Releases: openai/codex-security
Releases · openai/codex-security
Release list
Codex Security 0.1.5
Immutable
release. Only release title and notes can be modified.
What's Changed
Fixes
- fix: make historical GitHub release backfills idempotent by @mldangelo-oai in #165
- fix: safely backfill legacy signed npm releases by @mldangelo-oai in #166
- fix: make missing scan artifact failures actionable by @mldangelo-oai in #167
Other changes
- [codex-security] Polish completed scan summary by @ianw-oai in #113
- feat: Automatically match scan comparisons by @ianw-oai in #114
- [codex-security] Remove scan error prefixes by @ianw-oai in #115
- [codex-security] Support nested Git repositories in scan snapshots by @ianw-oai in #116
- release: publish protected multi-architecture Codex Security images by @dc-oai in #17
- fix: read container manifest digests without broken pipes by @mldangelo-oai in #161
- fix: authenticate registry before image attestation by @mldangelo-oai in #162
- ci: modernize and harden container workflows by @mldangelo-oai in #163
- feat: automate verified npm and GitHub releases by @mldangelo-oai in #91
- fix: allow completion when no draft manifest exists yet (#73) by @onurtirpan in #83
- fix: keep scan output private through completion and exports by @mldangelo-oai in #118
- fix: salvage malformed optional remediation fields during finding recovery by @alarcritty in #159
- fix: consolidate contributor runtime-security hardening by @mldangelo-oai in #152
New Contributors
- @dc-oai made their first contribution in #17
- @onurtirpan made their first contribution in #83
- @alarcritty made their first contribution in #159
Full Changelog: npm-v0.1.4...npm-v0.1.5
Codex Security 0.1.4
Immutable
release. Only release title and notes can be modified.
What's Changed
- fix: preserve authoritative security scan targets by @ianw-oai in #103
- fix: document CLI help and deep-scan configuration by @mldangelo-oai in #105
- fix(windows): preserve sandbox override compatibility by @mldangelo-oai in #96
- fix: harden Node CI and Windows package smoke by @mldangelo-oai in #84
- fix: support managed Codex credential keyrings by @mldangelo-oai in #101
- fix: harden npm package lifecycle and Node support by @mldangelo-oai in #104
- release: bump Codex Security to 0.1.4 by @mldangelo-oai in #111
Full Changelog: npm-v0.1.3...npm-v0.1.4
Codex Security 0.1.3
Immutable
release. Only release title and notes can be modified.
What's Changed
- fix: make ChatGPT/API-key auth conflicts actionable by @mldangelo-oai in #19
- fix: clarify API-key precedence after access-token login by @daneschneider-oai in #23
- fix(windows): normalize canonical scan path casing by @hoquanganh09 in #64
- fix: include personal account in bulk-scan discovery by @JustasMonkev in #65
- fix: recover malformed security scan findings by @ianw-oai in #86
- fix(windows): preserve platform-safe canonical scan paths by @mldangelo-oai in #85
- docs: define the trusted-local Codex Security threat model by @mldangelo-oai in #61
- docs: Update README.md by @ianw-oai in #93
- fix: Could not save the Codex Security scan by @Alessio2405 in #67
- release: bump Codex Security to 0.1.3 by @mldangelo-oai in #94
New Contributors
- @hoquanganh09 made their first contribution in #64
- @JustasMonkev made their first contribution in #65
- @Alessio2405 made their first contribution in #67
Full Changelog: npm-v0.1.2...npm-v0.1.3
Codex Security 0.1.2
Immutable
release. Only release title and notes can be modified.
What's Changed
- feat: sync false-positive feedback and update notice by @ianw-oai in #21
- fix: preserve npm release gitHead by @mldangelo-oai in #74
- docs: fix npx examples to use scoped @openai/codex-security package name by @nickytonline in #69
- fix: surface actual security scan failures by @ianw-oai in #76
- fix: preserve completed scans when targets change by @ianw-oai in #78
- fix: expand tilde CODEX_HOME during security preflight by @ianw-oai in #80
- feat: add reasoning effort controls to security CLI by @ianw-oai in #79
- fix: invoke trusted git absolute path in multiscan checkout by @batmnnn in #59
- fix: preserve scans when reusing archived output by @ianw-oai in #77
- test: fix flaky Codex login regression by @mldangelo-oai in #82
- fix: keep completed security scan output concise by @ianw-oai in #81
- release: bump Codex Security to 0.1.2 by @mldangelo-oai in #75
New Contributors
- @nickytonline made their first contribution in #69
- @batmnnn made their first contribution in #59
Full Changelog: npm-v0.1.1...npm-v0.1.2
Codex Security 0.1.1
Immutable
release. Only release title and notes can be modified.
What's Changed
- docs: update readme by @ianw-oai in #18
- fix: resolve scan authentication conflicts and state errors by @daneschneider-oai in #22
- release: publish Codex Security 0.1.1 by @mldangelo-oai in #24
Full Changelog: npm-v0.1.0...npm-v0.1.1
Codex Security 0.1.0
Immutable
release. Only release title and notes can be modified.
What's Changed
- feat: bootstrap TypeScript public SDK and Node workflows by @mldangelo-oai in #3
- fix: harden public SDK prompt and CI boundary by @mldangelo-oai in #4
- test: smoke test the npm release tarball by @mldangelo-oai in #5
- test: make temporary directory cleanup idempotent by @mldangelo-oai in #7
- test: make CLI tests Windows-compatible by @mldangelo-oai in #9
- Add Socket Firewall to GitHub Actions workflows by @bryane-oai in #10
- fix: complete bounded Codex Security public plugin by @mldangelo-oai in #13
- fix(windows): correct authentication and Git hook tests by @mldangelo-oai in #14
- fix: restore the SDK package and add Docker CI by @mldangelo-oai in #11
- fix: pin customer container images and restore SDK CI by @GrantBirki in #15
- fix: restore bundled scanner and unblock public CI by @mldangelo-oai in #16
- release: prepare stable Codex Security npm publishing by @mldangelo-oai in #12
New Contributors
- @bryane-oai made their first contribution in #10
- @GrantBirki made their first contribution in #15
Full Changelog: https://github.com/openai/codex-security/commits/npm-v0.1.0