forked from ilysenko/codex-desktop-linux
-
Notifications
You must be signed in to change notification settings - Fork 0
Review npm CLI auto-upgrade trust #65
Copy link
Copy link
Open
Labels
audience/maintainerMaintainer-facing work itemMaintainer-facing work itembacklogMigrated backlog itemMigrated backlog itempriority/mediumMedium priority backlog itemMedium priority backlog itemsecuritySecurity backlog itemSecurity backlog item
Metadata
Metadata
Assignees
Labels
audience/maintainerMaintainer-facing work itemMaintainer-facing work itembacklogMigrated backlog itemMigrated backlog itempriority/mediumMedium priority backlog itemMedium priority backlog itemsecuritySecurity backlog itemSecurity backlog item
Summary
Review and tighten trust handling for automatic
@openai/codexCLI upgrades.Source
Migrated from
docs/maintainers/security-backlog.md.Maintained Docs
docs/maintainers/security-backlog.mddocs/maintainers/threat-model.mddocs/maintainers/package-runtime-maintenance.mdContext
The launcher/updater preflight can query npm for the latest
@openai/codexversion and install that exact version globally or under~/.local. Missing CLI installation is interactive, but upgrades still trust npm latest-state.Review Gate
Run the
@codex-securityworkflow before treating implementation as review-ready.Desired State