Skip to content

feat(cli): run standalone validation after scan - #1007

Open
mldangelo-oai wants to merge 1 commit into
mainfrom
mdangelo/codex/scan-validate
Open

mldangelo-oai wants to merge 1 commit into
mainfrom
mdangelo/codex/scan-validate

Conversation

@mldangelo-oai

Copy link
Copy Markdown
Collaborator

Summary

Add opt-in scan --validate to run the existing standalone finding validation workflow after a completed scan. The separate validate command remains available.

Changes

  • Pass reported findings directly to the validator and run it from the scan output directory with the repository as a read target.
  • Save the assessment as validation.md, include its status and path in JSON output, and retain the completed scan if validation fails.
  • Keep the flag off by default. Reject combinations with dry-run, mock scans, and scan cost limits because the follow-up model call cannot enforce the scan limit.
  • Cover success, failure, interruption, cost-limit handling, and an existing report path with focused CLI tests.

Testing

  • Linux dev box: build, TypeScript types, format, and focused CLI tests passed on current main (162 tests). The full SDK suite passed with both fixed and random seeds (3,179 passed, 50 skipped, 0 failed).
  • macOS: TypeScript types, format, and focused CLI tests passed. The full SDK suite passed with both fixed and random seeds (3,172 passed, 57 skipped, 0 failed).
  • Built CLI help exposed --validate; the incompatible dry-run combination returned the expected error.
  • A live run against a synthetic local fixture saved the validation report and left the target source unchanged.

Risk and rollout

The new pass is opt-in and makes additional model calls. It does not rewrite sealed scan findings or change the severity failure policy. Validation failure exits with status 2 while preserving the completed scan. No migration is required.

Public disclosure review

  • No customer, partner, prospect, or user identities, data, or identifying details are included.
  • No credentials, personal data, private source, scan findings, or nonpublic links or tickets are included.
  • I reviewed the branch name, title, description, commits, changes, comments, logs, screenshots, attachments, and links for public disclosure.

@github-actions github-actions Bot added the enhancement New feature or request label Sep 23, 2026
@mldangelo-oai
mldangelo-oai marked this pull request as ready for review September 23, 2026 19:08
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-23T19:13:12.677713Z 5943f48 Draft marked ready
🔒 Security Review ✅ Completed 2026-09-23T19:15:20.471811Z 5943f48 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5943f48930

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread sdk/typescript/src/cli.ts
...providerOptions,
safetyIdentifier: arguments_.safetyIdentifier,
auth,
directory: result.scanDir,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Keep sealed artifacts out of the validator's writable root

For every nonempty --validate scan, passing result.scanDir as directory makes runSkill launch Codex with the entire completed scan directory as its workspace-write root. A validator influenced by repository/finding content can therefore overwrite findings.json, coverage.json, scan-manifest.json, or other sealed artifacts; because scanData was captured before validation and the seal is not rechecked afterward, the command can report success while leaving scan history and later exports corrupted. Run validation in a separate writable workspace or verify/protect every sealed artifact across the model call.

AGENTS.md reference: sdk/typescript/AGENTS.md:L23-L23

Useful? React with 👍 / 👎.

Comment thread sdk/typescript/src/cli.ts
safetyIdentifier: arguments_.safetyIdentifier,
auth,
directory: result.scanDir,
validationRepository: repository,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Validate the same checkout that produced the findings

If the checkout changes after security.run() returns or while the second model call is running, validation reads the live repository even though the scan's target observer has already been closed and targetWarnings can no longer be updated. The resulting report is then marked complete against code that may differ from the code which produced the supplied findings. Preserve the scanned snapshot for this pass or recheck the target digest before and after validation.

AGENTS.md reference: sdk/typescript/AGENTS.md:L23-L23

Useful? React with 👍 / 👎.

),
).toBe(0);
expect(validationPrompt).toContain("Example finding");
expect(validationPrompt).toContain("Leave the repository unchanged.");

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Avoid pinning the test to validation prompt prose

This assertion makes the test depend on one exact English sentence in the generated prompt, so a harmless wording change breaks the suite without changing observable validation behavior. Assert a stable contract or behavioral boundary instead of the Markdown prose, as required by the scoped test guidance.

AGENTS.md reference: sdk/typescript/AGENTS.md:L35-L35

Useful? React with 👍 / 👎.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant