Skip to content

OpenAI Launches Codex Security Cloud to Scan GitHub Repos and Draft Fixes

· by Pondero Newsdesk

The short version

OpenAI's Codex Security Cloud scans entire GitHub repositories on demand or on a schedule, triages and de-duplicates findings, and drafts pull-request fixes without a laptop open.

OpenAI Launches Codex Security Cloud to Scan GitHub Repos and Draft Fixes

A security team can now point Codex at an entire GitHub organization and get triaged, de-duplicated findings with a draft pull-request fix attached, no engineer needed to kick off or babysit the scan. OpenAI introduced Codex Security Cloud on September 29 at DevDay 2026, per the company's DevDay recap, and it is live now, not a future-quarter promise.

What happened

Codex Security Cloud scans entire GitHub repositories on demand or on a set schedule, with ongoing checks on new commits, per OpenAI's DevDay recap. The agent investigates each finding, removes duplicates, and prepares a fix in the cloud even when the user's laptop is closed. Access comes bundled with models offered through OpenAI's Daybreak Blue security tier, without requiring a separate Daybreak application, according to the same recap. The setup runs as a ChatGPT plugin: install it from the plugin marketplace, connect GitHub, pick a repository and a Codex cloud environment, and start a scan, per the setup documentation. It is available now to Pro, Business, Enterprise, and Edu users on desktop and web.

Fix-with-Codex turns a finding into a draft PR, not just a ticket

The workflow differs from a traditional scanner in one specific way: findings open into a proposed patch. Selecting "Fix with Codex" on a finding generates a remediation, and a reviewer can send it straight to a draft pull request rather than filing a ticket and waiting for someone to pick it up, per the setup docs. Ongoing monitoring works the same way. Once a repository is connected, switching a scan's "what to scan" setting from Repository to Commit changes turns the tool into a standing watcher on that repo, with adjustable history depth and a pause/resume toggle per repository. For a security team already stretched across dozens of repos, that closes the gap between "we found it" and "someone fixed it" instead of just adding another dashboard to check.

Context and reactions

Codex Security Cloud lands inside OpenAI's broader Daybreak push, which the company frames as a governed cyber defense stack combining frontier models, the Codex harness, and trusted workflows, and for which OpenAI is offering $1 billion in credits to defenders. The launch also puts OpenAI in direct competition with tools already in Pondero's coverage: Cursor shipped its own automated Security Review bot on September 23, now averaging 3.8 minutes per pull-request scan, per Cursor's blog post. GitHub's Copilot also ships code-scanning and autofix features. What is new here is the scope: Codex Security Cloud works at the whole-repository and whole-organization level with scheduled re-scans, rather than gating on individual pull requests.

What to watch next

OpenAI has not published independent benchmarks for Codex Security Cloud's false-positive rate or fix quality on real-world repositories. Whether outside security researchers test it against known-vulnerable codebases, and how its results compare to Cursor's and GitHub's existing scanners, is the open question for the weeks ahead.

Sources