news.volyx.in

Codex Security (github.com)

597 points by bakigul · 30 days ago · 229 comments on HN

Article summary

OpenAI has released Codex Security, a CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities in code. The tool scans repositories, reviews changes, and tracks findings over time, and can be integrated into CI workflows. It requires Node.js 22 or later, Python 3.10 or later, and access to Codex Security. The tool is open-source and has a documentation and quick start guide available.

Main themes

  • Code Security
  • Vulnerability Detection
  • CI Integration
  • Open-Source Tools
  • AI-Powered Security

What commenters say

  • The tool is still experiencing authentication issues and users are encountering errors when trying to use it.
  • Some users are questioning the value of Codex Security and whether it will replace existing security tools like Snyk.
  • Others are concerned about the limitations of the tool, including its inability to bypass model guardrails and its reliance on OpenAI's APIs.
  • There are differing opinions on the effectiveness of Codex Security compared to other tools, with some users finding it useful and others preferring alternative solutions.
  • Some users are interested in using Codex Security with local or OpenAI-compatible LLM endpoints, rather than relying on OpenAI's APIs.
  • The tool's rate limiting and retry mechanisms are being criticized for being inadequate and causing unnecessary costs.
  • There are discussions about the potential for Codex Security to disrupt the market for security tools and the impact it may have on companies like Snyk.
  • Some users are skeptical about the claims made by LLM labs and believe that their products do not live up to the hype.