Skip to content

release: bump Codex Security to 0.1.22 - #694

Merged
kmbroai merged 1 commit into
mainfrom
dev/kyleb/release-0.1.22
Aug 27, 2026
Merged

release: bump Codex Security to 0.1.22#694
kmbroai merged 1 commit into
mainfrom
dev/kyleb/release-0.1.22

Conversation

@kmbroai

@kmbroai kmbroai commented Aug 27, 2026

Copy link
Copy Markdown
Collaborator

Summary

Prepare Codex Security 0.1.22 with a version-matched changes report covering the changes since 0.1.21, including the consolidated findings service work in #660.

Merge after #660. Its planned functionality is included in the release notes, but its implementation is not copied into this PR. The release must include #660 before this version bump reaches main.

Changes

  • Bump sdk/typescript/package.json from 0.1.21 to 0.1.22. The lockfile does not record the root package version and needs no change.
  • Update .github/release-notes.md with findings storage and embeddings, custom publication, duplicate review and groups, resumable workflows, the read-only dashboard, and container distribution from feat(typescript): persist findings and embeddings through the API #660.
  • Summarize the merged artifact-restoration, cloud-cancellation, executable-resolution, finding-preview, and canonical plugin-source changes.
  • Include authentication, API usage, backup and migration, separate container publication, and source-build considerations, with versioned public documentation links. The release workflow supplies the categorized PR inventory.

This PR changes only release metadata and documentation. The CLI commands and flags described in the notes belong to #660; this PR adds no public CLI surface.

Testing

  • Release automation and release-cut workflow tests: 281 passed, zero failures, Bun 1.3.14, seed 122.
  • Generated model check, SDK TypeScript check (tsc --noEmit), and SDK build passed on Node 22.13.1.
  • Prettier checks for both changed files and git diff --check passed.
  • Verified the manifest changes only the version, the release-note marker matches, and 0.1.22 exceeds 0.1.21 and every published stable npm version. The registry still reported 0.1.21 as the newest version at preparation time.
  • Verified all nine versioned documentation paths and anchors against the source included in feat(typescript): persist findings and embeddings through the API #660. The 0.1.22 tag links become available when the release tag is created.

The full SDK suite, MCP typecheck, installed-package smoke, container tests, and native Windows/macOS checks were not run for this two-file change. Hosted CI is pending. This validation does not claim to retest #660's implementation.

Risk and rollout

Do not merge before #660. After it lands, confirm the release notes still match its final scope and required CI/review passes for the release commit. Merging this bump starts the existing npm release process after successful main CI; no tag, npm package, or container image has been published by this PR preparation.

The findings service remains an unauthenticated preview. The notes call out its local access boundary, embedding and review credentials/costs, automatic database migrations and backup requirements. Container releases remain separate from npm publication and depend on the documented registry setup.

Public disclosure review

Reviewed the branch name, title, description, proposed commit, complete two-file diff, validation output, and all documentation links. This PR adds no comments, screenshots, attachments, or uploaded logs; examples use generic selectors and URLs.

  • No customer, partner, prospect, or user identities, data, or identifying details are included.
  • No credentials, personal data, private source, scan findings, or nonpublic links or tickets are included.
  • I reviewed the branch name, title, description, commits, changes, comments, logs, screenshots, attachments, and links for public disclosure.

@github-actions github-actions Bot added the skip-release-notes Omit internal changes from generated release notes label Aug 27, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 27, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review Completed 2026-08-27T23:06:33.195204Z 40a1dd1 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@kmbroai
kmbroai merged commit cd4cc7e into main Aug 27, 2026
63 of 66 checks passed
@kmbroai
kmbroai deleted the dev/kyleb/release-0.1.22 branch August 27, 2026 23:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

skip-release-notes Omit internal changes from generated release notes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants