Codex Security 0.1.23
·
25 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
Highlights
- Store complete findings and embeddings in the preview findings service, with
paginated listing, repository-scoped candidate retrieval, and durable duplicate
groups. Publish a completed scan with
publish scan --to custom --scan SCAN_ID --findings-url URL, or preview the
payload with--dry-run. See the
findings service
and custom publication. - Review potential duplicates from the CLI or SDK with
dedupe --scan SCAN_ID --findings-url URL. Reviews run on the calling host and save accepted groups
without replacing original findings. Searches default to the scan's repository;
--all-repositoriesexplicitly broadens the scope. Add--workflow-idto scan,
custom publication, and deduplication to reuse completed stages and checkpointed
reviews after interruption. See
deduplication
and workflow recovery. - Browse stored findings and duplicate groups in the service's read-only
/dashboard, with search, repository filters, sorting, and record details.
The dashboard shows service-owned data, not local scan or workflow history.
See the dashboard guide. - Run the scanner and findings service from the same container image in separate
containers, with a Compose runner for the scanner CLI and separate persistent
state. The image supports Linuxamd64andarm64. See
container releases and the workflow runner. - Preserve sealed scan artifacts when optional follow-up instructions fail,
propagate caller cancellation during cloud publication, respect the exact
POSIXPATHwhen resolving trusted executables, and retain nested attack-path
evidence strings in saved finding previews.
Upgrade notes
- Version 0.1.22 was not published to npm or GitHub Releases. This release includes
its changes and the release-runner fix. - The findings API and dashboard have no built-in authentication. Keep the
service on a trusted local endpoint or behind an authenticated TLS proxy;
Compose publishes only to host loopback. Nonempty imports send complete finding
JSON to the OpenAI embeddings API and require an API key. A ChatGPT login is not
an embedding credential. Duplicate review uses the calling host's Codex
credentials separately, and embedding and review calls can incur usage charges. - Stop the findings service and back up its entire state directory before
upgrading. Startup applies SQLite migrations automatically; rollback requires
the pre-upgrade backup and previous image. Existing findings are not
automatically embedded: import them with their repository ID before using
repository-scoped deduplication. Keep runner state separate from service state.
See backups and upgrades. - Container publication is separate from npm publication. Use a version or digest
only after the selected image release is available; source builds remain
supported. Follow the container setup
before the first registry release. - Source checkouts now generate the SDK's bundled plugin from
plugins/codex-security. Contributors should edit the canonical plugin source
and runpnpm run build:plugin; the published npm package still includes the
runtime payload. See plugin source ownership.
The categorized list below contains the individual changes.
What's Changed
Features
- feat(typescript): add findings service plumbing by @kmbroai in #653
- feat(typescript): persist findings and embeddings through the API by @kmbroai in #660
Fixes
- fix(sdk): prefer exact POSIX PATH for trusted executables by @Hughhhhcoder in #676
- fix(sdk): preserve caller cancellation in cloud publication by @Hughhhhcoder in #677
- fix(ci): guard generated plugin Markdown changes by @soyeon-oai in #683
- fix(sdk): preserve sealed artifacts after post-scan failure by @mldangelo-oai in #626
- fix(plugin): preserve nested attack-path evidence in previews by @soyeon-oai in #691
- fix(publish): explain findings before scan details by @ianw-oai in #689
- fix(ci): install ripgrep for npm release verification by @kmbroai in #698
Documentation
- docs: clarify plugin source ownership by @soyeon-oai in #685
Other changes
- refactor(plugin): generate the bundled runtime from canonical source by @soyeon-oai in #675
- refactor(plugin): colocate runtime payload contract by @soyeon-oai in #686
- chore: configure development environment by @kylos101 in #697
- refactor(container): share one image for scanner and findings service by @kmbroai in #701
New Contributors
Full Changelog: npm-v0.1.21...npm-v0.1.23