Skip to content

Security: gshaowei6/CodexTray

Security

SECURITY.md

Security Policy

Supported version

Only the latest published Alpha release is currently supported.

Reporting a vulnerability

Please use GitHub's private vulnerability reporting feature for this repository. Do not put credentials, private Codex session data, auth.json, browser cookies, access tokens, refresh tokens, GitHub PATs, or unredacted local logs in a public issue.

Include the affected CodexTray version, operating system, reproduction steps, and a minimal sanitized diagnostic when possible.

Trust boundary

CodexTray is an unofficial local utility. It starts the locally installed Codex CLI in read-only app-server mode and reads local session counters. It is not an OpenAI authentication provider and should never ask you to paste an OpenAI token.

The current Alpha binaries are not backed by Windows Authenticode or Apple Developer ID notarization. Verify the SHA-256 shown in the GitHub Release before running a downloaded package.

There aren't any published security advisories