Skip to content

fix(deep-scan): preserve convergence across alias consolidation - #762

Open
Hughhhhcoder wants to merge 1 commit into
openai:mainfrom
Hughhhhcoder:codex/codex-security-lineage-convergence
Open

fix(deep-scan): preserve convergence across alias consolidation#762
Hughhhhcoder wants to merge 1 commit into
openai:mainfrom
Hughhhhcoder:codex/codex-security-lineage-convergence

Conversation

@Hughhhhcoder

Copy link
Copy Markdown
Contributor

Summary

Fixes #711.

Deep Scan used canonical finding identity to derive novelty, so consolidating semantically equivalent findings under one retained source lineage could be counted as a new finding and reset no-new convergence.

Changes

  • Match previous findings to current findings by complete source lineage, allowing multiple prior aliases to converge into one current finding.
  • Reject discarded, split, or ambiguously reassigned prior lineage.
  • Count only current findings with no prior lineage assignment as new.
  • Preserve exact-identity fallback for legacy findings without lineage metadata.
  • Add regression coverage for alias consolidation, persisted recovery, lineage splits, fresh evidence on an existing root, genuine new roots, identity collisions, and legacy artifacts.

Testing

  • npx --yes pnpm@11.9.0 --dir ../../plugins/codex-security/mcp-app run test:mcp — 23/23 test files passed after building the bundled plugin.
  • npx --yes pnpm@11.9.0 run typecheck — passed.
  • uvx --from ruff==0.16.1 ruff check --config plugins/codex-security/pyproject.toml .github/scripts/check_plugin_source_compatibility.py .github/scripts/test_check_plugin_source_compatibility.py plugins/codex-security — passed.
  • uvx --from ruff==0.16.1 ruff format --check --config plugins/codex-security/pyproject.toml .github/scripts/check_plugin_source_compatibility.py .github/scripts/test_check_plugin_source_compatibility.py plugins/codex-security — passed.
  • python .github/scripts/check_plugin_source_compatibility.py — passed.
  • git diff --check — passed.

The local SDK install emitted an engine warning because Node v25.4.0 is outside the declared Node 22/24/26 ranges; all listed checks still passed.

Risk and rollout

This changes internal convergence accounting only; it does not change a public API or artifact schema. Existing source-accounting checks remain in place, split/ambiguous lineage remains a hard error, and legacy artifacts retain exact-identity behavior. CI on a supported Node version provides the rollout gate.

Public disclosure review

  • No customer, partner, prospect, or user identities, data, or identifying details are included.
  • No credentials, personal data, private source, scan findings, or nonpublic links or tickets are included.
  • I reviewed the branch name, title, description, commits, changes, comments, logs, screenshots, attachments, and links for public disclosure.
@github-actions github-actions Bot added the bug Something isn't working label Aug 31, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 31, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-08-31T09:18:16.924647Z 27e1271 Manual request
🔒 Security Review Completed 2026-08-31T08:56:08.924757Z 27e1271 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@Hughhhhcoder

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Hooray!

Reviewed commit: 27e1271fab

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

1 participant