Skip to content

chore(agents): bump codex to 0.147.0 - #152

Merged
cspinetta merged 1 commit into
mainfrom
bump-agents/codex-0.147.0
Aug 10, 2026
Merged

cspinetta merged 1 commit into
mainfrom
bump-agents/codex-0.147.0

Conversation

@voidbox-automation

Copy link
Copy Markdown
Contributor

Automated bump for codex to version 0.147.0.

tuple prev url sha256 (computed by CI)
linux/x86_64 0.146.0 https://github.com/openai/codex/releases/download/rust-v0.147.0/codex-x86_64-unknown-linux-musl.tar.gz 0246e2e773834e07f0fb5249ed6ebad12e4591e608f8c7bb97dd6a9690544c36
linux/aarch64 0.146.0 https://github.com/openai/codex/releases/download/rust-v0.147.0/codex-aarch64-unknown-linux-musl.tar.gz eb677c80f666b1ab8b4b1d083b66e8d614b1281d960bb6f9fd8ca98f58b38b90

CI downloaded each artifact from the URL above and recorded the SHA-256 shown here.

How to verify the SHA-256s

Upstream publishes per-asset digests on the GitHub release page: https://github.com/openai/codex/releases/tag/rust-v0.147.0

Spot-check from the CLI:

gh release view rust-v0.147.0 --repo openai/codex --json assets \
  --jq '.assets[] | select(.name | test("^codex-(x86_64|aarch64)-unknown-linux-musl\\.tar\\.gz$")) | "\(.name) \(.digest)"'

Each printed sha256:… must match the row above for the corresponding arch.

Why this needs a human

Once merged, the hashes above lock these binaries in place — every future build aborts unless the download matches byte-for-byte. CI just computed them from a single fetch against upstream, so merging without spot-checking trusts whatever upstream served at that one moment. The cross-check above is what catches a CDN-edge tamper or an upstream-account compromise before it propagates into our images. A surprise version jump (off-schedule, several releases at once, pre-release tag) is its own signal worth a second look.

@cspinetta
cspinetta merged commit e087ee8 into main Aug 10, 2026
21 checks passed
@cspinetta
cspinetta deleted the bump-agents/codex-0.147.0 branch August 10, 2026 14:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant