Skip to content

chore(deps): bump the codex group across 3 directories with 2 updates - #897

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/plugins/codex-security/mcp-app/codex-2c1d1f2591
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/plugins/codex-security/mcp-app/codex-2c1d1f2591

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the codex group with 1 update in the /plugins/codex-security/mcp-app directory: @openai/codex-sdk.
Bumps the codex group with 1 update in the /plugins/codex-security/skills/triage-finding/evals directory: @openai/codex-sdk.
Bumps the codex group with 2 updates in the /sdk/typescript directory: @openai/codex-sdk and @openai/codex.

Updates @openai/codex-sdk from 0.154.0 to 0.155.1
Updates @openai/codex-sdk from 0.154.0 to 0.155.1
Updates @openai/codex-sdk from 0.154.0 to 0.155.1
Updates @openai/codex-sdk from 0.154.0 to 0.155.1
Updates @openai/codex-sdk from 0.154.0 to 0.155.1
Updates @openai/codex-sdk from 0.154.0 to 0.155.1
Updates @openai/codex-sdk from 0.154.0 to 0.155.1
Updates @openai/codex-sdk from 0.154.0 to 0.155.1

Release notes

Sourced from @​openai/codex-sdk's releases.

0.155.1

Bug Fixes

  • New local TUI sessions now leave reasoning summaries disabled by default, fixing request rejection by providers that do not support them. Explicit reasoning-summary settings remain respected. (#46467)

Changelog

Full Changelog: openai/codex@rust-v0.155.0...rust-v0.155.1

0.155.0-alpha.9.2

Release 0.155.0-alpha.9.2

0.155.0

New Features

  • Added experimental /voice conversations with live transcripts and microphone controls on supported builds, enabled through /experimental. (#43581, #43651, #44331)
  • The TUI now shows live reasoning summaries in the status row and completion timestamps after successful turns. (#43558, #43921)
  • Added task hiding, archiving, and deletion in the agents overview, plus worktree ownership details and confirmed deletion of clean managed worktrees. (#43942, #44424, #44433)
  • Added Touch ID verification for MCP requests in local TUI sessions on supported Macs. (#43624, #43712, #43715)
  • Added configurable daemon update schedules and codex app-server daemon update; saved threads and active goals can recover after daemon restarts. (#43542, #43562, #44314)
  • Amazon Bedrock can now obtain AWS credentials from configured commands, with caching, expiration-based refresh, and authentication recovery. (#44028)

Bug Fixes

  • Accepted prompts are now saved even when compaction fails before a turn starts. (#44487)
  • Fixed missed tmux resizes, transcript viewport restoration, and stale history appearing after switching threads. (#43603, #43889, #43994)
  • MCP servers now report expired OAuth credentials accurately and provide reconnect guidance when token refresh fails. (#43947, #44359)
  • Automatic approval reviews now preserve complete actions and authorization evidence more reliably, retry transient failures, and distinguish review failures from unsafe-action findings. (#44482, #44569, #44570)
  • Switching accounts now invalidates remote-control sessions, cached WebSocket state, and model catalogs belonging to the previous identity. (#43906, #44341, #44489)
  • Blocked Windows-process escapes from restricted WSL sandboxes and hardened brokered shell snapshots against credential exposure. (#44286, #43909, #44040)

Chores

  • Aligned Python SDK and runtime publishing with stable CLI releases, using matching versions and verifying runtime assets before SDK publication. (#44067)

Changelog

Full Changelog: openai/codex@rust-v0.154.0...rust-v0.155.0

... (truncated)

Commits

Updates @openai/codex from 0.154.0 to 0.155.1

Release notes

Sourced from @​openai/codex's releases.

0.155.1

Bug Fixes

  • New local TUI sessions now leave reasoning summaries disabled by default, fixing request rejection by providers that do not support them. Explicit reasoning-summary settings remain respected. (#46467)

Changelog

Full Changelog: openai/codex@rust-v0.155.0...rust-v0.155.1

0.155.0-alpha.9.2

Release 0.155.0-alpha.9.2

0.155.0

New Features

  • Added experimental /voice conversations with live transcripts and microphone controls on supported builds, enabled through /experimental. (#43581, #43651, #44331)
  • The TUI now shows live reasoning summaries in the status row and completion timestamps after successful turns. (#43558, #43921)
  • Added task hiding, archiving, and deletion in the agents overview, plus worktree ownership details and confirmed deletion of clean managed worktrees. (#43942, #44424, #44433)
  • Added Touch ID verification for MCP requests in local TUI sessions on supported Macs. (#43624, #43712, #43715)
  • Added configurable daemon update schedules and codex app-server daemon update; saved threads and active goals can recover after daemon restarts. (#43542, #43562, #44314)
  • Amazon Bedrock can now obtain AWS credentials from configured commands, with caching, expiration-based refresh, and authentication recovery. (#44028)

Bug Fixes

  • Accepted prompts are now saved even when compaction fails before a turn starts. (#44487)
  • Fixed missed tmux resizes, transcript viewport restoration, and stale history appearing after switching threads. (#43603, #43889, #43994)
  • MCP servers now report expired OAuth credentials accurately and provide reconnect guidance when token refresh fails. (#43947, #44359)
  • Automatic approval reviews now preserve complete actions and authorization evidence more reliably, retry transient failures, and distinguish review failures from unsafe-action findings. (#44482, #44569, #44570)
  • Switching accounts now invalidates remote-control sessions, cached WebSocket state, and model catalogs belonging to the previous identity. (#43906, #44341, #44489)
  • Blocked Windows-process escapes from restricted WSL sandboxes and hardened brokered shell snapshots against credential exposure. (#44286, #43909, #44040)

Chores

  • Aligned Python SDK and runtime publishing with stable CLI releases, using matching versions and verifying runtime assets before SDK publication. (#44067)

Changelog

Full Changelog: openai/codex@rust-v0.154.0...rust-v0.155.0

... (truncated)

Commits

Updates @openai/codex-sdk from 0.154.0 to 0.155.1

Release notes

Sourced from @​openai/codex-sdk's releases.

0.155.1

Bug Fixes

  • New local TUI sessions now leave reasoning summaries disabled by default, fixing request rejection by providers that do not support them. Explicit reasoning-summary settings remain respected. (#46467)

Changelog

Full Changelog: openai/codex@rust-v0.155.0...rust-v0.155.1

0.155.0-alpha.9.2

Release 0.155.0-alpha.9.2

0.155.0

New Features

  • Added experimental /voice conversations with live transcripts and microphone controls on supported builds, enabled through /experimental. (#43581, #43651, #44331)
  • The TUI now shows live reasoning summaries in the status row and completion timestamps after successful turns. (#43558, #43921)
  • Added task hiding, archiving, and deletion in the agents overview, plus worktree ownership details and confirmed deletion of clean managed worktrees. (#43942, #44424, #44433)
  • Added Touch ID verification for MCP requests in local TUI sessions on supported Macs. (#43624, #43712, #43715)
  • Added configurable daemon update schedules and codex app-server daemon update; saved threads and active goals can recover after daemon restarts. (#43542, #43562, #44314)
  • Amazon Bedrock can now obtain AWS credentials from configured commands, with caching, expiration-based refresh, and authentication recovery. (#44028)

Bug Fixes

  • Accepted prompts are now saved even when compaction fails before a turn starts. (#44487)
  • Fixed missed tmux resizes, transcript viewport restoration, and stale history appearing after switching threads. (#43603, #43889, #43994)
  • MCP servers now report expired OAuth credentials accurately and provide reconnect guidance when token refresh fails. (#43947, #44359)
  • Automatic approval reviews now preserve complete actions and authorization evidence more reliably, retry transient failures, and distinguish review failures from unsafe-action findings. (#44482, #44569, #44570)
  • Switching accounts now invalidates remote-control sessions, cached WebSocket state, and model catalogs belonging to the previous identity. (#43906, #44341, #44489)
  • Blocked Windows-process escapes from restricted WSL sandboxes and hardened brokered shell snapshots against credential exposure. (#44286, #43909, #44040)

Chores

  • Aligned Python SDK and runtime publishing with stable CLI releases, using matching versions and verifying runtime assets before SDK publication. (#44067)

Changelog

Full Changelog: openai/codex@rust-v0.154.0...rust-v0.155.0

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the codex group with 1 update in the /plugins/codex-security/mcp-app directory: [@openai/codex-sdk](https://github.com/openai/codex/tree/HEAD/sdk/typescript).
Bumps the codex group with 1 update in the /plugins/codex-security/skills/triage-finding/evals directory: [@openai/codex-sdk](https://github.com/openai/codex/tree/HEAD/sdk/typescript).
Bumps the codex group with 2 updates in the /sdk/typescript directory: [@openai/codex-sdk](https://github.com/openai/codex/tree/HEAD/sdk/typescript) and [@openai/codex](https://github.com/openai/codex/tree/HEAD/codex-cli).


Updates `@openai/codex-sdk` from 0.154.0 to 0.155.1
- [Release notes](https://github.com/openai/codex/releases)
- [Commits](https://github.com/openai/codex/commits/rust-v0.155.1/sdk/typescript)

Updates `@openai/codex-sdk` from 0.154.0 to 0.155.1
- [Release notes](https://github.com/openai/codex/releases)
- [Commits](https://github.com/openai/codex/commits/rust-v0.155.1/sdk/typescript)

Updates `@openai/codex-sdk` from 0.154.0 to 0.155.1
- [Release notes](https://github.com/openai/codex/releases)
- [Commits](https://github.com/openai/codex/commits/rust-v0.155.1/sdk/typescript)

Updates `@openai/codex-sdk` from 0.154.0 to 0.155.1
- [Release notes](https://github.com/openai/codex/releases)
- [Commits](https://github.com/openai/codex/commits/rust-v0.155.1/sdk/typescript)

Updates `@openai/codex-sdk` from 0.154.0 to 0.155.1
- [Release notes](https://github.com/openai/codex/releases)
- [Commits](https://github.com/openai/codex/commits/rust-v0.155.1/sdk/typescript)

Updates `@openai/codex-sdk` from 0.154.0 to 0.155.1
- [Release notes](https://github.com/openai/codex/releases)
- [Commits](https://github.com/openai/codex/commits/rust-v0.155.1/sdk/typescript)

Updates `@openai/codex-sdk` from 0.154.0 to 0.155.1
- [Release notes](https://github.com/openai/codex/releases)
- [Commits](https://github.com/openai/codex/commits/rust-v0.155.1/sdk/typescript)

Updates `@openai/codex-sdk` from 0.154.0 to 0.155.1
- [Release notes](https://github.com/openai/codex/releases)
- [Commits](https://github.com/openai/codex/commits/rust-v0.155.1/sdk/typescript)

Updates `@openai/codex` from 0.154.0 to 0.155.1
- [Release notes](https://github.com/openai/codex/releases)
- [Commits](https://github.com/openai/codex/commits/rust-v0.155.1/codex-cli)

Updates `@openai/codex-sdk` from 0.154.0 to 0.155.1
- [Release notes](https://github.com/openai/codex/releases)
- [Commits](https://github.com/openai/codex/commits/rust-v0.155.1/sdk/typescript)

---
updated-dependencies:
- dependency-name: "@openai/codex-sdk"
  dependency-version: 0.155.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codex
- dependency-name: "@openai/codex-sdk"
  dependency-version: 0.155.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codex
- dependency-name: "@openai/codex-sdk"
  dependency-version: 0.155.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codex
- dependency-name: "@openai/codex-sdk"
  dependency-version: 0.155.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codex
- dependency-name: "@openai/codex-sdk"
  dependency-version: 0.155.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codex
- dependency-name: "@openai/codex-sdk"
  dependency-version: 0.155.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codex
- dependency-name: "@openai/codex-sdk"
  dependency-version: 0.155.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codex
- dependency-name: "@openai/codex-sdk"
  dependency-version: 0.155.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codex
- dependency-name: "@openai/codex"
  dependency-version: 0.155.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codex
- dependency-name: "@openai/codex-sdk"
  dependency-version: 0.155.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codex
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 19, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants