Skip to content

ci(security): harden daily Codex scan - #2

Merged
jason-allen-oneal merged 1 commit into
mainfrom
ci/harden-codex-security
Jul 29, 2026
Merged

ci(security): harden daily Codex scan#2
jason-allen-oneal merged 1 commit into
mainfrom
ci/harden-codex-security

Conversation

@jason-allen-oneal

Copy link
Copy Markdown
Member

Replaces the broken duplicated Codex Security workflow with the hardened reusable scanner pinned to immutable odinn-maintainer commit d78c18b.

  • Targets this repository and its configured default branch.
  • Uses read-only repository permissions.
  • Pins Codex Security, proves the Linux sandbox, and uses the approved bounded model configuration centrally.
  • Encrypts all retained scan outputs and never publishes raw findings or SARIF.
  • Staggers the daily schedule to avoid cross-repository OAuth/model races.

Validation: caller YAML parses and git diff --check passes. The reusable implementation passed 39/39 tests before merge.

@jason-allen-oneal
jason-allen-oneal merged commit dc5d046 into main Jul 29, 2026
2 checks passed
@jason-allen-oneal
jason-allen-oneal deleted the ci/harden-codex-security branch July 29, 2026 21:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants