Skip to content

Releases: woosungchoi/codex-telegram-bot

1.4.5 — Security hardening

Choose a tag to compare

@woosungchoi woosungchoi released this 08 Oct 08:11
6f36f2e

Security patch release addressing seven follow-up findings.

Fixes

  • Filter Codex child environments across SDK, direct app-server, accounts and workers so unrelated service credentials are not inherited.
  • Enforce private-chat backup-administrator authorization before full-backup creation and again before delivery, including old tool callbacks.
  • Anchor cleanup operations to no-follow directory descriptors and planned file identities; write handoffs exclusively in private storage with non-overwriting creation.
  • Replace downloaded CLI shell installers with independently approved version/platform/SHA-256 artifact verification and bounded safe extraction.
  • Separate PR review and dependency execution from privileged publication runners. Pin Actions, use trusted helpers, and validate bounded data artifacts.

Upgrade notes

  • CLI updates require CODEX_UPDATE_TRUST_FILE with independently reviewed artifact metadata. Missing trust disables the bot's CLI updater; an existing installed CLI continues to run.
  • Regenerate cleanup previews made before this release. Cleanup mutations require Linux procfs and reject cross-filesystem quarantine moves.
  • Handoffs now use CODEX_HANDOFF_DIR, rather than repository-relative docs paths.
  • Environment filtering is not same-UID filesystem isolation. See security boundaries.

Validation

Public verification: 1,037 passed, one existing skip; 50 added regression tests preserved the previous suite. Dependency audit: zero vulnerabilities. Security patch and release changes passed the required GitHub checks before normal PR merge. This release does not imply a new scanner run.

Security patch: #114

1.4.4 — Security hardening

Choose a tag to compare

@woosungchoi woosungchoi released this 08 Oct 00:46
3cff7be

Security hardening

This release addresses the security boundaries reviewed in PR #112:

  • Keep failed-CI diagnosis deterministic; do not feed untrusted logs to a credentialed agent.
  • Authenticate worker RPC, rotate credentials on restart and give question tools expiring capabilities scoped to one job.
  • Bound RPC frames/connections, streamed attachment downloads and concurrent side replies.
  • Enforce direct app-server network, search, writable-root and Git-workspace controls.
  • Serialize recovery snapshot updates and prevent late updates from recreating completed tasks.
  • Reject upload/photo symlink escapes and send validated photo bytes instead of reopening paths.
  • Require private chats and explicit BACKUP_ADMIN_USER_IDS for full backups; an empty list permits nobody.

Upgrade notes

  1. Drain active jobs and pending final deliveries, then restart both bot and worker to load the authenticated RPC protocol.
  2. Review sandbox configuration. Same-user processes are not isolated by RPC credentials. Sidecar generation now requires explicitly trusted danger-full-access; unsupported sandboxed sidecar jobs fail closed. Do not weaken sandbox settings just to bypass this refusal.
  3. For sandboxed execution, stop the worker and set CODEX_WORKER_MODE=inline, CODEX_STEERING=false and CODEX_INTERACTIVE_QUESTIONS=false. The example env files select this configuration. Existing unspecified runtime defaults are retained.
  4. Configure backup administrator IDs explicitly. Chat-specific exports keep their existing behavior.
  5. Descriptor-based attachment validation currently requires Linux /proc/self/fd; unsupported platforms fail closed.

See security hardening and compatibility details.

Validation

The public distribution passed 987 tests with one pre-existing skipped test and no failures. Dependency audit reported zero vulnerabilities. The release PR is checked on Node 18, 20, 22, 24 and 26, with integration coverage and a dedicated security audit.

Full changelog: v1.4.3...v1.4.4

1.4.3 — Unified task dashboard and verified input receipts

Choose a tag to compare

@woosungchoi woosungchoi released this 06 Oct 13:49
0efcbb9

Unified task dashboard

  • Start each task with one pinned dashboard containing receipt, file and result
    buttons. Keep detail previews in the same card, with bounded output and a Back
    button; fall back to an ordinary card if pinning is unavailable.
  • Remove the whole card and its buttons only after confirmed final-answer
    delivery. Preserve uncertain or failed delivery, retry failed deletion across
    restarts, and prevent stale callbacks from recreating completed cards.
  • Show native plan, aggregate diff and token snapshots. Execution completion,
    input receipt and Telegram delivery remain separate states.

Input confirmation and safe inspection

  • Reflect durable worker input acknowledgements automatically. Distinguish
    unchecked and pending input from genuinely uncertain delivery; temporary
    lookup failures cannot erase a confirmed receipt.
  • Add owner-bound /progress and /recovery inspection in the current
    chat/topic, plus changed-file, bounded diff and verified result views.
  • Persist native client IDs before app-server submission and acknowledgements
    afterwards. Recover only already completed matching inputs from read-only
    history; uncertain input is never automatically resubmitted.
  • Preserve distinct completed, failed and interrupted outcomes, with English,
    Korean, Russian and Traditional Chinese UI text. See
    Task dashboard and input receipts.

Dependencies and upgrade

  • Update the Codex CLI and SDK packages to 0.160.1.
  • Restart both the bot and worker after upgrading, once active tasks and pending
    final deliveries finish, so the new receipt/inspection protocol is available.
  • Transports without native receipt support can remain unchecked until a
    completed result is available. Telegram API acceptance is not a human read receipt.

Full changes: v1.4.2...v1.4.3

1.4.2

Choose a tag to compare

@woosungchoi woosungchoi released this 06 Oct 07:23
6512060

Worker terminal delivery and recovery

  • Publish terminal status, completion time, final event and cursor together in
    the job snapshot before exposing completion to delivery consumers. This fixes
    the terminal-delivery receipt race addressed by
    PR #106.
  • Replay a terminal event from the committed snapshot when its log append was
    interrupted, including a final JSON record without a newline. Preserve event
    ordering, pagination and archive replay without duplicating the final event.
  • Keep raw Codex turn completion from prematurely finishing a worker job. Late
    heartbeat/control callbacks cannot reopen a completed job or move its cursor.
  • Preserve failure evidence during failed admission and orphan recovery. Retain
    the existing one-worker-per-state-directory and no-power-loss-durability limits.

Telegram steering and decisions

  • Default new or unset queue modes to steer; enable CODEX_STEERING by default.
    Existing saved modes and explicit CODEX_STEERING=false remain respected.
  • Add /steer, /queue_mode_steer and a queue-mode button. Safe mode retains an
    explicit Apply to current task action. Restore live replies/activity updates
    with app-server steering, without duplicate streamed text or final delivery.
  • Preserve durable steering receipts, requester/chat/topic validation, duplicate
    protection and explicit holds for uncertain delivery across restarts.
  • Add optional sequential Telegram decision buttons, typed answers and cancellation.
    The per-job MCP tool waits for required answers; independent chats remain concurrent.
    Frontend reconnects retain waiting questions. Interrupted worker decisions require
    explicit recovery and are never silently replayed. See
    Telegram questions.

Operational status

  • Add opt-in /ops snapshots with configurable service metrics, localized labels
    and timestamps, freshness warnings and bounded read-only JSON input. No shell
    execution or provider credentials are required by this command. See
    Operational status.

Upgrade and validation

  • Drain active jobs and final-message delivery before restarting the worker, then
    restart both worker and bot to load steering and terminal-state fixes. A package
    version bump alone does not update an already-running process.
  • Add regression coverage for terminal publication, interrupted writes, archives,
    late callbacks, steering and decision recovery, and operational status inputs.
    Verify each distribution against its own pinned dependencies and CI gates.

Full changelog: v1.4.1...v1.4.2

1.4.1 — Worker integrity and safer dependency updates

Choose a tag to compare

@woosungchoi woosungchoi released this 04 Oct 13:54
6a685f1

1.4.1 — Worker integrity and safer dependency updates

Worker transport and concurrent admission

  • Preserve Korean, emoji and other multibyte UTF-8 text when RPC data arrives
    across byte boundaries; reject incomplete frames on disconnect.
  • Serialize admission through durable reservation and controller registration.
    Matching job-ID retries return the existing status without executing twice;
    different chats continue to execute concurrently.
  • Keep live chat reservations even if the disk index changes. Roll back failed
    admissions; if rollback fails, pause new admission until healthy recovery.

Event log and storage recovery

  • Derive event sequences from the committed, newline-terminated JSONL prefix,
    reconciling stale state and cursors without reusing sequence numbers.
  • Preserve incomplete trailing writes in private quarantine before trimming.
    Reject duplicate/decreasing sequences and logs behind persisted cursors.
  • Surface EVENT_COMMITTED with the committed sequence when appending succeeds
    but saving job state fails. Callers must not blindly repeat that event body.
  • Distinguish missing files, corrupt JSON/container structures, and permission
    or I/O errors. Rebuild missing/corrupt active indexes only after validating
    job records, preserving originals and propagating quarantine failures.
  • Recover interrupted reservations at startup without re-executing orphaned work.

Dependency pull-request merge security

  • Verify updater author IDs/types and repository identity; reject spoofed branch
    names and external forks. Preserve supported owner-PAT and Actions identities.
  • Inspect files at immutable commits as data; execute only trusted workflow code.
    Permit dependency-version changes or Dependabot action-reference changes,
    while routing script, permission and unrelated changes to manual review.
  • Require successful CI for the exact head commit, recheck head/base SHAs before
    merging, and use --match-head-commit without an administrator bypass.

Upgrade and verification notes

  • Add regression coverage for UTF-8 splits, concurrent starts and retries,
    interrupted append/state saves, partial records, I/O failures, quarantine
    failures and malicious or changed dependency PRs.
  • Stop accepting new work and drain running jobs plus final delivery before
    restarting the worker. Historical invalid logs require explicit recovery;
    preserve originals rather than discarding or replaying ambiguous records.
  • Recovery assumes one worker per state directory. File writes are not fsynced,
    so this release does not promise OS/power-loss durability. Arbitrary event
    bodies have no deduplication key. See Worker integrity.

Dependencies

  • Public Codex SDK/CLI: 0.159.3 → 0.160.0.

Changes: v1.4.0…v1.4.1 · PR #99

1.4.0 — Cleanup storage reclamation and security

Choose a tag to compare

@woosungchoi woosungchoi released this 02 Oct 01:23
cdf7c20

Session cleanup and disk reclamation

  • Make the three Cleanup options follow distinct file operations. Quarantine
    only
    moves eligible session logs into the quarantine directory and retains
    their contents. Permanently delete only unlinks files that have already
    completed their quarantine period. Both quarantines new candidates and
    deletes only previously expired quarantine files.
  • Remove backup copies from permanent deletion. Newly deleted session contents
    are no longer duplicated in delete-backup directories, so deleting expired
    files can reclaim their storage. Keep only small plans, results and operation
    receipts, with irreversible deletion explicitly recorded in the manifest.
  • Preserve the existing retention policy: sessions become quarantine candidates
    after their configured retention period, and newly quarantined files must
    complete their own quarantine period before deletion. The default 14-day
    session retention and 7-day quarantine period are unchanged.

Execution safety and restore behavior

  • Recheck protected thread IDs and the current quarantine timestamp immediately
    before deletion. Skip files that are still protected, were quarantined too
    recently, have an invalid timestamp, or fall exactly on the retention cutoff.
    Execution uses current metadata instead of trusting a previously approved plan.
  • Refuse deletion outside the configured quarantine directory or through linked
    paths; require a regular file with a matching real path. Require regular
    quarantine metadata files, and reject unsupported action names before creating
    operation artifacts.
  • Keep missing-file handling idempotent: files already removed after planning
    are skipped instead of producing an ENOENT failure.
  • Return a restore-script path only when an operation actually quarantined files.
    New permanent deletions cannot be restored. Generated restore scripts skip
    irreversible deletion records while retaining support for quarantine moves
    and historical deletion records that already have backups. Existing historical
    backups are not automatically purged by this release.
  • Show the no-backup/no-restore notice in English, Korean, Traditional Chinese
    and Russian when permanent deletion occurs. Document all three options and
    their retention and restoration rules in both English and Korean READMEs.

Security and dependencies

  • Pin transitive basic-ftp to patched version 6.2.1 through an npm override,
    resolving GHSA-c475-qrg2-pj4r
    in the proxy-agent → pac-proxy-agent → get-uri dependency chain. Preserve the
    security audit gate and the existing proxy stack; this fix does not downgrade
    proxy-agent or suppress vulnerability reports. See
    PR #95.
  • Refresh the public Codex SDK and CLI packages from 0.159.0 in 1.3.9 to
    0.159.3. Preserve the existing application settings and persisted state.

Verification and upgrade notes

  • Add regression coverage for all three options, absence of payload backups,
    recently quarantined and protected files, changed timestamps, exact retention
    boundaries, linked paths, invalid actions, and mixed legacy/new restore records.
  • Verify the full suite (860 passed, one skipped), syntax, lint, formatting,
    types, architecture and UI localization. Verify zero reported npm
    vulnerabilities and FTP compatibility through the existing get-uri stack.
  • No state migration or new Cleanup setting is required. Review the permanent
    deletion choice with the understanding that new deletions are irreversible.

Full changelog: v1.3.9...v1.4.0

1.3.9 — Codex updates and clearer Telegram panels

Choose a tag to compare

@woosungchoi woosungchoi released this 30 Sep 03:46

Highlights

  • Codex updates from Telegram: find the update button under Tools → Codex Maintenance, below reports and backups. Administrator checks, expiring previews and installation locks guard activation. Updates are staged using the official installer, wait for active work and final replies, preserve queued requests and account/model settings, verify services, and support rollback.
  • One update panel: progress and the final success or failure result edit the original message, including after service restarts. Completion no longer adds a separate message or leaves “starting” behind.
  • Quiet menu closing: Close deletes the menu message without adding a confirmation message.
  • Reliable cleanup: candidates removed after planning are skipped instead of producing missing-file errors.
  • Worker startup readiness: bounded handshake retries handle transient socket startup errors before bot activation; genuine failures remain visible.
  • Security and dependencies: patched brace-expansion and ip-address, plus refreshed public Codex SDK/CLI and npm packages. Security checks remain enabled.

Verification

  • Full local verification: 852 tests passed, 1 skipped; syntax, lint, formatting, types, architecture and localization checks passed.
  • Security audit: 0 vulnerabilities.
  • GitHub Actions CI: all seven jobs passed on the release commit, including Node.js 18/20/22/24/26, integration coverage and the security audit.
  • GitHub Actions Release: passed; the annotated tag matches package version 1.3.9.
  • Package contents checked, including executable bot/worker entry points and the update runtime.

What's Changed

Full Changelog: v1.3.8...v1.3.9

1.3.8 — Clearer progress and reliable delivery

Choose a tag to compare

@github-actions github-actions released this 27 Sep 15:30

Highlights

  • Live progress no longer reports ignored Codex configuration notices as task errors; real errors remain visible.
  • Completed chats continue after an uncertain Telegram final-reply timeout without rerunning the Codex turn.
  • Guarded removal of the bot default account and clearer authenticated-account usage display.
  • Refreshed Codex dependencies and stabilized CI checks.

What's Changed

Full Changelog: v1.3.7...v1.3.8

1.3.7 — Complete UI localization and Russian support

Choose a tag to compare

@woosungchoi woosungchoi released this 16 Sep 13:33
888753c

1.3.7 - 2026-09-16

  • Add Russian and complete all 1,255 translation keys in English, Korean,
    Traditional Chinese and Russian, including settings, account and usage menus,
    skills, diagnostics, progress, time zones and default response instructions.
  • Move fixed Telegram UI text into shared locale catalogs. Resolve the current
    language when rendering and preserve command syntax, callback data, model IDs,
    external messages and user content.
  • Localize application validation errors at the UI boundary while retaining
    English diagnostic messages and optional locale metadata through worker
    requests, persisted events and recovery replay.
  • Add a UI localization source check to verification, document the translation
    policy, and cover all supported languages, live language changes, escaping,
    callback behavior and worker error replay with regression tests.
  • Update public tooling to TypeScript 7 and retain the TypeScript 6 compiler API
    for source checks. Make compiler selection explicit, preserve the existing
    strictness policy, and update Node.js types and markdown-it in
    PR #73.

Thank you to 9Lucky9 for the Russian locale contribution in
PR #76.

Update both the bot and worker after active jobs finish. Back up the complete state directory before restarting.

Full changelog: v1.3.6...v1.3.7

1.3.6 — Menu updates in place

Choose a tag to compare

@woosungchoi woosungchoi released this 14 Sep 10:15
375eb91

What's fixed

  • Account status checks, account selection, rotation, and registration/rename/removal prompts update the current Telegram message.
  • Reset credit browsing, pagination, confirmation, and results stay in the same panel. Prompt bindings remain correct when an edit changes nothing or Telegram requires a replacement message.
  • Queue cancellation/reordering controls and cleanup previews update the existing menu instead of appending messages.
  • Expired or unauthorized buttons show a callback notice without overwriting the current panel. Repeated confirmations cannot replace completed results or redeem another Reset credit.
  • Workspace errors preserve valid retry buttons, including private-chat topic setup guidance.

Upgrade

Update the bot and restart its service to load the callback fixes. This release has no state migration or runtime dependency changes; preserve the existing configuration and state directory.

The coverage artifact uploader also moves to actions/upload-artifact@v7.

Full changelog: v1.3.5...v1.3.6

Validation

  • Clean-install npm run verify: 783 passing tests, 0 failures, 1 existing Node 26 multipart compatibility skip.
  • Dependency audit: 0 vulnerabilities.
  • Package version, contents and executable entry points verified; checksum recorded.
  • GitHub release PR CI passed on Node 18, 20, 22, 24 and 26, including integration coverage and security audit.