For the complete documentation index, see llms.txt. Markdown versions of documentation pages are available by appending .md to the page URL.
Primary navigation

Security

Find and fix vulnerabilities in your code.

Use Codex to investigate security risks in your code and dependencies, then develop and test fixes. Start with a repository, a code change, or findings from tools you already use.

Find vulnerabilities

Start with a scan of one repository, run a deeper review, or scan a repository inventory. Automate scans in CI to review code on a schedule or as it changes. Review the findings and coverage to decide where to investigate next.

Review changes and dependencies

Check a pull request or local diff for security regressions, or assess your repository’s exposure to a package or supply chain advisory. Gather evidence before deciding what needs action.

Fix and verify findings

Turn a reviewed scan finding into a focused patch, or work through findings from an existing backlog. Review each change and its verification evidence before preparing it for merge.