-
Notifications
You must be signed in to change notification settings - Fork 741
feat(plugin): strengthen patch-risk falsifiers #658
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Closed
mldangelo-oai
wants to merge
104
commits into
mdangelo/codex/add-patch-risk-review
from
mdangelo/codex/port-patch-risk-falsifiers
Closed
Changes from all commits
Commits
Show all changes
104 commits
Select commit
Hold shift + click to select a range
58792a5
feat(plugin): strengthen patch-risk falsifiers
mldangelo-oai 6cbccbe
test(plugin): align falsifiers with risk validation
mldangelo-oai 5acc134
fix(plugin): preserve patch applicability precedence
mldangelo-oai c35552d
Merge patch-risk review fixes
mldangelo-oai ab07843
fix(plugin): preserve authoritative risk contracts
mldangelo-oai 6ebaac3
Merge nested Git parser fix
mldangelo-oai bf7b984
test(plugin): avoid prose-coupled risk assertions
mldangelo-oai 2ac4451
Merge exact-head review fixes
mldangelo-oai 482cdca
Merge applicability evidence fixtures
mldangelo-oai 8fd7ebb
Merge complete patch-risk review fixes
mldangelo-oai f987952
Merge reviewed ignored restoration fixes
mldangelo-oai a6b6a81
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai e8c6440
docs(plugin): separate comparison provenance
mldangelo-oai 910cd19
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai 851d6f2
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai 6fa9a4f
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai 78524ba
docs(plugin): align contract-narrowing evidence
mldangelo-oai 58f05a4
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai be1c457
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai 5e02fc0
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai b675a73
docs(plugin): allow replacement contract controls
mldangelo-oai 8ca1d49
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai cbdbf5a
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai 40d30d2
docs(plugin): handle retired contracts
mldangelo-oai 8d88e45
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai 67848d3
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai 5f68eda
Merge remote-tracking branch 'origin/mdangelo/codex/add-patch-risk-re…
mldangelo-oai 0cac322
Merge remote-tracking branch 'origin/mdangelo/codex/add-patch-risk-re…
mldangelo-oai c51f33d
Merge remote-tracking branch 'origin/mdangelo/codex/add-patch-risk-re…
mldangelo-oai 1d6ac62
Merge remote-tracking branch 'origin/mdangelo/codex/add-patch-risk-re…
mldangelo-oai ffd2867
Merge remote-tracking branch 'origin/mdangelo/codex/add-patch-risk-re…
mldangelo-oai aa05e20
Merge remote-tracking branch 'origin/mdangelo/codex/add-patch-risk-re…
mldangelo-oai 19627ea
Merge remote-tracking branch 'origin/mdangelo/codex/add-patch-risk-re…
mldangelo-oai a0b7159
docs(plugin): bind mutable authority inputs
mldangelo-oai 05f6660
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai d6dedb7
Merge patch-risk review hardening
mldangelo-oai a9fb57b
Merge patch-risk review hardening
mldangelo-oai d6e0c30
Merge updated patch-risk review fixtures
mldangelo-oai 242d6a2
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai 0ed8084
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai 04b8722
fix(plugin): require fresh authorization decisions
mldangelo-oai 65553b7
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai beeddb6
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai 46fe5a3
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai 2931b8c
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai 0d1889a
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai 24658a3
fix(plugin): align patch risk evidence contract
mldangelo-oai 372d235
Merge remote-tracking branch 'origin/mdangelo/codex/add-patch-risk-re…
mldangelo-oai 893517d
Merge remote-tracking branch 'origin/mdangelo/codex/add-patch-risk-re…
mldangelo-oai 741d490
Merge remote-tracking branch 'origin/mdangelo/codex/add-patch-risk-re…
mldangelo-oai fdb3697
Merge remote-tracking branch 'origin/mdangelo/codex/add-patch-risk-re…
mldangelo-oai b665e06
Merge remote-tracking branch 'origin/mdangelo/codex/add-patch-risk-re…
mldangelo-oai efdd91a
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai 0b697ec
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai 8141f40
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai ed378a3
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai 5c4d2b0
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai b5e24f8
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai 2ed3da9
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai ff8155c
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai 864ac8d
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai 166e8af
docs(plugin): align retirement risk ratings
mldangelo-oai cc7c866
Merge branch 'mdangelo/codex/add-patch-risk-review' into mdangelo/cod…
mldangelo-oai 3f70304
Merge commit 'e11efeb4' into mdangelo/codex/port-patch-risk-falsifiers
mldangelo-oai 5a08de1
Merge commit '00a7a6a0' into mdangelo/codex/port-patch-risk-falsifiers
mldangelo-oai cddf27b
Merge commit '25ae2536' into mdangelo/codex/port-patch-risk-falsifiers
mldangelo-oai 932fa88
Merge commit '2629404c' into mdangelo/codex/port-patch-risk-falsifiers
mldangelo-oai 06046fb
fix(plugin): version retirement evidence contract
mldangelo-oai cf59a88
Merge commit 'e70a3c3b' into mdangelo/codex/port-patch-risk-falsifiers
mldangelo-oai c85ca7a
fix(plugin): validate deferred boundary evidence
mldangelo-oai f80a381
Merge commit 'eee3c781fd0ef7a91b6872b2728d72e9ab3e598d' into mdangelo…
mldangelo-oai bee8791
Merge commit '042862ce' into mdangelo/codex/port-patch-risk-falsifiers
mldangelo-oai 487df49
Merge commit '562ab5e4' into mdangelo/codex/port-patch-risk-falsifiers
mldangelo-oai 9096d6b
Merge commit '12e6a5f1' into mdangelo/codex/port-patch-risk-falsifiers
mldangelo-oai d6e7a1b
Merge remote-tracking branch 'origin/mdangelo/codex/add-patch-risk-re…
mldangelo-oai 1c14efd
Merge remote-tracking branch 'origin/mdangelo/codex/add-patch-risk-re…
mldangelo-oai 716f511
Merge remote-tracking branch 'origin/mdangelo/codex/add-patch-risk-re…
mldangelo-oai 96118e5
fix: keep unresolved boundary branches on hold
mldangelo-oai 36cef14
Merge remote-tracking branch 'origin/mdangelo/codex/add-patch-risk-re…
mldangelo-oai 4d51608
Merge remote-tracking branch 'origin/mdangelo/codex/add-patch-risk-re…
mldangelo-oai 39a8263
fix: bind boundary evidence to outcomes
mldangelo-oai 90ce8b3
Merge remote-tracking branch 'origin/mdangelo/codex/add-patch-risk-re…
mldangelo-oai 69b4dbc
Merge branch 'mdangelo/codex/add-patch-risk-review' of https://github…
mldangelo-oai bb516ab
Merge branch 'mdangelo/codex/add-patch-risk-review' of https://github…
mldangelo-oai 948aec4
Merge branch 'mdangelo/codex/add-patch-risk-review' of https://github…
mldangelo-oai 4da1fda
docs(plugin): preserve non-applicable outcomes
mldangelo-oai dba6076
Merge branch 'mdangelo/codex/add-patch-risk-review' of https://github…
mldangelo-oai dba80b2
Merge branch 'mdangelo/codex/add-patch-risk-review' of https://github…
mldangelo-oai 1432c2c
Merge branch 'mdangelo/codex/add-patch-risk-review' of https://github…
mldangelo-oai 443b80c
Merge branch 'mdangelo/codex/add-patch-risk-review' of https://github…
mldangelo-oai 0dcc3ba
Merge commit 'd37eee8ff9409ae5a4af434be0292c7d671858a2' into mdangelo…
mldangelo-oai ced87b2
Merge commit 'b133d51f62e9c831ff32337a7f792d280c9489d0' into mdangelo…
mldangelo-oai 2fffe70
Merge commit '98ceeb5b' into mdangelo/codex/port-patch-risk-falsifiers
mldangelo-oai 7ef8df5
Merge commit '953eb10a' into mdangelo/codex/port-patch-risk-falsifiers
mldangelo-oai d540f5a
Merge commit '82ffb32e' into mdangelo/codex/port-patch-risk-falsifiers
mldangelo-oai f47177c
Merge commit 'c2436105' into mdangelo/codex/port-patch-risk-falsifiers
