Skip to content

ShadowClaw 1.3.1

Three commits landed on main after the v1.3.0 tag and none of them moved the version, so a build from main called itself 1.3.0 while behaving differently from the thing that tag points at. packaging/build.sh reads VERSION straight out of shadowclaw/authorship.py, which means the mislabelling reached the artifact filenames too. This release corrects that.

A way to take the tool off the machine

What a 1.3.1 user has that a 1.3.0 user did not, first, is scripts/uninstall.sh — it removes ShadowClaw from a host including the changes it made inside other people's products. The destination it added to DefenseClaw's config comes out through defenseclaw setup observability remove rather than by editing config.yaml, and a dashboard installed into a Grafana that was already running is deleted by UID, with the folder removed only when nothing else has been filed in it. Every process match is anchored to a path ShadowClaw owns, because Loki, Grafana, and eslogger are all things another product may be running, and a bare pkill would take a colleague's copy with it. The ledger survives by default. packaging/uninstall.sh still owns the pkg payload and is delegated to rather than reimplemented. See Uninstall.

Installing costs 418 MB less

Second, install.sh fetched the OpenTelemetry Collector by default, from when every export path went through one, and install-otelcol.sh left its 89 MB archive in dist/ afterwards and never cleaned up. Neither is needed on the documented path: Loki 3.x accepts OTLP directly, so the sensor posts to :3100 and no collector is started. The download is now --with-otelcol, the archive is deleted once its checksum verifies, and make validate reports what to fetch instead of failing on a missing binary. --skip-otelcol is still accepted, so anything written against the old default keeps working.

The dashboard survives real data volume

Third, Loki aborts a query whose result exceeds its 4 MB default gRPC ceiling, and Grafana renders that failure exactly like an empty result, so a panel reads "No data" with the reason only in Loki's log. The trigger is how many findings fall in the window rather than anything about the query, which is why panels that had worked for weeks went dark together without being edited.

An unwrapped range aggregation keeps every label of every matching line as its own series unless it names a grouping, and a finding carries about fifty-five labels, so by () is the difference between shipping tens of thousands of series and shipping one number. All sixteen unwrapping targets carried the same latent bug, not just the panel that was noticed. See Raise the gRPC message limits and Writing queries that scale.

Patch rather than minor

Nothing here touches detection. No signal, threshold, or score changed; no event was added, renamed, or reshaped; no telemetry attribute moved. Anything parsing ShadowClaw's output against 1.3.0 needs no change to read 1.3.1. This is tooling, packaging, and dashboards — which is also why it is worth releasing on its own rather than waiting to ride along with a detection change.

One caveat outlives the release

The findings-log panel is a logs panel, and showing every field when a line is expanded is its entire purpose, so there is nothing to aggregate away — it needs Loki's ceiling raised instead. Both halves of the failing hop have to move, since the querier's client to the query frontend carries a separate 4 MB default that the server setting does not cover. That configuration lives outside this repository — loki.yaml is written by the operator, and scripts/ShadowclawAI errors if it is absent — so upgrading to 1.3.1 does not fix that panel on a host that has not applied it. The requirement is documented in the DefenseClaw integration.

Verification

The attribution digest is unchanged, and that is correct rather than an oversight: it covers the product and author constants and deliberately not VERSION, so cutting a release cannot disturb the tamper evidence. Verified through the documented path, python3 -m shadowclaw --about, which reports the computed and expected digests as equal. 807 tests pass.

Next