Tools
Promptfoo adds a Codex Security SDK provider and hardens its code-scan GitHub Action supply chain
promptfoo 0.122.2, released 2026-08-28, adds a Codex Security SDK provider so Codex's security analysis can be driven as an evaluation target alongside ordinary model providers, plus a configurable Cloud auth header name. The same day's code-scan-action 0.2.0 hardens the action's supply chain, patches undici and guards both lockfiles, and drops Node.js 20 as a breaking change. Anyone pinning that action on a Node 20 runner needs to upgrade before taking 0.2.0.
Source
↳ Follow the thread