← Founder Notes
Archive

Openai just shipped a cli that looks for security holes in code. the tool, confirmed september 15,…

Yethikrishna ROriginal on Threads

openai just shipped a cli that looks for security holes in code. the tool, confirmed september 15, scans for vulnerabilities before they reach production and plugs into ci/cd.

the code writer became the code checker.

Context

The github.com/openai/codex-security repository page shows an Apache License 2.0 repository described as a CLI and TypeScript SDK for finding, validating and fixing security vulnerabilities, with a creation date of July 13, 2026. The ChatGPT Learn CI docs, which are undated, describe scanning pull-request and merge-request changes in CI, keeping structured results, uploading SARIF, optionally failing the check at a chosen severity, with GitHub Actions and GitLab CI/CD examples, and say running scans still requires Codex Security access using an API key stored as a CI secret. An OpenAI Developer Community forum post dated July 29 introduces the open-source CLI, and says the CLI and SDK are in beta and require access.

How it compares

The repository and CI capability are supported, matching scans before production and plugging into CI/CD. No source dated September 15, 2026 was found, so confirmed september 15 is unverified. The forum post was written by a user labelled Leader and authorship by OpenAI was not established from its text, so it is an attributed external claim and not proof of a vendor launch, date or beta. A repository creation date is not a public release date. Scans need Codex Security access, so shipped is bounded by that requirement. The code writer became the code checker is the author's take.

Watch next

  • A dated first-party OpenAI announcement and the access terms.

Sources

  1. GitHub: openai/codex-securitygithub.com
  2. ChatGPT Learn: Codex Security CLI in CIlearn.chatgpt.com
  3. OpenAI Developer Community: Introducing the open-source Codex Security CLIcommunity.openai.com

Provenance

The note above is reproduced unedited from the original post, first published on Threads on 22 September 2026 at 18:52 IST. Sources are the papers and datasets the note draws on.

View the original post
Embed this note
<iframe src="https://founder.myndlabs.tech/notes/embed/openai-just-shipped-a-cli-that-looks-for-Ddl1SkYDVdd" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="Openai just shipped a cli that looks for security holes in code. the tool, confirmed september 15,…"></iframe>

More notes