Skip to content

Security: Fuika0306/codex-verified-secure-release

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Use GitHub private vulnerability reporting.

Do not place credentials, personal data, private repository content, raw Codex Security artifacts, scanner match values, absolute local paths, or proof-of-concept payloads in a public issue.

If a real credential was exposed, revoke or rotate it before preparing a report. Include only the affected commit or version, operating system, Python version, rule or finding identifier, and a minimal synthetic reproduction.

Scope

Security reports are especially useful for:

  • release-audit output that reveals a matched value
  • missed credential classes demonstrated with synthetic data
  • Git history, path traversal, or symlink handling mistakes
  • acceptance of artifacts stored inside the target repository
  • acceptance of malformed, mismatched, incomplete, or tampered Codex Security artifacts
  • manifest SHA-256 verification bypasses
  • unsafe report overwrites or report paths
  • commands that mutate a target repository or call a network service
  • GitHub Actions permission or pinning regressions

Issues in the official Codex Security product or its canonical schemas should also be reported through the channels documented by openai/codex-security.

There aren't any published security advisories