extraction",
|
|
"main": "dist/index.js",
|
|
"types": "dist/index.d.ts",
|
|
"bin": {
|
|
"hindsight-openclaw-backfill": "dist/backfill.js"
|
|
},
|
|
"type": "module",
|
|
"openclaw": {
|
|
"extensions": [
|
|
"./dist/index.js"
|
|
]
|
|
},
|
|
"keywords": [
|
|
"openclaw",
|
|
"memory",
|
|
"ai",
|
|
"agent",
|
|
"hindsight",
|
|
"long-term-memory"
|
|
],
|
|
"author": "Vectorize <support@vectorize.io>",
|
|
"license": "MIT",
|
|
"repository": {
|
|
"type": "git",
|
|
"url": "https://github.com/vectorize-io/hindsight.git",
|
|
"directory": "hindsight-integrations/openclaw"
|
|
},
|
|
"files": [
|
|
"dist",
|
|
"openclaw.plugin.json",
|
|
"README.md"
|
|
],
|
|
"scripts": {
|
|
"build": "tsc",
|
|
"dev": "tsc --watch",
|
|
"clean": "rm -rf dist",
|
|
"backfill:help": "node dist/backfill.js --help",
|
|
"test": "vitest run src",
|
|
"test:watch": "vitest src",
|
|
"test:integration": "vitest run --config vitest.integration.config.ts",
|
|
"prepublishOnly": "npm run clean && npm run build"
|
|
},
|
|
"dependencies": {
|
|
"@vectorize-io/hindsight-client": "^0.5.0",
|
|
"@vectorize-io/hindsight-all": "^0.1.0"
|
|
},
|
|
"devDependencies": {
|
|
"@types/node": "^20.0.0",
|
|
"@vitest/ui": "^4.1.2",
|
|
"typescript": "^5.3.0",
|
|
"vitest": "^4.1.2"
|
|
},
|
|
"engines": {
|
|
"node": ">=22"
|
|
},
|
|
"overrides": {
|
|
"rollup": "^4.59.0",
|
|
"picomatch": ">=2.3.2 <3.0.0 || >=4.0.4",
|
|
"vite": ">=8.0.5"
|
|
}
|
|
}
|