-
Notifications
You must be signed in to change notification settings - Fork 691
All issues
Issue creation is restricted in this repository
Issues
is:issue state:open
is:issue state:open
Search results
Python 3.10: Deep Scan deadline and coordinator leases fail on Z-suffixed timestamps
area:pythonPython interpreter, bundled Python workbench, or Python integrationsPython interpreter, bundled Python workbench, or Python integrationsarea:reportsScan artifacts, findings, exports, manifests, history, or SARIFScan artifacts, findings, exports, manifests, history, or SARIFbugSomething isn't workingSomething isn't workingpriority:p1High-impact scan failure, integrity gap, or user-blocking regressionHigh-impact scan failure, integrity gap, or user-blocking regressionStatus: Open.#450 In openai/codex-security;Windows: scan leaves temporary sandbox SID ACLs in the state directory, then fails credential-home validation
area:authLogin, credentials, account access, or authorizationLogin, credentials, account access, or authorizationarea:sandboxExecution isolation, filesystem boundaries, trusted paths, or ACLsExecution isolation, filesystem boundaries, trusted paths, or ACLsbugSomething isn't workingSomething isn't workingplatform:windowsWindows, PowerShell, Windows paths, or Windows ACLsWindows, PowerShell, Windows paths, or Windows ACLspriority:p1High-impact scan failure, integrity gap, or user-blocking regressionHigh-impact scan failure, integrity gap, or user-blocking regressionStatus: Open.#421 In openai/codex-security;codex-security scanaborts mid-scan with "flagged for possible cybersecurity risk" on a private enterprise repoarea:authLogin, credentials, account access, or authorizationLogin, credentials, account access, or authorizationarea:cliCLI commands, arguments, output, or interactionCLI commands, arguments, output, or interactionarea:costUsage visibility, estimated spend, budgets, or cost trackingUsage visibility, estimated spend, budgets, or cost trackingarea:reportsScan artifacts, findings, exports, manifests, history, or SARIFScan artifacts, findings, exports, manifests, history, or SARIFbugSomething isn't workingSomething isn't workingpriority:p1High-impact scan failure, integrity gap, or user-blocking regressionHigh-impact scan failure, integrity gap, or user-blocking regressionStatus: Open.#375 In openai/codex-security;scan --diff always fails to save: scan.target.snapshotDigest: expected a non-empty string
area:cliCLI commands, arguments, output, or interactionCLI commands, arguments, output, or interactionarea:costUsage visibility, estimated spend, budgets, or cost trackingUsage visibility, estimated spend, budgets, or cost trackingarea:reportsScan artifacts, findings, exports, manifests, history, or SARIFScan artifacts, findings, exports, manifests, history, or SARIFbugSomething isn't workingSomething isn't workingpriority:p1High-impact scan failure, integrity gap, or user-blocking regressionHigh-impact scan failure, integrity gap, or user-blocking regressionStatus: Open.#299 In openai/codex-security;Windows deep scans can fail when subprocess output contains non-CP1252 bytes
area:pythonPython interpreter, bundled Python workbench, or Python integrationsPython interpreter, bundled Python workbench, or Python integrationsbugSomething isn't workingSomething isn't workingplatform:windowsWindows, PowerShell, Windows paths, or Windows ACLsWindows, PowerShell, Windows paths, or Windows ACLspriority:p2Significant defect or product gap with narrower impact or a workaroundSignificant defect or product gap with narrower impact or a workaroundquestionFurther information is requestedFurther information is requestedstatus:needs-infoWaiting for reporter details or a reliable reproductionWaiting for reporter details or a reliable reproductionStatus: Open.#283 In openai/codex-security;Deep Security Scan fails terminally when its discovery triggers cyber safety
area:authLogin, credentials, account access, or authorizationLogin, credentials, account access, or authorizationarea:costUsage visibility, estimated spend, budgets, or cost trackingUsage visibility, estimated spend, budgets, or cost trackingarea:reportsScan artifacts, findings, exports, manifests, history, or SARIFScan artifacts, findings, exports, manifests, history, or SARIFbugSomething isn't workingSomething isn't workingpriority:p1High-impact scan failure, integrity gap, or user-blocking regressionHigh-impact scan failure, integrity gap, or user-blocking regressionStatus: Open.#276 In openai/codex-security;Are there any plans to support self-built Literm in the future?
priority:p3Lower-impact improvement, documentation, or routine maintenanceLower-impact improvement, documentation, or routine maintenancequestionFurther information is requestedFurther information is requestedstatus:needs-infoWaiting for reporter details or a reliable reproductionWaiting for reporter details or a reliable reproductionStatus: Open.#257 In openai/codex-security;Run warnings never reach the SARIF projection, so drift is invisible to SARIF consumers
area:pythonPython interpreter, bundled Python workbench, or Python integrationsPython interpreter, bundled Python workbench, or Python integrationsarea:reportsScan artifacts, findings, exports, manifests, history, or SARIFScan artifacts, findings, exports, manifests, history, or SARIFbugSomething isn't workingSomething isn't workingpriority:p1High-impact scan failure, integrity gap, or user-blocking regressionHigh-impact scan failure, integrity gap, or user-blocking regressionStatus: Open.#251 In openai/codex-security;Content digests buffer entire git diff --binary patches in memory
area:pythonPython interpreter, bundled Python workbench, or Python integrationsPython interpreter, bundled Python workbench, or Python integrationsbugSomething isn't workingSomething isn't workingpriority:p2Significant defect or product gap with narrower impact or a workaroundSignificant defect or product gap with narrower impact or a workaroundStatus: Open.#249 In openai/codex-security;bulk-scan discards run warnings, so a drifted repository is recorded as completed with no signal
area:bulk-scanRepository discovery, bulk campaigns, inventory, or resumeRepository discovery, bulk campaigns, inventory, or resumearea:reportsScan artifacts, findings, exports, manifests, history, or SARIFScan artifacts, findings, exports, manifests, history, or SARIFbugSomething isn't workingSomething isn't workingpriority:p1High-impact scan failure, integrity gap, or user-blocking regressionHigh-impact scan failure, integrity gap, or user-blocking regressionStatus: Open.#248 In openai/codex-security;Document npm package, bundled plugin, and runtime version mapping
area:cliCLI commands, arguments, output, or interactionCLI commands, arguments, output, or interactiondocumentationImprovements or additions to documentationImprovements or additions to documentationpriority:p3Lower-impact improvement, documentation, or routine maintenanceLower-impact improvement, documentation, or routine maintenanceStatus: Open.#234 In openai/codex-security;scan.target.remote accepts embedded tab/newline/CR because new URL() strips them before validating
area:reportsScan artifacts, findings, exports, manifests, history, or SARIFScan artifacts, findings, exports, manifests, history, or SARIFbugSomething isn't workingSomething isn't workingpriority:p2Significant defect or product gap with narrower impact or a workaroundSignificant defect or product gap with narrower impact or a workaroundStatus: Open.#231 In openai/codex-security;