Skip to content

release: prepare stable Codex Security npm publishing - #12

Merged
mldangelo-oai merged 35 commits into
mainfrom
mdangelo/codex/codex-security-stable-npm-release-20260724
Jul 28, 2026
Merged

release: prepare stable Codex Security npm publishing#12
mldangelo-oai merged 35 commits into
mainfrom
mdangelo/codex/codex-security-stable-npm-release-20260724

Conversation

@mldangelo-oai

@mldangelo-oai mldangelo-oai commented Jul 24, 2026

Copy link
Copy Markdown
Collaborator

Summary

Prepare the stable @openai/codex-security@0.1.0 npm release and restore the one canonical bundled plugin file missing from the public projection.

Changes

  • Publish stable npm-vX.Y.Z tags to npm latest using the protected npm environment and provenance.
  • Keep the SHA-pinned Socket Firewall, firewall-routed dependency installs and package smoke tests.
  • Install trusted-publishing-compatible npm 11.15.0 on a real Node 24 release.
  • Preserve the verified tarball for 30 days and flatten the downloaded artifact before publishing.
  • Restore normalize_candidates.py byte-for-byte from approved internal source blob c4396d850d2829d8eca90c9c186ddad6f4e589fe.

Verification

  • 345 SDK tests passed; three expected skips.
  • 50 canonical Python normalizer tests passed; two expected skips.
  • All 93 declared plugin files and all 94 shipped bundle assets validated.
  • Built the real npm tarball; public SDK import, CLI and installed package checks passed.
  • Built and validated the customer Docker image.
  • Stable workflow YAML, formatting, firewall, protected environment, 30-day retention, artifact flattening and exact npm version checked.

Copyberry push sync for this repository is temporarily paused while the public release is reconciled upstream.

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b1adfc085a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/node-release.yml Outdated
@mldangelo-oai mldangelo-oai changed the title release: publish stable Codex Security versions release: publish stable Codex Security 0.1.0 Jul 25, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 28547de185

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/node-release.yml

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: fc0ddfd44e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/node-release.yml
ianw-oai
ianw-oai previously approved these changes Jul 25, 2026
Add the three exact plugin projection-contract files from the merged monorepo and remove issue, Dependabot, and pull request templates unrelated to publishing.
The current package inspector intentionally excludes internal ownership metadata and requires only the public plugin manifest plus shipped skill files. Retain the two policy skill files and remove the non-public OWNERS file.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ef131b1ccf

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/node-release.yml Outdated
Comment thread sdk/typescript/_bundled_plugin/skills/define-security-policy/SKILL.md Outdated
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Something went wrong. Try again later by commenting “@codex review”.

Failed to set up container
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mldangelo-oai

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4b565fe0a7

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/node-release.yml Outdated
@mldangelo-oai mldangelo-oai changed the title release: publish stable Codex Security 0.1.0 chore(release): publish Codex Security 0.1.0 Jul 27, 2026
ianw-oai
ianw-oai previously approved these changes Jul 28, 2026
@mldangelo-oai

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 60cb56f381

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/node-release.yml Outdated

@ianw-oai ianw-oai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocking: .github/workflows/node-release.yml is invalid on Actions because the verify job defines registry environment keys twice with case-only differences (NPM_CONFIG_REGISTRY / npm_config_registry, and the same for PNPM). The exact-head node-release run 30337814495 failed at workflow creation with zero jobs. Please keep one spelling per variable.

@mldangelo-oai

Copy link
Copy Markdown
Collaborator Author

@ianw-oai Fixed your blocking review in 094c6ef: the release workflow now uses one spelling per registry variable and passes actionlint. I also corrected the pinned Socket Firewall version and routed the privileged npm bootstrap through the firewall. Full SDK and Python tests, the actual npm tarball, Docker image, and independent release-security review all pass. Ready for another look.

@mldangelo-oai

Copy link
Copy Markdown
Collaborator Author

@codex review

@mldangelo-oai
mldangelo-oai requested a review from ianw-oai July 28, 2026 08:00
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Nice work!

Reviewed commit: 094c6ef61c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mldangelo-oai

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Can't wait for the next one!

Reviewed commit: 3e39f4cc9e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mldangelo-oai
mldangelo-oai merged commit a45e3ee into main Jul 28, 2026
3 checks passed
@mldangelo-oai
mldangelo-oai deleted the mdangelo/codex/codex-security-stable-npm-release-20260724 branch July 28, 2026 15:56
ylt pushed a commit to ylt/codex-security that referenced this pull request Jul 28, 2026
* release: publish stable Codex Security versions

* release: validate stable npm tags against package metadata

* release: harden public npm publishing and contributor guidance

* fix: complete the stable Codex Security npm package

Add the three exact plugin projection-contract files from the merged monorepo and remove issue, Dependabot, and pull request templates unrelated to publishing.

* fix: keep internal OWNERS out of the public npm package

The current package inspector intentionally excludes internal ownership metadata and requires only the public plugin manifest plus shipped skill files. Retain the two policy skill files and remove the non-public OWNERS file.

* fix: harden stable npm release safeguards

* fix: retain bundled plugin in stable release

* fix: remove internal links from release workflow

* fix(release): keep socket firewall public-compatible

* fix(release): validate firewall cutoff dates

* fix: restore public SDK cross-platform CI

* fix(release): make stable trusted publishing runnable

* fix(release): always enforce Socket Firewall

* fix(release): validate firewall-backed trusted publishing

* fix: harden trusted npm publishing

* fix: bootstrap protected first npm publication
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants