## 新功能
- 新增交互式 `codex agents` 仪表板,可用于搜索、启动、打开、重命名和停止任务,并支持配置快捷键。(#39094、#39112、#39114、#39142)
- 在 TUI 会话中新增 `/cd`、`/pwd` 和 `/cwd` 命令,用于管理工作目录。(#38894)
- 新增 `codex queue`,用于向现有本地或远程会话发送消息。(#39092)
- 扩展 Vim 编辑功能,支持字符替换以及更多修改动作,例如 `cw`、`c$` 和 `cc`。(#39661)
- `codex doctor` 现在可以诊断端点保护、网络/代理故障、桌面应用状态以及更新连接情况。(#38827、#38918、#39060、#39074)
- SDK 用户现在可以传入精确的 CLI 配置覆盖项,并选择 `max` 或 `ultra` 推理强度。(#38817、#39662)
## Bug 修复
- 排队的消息现在可以可靠地唤醒空闲会话,更合理地解决重复会话名称问题,并保留粘贴或延迟命令的语义。(#39034、#39385、#39604)
- 恢复和分叉的线程现在会还原其活动权限配置,而不会悄然回退到当前默认值。(#39153)
- 修复重复显示子代理活动的问题,并加强 TUI 对子代理通知和审批的路由处理。(#39049、#39088)
- 实时 WebRTC sideband 连接现在会在传输意外丢失后重新连接,同时不会丢弃待处理的输出。(#39257)
- TUI 内联历史记录现在仍可在 Windows Terminal 的回滚缓冲区中使用。(#39619)
- 现在会限制非活动 TUI 线程的重放缓冲区大小,避免保留过多的流式输出。(#39081)
## 文档
- 明确外部贡献应通过 issue 和设计讨论提交,而不是通过拉取请求提交。(#39089)
- 记录安全开发容器中的 DNS 数据外泄风险及其信任限制。(#39283)
## 更新日志
完整更新日志:https://github.com/openai/codex/compare/rust-v0.148.0...rust-v0.149.0
- #38817 为 TypeScript SDK 添加原始配置覆盖项 @copyberry
- #38819 支持为保留的线程 ID 暂存元数据 @copyberry
- #38822 避免克隆 TUI 历史记录跨度内容 @copyberry
- #38823 避免在装饰超链接时为每个字符分配内存 @copyberry
- #38827 为 `codex doctor` 添加端点保护检查 @copyberry
- #38830 将外部编辑器缓冲区与沙箱可写路径隔离 @copyberry
- #38837 在 TUI 编辑器组件之间共享编辑器键位映射 @copyberry
- #38840 在远程控制握手中识别 Mac mini 主机 @copyberry
- #38893 独立恢复线程时间戳最大值 @copyberry
- #38894 为 TUI 添加工作目录命令 @copyberry
- #38899 将需求策略的归属转移至 execpolicy @copyberry
- #38902 遵循按环境配置的 shell 变量策略 @copyberry
- #38907 使用 Vim 向上翻查历史记录编辑排队消息 @copyberry
- #38913 填满列区域后停止渲染列 @copyberry
- #38916 遵循旧版 `:project_roots` 权限条目 @copyberry
- #38918 改进 `codex doctor` 的网络诊断 @copyberry
- #38919 拒绝已过时的 app-server 权限配置字段 @copyberry
- #38921 在 TUI 中压缩显示成功的命令活动 @copyberry
- #38940 添加实验性的 app-server 项目 API @copyberry
- #38941 防止 Noise 身份验证令牌传递给子进程 @copyberry
- #38942 强制执行特定环境的命令策略 @copyberry
- #38947 停止在 Windows 上加载旧版托管配置 @copyberry
- #38978 添加可配置的技能目录令牌预算 @copyberry
- #38980 限制 Guardian v2 父级压缩上下文的大小 @copyberry
- #38987 在 Guardian v2 记录中包含图像 @copyberry
- #38990 从模型目录获取 Guardian v2 默认值 @copyberry
- #38993 评估近期技能选择和按字符路由的技能选择 @copyberry
- #38994 移除应用和插件的工作区设置门控 @copyberry
- #38997 重试临时性的 Guardian 采样失败 @copyberry
- #39001 忽略过时的 Guardian 工具风险评分 @copyberry
- #39005 对托管的自动审查器禁用 Guardian V2 @copyberry
- #39006 从 app-server 发出 API 密钥回合成本遥测数据 @copyberry
- #39007 在审批测试中等待 Guardian 评分进度 @copyberry
- #39008 将任务上下文添加到影子技能选择中 @copyberry
- #39017 将 MCP 策略类型移入 `codex-protocol` @copyberry
- #39019 在 OAuth 请求期间隔离 MCP 资源标头 @copyberry
- #39020 限制 Windows IDE 管道客户端模拟 @copyberry
- #39022 在 TUI 编辑器中处理软换行空白 @copyberry
- #39023 减少 TUI 历史记录中保留的 MCP 结果数据 @copyberry
- #39025 加速大型差异高亮测试 @copyberry
- #39026 在长时间输入测试中使用模拟时间 @copyberry
- #39028 缓存测试宠物精灵图表的编码结果 @copyberry
- #39030 加速应用内恢复 cwd 测试 @copyberry
- #39032 将 TUI 闪烁效果封装到 motion 模块中 @copyberry
- #39033 限制旧版恢复预览扫描范围 @copyberry
- #39034 分发由其他进程写入的排队消息 @copyberry
- #39035 为 Guardian V2 审批路由添加 app-server 覆盖测试 @copyberry
- #39036 允许配置读取加入活动的 app-server 读取批次 @copyberry
- #39038 在整个线程生命周期中恢复 Guardian 风险评分 @copyberry
- #39040 在托管网络审批中保留外部路径 @copyberry
- #39043 强制执行托管身份验证后端设置 @copyberry
- #39045 为应用内聊天和听写添加托管门控 @copyberry
- #39046 将 MCP HTTP 重定向限制到配置的源站 @copyberry
- #39047 禁用钩子时跳过插件钩子加载 @copyberry
- #39049 避免在 TUI 中重复渲染子代理活动 @copyberry
- #39050 在初始化期间准备遥测关闭工作线程 @copyberry
- #39051 在 TUI 提及功能中使用已安装的可调用应用 @copyberry
- #39055 为环境配置添加网络策略元数据 @copyberry
- #39056 在发布构建中验证固定版本的 zsh 清单 @copyberry
- #39057 根据实际发出时间限制 TUI 帧速率 @copyberry
- #39058 为 Codex Apps 协议发现指标添加标签 @copyberry
- #39060 为 `codex doctor` 添加桌面应用诊断 @copyberry
- #39061 避免重新渲染流式代码围栏 @copyberry
- #39063 在记录分页器中仅渲染可见行 @copyberry
- #39064 将排队消息编辑限制在专用绑定上 @copyberry
- #39065 将终端超链接布局限制在可见视口内 @copyberry
- #39067 添加桌面安全强制执行诊断 @copyberry
- #39068 移除技能模型委派支持 @copyberry
- #39072 通过回合执行器持久化生成的图像 @copyberry
- #39073 将调用方元数据传播到 rendezvous 连接 @copyberry
- #39074 为 `codex doctor` 添加桌面更新诊断 @copyberry
- #39075 避免冗余的终端行清除操作 @copyberry
- #39077 仅为远程 TUI 会话构建文件系统 JSON 参数 @copyberry
- #39078 保留环境解析的追踪上下文 @copyberry
- #39079 将用户 MCP 策略应用于选定的执行器插件 @copyberry
- #39081 按增量大小限制 TUI 线程重放缓冲区 @copyberry
- #39082 在远程 TUI 工作区中请求项目信任 @copyberry
- #39083 加强 Windows 沙箱配置,防止重解析点攻击 @copyberry
- #39084 保留文件系统权限路径约定 @copyberry
- #39087 从 AuthManager 读取插件身份验证状态 @copyberry
- #39088 加强 TUI 子代理导航 @copyberry
- #39089 明确外部贡献政策 @copyberry
- #39092 添加为现有会话排队消息的命令 @copyberry
- #39094 为 TUI 添加代理概览仪表板 @copyberry
- #39098 跟踪 exec-server 请求从接收至完成的全过程 @copyberry
- #39100 避免在插入历史记录期间重复查询终端大小 @copyberry
- #39101 将 rmcp 更新至 3.1.2 @copyberry
- #39102 提高 GPT-5.6 的最大上下文窗口 @copyberry
- #39103 从 Linux 沙箱进程中移除功能权限 @copyberry
- #39112 将代理概览改造成交互式任务仪表板 @copyberry
- #39113 在实时对话中显示交互式请求 @copyberry
- #39114 添加专用的 `codex agents` 仪表板命令 @copyberry
- #39115 移除实验性的线程配置端点 @copyberry
- #39117 拒绝有损的旧版权限投影 @copyberry
- #39122 对深度嵌套的命令包装器采用默认拒绝策略 @copyberry
- #39131 在插件创建工作流中验证标识符 @copyberry
- #39141 从 app-server 响应日志中隐藏身份验证令牌 @copyberry
- #39142 为代理仪表板添加可配置快捷键 @copyberry
- #39143 在选择时填充推荐插件元数据 @copyberry
- #39145 在回合上下文中持久化活动权限配置 @copyberry
- #39147 集中处理持久化恢复设置的查找 @copyberry
- #39152 将 PyPI 发布操作更新至 v1.14.2 @copyberry
- #39153 在线程恢复时还原权限配置 @copyberry
- #39154 将 TUI future 装箱,以限制 CLI 栈使用量 @copyberry
- #39155 准备 Python SDK 0.147.0 稳定版发布 @copyberry
- #39157 在 Guardian 需要严格审查时通知客户端 @copyberry
- #39159 要求审批包含动态 shell 单词的命令 @copyberry
- #39163 当协作指令内容发生变化时刷新指令 @copyberry
- #39165 防止市场身份冒充 @copyberry
- #39174 跳过自动空闲回合中的空用户消息 @copyberry
- #39176 远程压缩后丢弃后代进度更新 @copyberry
- #39187 将 MCP 应用资源读取限制在其发起调用的范围内 @copyberry
- #39192 在压缩过程中保留 MCP 资源来源 @copyberry
- #39200 为敏感文件添加符号链接安全读取器 @copyberry
- #39205 拒绝内存工作区中的符号链接 @copyberry
- #39213 添加默认拒绝的 Tree-sitter PowerShell lowerer @copyberry
- #39214 防止自定义提供商继承环境中的身份验证信息 @copyberry
- #39220 在身份验证变更后重新连接 Guardian 采样 WebSocket @copyberry
- #39221 跳过重定向的外部代理迁移目标 @copyberry
- #39224 添加 Guardian v2 审批审查指标 @copyberry
- #39227 在 Guardian v2 审查中包含 node_repl 截图 @copyberry
- #39235 将 Noise 中继流与 JSON-RPC 处理解耦 @copyberry
- #39240 使用共享信号量去重远程插件包同步 @copyberry
- #39241 记录 Guardian v2 分类指标 @copyberry
- #39242 添加安全的权限配置交集 @copyberry
- #39244 按连接器限定 MCP 资源读取范围 @copyberry
- #39246 为 Guardian 分类器连接分配独立的线程身份 @copyberry
- #39249 添加 exec-server 转发模式 @copyberry
- #39256 归档线程时去重发布批次迁移 @copyberry
- #39257 重新连接 WebRTC 实时 sideband 传输 @copyberry
- #39259 简化统一 exec 输出快照 @copyberry
- #39261 在错位策略违规时停止 TUI 聊天 @copyberry
- #39262 防止 ConPTY DLL 从当前目录加载 @copyberry
- #39264 改进 Guardian v2 风险分类 @copyberry
- #39266 在被拒绝的权限路径下要求重新审批 @copyberry
- #39267 将 Node REPL 策略注入 Guardian 审查会话 @copyberry
- #39273 在发布批次迁移期间保留线程名称 @copyberry
- #39274 添加由提供商负责的身份验证恢复 @copyberry
- #39277 声明实验性的 Amazon Bedrock 设置 API @copyberry
- #39278 保留所有者提供的环境配置 @copyberry
- #39279 传播 Windows 沙箱 ACL 更新失败 @copyberry
- #39281 将 shell 快照脚本移入 `codex-shell-command` @copyberry
- #39283 记录安全开发容器中的 DNS 数据外泄风险 @copyberry
- #39284 报告审批期间发生的网络断开 @copyberry
- #39285 在 TUI 变更审批中显示文件目标位置 @copyberry
- #39287 报告诊断上传失败 @copyberry
- #39288 注册异步消息功能标志 @copyberry
- #39290 为 `codex doctor` 添加 Windows 沙箱诊断 @copyberry
- #39293 移除 app-server 对 reqwest 的直接依赖 @copyberry
- #39294 增加 SQLite 日志接收器的批处理量 @copyberry
- #39296 在 Codex 会话中启用 MCP 工具钩子 @copyberry
- #39298 允许覆盖 Codex 软件包版本 @copyberry
- #39299 将代理角色限制为有界配置覆盖项 @copyberry
- #39301 防止 Node REPL 身份验证令牌传递给子进程 @copyberry
- #39303 记录 Guardian v2 分类令牌用量 @copyberry
- #39304 将 Guardian v2 风险评分保存在内存中 @copyberry
- #39306 在项目发现期间遵循托管配置 @copyberry
- #39307 Guardian V2 风险评分出错时采用默认拒绝策略 @copyberry
- #39309 将执行器技能调用归因于插件 @copyberry
- #39311 将统一 exec 审批绑定到 shell 可执行文件 @copyberry
- #39312 为代理消息添加异步传递元数据 @copyberry
- #39314 使用捕获的会话环境运行钩子 @copyberry
- #39315 以可缓存的区块驱逐 Guardian 记录条目 @copyberry
- #39316 支持 Edu Plus 和 Edu Pro 账户方案 @copyberry
- #39319 添加异步用户消息工具 @copyberry
- #39320 扩展 OAuth 元数据重定向测试覆盖范围 @copyberry
- #39322 对标头身份验证强制执行工作区限制 @copyberry
- #39325 停止迁移 Cursor 沙箱设置 @copyberry
- #39331 通过当前连接路由钩子 MCP 调用 @copyberry
- #39335 强制执行环境 MCP 策略 @copyberry
- #39372 将 TUI 审批请求限定到其所属线程 @copyberry
- #39385 按名称排队时优先选择最近的会话 @copyberry
- #39402 从仓库检查中移除 npm 软件包暂存 @copyberry
- #39404 支持旧版系统 Bubblewrap 的 FD 挂载 @copyberry
- #39410 刷新已过期的 AWS 凭据以用于 Bedrock @copyberry
- #39452 移除异步用户消息的功能门控 @copyberry
- #39474 将 Guardian 扩展整合到 `codex-guardian-v2` @copyberry
- #39480 将 shell 快照测试移入 shell-command @copyberry
- #39493 将 head-tail 缓冲区容量改为 const 泛型 @copyberry
- #39494 测试全景 Guardian 记录图像缩放 @copyberry
- #39496 在 cyber exec 策略测试中使用默认超时 @copyberry
- #39497 修正不同响应模式下标准化动态工具覆盖范围 @copyberry
- #39501 在统一图像缩放测试中使用窄版 fixture @copyberry
- #39505 测试代码模式运行时中的文本字符串化错误 @copyberry
- #39506 测试没有同步工具调用时的代码模式通知 @copyberry
- #39509 单独测试禁用增强版 Node REPL 记录图像的情况 @copyberry
- #39510 在分析中跟踪内置控制工具调用 @copyberry
- #39514 在生成回合摘要时使用已存储的条目类型 @copyberry
- #39515 使用 `mem::take` 清空统一 exec 输出缓冲区 @copyberry
- #39520 隔离自动插件 Git 操作 @copyberry
- #39523 在首次回合前持久化线程区段移动 @copyberry
- #39524 不再将 Git 命令视为固有安全 @copyberry
- #39584 添加用于组装 Codex 软件包的 just 配方 @copyberry
- #39585 测试插件同步与仓库 Git 配置的隔离 @copyberry
- #39586 在 Bubblewrap 沙箱中隔离 IPC @copyberry
- #39588 在执行策略中保留未解析的 shell 包装器 @copyberry
- #39590 加强安装期间的插件清单处理 @copyberry
- #39592 防止 SQLx 警告反馈到 SQLite 日志中 @copyberry
- #39594 将 MCP 工具名称限制提高至 128 字节 @copyberry
- #39595 将市场升级状态排除在配置之外 @copyberry
- #39597 将线程设置与环境配置分离 @copyberry
- #39599 保护 macOS Seatbelt 可写根锚点 @copyberry
- #39601 将异步用户消息保留在直接工具界面上 @copyberry
- #39602 使用进程内解析进行 PowerShell 命令分类 @copyberry
- #39604 保留排队 TUI 输入语义 @copyberry
- #39605 在 TUI 中隐藏已批准的自动审查警告 @copyberry
- #39606 在共享 CI 设置中启用用户命名空间 @copyberry
- #39607 按类型解析模型提供的 shell @copyberry
- #39608 加强技能安装,防止不安全的符号链接 @copyberry
- #39609 限制 macOS 上 Bazel 集成测试的线程数 @copyberry
- #39611 加强 MCP OAuth 回退凭据写入 @copyberry
- #39614 防止 `apply_patch` 扩大写入权限 @copyberry
- #39615 将 MCP OAuth 刷新令牌绑定到其签发者 @copyberry
- #39616 在继承项目信任前验证关联工作树 @copyberry
- #39618 将编辑器编辑偏好应用于 TUI 文本提示 @copyberry
- #39619 保留 Windows Terminal 中的 TUI 内联回滚内容 @copyberry
- #39620 流式读取执行器功能和技能文件 @copyberry
- #39623 防止 macOS Seatbelt 中受保护路径的重命名绕过 @copyberry
- #39625 添加相对于 cwd 的回合差异路径 @copyberry
- #39629 通过沙箱元数据挂载保留父仓库发现 @copyberry
- #39630 退役不受信任的审批策略 @copyberry
- #39631 默认跳过 Guardian v2 中的沙箱 shell 命令 @copyberry
- #39632 在核心 API 中公开权限配置解析结果 @copyberry
- #39635 在 TUI 中显示严格审查警告 @copyberry
- #39637 将 `invalid_grant` 刷新失败视为永久性失败 @copyberry
- #39640 在恢复或分叉前提示取消归档会话 @copyberry
- #39641 在完整历史记录的代理分叉中清理开发者上下文 @copyberry
- #39645 对模型提供商强制执行托管驻留要求 @copyberry
- #39646 在 cyber 策略测试中测试受限令牌沙箱 @copyberry
- #39649 通过 bin junction 解析捆绑的 Windows 辅助程序 @copyberry
- #39653 加载 AGENTS.md 时强制执行文件系统权限 @copyberry
- #39655 明确核心集成测试权限 @copyberry
- #39656 在图形化 Linux 会话中显示 Desktop 应用 @copyberry
- #39657 启动已弃用的 MCP 服务器时发出警告 @copyberry
- #39658 允许 Guardian V2 满足所需的模型审查 @copyberry
- #39659 加强无沙箱补丁的文件系统访问 @copyberry
- #39661 扩展 Vim 修改命令并添加字符替换 @copyberry
- #39662 为各 SDK 添加 max 和 ultra 推理强度 @copyberry
- #39663 将插件迁移限制在 home 作用域内 @copyberry
- #39665 添加 macOS Seatbelt 文件系统集成测试 @copyberry
- #39666 改进各平台上的 no-follow 文件系统行为 @copyberry
## New Features
- Added an interactive `codex agents` dashboard for searching, starting, opening, renaming, and stopping tasks, with configurable shortcuts. (#39094, #39112, #39114, #39142)
