Repository navigation
Releases: woosungchoi/codex-telegram-bot
Release list
1.4.5 — Security hardening
Security patch release addressing seven follow-up findings.
Fixes
- Filter Codex child environments across SDK, direct app-server, accounts and workers so unrelated service credentials are not inherited.
- Enforce private-chat backup-administrator authorization before full-backup creation and again before delivery, including old tool callbacks.
- Anchor cleanup operations to no-follow directory descriptors and planned file identities; write handoffs exclusively in private storage with non-overwriting creation.
- Replace downloaded CLI shell installers with independently approved version/platform/SHA-256 artifact verification and bounded safe extraction.
- Separate PR review and dependency execution from privileged publication runners. Pin Actions, use trusted helpers, and validate bounded data artifacts.
Upgrade notes
- CLI updates require
CODEX_UPDATE_TRUST_FILEwith independently reviewed artifact metadata. Missing trust disables the bot's CLI updater; an existing installed CLI continues to run. - Regenerate cleanup previews made before this release. Cleanup mutations require Linux procfs and reject cross-filesystem quarantine moves.
- Handoffs now use
CODEX_HANDOFF_DIR, rather than repository-relativedocspaths. - Environment filtering is not same-UID filesystem isolation. See security boundaries.
Validation
Public verification: 1,037 passed, one existing skip; 50 added regression tests preserved the previous suite. Dependency audit: zero vulnerabilities. Security patch and release changes passed the required GitHub checks before normal PR merge. This release does not imply a new scanner run.
Security patch: #114
1.4.4 — Security hardening
Security hardening
This release addresses the security boundaries reviewed in PR #112:
- Keep failed-CI diagnosis deterministic; do not feed untrusted logs to a credentialed agent.
- Authenticate worker RPC, rotate credentials on restart and give question tools expiring capabilities scoped to one job.
- Bound RPC frames/connections, streamed attachment downloads and concurrent side replies.
- Enforce direct app-server network, search, writable-root and Git-workspace controls.
- Serialize recovery snapshot updates and prevent late updates from recreating completed tasks.
- Reject upload/photo symlink escapes and send validated photo bytes instead of reopening paths.
- Require private chats and explicit
BACKUP_ADMIN_USER_IDSfor full backups; an empty list permits nobody.
Upgrade notes
- Drain active jobs and pending final deliveries, then restart both bot and worker to load the authenticated RPC protocol.
- Review sandbox configuration. Same-user processes are not isolated by RPC credentials. Sidecar generation now requires explicitly trusted
danger-full-access; unsupported sandboxed sidecar jobs fail closed. Do not weaken sandbox settings just to bypass this refusal. - For sandboxed execution, stop the worker and set
CODEX_WORKER_MODE=inline,CODEX_STEERING=falseandCODEX_INTERACTIVE_QUESTIONS=false. The example env files select this configuration. Existing unspecified runtime defaults are retained. - Configure backup administrator IDs explicitly. Chat-specific exports keep their existing behavior.
- Descriptor-based attachment validation currently requires Linux
/proc/self/fd; unsupported platforms fail closed.
See security hardening and compatibility details.
Validation
The public distribution passed 987 tests with one pre-existing skipped test and no failures. Dependency audit reported zero vulnerabilities. The release PR is checked on Node 18, 20, 22, 24 and 26, with integration coverage and a dedicated security audit.
Full changelog: v1.4.3...v1.4.4
1.4.3 — Unified task dashboard and verified input receipts
Unified task dashboard
- Start each task with one pinned dashboard containing receipt, file and result
buttons. Keep detail previews in the same card, with bounded output and a Back
button; fall back to an ordinary card if pinning is unavailable. - Remove the whole card and its buttons only after confirmed final-answer
delivery. Preserve uncertain or failed delivery, retry failed deletion across
restarts, and prevent stale callbacks from recreating completed cards. - Show native plan, aggregate diff and token snapshots. Execution completion,
input receipt and Telegram delivery remain separate states.
Input confirmation and safe inspection
- Reflect durable worker input acknowledgements automatically. Distinguish
unchecked and pending input from genuinely uncertain delivery; temporary
lookup failures cannot erase a confirmed receipt. - Add owner-bound
/progressand/recoveryinspection in the current
chat/topic, plus changed-file, bounded diff and verified result views. - Persist native client IDs before app-server submission and acknowledgements
afterwards. Recover only already completed matching inputs from read-only
history; uncertain input is never automatically resubmitted. - Preserve distinct completed, failed and interrupted outcomes, with English,
Korean, Russian and Traditional Chinese UI text. See
Task dashboard and input receipts.
Dependencies and upgrade
- Update the Codex CLI and SDK packages to
0.160.1. - Restart both the bot and worker after upgrading, once active tasks and pending
final deliveries finish, so the new receipt/inspection protocol is available. - Transports without native receipt support can remain unchecked until a
completed result is available. Telegram API acceptance is not a human read receipt.
Full changes: v1.4.2...v1.4.3
1.4.2
Worker terminal delivery and recovery
- Publish terminal status, completion time, final event and cursor together in
the job snapshot before exposing completion to delivery consumers. This fixes
the terminal-delivery receipt race addressed by
PR #106. - Replay a terminal event from the committed snapshot when its log append was
interrupted, including a final JSON record without a newline. Preserve event
ordering, pagination and archive replay without duplicating the final event. - Keep raw Codex turn completion from prematurely finishing a worker job. Late
heartbeat/control callbacks cannot reopen a completed job or move its cursor. - Preserve failure evidence during failed admission and orphan recovery. Retain
the existing one-worker-per-state-directory and no-power-loss-durability limits.
Telegram steering and decisions
- Default new or unset queue modes to
steer; enableCODEX_STEERINGby default.
Existing saved modes and explicitCODEX_STEERING=falseremain respected. - Add
/steer,/queue_mode_steerand a queue-mode button. Safe mode retains an
explicit Apply to current task action. Restore live replies/activity updates
with app-server steering, without duplicate streamed text or final delivery. - Preserve durable steering receipts, requester/chat/topic validation, duplicate
protection and explicit holds for uncertain delivery across restarts. - Add optional sequential Telegram decision buttons, typed answers and cancellation.
The per-job MCP tool waits for required answers; independent chats remain concurrent.
Frontend reconnects retain waiting questions. Interrupted worker decisions require
explicit recovery and are never silently replayed. See
Telegram questions.
Operational status
- Add opt-in
/opssnapshots with configurable service metrics, localized labels
and timestamps, freshness warnings and bounded read-only JSON input. No shell
execution or provider credentials are required by this command. See
Operational status.
Upgrade and validation
- Drain active jobs and final-message delivery before restarting the worker, then
restart both worker and bot to load steering and terminal-state fixes. A package
version bump alone does not update an already-running process. - Add regression coverage for terminal publication, interrupted writes, archives,
late callbacks, steering and decision recovery, and operational status inputs.
Verify each distribution against its own pinned dependencies and CI gates.
Full changelog: v1.4.1...v1.4.2
1.4.1 — Worker integrity and safer dependency updates
1.4.1 — Worker integrity and safer dependency updates
Worker transport and concurrent admission
- Preserve Korean, emoji and other multibyte UTF-8 text when RPC data arrives
across byte boundaries; reject incomplete frames on disconnect. - Serialize admission through durable reservation and controller registration.
Matching job-ID retries return the existing status without executing twice;
different chats continue to execute concurrently. - Keep live chat reservations even if the disk index changes. Roll back failed
admissions; if rollback fails, pause new admission until healthy recovery.
Event log and storage recovery
- Derive event sequences from the committed, newline-terminated JSONL prefix,
reconciling stale state and cursors without reusing sequence numbers. - Preserve incomplete trailing writes in private quarantine before trimming.
Reject duplicate/decreasing sequences and logs behind persisted cursors. - Surface
EVENT_COMMITTEDwith the committed sequence when appending succeeds
but saving job state fails. Callers must not blindly repeat that event body. - Distinguish missing files, corrupt JSON/container structures, and permission
or I/O errors. Rebuild missing/corrupt active indexes only after validating
job records, preserving originals and propagating quarantine failures. - Recover interrupted reservations at startup without re-executing orphaned work.
Dependency pull-request merge security
- Verify updater author IDs/types and repository identity; reject spoofed branch
names and external forks. Preserve supported owner-PAT and Actions identities. - Inspect files at immutable commits as data; execute only trusted workflow code.
Permit dependency-version changes or Dependabot action-reference changes,
while routing script, permission and unrelated changes to manual review. - Require successful CI for the exact head commit, recheck head/base SHAs before
merging, and use--match-head-commitwithout an administrator bypass.
Upgrade and verification notes
- Add regression coverage for UTF-8 splits, concurrent starts and retries,
interrupted append/state saves, partial records, I/O failures, quarantine
failures and malicious or changed dependency PRs. - Stop accepting new work and drain running jobs plus final delivery before
restarting the worker. Historical invalid logs require explicit recovery;
preserve originals rather than discarding or replaying ambiguous records. - Recovery assumes one worker per state directory. File writes are not fsynced,
so this release does not promise OS/power-loss durability. Arbitrary event
bodies have no deduplication key. See Worker integrity.
Dependencies
- Public Codex SDK/CLI:
0.159.3→0.160.0.
Changes: v1.4.0…v1.4.1 · PR #99
1.4.0 — Cleanup storage reclamation and security
Session cleanup and disk reclamation
- Make the three Cleanup options follow distinct file operations. Quarantine
only moves eligible session logs into the quarantine directory and retains
their contents. Permanently delete only unlinks files that have already
completed their quarantine period. Both quarantines new candidates and
deletes only previously expired quarantine files. - Remove backup copies from permanent deletion. Newly deleted session contents
are no longer duplicated indelete-backupdirectories, so deleting expired
files can reclaim their storage. Keep only small plans, results and operation
receipts, with irreversible deletion explicitly recorded in the manifest. - Preserve the existing retention policy: sessions become quarantine candidates
after their configured retention period, and newly quarantined files must
complete their own quarantine period before deletion. The default 14-day
session retention and 7-day quarantine period are unchanged.
Execution safety and restore behavior
- Recheck protected thread IDs and the current quarantine timestamp immediately
before deletion. Skip files that are still protected, were quarantined too
recently, have an invalid timestamp, or fall exactly on the retention cutoff.
Execution uses current metadata instead of trusting a previously approved plan. - Refuse deletion outside the configured quarantine directory or through linked
paths; require a regular file with a matching real path. Require regular
quarantine metadata files, and reject unsupported action names before creating
operation artifacts. - Keep missing-file handling idempotent: files already removed after planning
are skipped instead of producing anENOENTfailure. - Return a restore-script path only when an operation actually quarantined files.
New permanent deletions cannot be restored. Generated restore scripts skip
irreversible deletion records while retaining support for quarantine moves
and historical deletion records that already have backups. Existing historical
backups are not automatically purged by this release. - Show the no-backup/no-restore notice in English, Korean, Traditional Chinese
and Russian when permanent deletion occurs. Document all three options and
their retention and restoration rules in both English and Korean READMEs.
Security and dependencies
- Pin transitive
basic-ftpto patched version6.2.1through an npm override,
resolving GHSA-c475-qrg2-pj4r
in theproxy-agent → pac-proxy-agent → get-uridependency chain. Preserve the
security audit gate and the existing proxy stack; this fix does not downgrade
proxy-agentor suppress vulnerability reports. See
PR #95. - Refresh the public Codex SDK and CLI packages from
0.159.0in 1.3.9 to
0.159.3. Preserve the existing application settings and persisted state.
Verification and upgrade notes
- Add regression coverage for all three options, absence of payload backups,
recently quarantined and protected files, changed timestamps, exact retention
boundaries, linked paths, invalid actions, and mixed legacy/new restore records. - Verify the full suite (860 passed, one skipped), syntax, lint, formatting,
types, architecture and UI localization. Verify zero reported npm
vulnerabilities and FTP compatibility through the existingget-uristack. - No state migration or new Cleanup setting is required. Review the permanent
deletion choice with the understanding that new deletions are irreversible.
Full changelog: v1.3.9...v1.4.0
1.3.9 — Codex updates and clearer Telegram panels
Highlights
- Codex updates from Telegram: find the update button under Tools → Codex Maintenance, below reports and backups. Administrator checks, expiring previews and installation locks guard activation. Updates are staged using the official installer, wait for active work and final replies, preserve queued requests and account/model settings, verify services, and support rollback.
- One update panel: progress and the final success or failure result edit the original message, including after service restarts. Completion no longer adds a separate message or leaves “starting” behind.
- Quiet menu closing: Close deletes the menu message without adding a confirmation message.
- Reliable cleanup: candidates removed after planning are skipped instead of producing missing-file errors.
- Worker startup readiness: bounded handshake retries handle transient socket startup errors before bot activation; genuine failures remain visible.
- Security and dependencies: patched
brace-expansionandip-address, plus refreshed public Codex SDK/CLI and npm packages. Security checks remain enabled.
Verification
- Full local verification: 852 tests passed, 1 skipped; syntax, lint, formatting, types, architecture and localization checks passed.
- Security audit: 0 vulnerabilities.
- GitHub Actions CI: all seven jobs passed on the release commit, including Node.js 18/20/22/24/26, integration coverage and the security audit.
- GitHub Actions Release: passed; the annotated tag matches package version
1.3.9. - Package contents checked, including executable bot/worker entry points and the update runtime.
What's Changed
- build(deps): bump the npm-dependencies group with 2 updates by @dependabot[bot] in #89
- Update Codex packages by @woosungchoi in #90
- build(deps): bump the npm-dependencies group with 2 updates by @dependabot[bot] in #91
- Update Codex packages by @woosungchoi in #92
Full Changelog: v1.3.8...v1.3.9
1.3.8 — Clearer progress and reliable delivery
Highlights
- Live progress no longer reports ignored Codex configuration notices as task errors; real errors remain visible.
- Completed chats continue after an uncertain Telegram final-reply timeout without rerunning the Codex turn.
- Guarded removal of the bot default account and clearer authenticated-account usage display.
- Refreshed Codex dependencies and stabilized CI checks.
What's Changed
- Update Codex packages by @woosungchoi in #78
- Update Codex packages by @woosungchoi in #79
- build(deps): bump the npm-dependencies group with 3 updates by @dependabot[bot] in #80
- build(deps): bump the npm-dependencies group with 3 updates by @dependabot[bot] in #81
- Update Codex packages by @woosungchoi in #82
- Prevent dependency PR auto-merge races by @woosungchoi in #83
- Pin CI to Ubuntu 24.04 and stabilize Node 20 heartbeat test by @woosungchoi in #84
- Run CI on Ubuntu 26.04 by @woosungchoi in #85
- build(deps): bump dotenv from 18.0.1 to 18.0.2 in the npm-dependencies group by @dependabot[bot] in #86
- Update Codex packages by @woosungchoi in #87
- Update Codex packages by @woosungchoi in #88
Full Changelog: v1.3.7...v1.3.8
1.3.7 — Complete UI localization and Russian support
1.3.7 - 2026-09-16
- Add Russian and complete all 1,255 translation keys in English, Korean,
Traditional Chinese and Russian, including settings, account and usage menus,
skills, diagnostics, progress, time zones and default response instructions. - Move fixed Telegram UI text into shared locale catalogs. Resolve the current
language when rendering and preserve command syntax, callback data, model IDs,
external messages and user content. - Localize application validation errors at the UI boundary while retaining
English diagnostic messages and optional locale metadata through worker
requests, persisted events and recovery replay. - Add a UI localization source check to verification, document the translation
policy, and cover all supported languages, live language changes, escaping,
callback behavior and worker error replay with regression tests. - Update public tooling to TypeScript 7 and retain the TypeScript 6 compiler API
for source checks. Make compiler selection explicit, preserve the existing
strictness policy, and update Node.js types and markdown-it in
PR #73.
Thank you to 9Lucky9 for the Russian locale contribution in
PR #76.
Update both the bot and worker after active jobs finish. Back up the complete state directory before restarting.
Full changelog: v1.3.6...v1.3.7
1.3.6 — Menu updates in place
What's fixed
- Account status checks, account selection, rotation, and registration/rename/removal prompts update the current Telegram message.
- Reset credit browsing, pagination, confirmation, and results stay in the same panel. Prompt bindings remain correct when an edit changes nothing or Telegram requires a replacement message.
- Queue cancellation/reordering controls and cleanup previews update the existing menu instead of appending messages.
- Expired or unauthorized buttons show a callback notice without overwriting the current panel. Repeated confirmations cannot replace completed results or redeem another Reset credit.
- Workspace errors preserve valid retry buttons, including private-chat topic setup guidance.
Upgrade
Update the bot and restart its service to load the callback fixes. This release has no state migration or runtime dependency changes; preserve the existing configuration and state directory.
The coverage artifact uploader also moves to actions/upload-artifact@v7.
Full changelog: v1.3.5...v1.3.6
Validation
- Clean-install
npm run verify: 783 passing tests, 0 failures, 1 existing Node 26 multipart compatibility skip. - Dependency audit: 0 vulnerabilities.
- Package version, contents and executable entry points verified; checksum recorded.
- GitHub release PR CI passed on Node 18, 20, 22, 24 and 26, including integration coverage and security audit.