BotBeat
...
← Back

> ▌

OpenAIOpenAI
OPEN SOURCEOpenAI2026-07-28

OpenAI Open-Sources Codex Security: AI-Powered Code Vulnerability Scanner

Key Takeaways

  • ▸OpenAI open-sources Codex Security, an AI-powered code security analysis tool available via npm with CLI and TypeScript SDK support
  • ▸Supports cross-platform development (macOS, Linux, Windows) with Node.js 22+ requirement and optional Python 3.10+ for advanced scanning and export features
  • ▸Includes enterprise-grade capabilities: bulk scanning, CI/CD integration, git hooks, custom threat models, severity filtering, and multiple export formats (SARIF, CSV, JSON)
Source:
Hacker Newshttps://github.com/openai/codex-security↗

Summary

OpenAI has released Codex Security as an open-source CLI and TypeScript SDK, bringing AI-powered code vulnerability detection to developers. The tool leverages OpenAI's models to find, validate, and review security issues in codebases, with support for cross-platform development (macOS, Linux, Windows) and integration into CI/CD pipelines. Codex Security requires Node.js 22 or later and optional Python 3.10+ for scanning and export functionality, authenticating via OpenAI API keys or ChatGPT accounts.

The release includes comprehensive features such as severity-based filtering, git diff scanning, bulk repository scanning, custom threat model integration, and multiple export formats (SARIF, CSV, JSON) for seamless security toolchain integration. Developers can install the tool via npm and begin scanning with just a few commands, with additional capabilities like git hook installation for pre-commit security validation and scan result comparison across multiple runs.

  • Requires OpenAI API authentication or ChatGPT sign-in; follows semantic versioning with public API stability guaranteed after version 1.0.0
AI AgentsMLOps & InfrastructureCybersecurityOpen Source

More from OpenAI

OpenAIOpenAI
POLICY & REGULATION

The Worst Way to Regulate AI

2026-07-28
OpenAIOpenAI
INDUSTRY REPORT

OpenAI Models Break Containment and Hack Hugging Face—A Predictable Reckoning

2026-07-28
OpenAIOpenAI
RESEARCH

Research: Why Some Junior Employees Excel With Generative AI While Others Struggle

2026-07-28

Comments

Suggested

AnthropicAnthropic
RESEARCH

Anthropic Publishes Practical Key-Recovery Attack on HAWK-256 Post-Quantum Algorithm

2026-07-28
U.S. GovernmentU.S. Government
POLICY & REGULATION

FBI Seeks Predictive AI to Monitor Political Dissent as Threat Focus Shifts from Terrorism

2026-07-28
AnthropicAnthropic
FUNDING & BUSINESS

Anthropic Held Secret Acquisition Talks with Robotics Startup Physical Intelligence

2026-07-28
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us