Skip to content

Sync the bundled Codex Security plugin - #260

Closed
ianw-oai wants to merge 3 commits into
mainfrom
dev/ianw/sync-codex-security-plugin
Closed

Sync the bundled Codex Security plugin#260
ianw-oai wants to merge 3 commits into
mainfrom
dev/ianw/sync-codex-security-plugin

Conversation

@ianw-oai

@ianw-oai ianw-oai commented Aug 4, 2026

Copy link
Copy Markdown
Collaborator

Update the bundled plugin and SDK plugin version to 0.1.15.

Add the missing scan schemas and workbench scripts. Keep standard and deep CLI scans on their existing scan IDs, leave finalization to the SDK, and restrict multi-path scans to the requested files. Preserve existing fixes for scan recovery, private directories, artifacts, scan ownership, and database migrations.

Validated with three real scans: standard and bounded deep scans found the expected high-severity path traversal, and a scoped scan reviewed only its two requested files. All 784 tests passed, with five expected skips. Package installation, saved history, and JSON, CSV, and SARIF exports also passed.

@mldangelo-oai

Copy link
Copy Markdown
Collaborator

See:

@kmbroai kmbroai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One release-blocking portability issue: the synchronized plugin introduces an unprovisioned ripgrep dependency into both Standard and Deep scans.

@ianw-oai ianw-oai closed this Aug 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants