{"_id":"@openai/codex-security","_rev":"28-3bb2190b38aea62a5896a4208b14866a","name":"@openai/codex-security","dist-tags":{"latest":"0.1.27"},"versions":{"0.1.0":{"name":"@openai/codex-security","version":"0.1.0","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.0","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"26faa1630b98abab0783b2a23d97529868f3d6af","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.0.tgz","fileCount":178,"integrity":"sha512-7pH2xQiyGsS/+cKkwFKZogAIJJgBsRk9dbEvtj15hFJk1jz6tSbgvvtZKlP8i0eh26pO3S51XCfH4ME5u10pfg==","signatures":[{"sig":"MEYCIQDQEncVYk+o8Vw40yCuJpF1AI1NRhxz/1VjBJIs1771lwIhAMY9l64NU+jW3/ha6XFU9AtsOgGBMh4KQojYKpgSxn0e","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2593327},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"scripts":{"lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","build":"pnpm run clean && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,json,md}\"","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"mdangelo-openai","email":"mdangelo@openai.com"},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.0.tgz","_integrity":"sha512-7pH2xQiyGsS/+cKkwFKZogAIJJgBsRk9dbEvtj15hFJk1jz6tSbgvvtZKlP8i0eh26pO3S51XCfH4ME5u10pfg==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.16.0","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ajv":"8.20.0","incur":"0.4.13","fflate":"0.8.2","fast-uri":"3.1.4","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"5.6.205","extract-zip":"2.0.1","@octokit/core":"7.0.6","@openai/codex":"0.144.6","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.144.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.2.5","@types/bun":"1.3.13","typescript":"5.7.3","@types/node":"22.19.17","@types/papaparse":"5.3.15","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.0_1785258588194_0.16017099624766207","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@openai/codex-security","version":"0.1.1","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.1","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"2ed585c8d2dfd7b0ebccf94753921913b8402061","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.1.tgz","fileCount":178,"integrity":"sha512-sNxULf7IyicJRgYnycguaEzO2ZeANEv3oyrupjMoKVq5TjRrmIhORpaa7U2LVIpEHJP7//icGZV37MRIlp9X/A==","signatures":[{"sig":"MEQCIFNejgQYBCFBJhluKx8XUjOL4YYW9pWZ0QVD66NZChvOAiAxIIsKGlsd2cEpdTqrWV8qKmU1UKe4PN/BHM1B6/TzwQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2613965},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.1.tgz","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"scripts":{"lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","build":"pnpm run clean && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,json,md}\"","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.1.tgz","_integrity":"sha512-sNxULf7IyicJRgYnycguaEzO2ZeANEv3oyrupjMoKVq5TjRrmIhORpaa7U2LVIpEHJP7//icGZV37MRIlp9X/A==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.16.0","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ajv":"8.20.0","incur":"0.4.13","fflate":"0.8.2","fast-uri":"3.1.4","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"5.6.205","extract-zip":"2.0.1","@octokit/core":"7.0.6","@openai/codex":"0.144.6","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.144.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.2.5","@types/bun":"1.3.13","typescript":"5.7.3","@types/node":"22.19.17","@types/papaparse":"5.3.15","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.1_1785282503386_0.6889273776243623","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@openai/codex-security","version":"0.1.2","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.2","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"c5a1135c00fff21b5b410f6cadb59ba045c9942c","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.2.tgz","fileCount":179,"integrity":"sha512-7f00xAmS030AJiPgdHOcKOjyqutbv2NSF7SANsbfMOwgbrUJZzPMJOfbZcplQOz+l8SPOT7pDPmeDxuaB1VSDg==","signatures":[{"sig":"MEYCIQCD1lj356GtIlK7zhC7pMhJp5pGexIgsQwiGYarkErNwAIhANUxA03Eis2wc6taR0KkZ9P5hjAnF0i3YvL2rdLBf7VS","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2660705},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.2.tgz","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"1e03c89ad22d2df5ae65b146be1483b3608572a9","scripts":{"lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","build":"pnpm run clean && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,json,md}\"","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.2.tgz","_integrity":"sha512-7f00xAmS030AJiPgdHOcKOjyqutbv2NSF7SANsbfMOwgbrUJZzPMJOfbZcplQOz+l8SPOT7pDPmeDxuaB1VSDg==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.16.0","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ajv":"8.20.0","incur":"0.4.13","fflate":"0.8.2","fast-uri":"3.1.4","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"5.6.205","extract-zip":"2.0.1","@octokit/core":"7.0.6","@openai/codex":"0.144.6","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.144.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.2.5","@types/bun":"1.3.13","typescript":"5.7.3","@types/node":"22.19.17","@types/papaparse":"5.3.15","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.2_1785351067413_0.5105617773969857","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@openai/codex-security","version":"0.1.3","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.3","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"dc414937ec65bbcd2824405c422fcd6f6597fc05","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.3.tgz","fileCount":179,"integrity":"sha512-alpTs1JovABa5XzzGSZD097EWDHOHiMdSK8LBlJs311CtjyQuClSA/J4BkItkMi2jLE6Z2I7e6obvrtMsR/OIw==","signatures":[{"sig":"MEUCIEWYkjxn5TllVlHwz3QZPyoEt2g5DR39kGdtBEIeFFpEAiEAsITrp/x0/92xtW6n3JVypV1MyA8GvJeYGcyv8Zi1vhM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2676304},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.3.tgz","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"f89633aeee1e73dc6406edf76657b49a8b51a43b","scripts":{"lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","build":"pnpm run clean && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,json,md}\"","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.3.tgz","_integrity":"sha512-alpTs1JovABa5XzzGSZD097EWDHOHiMdSK8LBlJs311CtjyQuClSA/J4BkItkMi2jLE6Z2I7e6obvrtMsR/OIw==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.16.0","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ajv":"8.20.0","incur":"0.4.13","fflate":"0.8.2","fast-uri":"3.1.4","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"5.6.205","extract-zip":"2.0.1","@octokit/core":"7.0.6","@openai/codex":"0.144.6","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.144.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.2.5","@types/bun":"1.3.13","typescript":"5.7.3","@types/node":"22.19.17","@types/papaparse":"5.3.15","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.3_1785358072559_0.910953059936501","host":"s3://npm-registry-packages-npm-production"}},"0.1.4":{"name":"@openai/codex-security","version":"0.1.4","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.4","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"7e1c2bf9df9551b44b6e017bbbc787bfea15c6bc","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.4.tgz","fileCount":179,"integrity":"sha512-BOElTCc8oxlIVemL7j9a0Ekmsrb3/zboGzzyVf7i4opr9+Ij5D6qdMHcP5kcdPSowg+/rZhAndSJ3t7+Or0oKw==","signatures":[{"sig":"MEUCIQD5ROkwn59QN/Mv0Ri+KNJrcWSH8Soer9YgsBIgxjrbmwIgBr3Skj0JufPmBr5CTnEiBK0bIOrLxHpyOPovUY6C1E4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2779359},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.4.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.13.0 || ^24.0.0 || ^26.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"ab3b91c8b1fc0403d7fd6ae35a3a46f7fb2a470f","scripts":{"lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","build":"node --run clean && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,json,md}\"","audit:prod":"pnpm audit --prod --audit-level high","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.4.tgz","_integrity":"sha512-BOElTCc8oxlIVemL7j9a0Ekmsrb3/zboGzzyVf7i4opr9+Ij5D6qdMHcP5kcdPSowg+/rZhAndSJ3t7+Or0oKw==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.16.0","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ajv":"8.20.0","incur":"0.4.13","fflate":"0.8.2","fast-uri":"3.1.4","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"5.6.205","extract-zip":"2.0.1","@octokit/core":"7.0.6","@openai/codex":"0.144.6","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.144.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.2.5","@types/bun":"1.3.13","typescript":"5.7.3","@types/node":"22.19.17","@types/papaparse":"5.3.15","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.4_1785371716948_0.8116340370852901","host":"s3://npm-registry-packages-npm-production"}},"0.1.5":{"name":"@openai/codex-security","version":"0.1.5","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.5","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"bcda177c371a7d1a454d3dd842c9e73a3bcf3e8e","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.5.tgz","fileCount":179,"integrity":"sha512-P6RZCrtZjQ23TG55VVYdrz5+/o5SGt4A3xDy18C/1ZqhfbRQYFzZIVP+HzfR2j0HaJv0l1KsKzuKtR8UOeK/UQ==","signatures":[{"sig":"MEQCIEFZaDhy0iKFvJCqEGIYq3DHJOdnhzC3TRi73hg5CQFDAiAK3g8WqfOQitfxd0dIceeovPntnXZchS5dfxEbjZtHew==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2876650},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.5.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.13.0 || ^24.0.0 || ^26.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"66778d0d85f478d7832854b81d0a6ddb93a3ce4c","scripts":{"lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","build":"node --run clean && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,json,md}\"","audit:prod":"pnpm audit --prod --audit-level high","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.5.tgz","_integrity":"sha512-P6RZCrtZjQ23TG55VVYdrz5+/o5SGt4A3xDy18C/1ZqhfbRQYFzZIVP+HzfR2j0HaJv0l1KsKzuKtR8UOeK/UQ==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.15.0","dependencies":{"ajv":"8.20.0","incur":"0.4.13","fflate":"0.8.2","fast-uri":"3.1.4","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"5.6.205","extract-zip":"2.0.1","@octokit/core":"7.0.6","@openai/codex":"0.144.6","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.144.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.2.5","@types/bun":"1.3.13","typescript":"5.7.3","@types/node":"22.19.17","@types/papaparse":"5.3.15","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.5_1785514086040_0.18931515967657475","host":"s3://npm-registry-packages-npm-production"}},"0.1.6":{"name":"@openai/codex-security","version":"0.1.6","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.6","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"50b112e41146f594054d1587e5c074f8b558660d","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.6.tgz","fileCount":198,"integrity":"sha512-zF5HiN+wifp+5trPyGeZB40nl8+B3J3MXBkHR0Fedt4tGawaCB66uEzIq+u6u/cYvrbZbcaJItxCQzpeTl7z0A==","signatures":[{"sig":"MEUCIHbX080ER7u4KrV39ht7jJ9bILbQrUxO12xCBedxtbALAiEAp4LEUiXPejntspE/qLTzIMbAM+2GaI0Yw00XbCOTyXc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.6","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":3321430},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.6.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.13.0 || ^24.0.0 || ^26.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"18a183fe16bdc8ef43d9203360e88be2c43a1c8e","scripts":{"lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","build":"node --run clean && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,json,md}\"","audit:prod":"pnpm audit --prod --audit-level high","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.6.tgz","_integrity":"sha512-zF5HiN+wifp+5trPyGeZB40nl8+B3J3MXBkHR0Fedt4tGawaCB66uEzIq+u6u/cYvrbZbcaJItxCQzpeTl7z0A==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.15.0","dependencies":{"ajv":"8.20.0","incur":"0.4.13","fflate":"0.8.2","fast-uri":"3.1.5","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"5.6.205","extract-zip":"2.0.1","@octokit/core":"7.0.6","@openai/codex":"0.144.6","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.144.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.2.5","@types/bun":"1.3.13","typescript":"5.7.3","@types/node":"22.19.17","@types/papaparse":"5.3.15","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.6_1785916803639_0.723266310469584","host":"s3://npm-registry-packages-npm-production"}},"0.1.7":{"name":"@openai/codex-security","version":"0.1.7","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.7","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"e14bcbfc8a82befd7826da7c4304e01314d12d25","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.7.tgz","fileCount":198,"integrity":"sha512-aDiaokXM5SpNn6AiSkFKEge/+7iPhZnE7L99xrAIvoV8bU0yw24Y6cVkHv5rS1VjcNAZj3sGmbi7srwnthDuSg==","signatures":[{"sig":"MEUCIGagWDI/cMxMExZwNOkr1IBtj6fZfcyw57wnuc4eAPkGAiEA4dp5pmqOwDIdjgDnQf21bh2IGbL8Gn+GU+sAHrqwX2c=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.7","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":3332411},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.7.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.13.0 || ^24.0.0 || ^26.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"24a62a7a2470bf711882da6a74374359b5e80851","scripts":{"lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","build":"node --run clean && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,json,md}\"","audit:prod":"pnpm audit --prod --audit-level high","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.7.tgz","_integrity":"sha512-aDiaokXM5SpNn6AiSkFKEge/+7iPhZnE7L99xrAIvoV8bU0yw24Y6cVkHv5rS1VjcNAZj3sGmbi7srwnthDuSg==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.15.0","dependencies":{"ajv":"8.20.0","incur":"0.4.13","fflate":"0.8.2","fast-uri":"3.1.5","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"5.6.205","extract-zip":"2.0.1","@octokit/core":"7.0.6","@openai/codex":"0.144.6","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.144.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.2.5","@types/bun":"1.3.13","typescript":"5.7.3","@types/node":"22.19.17","@types/papaparse":"5.3.15","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.7_1785993771003_0.21303154700332594","host":"s3://npm-registry-packages-npm-production"}},"0.1.8":{"name":"@openai/codex-security","version":"0.1.8","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.8","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"604a9b870c66ff2bfaf52108c01b05b686c45cf5","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.8.tgz","fileCount":199,"integrity":"sha512-GFlCb0UPh/kWp6UJsNhWq4LGxIKMRv0dM9fL+xCWqoXV5uVNq4YK7+i/ld1twyD4hNhPTdulvKq0kpB9+zZgGQ==","signatures":[{"sig":"MEUCIEmTZHNfVjy/IudSHX/JiFV/0lhhO7GkmIdcNYQkGXKnAiEAkBwAh2kLgfdM0RY2tOOgtjkm1/LwUs90qhyanFgzr1k=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.8","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":3241381},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.8.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.13.0 || ^24.0.0 || ^26.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"8c40d7a0061488fedcd7e24a825c332f82d45483","scripts":{"lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","build":"node --run clean && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,json,md}\"","audit:prod":"pnpm audit --prod --audit-level high","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.8.tgz","_integrity":"sha512-GFlCb0UPh/kWp6UJsNhWq4LGxIKMRv0dM9fL+xCWqoXV5uVNq4YK7+i/ld1twyD4hNhPTdulvKq0kpB9+zZgGQ==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.15.0","dependencies":{"ajv":"8.20.0","incur":"0.4.13","fflate":"0.8.2","fast-uri":"3.1.5","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"5.6.205","extract-zip":"2.0.1","@octokit/core":"7.0.6","@openai/codex":"0.144.6","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.144.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.2.5","@types/bun":"1.3.13","typescript":"5.7.3","@types/node":"22.19.17","@types/papaparse":"5.3.15","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.8_1786139983805_0.24006160598765947","host":"s3://npm-registry-packages-npm-production"}},"0.1.9":{"name":"@openai/codex-security","version":"0.1.9","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.9","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"0d946948e79a155b17626f611542eadfb68f5cf4","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.9.tgz","fileCount":199,"integrity":"sha512-3uNv3cgwjvAD70RyW5N2+wKC7biPSULEKVAfOcfAzQQBF1IpAbFPGO1hwj5YgQdL/te7XP4Ie8JGa1K2Eb8gDA==","signatures":[{"sig":"MEYCIQCMP5N0AW3YIlGEEdZTH9CgtNm8lPdeQ207tSFSIeFplAIhAJm0g+1qeB0Sw4/+oRm8eIR8qaChci74My2d8gIYhFb/","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.9","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":3175276},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.9.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.13.0 || ^24.0.0 || ^26.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"bd5c91d514f69593a7ad6de6d8d49c776f94d9b7","scripts":{"lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","build":"node --run clean && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,json,md}\"","audit:prod":"pnpm audit --prod --audit-level high","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.9.tgz","_integrity":"sha512-3uNv3cgwjvAD70RyW5N2+wKC7biPSULEKVAfOcfAzQQBF1IpAbFPGO1hwj5YgQdL/te7XP4Ie8JGa1K2Eb8gDA==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.15.0","dependencies":{"ajv":"8.20.0","incur":"0.4.13","fflate":"0.8.2","fast-uri":"3.1.5","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"6.2.108","extract-zip":"2.0.1","@octokit/core":"7.0.6","@openai/codex":"0.144.6","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.144.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.2.5","@types/bun":"1.3.13","typescript":"5.7.3","@types/node":"22.19.17","@types/papaparse":"5.3.15","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.9_1786406555594_0.9293396116276718","host":"s3://npm-registry-packages-npm-production"}},"0.1.10":{"name":"@openai/codex-security","version":"0.1.10","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.10","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"9d6fbcaaecdf3ed04ddf990d38699096a8790693","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.10.tgz","fileCount":203,"integrity":"sha512-sm/Yen25EpM2twxv0CCUQ7OxToAN/1PAm+YvNT85XMuSnDDWGr5oS6cnfk+AARCRhjM28cgMBSYLydpfeCrDTQ==","signatures":[{"sig":"MEUCIQD/JWUV/4lKl4bHZUyqD6Mi2B7d9m0ua05YJUtdyfKbjgIgOqy6oC9T4lSez5pl4dpPBszZPsagCrB+vrgRrBmIhGI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.10","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":3218153},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.10.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.13.0 || ^24.0.0 || ^26.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"bf0184d05c7dce5ce86bbb91adc47ecd776b656c","scripts":{"lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","build":"node --run clean && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,json,md}\"","audit:prod":"pnpm audit --prod --audit-level high","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.10.tgz","_integrity":"sha512-sm/Yen25EpM2twxv0CCUQ7OxToAN/1PAm+YvNT85XMuSnDDWGr5oS6cnfk+AARCRhjM28cgMBSYLydpfeCrDTQ==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.15.0","dependencies":{"ajv":"8.20.0","incur":"0.4.13","fflate":"0.8.2","fast-uri":"3.1.5","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"6.2.108","extract-zip":"2.0.1","@octokit/core":"7.0.6","@openai/codex":"0.144.6","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.144.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.2.5","@types/bun":"1.3.13","typescript":"5.7.3","@types/node":"22.19.17","@types/papaparse":"5.3.15","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.10_1786500970788_0.9081859060173021","host":"s3://npm-registry-packages-npm-production"}},"0.1.11":{"name":"@openai/codex-security","version":"0.1.11","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.11","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"6bb5be96005c15e10de6157b488298f580ab09a6","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.11.tgz","fileCount":203,"integrity":"sha512-wxaE4fnz6Z2HM7gn7xMY4QKRBuZwsW8gUamLLSXMT1KJ211TBcfsfEAOONi4vrcZ8v/V20inEK6WOP1Kv9kfIA==","signatures":[{"sig":"MEUCIQDFX5+9XJDl0OIWTI+8Y0mCY5xDc9pSPkwE6+KsC+mq0wIgPwVyFCdecVfvyobRh2qOcj3iSn40nOA65qDtxxU4czk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.11","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":3220610},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.11.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.13.0 || ^24.0.0 || ^26.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"58887aafd5acc861daff83bdac9829dfa484b251","scripts":{"lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","build":"node --run clean && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,json,md}\"","audit:prod":"pnpm audit --prod --audit-level high","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.11.tgz","_integrity":"sha512-wxaE4fnz6Z2HM7gn7xMY4QKRBuZwsW8gUamLLSXMT1KJ211TBcfsfEAOONi4vrcZ8v/V20inEK6WOP1Kv9kfIA==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.15.0","dependencies":{"ajv":"8.20.0","incur":"0.4.13","fflate":"0.8.2","fast-uri":"3.1.5","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"6.2.108","extract-zip":"2.0.1","@octokit/core":"7.0.6","@openai/codex":"0.144.6","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.144.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.2.5","@types/bun":"1.3.13","typescript":"5.7.3","@types/node":"22.19.17","@types/papaparse":"5.3.15","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.11_1786646646047_0.6721325658827408","host":"s3://npm-registry-packages-npm-production"}},"0.1.12":{"name":"@openai/codex-security","version":"0.1.12","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.12","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"wadih-openai","email":"wadih@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"a6a5a69419355b8a24614ba48417685b8a47b854","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.12.tgz","fileCount":202,"integrity":"sha512-YOw2k2bdJlYuMlmPoF+8rR4MZzKoTrFKyfudJY9hOEaGeDBZCmkCbirE8JR9/VK8HKliRABRLAX8C2mJdtPADQ==","signatures":[{"sig":"MEUCIQD7CgNlXm2n/9qi/czd2aHZ8s4ZrEOuIoe1tLmjs56zVQIgX1Ks5siWZX4tBJ8qhZOo24kBAv0Pe14mfq37TZLR7WU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.12","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":3263183},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.12.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.13.0 || ^24.0.0 || ^26.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"ab8a012e0cacb3efbfea3eab56a6c8edf62420f8","scripts":{"lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","build":"node --run clean && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,json,md}\"","audit:prod":"pnpm audit --prod --audit-level high","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.12.tgz","_integrity":"sha512-YOw2k2bdJlYuMlmPoF+8rR4MZzKoTrFKyfudJY9hOEaGeDBZCmkCbirE8JR9/VK8HKliRABRLAX8C2mJdtPADQ==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.15.0","dependencies":{"ajv":"8.20.0","incur":"0.4.13","fflate":"0.8.2","fast-uri":"3.1.5","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"6.2.108","extract-zip":"2.0.1","@octokit/core":"7.0.6","@openai/codex":"0.148.0-alpha.8","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.148.0-alpha.8"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.2.5","@types/bun":"1.3.13","typescript":"5.7.3","@types/node":"22.19.17","@types/papaparse":"5.3.15","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.12_1786770943631_0.0217157136537387","host":"s3://npm-registry-packages-npm-production"}},"0.1.13":{"name":"@openai/codex-security","version":"0.1.13","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.13","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"wadih-openai","email":"wadih@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"7aaf6c6da54be4e5a1c5d92a3e9edb172c96b698","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.13.tgz","fileCount":218,"integrity":"sha512-HD6XrZ97Ku5MeyIk5wo5cAiII0wJEfs0+uzUWiJDJzwyot3mPfjBVV8P+aK1Jb0ueY9q0Xw8srwOo1FXxm/QcQ==","signatures":[{"sig":"MEYCIQCvHhvHpJuoqCXWygP5xcHYx6DOro2JLbuMN3f1J94vqwIhALOPBTemPdzTfaFlP10Okt+w62IZT1FkMW4pbm1JUtfJ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.13","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":3533458},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.13.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.13.0 || ^24.0.0 || ^26.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"fc93606caee3e06019b9873ed8994c29534b8c60","scripts":{"lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","build":"node --run clean && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,json,md}\"","audit:prod":"pnpm audit --prod --audit-level high","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.13.tgz","_integrity":"sha512-HD6XrZ97Ku5MeyIk5wo5cAiII0wJEfs0+uzUWiJDJzwyot3mPfjBVV8P+aK1Jb0ueY9q0Xw8srwOo1FXxm/QcQ==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.15.0","dependencies":{"ajv":"8.20.0","incur":"0.4.13","fflate":"0.8.2","fast-uri":"3.1.5","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"6.2.108","@linear/sdk":"89.0.0","extract-zip":"2.0.1","@octokit/core":"7.0.6","@openai/codex":"0.148.0-alpha.8","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.148.0-alpha.8"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.2.5","@types/bun":"1.3.13","typescript":"5.7.3","@types/node":"22.19.17","@types/papaparse":"5.3.15","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.13_1786851783934_0.5263298989667469","host":"s3://npm-registry-packages-npm-production"}},"0.1.14":{"name":"@openai/codex-security","version":"0.1.14","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.14","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"wadih-openai","email":"wadih@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"d2db4529ed6e1bc89e5dbf905007055bbd002bd4","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.14.tgz","fileCount":218,"integrity":"sha512-o3H5TtC3QxB6ml3ZesDHd/FFIvy0KnsUCGOmyx5VwMlscf1f6JGd9nPZBn7fUOWbRa2Y3XIJzp2lb3dVLPmJ+Q==","signatures":[{"sig":"MEUCIEqcjMeua51llfKL3nFqrzGwUEwINVSKXtODrsu8fqapAiEA0/2/iKt5qdMKqeyhf/1wv1F5Nm8u5+x7Z7yo0wJMZ2c=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.14","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":3536061},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.14.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.13.0 || ^24.0.0 || ^26.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"5d1afcd312933121e36dc892dcb12e8d2e3e1de3","scripts":{"lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","build":"node --run clean && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,json,md}\"","audit:prod":"pnpm audit --prod --audit-level high","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.14.tgz","_integrity":"sha512-o3H5TtC3QxB6ml3ZesDHd/FFIvy0KnsUCGOmyx5VwMlscf1f6JGd9nPZBn7fUOWbRa2Y3XIJzp2lb3dVLPmJ+Q==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.15.0","dependencies":{"ajv":"8.20.0","incur":"0.4.13","fflate":"0.8.2","fast-uri":"3.1.5","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"6.2.108","@linear/sdk":"89.0.0","extract-zip":"2.0.1","@octokit/core":"7.0.6","@openai/codex":"0.148.0-alpha.8","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.148.0-alpha.8"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.2.5","@types/bun":"1.3.13","typescript":"5.7.3","@types/node":"22.19.17","@types/papaparse":"5.3.15","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.14_1786859730670_0.8443818908921623","host":"s3://npm-registry-packages-npm-production"}},"0.1.15":{"name":"@openai/codex-security","version":"0.1.15","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.15","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"wadih-openai","email":"wadih@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"fd0fe52fadfd2a765768bfbbd25b02da469cb4f4","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.15.tgz","fileCount":231,"integrity":"sha512-hdoVhlm/fU7Wa2oX9t6AectzA15g1X3nsxDCwkI0a832X37U5SppsEizL3jjZfGI0m8NeHLqMI8/Wb8V8XfILg==","signatures":[{"sig":"MEUCIQCIxIuEoeBv74a8Jv4EN+sG3VlMzAZhlpZCsKbG5Hk8dQIgX5zrru1/Dx2i0X8RmyQjfj2Z+xpJpdyBMLdLg44VoPo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.15","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":3848760},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.15.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.13.0 || ^24.0.0 || ^26.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"b920ca4536a9ff4f24a32d895d4f7bb90fec76b4","scripts":{"lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","build":"node --run clean && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,tsx,json,md}\"","audit:prod":"pnpm audit --prod --audit-level high","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.15.tgz","_integrity":"sha512-hdoVhlm/fU7Wa2oX9t6AectzA15g1X3nsxDCwkI0a832X37U5SppsEizL3jjZfGI0m8NeHLqMI8/Wb8V8XfILg==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.15.0","dependencies":{"ajv":"8.20.0","ink":"6.8.0","incur":"0.4.13","react":"19.2.4","fflate":"0.8.2","fast-uri":"3.1.5","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"6.2.108","@linear/sdk":"89.0.0","extract-zip":"2.0.1","@octokit/core":"7.0.6","@openai/codex":"0.148.0-alpha.8","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.148.0-alpha.8"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.2.5","@types/bun":"1.3.13","typescript":"5.7.3","@types/node":"22.19.17","@types/react":"19.2.14","@types/papaparse":"5.3.15","ink-testing-library":"4.0.0","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.15_1787165575296_0.008323293247582741","host":"s3://npm-registry-packages-npm-production"}},"0.1.16":{"name":"@openai/codex-security","version":"0.1.16","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.16","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"wadih-openai","email":"wadih@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"31d6fbe8a02687e663df870165a1056861831b0d","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.16.tgz","fileCount":233,"integrity":"sha512-XkZiMzVwx8dm+hvU67yPQScSkiSMTAICL2J62yzsn6KfJXZ/NAr/RctIKtzUJ35yUPg6TCxZCYSXP0y98xZ23Q==","signatures":[{"sig":"MEUCIEvTa7X3ws6MKmRVJHmzsvbHU8ByEdDDLnD4+KoK82vGAiEA6ZXZYKrWKYE0dlF5d4abOyoWaBoN9m7oX+LHychSgW4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.16","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":3911493},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.16.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.13.0 || ^24.0.0 || ^26.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"7183cd129a7ff2f283429ae798e0cc819a7a0414","scripts":{"lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","build":"node --run clean && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,tsx,json,md}\"","audit:prod":"pnpm audit --prod --audit-level high","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.16.tgz","_integrity":"sha512-XkZiMzVwx8dm+hvU67yPQScSkiSMTAICL2J62yzsn6KfJXZ/NAr/RctIKtzUJ35yUPg6TCxZCYSXP0y98xZ23Q==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.15.0","dependencies":{"ajv":"8.20.0","ink":"6.8.0","incur":"0.4.13","react":"19.2.4","fflate":"0.8.2","fast-uri":"3.1.5","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"6.2.108","@linear/sdk":"89.0.0","extract-zip":"2.0.1","@octokit/core":"7.0.6","@openai/codex":"0.148.0-alpha.8","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.148.0-alpha.8"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.2.5","@types/bun":"1.3.13","typescript":"5.7.3","@types/node":"22.19.17","@types/react":"19.2.14","@types/papaparse":"5.3.15","ink-testing-library":"4.0.0","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.16_1787202719286_0.24582576751187002","host":"s3://npm-registry-packages-npm-production"}},"0.1.17":{"name":"@openai/codex-security","version":"0.1.17","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.17","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"wadih-openai","email":"wadih@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"5c70c67eebc9cfd8d9b56aab1078c0c827ed8466","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.17.tgz","fileCount":263,"integrity":"sha512-/RTOVcZo+UY/HR7y+qrk+d5bNKWbUZBuTkqb+KGQrIZBtRAYTOnlyVKItX8lUwo9A1v1qxnJq2QB0KYEDWCVkg==","signatures":[{"sig":"MEUCIE+txWRy1VtSqpjlopK1dkfXAfwgNx4SNBxuxwuAVJW8AiEAxoFKnU8UXxUEo2TOyRDGxIGlUwgocwRB9ftZ1kNDPtE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.17","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":4192293},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.17.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.13.0 || ^24.0.0 || ^26.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"e71fefc0918d918fb5b79486d0d626d5ec2ea2f3","scripts":{"lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","build":"node --run clean && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,tsx,json,md}\"","test:ci":"node -e \"require('node:fs').mkdirSync('reports',{recursive:true})\" && pnpm run test --coverage --coverage-reporter=text --coverage-reporter=lcov --reporter=junit --reporter-outfile=reports/junit.xml","audit:prod":"pnpm audit --prod --audit-level high","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","test:mutation":"stryker run","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.17.tgz","_integrity":"sha512-/RTOVcZo+UY/HR7y+qrk+d5bNKWbUZBuTkqb+KGQrIZBtRAYTOnlyVKItX8lUwo9A1v1qxnJq2QB0KYEDWCVkg==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.15.0","dependencies":{"ajv":"8.20.0","ink":"6.8.0","incur":"0.4.13","react":"19.2.4","fflate":"0.8.2","semver":"7.8.5","fast-uri":"3.1.5","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"6.2.108","@linear/sdk":"89.0.0","extract-zip":"2.0.1","@octokit/core":"7.0.6","@openai/codex":"0.148.0-alpha.8","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.148.0-alpha.8"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.2.5","@types/bun":"1.3.13","fast-check":"4.9.0","typescript":"5.7.3","@types/node":"22.19.17","@types/react":"19.2.14","@types/semver":"7.8.0","@types/papaparse":"5.3.15","ink-testing-library":"4.0.0","@stryker-mutator/core":"9.6.1","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.17_1787453912850_0.3138493261290507","host":"s3://npm-registry-packages-npm-production"}},"0.1.18":{"name":"@openai/codex-security","version":"0.1.18","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.18","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"wadih-openai","email":"wadih@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"657d580e1f96a7df63032156b1944c6bb454aa81","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.18.tgz","fileCount":265,"integrity":"sha512-YQNWlC4sRV6QO8bCdmjJRLO7MgHlnfaBKJbRWNqeYv6N1rLgSFLx0HtDwwfNwf5bs51+WPnDEjVB5Om5XvVAJw==","signatures":[{"sig":"MEUCIQDfxiDDTD3KjjC3CXsDpYnamHaak/XUeSDoSISvTPrLPwIgNPlzoIOS9oJuum9QmrlLZlHVAR9DfnG+P95uLGTiKgw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.18","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":4286047},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.18.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.13.0 || ^24.0.0 || ^26.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"227fc32ac47c9ac5d78f6dd246d8899673a67858","scripts":{"lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","build":"node --run clean && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,tsx,json,md}\"","test:ci":"node -e \"require('node:fs').mkdirSync('reports',{recursive:true})\" && pnpm run test --coverage --coverage-reporter=text --coverage-reporter=lcov --reporter=junit --reporter-outfile=reports/junit.xml","audit:prod":"pnpm audit --prod --audit-level high","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","test:mutation":"stryker run","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.18.tgz","_integrity":"sha512-YQNWlC4sRV6QO8bCdmjJRLO7MgHlnfaBKJbRWNqeYv6N1rLgSFLx0HtDwwfNwf5bs51+WPnDEjVB5Om5XvVAJw==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.15.0","dependencies":{"ajv":"8.20.0","ink":"6.8.0","incur":"0.4.13","react":"19.2.4","fflate":"0.8.2","semver":"7.8.5","fast-uri":"3.1.5","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"6.2.108","@linear/sdk":"89.0.0","extract-zip":"2.0.1","@octokit/core":"7.0.6","@openai/codex":"0.148.0-alpha.8","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.148.0-alpha.8"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.2.5","@types/bun":"1.3.13","fast-check":"4.9.0","typescript":"5.7.3","@types/node":"22.19.17","@types/react":"19.2.14","@types/semver":"7.8.0","@types/papaparse":"5.3.15","ink-testing-library":"4.0.0","@stryker-mutator/core":"9.6.1","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.18_1787525202737_0.5468808378888526","host":"s3://npm-registry-packages-npm-production"}},"0.1.19":{"name":"@openai/codex-security","version":"0.1.19","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.19","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"wadih-openai","email":"wadih@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"5f59500841661ae6e830e2c488f7b72f77364b4b","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.19.tgz","fileCount":269,"integrity":"sha512-agrgjCQxm/gPCFucg6EZR5VPy1SJzgAgzvq+7n6nz4fzSc2gzO3NHiqTNa+bMzm0CKlT8R3LGXMv8Z39Ighwtg==","signatures":[{"sig":"MEUCIBFV4whvQAgAoT9nfFaGLyvxGriYM6g1QU4QqJa6n5MUAiEAr5DlkK1S+ZNT66Prw0Juofh4lqoNQDYgI3Zvm2Ucg08=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.19","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":4341319},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.19.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.13.0 || ^24.0.0 || ^26.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"df61ecedbc1f139d21210e113e80af4ffcc87e65","scripts":{"lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","build":"node --run clean && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,tsx,json,md}\"","test:ci":"node -e \"require('node:fs').mkdirSync('reports',{recursive:true})\" && pnpm run test --coverage --coverage-reporter=text --coverage-reporter=lcov --reporter=junit --reporter-outfile=reports/junit.xml","audit:prod":"pnpm audit --prod --audit-level high","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","test:mutation":"stryker run","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.19.tgz","_integrity":"sha512-agrgjCQxm/gPCFucg6EZR5VPy1SJzgAgzvq+7n6nz4fzSc2gzO3NHiqTNa+bMzm0CKlT8R3LGXMv8Z39Ighwtg==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.15.0","dependencies":{"ajv":"8.20.0","ink":"6.8.0","incur":"0.4.13","react":"19.2.4","fflate":"0.8.2","semver":"7.8.5","fast-uri":"3.1.5","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"6.2.108","@linear/sdk":"89.0.0","extract-zip":"2.0.1","@octokit/core":"7.0.6","@openai/codex":"0.148.0-alpha.8","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.148.0-alpha.8"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.2.5","@types/bun":"1.3.13","fast-check":"4.9.0","typescript":"5.7.3","@types/node":"22.19.17","@types/react":"19.2.14","@types/semver":"7.8.0","@types/papaparse":"5.3.15","ink-testing-library":"4.0.0","@stryker-mutator/core":"9.6.1","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.19_1787618679936_0.9978454557843359","host":"s3://npm-registry-packages-npm-production"}},"0.1.20":{"name":"@openai/codex-security","version":"0.1.20","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.20","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"wadih-openai","email":"wadih@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"d62a1d8406dd58b1f15fac3f3f71f45393dd81dc","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.20.tgz","fileCount":269,"integrity":"sha512-cLDpc9lG2A/v57OqEUUKOEL2RtYx5xQ8QwH1kIhmYfLe7UTnnkP5hZwYu6tzvLlsWbgZsBcVHNENr1jYxdyiTg==","signatures":[{"sig":"MEUCIQC6mwirEhQ0c99Z1iqWg7lu8Rltc82aROr2ATQvnpKJJwIgIKocIixAcijub658GaQDwBXZkPjpUOrLPsVC9Oe7h60=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.20","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":4437261},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.20.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.13.0 || ^24.0.0 || ^26.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"59d026a0579af084b419cd7f33b8e1b867338ee8","scripts":{"lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","build":"node --run clean && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,tsx,json,md}\"","test:ci":"node -e \"require('node:fs').mkdirSync('reports',{recursive:true})\" && pnpm run test --coverage --coverage-reporter=text --coverage-reporter=lcov --reporter=junit --reporter-outfile=reports/junit.xml","audit:prod":"pnpm audit --prod --audit-level high","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","test:mutation":"stryker run","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.20.tgz","_integrity":"sha512-cLDpc9lG2A/v57OqEUUKOEL2RtYx5xQ8QwH1kIhmYfLe7UTnnkP5hZwYu6tzvLlsWbgZsBcVHNENr1jYxdyiTg==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.15.0","dependencies":{"ajv":"8.20.0","ink":"6.8.0","incur":"0.4.13","react":"19.2.4","fflate":"0.8.2","semver":"7.8.5","fast-uri":"3.1.5","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"6.2.108","@linear/sdk":"89.0.0","extract-zip":"2.0.1","@octokit/core":"7.0.6","@openai/codex":"0.148.0-alpha.8","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.148.0-alpha.8"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.2.5","@types/bun":"1.3.13","fast-check":"4.9.0","typescript":"5.7.3","@types/node":"22.19.17","@types/react":"19.2.14","@types/semver":"7.8.0","@types/papaparse":"5.3.15","ink-testing-library":"4.0.0","@stryker-mutator/core":"9.6.1","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.20_1787639109307_0.6565933714201566","host":"s3://npm-registry-packages-npm-production"}},"0.1.21":{"name":"@openai/codex-security","version":"0.1.21","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.21","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"wadih-openai","email":"wadih@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"0e2077dce383c4a89b682a4ebee3a85c2ee71a53","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.21.tgz","fileCount":282,"integrity":"sha512-hyNLeJ9iIR70G0g3oiuE0kDDKpMSpamQUGnbuBy5RubbwAfpYFeM4N+PuooEfWWKIwup7Uf+0uGgPE5EvXpunA==","signatures":[{"sig":"MEUCIQD3HTYveMIaK4dMpWMLFN0RIjvojsge0eIfQBiYxtvUPwIgIAWUw4Xa+Qh8qnmbXC8Fk5A0jwTbxA8cuByus6/S9aY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.21","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":4572928},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.21.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.13.0 || ^24.0.0 || ^26.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"fd98a9009b0a3a919b6cbce7c541b09d543dcaec","scripts":{"lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","build":"node --run clean && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,tsx,json,md}\"","test:ci":"node -e \"require('node:fs').mkdirSync('reports',{recursive:true})\" && pnpm run test --coverage --coverage-reporter=text --coverage-reporter=lcov --reporter=junit --reporter-outfile=reports/junit.xml","audit:prod":"pnpm audit --prod --audit-level high","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","test:mutation":"stryker run","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.21.tgz","_integrity":"sha512-hyNLeJ9iIR70G0g3oiuE0kDDKpMSpamQUGnbuBy5RubbwAfpYFeM4N+PuooEfWWKIwup7Uf+0uGgPE5EvXpunA==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.15.0","dependencies":{"ajv":"8.20.0","ink":"6.8.0","incur":"0.4.13","react":"19.2.4","fflate":"0.8.2","semver":"7.8.5","fast-uri":"3.1.5","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"6.2.108","@linear/sdk":"89.0.0","extract-zip":"2.0.1","@octokit/core":"7.0.6","@openai/codex":"0.149.1","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.149.1"},"publishConfig":{"access":"public","executableFiles":["_bundled_plugin/scripts/launch_codex_security_mcp"]},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.2.5","@types/bun":"1.3.13","fast-check":"4.9.0","typescript":"5.7.3","@types/node":"22.19.17","@types/react":"19.2.14","@types/semver":"7.8.0","@types/papaparse":"5.3.15","ink-testing-library":"4.0.0","@stryker-mutator/core":"9.6.1","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.21_1787817194389_0.6647134012540246","host":"s3://npm-registry-packages-npm-production"}},"0.1.23":{"name":"@openai/codex-security","version":"0.1.23","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.23","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"wadih-openai","email":"wadih@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"92b559befaba4579ea4ea3ad375f0953547b1ff5","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.23.tgz","fileCount":381,"integrity":"sha512-uLjEy8e5FN+lTGyTgZMNZQyz54UumRCWUQTfcqtksY3IXgqXmm5LH4TNTLEPwm0/6wHNCzxl+0XwI+t/q8Vwyw==","signatures":[{"sig":"MEUCIGfjDAV+2KAJ8Xcl2oX17zfjL0cJlvIL3rdQaqwecTxfAiEAr5VB2ZxN0AAKBPLuae+n9U0y/m5oF43vq2EH0sM4SIQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.23","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":5294136},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.23.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.13.0 || ^24.0.0 || ^26.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"3bccb23f85467d10237a28f510693af5e2bcc36d","scripts":{"lint":"tsc --noEmit","test":"node --run build:plugin && bun test --timeout 30000 ./tests-ts","build":"node --run clean && tsc -p tsconfig.build.json && node scripts/build-dashboard.mjs","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && npm --prefix ../../plugins/codex-security/mcp-app run typecheck && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,tsx,json,md}\"","test:ci":"node -e \"require('node:fs').mkdirSync('reports',{recursive:true})\" && pnpm run test --coverage --coverage-reporter=text --coverage-reporter=lcov --reporter=junit --reporter-outfile=reports/junit.xml","test:mcp":"node --run build:plugin && npm --prefix ../../plugins/codex-security/mcp-app run test:mcp","audit:prod":"pnpm audit --prod --audit-level high","build:plugin":"node scripts/build-plugin.mjs","start:server":"node dist/server/index.js","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","test:mutation":"stryker run","generate:models":"node scripts/generate-models.cjs","check:plugin-source":"node scripts/check-plugin-source.mjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.23.tgz","_integrity":"sha512-uLjEy8e5FN+lTGyTgZMNZQyz54UumRCWUQTfcqtksY3IXgqXmm5LH4TNTLEPwm0/6wHNCzxl+0XwI+t/q8Vwyw==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.15.0","dependencies":{"ajv":"8.20.0","ink":"6.8.0","incur":"0.4.13","react":"19.2.4","fflate":"0.8.2","semver":"7.8.5","fast-uri":"3.1.5","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"6.2.108","@linear/sdk":"89.0.0","extract-zip":"2.0.1","js-tiktoken":"1.0.21","@octokit/core":"7.0.6","@openai/codex":"0.149.1","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.149.1"},"publishConfig":{"access":"public","executableFiles":["_bundled_plugin/scripts/launch_codex_security_mcp"]},"_hasShrinkwrap":false,"devDependencies":{"esbuild":"0.28.2","postcss":"8.5.6","prettier":"3.2.5","react-dom":"19.2.4","@types/bun":"1.3.13","fast-check":"4.9.0","typescript":"5.7.3","@types/node":"22.19.17","tailwindcss":"4.3.3","@types/react":"19.2.14","@types/semver":"7.8.0","@types/papaparse":"5.3.15","@types/react-dom":"19.2.3","@openai/apps-sdk-ui":"0.2.2","ink-testing-library":"4.0.0","@tailwindcss/postcss":"4.3.3","@stryker-mutator/core":"9.6.1","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.23_1787925045794_0.3981770553464834","host":"s3://npm-registry-packages-npm-production"}},"0.1.24":{"name":"@openai/codex-security","version":"0.1.24","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.24","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"wadih-openai","email":"wadih@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"e7a90d479af5af76bd3e5941e387fe477b9f4ac5","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.24.tgz","fileCount":390,"integrity":"sha512-14HrUkO9pe3DY6x5JzXSik2/HAoa4T6JcVlY3LK9downpJbgi1yd5qYb5o6jzcj2Dupsc5bpXV6me+Cr9YinHQ==","signatures":[{"sig":"MEUCIQCTQio/qbULe5C3Z4gewtIreu7V6/jHGHJwN2rZfbKlPwIgChnlIv2VrjTI3S3bNEzQJvUuR2XjFbkXid4VIRzqYBg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.24","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":5330153},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.24.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.13.0 || ^24.0.0 || ^26.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"d4b7d29a87cb86c9072f7905ba867d02385d8fd3","scripts":{"lint":"tsc --noEmit","test":"node --run build:plugin && bun test --timeout 30000 ./tests-ts","build":"node --run clean && tsc -p tsconfig.build.json && node scripts/build-dashboard.mjs","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && npm --prefix ../../plugins/codex-security/mcp-app run typecheck && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,tsx,json,md}\"","test:ci":"node -e \"require('node:fs').mkdirSync('reports',{recursive:true})\" && pnpm run test --coverage --coverage-reporter=text --coverage-reporter=lcov --reporter=junit --reporter-outfile=reports/junit.xml","test:mcp":"node --run build:plugin && npm --prefix ../../plugins/codex-security/mcp-app run test:mcp","audit:prod":"pnpm audit --prod --audit-level high","build:plugin":"node scripts/build-plugin.mjs","start:server":"node dist/server/index.js","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","test:mutation":"stryker run","generate:models":"node scripts/generate-models.cjs","check:plugin-source":"node scripts/check-plugin-source.mjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.24.tgz","_integrity":"sha512-14HrUkO9pe3DY6x5JzXSik2/HAoa4T6JcVlY3LK9downpJbgi1yd5qYb5o6jzcj2Dupsc5bpXV6me+Cr9YinHQ==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.15.0","dependencies":{"ajv":"8.20.0","ink":"6.8.0","incur":"0.4.13","react":"19.2.4","fflate":"0.8.2","semver":"7.8.5","fast-uri":"3.1.5","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"6.2.108","@linear/sdk":"89.0.0","extract-zip":"2.0.1","js-tiktoken":"1.0.21","@octokit/core":"7.0.6","@openai/codex":"0.149.1","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.149.1"},"publishConfig":{"access":"public","executableFiles":["_bundled_plugin/scripts/launch_codex_security_mcp"]},"_hasShrinkwrap":false,"devDependencies":{"esbuild":"0.28.2","postcss":"8.5.23","prettier":"3.2.5","react-dom":"19.2.4","@types/bun":"1.3.13","fast-check":"4.9.0","typescript":"5.7.3","@types/node":"22.19.17","tailwindcss":"4.3.3","@types/react":"19.2.14","@types/semver":"7.8.0","@types/papaparse":"5.3.15","@types/react-dom":"19.2.3","@openai/apps-sdk-ui":"0.2.2","ink-testing-library":"4.0.0","@tailwindcss/postcss":"4.3.3","@stryker-mutator/core":"9.6.1","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.24_1788021774741_0.16908358528197964","host":"s3://npm-registry-packages-npm-production"}},"0.1.25":{"name":"@openai/codex-security","version":"0.1.25","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.25","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"wadih-openai","email":"wadih@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"df1ccb1a9592e17aea4d07273cb2a5bfc75c9e70","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.25.tgz","fileCount":398,"integrity":"sha512-ohJ7Awd6ZNKOVnzFLq+DWNepJlTOCJ3DX1Ax282Xsnw0mQZ0xrOGvYNVh54BikF3CTT+VVQcX2jhoGwO37spWA==","signatures":[{"sig":"MEUCIQCJBdmg/lSFTpSgMM00gzXUgUnWcqNiamZj8MEROQL33gIgfjtICiFTEVuJ4Uc8d2nN/8nQEK66yuZFk+cx8GKgnY8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.25","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":5549357},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.25.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.13.0 || ^24.0.0 || ^26.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"},"./server":{"types":"./dist/server/api.d.ts","import":"./dist/server/api.js","default":"./dist/server/api.js"}},"gitHead":"7d042cdaefdbf1c06eac886a25c2700897aae808","scripts":{"lint":"tsc --noEmit","test":"node --run build:plugin && bun test --timeout 30000 ./tests-ts","build":"node --run clean && tsc -p tsconfig.build.json && node scripts/build-dashboard.mjs","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && pnpm --dir ../../plugins/codex-security/mcp-app run typecheck && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,tsx,json,md}\"","test:ci":"node -e \"require('node:fs').mkdirSync('reports',{recursive:true})\" && pnpm run test --coverage --coverage-reporter=text --coverage-reporter=lcov --reporter=junit --reporter-outfile=reports/junit.xml","test:mcp":"node --run build:plugin && pnpm --dir ../../plugins/codex-security/mcp-app run test:mcp","audit:prod":"pnpm audit --prod --audit-level high","build:plugin":"node scripts/build-plugin.mjs","start:server":"node dist/server/index.js","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","test:mutation":"stryker run","generate:models":"node scripts/generate-models.cjs","check:plugin-source":"node scripts/check-plugin-source.mjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.25.tgz","_integrity":"sha512-ohJ7Awd6ZNKOVnzFLq+DWNepJlTOCJ3DX1Ax282Xsnw0mQZ0xrOGvYNVh54BikF3CTT+VVQcX2jhoGwO37spWA==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.15.0","dependencies":{"ajv":"8.20.0","ink":"6.8.0","incur":"0.4.13","react":"19.2.4","fflate":"0.8.2","semver":"7.8.5","fast-uri":"3.1.5","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"6.2.108","@linear/sdk":"89.0.0","extract-zip":"2.0.1","js-tiktoken":"1.0.21","@octokit/core":"7.0.6","@openai/codex":"0.149.1","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.149.1"},"publishConfig":{"access":"public","executableFiles":["_bundled_plugin/scripts/launch_codex_security_mcp"]},"_hasShrinkwrap":false,"devDependencies":{"esbuild":"0.28.2","postcss":"8.5.23","prettier":"3.2.5","react-dom":"19.2.4","@types/bun":"1.3.13","fast-check":"4.9.0","typescript":"5.7.3","@types/node":"22.19.17","tailwindcss":"4.3.3","@types/react":"19.2.14","@types/semver":"7.8.0","@types/papaparse":"5.3.15","@types/react-dom":"19.2.3","@openai/apps-sdk-ui":"0.2.2","ink-testing-library":"4.0.0","@tailwindcss/postcss":"4.3.3","@stryker-mutator/core":"9.6.1","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.25_1788308040020_0.6584095093233309","host":"s3://npm-registry-packages-npm-production"}},"0.1.26":{"name":"@openai/codex-security","version":"0.1.26","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.26","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"wadih-openai","email":"wadih@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"3c85bdb3e15a9d472d974fd8c8ca6e4fb6a15823","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.26.tgz","fileCount":415,"integrity":"sha512-j+NTS3DHRAR63pvfsNlpKcqG3gWDjfQZmI4o7qXJ2F+P3vqYOIdfAU3twyulcdt210b2XAANJ7KbV3faglA1FA==","signatures":[{"sig":"MEUCIC/cVV9Cii/XKQ+IAg94yM0jsJfosnNnq+9SMnUrb69DAiEA7f4cDmC8gpyXd1fotxjKUHvS15JAWtq7yd4GB2W82Lk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.26","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":5751146},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.26.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.13.0 || ^24.0.0 || ^26.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"},"./server":{"types":"./dist/server/api.d.ts","import":"./dist/server/api.js","default":"./dist/server/api.js"}},"gitHead":"2536d104deef9bca8ced84c6f6263b915418253b","scripts":{"lint":"tsc --noEmit","test":"node --run build:plugin && bun test --timeout 30000 ./tests-ts","build":"node --run clean && tsc -p tsconfig.build.json && node scripts/build-dashboard.mjs","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && pnpm --dir ../../plugins/codex-security/mcp-app run typecheck && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,tsx,json,md}\"","test:ci":"node -e \"require('node:fs').mkdirSync('reports',{recursive:true})\" && pnpm run test --coverage --coverage-reporter=text --coverage-reporter=lcov --reporter=junit --reporter-outfile=reports/junit.xml","test:mcp":"node --run build:plugin && pnpm --dir ../../plugins/codex-security/mcp-app run test:mcp","audit:prod":"pnpm audit --prod --audit-level high","build:plugin":"node scripts/build-plugin.mjs","start:server":"node dist/server/index.js","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","test:mutation":"stryker run","generate:models":"node scripts/generate-models.cjs","check:plugin-source":"node scripts/check-plugin-source.mjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.26.tgz","_integrity":"sha512-j+NTS3DHRAR63pvfsNlpKcqG3gWDjfQZmI4o7qXJ2F+P3vqYOIdfAU3twyulcdt210b2XAANJ7KbV3faglA1FA==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.15.0","dependencies":{"ajv":"8.20.0","ink":"6.8.0","incur":"0.4.13","react":"19.2.4","fflate":"0.8.3","semver":"7.8.5","fast-uri":"3.1.6","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"6.2.108","@linear/sdk":"89.0.0","extract-zip":"2.0.1","js-tiktoken":"1.0.21","@octokit/core":"7.0.6","@openai/codex":"0.149.1","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.149.1"},"publishConfig":{"access":"public","executableFiles":["_bundled_plugin/scripts/launch_codex_security_mcp"]},"_hasShrinkwrap":false,"devDependencies":{"esbuild":"0.28.2","postcss":"8.5.23","prettier":"3.2.5","react-dom":"19.2.4","@types/bun":"1.3.13","fast-check":"4.9.0","typescript":"5.7.3","@types/node":"22.19.17","tailwindcss":"4.3.3","@types/react":"19.2.14","@types/semver":"7.8.0","@types/papaparse":"5.3.15","@types/react-dom":"19.2.3","@openai/apps-sdk-ui":"0.2.2","ink-testing-library":"4.0.0","@tailwindcss/postcss":"4.3.3","@stryker-mutator/core":"9.6.1","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.26_1788896727451_0.47160922711915965","host":"s3://npm-registry-packages-npm-production"}},"0.1.27":{"_id":"@openai/codex-security@0.1.27","bin":{"codex-security":"bin/codex-security.mjs"},"bugs":{"url":"https://github.com/openai/codex-security/issues"},"dist":{"shasum":"29b42b2d377f9a707bc235936a17df80696c5b75","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.27.tgz","fileCount":454,"integrity":"sha512-PMeI03NA05rKDST630ijZp/9b3OI4o/p8s24Za5cGeGbMa3sTvBOS/nHDDqIgvvqmVPE09hVJTfCPkZrPIdy4g==","signatures":[{"sig":"MEQCIBO+c+4dqOJqUXFU3rO7RNZwItXG9qgED86TgBN1xMpjAiB7MDaXt/O+Ma9bINWTfKNCv9kAu7ZS9fTgrp3y5w03Jw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCqNAXtaDGRHA1KlGF2opAh6LiMKbbJJ+x4zTEjHkN5FQIgLYUDnaI0OpjxVG6lsb7CEPGWk3OnA0PCDL8nT8Yxllg="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.27","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":10180932},"main":"./dist/index.js","name":"@openai/codex-security","type":"module","_from":"file:dist/openai-codex-security-0.1.27.tgz","types":"./dist/index.d.ts","author":{"name":"OpenAI"},"engines":{"node":"^22.13.0 || ^24.0.0 || ^26.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"},"./server":{"types":"./dist/server/api.d.ts","import":"./dist/server/api.js","default":"./dist/server/api.js"}},"gitHead":"c40d059935592adc1ae04119eb7ad5286d9de554","license":"Apache-2.0","scripts":{"lint":"tsc --noEmit","test":"node --run build:plugin && bun test --timeout 30000 ./tests-ts","build":"node --run clean && tsc -p tsconfig.build.json && node scripts/build-dashboard.mjs","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && pnpm --dir ../../plugins/codex-security/mcp-app run typecheck && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,mts,tsx,json,md}\" \"../../.github/scripts/*.mts\" \"../../examples/custom-validation/*.{mts,md}\" \"../../plugins/codex-security/native/*.{mts,md}\"","test:ci":"node -e \"require('node:fs').mkdirSync('reports',{recursive:true})\" && pnpm run test --coverage --coverage-reporter=text --coverage-reporter=lcov --reporter=junit --reporter-outfile=reports/junit.xml","build:ci":"tsc -p tsconfig.ci.json","test:mcp":"node --run build:plugin && pnpm --dir ../../plugins/codex-security/mcp-app run test:mcp","audit:prod":"pnpm audit --prod --audit-level high","build:plugin":"node scripts/build-plugin.mjs","start:server":"node dist/server/index.js","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","test:mutation":"stryker run","build:examples":"tsc -p tsconfig.examples.json","generate:models":"node scripts/generate-models.cjs","check:plugin-source":"node scripts/check-plugin-source.mjs","generate:models:check":"node scripts/generate-models.cjs --check"},"version":"0.1.27","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"homepage":"https://developers.openai.com/codex/security","_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.27.tgz","_integrity":"sha512-PMeI03NA05rKDST630ijZp/9b3OI4o/p8s24Za5cGeGbMa3sTvBOS/nHDDqIgvvqmVPE09hVJTfCPkZrPIdy4g==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"TypeScript SDK and CLI for Codex Security","directories":{},"maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"wadih-openai","email":"wadih@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"_nodeVersion":"24.15.0","dependencies":{"ajv":"8.20.0","ink":"6.8.0","incur":"0.4.13","react":"19.2.4","fflate":"0.8.3","semver":"7.8.5","fast-uri":"3.1.6","papaparse":"5.5.3","smol-toml":"1.7.1","pdfjs-dist":"6.2.108","@linear/sdk":"89.0.0","extract-zip":"2.0.1","js-tiktoken":"1.0.21","@octokit/core":"7.0.6","@openai/codex":"0.149.1","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.149.1"},"publishConfig":{"access":"public","executableFiles":["_bundled_plugin/scripts/launch_codex_security_mcp"]},"_hasShrinkwrap":false,"devDependencies":{"saxes":"6.0.0","esbuild":"0.28.2","postcss":"8.5.23","prettier":"3.2.5","minimatch":"10.2.6","react-dom":"19.2.4","@types/bun":"1.3.13","fast-check":"4.9.0","typescript":"5.7.3","@types/node":"22.19.17","tailwindcss":"4.3.3","@types/react":"19.2.14","@types/semver":"7.8.0","@types/papaparse":"5.3.15","@types/react-dom":"19.2.3","@openai/apps-sdk-ui":"0.2.2","ink-testing-library":"4.0.0","@tailwindcss/postcss":"4.3.3","@stryker-mutator/core":"9.6.1","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/codex-security_0.1.27_1789087455627_0.9964034439635312"}}},"time":{"created":"2026-07-28T17:09:48.017Z","modified":"2026-09-11T00:44:16.257Z","0.1.0":"2026-07-28T17:09:48.381Z","0.1.1":"2026-07-28T23:48:23.585Z","0.1.2":"2026-07-29T18:51:07.650Z","0.1.3":"2026-07-29T20:47:52.768Z","0.1.4":"2026-07-30T00:35:17.130Z","0.1.5":"2026-07-31T16:08:06.229Z","0.1.6":"2026-08-05T08:00:03.813Z","0.1.7":"2026-08-06T05:22:51.196Z","0.1.8":"2026-08-07T21:59:44.027Z","0.1.9":"2026-08-11T00:02:35.774Z","0.1.10":"2026-08-12T02:16:11.004Z","0.1.11":"2026-08-13T18:44:06.276Z","0.1.12":"2026-08-15T05:15:43.827Z","0.1.13":"2026-08-16T03:43:04.117Z","0.1.14":"2026-08-16T05:55:30.840Z","0.1.15":"2026-08-19T18:52:55.533Z","0.1.16":"2026-08-20T05:11:59.552Z","0.1.17":"2026-08-23T02:58:33.093Z","0.1.18":"2026-08-23T22:46:42.933Z","0.1.19":"2026-08-25T00:44:40.162Z","0.1.20":"2026-08-25T06:25:09.501Z","0.1.21":"2026-08-27T07:53:14.598Z","0.1.23":"2026-08-28T13:50:45.968Z","0.1.24":"2026-08-29T16:42:54.898Z","0.1.25":"2026-09-02T00:14:00.248Z","0.1.26":"2026-09-08T19:45:27.785Z","0.1.27":"2026-09-11T00:44:15.828Z"},"bugs":{"url":"https://github.com/openai/codex-security/issues"},"author":{"name":"OpenAI"},"license":"Apache-2.0","homepage":"https://developers.openai.com/codex/security","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"description":"TypeScript SDK and CLI for Codex Security","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"wadih-openai","email":"wadih@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"readme":"# `@openai/codex-security`\n\nRun Codex Security scans from TypeScript or the command line. This ESM-only\npackage includes TypeScript declarations and the Codex runtime.\n\nBefore version `1.0.0`, minor releases may change the public API.\n\n## Install\n\n```bash\nnpm install @openai/codex-security\nnpx @openai/codex-security --version\n```\n\nUse Node.js 22.13.0+ (22.x), 24.x, or 26.x on macOS, Linux, or Windows.\nPolicy drafting, scans, exports, scan history, and saved findings also need Python 3.10+\n(plus `tomli` on Python 3.10).\n\n## Run a scan from TypeScript\n\nSign in with `npx @openai/codex-security login` or set `OPENAI_API_KEY` or\n`CODEX_API_KEY`, then scan a repository you own or have permission to assess:\n\n```ts\nimport { CodexSecurity } from \"@openai/codex-security\";\n\nconst security = new CodexSecurity();\n\ntry {\n  const result = await security.run(\"/path/to/repository\", {\n    outputDir: \"/path/outside/repository/results\",\n  });\n\n  console.log(result.reportPath);\n  console.log(result.findings.findings.length);\n} finally {\n  await security.close();\n}\n```\n\n`result.findings` contains this scan's findings; `repositoryFindings` also\nincludes earlier open findings when available. Matching earlier findings can\nmake extra model calls; see [Progress and cost](#progress-and-cost).\n\nKeep results outside the repository and restrict access: reports can contain\nsource code, vulnerability details, and reproduction steps.\n\n### Validate an existing finding\n\n```ts\nconst security = new CodexSecurity();\ntry {\n  const result = await security.validate({\n    repositoryPath: \"/path/to/repository\",\n    finding: {\n      title: \"Possible SQL injection\",\n      location: \"src/query.ts:42\",\n    },\n    outputDir: \"/path/outside/repository/validation\",\n  });\n  console.log(result.disposition);\n  console.log(result.report);\n} finally {\n  await security.close();\n}\n```\n\nPass literal text or a JSON-serializable object as `finding`, not a file path.\nValidation uses the client's settings and credentials without changing\nrepository files or adding a scan to history.\n\nTo disable Codex usage analytics and built-in metrics, create the client with\n`new CodexSecurity({ codexOverrides: { analytics: { enabled: false } } })`.\nThis setting also applies to scans run by the same client.\n\nResults include `disposition` (`reportable`, `suppressed`, `not_applicable`,\nor `deferred`), a Markdown `report`, `threadId`, and evidence `outputDir`.\n`reportable` may rely on static analysis; `deferred` means insufficient evidence.\nFailed, incomplete, or malformed responses reject the promise.\n\n`outputDir` must be empty and outside the Git worktree; it defaults to\n`validations/` under the state directory. Pass `auth` to select credentials\nor `signal` to cancel.\n\n### Import GitHub code scanning alerts\n\nImport alerts, including third-party SARIF uploads, and validate them against\nthe matching local checkout:\n\n```ts\nimport {\n  CodexSecurity,\n  importGitHubCodeScanningAlerts,\n} from \"@openai/codex-security\";\n\nconst findings = await importGitHubCodeScanningAlerts({\n  repository: \"example/repository\",\n  alertNumbers: [12, 18], // Omit to list all open alerts on the default branch.\n  githubToken: process.env[\"GH_TOKEN\"],\n});\n\nconst security = new CodexSecurity();\ntry {\n  for (const finding of findings) {\n    const result = await security.validate({\n      repositoryPath: \"/path/to/repository\",\n      finding,\n    });\n    console.log(finding.url, result.disposition, result.outputDir);\n  }\n} finally {\n  await security.close();\n}\n```\n\nEach result contains `source`, `repository`, `number`, `url`, and the full\nupstream `alert`. Import is read-only and does not start Codex or check out code.\n\nWithout `alertNumbers`, `state` filters alerts and defaults to `\"open\"`.\nIt also accepts `\"closed\"`, `\"dismissed\"`, `\"fixed\"`, and `\"all\"`. Exact alert\nnumbers ignore state and reject a nondefault `state`. Use `ref` for another\nbranch or pull-request reference.\n\nSupply `githubToken` or use your `gh auth token` credentials, including GitHub\nCLI token environment variables. `githubHost` defaults to `GH_HOST` or\n`github.com`. The token needs read access to code scanning alerts; access\nfailures reject the import. Pass `signal` to cancel.\n\n### SDK configuration and scan options\n\nConstructor options:\n\n| Option           | Description                                                             |\n| ---------------- | ----------------------------------------------------------------------- |\n| `pluginPath`     | Plugin directory or ZIP; defaults to the bundled plugin.                |\n| `pythonPath`     | Python interpreter; overrides `PYTHON`.                                 |\n| `codexOverrides` | Supported settings to deep-merge into the isolated Codex configuration. |\n\nOptions for `security.run(repository, options)` and\n`security.preflight(repository, options)`:\n\n| Option                  | Description                                                                    |\n| ----------------------- | ------------------------------------------------------------------------------ |\n| `auth`                  | Credential source: `\"auto\"`, `\"chatgpt\"`, or `\"api-key\"`.                      |\n| `safetyIdentifier`      | Stable hashed end-user ID for model requests; requires API-key authentication. |\n| `target`                | Repository, repository-relative paths, committed diff, or working-tree diff.   |\n| `mode`                  | `\"standard\"` or `\"deep\"`; deep mode supports repositories and paths.           |\n| `knowledgeBasePaths`    | Architecture documents, security policies, threat models, or directories.      |\n| `outputDir`             | Artifact directory outside the enclosing Git worktree.                         |\n| `archiveExisting`       | Archive existing results in `outputDir` before scanning.                       |\n| `maxCostUsd`            | Stop when estimated model cost exceeds this positive USD amount.               |\n| `maxTimeHours`          | Deep-scan discovery limit in hours: greater than zero, up to 96.               |\n| `failureSeverity`       | Finding-severity policy to record in the saved scan recipe.                    |\n| `parentScanId`          | Parent scan ID for a rerun.                                                    |\n| `expectedPluginVersion` | Required original plugin version when replaying a scan.                        |\n| `signal`                | `AbortSignal` to cancel a scan.                                                |\n\nFollow scans with `onWorkerStatus` and `onReconnect`. `onSessionEvent` receives\nsaved events with thread IDs and worker numbers. Deep scans can additionally use\n`onDeepProgress` for durable independent-review counts: `completed`, `active`,\nand `maximum`. The maximum is a configured cap, not a percentage denominator.\n`ScanOptions` lists all callbacks.\n\n`preflight` and CLI `--dry-run` check local inputs without starting Codex or\nusing the network. They don't authenticate, verify model access, resolve Python,\ninspect the plugin, or run scan-lifecycle callbacks. Dry runs print effective settings.\n\n## Authentication\n\nSign in with ChatGPT:\n\n```bash\nnpx @openai/codex-security login\nnpx @openai/codex-security scan .\n```\n\nUse device authentication on remote or headless machines:\n\n```bash\nnpx @openai/codex-security login --device-auth\n```\n\nFor CI, set `OPENAI_API_KEY` or `CODEX_API_KEY`. To save a key, pass it on stdin:\n\n```bash\nprintenv OPENAI_API_KEY | npx @openai/codex-security login --with-api-key\n```\n\nEnvironment API keys apply to the current command; only `login --with-api-key`\nsaves them. Pass Codex access tokens on stdin to `login --with-access-token`.\nAccess-token environment variables are not scan API keys.\n\nSDK callers can select native command authentication through\n`codexOverrides.model_providers.<id>.auth` and `model_provider` (including a\nselected `profile`). Scans, comparisons, and deduplication reviews preserve\nthat selection without requiring an API key or replacing it with a stored\nlogin. Codex executes the helper and renews its token. Helper paths and relative\n`auth.cwd` values resolve from the supplied `CODEX_HOME` (default `~/.codex`),\nnot the source checkout; an absolute `auth.cwd` is preserved. Comparisons and\nreviews also honor the selected command provider in that home's `config.toml`.\nConfiguration is passed to Codex for validation, including profile support.\n\nFor other inference providers:\n\n```bash\nexport OPENROUTER_API_KEY=\"<your-openrouter-api-key>\"\nnpx @openai/codex-security scan . --provider openrouter --model anthropic/claude-sonnet-4.5\n\nexport FIREWORKS_API_KEY=\"<your-fireworks-api-key>\"\nnpx @openai/codex-security scan . --provider fireworks --model accounts/fireworks/models/qwen3-235b-a22b\n\nexport AWS_BEARER_TOKEN_BEDROCK=\"<your-bedrock-api-key>\"\nexport AWS_REGION=\"us-east-2\"\nnpx @openai/codex-security scan . --provider amazon-bedrock --model openai.gpt-5.6-luna\n```\n\nBedrock also accepts AWS access keys, profiles, web identity, container\ncredentials, and the default AWS credential chain. Set `AWS_REGION` and choose\na Bedrock model with `--model`; OpenAI models such as `openai.gpt-5.6-luna`\nsupport `--max-cost`.\n\nBedrock scans, including Deep Scan workers, default to\n`model_reasoning_summary = \"none\"` because some Bedrock models reject\n`reasoning.summary`. This leaves reasoning effort unchanged. Explicit summary\nsettings in `--codex` overrides or the selected Codex profile take precedence.\nFor standard scans on older CLI versions, append\n`--codex 'model_reasoning_summary=\"none\"'` to your scan command if Bedrock\nreports that `reasoning.summary` is unsupported. Deep scans require a CLI\nversion that forwards this setting to workers.\n\nOn Windows, set the API key in PowerShell:\n\n```powershell\n$env:OPENAI_API_KEY = \"<your-api-key>\"\nnpx @openai/codex-security scan C:\\code\\repository\n```\n\nLogin, logout, scans, validation, patching, and fix verification share a private\ncredential home for stored OpenAI credentials, including custom providers with\n`requires_openai_auth = true`:\n`$CODEX_SECURITY_STATE_DIR/codex-home`, or\n`$CODEX_HOME/state/plugins/codex-security/codex-home`. Keep this credential\nhome outside the target directory and every enclosing Git worktree, including\nwhen running a command from a subdirectory. Codex carries\n`cli_auth_credentials_store`, `forced_login_method`, and\n`forced_chatgpt_workspace_id` from the ambient configuration into this home,\nincluding removing settings that are no longer present in the ambient configuration.\nEach command carries its selected provider into this home. Patching and fix\nverification also synchronize the ambient home's project-trust decisions and\nproject-root markers, preserving which project configuration Codex loads.\nThey hold the credential-home lock until the app-server thread is ready,\nthen release it before model execution.\nManaged-device policies still apply. If this home has no credentials, it imports\nan existing file-based Codex sign-in. Logout disables\nimports until you log in again.\n\nFinish operations using older versions before upgrading. Runtime preparation\nholds the credential-home lock through pauses; exit or crash releases it.\nCompatibility heartbeats protect active locks from older heartbeat-only\nclients, but those clients can replace a paused client's lock.\n\nKeep `.codex-security-scan.sqlite3` between operations; never remove it during\nan operation. PID reuse can make old PID-only locks appear active and block\nrecovery. Stop all operations using this home before removing an old\n`.codex-security-scan.lock` directory manually.\n\nIf ChatGPT credentials cannot be refreshed, run `login status`. Retry if the\nsign-in recently changed; otherwise run `logout`, then `login`.\n\nInteractive scans ask whether to use ChatGPT or an environment API key when\nboth are available. The choice applies to that scan. Noninteractive scans,\nincluding CI, JSON output, and dry runs, prefer the API key. Choose with `--auth`:\n\n```bash\nnpx @openai/codex-security scan . --auth chatgpt\nnpx @openai/codex-security scan . --auth api-key\n```\n\n`--auth` also works with `validate`, `patch`, and `verify-fix`. These commands\nuse the same stored login as `scan`, including a sign-in created with\n`codex-security login --device-auth`:\n\n```bash\nnpx @openai/codex-security patch OCCURRENCE_ID --auth chatgpt\nnpx @openai/codex-security verify-fix OCCURRENCE_ID --auth api-key\n```\n\n`--auth chatgpt` ignores environment API keys. `--auth api-key` requires\n`OPENAI_API_KEY` or `CODEX_API_KEY`. The default is `--auth auto`; noninteractive\ncommands prefer `OPENAI_API_KEY`, then `CODEX_API_KEY`, then stored credentials.\nPatch follow-up assessment uses the same selection, and `scan --patch` keeps\nthe scan's choice. Environment API keys do not replace the saved login.\nThe SDK uses the same `auth` option on `run`, `validate`, and `preflight`.\nCodex may still need ChatGPT credentials to load workspace-managed policies\nwhen using an API key.\n\nSome cybersecurity requests and protected findings require Trusted Access for\nCyber approval. Apply or check your access at\n[chatgpt.com/cyber](https://chatgpt.com/cyber).\n\n## Generate a security policy\n\n`policy` drafts `SECURITY.md` guidance for future scans. It does not run a\nvulnerability scan, change application settings, or install the draft in the\ncheckout. It uses the scan runtime and authentication, requesting read-only\naccess to the selected repository or component and required tools. Network access,\nweb search, apps, and MCP servers are disabled. Drafts stay outside the checkout.\nThe host resolves inherited guidance once and includes each checked descendant\npolicy separately. Descendant policy links must stay within the selected component.\nInherited and reporting-policy links may also resolve to ancestor `SECURITY.md`\nfiles or the checkout's `.github/SECURITY.md` and `docs/SECURITY.md`.\nThe model cannot read sibling components or Git metadata. Policy turns deny\naccess to the resolved Git metadata and markers, including those inside the\nselected source tree, nested bare repositories, and associated alternate object\nstores.\nPolicy shell tools inherit only Codex's core environment; custom shell environment\nsettings, login shells, and shell snapshots are disabled for these turns.\nKnowledge-base text stays with the private review artifacts during generation\nand is removed afterward.\n\nKnown limitation: policy preflight and generation currently fail on Unix\ndirectories with non-UTF-8 names.\n\nOn macOS, the pinned Codex runtime does not fully enforce write restrictions\nunder `/tmp` (including `/private/tmp`). Keep the repository and artifacts outside\nthat tree when read-only enforcement is required. See the\n[upstream sandbox limitation](https://github.com/openai/codex/issues/32395).\n\n```bash\nnpx @openai/codex-security policy .\nnpx @openai/codex-security policy . --path services/api\nnpx @openai/codex-security policy . --knowledge-base architecture.md --model gpt-5.6-terra --effort high\nnpx @openai/codex-security policy . --dry-run --json\n```\n\nThe repository defaults to the current directory. `--path` selects a component,\nwhich inherits policies from its Git root, with the closest policy taking\nprecedence. Linked worktrees and initialized submodules use their own roots.\nTargets and policy links must stay in the selected checkout, outside Git\nmetadata; ancestor links cannot widen a component policy's scope.\n\nFor an intentional separate Git directory, set `core.worktree` to the checkout's\nabsolute path. Use `git worktree repair` for moved linked worktrees.\n\nGeneration uses three Codex stages: describe the system, build a threat model,\nthen draft the policy. The first two documents support review; they are not\nadditional approval steps or policies to install.\nIn a terminal, it asks about facts the source cannot establish and shows the\nexact diff. If both ChatGPT and API-key credentials are available, it asks which\nto use; `--auth chatgpt` or `--auth api-key` selects one explicitly.\n\n| Invocation                   | Calls Codex? | Result                                                                  |\n| ---------------------------- | ------------ | ----------------------------------------------------------------------- |\n| `policy .`                   | Yes          | Ask owner questions, save documents, and preview the draft.             |\n| `policy . --headless --json` | Yes          | Save documents without prompts and return their paths and review notes. |\n| `policy . --format md`       | Yes          | Generate a draft and write its Markdown to stdout.                      |\n| `policy . --dry-run --json`  | No           | Check local inputs and show the resolved target and settings.           |\n\nNone of these commands installs `SECURITY.md` in the repository. Output formats\nchange presentation; they do not turn generation into a saved-draft read.\n\n### Review the draft\n\nReview the saved `SECURITY.md` before copying it to the reported target. Check\nlinks from `.github/SECURITY.md` or `docs/SECURITY.md`: copying can change their\nguidance too. Preserve reporting instructions and obtain owner approval for\nexclusions, accepted risks, and severity decisions. Later scans read this policy.\n\nGeneration and preview check for changes to the selected or inherited policies.\nIf governing guidance changes during generation, completed documents remain for\ninspection, but no completed-draft manifest is written. Other source files are not\nfrozen; regenerate if relevant source or neighboring policies change.\nA failed terminal preview reports a warning and the saved draft paths. Explicit\noutput formats return the draft directly without running a diff preview.\n\nUse `--headless` or an explicit output format to skip questions. Unanswered\nquestions remain in the review notes. Drafts default to the Codex Security state\ndirectory; `--output-dir` selects an empty directory outside every enclosing\nGit checkout and its Git metadata.\n\n```bash\nnpx @openai/codex-security policy . --path services/api \\\n  --headless --output-dir /path/outside/repository/api-policy --json\n```\n\nThe artifact directory contains:\n\n| File                   | Purpose                                                   |\n| ---------------------- | --------------------------------------------------------- |\n| `SECURITY.md`          | Editable policy draft.                                    |\n| `THREAT_MODEL.md`      | Detailed threat model with source references.             |\n| `project-spec.md`      | System description and security boundaries.               |\n| `previous-SECURITY.md` | Original policy used for the diff.                        |\n| `policy-draft.json`    | Target, policy hashes, revision, model, and review notes. |\n\nKeep supporting documents private until reviewed for disclosure. A generated\nthreat scenario is neither owner approval nor a confirmed vulnerability.\n\n`--format md` writes the draft to stdout. `--json` returns paths, review notes,\nstatus, and estimated cost. Global filters and token options work with these\nformats. Progress goes to stderr. `--full-output` reports failures with\n`ok: false`. `--max-cost` applies to the whole generation. If a stage cannot\ninspect required source evidence, generation stops and preserves completed\ndocuments. Fix the reported problem and use a new output directory to retry.\n\n### Generate a policy from TypeScript\n\n```ts\nimport { CodexSecurity } from \"@openai/codex-security\";\n\nconst security = new CodexSecurity();\ntry {\n  const draft = await security.generatePolicy(\"/path/to/repository\", {\n    path: \"services/api\",\n    knowledgeBasePaths: [\"/path/to/architecture.md\"],\n    onStage: (stage) => console.error(stage),\n  });\n\n  console.log(await security.previewPolicy(draft));\n  // Open draft.draftPath in an editor to review the saved policy.\n} finally {\n  await security.close();\n}\n```\n\n`preflightPolicy()` checks local inputs without starting Codex.\n`previewPolicy()` previews the supplied in-memory draft, uses the client's Python\nsetting, and makes terminal control characters visible. Editing the saved file\ndoes not change that object. The standalone `securityPolicyDiff()` returns a raw diff\nfor files or other non-terminal uses; pass an interpreter explicitly if needed.\n`generatePolicy()` accepts `auth`, `path`, `knowledgeBasePaths`, `outputDir`,\n`maxCostUsd`, `signal`, and progress and cost callbacks. An optional\n`answerQuestions` callback receives each group of up to three owner questions\nand a cancellation signal. Without it, the questions remain unresolved.\n\n## CLI\n\n```bash\nnpx @openai/codex-security policy . --path services/api\nnpx @openai/codex-security scan .\nnpx @openai/codex-security scan /path/to/repository --path src --path tests\nnpx @openai/codex-security scan /path/to/repository --diff origin/main --json\nnpx @openai/codex-security scan /path/to/repository --output-dir /path/outside/repository/results\nnpx @openai/codex-security scan /path/to/repository --dry-run\n```\n\nUse `scan --help` for options, `--version` for the installed version, and\n`info --json` for package, plugin, runtime, and model details. `--dry-run`\nruns local preflight checks.\n\n### Scan options and output\n\n`--path` scopes a scan to one or more paths, `--diff` scans committed changes,\nand `--working-tree` scans staged and unstaged changes. Deep scans support\nrepository and path targets.\n\nWorking-tree snapshots include files from untracked nested Git repositories.\nInitialized submodules must be clean and checked out at the commit recorded by\nthe parent repository.\n\nRepeat `--knowledge-base PATH` for Markdown, text, PDF, or Word (`.docx`) files.\nDirectories are searched recursively. Bulk scans share these documents with\nevery repository.\n\nUse an empty output directory outside the scanned directory and enclosing Git\nworktree. On macOS/Linux, existing directories must be private to you\n(`chmod 700`). `--archive-existing` moves previous results to\n`<output-dir>.previous-<timestamp>-<id>`; add `--dry-run` to preview the move.\nSARIF output, when produced, is at `<scan-dir>/exports/results.sarif`.\n\nScans are report-only by default. Set `--fail-on-severity high` to exit with\n`1` if a completed scan finds high or critical issues. Incomplete scans exit\nwith `2`, writing available results to stdout and a coverage warning to stderr.\n\n### Import findings as a saved scan\n\nImport an existing findings CSV or JSON file into local scan history and SQLite:\n\n```bash\ncodex-security scan import --csv /path/to/findings.csv\ncodex-security scan import --json /path/to/findings.json --format json\ncodex-security scan import --csv /path/to/findings.csv --dry-run\n```\n\nSupply exactly one of `--csv PATH` or `--json PATH`. CSV uses the existing\n[findings CSV template](https://github.com/openai/codex-security/blob/main/examples/findings.csv),\nincluding the optional `candidate_id` column. JSON accepts a complete\n`codex-security.findings` document or `{ \"findings\": [...] }`, with each finding\nmatching the existing findings schema. On `scan import`, `--json` selects the\ninput file; use `--format json` for JSON output. Other commands retain their\nexisting `--json` output flag. The selected input must be a regular file, and its\npath must not traverse symbolic links or directory junctions. Use the direct\nfilesystem path when the file or a parent directory is linked.\n\nEach import creates one completed scan using the configured\n`CODEX_SECURITY_STATE_DIR`. The target is a retained copy of the input dataset,\nindependent of the current repository. Every source occurrence remains a separate\nfinding, including duplicate reports. Original identifiers are preserved in\n`extensions.import`; the original file is sealed under `artifacts/import/`.\nJSON writeup paths are retained as source metadata without reading external files.\n\nCompletion means the import finished. Coverage is unknown and the report states\nthat no security analysis was performed. Importing requires no model calls or\nauthentication. `--dry-run` validates without saving a scan. `--output-dir` and\n`--archive-existing` control saved output, and `scans rerun SCAN_ID` reimports the\nretained input.\n\n### Generate mock scan results\n\nUse `--mock` to populate a Standard scan with synthetic test data in seconds,\nwithout Codex authentication or any LLM calls:\n\n```bash\ncodex-security scan /path/to/repository --mock\ncodex-security scan /path/to/repository --mock --output-dir /path/outside/repository/mock-results\n```\n\nThe SDK equivalent is `await security.run(repository, { mock: true })`.\nMock mode is off by default. It uses normal target validation, scan registration,\nartifact finalization, reports, and local scan/finding history. Output directories,\narchiving, JSON output, exports, and `--fail-on-severity` work as usual.\n`--dry-run` only validates inputs; `--mock` saves a completed scan.\n\nEach run contains 12 findings across all severity levels: eight stable findings\nrecur on subsequent scans of the same repository, and four have new identities\non every run. Two pairs describe the same root causes with different titles and\nidentities, providing inputs for deduplication testing. Mock scans skip automatic\nLLM matching; existing identity-based history indexing still runs. Separate\ncomparison or deduplication commands retain their usual model behavior.\n\nTitles, provenance, artifact metadata, and reports identify the results as\nsynthetic. Paths and code snippets are fictional and are never written into the\nrepository. Completion means fixture generation finished, not that the repository\nwas audited. Results enter the selected local state just like other scans; set\n`CODEX_SECURITY_STATE_DIR` to a separate directory when creating disposable data.\nToken usage is zero. `scans rerun` preserves mock mode.\n\nMock mode supports repository, path, and diff targets in Standard mode. It cannot\nbe combined with `--dry-run`, `--patch`, Deep mode, custom validation, or post-scan\nprompts. Scan prompts and knowledge-base inputs do not change the fixtures, and\nmock scans do not offer interactive patching.\n\n### Attribute scans to end users\n\nWhen scanning on behalf of users, pass each user's stable hashed ID:\n\n```ts\nawait security.run(\"/path/to/repository\", {\n  auth: \"api-key\",\n  safetyIdentifier: hashedUserId,\n});\n```\n\n```bash\ncodex-security scan /path/to/repository --auth api-key --safety-identifier hashed-user-id\n```\n\nUse a nonblank ID of 1 to 64 characters without NUL or personal data such as\nemail addresses. It applies to the scan, workers, retries, and follow-up work\nwithout changing shared configuration. Supply it again for reruns.\n\nThe runtime needs native `--safety-identifier` support, and the plugin must\nforward it to workers. The bundled runtime doesn't support it yet; choose a\ncompatible build with `CODEX_CLI_PATH`. The SDK checks the ID's format, not\nruntime or plugin compatibility. Older versions may omit the ID.\n\n### Scan project components\n\n`scan --path` runs one scan across selected paths. To scan each local project\ncomponent separately in standard mode, use `scan-components`:\n\n```bash\nnpx @openai/codex-security scan-components /path/to/project \\\n  --component apps/api --component apps/web --component packages/shared \\\n  --workers 4 --output-dir /path/outside/project/results\n```\n\nUse `--auto` instead of `--component` for a proposed split. Save a plan to\nreview or edit, then run it with a new output directory:\n\n```bash\nnpx @openai/codex-security scan-components /path/to/project \\\n  --auto --plan-only --output-dir /path/outside/project/plan\nnpx @openai/codex-security scan-components /path/to/project \\\n  --components-file /path/outside/project/plan/components.json \\\n  --output-dir /path/outside/project/results\n```\n\nFor large repositories, automatic planning splits inventories into separate calls\nthat fit Codex's input character limit. It preserves directory boundaries where\npossible and subdivides oversized packages and flat directories as needed. Each\ncall uses a fresh context and can select only paths within its batch. Omitted\nfiles are retained in `Other files` components within those same boundaries.\nLarge repositories can therefore require more planning calls and produce more\ncomponents. Review or edit the saved plan before scanning with `--components-file`.\n\nComponents use repository-relative paths:\n\n```json\n{\n  \"components\": [\n    { \"name\": \"API\", \"paths\": [\"apps/api\", \"packages/auth\"] },\n    { \"name\": \"Web\", \"paths\": [\"apps/web\"] }\n  ]\n}\n```\n\nAutomatic planning respects Git ignore rules and groups omitted files under\n`Other files`. Each proposed path must contain an inventoried file. Planning\nleaves source files unchanged.\n\nEach component saves artifacts under `component-N/`. Combined `findings.json`\nmerges high-confidence root-cause matches, keeping the highest severity and\noriginal IDs. Uncertain matches stay separate. `summary.json` records coverage\nand matching status; `report.md` links to component reports. Export and publish\nfrom the individual scan folders, not the combined summary.\n\nLarge comparisons use bounded batches that cover every earlier/later finding\npair. Overlapping confirmed groups are joined in code. Finding text is not\ntruncated; pairs above Codex's input limit leave matching incomplete.\n\nUse an empty output directory outside the project. Failed components don't\nstop others, but failures, incomplete coverage, or failed matching exit with\n`2`. Retry failed or incomplete components with\n`--components-file retry-components.json` and a new output directory.\nThe retry report covers only those components; it does not update the original\ncombined report.\n\n`--max-cost` applies per component, excluding planning and matching.\n`--model` and `--effort` also apply to matching; `--auth` applies throughout.\nPlanning and matching reject an ambient command provider that conflicts with\nexplicit `--auth chatgpt` or `--auth api-key`. A command provider explicitly\nselected through SDK `codexOverrides` retains its authentication configuration.\nUse `--knowledge-base`, `--scan-prompt-file`, and `--post-scan-prompt-file` as for\nbulk scans.\n\nFrom TypeScript, use `runComponentScans({ repository, outputDir, components })`.\nUse `auto: true` for planning, `planOnly: true` to save the plan without scans,\nand `scanOptions.auth` to select credentials.\n\n### Configure deep scans\n\nFor `scan --mode deep`, `--workers` sets discovery concurrency and `--subagents`\nsets subagents per worker. `--stop-after-no-new` stops after that many runs\nwithout new issues. `--max-discovery-runs` and `--max-time-hours` cap discovery\nruns and duration. SDK equivalents:\n\n```ts\nawait security.run(\"/path/to/repository\", {\n  mode: \"deep\",\n  workers: 2,\n  subagents: 0,\n  stopAfterNoNew: 3,\n  maxDiscoveryRuns: 10,\n  maxTimeHours: 1.5,\n});\n```\n\nSet defaults in `$CODEX_HOME/codex-security/config.toml`:\n\n```toml\n[deep_scan]\nworkers = 4\nsubagents = 3\nstop_after_no_new = 4\nstop_after_consecutive_errors = 3\nmax_discovery_runs = 40\nmax_time_hours = 96\n```\n\nCLI and SDK options override these defaults. Set `stop_after_consecutive_errors`\nin the file; `--codex` cannot configure this section. Worker and run counts must\nbe positive integers; `subagents` can be zero. Legacy `workers = \"auto\"` means\nfour workers. Unknown keys are rejected.\n\n`max_time_hours` accepts positive values up to 96, including fractional hours.\nAt the deadline, discovery stops; the scan combines and returns completed findings.\n\n`scan --workers` controls discovery workers within one deep scan;\n`bulk-scan --workers` controls how many repositories are scanned concurrently.\n\n### Runtime configuration and worker limits\n\nScans use these isolated Codex defaults instead of your user or repository\nconfiguration:\n\n```toml\napproval_policy = \"on-request\"\napprovals_reviewer = \"auto_review\"\ncli_auth_credentials_store = \"auto\"\nmodel = \"gpt-5.6-sol\"\nmodel_reasoning_effort = \"xhigh\"\nmodel_reasoning_summary = \"detailed\" # \"none\" for amazon-bedrock\nshow_raw_agent_reasoning = true\n\n[features]\nplugins = true\ngoals = true\n\n[features.multi_agent_v2]\nenabled = true\nmax_concurrent_threads_per_session = 9\n\n[windows]\nsandbox = \"unelevated\"\n```\n\nUse `--model` to choose a model and `--effort minimal|low|medium|high|xhigh|max`\nfor reasoning effort. Repeat `--codex KEY=VALUE` for other TOML settings:\n\n```bash\nnpx @openai/codex-security scan . \\\n  --model gpt-5.6-terra \\\n  --effort high \\\n  --codex features.multi_agent_v2.max_concurrent_threads_per_session=4\n```\n\nThe thread limit of `9` includes the parent and up to eight delegated workers.\nIt is separate from deep-scan and bulk-scan worker counts.\n\nQuote string values as TOML, for example\n`--codex 'model_reasoning_effort=\"high\"'`. Do not pass both `--model` and\n`--codex 'model=\"...\"'`, or both `--effort` and\n`--codex 'model_reasoning_effort=\"...\"'`: conflicting or repeated keys are\nrejected.\n\nChoose plugins with `--plugin-path`. Overrides of `plugins`, `marketplaces`,\nor `features.plugins` are rejected, including in profiles. Multi-agent v2 must\nstay enabled: `agents.max_threads` and\n`features.multi_agent_v2.enabled=false` are rejected.\n\n`validate`, `patch`, and `verify-fix` accept `--auth`, `--effort`, and the `model`,\n`model_reasoning_effort`, and `analytics.enabled` keys in `--codex`, but no\nother runtime overrides.\n\nUse `--codex 'analytics.enabled=false'` to disable Codex usage analytics and\nbuilt-in metrics for a command:\n\n```bash\nnpx @openai/codex-security validate \"Candidate finding\" --codex 'analytics.enabled=false'\nnpx @openai/codex-security patch \"Security issue\" --codex 'analytics.enabled=false'\nnpx @openai/codex-security verify-fix \"Security issue\" --codex 'analytics.enabled=false'\n```\n\nThe same setting works for `scan` and `bulk-scan`. An explicit setting is\npreserved when `scan --patch` starts remediation and when\n`patch --assess-patch-risk` starts its follow-up assessment. Boolean `true`\nis also accepted; omitting the setting preserves the command's existing\nconfiguration and Codex defaults. Validation ignores user configuration.\nFor stored OpenAI credentials, patching and verification read configuration\nfrom the shared credential home. API-key commands and custom providers that use their own credentials retain\ntheir ambient Codex configuration. Patching and verification preserve project trust from the\nambient home; explicit `--codex` settings apply to the command and its\npatch-risk assessment.\n\nThis setting does not control explicitly configured OpenTelemetry log or trace\nexporters, authentication, integrations, or CLI update checks.\n\nSee [Local security model](#local-security-model) for approval and filesystem\nrestrictions.\n\n### Environment variables\n\n| Variable                                                                    | Effect                                                                               |\n| --------------------------------------------------------------------------- | ------------------------------------------------------------------------------------ |\n| `OPENAI_API_KEY`, `CODEX_API_KEY`                                           | Scan credentials; `OPENAI_API_KEY` wins if both are set.                             |\n| `CODEX_SECURITY_EMBEDDINGS_URL`                                             | Findings service endpoint; see [Embeddings and storage](#embeddings-and-storage).    |\n| `CODEX_SECURITY_LINEAR_TEAM`, `CODEX_SECURITY_LINEAR_PROJECT`               | Default team and project for completed-scan publication.                             |\n| `CODEX_SECURITY_LINEAR_API_KEY`                                             | Personal API key for Linear patching and direct publication.                         |\n| `CODEX_SECURITY_LOG_LEVEL`                                                  | CLI-only; `debug` enables verbose diagnostics.                                       |\n| `LOG_LEVEL`                                                                 | CLI-only fallback when `CODEX_SECURITY_LOG_LEVEL` is unset.                          |\n| `CODEX_SECURITY_STATE_DIR`                                                  | Private scan-history, workbench, and default artifact directory.                     |\n| `CODEX_HOME`                                                                | Ambient Codex home for file-based sign-in and default state; defaults to `~/.codex`. |\n| `CODEX_CLI_PATH`                                                            | Codex executable for authentication, plugin setup, scans, and workers.               |\n| `PYTHON`                                                                    | Python interpreter when `--python` or SDK `pythonPath` is unset.                     |\n| `GH_HOST`                                                                   | GitHub Enterprise host for interactive `bulk-scan` discovery.                        |\n| `CODEX_SECURITY_NO_UPDATE_NOTICE`, `NO_UPDATE_NOTIFIER`                     | Either variable disables interactive update notices.                                 |\n| `CODEX_SECURITY_NPM_REGISTRY`, `npm_config_registry`, `NPM_CONFIG_REGISTRY` | Update-check registry, in precedence order.                                          |\n| `CI`                                                                        | Disables interactive update notices.                                                 |\n| `NO_COLOR`, `TERM`                                                          | Disables colored scan history when `NO_COLOR` is defined or `TERM=dumb`.             |\n\nCustom Codex executables need thread source attribution for `exec` and\n`app-server` (Codex 0.149.1+). On Windows, use a native `.exe` or `.com`;\ncommand shims such as `codex.cmd` fall back to the bundled executable.\n\nPython lookup order: `--python` (on `scan`, `bulk-scan`, or `export`) or SDK\n`pythonPath`, then `PYTHON`, the managed Codex runtime, and `python3` or `python`\non `PATH` (`py` also works on Windows). `CODEX_SECURITY_STATE_DIR` overrides\n`CODEX_HOME` for state storage. Keep state and results outside the repository.\n\n### Progress and cost\n\nInteractive scans show full-screen progress; CI, redirected output, and\n`--headless` use plain status lines. Results go to stdout, progress and\ndiagnostics to stderr. Add `--verbose` for diagnostics. Check logs for\nsensitive information before sharing them.\n\nThe token summary shows uncached input, cache reads, cache writes, output,\nand total tokens. Total tokens include all input plus output; cache reads and\nwrites are subsets of input, not extra tokens. When cache-write usage is missing,\nthe summary shows uncached input and cache writes as unavailable.\nThe final summary preserves missing-data information from a matching session log.\nIf the Codex runtime converts an omitted count to zero before recording it, the\nCLI cannot distinguish that zero from reported usage.\n\nJSON results, scan history, and bulk-scan receipts record the model, tokens,\nestimated cost, and `cost.pricing`: the price source, verification date, processing\ntier, context category, and rates in USD per million tokens. Estimates use\n[standard, short-context API prices](https://developers.openai.com/api/docs/pricing),\nincluding cache reads and writes. They exclude long-context and other processing\ntier adjustments, fees, and surcharges. GPT-5.5 and GPT-6 Astra are supported;\nmodels without known prices show an unavailable estimate.\n\nFor compatibility, `cacheWriteInputTokens` remains the reported token subtotal.\n`cacheWriteInputTokensReported: false` means at least one included usage record\ndid not report cache writes. Raw usage uses `cache_write_input_tokens_reported`.\nIn that case, the estimate prices unclassified input at the ordinary input rate;\nit may undercount cache-write charges. Older saved records lack this distinction\nand the saved pricing basis.\n\n`--max-cost USD` stops the scan and its workers when estimated cost exceeds\nthe limit, though in-flight requests can finish above it. If deep-scan\ndiscovery has finished, the scan returns a sealed partial report without more\nmodel calls and lists unvalidated candidates as follow-up work. Bulk scans\napply the limit per repository attempt.\n\nWith `--max-cost`, automatic finding-history matching makes at most one extra\nmodel call. If it needs more context, the completed scan is kept and a warning\ndirects you to run `scans match --all` explicitly.\n\nFor a single scan in the interactive dashboard, reaching 80% of the limit\noffers a higher **total** USD limit. Enter a larger amount to approve it, or\npress Enter with an empty input or Escape to keep the current limit. The scan\ncontinues running while you decide, and the existing limit remains enforced\nuntil the increase is saved. Increases keep the same scan and accumulated cost;\nthey do not restart work or extend time or discovery limits. CI, JSON/JSONL,\n`--headless`, and `--verbose` scans do not offer budget increases. If usage crosses the limit\nbefore an increase is approved, the scan still stops.\n\nSDK callers can supply `onBudgetApproaching({ maxCostUsd, cost, signal })` and\nreturn a higher total limit, or `undefined` to keep the current limit. The\ncallback runs once per limit at 80% usage without blocking tracking or\nexecution. Its signal aborts when the scan stops or finishes model work; late\nanswers are ignored. Invalid increases or failures to save them leave the\nexisting limit in place and report a warning. `onCost(cost, maxCostUsd)` reports\nthe current limit, including after an approved increase.\n\nThese amounts estimate API-equivalent model usage, not ChatGPT subscription\nallowance. Post-scan prompts run after scan cost tracking ends and are outside\nthis limit.\n\n### Bulk scans\n\nRun `gh auth login`, then `npx @openai/codex-security bulk-scan` to select\nGitHub repositories pushed in the last 90 days. Forks and archived repositories\nare excluded; private checkouts use your GitHub CLI sign-in. The command asks\nfor an output directory and saves your selection there as `repositories.csv`.\n`--output-dir` requires CSV input.\n\nFor CI or an existing repository list, pass a CSV with `id`, `repository`, and\n`revision` (full commit hash). Optional `scope`, `mode`, and `prompt` columns\ncustomize each scan:\n\n```csv\nid,repository,revision,scope,mode,prompt\nservice,https://github.com/acme/service.git,0123456789abcdef0123456789abcdef01234567,src,standard,Focus on authentication and authorization.\n```\n\n```bash\nnpx @openai/codex-security bulk-scan repositories.csv \\\n  --output-dir /path/outside/repositories/security-scans --workers 4\n```\n\n`--scan-prompt-file PATH` adds instructions to a scan or all bulk scans. Each\nrepository's CSV `prompt` follows the shared instructions.\n`--post-scan-prompt-file PATH` runs a follow-up in the same authenticated session,\neven after a failed or incomplete scan, but not after cancellation or a\ncost-limit stop.\n\n`--workers` defaults to `4`. `--max-attempts` defaults to `1` attempt per pending\nrepository per invocation. Rerunning the command continues the campaign, skips\ncompleted results, and starts new attempts for pending repositories. If an\nattempt directory is occupied, that repository stops before replacing its\ncheckout and the command recommends `--recover`.\n\n#### Recovering failed or interrupted bulk scans\n\nUse the original CSV, output directory, and campaign options with `--recover`:\n\n```bash\nnpx @openai/codex-security bulk-scan repositories.csv \\\n  --output-dir /path/outside/repositories/security-scans --recover\n```\n\nRecovery requires an existing campaign with a matching manifest. It skips\ncompleted results, including partial coverage, and repositories never started.\nFor each failed or interrupted repository, it checks the latest attempt:\n\n- A sealed scan is recorded in `results.jsonl` without scanning again.\n- An eligible running Deep Scan resumes its original session, keeping its scan\n  ID, completed workers, artifacts, saved settings, and accumulated cost.\n- A failed, canceled, or otherwise unavailable scan starts a new attempt at the\n  CSV's pinned revision. Attempt numbers account for both receipts and existing\n  directories. Old artifacts and checkouts are preserved; new attempts use\n  `recovery-checkouts/<id>/attempt-<n>`.\n\n`--workers` still defaults to `4`; `--max-attempts` defaults to one recovery or\nnew attempt per repository. A resume connection failure stops that repository\nfor this invocation instead of starting another scan. Other repositories\ncontinue. Failed and interrupted recovery checkouts remain available for a later\n`--recover`; fresh completed checkouts are removed after recording the result.\nIf a reboot interrupted a receipt write, its unfinished tail is saved beside\n`results.jsonl` as `results.jsonl.interrupted-<id>` before appending valid records.\n\nSame-scan resume requires the original checkout, session logs, and Codex Security\nstate directory. Recovery does not reconstruct deleted checkpoints or fix the\nunderlying cause of execution failures. New attempts incur new scan costs.\nAny remaining failures or partial coverage keep exit code `2`.\n`bulk-scan --help` lists all options.\n\n### Custom validation\n\nReplace the final validation step of a standard or diff scan with a prompt\nfile. Source review still runs; discovery workers do not receive this prompt.\n\n```bash\nnpx @openai/codex-security scan . --validation-prompt-file validation.md\n```\n\nThe SDK accepts the same text as `validationPrompt`:\n\n```ts\nconst result = await security.run(repository, {\n  validationPrompt:\n    \"Run scripts/validate.sh, test each candidate through the local API, and stop the test environment when finished.\",\n});\n```\n\nPut setup, allowed targets, required evidence, and cleanup in the prompt.\nThere are no separate setup or teardown hooks. Use environment variables for\ncredentials; keep secrets out of prompts and validation output. Deep scans\nreject this option; scans without candidates skip it.\n\nThe SDK supplies the candidate IDs and requires a `CustomValidationResult`:\n\n```json\n{\n  \"status\": \"complete\",\n  \"reason\": null,\n  \"validations\": [\n    {\n      \"candidateId\": \"candidate-1\",\n      \"validation\": {\n        \"disposition\": \"reportable\",\n        \"method\": \"integration test\",\n        \"confidence\": \"high\",\n        \"confidence_rationale\": \"The test reproduced the reported behavior.\",\n        \"rubric\": \"Check the protected operation.\",\n        \"evidence\": [\"The unauthorized request succeeded.\"],\n        \"counterevidence_or_proof_gap\": \"\",\n        \"remaining_uncertainty\": \"\",\n        \"artifact_paths\": []\n      },\n      \"severity\": null,\n      \"impact\": null\n    }\n  ]\n}\n```\n\nReturn one result per candidate with disposition `reportable`, `suppressed`,\n`not_applicable`, or `deferred`. Set `severity` or `impact` to\n`{ \"level\": \"medium\", \"rationale\": \"...\" }` to revise an assessment, or `null`\nto retain it. Identity and source locations stay unchanged.\n\nThe scan saves candidates and results, including suppressed and deferred\ncases, under `artifacts/custom-validation/`. Coverage is incomplete if setup\nfails, output is incomplete or invalid, or any candidate is deferred. An\nincompatible plugin stops the scan; validation never falls back to the default.\nRepeat `--validation-prompt-file` on reruns.\n\n### Publish findings to Cloud\n\nChoose completed scans from local history:\n\n```bash\nnpx @openai/codex-security publish scan --to cloud --dry-run --json\n```\n\nPress Space to select scans, then Enter to submit. Nothing is preselected.\n\nFor scripts, repeat `--scan` with saved IDs or unique prefixes of at least\neight characters:\n\n```bash\nnpx @openai/codex-security publish scan \\\n  --scan SCAN_ID_A --scan SCAN_ID_B \\\n  --to cloud --dry-run --json\n```\n\nFind IDs with `scans list --json`, or use `--scan latest` for the current\nrepository's latest completed scan. You still need the local sealed artifacts.\n\n`--dry-run` checks inputs and prints findings without logging in or uploading.\nUploads need ChatGPT credentials saved to a file. Set this in Codex\n`config.toml`, then sign in with ChatGPT again:\n\n```toml\ncli_auth_credentials_store = \"file\"\n```\n\nCloud publication rejects automatic and keyring storage, even if an\n`auth.json` file exists: the file may be stale or belong to another account.\n\nFor CSV input, use an export from `codex-security export --export-format csv`:\n\n```bash\nnpx @openai/codex-security publish scan --to cloud \\\n  --csv /path/outside/repository/findings.csv\n```\n\nThe [findings CSV template](https://github.com/openai/codex-security/blob/main/examples/findings.csv)\nhas the required columns; deep-scan exports may add `candidate_id`. `--csv`\nonly supports Cloud and cannot be combined with scan IDs or directories.\n\nFor artifacts outside local history, pass a directory or repeat `--scan-dir PATH`.\nEach directory must contain one completed, sealed scan. Bulk-run directories\nand `results.jsonl` files aren't accepted. Don't mix directories with `--scan`.\n\nMultiple scans return:\n\n- `results`: receipts or dry-run previews, each with its `scanId` and `scanDir`.\n- `failed`: errors with `scanDir` and, for saved selections, `scanId`.\n- `notAttempted`: saved scan IDs, or paths for directory inputs, that the command\n  did not reach before cancellation.\n\nOne scan returns its result directly. Uploads run sequentially. A failed upload\ndoesn't stop the rest, but the command exits with `2` if any failed. Cancellation\nstops new requests and returns results so far with `130` (Ctrl-C) or `143`\n(SIGTERM), unless all publications were already confirmed.\n\nSave the output: Cloud receipts aren't stored in scan history. They contain\nCloud finding IDs in request order, not local IDs. Uploads aren't retried\nautomatically. Cloud may have accepted an upload even if its receipt is missing\nor invalid. Check Cloud before retrying; never resend a scan with a confirmed\nreceipt.\n\n### Publish completed scans to Linear\n\nLinear publication accepts one completed scan:\n\n```bash\nnpx @openai/codex-security publish scan --scan SCAN_ID \\\n  --to linear \\\n  --linear-team TEAM_ID\n```\n\nChoose a scan by ID, unique prefix, `latest`, or directory (positional or\n`--scan-dir PATH`). Omit the selector for an interactive picker. Live publication\nand `--skip-existing` require the scan in local history; a directory-based\n`--dry-run` alone does not.\n\nAdd `--linear-project PROJECT_ID` (`--project` is an alias) to place issues in\na project. Destination flags override `CODEX_SECURITY_LINEAR_TEAM` and\n`CODEX_SECURITY_LINEAR_PROJECT`. `--dry-run` previews issue titles without\ncontacting Linear; `--json` returns structured results.\n\nSign in to Codex and connect Linear to publish with your existing Codex\nconfiguration; publication doesn't use the isolated scan home. To use the\nLinear API directly, set a personal API key:\n\n```bash\nexport CODEX_SECURITY_LINEAR_API_KEY=YOUR_LINEAR_PERSONAL_API_KEY\nnpx @openai/codex-security publish scan /path/to/completed-scan \\\n  --to linear \\\n  --linear-team TEAM_ID\n```\n\nDirect API publication leaves issues unassigned unless `--linear-assignee`\nspecifies a user ID or email. `--linear-api-key KEY` overrides the environment\nvariable, but exposes the key in shell history and process listings. Keys are\nomitted from saved results and artifacts; error messages are returned unchanged.\n\nCheck scan integrity and recorded publications before publishing:\n\n```bash\nnpx @openai/codex-security publish check /path/to/completed-scan \\\n  --to linear --linear-team TEAM_ID --json\n```\n\n`publish check` is read-only. With an API key it also checks authentication,\nteam, project, and assignee access; connected-app access is `not-checked`.\nIssue-creation permission is always `not-tested`.\n\nEach finding becomes an issue titled `[Codex Security][HIGH] Finding title`\nwith source locations, code, evidence, and remediation. Choose a destination\nauthorized to receive these details. Local history stores successful issue IDs\nseparately from sealed scan artifacts.\n\nRepublishing creates duplicates by default. `--skip-existing` skips recorded\nsuccesses for the same occurrence, team, and project, without checking remote\nissues. Results distinguish `created` and `skipped` issues. Add `--dry-run`\nto preview the remaining findings.\n\nAfter an interrupted or indeterminate publication, check the retained handoff,\nevidence, and Linear destination before retrying. Issues may exist without a\nlocal record. The CLI can't recover those issues, and `--skip-existing` can't\nprevent duplicates from them or concurrent publications.\n\n```ts\nimport { publishScan } from \"@openai/codex-security\";\n\nconst publication = await publishScan(\"/path/to/completed-scan\", {\n  destination: \"linear\",\n  teamId: \"TEAM_ID\",\n});\n\nconsole.log(publication.scanId);\nconsole.log(publication.created.length);\n```\n\nOptions include `projectId`, `skipExisting`, `linearApiKey` for direct API\npublication, and `assigneeId` (user ID or email). `checkScanPublication` accepts\nthe same destination options for a read-only check.\n\n### Classify finding severity\n\nClassify findings after a scan or dedupe without repeating discovery or changing\nthe original severity, evidence, or sealed scan artifacts:\n\n```bash\ncodex-security classify-severity --scan SCAN_ID --rubric /path/to/policy.md --json\ncodex-security classify-severity --scan latest --rubric /path/to/policy.md --json\ncodex-security classify-severity --scan-dir /path/to/completed-scan --json\n```\n\n`--scan` accepts a saved scan ID, unique prefix, or `latest` for the current\nrepository, matching `dedupe` and `publish scan`. `--scan-dir` accepts an external\ncompleted scan without requiring local history. Supply exactly one selector.\nOmitting `--rubric` inherits each finding's existing severity without a model call.\n\n`--rubric PATH` supplies the classification policy. Repeat `--knowledge-base PATH`\nto provide supporting architecture, deployment, or business context. Both accept\nthe same Markdown, text, PDF, DOCX, and directory inputs as scan knowledge bases.\nRubric classification uses the full supplied report and context in a separate\nread-only Codex turn per finding, without source inspection, tools, or new\nvalidation. `--model` and `--effort` select the classification model and reasoning\neffort; otherwise Codex's configured model and the helper's medium effort apply.\n\nThe result contains one assessment per selected finding:\n\n- `decision`: `assessed` or `excluded`; policy exclusions do not become Low.\n- `level`: `critical`, `high`, `medium`, `low`, or `informational`; null for exclusions.\n- `rubricLabel`: the policy's original label, such as `URGENT`, normalized to\n  `critical`; null for inherited severity or exclusions.\n- `rationale`, separate `confidence`, and `reviewTrigger` describing a missing\n  fact that would change the classification. Inherited severity has no new\n  classification-confidence judgment.\n- `findingId`, `occurrenceId`, and `inputSha256` binding the assessment to the\n  report. Top-level metadata includes `assessedAt`, `rubricSha256`, and\n  `knowledgeBaseSha256` for the supplied policy and context snapshots.\n\nScan classification saves each successful finding immediately in the local\nworkbench SQLite database. Rerunning skips assessments with matching finding\nevidence, rubric, and knowledge-base hashes, including exclusions, and returns\nboth reused and newly generated assessments. Changed inputs are classified again.\nUse `--reprocess` to rerun every selected finding regardless of its saved\nassessment; each row is replaced only after its new assessment succeeds. A failed\nor canceled run keeps completed checkpoints, so a normal retry resumes missing\nwork. Changing only the model or effort requires `--reprocess`.\n\nSQLite is authoritative. A successful run also exports the complete selected\nresult to `severity-classification.json` alongside the sealed artifacts. The file\nis replaced atomically and is not read for reuse or publication. The scan's\noriginal findings and severity are unchanged. The database stores the requested\nselection and policy/context hashes; publication rejects an incomplete selection\nor assessments whose inputs no longer match. Rubric documents are read at\nclassification time, not again at publication time.\n\n```bash\ncodex-security classify-severity --scan latest --rubric /path/to/policy.md --reprocess\n```\n\nUse repeatable `--finding-id ID` to classify a selected set, such as the\n`uniqueFindingIds` returned by dedupe. With a saved classification, Linear\npublication defaults to that selection, omits excluded records, and uses assessed\nseverity for issue priority and title. The description retains original scan\nseverity and adds classification reasoning. Without a saved classification,\npublication retains its existing severity mapping and selection behavior.\nPublication rejects assessments whose IDs or evidence hashes no longer match.\n\n```bash\ncodex-security classify-severity --scan SCAN_ID --rubric /path/to/policy.md \\\n  --finding-id FINDING_ID --json\ncodex-security publish scan --scan SCAN_ID --to linear --linear-team TEAM_ID \\\n  --dry-run --json\ncodex-security publish scan --scan SCAN_ID --to linear --linear-team TEAM_ID \\\n  --skip-existing --json\n```\n\n`publish scan --to linear` also accepts repeatable `--finding-id ID` to select a\nsubset directly. If a classification exists, every explicitly selected finding\nmust have an assessment. Classification does not change existing Linear tickets;\n`--skip-existing` preserves recorded tickets and any human priority edits. It\nretains the existing limitations around unrecorded or concurrent publications.\n\nThe SDK exposes the same operations:\n\n```ts\nimport {\n  classifySeverity,\n  classifyScanSeverity,\n  classifyScanDirectorySeverity,\n  publishScan,\n} from \"@openai/codex-security\";\n\n// Supplied reports from any source: returns an assessment without writing files.\nconst classification = await classifySeverity(findings, {\n  rubricPath: \"/path/to/policy.md\",\n  knowledgeBasePaths: [\"/path/to/context.md\"],\n});\n\n// Saved IDs (including prefixes/latest), or sealed directories; saves an assessment.\nawait classifyScanSeverity(\"SCAN_ID\", { rubricPath: \"/path/to/policy.md\" });\nawait classifyScanDirectorySeverity(scanDirectory, {\n  rubricPath: \"/path/to/policy.md\",\n  findingIds: dedupeResult.uniqueFindingIds,\n});\n\nawait publishScan(scanDirectory, {\n  destination: \"linear\",\n  teamId: \"TEAM_ID\",\n  skipExisting: true,\n});\n\n// Alternatively supply a classification directly, without a saved assessment.\nawait publishScan(scanDirectory, {\n  destination: \"linear\",\n  teamId: \"TEAM_ID\",\n  classification,\n  findingIds: classification.assessments.map(({ findingId }) => findingId),\n  dryRun: true,\n});\n```\n\n`classifySeverity` accepts reports with `findingId`, `title`, and `summary`, plus\ntheir available evidence and metadata. Original `severity` and `occurrenceId`\nmay be absent for imported reports; reports without severity require a rubric.\n`classifySeverity` remains an in-memory operation without database persistence.\nThe scan wrappers use the local state database (also for external scan\ndirectories), accept `reprocess: true`, and accept `findingIds: []` as an\nintentionally empty selection. Rows outside the selected set are retained.\nUse the same `CODEX_SECURITY_STATE_DIR` for classification and publication.\nJSON exports from versions without database checkpoints must be reclassified\nonce before they can be reused.\nPass `signal` to cancel any classification operation. Keep human overrides in the\ncalling workflow or issue tracker; assessments remain separate recommendations.\n\n### Feedback\n\nSend a problem report to OpenAI and share the returned feedback ID with support:\n\n```sh\ncodex-security feedback --reason \"The scan stopped before it finished\"\ncodex-security feedback SCAN_ID --reason \"The scan stopped before it finished\" --include-logs\n```\n\nWithout an ID, `feedback` selects the most recently started scan in the current\nrepository, including active or failed scans. If there are no saved scans, it sends\na general report. The report includes your description, version details, and the selected\nscan and session IDs. Add `--json` for structured output.\n\nLogs are off by default. `--include-logs` uploads Codex diagnostics and saved scan\nand worker activity. These can contain source code, prompts, findings, tool\noutput, and other sensitive data. Only include logs you can share with OpenAI.\nThe command uses Codex's feedback service and respects `feedback.enabled = false`.\n\n### Scan history and reruns\n\nCommands default to the current repository. Select scans by full ID or a\nunique prefix of at least eight characters.\n\n| Command                                               | Purpose                                                                                                     |\n| ----------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |\n| `scans list [REPOSITORY]`                             | List scans. Filter by artifact root with `--scan-root DIR`.                                                 |\n| `scans show [SCAN_ID]`                                | Show a scan; defaults to the latest completed one. `--show-linked-findings` includes earlier finding links. |\n| `scans logs [SCAN_ID]`                                | Show session events; defaults to the latest scan, including active scans.                                   |\n| `scans resume SCAN_ID`                                | Resume an interrupted Deep Scan in its original session and output directory.                               |\n| `scans rerun [SCAN_ID]`                               | Repeat a scan on the current checkout; defaults to the latest completed scan.                               |\n| `scans match BEFORE AFTER`                            | Link findings with the same root cause.                                                                     |\n| `scans match --all`                                   | Match completed scans across the repository's worktrees and clones.                                         |\n| `scans compare [BEFORE] [AFTER]`                      | Compare scans; defaults to the latest two completed scans.                                                  |\n| `findings list [REPOSITORY]`                          | List open findings. `findings` is an alias.                                                                 |\n| `findings false-positive OCCURRENCE_ID --reason TEXT` | Mark a false positive. Later scans dismiss matches only while the reason applies.                           |\n\n#### Resuming an interrupted Deep Scan\n\nAfter the CLI process or host stops unexpectedly, find the scan and rejoin it:\n\n```bash\nnpx @openai/codex-security scans list --scan-root /path/to/security-scans\nnpx @openai/codex-security scans resume SCAN_ID\n```\n\nThe scan must still be `running`, with its original checkout, output directory,\nand owning Codex session available in the same Codex Security state directory.\nThe checkout's identity, revision, and contents must match the saved target.\nCompleted, failed, and canceled scans cannot resume; `scans rerun` starts a new scan.\n\nResume uses the saved configuration and instructions with the installed plugin.\nNew scans save the explicit safety identifier and post-scan prompt contents.\nSingle-scan resume restores them even if the prompt file changes or disappears.\nOlder records that did not save these values cannot reconstruct them. Bulk\nrecovery still requires matching campaign inputs and options; it uses the supplied\npost-scan prompt when the scan has no saved prompt.\nIt keeps the scan ID, completed workers, artifacts, and accumulated session cost.\nThe existing coordinator recovers interrupted workers after its lease expires.\nIf discovery finished before the interruption, resume completes and seals the\nsame scan. No archiving or new attempt directory is needed. A failed connection\nleaves the existing scan available for another resume attempt.\n\nCompatible saved scans can resume after a plugin update. Already-sealed results\nkeep their original producer version and contents when completion is recorded.\nUnsupported or invalid sealed artifacts are rejected before resuming, preserving\nthe saved scan state and files.\n\nFor bulk campaigns, use [`bulk-scan --recover`](#recovering-failed-or-interrupted-bulk-scans)\nto recover eligible attempts and update `results.jsonl`. Individual `scans resume`\ndoes not update campaign receipts.\n\n#### Matching saved scans\n\nMatching requires sealed artifacts and reuses saved matches unless you pass\n`--force`. Comparisons classify findings as new, persisting, reopened, resolved,\nor unknown. Missing findings aren't resolved if the later scan is incomplete\nor excludes their original scope. With one ID, `scans compare` compares it\nto the latest completed scan.\n\nUse `scans match --all --force` to rebuild comparisons chronologically while\nretaining stable finding identities. Ctrl-C keeps comparisons already saved.\nOnly high-confidence duplicates are grouped; uncertain and independently\nrelated findings stay separate. Matching preserves triage and sealed artifacts.\n\nCodex is called only when a new decision is needed, using existing authentication.\nScans without sealed artifacts are skipped, but their confirmed links can still\nbe reused. Older custom plugins save confirmed and uncertain matches; use the\nbundled plugin for related links and large comparisons.\n\nSDK callers can compare findings without saving a workbench comparison:\n\n```ts\nimport { readFile } from \"node:fs/promises\";\nimport","readmeFilename":"README.md"}