Use GitHub private vulnerability reporting.
Do not place credentials, personal data, private repository content, raw Codex Security artifacts, scanner match values, absolute local paths, or proof-of-concept payloads in a public issue.
If a real credential was exposed, revoke or rotate it before preparing a report. Include only the affected commit or version, operating system, Python version, rule or finding identifier, and a minimal synthetic reproduction.
Security reports are especially useful for:
- release-audit output that reveals a matched value
- missed credential classes demonstrated with synthetic data
- Git history, path traversal, or symlink handling mistakes
- acceptance of artifacts stored inside the target repository
- acceptance of malformed, mismatched, incomplete, or tampered Codex Security artifacts
- manifest SHA-256 verification bypasses
- unsafe report overwrites or report paths
- commands that mutate a target repository or call a network service
- GitHub Actions permission or pinning regressions
Issues in the official Codex Security product or its canonical schemas should also be reported through the channels documented by openai/codex-security.