Release Openclaw Mac logo

Release Openclaw Mac

OrganizationPopular
openclaw
release-openclaw-mac

Run or recover OpenClaw macOS release signing, notarization, appcast, and asset promotion.

Overview

Publisheropenclaw
Repositoryopenclaw
Skill namerelease-openclaw-mac
Stars
391K
Forks
82.2K
Bundled files
Instructions only
Links
  • Markdown instructions

    A SKILL.md file the model loads on demand, so it only costs tokens when a request actually matches.

  • Works with any LLM

    AI skills are plain Markdown, not provider-specific code, so this works with GPT, Claude, Gemini, Grok, or a local model.

  • Self-contained

    Everything the model needs lives in the instructions — no extra files to sync.

  • Open source

    Published by openclaw on GitHub. Read the source before you install it.

Installation

Install the Release Openclaw Mac AI skill in TypingMind to use it with any LLM, or drop it into another agent that reads SKILL.md.

1

Install in TypingMind

TypingMind installs a skill straight from its GitHub folder — it reads SKILL.md, bundles the resource files, and stores the result locally.

  1. Open the app and go to Plugins → Skills.
  2. Choose "Install from GitHub".
  3. Paste the skill folder URL below and confirm.
    https://github.com/openclaw/openclaw/tree/main/.agents/skills/release-openclaw-mac
  4. Enable the skill in any chat where you want it available.
Plugins → Skills → Add skill → From GitHub URL, then paste the folder URL and press Continue.
2

Install in another agent

Any agent that reads the Agent Skills format can use this skill — copy the folder into that agent's skills directory.

Claude Code — .claude/skills
git clone --depth 1 https://github.com/openclaw/openclaw.git /tmp/openclaw
mkdir -p .claude/skills
cp -r /tmp/openclaw/.agents/skills/release-openclaw-mac .claude/skills/release-openclaw-mac
Restart Claude Code after copying so it picks up the new skill.

Use it in TypingMind

Enable Release Openclaw Mac in any TypingMind chat and the model takes it from there. Its name and description sit in the system prompt, and the moment a request matches, the model loads the full instructions itself — you never invoke it by hand, and it costs no tokens until it is actually used.

The model loads Release Openclaw Mac on its own as soon as a request matches it.

Works with any AI model

AI skills are plain Markdown instructions rather than provider-specific code, so Release Openclaw Mac is not tied to the model it was written for. Install it once in TypingMind and use it with GPT-5, Claude, Gemini, Grok, DeepSeek, Mistral, Llama, or a local model you run yourself — all on your own API keys.

  • Loaded only when it is needed

    The system prompt carries just the name and description. The instructions are fetched on the first matching request, so an idle skill costs nothing.

  • Switch models mid-chat

    Because the skill is instructions rather than code, changing model does not break it — the next model reads the same SKILL.md.

Skill instructions

This is the SKILL.md content the model loads. Read it before installing — a skill is instructions your model will follow.

OpenClaw Mac Release

Use with $release-openclaw-maintainer, $release-openclaw-ci, $one-password, and $release-private if it exists when stable macOS assets, release-ops mac preflight, notarization, appcast promotion, or mac release recovery is involved.

This is a regular stable-release skill. Do not invoke it for extended-stable; that track's GitHub Release carries shared validation evidence but does not inherit macOS assets or appcast promotion.

Release authorization

An explicit stable or full release request includes macOS publication unless the operator limits its scope. Continue through validation, signing, notarization, promotion, and verification without asking for separate macOS consent. Keep the exact release identity and all artifact checks. macOS publication runs in parallel with npm and never blocks it; a mac failure does not hold the npm/ClawHub release, GitHub release finalization, or main closeout. Fix it in parallel.

Follow the current owner-configured environment policy. Do not invent an extra reviewer requirement or recreate an obsolete one. If GitHub still enforces an approval, report the actual rule and resolve it through its owner; policy changes require explicit organization-owner direction and verified active admin membership. Never impersonate a reviewer, fabricate approval, or use another signing path to bypass an enforced rule.

