Codex Security 0.2.0 released
Threat models are now saved with Standard, Deep, and Diff scan results and generated security policies. Export a saved model without another model call using codex-security export --artifact…; Scans now check for exposed credentials in source code, including…
What changed
- Threat models are now saved with Standard, Deep, and Diff scan results and generated security policies. Export a saved model without another model call using codex-security export --artifact…
- Scans now check for exposed credentials in source code, including unused code and tests, and distinguish suspected exposures from placeholders. This check runs offline, without trying discovered…
- Use --model and --effort when generating patches, validating findings, verifying fixes, or matching and comparing saved scans. Deep Scan workers and patches generated during a scan also respect…
- Patch, validation, and fix-verification commands now respect custom model providers and their authentication settings. Amazon Bedrock users get clearer authentication errors and cost estimates for…
- Scans include previously overlooked C++ headers (.hh and .hxx), server-rendered templates (EJS, ERB, and PHTML), and Vyper source files when selecting code to review. (#1079, #1197,
- On Unix, scans check that the sandbox works before starting paid model calls. Completed results are kept if you cancel follow-up work. CSV exports can now be reimported without rejecting multiple…
- If your integration reads threat models, check SecurityPolicyDraft.threatModelPath for null before opening the file. Policy generation now writes threatmodel.md instead of THREATMODEL.md; use the…
- Findings service clients must send Content-Type: application/json to POST /v1/bulk/findings and POST /v1/dedupe-groups. Missing or other content types return HTTP 400 invalidrequest. A charset…
Generated from AgentGid's daily data on public sources. How we collect it.