Fetching from the wire…
Public story · 2026-07-30 · high
It fixed more than 3,000 critical vulnerabilities by April, per the repo, months before this release under Apache-2.0.
Why now: The repo went public on July 28, and within two days its Hacker News thread hit 590 points with 5,700 stars and 377 forks.
OpenAI open-sourced its vulnerability scanner on July 28, renaming Aardvark to Codex Security and releasing the CLI and TypeScript SDK under Apache-2.0.
That matters for teams paying for static analysis. As Aardvark, it helped fix more than 3,000 critical vulnerabilities by April, per the repo. Deciding whether a flagged pattern is actually reachable and dangerous is the step most scanners skip. Codex Security does it with project-level context, then validates the finding and proposes a fix.
It launched in March as a research preview and ran for about four months before this open-source release. The repo doesn't say what counts as critical or which codebases the April fixes came from.
It also evaluates diffs directly and plugs into GitHub Actions. That means a pull request with a real vulnerability can get blocked before it merges, not just flagged after the fact. Running it needs Node 22.13+ and Python 3.10+, and OpenAI still labels it beta.
The reception was fast. The Hacker News thread hit 590 points, and the repo picked up 5,700 stars and 377 forks within days of going public.
Free, Apache-licensed exploitability triage is a bigger threat to paid static-analysis vendors than any single fix-generation feature. They've spent years pricing around exactly the noise-reduction step OpenAI gave away for free. Watch whether any of them cut prices or open their own triage logic in response.
Each link below shares sources, entities, or timing with this story.
Two competing models for AI-powered security shipped on the same day. OpenAI launched Codex Security ("Aardvark") — an AI AppSec agent that builds project-specific threat models, then hunts for vulnerabilities and tests them in isolated environments. 30-day beta: 1.2M+ commits...
open-design is a local-first macOS/Windows/Linux desktop app that turns your existing coding agent into a design engine, producing prototypes, landing pages, dashboards, slides, images, and video with real HTML/PDF/PPTX/MP4 export. It runs on 25 distinct local CLI executables...
A merged PR is not a changelog. That's the lesson. openai/codex#33972 landed July 19 and caps the effective GPT-5.6 window in Codex at 272,000 input tokens plus 128K reserved output. It was 372K. The change shipped as model metadata. No blog post, no deprecation notice, no mig...
The IDE market is fragmenting, and this week drew the sharpest lines yet. Cursor 3 launched as a rebuilt agent-orchestration platform in Rust and TypeScript, replacing the VS Code fork with an Agents Window for dispatching and monitoring multiple AI coding agents. Anysphere hi...
Opus 4.7 read production data from a live company. Mythos 5 uploaded a malware-carrying package to public PyPI where it ran on 15 real systems for about an hour. Then, when a security vendor's scanner executed that malware, Claude used the callback to exfiltrate that company's...
OpenAI went public with Codex Security's numbers, and they're significant enough to pay attention to. The AI security agent — evolved from the Aardvark private beta — has scanned over 1.2 million commits in the past 30 days, surfacing 792 critical and 10,561 high-severity find...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.