公告
数据公告

QQ群和tg群已经启用,欢迎加入。公开信息来源均审核后发布;请结合来源、库存和更新时间判断。

社群与联系Telegram 群点击加入Telegram 频道点击订阅联系我们tgAIPricedb交流群979789483
返回资讯列表
product

OpenAI 开源 Codex Security CLI,支持代码库漏洞检测与 CI/CD 集成

OpenAI 发布了开源的 Codex Security CLI,帮助安全和开发团队扫描代码库、持续跟踪漏洞、验证修复,并将安全检查接入 CI/CD 流程。

92% VERIFIED

Codex Security CLI 是一款面向命令行环境的代码安全工具,可对用户拥有或获授权评估的代码库执行扫描,比较多次运行结果,并检查漏洞修复是否生效。相关资料还提到,它支持跨多个代码库开展扫描,并提供配套的 TypeScript SDK。

该工具目前处于早期测试阶段,社区公告称 CLI 和 SDK 需要获得访问权限。报道显示,安装通常通过 npm 完成,并要求 Node.js 22 及以上版本和 Python 3.10 或更高版本。OpenAI 表示将根据开发者反馈继续改进产品。

来源证据

OpenAI Open-Sources Codex Security CLI Under Apache-2.0 | AI Weeklyaiweekly.co · supporting

> Codex Security positions AI-assisted code review as a repeatable application security workflow rather than a one-time prompt. 4. Gigazine Read → Documents the Hacker News pre-discovery, developer-reported rate-limiting issues, and the distinction between this CLI and the existing Codex IDE plugin. > We quietly released the open-source Codex Security CLI, but Hacker News found it before we could share it. ## Shared on Bluesky by 1 AI expert Sung Kim @sungkim.bsky.social: OpenAI's Codex Security A CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities in your code. Scan repositori… → Originally reported by github.com Read the original article → [...] ## TL;DR The tool originated as an internal OpenAI project called Aardvark before entering a March 2026 research preview. Codex Security fixed more than 3,000 critical vulnerabilities during its closed preview period before the open-source release. Hacker News surfaced the repository before

Introducing the Open-Source Codex Security CLIcommunity.openai.com · supporting

# Introducing the Open-Source Codex Security CLI Codex Security helps security and engineering teams find, confirm, and fix vulnerabilities. Use its command-line interface (CLI) to scan repositories you own or have permission to assess, review findings over time, and check changes before they land. This is an early release, and we’re listening to your feedback as we continue improving it. The Codex Security CLI and SDK are in beta and require access. Follow the installation instructions provided with your access. For an interactive scan in Codex, start with the Codex Security plugin quickstart. For connected GitHub repositories, see Codex Security cloud setup. Install the open-source Codex Security CLI,: `npm install @OpenAI/codex-security` `npm install @OpenAI/codex-security` [...] `npm install @OpenAI/codex-security` Or start with: `npx @OpenAI/codex-security@latest --help` `npx @OpenAI/codex-security@latest --help` NPM: npmjs.com/package/@openai/codex-security This look

OpenAI open-sources Codex Security CLI to help developers find and fix ...the-decoder.com · supporting

Jul 29, 2026 OpenAI has released Codex Security CLI. The open-source command-line tool, licensed under Apache 2.0, helps security and development teams automatically find, confirm, and fix vulnerabilities in code repositories. Codex Security CLI can scan repositories, compare results across multiple runs, verify fixes, and plug security checks into CI/CD pipelines. Bulk scans across multiple repositories are also supported. The tool requires Node.js 22 and Python 3.10 or higher, is currently in beta, and installs via npm. The documentation covers all commands and output formats. [...] Subscribe now Source: OpenAI wpDiscuz [...] Skip to content Sign In Register Subscribe Now ### The Decoder Opens discord in a new tab Opens LinkedIn in a new tab Short News Copy the url to clipboard Share this article Go to comment section # OpenAI open-sources Codex Security CLI to help developers find and fix vulnerabilities from the command line Matthias Bastian Matthias Bastian Vi

OpenAI Open-Sourced Codex Security: What HN Thinksdevelopersdigest.tech · supporting

OpenAI open-sourced the Codex Security CLI and TypeScript SDK this week, publishing the repository at github.com/openai/codex-security. The release hit the Hacker News front page with 392 points and 122 comments. Here is what the repo actually contains, what the HN discussion revealed, and why the harness matters more than the scanner. ## What the Release Actually Is# The `@openai/codex-security` package gives you a CLI and SDK for finding, validating, and fixing security vulnerabilities in code. You install it with npm, authenticate with your OpenAI account or API key, and run `npx codex-security scan .` against a repository. It requires Node.js 22 or later and Python 3.10 or later. [...] The core scanning logic is not new -- it was already available as a plugin inside the Codex app. What is new is the standalone tooling: org-wide scanning across many repos, historical result tracking, deduplication across runs, false-positive tracking, budget controls via `--max-cost`, and CI integ

Instagraminstagram.com · supporting

Log In Sign Up artificialintelligenceupdater's profile picture Never miss a post from artificialintelligenceupdater Sign up for Instagram to stay in the loop. Sign up Log in Photo by Artificial Intelligence (AI) Updater on July 29, 2026. May be an image of text that says 'Artificial Intelligence updater OPENAI JUST OPEN- SOURCED THE CODEX SECURITY CLI Swipe for Swipeformore more'. artificialintelligenceupdater's profile picture artificialintelligenceupdater • Follow artificialintelligenceupdater's profile picture artificialintelligenceupdater OpenAI released the open-source Codex Security CLI. You can now use it to scan repositories, track findings across runs, verify fixes, and add security checks to CI/CD. It's an early release. ## No comments yet.

OpenAI Releases Code Security CLI for CI/CD Pipelines | Illia Oleksiuk posted on the topic | LinkedInlinkedin.com · supporting

Agree & Join LinkedIn By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy. # OpenAI Releases Code Security CLI for CI/CD Pipelines View profile for Illia Oleksiuk OpenAI open-sourced the 𝐂𝐨𝐝𝐞𝐱 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐂𝐋𝐈 👀 They dropped it quietly, and the community found it on Hacker News before any official announcement. It lets you scan repositories, track findings across runs, verify fixes, and integrate security checks directly into CI/CD pipelines. Source code & docs in the comments 👇 It’s an early release, and OpenAI is actively collecting feedback. graphical user interface, text, application, email Illia Oleksiuk, graphic Niklas Zajewski, graphic It’s super interesting and reminds me on ;) Patrick Wilson, graphic love it