Openai just shipped a cli that looks for security holes in code. the tool, confirmed september 15,…
openai just shipped a cli that looks for security holes in code. the tool, confirmed september 15, scans for vulnerabilities before they reach production and plugs into ci/cd.
the code writer became the code checker.
Context
The github.com/openai/codex-security repository page shows an Apache License 2.0 repository described as a CLI and TypeScript SDK for finding, validating and fixing security vulnerabilities, with a creation date of July 13, 2026. The ChatGPT Learn CI docs, which are undated, describe scanning pull-request and merge-request changes in CI, keeping structured results, uploading SARIF, optionally failing the check at a chosen severity, with GitHub Actions and GitLab CI/CD examples, and say running scans still requires Codex Security access using an API key stored as a CI secret. An OpenAI Developer Community forum post dated July 29 introduces the open-source CLI, and says the CLI and SDK are in beta and require access.
The repository and CI capability are supported, matching scans before production and plugging into CI/CD. No source dated September 15, 2026 was found, so confirmed september 15 is unverified. The forum post was written by a user labelled Leader and authorship by OpenAI was not established from its text, so it is an attributed external claim and not proof of a vendor launch, date or beta. A repository creation date is not a public release date. Scans need Codex Security access, so shipped is bounded by that requirement. The code writer became the code checker is the author's take.
Watch next
- A dated first-party OpenAI announcement and the access terms.
Sources
- GitHub: openai/codex-securitygithub.com
- ChatGPT Learn: Codex Security CLI in CIlearn.chatgpt.com
- OpenAI Developer Community: Introducing the open-source Codex Security CLIcommunity.openai.com
Provenance
The note above is reproduced unedited from the original post, first published on Threads on 22 September 2026 at 18:52 IST. Sources are the papers and datasets the note draws on.
View the original post ↗Embed this note
More notes
The air is now being asked to keep its own ledger
the air is now being asked to keep its own ledger: ecmwf’s aifs compo becomes the first ai model to forecast atmospheric composition globally every three hours, cleanair simulates 365 days of pm2.5 over china in ten seconds, and a unified framework maps six pollutants at one kilometer across the whole country. the air now files its own composition report.
read the note →The current is now being asked to draw its own map
the current is now being asked to draw its own map: china’s langya 2.0 predicts six ocean phenomena including internal waves and mesoscale eddies, a deep net called wenhai resolves eddies globally with air sea flux formulas built in, and scripps infers surface currents from the way temperature patterns deform in satellite images. the ocean now files its own circulation report.
read the note →The soil is now being asked to report its own carbon
the soil is now being asked to report its own carbon: a nix color sensor paired with generative data augmentation predicts soil organic carbon without a lab, random forest drives 74 percent of soil health mapping studies, and sentinel 2 tracks five year carbon change across france and italy from 922 samples. the dirt now files its own carbon account.
read the note →