Skip to content

Feature/codex - #6

Merged
DevNiall merged 12 commits into
mainfrom
feature/codex
Nov 7, 2025
Merged

Feature/codex#6
DevNiall merged 12 commits into
mainfrom
feature/codex

Conversation

@DevNiall

Copy link
Copy Markdown
Contributor

This pull request significantly enhances the development container setup by adding support for local and remote AI assistant tools, improving R and Python development features, and updating related configurations. The changes streamline integration with AI models (Codex and Continue), expand tooling for data science workflows, and update extension management for a better developer experience.

AI Assistant Integration and Configuration:

  • Added default configuration files for Codex (codex-config.toml) and Continue (continue-config.yaml, continue.env), enabling seamless use of local and remote LLMs via Ollama and OpenWeb APIs. These files are now copied into the container during build. [1] [2] [3] [4]
  • Updated .devcontainer/Dockerfile to copy new AI assistant configuration files and set up the VS Code server with the latest commit.

Development Tooling Enhancements:

  • Added new devcontainer features: Codex, tmux, fzf, and improved R (with TinyTeX, Chromium, and testing support). Python tooling now includes nvitop for GPU monitoring. The default username for the container is set to none for improved compatibility. [1] [2]
  • Updated the list of VS Code extensions to install, including Continue.continue, openai.chatgpt, and R support extensions, and removed the deprecated marimo extension. [1] [2]

Devcontainer Build and Tagging Improvements:

  • Improved GitHub Actions workflow for building the devcontainer by refining tag naming, especially for PR builds and main branch releases, and clarifying VS Code commit hash usage. [1] [2]

DevNiall and others added 6 commits October 2, 2025 15:04
* Add Continue Dev configuration and environment files for enhanced functionality. Also incuded fzf and tmux

* Update Dockerfile and devcontainer configuration for improved compatibility and clarity. Adjust VS Code commit hash and correct Continue Dev config file extension. Comment out deprecated npm package feature in devcontainer.json and update extensions list for clarity.

* Comment out sensitive OPENWEB_API_KEY in continue.env for security reasons
@github-actions

Copy link
Copy Markdown

🔒 Trivy Security Scan Results

Status: ⚠️ Vulnerabilities found (see details in artifacts)
Vulnerabilities Found: 130 critical/high severity issues

⚠️ Action Required: Critical or high severity vulnerabilities detected.

Top 10 Critical/High Severity Vulnerabilities:

Type Package Vulnerability Severity Fixed Version
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
node-pkg grunt CVE-2020-7729 HIGH 1.3.0
node-pkg grunt CVE-2022-1537 HIGH 1.5.3
node-pkg npm CVE-2018-7408 HIGH 5.7.1
node-pkg npm CVE-2019-16775 HIGH 6.13.3
node-pkg npm CVE-2019-16776 HIGH 6.13.3
node-pkg npm CVE-2019-16777 HIGH 6.13.4

... and 4 more issues.

📊 Scan Details

  • Image: ghcr.io/smartdatafoundry/devcontainer
  • Scan Date: 2025-10-16 23:42:16 UTC
  • Total Vulnerabilities: 130

Action Run: view run
Trivy Report: view report

@github-actions

Copy link
Copy Markdown

🔒 Trivy Security Scan Results

Status: ⚠️ Vulnerabilities found (see details in artifacts)
Vulnerabilities Found: 189 critical/high severity issues

⚠️ Action Required: Critical or high severity vulnerabilities detected.

Top 10 Critical/High Severity Vulnerabilities:

Type Package Vulnerability Severity Fixed Version
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
ubuntu linux-libc-dev CVE-2025-22036 HIGH 6.8.0-86.87
ubuntu linux-libc-dev CVE-2025-39735 HIGH 6.8.0-86.87
node-pkg grunt CVE-2020-7729 HIGH 1.3.0
node-pkg grunt CVE-2022-1537 HIGH 1.5.3
node-pkg npm CVE-2018-7408 HIGH 5.7.1
node-pkg npm CVE-2019-16775 HIGH 6.13.3

... and 6 more issues.

📊 Scan Details

  • Image: ghcr.io/smartdatafoundry/devcontainer
  • Scan Date: 2025-10-24 13:59:02 UTC
  • Total Vulnerabilities: 189

Action Run: view run
Trivy Report: view report

@github-actions

Copy link
Copy Markdown

🔒 Trivy Security Scan Results

Status: ⚠️ Vulnerabilities found (see details in artifacts)
Vulnerabilities Found: 189 critical/high severity issues

⚠️ Action Required: Critical or high severity vulnerabilities detected.

Top 10 Critical/High Severity Vulnerabilities:

Type Package Vulnerability Severity Fixed Version
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
ubuntu linux-libc-dev CVE-2025-22036 HIGH 6.8.0-86.87
ubuntu linux-libc-dev CVE-2025-39735 HIGH 6.8.0-86.87
node-pkg grunt CVE-2020-7729 HIGH 1.3.0
node-pkg grunt CVE-2022-1537 HIGH 1.5.3
node-pkg npm CVE-2018-7408 HIGH 5.7.1
node-pkg npm CVE-2019-16775 HIGH 6.13.3

... and 6 more issues.

📊 Scan Details

  • Image: ghcr.io/smartdatafoundry/devcontainer
  • Scan Date: 2025-10-24 18:01:38 UTC
  • Total Vulnerabilities: 189

Action Run: view run
Trivy Report: view report

@github-actions

Copy link
Copy Markdown

🔒 Trivy Security Scan Results

Status: ⚠️ Vulnerabilities found (see details in artifacts)
Vulnerabilities Found: 231 critical/high severity issues

⚠️ Action Required: Critical or high severity vulnerabilities detected.

Top 10 Critical/High Severity Vulnerabilities:

Type Package Vulnerability Severity Fixed Version
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
ubuntu linux-libc-dev CVE-2025-22036 HIGH 6.8.0-86.87
ubuntu linux-libc-dev CVE-2025-39735 HIGH 6.8.0-86.87
node-pkg grunt CVE-2020-7729 HIGH 1.3.0
node-pkg grunt CVE-2022-1537 HIGH 1.5.3
node-pkg npm CVE-2018-7408 HIGH 5.7.1
node-pkg npm CVE-2019-16775 HIGH 6.13.3

... and 8 more issues.

📊 Scan Details

  • Image: ghcr.io/smartdatafoundry/devcontainer
  • Scan Date: 2025-10-30 13:28:34 UTC
  • Total Vulnerabilities: 231

Action Run: view run
Trivy Report: view report

@DevNiall
DevNiall requested a review from Copilot November 7, 2025 13:56

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR enhances the devcontainer configuration with AI coding assistant integrations (Continue and Codex), updates VS Code extensions, improves the CI/CD workflow tagging strategy, and adds several development tools.

Key changes:

  • Integrates Continue and Codex AI coding assistants with local LLM configuration
  • Updates Docker image tagging strategy to differentiate between default branch and PR builds
  • Adds new VS Code extensions and development tools (PostgreSQL client, nvitop, etc.)

Reviewed Changes

Copilot reviewed 9 out of 9 changed files in this pull request and generated 11 comments.

Show a summary per file
File Description
.github/workflows/build-devcontainer.yml Improved Docker tagging strategy to add PR-specific tags and limit certain tags to default branch only
.devcontainer/vscode-init/extensions-to-install.txt Added PostgreSQL and ChatGPT extensions, commented out unavailable marimo extension
.devcontainer/vscode-init/extensions-to-download.txt Added host-side extensions including Continue, Jupyter keymap, ChatGPT, and R syntax
.devcontainer/vscode-init/01-install-extensions.sh Refactored extension installation logic to handle newlines more reliably
.devcontainer/devcontainer.json Added nvitop tool, Quarto features (TinyTeX, Chromium), npm packages for AI tools, apt packages, and updated common-utils configuration
.devcontainer/continue.env New environment configuration for Continue extension with OpenWebUI base URL
.devcontainer/continue-config.yaml New Continue configuration defining multiple local LLM models for AI assistance
.devcontainer/codex-config.toml New Codex configuration for AI coding assistance via local Ollama instance
.devcontainer/Dockerfile Updated VS Code commit hash and added config file copying for Continue and Codex

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread .devcontainer/vscode-init/extensions-to-download.txt
Comment thread .devcontainer/vscode-init/extensions-to-download.txt
Comment thread .devcontainer/vscode-init/extensions-to-download.txt
Comment thread .devcontainer/continue-config.yaml
Comment thread .devcontainer/continue-config.yaml Outdated
Comment thread .devcontainer/Dockerfile Outdated
Comment thread .devcontainer/continue-config.yaml
Comment thread .devcontainer/continue-config.yaml Outdated
Comment thread .devcontainer/continue.env Outdated
Comment thread .devcontainer/devcontainer.json Outdated
@github-actions

github-actions Bot commented Nov 7, 2025

Copy link
Copy Markdown

🔒 Trivy Security Scan Results

Status: ⚠️ Vulnerabilities found (see details in artifacts)
Vulnerabilities Found: 239 critical/high severity issues

⚠️ Action Required: Critical or high severity vulnerabilities detected.

Top 10 Critical/High Severity Vulnerabilities:

Type Package Vulnerability Severity Fixed Version
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
ubuntu linux-libc-dev CVE-2025-22036 HIGH 6.8.0-86.87
ubuntu linux-libc-dev CVE-2025-38118 HIGH 6.8.0-87.88
ubuntu linux-libc-dev CVE-2025-38352 HIGH 6.8.0-87.88
ubuntu linux-libc-dev CVE-2025-39735 HIGH 6.8.0-86.87
ubuntu linux-libc-dev CVE-2025-40300 HIGH 6.8.0-87.88
node-pkg grunt CVE-2020-7729 HIGH 1.3.0

... and 8 more issues.

📊 Scan Details

  • Image: ghcr.io/smartdatafoundry/devcontainer
  • Scan Date: 2025-11-07 14:11:28 UTC
  • Total Vulnerabilities: 239

Action Run: view run
Trivy Report: view report

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
@github-actions

github-actions Bot commented Nov 7, 2025

Copy link
Copy Markdown

🔒 Trivy Security Scan Results

Status: ⚠️ Vulnerabilities found (see details in artifacts)
Vulnerabilities Found: 239 critical/high severity issues

⚠️ Action Required: Critical or high severity vulnerabilities detected.

Top 10 Critical/High Severity Vulnerabilities:

Type Package Vulnerability Severity Fixed Version
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
gobinary stdlib CVE-2024-24790 CRITICAL 1.21.11, 1.22.4
ubuntu linux-libc-dev CVE-2025-22036 HIGH 6.8.0-86.87
ubuntu linux-libc-dev CVE-2025-38118 HIGH 6.8.0-87.88
ubuntu linux-libc-dev CVE-2025-38352 HIGH 6.8.0-87.88
ubuntu linux-libc-dev CVE-2025-39735 HIGH 6.8.0-86.87
ubuntu linux-libc-dev CVE-2025-40300 HIGH 6.8.0-87.88
node-pkg grunt CVE-2020-7729 HIGH 1.3.0

... and 8 more issues.

📊 Scan Details

  • Image: ghcr.io/smartdatafoundry/devcontainer
  • Scan Date: 2025-11-07 15:11:30 UTC
  • Total Vulnerabilities: 239

Action Run: view run
Trivy Report: view report

@DevNiall
DevNiall merged commit 4b88851 into main Nov 7, 2025
1 check passed
@DevNiall
DevNiall deleted the feature/codex branch November 7, 2025 16:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants