- Sources: openai/codex-security, HN 49089755
- Summary: OpenAI published the openai/codex-security repository, carrying a Codex Security command-line tool and a TypeScript SDK. The repository is licensed Apache-2.0. Running the tool requires Codex Security access and either a ChatGPT sign-in or an
OPENAI_API_KEY, so the open licence covers the client rather than the analysis. - Why it matters: It drops a vendor-run scanner into the CI slot teams already fill with Snyk or CodeQL, with the scanning itself behind an OpenAI account.
- Follow-up: Watch for the access terms and pricing attached to Codex Security itself.
send feedback on this story