Skip to content

chore(deps): bump the codex group across 3 directories with 2 updates - #968

Merged
mldangelo-oai merged 3 commits into
mainfrom
dependabot/npm_and_yarn/plugins/codex-security/mcp-app/codex-2ad6a7f258
Sep 18, 2026
Merged

mldangelo-oai merged 3 commits into
mainfrom
dependabot/npm_and_yarn/plugins/codex-security/mcp-app/codex-2ad6a7f258

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Update the bundled Codex CLI and TypeScript SDK from 0.154.0 to 0.155.0 so the CLI, MCP app, and triage evals use the same release.

Changes

  • Bump @openai/codex and @openai/codex-sdk in the TypeScript SDK and @openai/codex-sdk in the MCP app and triage eval package.
  • Update all three pnpm lockfiles, including the eval overrides and six native Codex distributions.

Testing

  • SDK and MCP app frozen-lockfile installs passed; the triage eval package's frozen-lockfile-only validation passed.
  • pnpm --dir sdk/typescript run types, run format, and run build:ci: passed.
  • pnpm --dir sdk/typescript run build:plugin: passed. The plugin source compatibility check and all nine checker tests passed.
  • The installed CLI reported codex-cli 0.155.0; its exec --help smoke check passed.
  • SDK runtime, authentication, preflight, and native-skill configuration tests: 183 passed, 23 platform-dependent cases skipped on macOS.
  • The MCP Deep Scan executor suite passed, including fresh and resumed workers and child-process configuration. The coordinator, parent-sandbox, and permission-preflight suites also passed.
  • The triage eval package's deterministic harness and configuration tests passed.

Risk and rollout

This updates the shipped runtime, so package verification and Windows, macOS, and Linux CI should pass before merge. Local verification used fixtures and CLI startup; no live model calls or real integration credentials were used. The TypeScript SDK source files are unchanged between the upstream release tags. No public wrapper CLI settings change.

Public disclosure review

  • No customer, partner, prospect, or user identities, data, or identifying details are included.
  • No credentials, personal data, private source, scan findings, or nonpublic links or tickets are included.
  • I reviewed the branch name, title, description, commits, changes, comments, logs, screenshots, attachments, and links for public disclosure.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 18, 2026
---
updated-dependencies:
- dependency-name: "@openai/codex"
  dependency-version: 0.155.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codex
- dependency-name: "@openai/codex-sdk"
  dependency-version: 0.155.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codex
- dependency-name: "@openai/codex-sdk"
  dependency-version: 0.155.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codex
- dependency-name: "@openai/codex-sdk"
  dependency-version: 0.155.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codex
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/plugins/codex-security/mcp-app/codex-2ad6a7f258 branch from a64792f to 5be1e94 Compare September 18, 2026 16:18
@mldangelo-oai

Copy link
Copy Markdown
Collaborator

@codex review the current head 205e555.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-18T16:44:58.999118Z 205e555 Manual request
🔒 Security Review ✅ Completed 2026-09-18T16:46:29.409436Z 205e555 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Already looking forward to the next diff.

Reviewed commit: 205e555652

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mldangelo-oai
mldangelo-oai merged commit b998318 into main Sep 18, 2026
68 of 80 checks passed
@mldangelo-oai
mldangelo-oai deleted the dependabot/npm_and_yarn/plugins/codex-security/mcp-app/codex-2ad6a7f258 branch September 18, 2026 17:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant