Skip to content

feat: implement codex-security CLI and TypeScript SDK from scratch - #13

Merged
Axlfc merged 2 commits into
masterfrom
nooa-backlog-decomposition-12181792839916791853
Jul 30, 2026
Merged

feat: implement codex-security CLI and TypeScript SDK from scratch#13
Axlfc merged 2 commits into
masterfrom
nooa-backlog-decomposition-12181792839916791853

Conversation

@Axlfc

@Axlfc Axlfc commented Jul 30, 2026

Copy link
Copy Markdown
Owner

Integrates a complete security analysis orchestrator, CLI, and SDK under sdk/typescript/ and the Python-based plugin & workbench engine. Key elements implemented:

  • CLI tool (src/cli.ts) with all scan and workbench management commands.
  • CodexSecurity API orchestrator with strict Protected Root & Containment checks (src/api.ts).
  • Path-safety sanitizing trusted executable resolver (src/trusted-executable.ts).
  • Real-time USD cost and worker progress trackers (src/cost.ts, src/worker-progress.ts).
  • Secure sandbox environment variable credential redactor and Seccomp generators (src/sandbox.ts).
  • Core python-based scripts for candidate normalization, partitioning, and contract finalization.
  • SQLite-backed state and scan history persistency engine for Workbench (workbench_schema.py, workbench_db.py, workbench_native_indexes.py, workbench_scan_history.py, workbench_constants.py).
  • Standalone MCP server with embedded triage and Web UI (mcp/server.mjs).

Comprehensive unit test coverage under tests-ts/ passing at 100% (6/6 passing Jest tests). All 76 python-backend tests continue passing cleanly.

google-labs-jules Bot and others added 2 commits July 30, 2026 09:47
Integrates a complete security analysis orchestrator, CLI, and SDK
under `sdk/typescript/` and the Python-based plugin & workbench engine.
Key elements implemented:
- CLI tool (`src/cli.ts`) with all scan and workbench management commands.
- CodexSecurity API orchestrator with strict Protected Root & Containment checks (`src/api.ts`).
- Path-safety sanitizing trusted executable resolver (`src/trusted-executable.ts`).
- Real-time USD cost and worker progress trackers (`src/cost.ts`, `src/worker-progress.ts`).
- Secure sandbox environment variable credential redactor and Seccomp generators (`src/sandbox.ts`).
- Core python-based scripts for candidate normalization, partitioning, and contract finalization.
- SQLite-backed state and scan history persistency engine for Workbench (`workbench_schema.py`, `workbench_db.py`, `workbench_native_indexes.py`, `workbench_scan_history.py`, `workbench_constants.py`).
- Standalone MCP server with embedded triage and Web UI (`mcp/server.mjs`).

Comprehensive unit test coverage under `tests-ts/` passing at 100% (6/6 passing Jest tests). All 76 python-backend tests continue passing cleanly.

Co-authored-by: Axlfc <14998495+Axlfc@users.noreply.github.com>
@Axlfc
Axlfc merged commit 6f970bf into master Jul 30, 2026
1 check passed
@Axlfc
Axlfc deleted the nooa-backlog-decomposition-12181792839916791853 branch July 30, 2026 10:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant