Skip to content

feat(scan): record available validation tools - #347

Closed
ianw-oai wants to merge 3 commits into
mainfrom
dev/ianw/codex-security-validation-tools
Closed

feat(scan): record available validation tools#347
ianw-oai wants to merge 3 commits into
mainfrom
dev/ianw/codex-security-validation-tools

Conversation

@ianw-oai

Copy link
Copy Markdown
Collaborator

Save the Python interpreter and tools available when each scan starts.

Show recorded scan limitations and unfinished work in scan history. Read limitations from existing scan files. Do not claim that tools ran or had sandbox access.

Tests: scan history and recovery tests, TypeScript type checks, generated models, and formatting.

@github-actions github-actions Bot added the enhancement New feature or request label Aug 11, 2026

@mldangelo-oai mldangelo-oai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for making the interpreter, available tools, and limitations visible; this should make scan behavior easier to explain.

I noticed that the capture happens in register_cli_scan, while scan_validation_environment returns nothing when recipe_json is absent. A native/headless plugin scan I started therefore had no validationEnvironment, even though a CLI scan did.

Could we also capture this through the native scan-creation path, or clarify that this first pass intentionally covers CLI-created scans only? That distinction seems especially relevant if the customer is using the plugin directly.

Comment on lines +1335 to +1337
"python python3 pip uv poetry pytest node npm npx pnpm yarn bun "
"java javac mvn gradle go cargo rustc ruby bundle php composer "
"dotnet gcc clang make cmake gdb lldb valgrind docker"

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

where did this list come from?

@ianw-oai ianw-oai closed this Aug 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants