Skip to content

chore(evals): update Codex SDK to 0.151.0 - #755

Open
mldangelo-oai wants to merge 3 commits into
mainfrom
mdangelo/codex/triage-sdk-0.151.0
Open

chore(evals): update Codex SDK to 0.151.0#755
mldangelo-oai wants to merge 3 commits into
mainfrom
mdangelo/codex/triage-sdk-0.151.0

Conversation

@mldangelo-oai

Copy link
Copy Markdown
Collaborator

Summary

The triage evaluation harness pins Codex SDK 0.137.0. Update it to 0.151.0, the public npm latest release verified on August 30, 2026, so evaluations use the current published SDK and its matching Codex CLI.

Changes

  • Pin @openai/codex-sdk to 0.151.0 and update its CLI and six platform package entries in the lockfile.
  • Preserve all unrelated dependency resolutions, including Promptfoo and the OpenCode SDK. Production dependencies and product version numbers are unchanged.

Testing

  • Frozen-lockfile installation with pnpm 11.9.0: passed.
  • All eight updated package integrity hashes match metadata fetched directly from the public npm registry; unrelated lockfile entries are unchanged.
  • All deterministic triage and SastBench harness checks: passed.
  • Promptfoo configuration validation: passed.
  • Actual Promptfoo provider initialization loads SDK 0.151.0; its selected executable reports codex-cli 0.151.0.
  • Required plugin Ruff checks, formatting, portable source compatibility checks, and git diff --check: passed.

Risk and rollout

This affects the evaluation harness only. Production remains on Codex SDK 0.149.1. No model-backed evaluations were run, so these checks do not establish benchmark score equivalence.

Because 0.151.0 is younger than the harness's seven-day dependency-age window, lockfile generation used a temporary exception limited to the eight exact Codex package versions. The existing age policy is unchanged, and no persistent exception is included.

This PR does not publish packages or change public CLI behavior.

Public disclosure review

  • No customer, partner, prospect, or user identities, data, or identifying details are included.
  • No credentials, personal data, private source, scan findings, or nonpublic links or tickets are included.
  • I reviewed the branch name, title, description, commits, changes, comments, logs, screenshots, attachments, and links for public disclosure.

@mldangelo-oai
mldangelo-oai marked this pull request as ready for review August 30, 2026 14:01
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 30, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-09-01T00:57:51.464955Z 94a25b3 New commits
🔒 Security Review Completed 2026-09-01T00:59:34.702194Z 94a25b3 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@mldangelo-oai

Copy link
Copy Markdown
Collaborator Author

@codex review

Please review the current head 1d1debf2b72d1180012f41d0e5f2c80b522758e9.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Swish!

Reviewed commit: 1d1debf2b7

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mldangelo-oai

Copy link
Copy Markdown
Collaborator Author

@codex review

Please review the current head 9d9349c0a2fd25865dbc9944e597337d7c8f29d7.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Delightful!

Reviewed commit: 9d9349c0a2

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

* chore(deps): automate updates with a release cooldown

* fix(deps): group Codex security updates

* fix(deps): use the supported daily update schedule
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant