OpenAI открыла исходный код Codex Security CLI для поиска уязвимостей
OpenAI выпустила открытый Codex Security CLI — инструмент командной строки для сканирования репозиториев, отслеживания находок, проверки исправлений и интеграции проверок безопасности в CI/CD.
Codex Security CLI предназначен для команд разработки и информационной безопасности, которым нужен повторяемый процесс поиска и устранения уязвимостей. Инструмент позволяет сканировать репозитории, которыми пользователь владеет или на проверку которых имеет разрешение, сравнивать результаты разных запусков и проверять эффективность исправлений. Также сообщается о поддержке массового сканирования нескольких репозиториев и TypeScript SDK.
Сейчас CLI и SDK находятся на ранней стадии бета-тестирования; в публикации сообщества OpenAI указано, что для работы требуется доступ. По данным отраслевых материалов, установка выполняется через npm, а среди требований указаны Node.js версии 22 или новее и Python 3.10 или новее. OpenAI продолжает собирать отзывы пользователей.
Источники
OpenAI Open-Sources Codex Security CLI Under Apache-2.0 | AI Weeklyaiweekly.co · supporting> Codex Security positions AI-assisted code review as a repeatable application security workflow rather than a one-time prompt. 4. Gigazine Read → Documents the Hacker News pre-discovery, developer-reported rate-limiting issues, and the distinction between this CLI and the existing Codex IDE plugin. > We quietly released the open-source Codex Security CLI, but Hacker News found it before we could share it. ## Shared on Bluesky by 1 AI expert Sung Kim @sungkim.bsky.social: OpenAI's Codex Security A CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities in your code. Scan repositori… → Originally reported by github.com Read the original article → [...] ## TL;DR The tool originated as an internal OpenAI project called Aardvark before entering a March 2026 research preview. Codex Security fixed more than 3,000 critical vulnerabilities during its closed preview period before the open-source release. Hacker News surfaced the repository before
Introducing the Open-Source Codex Security CLIcommunity.openai.com · supporting# Introducing the Open-Source Codex Security CLI Codex Security helps security and engineering teams find, confirm, and fix vulnerabilities. Use its command-line interface (CLI) to scan repositories you own or have permission to assess, review findings over time, and check changes before they land. This is an early release, and we’re listening to your feedback as we continue improving it. The Codex Security CLI and SDK are in beta and require access. Follow the installation instructions provided with your access. For an interactive scan in Codex, start with the Codex Security plugin quickstart. For connected GitHub repositories, see Codex Security cloud setup. Install the open-source Codex Security CLI,: `npm install @OpenAI/codex-security` `npm install @OpenAI/codex-security` [...] `npm install @OpenAI/codex-security` Or start with: `npx @OpenAI/codex-security@latest --help` `npx @OpenAI/codex-security@latest --help` NPM: npmjs.com/package/@openai/codex-security This look
OpenAI open-sources Codex Security CLI to help developers find and fix ...the-decoder.com · supportingJul 29, 2026 OpenAI has released Codex Security CLI. The open-source command-line tool, licensed under Apache 2.0, helps security and development teams automatically find, confirm, and fix vulnerabilities in code repositories. Codex Security CLI can scan repositories, compare results across multiple runs, verify fixes, and plug security checks into CI/CD pipelines. Bulk scans across multiple repositories are also supported. The tool requires Node.js 22 and Python 3.10 or higher, is currently in beta, and installs via npm. The documentation covers all commands and output formats. [...] Subscribe now Source: OpenAI wpDiscuz [...] Skip to content Sign In Register Subscribe Now ### The Decoder Opens discord in a new tab Opens LinkedIn in a new tab Short News Copy the url to clipboard Share this article Go to comment section # OpenAI open-sources Codex Security CLI to help developers find and fix vulnerabilities from the command line Matthias Bastian Matthias Bastian Vi
OpenAI Open-Sourced Codex Security: What HN Thinksdevelopersdigest.tech · supportingOpenAI open-sourced the Codex Security CLI and TypeScript SDK this week, publishing the repository at github.com/openai/codex-security. The release hit the Hacker News front page with 392 points and 122 comments. Here is what the repo actually contains, what the HN discussion revealed, and why the harness matters more than the scanner. ## What the Release Actually Is# The `@openai/codex-security` package gives you a CLI and SDK for finding, validating, and fixing security vulnerabilities in code. You install it with npm, authenticate with your OpenAI account or API key, and run `npx codex-security scan .` against a repository. It requires Node.js 22 or later and Python 3.10 or later. [...] The core scanning logic is not new -- it was already available as a plugin inside the Codex app. What is new is the standalone tooling: org-wide scanning across many repos, historical result tracking, deduplication across runs, false-positive tracking, budget controls via `--max-cost`, and CI integ
Instagraminstagram.com · supportingLog In Sign Up artificialintelligenceupdater's profile picture Never miss a post from artificialintelligenceupdater Sign up for Instagram to stay in the loop. Sign up Log in Photo by Artificial Intelligence (AI) Updater on July 29, 2026. May be an image of text that says 'Artificial Intelligence updater OPENAI JUST OPEN- SOURCED THE CODEX SECURITY CLI Swipe for Swipeformore more'. artificialintelligenceupdater's profile picture artificialintelligenceupdater • Follow artificialintelligenceupdater's profile picture artificialintelligenceupdater OpenAI released the open-source Codex Security CLI. You can now use it to scan repositories, track findings across runs, verify fixes, and add security checks to CI/CD. It's an early release. ## No comments yet.
OpenAI Releases Code Security CLI for CI/CD Pipelines | Illia Oleksiuk posted on the topic | LinkedInlinkedin.com · supportingAgree & Join LinkedIn By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy. # OpenAI Releases Code Security CLI for CI/CD Pipelines View profile for Illia Oleksiuk OpenAI open-sourced the 𝐂𝐨𝐝𝐞𝐱 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐂𝐋𝐈 👀 They dropped it quietly, and the community found it on Hacker News before any official announcement. It lets you scan repositories, track findings across runs, verify fixes, and integrate security checks directly into CI/CD pipelines. Source code & docs in the comments 👇 It’s an early release, and OpenAI is actively collecting feedback. graphical user interface, text, application, email Illia Oleksiuk, graphic Niklas Zajewski, graphic It’s super interesting and reminds me on ;) Patrick Wilson, graphic love it