feat: match repeated findings across scan history - #575
Conversation
|
Codex Review: Didn't find any major issues. 🚀 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
@codex review The description now includes the final QA results and merge order. Please review the current head, |
|
Codex Review: Didn't find any major issues. Keep them coming! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
Security findingsBlocking findings (1)
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c3d4a5661b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please review the current head, |
|
Codex Review: Didn't find any major issues. Can't wait for the next one! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
@codex review Please review the current head, |
|
Codex Review: Didn't find any major issues. You're on a roll. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
…iew-575-f533 # Conflicts: # sdk/typescript/src/cli.ts
|
@codex review Please review the current head, |
|
Codex Review: Didn't find any major issues. 🎉 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
Codex Review: Didn't find any major issues. Already looking forward to the next diff. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Keep legacy repositories separate when preparing matching inputs, simplify finding alias bookkeeping, and retain the shared workbench stdin API. Use platform-aware Python probes and exercise comparison payloads larger than command-line limits.
|
Codex Review: Didn't find any major issues. Chef's kiss. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
Before I approve this PR, please refresh it onto the current #574 head ( Please resolve the stack against the reconciled canonical plugin source and migration history, preserving #574's migration 40 and synchronized plugin metadata. Then rerun full exact-head CI and request fresh code/security review. The existing successful checks and approval validate the old parent, not the updated stack. I do not have a separate feature-design blocker; the required change is to reconcile and revalidate the child on its current parent. |
kmbroai
left a comment
There was a problem hiding this comment.
Approved for the feature implementation at 222e398877b37f186171847e920b752c13b37a17.
This approval does not clear the stack-integration blocker: the PR is currently conflicting with its updated #574 base. Resolve that conflict, preserve the reconciled migration and plugin-source changes, and obtain fresh exact-head CI/review before merge.
|
@codex review Please review current head |
|
Codex Review: Didn't find any major issues. 👍 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
There was a problem hiding this comment.
💡 Codex Security Review
Here are some automated security review suggestions for this pull request.
Reviewed commit: f17ed63000
ℹ️ About Codex security reviews in GitHub
This is an experimental Codex feature. Security reviews are triggered when:
- You comment "@codex security review"
- A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review
Once complete, Codex will leave suggestions, or a comment if no findings are found.
|
@codex review Please review head Focused catalogue, comparison, and comparison-property tests: 106 passed and 3 Windows-only skips. SDK TypeScript check, plugin bundle generation, package smoke-script syntax, changed-file formatting, and git diff --check passed. The full suite is left to CI. |
|
Codex Review: Didn't find any major issues. Chef's kiss. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Summary
Match repeated findings across scan history using compact catalogues, paged evidence, and deterministic confirmed identities. This PR now targets
mainafter #574 merged and reuses existing Codex authentication.Changes
matchScanFindingswith self-contained public input, result, progress, cancellation, and reasoning-effort types. No additional public CLI syntax or defaults change.mainata82fc14, preserving the canonical plugin source, migration history, plugin metadata, native command authentication, interactive budget increases, shared test fixtures, and existing public API exports.Testing
Merge conflict resolution at
0eb54b1bb4b93d837a332ca699bcb29492fa2470againstmainat6750642c94edce8d60112f816631de05dc10efd6:Earlier validation recorded for prior heads:
f17ed63000f7c4cadaa17eecbd4fd1be6c1933d4, seed12345: 2,273 passed, 43 skipped, 0 failures across 114 files.f17ed63000f7c4cadaa17eecbd4fd1be6c1933d4: four sealed scans, six scan pairs, catalogue and evidence turns, cached reruns without model calls, forced recomputation, related-finding separation, SIGINT, invalid model output, and all 16 sealed artifact hashes preserved.model_providerandmodel_providerscould not redirect the synthetic API key or finding prompt. Verified both an explicit repository working directory and a process launched from that repository.f17ed63000f7c4cadaa17eecbd4fd1be6c1933d4passed under Node 24.15.0, including archive inspection, public imports, NodeNext declarations, CLI and SDK lifecycle checks, credential locking, MCP initialization, dashboard assets, and nested worker startup without global Codex.Risk and rollout
#574 is merged. Saved comparisons are not rewritten automatically; the existing forced matching command recomputes them when requested. Preserve globally unique occurrence IDs, confirmed identity validation, read-only matching with repository instructions, tools, MCP, and network disabled, and separate related findings. The single-turn automatic matching guard is not a dollar-accurate spending guarantee.
The bundled Codex 0.149.1 already filters provider, endpoint, and profile settings from project configuration, before merging those project layers. The native-request probes above confirm this existing protection against the automated provider-redirection review concern.
Public disclosure review
Existing commit metadata and automated comments contain author contact metadata and account-specific links, so the second attestation remains unchecked. The new commits use GitHub noreply author and committer addresses; fixtures and examples are synthetic.