dangelosaurus 3 hours ago
Thanks for checking this out and for flagging the auth issues. We just open-sourced it, and there's still plenty for us to improve. Expect the product to evolve quickly.
If you try it, I'd really appreciate hearing what works well and what you think we should improve. Happy to answer questions here.
CLI docs: https://learn.chatgpt.com/docs/security/cli
EDIT: If you'd like to help make this better, we're hiring: https://openai.com/careers/full-stack-software-engineer-cybe...
gregwebs 2 hours ago
npx codex-security scan .
[00:00] Preparing scan
[00:00] Authentication: stored Codex credentials.
[00:03] Preparing scan
[01:20] Running scan
[01:20] Preflight: worker delegation supported (up to 8 worker slots).
[52:47] Running scan
codex-security: Could not save the Codex Security scan: Repository HEAD changed while the scan was running. Start a new scan.
codex-security: Partial output was kept at ...varenc an hour ago
Some of approaches there could be useful in other contexts. OAI has the compute to experiment with different prompts and I'd expect these to be somewhat optimized.
luciana1u 2 hours ago
bakigul 3 hours ago
moehm 3 hours ago
minraws 3 hours ago
Can they explain what types of projects it works on and how does it check I own it? Like will it just not work on Linux kernel even on my own patches to it?
jaimex2 36 minutes ago
iancarroll 2 hours ago
petilon 2 hours ago
game_the0ry 3 hours ago
halfax 2 hours ago
shooker435 3 hours ago
yashasgunderia 43 minutes ago
petesergeant 3 hours ago
Edit: there's a little bit more meat here: https://github.com/openai/codex-security/tree/main/sdk/types...
bearsyankees 3 hours ago
alealvarezarg 3 hours ago
dlahoda an hour ago
onatozmen an hour ago
sillysaurusx 3 hours ago
sams99 an hour ago
knighthacker 2 hours ago
I'm building AQ, a coding harness for teams and the pattern is identical. For a while, I thought the raw model is the answer and quickly changed my mind. Purpose built harnesses are way more powerful than it sounds.