mldangelo-oai 059f08c
feat(plugin): add patch-risk assessment (#654)
mldangelo-oai 01bd062
feat(cli): assess patch risk on request (#664)
soyeon-oai a1b0270
fix(cli): simplify and bind independent patch reviews
mldangelo-oai 6de9244
fix(cli): consolidate validated patch risk reviews
mldangelo-oai c4cae92
fix(plugin): align patch risk guidance and review integration
mldangelo-oai 67bc0b7
fix(package): preserve bundled MCP launcher permissions (#678)
soyeon-oai fd98a90
release: bump Codex Security to 0.1.21 (#672)
mldangelo-oai a5c0a90
chore: merge final release packaging updates
mldangelo-oai File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,9 +1,36 @@ | ||
| <!-- release-version: 0.1.20 --> | ||
| <!-- release-version: 0.1.21 --> | ||
|
|
||
| ## Highlights | ||
|
|
||
| - Bug fixes and reliability improvements for cloud publication, including | ||
| access checks, recovery handling, and skipping findings that were already | ||
| recorded. | ||
| - Request an advisory assessment of a completed patch with | ||
| `patch --assess-patch-risk`. Add `--create-pr` to include its concise summary | ||
| in the draft pull request. The assessment is opt-in and does not approve or | ||
| merge changes. See | ||
| [patching and risk assessment](https://github.com/openai/codex-security/blob/npm-v0.1.21/sdk/typescript/README.md#validate-and-patch-findings). | ||
| - Import GitHub code scanning alerts through the CLI or SDK for validation | ||
| against a local checkout. Imports are read-only and preserve the upstream | ||
| alert context. See | ||
| [GitHub alert imports](https://github.com/openai/codex-security/blob/npm-v0.1.21/sdk/typescript/README.md#import-github-code-scanning-alerts). | ||
| - Publish findings from CSV with `publish scan --to cloud --csv PATH`, or | ||
| preview the upload without signing in or sending data with `--dry-run`. | ||
| See | ||
| [Cloud publication](https://github.com/openai/codex-security/blob/npm-v0.1.21/sdk/typescript/README.md#publish-findings-to-cloud). | ||
| - Improve repeated-scan credential handling on Windows, sign-in recovery | ||
| messages, cleanup after interrupted publication, and refreshes of changed | ||
| bundled plugins. | ||
|
|
||
| ## Upgrade notes | ||
|
|
||
| - Finish operations using older versions before upgrading; credential-home | ||
| locks now follow the owning process's lifetime. See | ||
| [authentication](https://github.com/openai/codex-security/blob/npm-v0.1.21/sdk/typescript/README.md#authentication). | ||
| - The bundled Codex runtime and SDK are now `0.149.1`. Custom executables | ||
| selected with `CODEX_CLI_PATH` need thread-source attribution support for | ||
| both `exec` and `app-server` (Codex `0.149.1+`). See | ||
| [runtime configuration](https://github.com/openai/codex-security/blob/npm-v0.1.21/sdk/typescript/README.md#environment-variables). | ||
| - Existing Windows state with invalid ancestor permissions is not repaired | ||
| automatically. Keep the old reports and select a new private state | ||
| directory as described in | ||
| [scan history and recovery](https://github.com/openai/codex-security/blob/npm-v0.1.21/sdk/typescript/README.md#scan-history-and-reruns). | ||
|
|
||
| The categorized list below contains the individual changes. | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The release highlight calls
--assess-patch-riskan “advisory assessment,” but the implemented behavior andsdk/typescript/README.mdlines 882-887 say that every non-merge recommendation fails the selected review and prevents automatic publication. Users or automation relying on these release notes can therefore enable what appears to be reporting-only behavior and unexpectedly have otherwise completed patches rejected; describe the flag as an opt-in gating review here as well.AGENTS.md reference: AGENTS.md:L40-L41
Useful? React with 👍 / 👎.