Skip to content

Codex Security 0.1.25

Choose a tag to compare

@github-actions github-actions released this 02 Sep 00:14
· 552 commits to main since this release
Immutable release. Only release title and notes can be modified.
7d042cd

Highlights

  • Preserve confirmed finding identities across scans and comparisons, and show
    related findings with their reasons while keeping distinct findings separate.
    Large comparisons now use bounded batches without truncating finding text;
    inputs that cannot fit leave matching explicitly incomplete.
  • Improve deduplication with separate screening and pair reviews, validated
    pair assignments, and groups that respect explicit DISTINCT decisions.
    Invalid submissions receive one corrective turn; blocked reviews fail without
    recording a verdict. DeduplicationReviewError exposes structured, sanitized
    failure details. The SDK also adds deduplicateScanDirectory for complete,
    sealed scans outside local history.
  • Generate synthetic Standard scan results with scan --mock or the SDK's
    mock: true, without authentication or model calls. Mock results support
    normal reports, exports, history, and reruns. See
    mock scans.
  • Increase a running scan's total budget from the interactive dashboard when
    usage reaches 80% of its limit, or use the SDK's onBudgetApproaching
    callback. The existing limit remains enforced until an increase is saved.
    See scan cost limits.
  • Recognize existing Codex authentication in CLI and SDK login status. SDK
    scans, comparisons, and deduplication reviews now honor native command-auth
    providers, including renewable tokens.
  • Configure the findings service's full embeddings endpoint with
    CODEX_SECURITY_EMBEDDINGS_URL. The new @openai/codex-security/server
    exports support embedding credentials supplied by a callback before each
    HTTP batch. See
    embeddings and storage.
  • Include PowerShell module (.psm1) and data (.psd1) files in scan
    inventories, and recognize BOM-marked UTF-16 source files as text.
  • Preserve scoped scan and component-plan inventories after directory renames
    that change only letter casing on case-insensitive filesystems.
  • Support long Codex executable paths on Windows, including nested Deep Scan
    workers, and retry credential snapshots for another Get-Acl path-not-found
    race when a descendant disappears during inspection.
  • Honor case-insensitive Windows environment variable names during finding
    deduplication, so configured API credentials and private configuration paths
    are used consistently.
  • Stream tracked binary diffs when hashing repository snapshots, reducing
    memory use while preserving the existing digest format.
  • Include complete OCI metadata in container image labels and multiarchitecture
    annotations, with documentation pinned to the source commit and image
    verification commands in the release workflow summary. See
    container metadata and verification.

Upgrade notes

  • Mock mode is opt-in and saves clearly marked synthetic findings in local
    history; use a separate CODEX_SECURITY_STATE_DIR for disposable test data.
    It supports Standard scans only and does not audit the repository.
  • Interactive budget increases are unavailable in CI, JSON/JSONL, headless,
    and verbose modes. Existing cost limits continue to apply in those modes.
  • The embeddings URL defaults to the existing OpenAI endpoint. A configured
    endpoint receives finding inputs and the bearer credential and must support
    the OpenAI embeddings format. Embeddings credentials remain separate from
    Codex ChatGPT sign-in.
  • Local history applies an automatic database index migration. Completed scan
    artifacts remain unchanged.
  • Source builds now use repository-pinned pnpm 11.19.0, including MCP app
    dependencies, whose configuration requires a seven-day minimum release age.
    From the repository root, run
    pnpm --dir plugins/codex-security/mcp-app install --frozen-lockfile.
    See
    running without Docker.
  • Container publication remains separate from npm publication. Existing stable
    container tags are not updated in place.

Build and CI updates also improve package verification, portable Python checks,
Windows fixtures, and test scheduling. Documentation clarifies portable
environment-variable guidance and safe examples.

The categorized list below contains the individual changes.

What's Changed

Features

  • feat: allow configuring the findings embeddings URL by @kmbroai in #765
  • feat(cli): allow interactive scan budget increases by @mldangelo-oai in #724
  • feat(sdk): honor command auth and renewable embeddings credentials by @kmbroai in #769
  • feat: preserve cross-scan finding relationships by @mldangelo-oai in #574
  • feat(sdk): deduplicate sealed scan directories by @kmbroai in #779
  • feat(cli): add mock scans with synthetic findings by @kmbroai in #783
  • feat(typescript): align deduplication review stages by @kmbroai in #780

Fixes

  • fix(sdk): retry Windows Get-Acl path-not-found races by @faizan-oai in #731
  • fix(ci): preserve LF Python source checkouts by @faizan-oai in #726
  • fix(container): publish metadata on multi-architecture images by @mldangelo-oai in #714
  • fix(plugin): include PowerShell module and data files by @faizan-oai in #715
  • fix(windows): preserve scoped inventories after case-only renames by @faizan-oai in #633
  • fix(windows): honor dedupe environment settings by @faizan-oai in #696
  • fix(windows): support long Codex executable paths by @faizan-oai in #704
  • fix(plugin): recognize BOM-marked UTF-16 source files by @faizan-oai in #716
  • fix(cli): use shell-neutral env-var removal guidance by @mangeshraut712 in #754
  • fix(auth): make login status recognize existing Codex authentication by @Ultron09 in #738
  • fix: limit finding comparison input size by @ianw-oai in #638
  • fix: surface deduplication review failure reasons by @kmbroai in #766
  • fix(plugin): stream tracked diffs while hashing by @Hughhhhcoder in #773
  • fix(typescript): harden deduplication review validation by @kmbroai in #781

Documentation

Other changes

New Contributors

Full Changelog: npm-v0.1.24...npm-v0.1.25