Skip to content

Upgrade codex and claude to latest - #178

Merged
cramforce merged 2 commits into
mainfrom
deps-09-23
Sep 23, 2026
Merged

cramforce merged 2 commits into
mainfrom
deps-09-23

Conversation

@cramforce

Copy link
Copy Markdown
Contributor

What changed

Why

Verification

  • pnpm test passes
  • pnpm lint passes
  • pnpm knip passes
  • If this adds a matcher: ran it against at least one real repo and confirmed the candidate count is sane

Notes for reviewer

@vercel

vercel Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
deepsec-website Ready Ready Preview, v0 Sep 23, 2026 12:57pm UTC
1 Skipped Deployment
Project Deployment Actions Updated
deepsec Ignored Ignored v0 Sep 23, 2026 12:57pm UTC

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​@​anthropic-ai/​claude-agent-sdk@​0.3.260 ⏵ 0.3.280100 +110092 +110070
Updatednpm/​@​openai/​codex@​0.153.2-win32-x64 ⏵ 0.156.110010093 +14100100
Updatednpm/​@​openai/​codex-sdk@​0.153.2 ⏵ 0.156.199100100100100

View full report

@auto-maintain

auto-maintain Bot commented Sep 23, 2026

Copy link
Copy Markdown

🤖 auto-maintain review

Automated, advisory triage for @cramforce's PR. Facts below are read from the GitHub API.

Check Result
Author's merged PRs (this repo) 69
Account established ✅ (age 6326d · 1154 followers · 98 public repos)
Commits signed/verified ✅ 2/2

Review panel: 🟡 medium highest severity

deepsec maintainer code review: 🟢 low

Dependency upgrades and lockfile updates are consistent; no actionable regressions found.

General code review: 🟡 medium

The dependency upgrade will not be published because the deepsec package version was not incremented.

  • packages/deepsec/package.json:3 — Bump the package version with these dependency updates. It remains 2.3.9, so release.yml will detect the already-published version and skip publishing; existing CLI users remain on Codex ^0.153.2 (<0.154.0) instead of receiving 0.156.1.

Scanner and matcher quality: 🟢 low

Dependency-only upgrade is internally synchronized; no scanner or matcher quality regressions found.

Sandbox and credential boundaries: 🟢 low

Pure dependency bump of @anthropic-ai/claude-agent-sdk (0.3.260→0.3.280) and @openai/codex[-sdk] (0.153.2→0.156.1) in packages/deepsec and packages/processor with a consistent lockfile update; no stale references to the old versions remain, both workspaces stay in version lockstep, and no sandbox, egress-allowlist, credential, or command-construction code hardcodes these versions (setup.ts resolves SDK/platform-binary versions dynamically from the installed host package), so no boundary behavior changes in the diff itself.

Durability and distributed state: 🟢 low

No durability or distributed-state issues found in the dependency-only upgrade.

Posted by auto-maintain. This automated code review is advisory; a human maintainer makes the call.

@cramforce
cramforce merged commit ce64674 into main Sep 23, 2026
10 of 11 checks passed

This branch is waiting to be deployed

1 active and 1 waiting deployments
Preview – deepsec-website — 5e35942d Deployed Sep 23, 2026 by vercel[bot]
deepsec-run — 5e35942d Waiting Sep 23, 2026 by cramforce via analyze #206
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant