Skip to content

ci: scan maintained JavaScript and Python with CodeQL - #823

Merged
jbeckwith-oai merged 1 commit into
mainfrom
codex/ruby-sdk-health-codeql
Oct 9, 2026
Merged

jbeckwith-oai merged 1 commit into
mainfrom
codex/ruby-sdk-health-codeql

Conversation

@jbeckwith-oai

Copy link
Copy Markdown
Contributor

Maintained browser examples and JavaScript/Python repository tooling were omitted from the security CodeQL matrix. Add javascript-typescript and python to the existing PR, main, and merge-group analyses, preserving Ruby/Actions coverage and the existing all-findings rejection step.

Updated the focused workflow regression tests. Validation: 10 tests / 40 assertions pass; rubyfmt and git diff --check pass. Two independent review rounds found no blockers. Full Bundler checks require CI because the local checkout lacks its locked dependencies.

The existing native CodeQL ruleset now requires all alert severities; no new check names were invented or protections bypassed. This addresses both SDK Health Code scanning and its derived GitHub security coverage finding. Main-head coverage remains pending merge and successful analysis; this PR does not claim a current-main Green rating.

@jbeckwith-oai
jbeckwith-oai requested a review from a team as a code owner October 9, 2026 20:50
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-09T20:52:26.635015Z d7c5999 PR opened
🔒 Security Review ✅ Completed 2026-10-09T20:52:46.563139Z d7c5999 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@openai-sdks

openai-sdks Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

OkTest Summary

❌ Failed for Ruby SDK PR #823.

View OkTest run #37989711081

SDK merge (ef901c324c84) · head (d7c59992ea53) · base (ab350864252b) · OkTest (aae4f6a5102a)

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Castiron custom code

Evaluated main: ab350864252bdc66f45f9e398032ad162c6a95b2.

✅ No new custom-code files detected.

84 mixed files remain; 0 existing customizations changed.

Compared ab350864252b → d7c59992ea53. Generated baselines verified.

84 existing customizations unchanged
  • lib/openai.rb
  • lib/openai/client.rb
  • lib/openai/models/audio/transcription_create_response.rb
  • lib/openai/models/audio/translation_create_response.rb
  • lib/openai/models/audio/voice_create_params.rb
  • lib/openai/models/beta/agents/vault_status_filter.rb
  • lib/openai/models/chat/chat_completion_message.rb
  • lib/openai/models/chat/chat_completion_message_function_tool_call.rb
  • lib/openai/models/chat/completion_create_params.rb
  • lib/openai/models/image_edit_completed_event.rb
  • lib/openai/models/image_edit_partial_image_event.rb
  • lib/openai/models/image_gen_completed_event.rb
  • lib/openai/models/image_gen_partial_image_event.rb
  • lib/openai/models/images_response.rb
  • lib/openai/models/response_format_json_schema.rb
  • lib/openai/models/responses/function_tool.rb
  • lib/openai/models/responses/response.rb
  • lib/openai/models/responses/response_create_params.rb
  • lib/openai/models/responses/response_format_text_config.rb
  • lib/openai/models/responses/response_format_text_json_schema_config.rb
  • lib/openai/models/responses/response_function_tool_call.rb
  • lib/openai/models/responses/response_function_web_search.rb
  • lib/openai/models/responses/response_output_text.rb
  • lib/openai/models/responses/tool.rb
  • lib/openai/models/webhooks/webhook_endpoint_with_secret.rb
  • lib/openai/resources/audio/transcriptions.rb
  • lib/openai/resources/audio/translations.rb
  • lib/openai/resources/beta/agents/environments/files.rb
  • lib/openai/resources/beta/agents/sessions.rb
  • lib/openai/resources/beta/agents/sessions/artifacts.rb
  • lib/openai/resources/beta/threads.rb
  • lib/openai/resources/chat/completions.rb
  • lib/openai/resources/containers/files.rb
  • lib/openai/resources/files.rb
  • lib/openai/resources/responses.rb
  • lib/openai/resources/vector_stores/file_batches.rb
  • lib/openai/resources/vector_stores/files.rb
  • lib/openai/resources/webhooks.rb
  • rbi/openai/client.rbi
  • rbi/openai/models/audio/transcription_create_response.rbi

44 more in the full report.

A changed generated baseline means this report cannot reliably identify which handwritten lines changed.

Inspect the custom-code diff

Download the exact patch produced by this run (requires repository access):

gh run download 37989763666 --repo openai/openai-ruby \
  --name castiron-custom-code-37989763666-1 --dir /tmp/castiron-custom-code-37989763666-1
git apply --stat /tmp/castiron-custom-code-37989763666-1/custom-code.patch
cat /tmp/castiron-custom-code-37989763666-1/custom-code.patch

Or reproduce it from an SDK checkout containing the vendored reporter:

git fetch --no-tags origin ab350864252bdc66f45f9e398032ad162c6a95b2 d7c59992ea537d3293d944b03cf30a94b5c631a3
python3 scripts/castiron/custom_code_report.py report \
  --base ab350864252bdc66f45f9e398032ad162c6a95b2 \
  --head d7c59992ea537d3293d944b03cf30a94b5c631a3 --fetch --require-head-hash --public \
  --out /tmp/castiron-custom-code-d7c59992ea53
cat /tmp/castiron-custom-code-d7c59992ea53/custom-code.patch

This is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR.

Full report and patch

@jbeckwith-oai

Copy link
Copy Markdown
Contributor Author

Readiness correction: all 20 native repository checks passed (two intentionally skipped), but overall CI is not green. The external OkTest report is FAILED for head d7c59992ea537d3293d944b03cf30a94b5c631a3 and merge revision ef901c324c8424c4353fb61ab6ac9f493b5c1b11.

I verified run 37989711081 / job 114020884900: Docker Hub returned HTTP 429 to the ruby:3.3-slim manifest HEAD request during the Ruby bridge image build, before tests. The missing ruby.json artifact is a downstream consequence. This establishes an infrastructure blocker, not a Ruby source defect.

No retry, registry/authentication/permission change, or gate bypass was performed. Keep the external failure unresolved pending normal service recovery or separately authorized recovery; native CodeQL success does not replace OkTest validation.

@markstuart-oai markstuart-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed d7c59992ea537d3293d944b03cf30a94b5c631a3. The new languages use the existing CodeQL job and separate output directories. They keep the pinned actions and SARIF findings gate. Actions and Ruby coverage, limited permissions, and checkout credential handling remain intact. The updated assertions cover all four languages. I found no actionable issues in this two-file change.

The repository's reported checks passed or were intentionally skipped, including all four CodeQL jobs. External OkTest remains failed for this exact head. Its Docker Hub image request returned HTTP 429 before compatibility tests started, so overall CI remains incomplete. I reviewed source and hosted CI evidence without running local tests. Main-branch coverage still needs validation after merge.

@jbeckwith-oai
jbeckwith-oai added this pull request to the merge queue Oct 9, 2026
Merged via the queue into main with commit d460a5a Oct 9, 2026
22 checks passed
@jbeckwith-oai
jbeckwith-oai deleted the codex/ruby-sdk-health-codeql branch October 9, 2026 22:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants