New @openai/codex-security package scans repos and CI pipelines for vulnerabilities via CLI or TypeScript SDK, requires Node.js 22+ and Python 3.10+.
Summary
Integrates security scanning directly into developer workflows and CI without switching tools. Supports both ChatGPT and API-key auth, with straightforward state management for reproducible scans across environments.
Why it matters
Integrates security scanning directly into developer workflows and CI without switching tools. Supports both ChatGPT and API-key auth, with straightforward state management for reproducible scans across environments.
Implementation verdict
Replaces ad-hoc security audits or separate SAST tools. Requires Node 22+, Python 3.10+, and Codex Security access. Ready to try now if you have OpenAI API access—install via npm, authenticate, run `scan .` in seconds. CI setup is standard env-var driven.
Sources
Dev Signal
Get briefs like this in your inbox — free, every weekday.
100+ sources compressed into one 4-minute read. Ranked, cited, implementation-ready.