| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| openai-codex-security-0.1.28.tgz | 2026-09-16 | 3.3 MB | |
| Codex Security 0.1.28 source code.tar.gz | 2026-09-16 | 2.3 MB | |
| Codex Security 0.1.28 source code.zip | 2026-09-16 | 2.7 MB | |
| README.md | 2026-09-16 | 10.2 kB | |
| Totals: 4 Items | 8.4 MB | 4 | |
Highlights
- use versioned conventional commit titles (#879)
- share scan settings across the CLI and SDK (#742)
- keep parameterized JUnit names unique (#877)
- accept large saved post-scan prompts (#876)
- make cost display optional (#881)
- collect Desktop and worker session logs (#872)
- skip unavailable Daybreak access advisories (#878)
- align Codex 0.154.0 and dependency cooldowns (#755)
- bump docker/setup-buildx-action from 4.2.0 to 4.3.0 (#891)
- bump actions/attest-build-provenance from 4.1.1 to 4.2.2 (#886)
- update setuptools requirement from >=64.0 to >=84.0.0 in /plugins/codex-security (#889)
- bump SocketDev/action from 1.3.0 to 1.3.2 (#884)
- bump ruff from 0.16.1 to 0.16.6 in /plugins/codex-security (#887)
- bump typescript from 6.0.3 to 7.0.2 in /plugins/codex-security/mcp-app (#894)
- bump pytest from 9.0.3 to 9.1.1 in /plugins/codex-security (#885)
- bump typescript from 5.7.3 to 7.0.2 in /sdk/typescript (#898)
- simplify fast-uri dependency and update Ajv resolver (#895)
- bump @linear/sdk from 89.0.0 to 93.0.1 in /sdk/typescript (#896)
- bump actions/checkout from 6.0.2 to 7.0.1 (#890)
- bump actions/setup-node from 6.3.0 to 7.0.0 (#888)
- bump @types/node from 22.19.17 to 26.4.1 in /sdk/typescript (#897)
- bump @types/node from 25.9.1 to 26.4.1 in /plugins/codex-security/mcp-app (#893)
- bump the third-party group across 3 directories with 19 updates (#892)
- report patch failures and changed files (#874)
- persist scan artifacts through MCP (#862)
- advance scan progress when saving drafts (#882)
- simplify scan runtime bookkeeping (#903)
- upgrade json-schema-to-typescript to 16.0.0 (#914)
- upgrade eval OpenCode SDK to 1.18.29 (#911)
- upgrade Ink and use complete Escape input in TUI tests (#913)
- upgrade pnpm setup and align the package-manager pin (#910)
- upgrade actions/setup-python to 7.0.0 (#909)
- upgrade Stryker with compatible mutation tooling (#912)
- limit fix-finding to security vulnerabilities (#923)
- accept text knowledge-base files with any extension (#924)
- declare native release workflow permissions (#925)
- report context-aware estimate ranges (#926)
- update vulnerable image and archive dependencies (#927)
- update Inquirer prompts and Node/Bun types (#929)
Upgrade notes
Review compatibility and document any required migration steps before releasing.
What's Changed
Features
- feat: share scan settings across the CLI and SDK by @mldangelo-oai in https://github.com/openai/codex-security/pull/742
- feat(cli): make cost display optional by @ianw-oai in https://github.com/openai/codex-security/pull/881
- feat(plugin): persist scan artifacts through MCP by @soyeon-oai in https://github.com/openai/codex-security/pull/862
- feat(cli): accept text knowledge-base files with any extension by @kmbroai in https://github.com/openai/codex-security/pull/924
Fixes
- fix(release): use versioned conventional commit titles by @mldangelo-oai in https://github.com/openai/codex-security/pull/879
- fix(test): keep parameterized JUnit names unique by @mldangelo-oai in https://github.com/openai/codex-security/pull/877
- fix(scan): accept large saved post-scan prompts by @mldangelo-oai in https://github.com/openai/codex-security/pull/876
- fix(feedback): collect Desktop and worker session logs by @daneschneider-oai in https://github.com/openai/codex-security/pull/872
- fix(plugin): skip unavailable Daybreak access advisories by @soyeon-oai in https://github.com/openai/codex-security/pull/878
- fix(cli): report patch failures and changed files by @ianw-oai in https://github.com/openai/codex-security/pull/874
- fix: advance scan progress when saving drafts by @ianw-oai in https://github.com/openai/codex-security/pull/882
- fix(skills): limit fix-finding to security vulnerabilities by @tiffanycitra in https://github.com/openai/codex-security/pull/923
- fix(cost): report context-aware estimate ranges by @zcrab-oai in https://github.com/openai/codex-security/pull/926
- fix(evals): update vulnerable image and archive dependencies by @mldangelo-oai in https://github.com/openai/codex-security/pull/927
Other changes
- chore(deps): align Codex 0.154.0 and dependency cooldowns by @mldangelo-oai in https://github.com/openai/codex-security/pull/755
- ci: bump docker/setup-buildx-action from 4.2.0 to 4.3.0 by @dependabot[bot] in https://github.com/openai/codex-security/pull/891
- ci: bump actions/attest-build-provenance from 4.1.1 to 4.2.2 by @dependabot[bot] in https://github.com/openai/codex-security/pull/886
- chore(deps-dev): update setuptools requirement from >=64.0 to >=84.0.0 in /plugins/codex-security by @dependabot[bot] in https://github.com/openai/codex-security/pull/889
- ci: bump SocketDev/action from 1.3.0 to 1.3.2 by @dependabot[bot] in https://github.com/openai/codex-security/pull/884
- chore(deps-dev): bump ruff from 0.16.1 to 0.16.6 in /plugins/codex-security by @dependabot[bot] in https://github.com/openai/codex-security/pull/887
- chore(deps-dev): bump typescript from 6.0.3 to 7.0.2 in /plugins/codex-security/mcp-app by @dependabot[bot] in https://github.com/openai/codex-security/pull/894
- chore(deps-dev): bump pytest from 9.0.3 to 9.1.1 in /plugins/codex-security by @dependabot[bot] in https://github.com/openai/codex-security/pull/885
- chore(deps-dev): bump typescript from 5.7.3 to 7.0.2 in /sdk/typescript by @dependabot[bot] in https://github.com/openai/codex-security/pull/898
- chore(deps): simplify fast-uri dependency and update Ajv resolver by @dependabot[bot] in https://github.com/openai/codex-security/pull/895
- chore(deps): bump @linear/sdk from 89.0.0 to 93.0.1 in /sdk/typescript by @dependabot[bot] in https://github.com/openai/codex-security/pull/896
- ci: bump actions/checkout from 6.0.2 to 7.0.1 by @dependabot[bot] in https://github.com/openai/codex-security/pull/890
- ci: bump actions/setup-node from 6.3.0 to 7.0.0 by @dependabot[bot] in https://github.com/openai/codex-security/pull/888
- chore(deps-dev): bump @types/node from 22.19.17 to 26.4.1 in /sdk/typescript by @dependabot[bot] in https://github.com/openai/codex-security/pull/897
- chore(deps-dev): bump @types/node from 25.9.1 to 26.4.1 in /plugins/codex-security/mcp-app by @dependabot[bot] in https://github.com/openai/codex-security/pull/893
- chore(deps): bump the third-party group across 3 directories with 19 updates by @dependabot[bot] in https://github.com/openai/codex-security/pull/892
- refactor: simplify scan runtime bookkeeping by @mldangelo-oai in https://github.com/openai/codex-security/pull/903
- chore(deps-dev): upgrade json-schema-to-typescript to 16.0.0 by @dependabot[bot] in https://github.com/openai/codex-security/pull/914
- chore(deps): upgrade eval OpenCode SDK to 1.18.29 by @dependabot[bot] in https://github.com/openai/codex-security/pull/911
- chore(deps): upgrade Ink and use complete Escape input in TUI tests by @dependabot[bot] in https://github.com/openai/codex-security/pull/913
- ci: upgrade pnpm setup and align the package-manager pin by @dependabot[bot] in https://github.com/openai/codex-security/pull/910
- ci: upgrade actions/setup-python to 7.0.0 by @dependabot[bot] in https://github.com/openai/codex-security/pull/909
- chore(deps-dev): upgrade Stryker with compatible mutation tooling by @dependabot[bot] in https://github.com/openai/codex-security/pull/912
- ci: declare native release workflow permissions by @mldangelo-oai in https://github.com/openai/codex-security/pull/925
- chore(deps): update Inquirer prompts and Node/Bun types by @dependabot[bot] in https://github.com/openai/codex-security/pull/929
New Contributors
- @tiffanycitra made their first contribution in https://github.com/openai/codex-security/pull/923
Full Changelog: https://github.com/openai/codex-security/compare/npm-v0.1.27...npm-v0.1.28