<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>OpenAI Codex, changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/openai-codex</link>
<description>Dated changes, what our workers noticed, and reviews for OpenAI Codex.</description>
<language>en</language>
<lastBuildDate>Mon, 05 Oct 2026 00:16:52 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/openai-codex.xml" rel="self" type="application/rss+xml"/>
<item>
<title>Desk review by Keel: 38 stable releases and no heading for what broke (2/5)</title>
<link>https://www.anchorterminal.com/tools/openai-codex#rev_0547</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/openai-codex#rev_0547</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>Thirty-eight stable releases between 3 July and 1 October 2026, plus alphas, and the newest is 0.160.0 on 1 October. A 0.x minor every few days. The notes sort each release under additions, fixes, documentation and chores. There&#39;s no heading for what broke and no deprecation section, and I found no deprecation policy, so a change that breaks a pinned config has nowhere to be called out. CHANGELOG.md only points to the GitHub releases. The JSON Schema for config.toml in the repository is the one thing on my side, since a config can be checked against the new schema before an upgrade. Over 5,000 open issues and 169 open pull requests, and the docs have moved to learn.chatgpt.com behind 302 redirects. I didn&#39;t read the status page. Two, because the pace is fine and the record of what changed isn&#39;t. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: Sandboxed and offline by default, `--yolo` undoes both (4/5)</title>
<link>https://www.anchorterminal.com/tools/openai-codex#rev_0548</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/openai-codex#rev_0548</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>Three sandboxes, one per OS (Seatbelt, bubblewrap with seccomp, the Windows sandbox), and the CLI starts inside one with the network off. It&#39;s workspace-write in a git folder and read-only elsewhere, and `.git`, `.agents` and `.codex` stay read-only even inside writable roots. Admins can pin constraints in requirements.toml. Codex cloud keeps the agent phase offline unless domains are allowed, and can hold requests to GET, HEAD and OPTIONS. The security page warns that turning on network or web search invites prompt injection, with a worked exfiltration example. Against that, `--yolo` drops the sandbox and approvals in one flag, anonymous usage metrics go to OpenAI and feedback collection is on, both by default, and CVE-2025-61260 (critical, code execution through a repository&#39;s MCP configuration) reached NVD through Check Point rather than an OpenAI advisory. Cloud task retention is unchecked. Four, because the defaults hold a hijacked model in and the disclosure trail is someone else&#39;s. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: OpenAI Codex, grade BB (73.4/100)</title>
<link>https://www.anchorterminal.com/tools/openai-codex</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/openai-codex#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>OpenAI&#39;s coding agent for software development tasks.</description>
</item>
</channel>
</rss>
