feat: add audited Codex Image 2 WeChat reports#6
Merged
Conversation
# Conflicts: # README.md
kdnsna
marked this pull request as ready for review
July 20, 2026 13:02
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Why
The goal is to make WeChat a trustworthy monitoring destination for scheduled Codex work. It reports what ran, what evidence was produced, and what action is recommended, while deliberately excluding WeChat-triggered Codex, shell, or Mac remote control.
Safety boundary
vendor/cli-in-wechatremains a pinned QR-login/context/proactive-send adapter; its upstream remote-control entry points are not started or reused.Notable fixes
message_idvalues as identifiers instead of unsafe JavaScript numbersVerification
npm test -- --reporter=dot --maxWorkers=1: 65 files, 645 tests passednpm run typecheck: passed on Node 22npm run build: passed on Node 22npm --prefix vendor/cli-in-wechat test: 81 tests passedplutil -lint launchd/com.kdnsna.daily-tech-digest.plist: OKgit diff --cached --check: passed before merge commitKnown dependency note
The pinned upstream adapter currently reports one high-severity
undiciadvisory set and one low-severityesbuildadvisory. WeChatPilot does not enable the affected upstream WebSocket or development-server entry points. This draft keeps the upstream pin intact so a dependency update can be reviewed and tested separately instead of silently changing the adapter snapshot.Operational result
The local LaunchAgent schedule remains 08:00. End-to-end checks produced detailed numbered 1080 x 2400 report cards and recorded accepted text/image delivery receipts. Runtime state, QR images, logs, and generated output are intentionally untracked.