Credentials

  • Resolve Peter-owned ASC item refs, key ids, issuer ids, and service-token provenance from $release-private.
  • Fields: private_key_p8, key_id, issuer_id.
  • Stale/revoked key symptom: xcrun notarytool submit fails with HTTP status code: 401. Unauthenticated.
  • Validate candidate ASC credentials with xcrun notarytool history before setting GitHub secrets.

1Password

  • Use $one-password: all op work inside one persistent tmux session, no secret output.
  • Use the service-token guidance from $release-private when available.
  • If a service token fails, run status-only checks: token present/length and op whoami; never print token values.
  • If desktop app auth is needed but Touch ID is unavailable, set OP_BIOMETRIC_UNLOCK_ENABLED=false for the manual op account add --signin path.

GitHub Secrets

Target release-ops repo environment: openclaw/releases, env mac-release.

Set only after local notary auth validation:

  • APP_STORE_CONNECT_API_KEY_P8
  • APP_STORE_CONNECT_KEY_ID
  • APP_STORE_CONNECT_ISSUER_ID

Do not update these from mixed sources. All three ASC fields must come from the same 1Password item.

Workflow Shape

  • openclaw/openclaw is the public product repo. Its GitHub Releases page is where macOS assets are ultimately attached.
  • openclaw/openclaw macos-release.yml is public handoff validation only. It never signs, notarizes, or uploads macOS assets, regardless of preflight_only.
  • openclaw/releases is the restricted release-ops repo. Its macOS workflows sign, notarize, validate, and promote assets onto the openclaw/openclaw GitHub release.
  • Public release branch may carry mac-only packaging fixes after the stable tag/npm are already live.
  • Use source_ref=release/YYYY.M.PATCH for release-ops mac preflight/validation when building that branch variation.
  • Keep tag=vYYYY.M.PATCH pointing at the original stable release commit.
  • Real mac publish must reuse:
    • a successful release-ops mac preflight run for the same tag/source SHA
    • a successful release-ops mac validation run for the same tag/source SHA
  • Release-ops preflight and real publish use the mac-release environment for signing and promotion secrets and its main-only deployment policy. The authorized release operator continues under that environment's current rules.
  • If preflight source SHA differs from tag SHA, validation must also use the same source_ref; promotion rejects mismatched proof.

Notarization

  • OpenClaw uses scripts/notarize-mac-artifact.sh.
  • xcrun notarytool submit should use --no-s3-acceleration; accelerated upload can surface misleading 401s even when notarytool history succeeds.
  • If signing succeeds but notarization fails immediately with 401, check ASC key freshness first.
  • If notarization stays in progress for several minutes after key-file write, that is normal Apple wait time; do not edit blindly.

Dispatch

The public handoff workflow validates the tag, source, build, and package metadata before publication. It does not require a GitHub release page because it does not upload assets. Keep this validation before the real publish workflow. The core publisher owns GitHub release finalization; macOS promotion attaches its verified assets to that release whether it is still a draft or already public, so it never waits for the npm flip.

Public handoff validation:

bash
gh workflow run macos-release.yml --repo openclaw/openclaw \
  --ref release/YYYY.M.PATCH \
  -f tag=vYYYY.M.PATCH \
  -f preflight_only=true \
  -f public_release_branch=release/YYYY.M.PATCH
  • Use the public release branch as the workflow ref so the Actions list displays release/YYYY.M.PATCH, matching prior stable macOS handoff runs.
  • Do not use --ref main or --ref vYYYY.M.PATCH for this public handoff validation. The workflow checks out the tag from the tag input internally.

Release-ops preflight:

bash
gh workflow run openclaw-macos-publish.yml --repo openclaw/releases --ref main \
  -f tag=vYYYY.M.PATCH \
  -f source_ref=release/YYYY.M.PATCH \
  -f preflight_only=true \
  -f smoke_test_only=false \
  -f allow_late_calver_recovery=false \
  -f public_release_branch=release/YYYY.M.PATCH

Follow the run through signing and notarization under the configured environment policy. Record the successful preflight run id; an approval pause is not a successful preflight.

Resume is the default. Re-dispatching the same preflight command after a failure (notary outage, DMG packaging, collector) resumes every variant from the newest checkpoint left by a failed or cancelled main dispatch for the same tag and source SHA; only variants without a checkpoint rebuild. The run log prints Resuming <variant> from run <id> attempt <n> or Building <variant>. ignore_checkpoints=true forces fresh builds. Pass resume_notarization_run_id, resume_notarization_run_attempt, and resume_notarization_variant only to pin one specific run, or for checkpoints made before the resume index existed (macos-resume-<tag>-<variant>-<sha> artifacts). Prefer gh run rerun <run-id> --failed --repo openclaw/releases when the failed job is still in the current run.

Release-ops validation for a branch-variation preflight:

bash
gh workflow run openclaw-macos-validate.yml --repo openclaw/releases --ref main \
  -f tag=vYYYY.M.PATCH \
  -f source_ref=release/YYYY.M.PATCH

Record the successful validation run id.

Real publish:

bash
gh workflow run openclaw-macos-publish.yml --repo openclaw/releases --ref main \
  -f tag=vYYYY.M.PATCH \
  -f preflight_only=false \
  -f smoke_test_only=false \
  -f preflight_run_id=<successful-preflight-run> \
  -f validate_run_id=<successful-validation-run> \
  -f allow_late_calver_recovery=false \
  -f public_release_branch=release/YYYY.M.PATCH

Follow promotion through asset upload and appcast publication under the same release authorization and current environment policy.

  • Release-ops openclaw/releases publish/validate workflows run from their own trusted main workflow ref. Real publish has a guard that rejects any other workflow ref. That displayed main ref is expected; the public OpenClaw source is selected by tag and optional source_ref.

Verify

  • gh release view vYYYY.M.PATCH --repo openclaw/openclaw shows zip, dmg, dSYM zip; once the npm publisher has flipped it: not draft, not prerelease.
  • Public main appcast.xml points at OpenClaw-YYYY.M.PATCH.zip.
  • Appcast entry has sparkle:version, sparkle:shortVersionString, length, and sparkle:edSignature.

Frequently asked questions

What does the Release Openclaw Mac AI skill do?

Run or recover OpenClaw macOS release signing, notarization, appcast, and asset promotion.

Why use Release Openclaw Mac on TypingMind?

Because you install it once and use it with any model. Release Openclaw Mac is plain Markdown rather than provider-specific code, so the same skill runs on GPT-5, Claude, Gemini, Grok, or a local model — and you can switch model mid-chat without it breaking. TypingMind runs on your own API keys, so you pay providers directly instead of a per-seat subscription, and your skills and chats stay in your own storage.

How do I install Release Openclaw Mac in TypingMind?

Open Plugins → Skills → Install from GitHub in TypingMind and paste https://github.com/openclaw/openclaw/tree/main/.agents/skills/release-openclaw-mac. TypingMind reads its SKILL.md and installs it as a skill you can enable per chat.

Which AI models can use Release Openclaw Mac?

Any model you connect in TypingMind. AI skills are plain Markdown instructions rather than provider-specific code, so GPT, Claude, Gemini, Grok, and local models can all load this skill when a request matches it.

How many AI models can I use with Release Openclaw Mac?

As many as you like. As long as a model supports skills, you can use Release Openclaw Mac with it — GPT, Claude, Gemini, Grok, DeepSeek, Mistral, Llama and more — all on TypingMind with your own API keys.

Is the Release Openclaw Mac AI skill free?

It is published on GitHub by openclaw. Check the repository for licensing terms. You only pay your own AI provider for the tokens you use.

What are AI skills?

An AI skill is a reusable instruction bundle that teaches an AI model how to do one specific task. It follows the open Agent Skills format: a SKILL.md file with a name and description, plus any scripts, templates or reference files the model may need. The model reads the instructions only when your request matches the skill, so an installed skill costs nothing until it is used.

How are AI skills different from plugins or MCP servers?

A plugin or MCP server gives a model new tools to call — code that runs somewhere and returns a result. An AI skill gives the model knowledge and process instead: how to approach a task, which steps to follow, what good output looks like. Skills are plain Markdown, so they need no server, no API key and no runtime, and they work with any model.

View all

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