OpenAI just open-sourced Codex Security
OpenAI has released 'Codex Security' as an open-source CLI and TypeScript SDK designed to help developers identify and validate security vulnerabilities in their code. The tool supports multiple operating systems and integrates with various CI/CD workflows.
Why it matters
Providing accessible security auditing tools for developers can help reduce software supply chain risks and improve overall code quality.
Codex Security is an open-source CLI and TypeScript SDK for finding, validating, and reviewing security issues in code you own or have permission to assess.
This package follows semantic versioning. Its public API may change between minor versions before 1.0.0 .
The SDK and CLI support macOS, Linux, and Windows and require Node.js 22 or later. Scanning and exporting findings also require Python 3.10 or later. If you use Python 3.10, install the tomli package. Python is not needed to install the package or run --help and --version .
npm install @openai/codex-security npx codex-security login npx codex-security scan /path/to/repo Run npx codex-security --help to see all commands and npx codex-security scan --help for scan options.
On a remote or headless machine, use npx codex-security login --device-auth . For CI and other unattended scans, set OPENAI_API_KEY or CODEX_API_KEY using your shell, CI secret, or secret manager.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in