Use Codex to investigate security risks in your code and dependencies, then develop and test fixes. Start with a repository, a code change, or findings from tools you already use.
Find vulnerabilities
Start with a scan of one repository, run a deeper review, or scan a repository inventory. Automate scans in CI to review code on a schedule or as it changes. Review the findings and coverage to decide where to investigate next.
Run your first security scan
Use the Codex Security plugin to scan a local repository, review the evidence and coverage...
Run a deep security scan
Use the Codex Security plugin to run a more comprehensive audit of a repository or scoped...
Scan multiple repositories
Use the Codex Security CLI to scan a list of repositories at specific commits, review each...
Automate security scans in CI
Add the Codex Security CLI to your CI pipeline
Review changes and dependencies
Check a pull request or local diff for security regressions, or assess your repository’s exposure to a package or supply chain advisory. Gather evidence before deciding what needs action.
Scan code changes for security
Use the Codex Security plugin to examine a Git-backed change set, validate plausible...
Audit dependency incidents
Use Codex to turn a public package or supply chain advisory into a read-only audit, then...
Fix and verify findings
Turn a reviewed scan finding into a focused patch, or work through findings from an existing backlog. Review each change and its verification evidence before preparing it for merge.