Fetching from the wire…
Public story · 2026-07-30 · high
It fixed more than 3,000 critical vulnerabilities by April, per the repo, months before this release under Apache-2.0.
Why now: The repo went public on July 28, and within two days its Hacker News thread hit 590 points with 5,700 stars and 377 forks.
OpenAI open-sourced its vulnerability scanner on July 28, renaming Aardvark to Codex Security and releasing the CLI and TypeScript SDK under Apache-2.0.
That matters for teams paying for static analysis. As Aardvark, it helped fix more than 3,000 critical vulnerabilities by April, per the repo. Deciding whether a flagged pattern is actually reachable and dangerous is the step most scanners skip. Codex Security does it with project-level context, then validates the finding and proposes a fix.
It launched in March as a research preview and ran for about four months before this open-source release. The repo doesn't say what counts as critical or which codebases the April fixes came from.
It also evaluates diffs directly and plugs into GitHub Actions. That means a pull request with a real vulnerability can get blocked before it merges, not just flagged after the fact. Running it needs Node 22.13+ and Python 3.10+, and OpenAI still labels it beta.
The reception was fast. The Hacker News thread hit 590 points, and the repo picked up 5,700 stars and 377 forks within days of going public.
Free, Apache-licensed exploitability triage is a bigger threat to paid static-analysis vendors than any single fix-generation feature. They've spent years pricing around exactly the noise-reduction step OpenAI gave away for free. Watch whether any of them cut prices or open their own triage logic in response.
Each link below shares sources, entities, or timing with this story.
Codex Security benchmarked against OpenSSH / Shared entities / Same source domain / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (Codex Security benchmarked against OpenSSH); both cover Aardvark, Codex Security, OpenAI; reported by the same outlet (github.com).
OpenAI released Codex Security / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (OpenAI released Codex Security); both cover Apache, CLI, OpenAI; reported by the same outlet (github.com).
Linked by a graph relationship (OpenAI released Codex Security); both cover Hacker News, July, OpenAI; reported by the same outlet (github.com).
OpenAI released Codex Security / Shared entities / Same source domain / Earlier coverage / Tension
Linked by a graph relationship (OpenAI released Codex Security); both cover CLI, Hacker News, OpenAI; reported by the same outlet (github.com).
Codex Security benchmarked against OpenSSH / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Codex Security benchmarked against OpenSSH); both cover Aardvark, Codex Security, OpenAI; overlapping topics (codex, context, vulnerability).
OpenAI released Codex / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (OpenAI released Codex); both cover Apache, July; reported by the same outlet (github.com).
OpenAI released Codex Security / Shared entities / Same source domain / Earlier coverage
Linked by a graph relationship (OpenAI released Codex Security); both cover CLI, July, OpenAI; reported by the same outlet (github.com).
OpenAI released Codex Security / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (OpenAI released Codex Security); both cover Apache, April, OpenAI; overlapping topics (context, drop).