release: prepare stable Codex Security npm publishing - #12
Conversation
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b1adfc085a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 28547de185
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: fc0ddfd44e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Add the three exact plugin projection-contract files from the merged monorepo and remove issue, Dependabot, and pull request templates unrelated to publishing.
The current package inspector intentionally excludes internal ownership metadata and requires only the public plugin manifest plus shipped skill files. Retain the two policy skill files and remove the non-public OWNERS file.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ef131b1ccf
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Codex Review: Something went wrong. Try again later by commenting “@codex review”. ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
…/codex/codex-security-stable-npm-release-20260724
…/codex/codex-security-stable-npm-release-20260724
…/codex/codex-security-stable-npm-release-20260724
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4b565fe0a7
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…/codex/codex-security-stable-npm-release-20260724
…able-npm-release-20260724' into mdangelo/codex/codex-security-stable-npm-release-20260724
…security-stable-npm-release-20260724
…security-main-ci-recovery-20260727 # Conflicts: # sdk/typescript/tests-ts/runtime.test.ts
…' into mdangelo/codex/codex-security-stable-npm-release-20260724
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 60cb56f381
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
ianw-oai
left a comment
There was a problem hiding this comment.
Blocking: .github/workflows/node-release.yml is invalid on Actions because the verify job defines registry environment keys twice with case-only differences (NPM_CONFIG_REGISTRY / npm_config_registry, and the same for PNPM). The exact-head node-release run 30337814495 failed at workflow creation with zero jobs. Please keep one spelling per variable.
|
@ianw-oai Fixed your blocking review in |
|
@codex review |
…security-stable-npm-release-20260724
|
Codex Review: Didn't find any major issues. Nice work! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
@codex review |
|
Codex Review: Didn't find any major issues. Can't wait for the next one! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
* release: publish stable Codex Security versions * release: validate stable npm tags against package metadata * release: harden public npm publishing and contributor guidance * fix: complete the stable Codex Security npm package Add the three exact plugin projection-contract files from the merged monorepo and remove issue, Dependabot, and pull request templates unrelated to publishing. * fix: keep internal OWNERS out of the public npm package The current package inspector intentionally excludes internal ownership metadata and requires only the public plugin manifest plus shipped skill files. Retain the two policy skill files and remove the non-public OWNERS file. * fix: harden stable npm release safeguards * fix: retain bundled plugin in stable release * fix: remove internal links from release workflow * fix(release): keep socket firewall public-compatible * fix(release): validate firewall cutoff dates * fix: restore public SDK cross-platform CI * fix(release): make stable trusted publishing runnable * fix(release): always enforce Socket Firewall * fix(release): validate firewall-backed trusted publishing * fix: harden trusted npm publishing * fix: bootstrap protected first npm publication
Summary
Prepare the stable
@openai/codex-security@0.1.0npm release and restore the one canonical bundled plugin file missing from the public projection.Changes
npm-vX.Y.Ztags to npmlatestusing the protectednpmenvironment and provenance.11.15.0on a real Node 24 release.normalize_candidates.pybyte-for-byte from approved internal source blobc4396d850d2829d8eca90c9c186ddad6f4e589fe.Verification
Copyberry push sync for this repository is temporarily paused while the public release is reconciled upstream.