- Added `/cd`, `/pwd`, and `/cwd` commands for managing the working directory in TUI sessions. (#38894)
- Added `codex queue` for sending messages to existing local or remote sessions. (#39092)
- Expanded Vim editing with character replacement and more change motions such as `cw`, `c$`, and `cc`. (#39661)
- `codex doctor` now diagnoses endpoint protection, network/proxy failures, desktop app state, and update connectivity. (#38827, #38918, #39060, #39074)
- SDK users can now pass exact CLI config overrides and select `max` or `ultra` reasoning effort. (#38817, #39662)
## Bug Fixes
- Queued messages now wake idle sessions reliably, resolve duplicate session names more usefully, and preserve pasted or deferred command semantics. (#39034, #39385, #39604)
- Resumed and forked threads now restore their active permission profile instead of silently falling back to current defaults. (#39153)
- Fixed duplicate sub-agent activity and tightened TUI routing for sub-agent notifications and approvals. (#39049, #39088)
- Realtime WebRTC sideband connections now reconnect after unexpected transport loss without dropping pending output. (#39257)
- Inline TUI history now remains available in Windows Terminal scrollback. (#39619)
- Inactive TUI thread replay buffers are now bounded to prevent excessive retained streamed output. (#39081)
## Documentation
- Clarified that external contributions should go through issues and design discussion rather than pull requests. (#39089)
- Documented DNS exfiltration risks and trust limitations for secure devcontainers. (#39283)
## Changelog
Full Changelog: https://github.com/openai/codex/compare/rust-v0.148.0...rust-v0.149.0
- #38817 Add raw config overrides to the TypeScript SDK @copyberry
- #38819 Support metadata staging for reserved thread IDs @copyberry
- #38822 Avoid cloning TUI history span content @copyberry
- #38823 Avoid allocating per character when decorating hyperlinks @copyberry
- #38827 Add endpoint protection checks to `codex doctor` @copyberry
- #38830 Isolate external editor buffers from sandbox-writable paths @copyberry
- #38837 Share editor keymaps across TUI composer components @copyberry
- #38840 Identify Mac mini hosts in remote control handshakes @copyberry
- #38893 Restore thread timestamp maxima independently @copyberry
- #38894 Add working-directory commands to the TUI @copyberry
- #38899 Move requirements policy ownership to execpolicy @copyberry
- #38902 Honor per-environment shell variable policies @copyberry
- #38907 Edit queued messages with Vim history-up @copyberry
- #38913 Stop rendering columns after filling their area @copyberry
- #38916 Honor legacy `:project_roots` permission entries @copyberry
- #38918 Improve `codex doctor` network diagnostics @copyberry
- #38919 Reject obsolete app-server permission profile fields @copyberry
- #38921 Compact successful command activity in the TUI @copyberry
- #38940 Add experimental app-server project APIs @copyberry
- #38941 Prevent Noise auth tokens from reaching child processes @copyberry
- #38942 Enforce environment-specific command policies @copyberry
- #38947 Stop loading legacy managed config on Windows @copyberry
- #38978 Add a configurable skill catalog token budget @copyberry
- #38980 Bound Guardian v2 parent compaction context @copyberry
- #38987 Include images in Guardian v2 transcripts @copyberry
- #38990 Source Guardian v2 defaults from the model catalog @copyberry
- #38993 Evaluate recent and character-routed skill selection @copyberry
- #38994 Remove the workspace settings gate for apps and plugins @copyberry
- #38997 Retry transient Guardian sampling failures @copyberry
- #39001 Ignore stale Guardian tool risk scores @copyberry
- #39005 Disable Guardian V2 for managed automatic reviewers @copyberry
- #39006 Emit API-key turn cost telemetry from app-server @copyberry
- #39007 Wait for Guardian score progress in approval tests @copyberry
- #39008 Add task context to shadow skill selection @copyberry
- #39017 Move MCP policy types into `codex-protocol` @copyberry
- #39019 Isolate MCP resource headers during OAuth requests @copyberry
- #39020 Restrict Windows IDE pipe client impersonation @copyberry
- #39022 Hang soft-break whitespace in the TUI composer @copyberry
- #39023 Reduce retained MCP result data in TUI history @copyberry
- #39025 Speed up the large diff highlighting test @copyberry
- #39026 Use simulated time in the long typing test @copyberry
- #39028 Cache the test pet spritesheet encoding @copyberry
- #39030 Speed up the in-app resume cwd test @copyberry
- #39032 Encapsulate TUI shimmer under the motion module @copyberry
- #39033 Bound legacy resume preview scans @copyberry
- #39034 Dispatch queued messages written by other processes @copyberry
- #39035 Add app-server coverage for Guardian V2 approval routing @copyberry
- #39036 Allow config reads to join active app-server read batches @copyberry
- #39038 Restore Guardian risk scores across thread lifecycles @copyberry
- #39040 Preserve foreign paths in managed network approvals @copyberry
- #39043 Enforce managed authentication backend settings @copyberry
- #39045 Add managed gates for in-app chat and dictation @copyberry
- #39046 Restrict MCP HTTP redirects to the configured origin @copyberry
- #39047 Skip plugin hook loading when hooks are disabled @copyberry
- #39049 Avoid rendering sub-agent activity twice in the TUI @copyberry
- #39050 Prepare the telemetry shutdown worker during initialization @copyberry
- #39051 Use installed callable apps for TUI mentions @copyberry
- #39055 Add network policy metadata to environment configuration @copyberry
- #39056 Verify the pinned zsh manifest in release builds @copyberry
- #39057 Rate-limit TUI frames from their actual emission time @copyberry
- #39058 Tag Codex Apps protocol discovery metrics @copyberry
- #39060 Add desktop app diagnostics to `codex doctor` @copyberry
- #39061 Avoid rerendering streamed code fences @copyberry
- #39063 Render only visible rows in the transcript pager @copyberry
- #39064 Restrict queued-message editing to its dedicated binding @copyberry
- #39065 Limit terminal hyperlink layout to the visible viewport @copyberry
- #39067 Add desktop security enforcement diagnostics @copyberry
- #39068 Remove skill model delegation support @copyberry
- #39072 Persist generated images through turn executors @copyberry
- #39073 Propagate caller metadata to rendezvous connections @copyberry
- #39074 Add desktop update diagnostics to `codex doctor` @copyberry
- #39075 Avoid redundant terminal row clears @copyberry
- #39077 Build filesystem JSON params only for remote TUI sessions @copyberry
- #39078 Preserve tracing context for environment resolution @copyberry
- #39079 Apply user MCP policy to selected executor plugins @copyberry
- #39081 Bound TUI thread replay buffers by delta size @copyberry
- #39082 Prompt for project trust in remote TUI workspaces @copyberry
- #39083 Harden Windows sandbox provisioning against reparse points @copyberry
- #39084 Preserve filesystem permission path conventions @copyberry
- #39087 Read plugin authentication state from AuthManager @copyberry
- #39088 Harden TUI subagent navigation @copyberry
- #39089 Clarify the external contribution policy @copyberry
- #39092 Add a command to queue messages for existing sessions @copyberry
- #39094 Add an agents overview dashboard to the TUI @copyberry
- #39098 Trace exec-server requests from receipt through completion @copyberry
- #39100 Avoid redundant terminal size queries during history insertion @copyberry
- #39101 Update rmcp to 3.1.2 @copyberry
- #39102 Raise the GPT-5.6 maximum context window @copyberry
- #39103 Drop capabilities from Linux sandbox processes @copyberry
- #39112 Make the agents overview an interactive task dashboard @copyberry
- #39113 Surface interactive requests in realtime conversations @copyberry
- #39114 Add a dedicated `codex agents` dashboard command @copyberry
- #39115 Remove the experimental thread config endpoint @copyberry
- #39117 Reject lossy legacy permission projections @copyberry
- #39122 Fail closed on deeply nested command wrappers @copyberry
- #39131 Validate identifiers in plugin creator workflows @copyberry
- #39141 Redact auth tokens from app-server response logs @copyberry
- #39142 Add configurable shortcuts for the agents dashboard @copyberry
- #39143 Hydrate recommended plugin metadata on selection @copyberry
- #39145 Persist active permission profiles in turn context @copyberry
- #39147 Centralize persisted resume settings lookup @copyberry
- #39152 Update PyPI publish action to v1.14.2 @copyberry
- #39153 Restore permission profiles when resuming threads @copyberry
- #39154 Box the TUI future to bound CLI stack usage @copyberry
- #39155 Prepare Python SDK 0.147.0 stable release @copyberry
- #39157 Notify clients when Guardian requires strict review @copyberry
- #39159 Require approval for commands with dynamic shell words @copyberry
- #39163 Refresh collaboration instructions when their content changes @copyberry
- #39165 Prevent marketplace identity spoofing @copyberry
- #39174 Skip empty user messages for automatic idle turns @copyberry
- #39176 Drop descendant progress updates after remote compaction @copyberry
- #39187 Scope MCP app resource reads to their originating call @copyberry
- #39192 Preserve MCP resource origins across compaction @copyberry
- #39200 Add a symlink-safe reader for sensitive files @copyberry
- #39205 Reject symbolic links in memory workspaces @copyberry
- #39213 Add a fail-closed Tree-sitter PowerShell lowerer @copyberry
- #39214 Prevent custom providers from inheriting ambient auth @copyberry
- #39220 Reconnect Guardian sampling WebSockets after auth changes @copyberry
- #39221 Skip redirected external-agent migration destinations @copyberry
- #39224 Add Guardian v2 approval review metrics @copyberry
- #39227 Include node_repl screenshots in Guardian v2 reviews @copyberry
- #39235 Decouple Noise relay streams from JSON-RPC processing @copyberry
- #39240 Deduplicate remote plugin bundle syncs with shared semaphores @copyberry
- #39241 Record Guardian v2 classification metrics @copyberry
- #39242 Add safe permission profile intersection @copyberry
- #39244 Scope MCP resource reads by connector @copyberry
- #39246 Give Guardian classifier connections distinct thread identities @copyberry
- #39249 Add exec-server forwarding mode @copyberry
- #39256 Deduplicate rollout moves when archiving threads @copyberry
- #39257 Reconnect WebRTC Realtime sideband transports @copyberry
- #39259 Simplify unified exec output snapshots @copyberry
- #39261 Stop TUI chats on misalignment policy violations @copyberry
- #39262 Prevent ConPTY DLL loading from the current directory @copyberry
- #39264 Improve Guardian v2 risk classification @copyberry
- #39266 Require fresh approval beneath denied permission paths @copyberry
