# OpenAI 发布了 Codex Security CLI 和 TypeScript SDK，支持仓库扫描、变更审查和 CI 集成，用于发现和修复代码安全漏洞

- 来源：jason@jxnlco
- 发布时间：2026-07-29 07:05
- AIWatch 分数：62
- AIWatch 标记：当日精选
- AIWatch 链接：https://aiwatch.icu/events/evt_01kynkzd3spxa1mv8wqfnb80an
- 原文链接：https://x.com/jxnlco/status/2082253183129202885

## 精选理由

常规快讯，保留列表

## AI 摘要

OpenAI 发布了 Codex Security CLI 和 TypeScript SDK，支持仓库扫描、变更审查和 CI 集成，用于发现和修复代码安全漏洞。

## 正文

@openai/codex-security is a CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities in your code. Scan repositories, review changes, track findings over time, and run security checks in CI.

Documentation

Quick start

Requires Node.js 22 or later, Python 3.10 or later, and access to Codex Security.

npm install @openai/codex-security
npx codex-security login
npx codex-security scan .

For CI, set OPENAI_API_KEY instead of signing in.

If both a ChatGPT sign-in and an API key are available, interactive scans ask which credential to use. CI and other noninteractive scans keep the existing API-key precedence. Select a credential explicitly when needed:

npx codex-security scan . --auth chatgpt
npx codex-security scan . --auth api-key

To make your ChatGPT sign-in the automatic default, unset any configured API keys:

unset OPENAI_API_KEY CODEX_API_KEY

Scan history is stored in the Codex Security workbench state directory. If that directory cannot be written, set CODEX_SECURITY_STATE_DIR to a writable directory outside the repository.

TypeScript SDK

import { CodexSecurity } from "@openai/codex-security";

const security = new CodexSecurity();
const result = await security.run(".");

console.log(result.reportPath);
await security.close();

For installation, authentication, scan options, and CI setup, see the official documentation.
