OpenAI, Open-Sourced

marsbit2026-07-30 tarihinde yayınlandı2026-07-30 tarihinde güncellendi

Özet

OpenAI has open-sourced its code security tool, Codex Security CLI. The tool, which originated from the private beta project Aardvark in October 2025, is designed to automatically discover, verify, and fix vulnerabilities in codebases. It functions as an application security agent, first analyzing a repository to build a threat model, then identifying and ranking vulnerabilities based on real-world impact, and finally testing them in a sandbox for validation. According to OpenAI, in its first 30 days, the tool scanned over 1.2 million commits, uncovering 792 critical and 10,561 high-severity vulnerabilities, with a reported reduction of over 50% in false positives upon repeated scans of the same repositories. However, initial user experiences on platforms like Hacker News highlighted significant issues, particularly concerning cost and reliability. Developers reported failed scans that consumed substantial portions of API rate limits and incurred high expenses, with one user noting a cost of approximately $13 for an aborted run. The high cost is attributed to the tool's default configuration, which uses the premium GPT-5.6-sol model with inference intensity set to "extra-high." The release follows public statements by NVIDIA's Jensen Huang advocating for open-source AI. While OpenAI has open-sourced the application-layer CLI and SDK, the core AI models remain proprietary. The move opens the door for community development and potential adaptations of the tool.

OpenAI has finally become "Open" once again!

Recently, OpenAI officially announced: it has quietly released an open-source code security tool—Codex Security CLI.

Previously, someone on Hacker News discovered it first, sparking instant discussions, and GitHub stars surged to 1.2k.

Seeing that it could no longer be kept hidden, OpenAI had no choice but to come forward and claim it.

GitHub address: https://github.com/openai/codex-security

A few days ago, Jensen Huang personally stepped in, publicly expressing strong support for open-source AI, and soon after, OpenAI officially joined the camp.

Little did we expect that the surprise would come so quickly, as the heavyweight open-source masterpiece was unveiled almost instantly.

It has to be said, Huang's words still carry significant weight!

OpenAI's Code Security Tool is Now Open-Source

The "star" of this open-source release is codex-security, comprising a CLI and a TypeScript SDK.

Its core functionality is very straightforward, focusing on a "combo punch": automatically discovering vulnerabilities in a codebase, verifying them, and fixing them.

It's designed to be ready-to-use; the entire workflow can be run with just three lines of commands:

  • npm install @openai/codex-security
  • npx codex-security login
  • npx codex-security scan .

For CI runs, logging in isn't required; just configure an OPENAI_API_KEY.

The requirements are Node.js 22 or higher, Python 3.10 or higher, plus access to Codex Security.

1.2 Million Commits, 792 Critical Vulnerabilities

Strictly speaking, Codex Security isn't a completely "new species".

It evolved from the private beta project Aardvark in October 2025 and was renamed and launched as a research preview version on March 6th this year.

The most hardcore aspect of this tool lies in its positioning—an application security agent.

Codex Security truly dives deep into the underlying code to understand what your system is actually doing. Its workflow is divided into three steps:

First, it reads the entire repository to generate an editable threat model, figuring out what the project does and where it's most exposed;

Then, based on this context, it searches for vulnerabilities and ranks them by their real-world impact;

Finally, it throws suspicious issues into a sandbox for real stress testing, only reporting those that can be verified.

Looking at its track record, it's indeed quite formidable.

In its first 30 days online, it scanned over 1.2 million commits, uncovering 792 critical severity findings and 10,561 high severity findings.

OpenAI also mentioned that for the same batch of repositories scanned repeatedly, the false positive rate dropped by over 50%.

The First Batch of Early Adopters, Bills Exploded

No matter how grand the official promises are, they can't compare to the "real-world test disasters" that immediately surfaced among developers.

On HN, a developer named gregwebs tested it on a small repository and directly posted the utterly devastating terminal logs.

Preparation started at 0:03, scanning began at 1:20, ran all the way to 52:47, and finally, a line of red text popped up—the repository HEAD changed during scanning, please start over.

Not only did it waste an hour, but this single run also consumed half of his Pro plan's weekly quota.

Another user, Quai, had it worse. The scan hit account rate limits right after starting, and the tool retried for a minute before giving up.

The tool did hint that "partial results have been preserved," but he couldn't find an obvious way to use them in the next scan. This failed run cost about $13.

Why is it so expensive? Just look at the default configuration and the answer becomes clear.

Codex Security defaults to calling gpt-5.6-sol and brutally cranks the "reasoning effort" up to extra-high.

It's important to know that Sol is the most "premium" tier in the GPT-5.6 family, with API pricing as high as $5 per 1M input tokens and $30 per 1M output tokens.

Huang Kicked Things Off, OpenAI Took a Step

Just after Jensen Huang publicly voiced strong support for open-source AI, OpenAI brought out Codex Security.

However, don't interpret this "open-source" move as too generous just yet.

OpenAI's step is quite calculated: they've open-sourced the application-layer shell, while the model layer is still tightly held in their own hands.

Regardless, the Pandora's box of agents taking over code security has been opened.

Next, it's up to developers to see how they can hack and modify this open-source artifact, using the magic of the community to counter OpenAI's own magic.

References:

https://x.com/gdb/status/2082235089539526690?s=20

https://x.com/OpenAI/status/2082263717916586117?s=20

This article is from WeChat public account "AI Era", author: ASI Revelations

İlgili Sorular

QWhat did OpenAI recently open-source, and what is its primary function?

AOpenAI recently open-sourced Codex Security CLI, a tool designed to automatically detect, validate, and fix security vulnerabilities in codebases.

QWhat commands are needed to run the basic workflow of the open-sourced tool?

AThe basic workflow requires three commands: `npm install @openai/codex-security`, `npx codex-security login`, and `npx codex-security scan .`.

QWhat were some of the early user complaints regarding the Codex Security tool?

AEarly users complained about high costs, slow scans, account rate-limiting, and the tool's default use of the expensive `gpt-5.6-sol` model with the `extra-high` reasoning setting.

QAccording to the article, what significant results did Codex Security achieve in its first 30 days?

AIn its first 30 days, Codex Security scanned over 1.2 million commits and identified 792 critical and 10,561 high-severity findings.

QHow does the article characterize the nature of OpenAI's 'open-sourcing' of Codex Security?

AThe article characterizes it as a strategic move where OpenAI open-sourced the application layer (the CLI/SDK) but keeps the core model layer proprietary and under its control.

İlgili Okumalar

Ethereum's 11th Year: Why Is This Year Particularly Crucial?

Ethereum's 11th year proved pivotal, marked by a dual evolution in its technical roadmap and organizational structure. The year saw the completion of the Fusaka upgrade, introducing PeerDAS to make data availability sampling more efficient and laying groundwork for future L2 scaling. This was followed by a significant reorganization of the Ethereum Foundation (EF). The EF downsized, redefining its core mandate around user sovereignty and CROPS principles, while spinning off key functions. Independent entities like Ethlabs (non-profit R&D), Ethereum Institutional (institutional onboarding), and EthSystems (institutional privacy solutions) now operate separately. Technologically, the community debated a bold, long-term vision outlined in Justin Drake's "Lean Ethereum" proposal and the collaborative "Strawmap." These point toward a "third major iteration" for Ethereum, targeting goals like faster finality (~1 second), gigagas-scale L1 throughput, teragas-scale L2 capacity, post-quantum cryptography, and protocol-level privacy. Data underscores Ethereum's dominant position: its L1 still holds roughly half of all stablecoin value, leads in tokenized Real-World Assets (RWA), and commands over 55% of total DeFi TVL. While L2s now handle over 10x more transactions than the mainnet, high-value assets remain concentrated on L1. The launch of Robinhood Chain, an EVM-compatible L2 for stock tokens, signals growing institutional adoption. The immediate roadmap includes the Glamsterdam upgrade (featuring ePBS for in-protocol proposer-builder separation and Block Access Lists for parallelism), potentially followed by Hegotá focusing on anti-censorship via FOCIL. In summary, Ethereum's 11th year was defined by setting ambitious technical foundations for its next decade and restructuring its core development ecosystem to be more modular and sustainable, all while maintaining its role as the leading settlement layer for decentralized finance and assets.

marsbit4 dk önce

Ethereum's 11th Year: Why Is This Year Particularly Crucial?

marsbit4 dk önce

Notable Forecast from an Analytical Company Regarding Bitcoin (BTC): After This Date, a New Bull Season Could Begin!

Bitcoin continues to trade sideways around $64,000 amid ongoing uncertainty regarding U.S. monetary policy and geopolitical risks in the Middle East. As BTC struggles for direction, an analyst predicts the next major uptrend could commence after the U.S. midterm elections. João Wedson, founder and CEO of crypto analytics firm Alphractal, revisited the connection between Bitcoin's price movements and the U.S. election calendar in his latest analysis. Wedson claims that analyzing past market cycles reveals similar patterns in Bitcoin's price behavior, particularly around U.S. midterm and presidential elections. Historically, Bitcoin has faced headwinds leading up to midterms but tends to recover once election-related uncertainty subsides. Based on historical data, Bitcoin entered bear markets roughly a year before past midterm elections, only to initiate prolonged bull markets after the elections concluded. In some cycles, price bottoms formed just days before the vote, while in others, the low occurred immediately after. The analyst also noted presidential elections have a distinct impact: Bitcoin experiences strong rallies each time a president wins re-election and approaches the peak of its main cycle shortly after the presidential inauguration. As an example, Wedson pointed to XRP, which began a sharp rise on the day Donald Trump won the 2024 election and reached a local peak on January 20, 2025, his inauguration day.

cryptonews.ru19 dk önce

Notable Forecast from an Analytical Company Regarding Bitcoin (BTC): After This Date, a New Bull Season Could Begin!

cryptonews.ru19 dk önce

Lummis: The CLARITY Act mechanism "is not working" as the Senate drags its feet

U.S. Senator Cynthia Lummis has argued that the current regulatory framework for digital assets is inadequate, harming industry, investors, and regulators alike. She is urgently pushing for the Senate to pass the Digital Asset Market Clarity Act (H.R. 3633/CLARITY Act) before the August recess, warning the current momentum for the bill is a unique opportunity this decade. The legislation aims to divide oversight between the SEC and CFTC. Time is running out, as the Senate must act before its August 8th recess. Delays would push the debate to September, further squeezing the legislative calendar before the midterm elections. Forecasting platforms now estimate only a 30% chance of the bill becoming law in 2026, a sharp drop from over 80% in February. Passage requires 60 votes, meaning at least seven Democrats must join Republicans, a task complicated by Democratic opposition. Key objections from figures like Senator Elizabeth Warren center on concerns the bill could weaken oversight of decentralized finance (DeFi) and consumer protection, potentially endangering the financial system. Over 200 crypto industry organizations, including Coinbase and Ripple, are lobbying for a vote, arguing continued uncertainty drives innovation and jobs overseas. Lummis contends the bill's custody and disclosure rules are precisely the consumer protections needed to close existing loopholes. The bill's fate now hinges on whether Senate Majority Leader John Thune schedules a vote this week or delays it until the fall session, where it would face an even more constrained political environment.

cryptonews.ru19 dk önce

Lummis: The CLARITY Act mechanism "is not working" as the Senate drags its feet

cryptonews.ru19 dk önce

İşlemler

Spot
活动图片