- #39267 Inject Node REPL policy into Guardian review sessions @copyberry
- #39273 Preserve thread names during rollout migration @copyberry
- #39274 Add provider-owned authentication recovery @copyberry
- #39277 Declare experimental Amazon Bedrock setup APIs @copyberry
- #39278 Preserve owner-provided environment configuration @copyberry
- #39279 Propagate Windows sandbox ACL update failures @copyberry
- #39281 Move shell snapshot scripts into `codex-shell-command` @copyberry
- #39283 Document secure devcontainer DNS exfiltration risk @copyberry
- #39284 Report network disconnects during approval @copyberry
- #39285 Show file destinations in TUI change approvals @copyberry
- #39287 Report diagnostic upload failures @copyberry
- #39288 Register the async message feature flag @copyberry
- #39290 Add Windows sandbox diagnostics to `codex doctor` @copyberry
- #39293 Remove app-server's direct reqwest dependency @copyberry
- #39294 Increase SQLite log sink batching @copyberry
- #39296 Enable MCP tool hooks in Codex sessions @copyberry
- #39298 Allow overriding Codex package versions @copyberry
- #39299 Restrict agent roles to bounded configuration overrides @copyberry
- #39301 Prevent Node REPL auth tokens from reaching child processes @copyberry
- #39303 Record Guardian v2 classification token usage @copyberry
- #39304 Keep Guardian v2 risk scores in memory @copyberry
- #39306 Honor managed config during project discovery @copyberry
- #39307 Fail closed on Guardian V2 risk scoring errors @copyberry
- #39309 Attribute executor skill invocations to plugins @copyberry
- #39311 Bind unified exec approvals to shell executables @copyberry
- #39312 Add async delivery metadata to agent messages @copyberry
- #39314 Run hooks with the captured session environment @copyberry
- #39315 Evict guardian transcript entries in cacheable chunks @copyberry
- #39316 Support Edu Plus and Edu Pro account plans @copyberry
- #39319 Add the async user message tool @copyberry
- #39320 Expand OAuth metadata redirect test coverage @copyberry
- #39322 Enforce workspace restrictions for header authentication @copyberry
- #39325 Stop migrating Cursor sandbox settings @copyberry
- #39331 Route hook MCP calls through current connections @copyberry
- #39335 Enforce environment MCP policies @copyberry
- #39372 Scope TUI approval requests to their threads @copyberry
- #39385 Prefer the most recent session when queueing by name @copyberry
- #39402 Remove npm package staging from repo checks @copyberry
- #39404 Support FD mounts with older system Bubblewrap versions @copyberry
- #39410 Refresh expired AWS credentials for Bedrock @copyberry
- #39452 Remove the feature gate for async user messages @copyberry
- #39474 Consolidate Guardian extensions into `codex-guardian-v2` @copyberry
- #39480 Move shell snapshot tests into shell-command @copyberry
- #39493 Make head-tail buffer capacity const generic @copyberry
- #39494 Test panoramic Guardian transcript image resizing @copyberry
- #39496 Use default timeouts in cyber exec policy tests @copyberry
- #39497 Correct normalized dynamic tool coverage across response modes @copyberry
- #39501 Use a narrow fixture for the unified image resize test @copyberry
- #39505 Test text stringify errors in the code mode runtime @copyberry
- #39506 Test code mode notifications without a sync tool call @copyberry
- #39509 Test disabled enhanced Node REPL transcript images separately @copyberry
- #39510 Track built-in control tool calls in analytics @copyberry
- #39514 Use stored item types when materializing turn summaries @copyberry
- #39515 Use `mem::take` to drain unified exec output buffers @copyberry
- #39520 Isolate automatic plugin Git operations @copyberry
- #39523 Persist thread section moves before the first turn @copyberry
- #39524 Stop treating Git commands as inherently safe @copyberry
- #39584 Add a just recipe for assembling Codex packages @copyberry
- #39585 Test plugin sync isolation from repository Git config @copyberry
- #39586 Isolate IPC in Bubblewrap sandboxes @copyberry
- #39588 Preserve unparsed shell wrappers in exec policy @copyberry
- #39590 Harden plugin manifest handling during installation @copyberry
- #39592 Prevent SQLx warnings from feeding back into SQLite logs @copyberry
- #39594 Raise the MCP tool name limit to 128 bytes @copyberry
- #39595 Keep marketplace upgrade state out of config @copyberry
- #39597 Separate thread settings from environment configuration @copyberry
- #39599 Protect macOS Seatbelt writable root anchors @copyberry
- #39601 Keep async user messages on the direct tool surface @copyberry
- #39602 Use in-process parsing for PowerShell command classification @copyberry
- #39604 Preserve queued TUI input semantics @copyberry
- #39605 Hide approved automatic review warnings in the TUI @copyberry
- #39606 Enable user namespaces in shared CI setup @copyberry
- #39607 Resolve model-provided shells by type @copyberry
- #39608 Harden skill installation against unsafe symlinks @copyberry
- #39609 Limit Bazel integration test threads on macOS @copyberry
- #39611 Harden MCP OAuth fallback credential writes @copyberry
- #39614 Prevent `apply_patch` from widening write permissions @copyberry
- #39615 Bind MCP OAuth refresh tokens to their issuer @copyberry
- #39616 Validate linked worktrees before inheriting project trust @copyberry
- #39618 Apply composer editing preferences to TUI text prompts @copyberry
- #39619 Preserve inline TUI scrollback in Windows Terminal @copyberry
- #39620 Stream executor capability and skill file reads @copyberry
- #39623 Prevent protected-path rename bypasses in macOS Seatbelt @copyberry
- #39625 Add cwd-relative turn diff paths @copyberry
- #39629 Preserve parent repository discovery through sandbox metadata mounts @copyberry
- #39630 Retire the untrusted approval policy @copyberry
- #39631 Skip sandboxed shell commands in Guardian v2 by default @copyberry
- #39632 Expose permission profile resolution in the core API @copyberry
- #39635 Show strict review warnings in the TUI @copyberry
- #39637 Treat `invalid_grant` refresh failures as permanent @copyberry
- #39640 Prompt to unarchive sessions before resuming or forking @copyberry
- #39641 Sanitize developer context in full-history agent forks @copyberry
- #39645 Enforce managed residency for model providers @copyberry
- #39646 Exercise restricted-token sandboxing in cyber policy tests @copyberry
- #39649 Resolve bundled Windows helpers through bin junctions @copyberry
- #39653 Enforce filesystem permissions when loading AGENTS.md @copyberry
- #39655 Make core integration test permissions explicit @copyberry
- #39656 Advertise the Desktop app in graphical Linux sessions @copyberry
- #39657 Warn when launching the deprecated MCP server @copyberry
- #39658 Let Guardian V2 satisfy required model reviews @copyberry
- #39659 Harden unsandboxed patch filesystem access @copyberry
- #39661 Expand Vim change commands and add character replacement @copyberry
- #39662 Add max and ultra reasoning efforts to the SDKs @copyberry
- #39663 Restrict plugin migration to home scope @copyberry
- #39665 Add macOS Seatbelt filesystem integration tests @copyberry
- #39666 Improve no-follow filesystem behavior across platforms @copyberry