OpenAI Codex Security 0.1.26 adds severity rubrics and GitLab merge requests
OpenAI released Codex Security 0.1.26, adding custom rubric-based finding severity classification through the CLI and SDK, matching of repeated findings across scan history, and draft GitLab merge request creation for verified patches, including self-hosted GitLab. Severity classification is opt-in; GitLab patch publication requires an authenticated glab CLI.
Sources and evidence
Summary last validated Sep 14, 2026
Reader actions
Report an issue
Use this for an incorrect summary, wrong source, duplicate story, or wrong category. Submissions are private and do not change the story automatically.
Related coverage
- agents
Anthropic ships Claude Code v2.1.296 with gateway code policies and subagent auto-compact
Anthropic released Claude Code v2.1.296. It adds a `code` key to the Claude apps gateway's managed policies, applying CLI settings in Claude Desktop's Code tab and enabling gateway mode. Subagent frontmatter and `--agents` gain `autoCompactWindow`, plus new env vars for workflow subagent models and overloaded-request retry delays. Several managed-hook and gateway sign-in bugs were fixed.
- open source
Mistral TypeScript SDK v3.0.0 removes Runs API and changes security error types
Mistral AI released client-ts v3.0.0, a breaking update to its TypeScript SDK. The stable API surface drops six items including Runs, Runs.getRun, Runs.getRunHistory, Runs.listRuns, SecurityErrorCode, and dlv. SecurityError.code is now required, and twelve type signatures changed, including Workflows.runs becoming WorkflowsRuns and several encoding helpers switching to a CharEncoding type.
- security
Microsoft urges early testing of post-quantum certificate ecosystems
Microsoft published guidance urging organizations to begin testing certificate ecosystems for post-quantum authentication now, highlighting its PQC TLS Pilot Program as a way to advance future readiness. The post appeared on the Microsoft Security Blog.
- agents
Claude Code v2.1.295 adds hook failure blocking and gateway model controls
Anthropic released Claude Code v2.1.295, adding onFailure:"block" so hooks that fail to start, time out, or exit unexpectedly block the action. It also adds Program Status Protocol (OSC 7501) terminal support, optional per-upstream models lists with wildcards, upstream_ttfb_ms stream timeouts, and gateway login settings.
- security
CISA: Chinese Government-linked Hackers Target US Critical Infrastructure
CISA published an advisory stating Chinese government-linked cyber threat actors, enabled by China-based Integrity Technology Group, combine automated scanning, botnets, and hands-on exploitation to steal sensitive data from organizations worldwide, including US critical infrastructure. Tactics include cross-site scripting and password spraying on Microsoft Exchange servers, VPN persistence, and email and credential exfiltration via scripts.