Codex Security Cloud: Scan Your Repo While You Sleep OpenAI shipped Codex Security Cloud at DevDay 2026, an always-on vulnerability scanner that connects to GitHub repositories, generates a project-specific threat model, validates suspected vulnerabilities in an isolated sandbox, deduplicates findings, and drafts pull request patches, with a companion open-source CLI (@openai/codex-security) for local and CI/CD scans. The CLI runs on Node.js 22+ and Python 3.10+, exports SARIF output for GitHub code-scanning alerts or GitLab SAST dashboards (GitLab Ultimate 19.2+ for native ingestion), and exits with three codes — 0 for complete coverage, 1 for findings above the severity threshold, and 2 for errors or incomplete coverage, which is not a pass. OpenAI positions the product as complementing existing SAST tools such as Snyk, Semgrep, and CodeQL rather than replacing them, with cloud scans continuing while the developer's laptop is closed, powered by OpenAI's Daybreak Blue cybersecurity models. OpenAI shipped Codex Security Cloud at DevDay 2026: an always-on vulnerability scanner that connects to your GitHub repository and keeps investigating findings after you close your laptop. It generates a project-specific threat model, attempts to validate suspected vulnerabilities in an isolated sandbox, deduplicates noise, and drafts pull request patches — all without you watching. A companion open-source CLI @openai/codex-security handles local scans and CI/CD integration. This is not another linting rule set. It is the first mainstream agentic security product aimed squarely at development teams. Why the Async Model Matters Traditional SAST tools — Snyk, Semgrep, CodeQL — are synchronous. They run when triggered, block your pipeline waiting for results, and hand you a list of pattern-matched findings to sort through. The ratio of false positives to real vulnerabilities is high enough that many teams learn to tune them down or ignore them entirely. Codex Security Cloud does something structurally different. It runs in the background. Connect a repository, set a schedule or enable commit-triggered scanning, and the system keeps working when your machine is off. More importantly, it attempts to validate each finding by trying to exploit it in an isolated environment before surfacing it. A finding that cannot be exercised in a sandbox does not make the list. The result is a shorter, more credible finding set — which is the actual problem traditional SAST has never solved. OpenAI is explicit that this complements existing SAST rather than replacing it. Semgrep is still faster for broad, repeatable pattern checks on large codebases. Codex Security handles the contextual reasoning work that rule-based tools cannot. Think of it as a security researcher running in parallel with your existing toolchain, not a replacement for it. Three Modes: Cloud, PR, and CLI The product ships as three overlapping scanning surfaces: Cloud mode is the async layer. You connect a GitHub repository through the Codex Security plugin in ChatGPT desktop or web . The initial scan generates a threat model — attacker entry points, trust boundaries, sensitive data flows, critical code paths — that you can customize. Subsequent scans focus on newly introduced code, not the full repo each time. All of this continues while your laptop is closed, powered by OpenAI’s Daybreak Blue cybersecurity models https://the-decoder.com/openai-expands-codex-and-its-api-at-devday-with-security-scans-a-decisions-api-and-ultrafast/ included at no extra application process. PR mode runs automatically on pull requests. Before a human reviewer touches the code, Codex Security does a first-pass security review — reading the diff in context of the surrounding codebase, not just the changed lines. This surfaces issues that diff-only linters miss. CLI mode is the local and CI/CD layer. The open-source package https://community.openai.com/t/introducing-the-open-source-codex-security-cli/1388319 runs on Node.js 22+ and Python 3.10+. Install it, authenticate, scan: npx @openai/codex-security@latest scan . --auth chatgpt --output-dir ./scan-results The CLI exports SARIF output, which feeds into GitHub code-scanning alerts or GitLab SAST dashboards GitLab Ultimate 19.2+ required for native ingestion . A pre-commit hook is a single command: npx @openai/codex-security@latest install-hook The hook scans staged and unstaged changes and blocks High findings by default before the commit goes through. The Exit Code You Cannot Ignore One detail that matters for CI/CD integrations: the CLI exits with three codes, not two. - Exit 0 : Complete coverage, policy passed - Exit 1 : Findings above your severity threshold - Exit 2 : Errors or incomplete coverage — this is not a pass Most security tools exit 0 or 1. Exit code 2 means the scan did not fully complete — and that is not a pass. It means something in the setup, environment, or scope prevented comprehensive analysis. Treat it as a pipeline failure and investigate. Teams that configure CI gates expecting only exit 1 to be a failure will quietly get incomplete coverage without knowing it. This is the kind of detail that bites teams in production. What to Know Before You Roll It Out Codex Security Cloud launched as a research preview at DevDay, not general availability. A few gaps matter for planning: - Plus plan is excluded — Only Pro, Business, Enterprise, and Edu plans get Cloud access. Individual developers on Plus are out for now. - GitLab gets CLI only — The Cloud product connects to GitHub. GitLab teams use the CLI with SARIF export to their dashboards. - Costs are not fully transparent — Seat pricing starts at $125/month for five Standard Business seats, but scan usage is billed separately on a token basis. Actual costs at scale are unpublished. - Human review is mandatory — The system generates draft pull requests with proposed patches. It never merges anything. This is intentional design, not a gap. The Bottom Line The “scan while you sleep” framing is marketing, but the underlying architectural shift is real. Security tooling is moving from synchronous rule evaluation to async agentic investigation — the same structural move that has already happened across coding assistants, code review, and CI/CD. Codex Security Cloud is the first mainstream product to make that shift explicit for vulnerability management. If you are already running Snyk or Semgrep, the question is not whether to replace them. It is whether async background scanning with attempted validation is worth the additional cost and preview-grade stability risk. For most teams, the async model is worth it. The preview stability question depends on your tolerance for a product that will change while you are using it. The CLI is Apache 2.0 and available today for lower-risk evaluation. Start with a local scan https://omidsaffari.com/blog/codex-security-cloud-cli-devday-2026 before committing to cloud-scale token costs. If the findings quality is meaningfully better than what your existing SAST produces, the upgrade path is straightforward. If not, the CLI costs you nothing to run and nothing to remove. For context on the broader DevDay 2026 developer platform changes — Agents API computer use, GPT-6.1 Sol, Dots — see the full Codex Cloud feature breakdown https://nerdschalk.com/codex-cloud-code-review-security-cloud/ . The security piece is one part of a larger push to make Codex a development platform rather than just a coding assistant.