Skip to content

Codex Security 0.2.0

Latest

Choose a tag to compare

@github-actions github-actions released this 06 Oct 03:20
· 253 commits to main since this release
Immutable release. Only release title and notes can be modified.
4949af7

Highlights

  • Threat models are now saved with Standard, Deep, and Diff scan results and generated security policies. Export a saved model without another model call using codex-security export --artifact threat-model or the SDK's exportArtifact helper. (#1133)

  • Scans now check for exposed credentials in source code, including unused code and tests, and distinguish suspected exposures from placeholders. This check runs offline, without trying discovered credentials against a service. (#1134)

  • Use --model and --effort when generating patches, validating findings, verifying fixes, or matching and comparing saved scans. Deep Scan workers and patches generated during a scan also respect your selected service tier. (#1143, #1238, #1274)

  • Patch, validation, and fix-verification commands now respect custom model providers and their authentication settings. Amazon Bedrock users get clearer authentication errors and cost estimates for Daybreak Blue and Red. Eligible OpenAI API-key users can select a Cyber access program for each scan. (#1131, #1187, #1188, #1185)

  • Scans include previously overlooked C++ headers (.hh and .hxx), server-rendered templates (EJS, ERB, and PHTML), and Vyper source files when selecting code to review. (#1079, #1197, #1306)

  • On Unix, scans check that the sandbox works before starting paid model calls. Completed results are kept if you cancel follow-up work. CSV exports can now be reimported without rejecting multiple occurrences of a finding or losing leading apostrophes. (#1084, #1057, #1247)

Upgrade notes

  • If your integration reads threat models, check SecurityPolicyDraft.threatModelPath for null before opening the file. Policy generation now writes threatmodel.md instead of THREAT_MODEL.md; use the returned path. Saved models can contain Markdown (format: "markdown", content) or the previous structured format, so readers must handle both. Existing models remain readable and exportable without migration. (#1133)

  • Findings service clients must send Content-Type: application/json to POST /v1/bulk/findings and POST /v1/dedupe-groups. Missing or other content types return HTTP 400 invalid_request. A charset parameter is accepted. (#1277)

  • Codex Security no longer masks diagnostic text that looks like credentials. CLI output and saved error, publication, and patch-risk summaries can contain sensitive values. Review them before sharing. (#1179)

  • SDK types and CLI schemas now accept any nonempty string for reasoning effort. Update integrations that assume a fixed list. The chosen value must still be supported by Codex and your model provider. (#1237)

  • Older CSV exports may have ambiguous leading apostrophes that cannot be recovered from the CSV alone. Export the original saved results as JSON if you need those exact values. (#1247)

What's Changed

Expand the full list of changes

Breaking changes

  • feat(threat-model)!: save models with results and support offline export by @mldangelo-oai (#1133)

Features

Fixes

Documentation

Other changes

  • The default remains GPT-5.6 Sol. The proposed GPT-6 Sol xhigh default in #1078 was reverted before release in #1181.
  • Diagnostic redaction was removed before release. The opt-out added in #1176 was superseded by #1179; see the upgrade notes above.
  • chore(deps): bump the third-party group across 2 directories with 4 updates by @dependabot[bot] (#1032)
  • chore(deps-dev): bump ruff from 0.16.7 to 0.16.8 in /plugins/codex-security by @dependabot[bot] (#1022)
  • chore(deps): bump the codex group across 3 directories with 2 updates by @dependabot[bot] (#1033)
  • chore(deps): upgrade Codex CLI and SDK to 0.157.1 by @dependabot[bot] (#1041)
  • chore(deps): bump the third-party group across 3 directories with 3 updates by @dependabot[bot] (#1070)
  • chore(deps): bump the codex group across 3 directories with 2 updates by @dependabot[bot] (#1076)
  • chore(release): 0.1.32 by @github-actions[bot] (#1027)
  • chore(deps): upgrade Codex CLI and SDK to 0.159.0 by @dependabot[bot] (#1088)
  • chore(deps): upgrade OpenCode SDK to 1.18.32 by @dependabot[bot] (#1090)
  • chore(deps): bump Codex CLI and SDK to 0.159.2 by @dependabot[bot] (#1100)
  • chore(deps): update Linear SDK, smol-toml, and Prettier by @dependabot[bot] (#1101)
  • chore(deps): bump fast-uri from 3.1.7 to 3.1.8 in /sdk/typescript by @dependabot[bot] (#1106)
  • chore(deps): bump fast-uri from 3.1.7 to 3.1.8 in /plugins/codex-security/mcp-app by @dependabot[bot] (#1109)
  • chore(deps): bump brace-expansion from 5.0.9 to 5.0.12 in /sdk/typescript by @dependabot[bot] (#1107)
  • chore(deps): bump ip-address from 10.7.0 to 10.7.2 in /plugins/codex-security/mcp-app by @dependabot[bot] (#1108)
  • chore(deps): bump Codex SDK and CLI to 0.159.3 by @dependabot[bot] (#1170)
  • chore(deps): bump MCP SDK to 1.30.1 in MCP app and evals by @dependabot[bot] (#1171)
  • ci: reuse native builds across package and container checks by @mldangelo-oai (#1130)
  • ci: smoke test published npm installs across supported platforms by @mldangelo-oai (#1129)
  • ci: require workflow checks and production dependency audits by @mldangelo-oai (#1128)
  • revert: restore GPT-5.6 Sol as the default model by @mluck-openai (#1181)
  • chore(deps): update Codex for per-turn Cyber selection by @mldangelo-oai (#1184)
  • refactor(plugin): add wide Windows candidate file operations by @kmbroai (#836)
  • refactor(plugin): port candidate normalization to TypeScript by @kmbroai (#837)
  • chore(deps): bump @linear/sdk from 95.2.0 to 96.0.0 in /sdk/typescript by @dependabot[bot] (#1191)
  • chore(deps-dev): bump ruff from 0.16.8 to 0.16.9 in /plugins/codex-security by @dependabot[bot] (#1189)
  • chore(deps): bump the codex group across 3 directories with 2 updates by @dependabot[bot] (#1195)
  • refactor(native): remove unused OS primitives and proofs by @mldangelo-oai (#1192)
  • refactor(mcp): remove unused scan machinery and share fixtures by @mldangelo-oai (#1193)
  • refactor(sdk): consolidate helpers and adjacent tooling by @mldangelo-oai (#1194)
  • chore(deps-dev): bump @types/node to 26.6.3 by @dependabot[bot] (#1199)
  • chore(deps): bump Codex CLI and SDK to 0.162.0-alpha.9 by @dependabot[bot] (#1198)
  • refactor(evals): share triage assertion output parsing by @mldangelo-oai (#1201)
  • refactor(sdk): simplify contradiction grouping state by @mldangelo-oai (#1202)
  • refactor(tooling): share repository Git adapters by @mldangelo-oai (#1203)
  • refactor(ci): consolidate build and tool setup by @mldangelo-oai (#1204)
  • refactor(plugin): simplify workbench owner calls by @mldangelo-oai (#1205)
  • refactor(plugin): simplify artifact storage boundaries by @mldangelo-oai (#1206)
  • refactor(sdk): reuse runtime and authentication setup by @mldangelo-oai (#1207)
  • refactor(plugin): share finalizer fixtures and migration moves by @mldangelo-oai (#1216)
  • refactor(ci): reuse Markdown tool setup by @mldangelo-oai (#1215)
  • refactor(cli): simplify command setup and fixtures by @mldangelo-oai (#1208)
  • refactor(sdk): simplify persisted finding workflows by @mldangelo-oai (#1210)
  • refactor(sdk): simplify publication preparation by @mldangelo-oai (#1211)
  • refactor(plugin): simplify Deep Scan coordinator ownership by @mldangelo-oai (#1213)
  • refactor(plugin): simplify Deep Scan worker launch by @mldangelo-oai (#1212)
  • refactor(sdk): share progress and event parsing by @mldangelo-oai (#1209)
  • refactor(plugin): simplify artifact projections by @mldangelo-oai (#1227)
  • refactor(plugin): simplify workbench persistence by @mldangelo-oai (#1226)
  • refactor(mcp): reuse parsed artifact tool inputs by @mldangelo-oai (#1224)
  • refactor(evals): reuse parsing and Git helpers by @mldangelo-oai (#1222)
  • chore(deps): bump the codex group across 3 directories with 2 updates by @dependabot[bot] (#1220)
  • refactor(plugin): reuse migration repair declarations by @mldangelo-oai (#1225)
  • refactor(release): share provenance verification plumbing by @mldangelo-oai (#1233)
  • refactor(sdk): consolidate internal runtime helpers by @mldangelo-oai (#1230)
  • refactor(ci): share container Compose smoke checks by @mldangelo-oai (#1231)
  • refactor(tooling): migrate tests to TypeScript and simplify tooling by @mldangelo-oai (#1219)
  • chore(deps): update Codex CLI and SDK to 0.162.0-alpha.14 by @dependabot[bot] (#1242)
  • chore(deps): bump eval OpenCode SDK to 1.18.33 by @dependabot[bot] (#1243)
  • refactor(tests): simplify fixtures and eval tooling by @mldangelo-oai (#1292)
  • chore(deps): cover container and native dependencies by @mldangelo-oai (#1246)
  • chore(deps): update Codex CLI and SDK to 0.162.0-alpha.15 by @dependabot[bot] (#1303)
  • chore(deps): upgrade native napi build and derive dependencies by @dependabot[bot] (#1302)
  • chore(deps): bump node from 22-bookworm-slim to 26-bookworm-slim by @dependabot[bot] (#1300)
  • chore(deps): update GitHub CLI and Docker-in-Docker features by @dependabot[bot] (#1299)
  • chore(deps): bump @linear/sdk from 96.0.0 to 97.0.0 in /sdk/typescript by @dependabot[bot] (#1305)
  • chore(deps): update MCP SDK to 1.31.0 for plugin and evals by @dependabot[bot] (#1304)
  • chore(deps): bump proxy-addr from 2.0.7 to 2.0.8 in /evals/triage-finding by @dependabot[bot] (#1315)
  • chore(deps): bump compression from 1.8.1 to 1.8.2 in /evals/triage-finding by @dependabot[bot] (#1316)
  • chore(deps): bump proxy-addr from 2.0.7 to 2.0.8 in /plugins/codex-security/mcp-app by @dependabot[bot] (#1314)

New Contributors

Full Changelog: npm-v0.1.31...npm-v0.2.0