Pattern: Vendors Are Racing to Own the Security Gate in the Merge Path
Within 48 hours, OpenAI open-sourced a Codex Security CLI that installs as a CI/CD check and tracks findings across runs, GitHub took Copilot code review's agent skills and MCP support to GA for Pro through Enterprise so teams' own tools and standards run inside every review, and CodeQL 2.26.1 shipped accuracy and framework-coverage improvements. The strategic read: as agents generate more code than humans can review, the review gate becomes the highest-leverage place to sell — and both labs now want their scanner to be the one sitting between agent output and main. Practical consequence for builders is that a first-party, agent-aware scanner is now free in both ecosystems, so the argument for a third-party one has to be portfolio-wide coverage rather than depth.
↳ Follow the thread