# codex-security **Repository Path**: gcfgcf/codex-security ## Basic Information - **Project Name**: codex-security - **Description**: No description available - **Primary Language**: Unknown - **License**: Apache-2.0 - **Default Branch**: main - **Homepage**: None - **GVP Project**: No ## Statistics - **Stars**: 0 - **Forks**: 0 - **Created**: 2026-08-02 - **Last Updated**: 2026-08-11 ## Categories & Tags **Categories**: Uncategorized **Tags**: None ## README # Codex Security `@openai/codex-security` is a CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities in your code. **See the [Codex Security documentation](https://learn.chatgpt.com/docs/security/cli)** for more details. Some cybersecurity requests and protected findings require approval through Trusted Access for Cyber. To apply or check your access, visit [chatgpt.com/cyber](https://chatgpt.com/cyber). ## Quick start Requires Node.js 22.13.0 or later in the 22.x release line, Node.js 24.x, or Node.js 26.x; Python 3.10 or later; and access to Codex Security. ```bash npm install @openai/codex-security npx @openai/codex-security login npx @openai/codex-security scan . npx @openai/codex-security scan . --model gpt-5.6-terra --effort high npx @openai/codex-security scan . --mode deep --workers 2 --subagents 0 --stop-after-no-new 3 --max-discovery-runs 10 ``` For CI, set `OPENAI_API_KEY` or `CODEX_API_KEY` instead of signing in. Environment API keys are passed directly to the current scan and are never stored in Codex's credential home or system keyring. To use another inference provider, set its API key and select a model: ```bash export OPENROUTER_API_KEY="" npx @openai/codex-security scan . --provider openrouter --model anthropic/claude-sonnet-4.5 export FIREWORKS_API_KEY="" npx @openai/codex-security scan . --provider fireworks --model accounts/fireworks/models/qwen3-235b-a22b export AWS_BEARER_TOKEN_BEDROCK="" export AWS_REGION="us-east-2" npx @openai/codex-security scan . --provider amazon-bedrock --model openai.gpt-5.6-luna ``` Amazon Bedrock also supports standard AWS access keys, profiles, web identity, container credentials, and the default AWS credential chain. Local sign-in honors Codex's configured credential backend, including a system keyring required by a managed device. Codex Security keeps login and scan credentials in the same private, persistent state directory. If both a ChatGPT sign-in and an API key are available, interactive scans ask which credential to use. CI and other noninteractive scans keep the existing API-key precedence. Select a credential explicitly when needed: ```bash npx @openai/codex-security scan . --auth chatgpt npx @openai/codex-security scan . --auth api-key ``` To make your ChatGPT sign-in the automatic default, unset any configured API keys: ```bash unset OPENAI_API_KEY CODEX_API_KEY ``` Scan history is stored in the Codex Security workbench state directory. If that directory cannot be written, set `CODEX_SECURITY_STATE_DIR` to a writable directory outside the repository. `scans compare BEFORE_SCAN_ID AFTER_SCAN_ID` automatically matches findings by root cause, reuses saved matches, and identifies new, persisting, reopened, resolved, or unknown findings. Missing findings remain unknown when coverage is incomplete or their original location was not reviewed. ## Verbose diagnostics Add `--verbose` to print redacted scan diagnostics to stderr: ```bash npx @openai/codex-security scan . --verbose ``` `CODEX_SECURITY_LOG_LEVEL=debug` also enables diagnostics; `LOG_LEVEL=debug` is its fallback. JSON results remain on stdout, and credentials and provider identifiers remain redacted. ## TypeScript SDK ```ts import { CodexSecurity } from "@openai/codex-security"; const security = new CodexSecurity(); const result = await security.run("."); await security.run(".", { mode: "deep", workers: 2, subagents: 0, stopAfterNoNew: 3, maxDiscoveryRuns: 10, }); console.log(result.reportPath); await security.close(); ``` ## Containerized bulk scans Use the official image and included Docker Compose configuration for noninteractive, resumable scans of repositories pinned to immutable Git revisions. See the [container quick start](sdk/typescript/README.md#containerized-bulk-scans) for authentication, private result storage, and optional Ubuntu AppArmor hardening. Pass `--knowledge-base PATH` to share a security document or directory with every repository. For complete command help, runtime defaults, native multi-agent worker limits, environment variables, deep-scan configuration, and SDK options, see the [package README](sdk/typescript/README.md) and the [official CLI reference](https://learn.chatgpt.com/docs/security/cli/reference).