律动BlockBeats|Jul 29, 2026 07:33
[OpenAI Open-Sources Codex Security Tool, Vulnerability Scanning Still Requires Account Permissions]
According to monitoring by Beating, OpenAI has open-sourced the command-line tool and TypeScript SDK for Codex Security. Developers can install it on their computers to scan code repositories, check new code commits, log identified issues, and integrate security checks into their company's automated development workflows. Codex Security reads the entire project to identify potential attack vectors. Once an issue is detected, it attempts to reproduce it in an isolated environment to confirm the existence of the vulnerability before providing a fix, which is then submitted for developer review.
The open-sourced release includes the tool code for running and managing scanning tasks. Anyone can view, modify, and republish it. However, the actual Codex Security service responsible for analyzing code, verifying vulnerabilities, and generating fixes is still operated by OpenAI. Therefore, downloading the source code does not equate to full functionality. Users must still log in with an OpenAI account and obtain Codex Security permissions.
Currently, it is in the research preview phase and is available to ChatGPT Pro, Business, Edu, and Enterprise users. Enterprise accounts may also require administrators to enable permissions. [Original Link]
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink