Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
135 commits
Select commit Hold shift + click to select a range
c7b3a26
refactor(deep-scan): run Standard scans in ordered batches
mldangelo-oai Sep 15, 2026
6546a75
test(deep-scan): wait for reducer launch before restart
mldangelo-oai Sep 15, 2026
4888f4d
fix(deep-scan): report unfinished passes at time limit
mldangelo-oai Sep 15, 2026
f5b9d76
refactor(deep-scan): simplify pass inputs and retain checkpoint links
mldangelo-oai Sep 15, 2026
329545c
refactor: compose deep scans from ordinary scan runs
mldangelo-oai Sep 15, 2026
26f2be8
fix: preserve stopped scan observations before the first merge
mldangelo-oai Sep 15, 2026
22c15d6
fix: retain scan settings and unmerged observations through shared li…
mldangelo-oai Sep 15, 2026
b9dc804
fix: preserve native ownership and account lookup errors
mldangelo-oai Sep 15, 2026
b344790
fix: retain incomplete scan coverage at configured limits
mldangelo-oai Sep 15, 2026
a5aeddd
fix: preserve scan settings and stopping semantics
mldangelo-oai Sep 15, 2026
8a92a4e
fix: retain merge failure limits across interrupted scans
mldangelo-oai Sep 15, 2026
6f06212
fix: retain merger failures during legacy scan migration
mldangelo-oai Sep 15, 2026
a4b0031
Fix saved logs for scans with recorded worker sessions
mldangelo-oai Sep 15, 2026
0ee069a
Clarify saved Deep Scan resume requirements
mldangelo-oai Sep 15, 2026
7c95ef3
fix: finalize retained legacy discovery at its saved budget
mldangelo-oai Sep 15, 2026
87b2585
docs: describe composed Deep Scan findings and coverage
mldangelo-oai Sep 16, 2026
1f4ca52
fix(deep-scan): preserve native resume and archived child state
mldangelo-oai Sep 16, 2026
3b95e3d
fix(deep-scan): drain stopped scans and preserve legacy resume settings
mldangelo-oai Sep 16, 2026
bdd6e74
fix(deep-scan): retain progress and read large merge inputs from disk
mldangelo-oai Sep 16, 2026
225abe0
fix(deep-scan): preserve native runtime and terminal pass state
mldangelo-oai Sep 16, 2026
20779b4
Merge remote-tracking branch 'origin/main' into mdangelo/codex/simpli…
mldangelo-oai Sep 16, 2026
5862e8d
fix(deep-scan): preserve feedback, recovery and budget boundaries
mldangelo-oai Sep 16, 2026
0c3f4b1
Merge remote-tracking branch 'origin/main' into mdangelo/codex/simpli…
mldangelo-oai Sep 16, 2026
21743ff
fix(deep-scan): rejoin legacy runs and share worker attribution
mldangelo-oai Sep 16, 2026
745f5ed
fix(deep-scan): preserve permissions and resume boundaries
mldangelo-oai Sep 16, 2026
0a34122
fix(deep-scan): preserve worker checks and cost completeness
mldangelo-oai Sep 16, 2026
c957af8
fix(deep-scan): preserve completion limits and session accounting
mldangelo-oai Sep 16, 2026
041769d
fix(deep-scan): preserve runtime and scope compatibility
mldangelo-oai Sep 16, 2026
2e8ec2e
fix(deep-scan): preserve failure and cleanup behavior
mldangelo-oai Sep 16, 2026
b153d60
fix(deep-scan): preserve resume and finding visibility
mldangelo-oai Sep 16, 2026
53b4f2a
fix(deep-scan): complete cancellation and cross-platform checks
mldangelo-oai Sep 16, 2026
690cd7b
fix(deep-scan): retain publication results and recovered failures
mldangelo-oai Sep 16, 2026
f9cec65
fix(deep-scan): coordinate checkpoints and failed-pass accounting
mldangelo-oai Sep 16, 2026
f69cb00
fix(deep-scan): preserve native home and proof compatibility
mldangelo-oai Sep 16, 2026
1b4e093
fix(deep-scan): preserve scan outcomes and default home selection
mldangelo-oai Sep 17, 2026
6754e4d
fix(native-scan): retain startup failures during cleanup [skip ci]
mldangelo-oai Sep 17, 2026
1535d52
fix(deep-scan): give validation errors to merge retries
mldangelo-oai Sep 25, 2026
c6c2e19
fix(plugin): port empty-artifact finalization from #941
mldangelo-oai Sep 25, 2026
85c7c17
fix(plugin): port finalized report status from #703
mldangelo-oai Sep 25, 2026
3773155
fix(workbench): port saved-question deduplication from #951
mldangelo-oai Sep 25, 2026
c830d91
fix(cli): port structured scan errors from #709
mldangelo-oai Sep 25, 2026
aebf591
fix(cli): port full-output scan errors from #971
mldangelo-oai Sep 25, 2026
c8ee906
fix(plugin): port structured result guidance from #1029
mldangelo-oai Sep 25, 2026
a29020b
chore: merge main into deep scan composition branch
mldangelo-oai Sep 25, 2026
c572c92
chore: sync latest main inventory fix
mldangelo-oai Sep 25, 2026
d4bd67b
fix(ci): rebalance Windows tests and shard isolated coverage
mldangelo-oai Sep 25, 2026
f364ada
fix(deep-scan): preserve resume state and cleanup outcomes
mldangelo-oai Sep 25, 2026
87c279a
fix(ci): allow full Windows parallel run to finish cleanup
mldangelo-oai Sep 25, 2026
36f56e9
fix(deep-scan): retain migrated findings and render merged details
mldangelo-oai Sep 25, 2026
595ba9f
fix(ci): give the full Windows baseline enough execution time
mldangelo-oai Sep 25, 2026
675c1b0
fix(ci): align quality checks with the supported Bun runner
mldangelo-oai Sep 25, 2026
b215268
fix(ci): use stable Bun isolation and portable terminal assertions
mldangelo-oai Sep 25, 2026
d96f6e0
test: make dashboard file URLs portable on Windows
mldangelo-oai Sep 25, 2026
458fcf2
test: consume synthetic CLI input before fixture exit
mldangelo-oai Sep 25, 2026
a9f5fa6
perf(deep-scan): reduce merge and persistence overhead
mldangelo-oai Sep 26, 2026
4b96cb1
Merge main into deep-scan replacement
mldangelo-oai Sep 26, 2026
27e6dfd
Merge main into deep-scan replacement
mldangelo-oai Sep 26, 2026
5ec4bc7
perf(scan-merge): share copy slots and reuse sealed reports
mldangelo-oai Sep 27, 2026
6c613c9
fix(ci): disambiguate test cases and drain ACL output at EOF
mldangelo-oai Sep 27, 2026
c6f1984
fix(native): reuse trusted executable resolution before startup
mldangelo-oai Sep 27, 2026
aec2391
fix(native): continue trusted PATH discovery
mldangelo-oai Sep 27, 2026
4d40d08
fix(native): retain Windows discovery for trusted candidates
mldangelo-oai Sep 27, 2026
03149f6
test(ci): check native discovery on every host platform
mldangelo-oai Sep 27, 2026
bf93e59
fix(native): handle quoted Windows search paths
mldangelo-oai Sep 27, 2026
79cd375
test(ci): propagate native failures and keep fixtures on the cwd drive
mldangelo-oai Sep 27, 2026
75d8a57
fix(deep-scan): harden recovery and preserve merge quality
mldangelo-oai Sep 27, 2026
86944a4
fix(deep-scan): preserve cancellation, deferred work and measured costs
mldangelo-oai Sep 27, 2026
27858c2
fix(deep-scan): retain accounting and candidates through recovery
mldangelo-oai Sep 27, 2026
b404deb
fix(scan-draft): retain historical candidate associations
mldangelo-oai Sep 27, 2026
e3cbe97
merge(main): preserve runtime fixes in composed Deep scans
mldangelo-oai Sep 27, 2026
931091e
fix(runtime): retain the scan home for usage collection
mldangelo-oai Sep 27, 2026
13d4f53
fix(scan-draft): retain legacy candidate scope without rewriting IDs
mldangelo-oai Sep 28, 2026
2abd7f5
test: align fixtures with shared lifecycle contracts
mldangelo-oai Sep 28, 2026
a7f12ca
fix(deep-scan): freeze knowledge roots and normalize config paths
mldangelo-oai Sep 28, 2026
0e2cad8
fix(deep-scan): preserve recovery and publication invariants
codex Sep 27, 2026
433f4dc
Preserve saved total cost when a terminal Deep Scan resume is rejected
codex Sep 27, 2026
d7170ae
Recover terminal Deep Scan costs without resuming execution
codex Sep 27, 2026
bf6d45c
Include independent legacy workers in terminal scan costs
codex Sep 27, 2026
21e87a8
fix(deep-scan): retain unknown costs after optional persistence failures
codex Sep 28, 2026
38c6117
Check expanded package assets without compressed-byte false positives
codex Sep 28, 2026
03c6eab
fix(deep-scan): retain unknown unregistered merge costs
codex Sep 28, 2026
97d137e
test: give boolean cases distinct report names
codex Sep 28, 2026
bdfef1f
Avoid duplicating shared terminal accounting integration cases
codex Sep 28, 2026
3105da8
Keep completion metadata out of artifact path expectations
codex Sep 28, 2026
087cacc
Give trusted Git cases distinct JUnit identities
codex Sep 28, 2026
69bb712
Type semantic drafts and centralize composition checkpoint boundaries
codex Sep 27, 2026
174a6e6
Name Deep Scan lifecycle transitions and retain durable stop decisions
codex Sep 27, 2026
ef308d1
Mark Deep pass membership in private registration context
codex Sep 27, 2026
5751900
Persist Deep Scan child membership and share composition reads
codex Sep 27, 2026
679f57f
Verify Python roundtrips shared composition checkpoint fixtures
codex Sep 27, 2026
52fc58d
Distinguish lightweight composition summaries from persisted checkpoints
codex Sep 27, 2026
8f2a589
Register resumed Deep fixture children with their private role
codex Sep 27, 2026
52f638b
test: align history fixtures with explicit child membership
codex Sep 27, 2026
9cf2be8
fix: preserve script help for composition support
codex Sep 27, 2026
f51aeed
Keep terminal accounting fixtures consistent with semantic coverage
codex Sep 27, 2026
5bdda42
Register the terminal MCP fixture as a Deep Scan pass
codex Sep 28, 2026
8f46300
Preserve unrelated migrations in severity rollback fixture
codex Sep 28, 2026
64f93d9
Specify shared child projection behavior with cross-language fixtures
codex Sep 27, 2026
dd3aa9b
Share Python artifact projection across completed and stopped scans
codex Sep 27, 2026
37d042f
Use the shared artifact projector for SDK composition
codex Sep 27, 2026
851c409
fix: support conventional help for private projection helper
codex Sep 27, 2026
6057ce5
Preserve legacy and large scan projection compatibility
codex Sep 28, 2026
da393d6
Precompute projection scope paths before filtering findings
codex Sep 28, 2026
72098e3
Preserve upstream merge and empty scan behavior with shared projection
codex Sep 28, 2026
b5e47e9
Make projection scope tests independent
codex Sep 28, 2026
4906a41
Share execution preparation across SDK and native scans
codex Sep 27, 2026
0264a54
refactor(scan): centralize publication and isolate execution boundaries
codex Sep 27, 2026
f447c01
Prepare scan skills and saved recipes outside the runner
codex Sep 27, 2026
ec60e9e
Reconcile shared execution policy and authentication fixtures
codex Sep 27, 2026
918c000
Preserve helper provider authentication and public declaration bounda…
codex Sep 28, 2026
1c568d9
Retain the artifact restoration failure type after extraction
codex Sep 28, 2026
cec3cd4
Merge current main into consolidated Deep Scan stack
mldangelo-oai Sep 29, 2026
1eb48f7
refactor(deep-scan): share retained coverage and child failure handling
mldangelo-oai Sep 29, 2026
1c67214
fix(deep-scan): handle exited preflights and long report names
mldangelo-oai Sep 29, 2026
4abb9eb
test(deep-scan): clean up exited permission fixtures on Windows
mldangelo-oai Sep 29, 2026
83779e8
Merge main and allow expanded Windows test coverage to finish
mldangelo-oai Sep 29, 2026
3e23f53
fix(native-scan): preserve configured provider safety identifiers
mldangelo-oai Sep 29, 2026
1189c07
Merge remote-tracking branch 'origin/pr939-latest-main' into mdangelo…
mldangelo-oai Sep 29, 2026
38e6944
fix(deep-scan): serialize native starts before joining
mldangelo-oai Sep 29, 2026
97bd7ac
fix(deep-scan): recover interrupted child usage before merging
mldangelo-oai Sep 29, 2026
3603c4c
fix(deep-scan): preserve results and accounting at budget stops
mldangelo-oai Sep 29, 2026
5b6560b
refactor(deep-scan): simplify composition and scan indexing
mldangelo-oai Sep 29, 2026
2f6b324
fix(deep-scan): preserve native retry and usage results
mldangelo-oai Sep 29, 2026
d8cfeea
fix(deep-scan): retain accounting and merge retry semantics
mldangelo-oai Sep 29, 2026
6e6b9af
fix(deep-scan): preserve unknown child accounting on recovery
mldangelo-oai Sep 29, 2026
54eb9b6
fix(deep-scan): recover composed results after publication failures
mldangelo-oai Sep 29, 2026
2e6cc2a
fix(scan): preserve unknown usage and reuse result projection
mldangelo-oai Sep 29, 2026
03d9a7b
fix(scan): finalize validated drafts and preserve runtime lifecycle
mldangelo-oai Sep 29, 2026
03f32c9
test(scan): expect one projection for selected findings
mldangelo-oai Sep 29, 2026
c41c587
fix(scan): recognize known runtime refusal messages
mldangelo-oai Sep 29, 2026
a0f439f
fix(scan): isolate merge workers from workbench tools
mldangelo-oai Sep 29, 2026
d1a3392
fix(scan): isolate workers and recover completion order
mldangelo-oai Sep 29, 2026
907ac45
fix(scan): preserve legacy cost attribution
mldangelo-oai Sep 29, 2026
a066b6a
ci: use the Windows job deadline for test shards
mldangelo-oai Sep 29, 2026
e367e17
refactor!: simplify saved scans and remove retired recovery (#1092)
mldangelo-oai Sep 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 21 additions & 8 deletions .github/workflows/node-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -393,13 +393,17 @@ jobs:
with:
package_json_file: package.json
cache: true
cache_dependency_path: plugins/codex-security/mcp-app/pnpm-lock.yaml
cache_dependency_path: |
sdk/typescript/pnpm-lock.yaml
plugins/codex-security/mcp-app/pnpm-lock.yaml
- name: Set up Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "22.13.0"
- name: Install dependencies
run: pnpm --dir plugins/codex-security/mcp-app install --frozen-lockfile
run: |
pnpm --dir sdk/typescript install --frozen-lockfile
pnpm --dir plugins/codex-security/mcp-app install --frozen-lockfile
- name: Install ripgrep
run: |
sudo apt-get update
Expand Down Expand Up @@ -435,25 +439,35 @@ jobs:
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
steps:
- name: Checkout plugin source without the SDK
- name: Checkout plugin and shared SDK source
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
sparse-checkout: plugins/codex-security
sparse-checkout: |
plugins/codex-security
sdk/typescript
- name: Set up pnpm
uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0
with:
package_json_file: package.json
cache: true
cache_dependency_path: plugins/codex-security/mcp-app/pnpm-lock.yaml
cache_dependency_path: |
plugins/codex-security/mcp-app/pnpm-lock.yaml
sdk/typescript/pnpm-lock.yaml
- name: Set up Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "22.13.0"
- name: Install plugin dependencies
run: pnpm --dir plugins/codex-security/mcp-app install --frozen-lockfile
- name: Install plugin build dependencies
run: |
pnpm --dir sdk/typescript install --frozen-lockfile
pnpm --dir plugins/codex-security/mcp-app install --frozen-lockfile
- name: Build and test the standalone host runtime
run: node --test plugins/codex-security/mcp-app/scripts/test_host_build.mjs
- name: Test native executable discovery
run: node --test plugins/codex-security/mcp-app/tests/test_native_executable.mjs
- name: Test native scan preparation
run: node --test --test-name-pattern="native preparation requires" plugins/codex-security/mcp-app/tests/test_native_scan.mjs

plugin-source:
name: plugin source contracts
Expand Down Expand Up @@ -589,7 +603,6 @@ jobs:
shell: pwsh
run: ./sdk/typescript/scripts/prepare-windows-test-root.ps1
- name: Test shard ${{ matrix.shard }}
timeout-minutes: 10
env:
TEMP: ${{ steps.windows-temp.outputs.path }}
TMP: ${{ steps.windows-temp.outputs.path }}
Expand Down
31 changes: 28 additions & 3 deletions .github/workflows/test-quality.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,21 +32,45 @@ jobs:
if: ${{ !cancelled() && (inputs.native-artifacts-ready || needs.native.result == 'success') }}
name: ${{ matrix.os }} / ${{ matrix.mode }}
runs-on: ${{ matrix.os }}
timeout-minutes: ${{ matrix.os == 'windows-latest' && (matrix.mode == 'baseline' || matrix.mode == 'isolated') && 45 || 30 }}
timeout-minutes: ${{ matrix.os == 'windows-latest' && (matrix.mode == 'baseline' && 60 || matrix.mode == 'parallel' && 45) || 30 }}
env:
CODEX_SECURITY_PROPERTY_SEED: ${{ github.event_name == 'pull_request' && 1 || github.run_number }}
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, windows-latest]
mode: [baseline, isolated, parallel]
exclude:
- os: windows-latest
mode: isolated
include:
- mode: baseline
args: ""
- mode: isolated
args: --isolate
- mode: parallel
args: --parallel=2
- os: windows-latest
mode: isolated-1
args: --isolate --shard=1/7
- os: windows-latest
mode: isolated-2
args: --isolate --shard=2/7
- os: windows-latest
mode: isolated-3
args: --isolate --shard=3/7
- os: windows-latest
mode: isolated-4
args: --isolate --shard=4/7
- os: windows-latest
mode: isolated-5
args: --isolate --shard=5/7
- os: windows-latest
mode: isolated-6
args: --isolate --shard=6/7
- os: windows-latest
mode: isolated-7
args: --isolate --shard=7/7
- os: windows-latest
mode: shard-1
args: --shard=1/7
Expand Down Expand Up @@ -92,7 +116,7 @@ jobs:
plugins/codex-security/mcp-app/pnpm-lock.yaml
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
with:
bun-version: "1.3.13"
bun-version: "1.4.2"
- name: Install dependencies
run: |
pnpm --dir sdk/typescript install --frozen-lockfile
Expand All @@ -104,6 +128,7 @@ jobs:
run: ./sdk/typescript/scripts/prepare-windows-test-root.ps1
- name: Test runner mode
env:
CODEX_SECURITY_TEST_TIMEOUT_MS: ${{ runner.os == 'Windows' && '120000' || '30000' }}
TEMP: ${{ steps.windows-temp.outputs.path || runner.temp }}
TMP: ${{ steps.windows-temp.outputs.path || runner.temp }}
TMPDIR: ${{ steps.windows-temp.outputs.path || runner.temp }}
Expand Down Expand Up @@ -152,7 +177,7 @@ jobs:
comparison_status=0
for os in ubuntu-latest windows-latest; do
for mode in isolated parallel; do
node sdk/typescript/scripts/compare-test-reports.mjs "reports/runner-$os-baseline.xml" "reports/runner-$os-$mode.xml" >> "$GITHUB_STEP_SUMMARY" || comparison_status=1
node sdk/typescript/scripts/compare-test-reports.mjs "reports/runner-$os-baseline.xml" "reports/runner-$os-$mode*.xml" >> "$GITHUB_STEP_SUMMARY" || comparison_status=1
done
done
node sdk/typescript/scripts/compare-test-reports.mjs reports/runner-windows-latest-baseline.xml 'reports/runner-windows-latest-shard-*.xml' >> "$GITHUB_STEP_SUMMARY" || comparison_status=1
Expand Down
3 changes: 1 addition & 2 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,8 +16,7 @@ packages and releases. Do not edit or commit files in that directory. See the
commands.

Model-based evaluations live in [`evals/`](evals/README.md), outside the plugin
source. Deterministic triage checks and the MCP reducer IPC regression remain
part of normal CI.
source. Deterministic triage checks remain part of normal CI.

Search [existing issues](https://github.com/openai/codex-security/issues)
before opening a new one.
Expand Down
8 changes: 8 additions & 0 deletions docs/project-configuration.md
Original file line number Diff line number Diff line change
Expand Up @@ -348,3 +348,11 @@ and applies its severity policy to recovered findings.
Workflow identity records explicitly requested deep settings, not ambient values
or shipped defaults, so changing those defaults does not prevent resumption.
Changing the explicit request still requires a different workflow ID.

### Native executable selection

Native plugin sessions use `CODEX_CLI_PATH` when supplied, or a real `codex`
executable on `PATH` (`codex.exe` on Windows). The selected executable must be
outside the scan target. Windows npm shims, managed-package directories and
desktop cache directories are no longer searched; set `CODEX_CLI_PATH` to the
installed executable when it is not directly on `PATH`.
6 changes: 1 addition & 5 deletions evals/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,5 @@ being embedded in its source tree or shipped npm runtime.

- [Triage finding](triage-finding/README.md): Promptfoo input contracts, OSS
calibration, and SastBench. This suite owns its private package and lockfile.
- [Deep reducer](deep-reducer/README.md): optional model evaluation of real IPC
size-limit recovery, pagination, and finding retention. It reuses the MCP
test helpers and dependencies.

Model runs are opt-in. CI still runs the deterministic triage helper checks and
the real-IPC reducer regression through the normal MCP test suite.
Model runs are opt-in. CI still runs the deterministic triage helper checks.
1 change: 0 additions & 1 deletion evals/deep-reducer/.gitignore

This file was deleted.

27 changes: 0 additions & 27 deletions evals/deep-reducer/README.md

This file was deleted.

15 changes: 0 additions & 15 deletions evals/deep-reducer/run.mjs

This file was deleted.

98 changes: 0 additions & 98 deletions plugins/codex-security/mcp-app/artifact-writer-main.ts

This file was deleted.

20 changes: 3 additions & 17 deletions plugins/codex-security/mcp-app/main.ts
Original file line number Diff line number Diff line change
@@ -1,25 +1,16 @@
import { StdioServerTransport } from "@modelcontextprotocol/sdk/server/stdio.js";
import { createCodexSecurityArtifactWriterServer } from "./artifact-writer-main.js";
import { createCodexSecurityServer } from "./server.js";

async function main(): Promise<void> {
const artifactWriter = process.argv.includes("--artifact-writer");
const server = artifactWriter
? await createCodexSecurityArtifactWriterServer()
: createCodexSecurityServer();
const server = createCodexSecurityServer();
await server.connect(new StdioServerTransport());
let closing = false;
const close = async (exitCode?: number): Promise<void> => {
if (closing) return;
closing = true;
if (exitCode !== undefined) process.exitCode = exitCode;
await server.close().catch((error: unknown) => {
console.error(
artifactWriter
? "Codex Security artifact writer failed to close:"
: "Codex Security MCP server failed to close:",
error,
);
console.error("Codex Security MCP server failed to close:", error);
});
};
process.stdin.once("end", () => void close());
Expand All @@ -28,11 +19,6 @@ async function main(): Promise<void> {
}

main().catch((error) => {
console.error(
process.argv.includes("--artifact-writer")
? "Codex Security artifact writer failed to start:"
: "Codex Security MCP server failed to start:",
error,
);
console.error("Codex Security MCP server failed to start:", error);
process.exitCode = 1;
});
3 changes: 1 addition & 2 deletions plugins/codex-security/mcp-app/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,14 +11,13 @@
},
"dependencies": {
"@modelcontextprotocol/sdk": "^1.30.0",
"@openai/codex-sdk": "0.158.0",
"smol-toml": "1.8.0",
"zod": "^4.6.5"
},
"devDependencies": {
"@types/node": "^26.6.2",
"esbuild": "^0.28.2",
"prettier": "3.9.8",
"smol-toml": "1.8.0",
"typescript": "^7.0.2"
}
}
Loading
Loading