OpenClaw went viral. Meet the maintainers building and securing it.

Imported from official source

Security notice

Cybersecurity Classified by Officially

What began as a personal experiment quickly became a global open source project with extraordinary momentum.

OpenClaw is a personal AI assistant that runs on users’ devices and connects with the messaging channels they already use. Started by Peter Steinberger as a weekend project in November 2025, its GitHub repository has grown to approximately 388,000 stars, 81,000 forks, and more than 80,000 commits by August 26, 2026.

In this video interview, filmed just six months into the project, creator Peter Steinberger and several OpenClaw maintainers discuss managing a surge of pull requests, rethinking contributor trust and code review, addressing software supply chain risks, and balancing powerful agent capabilities with security. They also share security lessons from the GitHub Secure Open Source Fund and the value of connecting with maintainers facing similar challenges. Watch the full video above, then explore the key lessons below.

People in this video

The following maintainers shared their experiences maintaining and securing OpenClaw.

Here are the top 10 lessons that we took away from the conversation.

Lessons 1–3: How AI changed contributions and community

1. Pull requests became prompt requests

OpenClaw’s maintainers found themselves managing thousands of pull requests and issues, with some contributors opening hundreds of pull requests at once.

I don’t even call them pull requests. I call them prompt requests.

Peter Steinberger

There were some contributors that had multiple hundreds of pull requests running these sort of automated software factories that were just mining everything for issues.

Josh Lehman

This is an extract. The publication continues at the source.

Read the original at the source: https://github.blog/open-source/maintainers/openclaw-went-viral-meet-the-maintainers-building-and-securing-it/

Officially imported this from GitHub’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
GitHub — imported from official source
Official source
https://github.blog/security/feed/ RSS
Imported
September 15, 2026 20:57
Versions
1 recorded
Identity
https://github.blog/?p=98468

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.