{"_id":"@ai-plugins-cc/codex-adapter","_rev":"3-1e036eaa9aa8b7a0cd8df2b9801d2f20","name":"@ai-plugins-cc/codex-adapter","dist-tags":{"latest":"0.2.1"},"versions":{"0.1.0":{"name":"@ai-plugins-cc/codex-adapter","version":"0.1.0","license":"Apache-2.0","_id":"@ai-plugins-cc/codex-adapter@0.1.0","maintainers":[{"name":"builtwithlove","email":"norcal.kieran@gmail.com"}],"homepage":"https://github.com/dysfunc/ai-plugins-cc#readme","bugs":{"url":"https://github.com/dysfunc/ai-plugins-cc/issues"},"dist":{"shasum":"6c9f4724d201de5ecb987b37e3f0f659ea8c45cf","tarball":"https://registry.npmjs.org/@ai-plugins-cc/codex-adapter/-/codex-adapter-0.1.0.tgz","fileCount":13,"integrity":"sha512-rF/8qnWG4ZKXfM7c7+J2ktWualEZVKDLiXl7RGuyGfn4JIOa1RnDjBRTLfKNQza1IT3lkujEYKu85TgJ4wq3xg==","signatures":[{"sig":"MEYCIQCsvufZsTPWfCEvS9gkGXo5uPhAAbD43EZSPTGMB8gmzwIhALmUz/kjpoUqXlOHEv/UjRvpBoEpAaeNkFiHJR8G9QyF","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":48974},"main":"./src/index.mjs","type":"module","engines":{"node":">=20.0.0"},"exports":{".":"./src/index.mjs","./invoke":"./src/invoke.mjs","./install":"./src/install.mjs","./discover":"./src/discover.mjs","./normalize":"./src/normalize.mjs"},"gitHead":"468b26667f7a9e2d4b0185807d6bb903bf7b99fd","private":false,"scripts":{"test":"node --test tests/*.test.mjs"},"_npmUser":{"name":"builtwithlove","email":"norcal.kieran@gmail.com"},"repository":{"url":"git+https://github.com/dysfunc/ai-plugins-cc.git","type":"git","directory":"packages/codex-adapter"},"_npmVersion":"10.9.7","description":"Adapter that integrates with upstream openai/codex-plugin-cc: discovery, version pinning, subprocess invocation, output normalization.","directories":{},"_nodeVersion":"22.22.2","dependencies":{"@ai-plugins-cc/core":"*","@ai-plugins-cc/shared-prompts":"*"},"ai-plugins-cc":{"upstream":{"repo":"openai/codex-plugin-cc","pinnedSha":"2cbcbcb01e937f2a11e1e9b05b4e2a31529417d0eae00b80b7febb2381e4e88c","pinnedTag":"v1.0.4","_pinnedShaComment":"Pin a SHA-256 of the GitHub tarball here for hash-verified installs. Leave null to install without verification (acceptable for development; production should pin)."}},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/codex-adapter_0.1.0_1777645366461_0.5696261977982116","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@ai-plugins-cc/codex-adapter","version":"0.2.0","license":"Apache-2.0","_id":"@ai-plugins-cc/codex-adapter@0.2.0","maintainers":[{"name":"builtwithlove","email":"norcal.kieran@gmail.com"}],"homepage":"https://github.com/dysfunc/ai-plugins-cc#readme","bugs":{"url":"https://github.com/dysfunc/ai-plugins-cc/issues"},"dist":{"shasum":"ef29a2dd44cb52db10276e245a308c29ee613b10","tarball":"https://registry.npmjs.org/@ai-plugins-cc/codex-adapter/-/codex-adapter-0.2.0.tgz","fileCount":13,"integrity":"sha512-WXhXJ1siiGNqdRxD3fVQyEqZJvs9u1d0BeK2MvGY9PhPZWos9HUDGsonOK3vxsJSoUl6QMrK9Yv3e76AFmSmtA==","signatures":[{"sig":"MEQCIEauDPqhjW4D2LpMU930YH6qcKEU+WLpjlUWWoUDzQrdAiArSncTK08hhwb/C1qQ/W78hF+dVuUjHoCoG8FOjLWkzQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":52950},"main":"./src/index.mjs","type":"module","engines":{"node":">=20.0.0"},"exports":{".":"./src/index.mjs","./invoke":"./src/invoke.mjs","./install":"./src/install.mjs","./discover":"./src/discover.mjs","./normalize":"./src/normalize.mjs"},"gitHead":"175fa81430f60cfdf16be083249ace1208df7a70","private":false,"scripts":{"test":"node --test tests/*.test.mjs"},"_npmUser":{"name":"builtwithlove","email":"norcal.kieran@gmail.com"},"repository":{"url":"git+https://github.com/dysfunc/ai-plugins-cc.git","type":"git","directory":"packages/codex-adapter"},"_npmVersion":"10.9.7","description":"Adapter that integrates with upstream openai/codex-plugin-cc: discovery, version pinning, subprocess invocation, output normalization.","directories":{},"_nodeVersion":"22.22.2","dependencies":{"@ai-plugins-cc/core":"*","@ai-plugins-cc/shared-prompts":"*"},"ai-plugins-cc":{"upstream":{"repo":"openai/codex-plugin-cc","pinnedSha":"2cbcbcb01e937f2a11e1e9b05b4e2a31529417d0eae00b80b7febb2381e4e88c","pinnedTag":"v1.0.4","_pinnedShaComment":"Pin a SHA-256 of the GitHub tarball here for hash-verified installs. Leave null to install without verification (acceptable for development; production should pin)."}},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/codex-adapter_0.2.0_1777651128324_0.947138838137535","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@ai-plugins-cc/codex-adapter","version":"0.2.1","private":false,"type":"module","description":"Adapter that integrates with upstream openai/codex-plugin-cc: discovery, version pinning, subprocess invocation, output normalization.","license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/dysfunc/ai-plugins-cc.git","directory":"packages/codex-adapter"},"homepage":"https://github.com/dysfunc/ai-plugins-cc#readme","bugs":{"url":"https://github.com/dysfunc/ai-plugins-cc/issues"},"publishConfig":{"access":"public"},"engines":{"node":">=20.0.0"},"main":"./src/index.mjs","exports":{".":"./src/index.mjs","./discover":"./src/discover.mjs","./install":"./src/install.mjs","./invoke":"./src/invoke.mjs","./normalize":"./src/normalize.mjs"},"dependencies":{"@ai-plugins-cc/core":"*","@ai-plugins-cc/shared-prompts":"*"},"scripts":{"test":"node --test tests/*.test.mjs"},"ai-plugins-cc":{"upstream":{"repo":"openai/codex-plugin-cc","pinnedTag":"v1.0.4","_pinnedShaComment":"Pin a SHA-256 of the GitHub tarball here for hash-verified installs. Leave null to install without verification (acceptable for development; production should pin).","pinnedSha":"2cbcbcb01e937f2a11e1e9b05b4e2a31529417d0eae00b80b7febb2381e4e88c"}},"_id":"@ai-plugins-cc/codex-adapter@0.2.1","gitHead":"7463bcaabda5dd8983df26adefead80e90cb77e8","_nodeVersion":"22.22.2","_npmVersion":"10.9.7","dist":{"integrity":"sha512-+EiinC98ncfVYijhLN6Rg8uVjTpDfJa0WKJ9NJGqhSQxnG5ji4CDf8UYf7ex9C1mp13XaLTa6B9BlsEtvbwu/g==","shasum":"0d1f19fca4406ab85eae9fc3fe5a698666d34876","tarball":"https://registry.npmjs.org/@ai-plugins-cc/codex-adapter/-/codex-adapter-0.2.1.tgz","fileCount":13,"unpackedSize":55084,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIAllxhWuyitVTv0Z15I4hrfqz+dVmtq8i43Jwb1/HjilAiEAkXrdfSwNnY8mYNXMaQG5q4A9+Iv76fXZdWobwVVBxdQ="}]},"_npmUser":{"name":"builtwithlove","email":"norcal.kieran@gmail.com"},"directories":{},"maintainers":[{"name":"builtwithlove","email":"norcal.kieran@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/codex-adapter_0.2.1_1777901501077_0.4494083380599787"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-01T14:22:46.404Z","modified":"2026-05-04T13:31:41.421Z","0.1.0":"2026-05-01T14:22:46.612Z","0.2.0":"2026-05-01T15:58:48.465Z","0.2.1":"2026-05-04T13:31:41.251Z"},"bugs":{"url":"https://github.com/dysfunc/ai-plugins-cc/issues"},"license":"Apache-2.0","homepage":"https://github.com/dysfunc/ai-plugins-cc#readme","repository":{"type":"git","url":"git+https://github.com/dysfunc/ai-plugins-cc.git","directory":"packages/codex-adapter"},"description":"Adapter that integrates with upstream openai/codex-plugin-cc: discovery, version pinning, subprocess invocation, output normalization.","maintainers":[{"name":"builtwithlove","email":"norcal.kieran@gmail.com"}],"readme":"# @ai-plugins-cc/codex-adapter\n\nAdapter that integrates with upstream [`openai/codex-plugin-cc`](https://github.com/openai/codex-plugin-cc) without vendoring its source.\n\n## Why\n\nCodex isn't ours to maintain — it's an OpenAI plugin. But we want `/ai:review --provider=codex` to work alongside our in-house Gemini and Grok providers, with the same uniform shape. This package is the seam.\n\n## Surface\n\n```js\nimport {\n  discoverCodexInstall,\n  installCodexUpstream,\n  invokeCodexCommand,\n  normalizeReviewOutput,\n  readUpstreamConfig\n} from \"@ai-plugins-cc/codex-adapter\";\n```\n\n| Module | What it does |\n|---|---|\n| `discover.mjs` | Locate an installed copy of upstream codex. Source priority: explicit `options.path` / `CODEX_PLUGIN_PATH` env → managed cache (`~/.cache/ai-plugins-cc/codex-plugin-cc/`) → sibling repo (`<cwd>/../codex-plugin-cc`, useful in monorepo dev). Throws a self-explanatory error listing every path tried when nothing is found. |\n| `install.mjs` | Fetch a SHA-pinned GitHub release tarball, hash-verify, extract, atomic-rename into the managed cache. `fetchImpl` and `extractImpl` are injectable for tests; defaults use Node's built-in `fetch` and a shell `tar -xzf`. Refuses to install on SHA mismatch and leaves the prior install untouched. |\n| `invoke.mjs` | Spawn the upstream `codex-companion.mjs` as a subprocess with security boundaries: env allowlist (`PATH`, `HOME`, locale, `OPENAI_API_KEY`, `CODEX_API_KEY`, …), configurable timeout (default 10 min, kills via SIGKILL on overrun), configurable stdout cap (default 50 MB), resolves on stdio `'close'` so trailing bytes aren't truncated. |\n| `normalize.mjs` | Validate upstream review JSON against our canonical schema (`verdict`, `summary`, `findings[]`, optional `next_steps[]`). Surfaces drift as `unsupported upstream version (X.Y.Z)` rather than a generic shape error. Tolerant of leading prose. |\n\n## Pinning\n\nThe upstream tag and optional SHA-256 live in this package's `package.json`:\n\n```jsonc\n{\n  \"ai-plugins-cc\": {\n    \"upstream\": {\n      \"repo\": \"openai/codex-plugin-cc\",\n      \"pinnedTag\": \"v1.0.4\",\n      \"pinnedSha\": null   // SHA-256 of the GitHub source tarball, hex\n    }\n  }\n}\n```\n\n`pinnedSha: null` is acceptable for development; production should pin. The daily `codex-canary` workflow re-fetches the pinned tag and would surface a hash mismatch loudly.\n\n## Tests\n\n```sh\nnpm test --workspace=@ai-plugins-cc/codex-adapter\n```\n\n24 tests:\n\n- **discover (5)** — env override, options.path override, sibling-repo discovery, missing-companion rejection, helpful error on miss.\n- **install (5)** — happy path, replace-on-rerun, SHA happy path, SHA mismatch refuses install + leaves target untouched, missing-tag error.\n- **invoke (5)** — captures stdout, surfaces non-zero exits, enforces timeout, caps stdout, applies env allowlist.\n- **normalize (9)** — well-formed pass-through, leading-prose tolerance, defaulted next_steps, empty stdout, malformed JSON, unknown verdict (with version diagnostic), missing top-level key, missing finding field, unknown severity.\n","readmeFilename":"README.md"}