OpenAI adds Codex Security Cloud with on-demand and scheduled GitHub repository scans
At DevDay 2026, OpenAI extended Codex with Codex Security Cloud for security teams, enabling full GitHub repository scans on demand or on a schedule and ongoing review of new commits. OpenAI said cyber-capable models through Daybreak Blue are included by default, with investigation, deduplication, and fixes prepared for review, alongside reusable cloud environments, a desktop code review view, and broader DevDay API updates including Computer Use and a Decisions API for fast single decisions per The Decoder. TechCrunch and Techmeme excerpts added a refreshed CLI and cloud dev environments, a five-hundred-dollar monthly Pro tier with up to eightfold faster Codex tokens via Ultrafast, and Baseten routing of enterprise OpenAI commitments to open models in Codex or the Responses API. Packet excerpts leave terms, availability, and independent proof of scan quality or model parity unverified.
OpenAI adds Codex Security Cloud with on-demand and scheduled GitHub repository scans
At DevDay 2026, OpenAI gave Codex reusable cloud environments, automatic security scans for GitHub repositories, and a code review view in the desktop app. Codex Security Cloud is aimed at security teams and scans entire GitHub repositories on demand or on a schedule and keeps checking new commits as they come in.
Key takeaway
Codex Security Cloud turns GitHub-wide scanning and commit monitoring into a first-class OpenAI product surface, but adoption hinges on unverified scan quality and undisclosed enterprise terms.
What happened
At DevDay 2026, OpenAI introduced Codex Security Cloud aimed at security teams, with automatic security scans for GitHub repositories that can run on demand or on a schedule and keep checking new commits as they arrive, according to The Decoder and the owned-news body in the packet.
OpenAI posted on X that the Security Cloud upgrade includes Daybreak Blue cyber-capable models by default, scans entire GitHub repos, continuously reviews commits, deduplicates findings, and prepares fixes for review, while TechCrunch and Techmeme excerpts tied the same DevDay wave to reusable cloud dev environments, CLI and code-review updates, Ultrafast and Pro pricing, and a Baseten partnership for open models via Codex or the Responses API.
Evidence
Codex Security Cloud scans GitHub repositories on demand or on a schedule and monitors new commits.
The Decoder · attributed
Codex Security Cloud is aimed at security teams and scans entire GitHub repositories on demand or on a schedule and keeps checking new commits as they come in.
OpenAI says Security Cloud includes Daybreak Blue models and prepares fixes for review.
OpenAI · attributed
Codex Security Cloud is getting a major upgrade, with access to cyber-capable models through Daybreak Blue included by default. It scans entire GitHub repos, continuously reviews new commits, investigates and deduplicates findings, and prepares fixes for review
DevDay reporting tied Codex to reusable cloud environments and a desktop code review view.
TechCrunch AI · attributed
At DevDay 2026, OpenAI gave Codex reusable cloud environments, automatic security scans for GitHub repositories, and a code review view in the desktop app.
OpenAI unveiled a $500/month Pro plan with Ultrafast up to 8x faster Codex token generation.
Techmeme · attributed
OpenAI unveils a $500/month Pro plan, offering its highest usage allowance and access to its new Ultrafast tier, with up to 8x faster token generation in Codex
Baseten partnership lets enterprise customers use OpenAI commitments for Baseten-served open models in Codex or via the Responses API.
Techmeme · attributed
Baseten is partnering with OpenAI to serve open models natively via Codex and the Responses API.
OpenAI claims GPT-6.1 Sol nearly matches Astra on agentic coding at about one-fifth of Astra standard prices in Work and Codex.
Techmeme · attributed
OpenAI releases GPT-6.1 Sol, saying it nearly matches Astra on agentic coding and professional work at one-fifth of Astra's standard prices, in Work and Codex
Why it matters
Security and platform teams now get a vendor-backed path to continuous repo scanning inside the same Codex stack used for coding agents, which could centralize spend and workflows if the scans prove reliable.
Limits and uncertainties
Packet excerpts do not define Codex Security Cloud pricing, rollout scope, or general availability.
OpenAI's Daybreak Blue and GPT-6.1 Sol performance claims are self-reported in promotional or excerpt sources without independent benchmarks in the packet.
The Baseten partnership excerpt attributed to Dannie Herzberg does not specify eligible models, commitment mechanics, or timing.
Bloomberg's Altman interview covers Dots and IPO timing, not hands-on validation of Codex Security Cloud.
Practical implications
Security teams evaluating GitHub App scanners should compare OpenAI's scheduled and commit-triggered Codex Security Cloud scans against existing SAST pipelines before migrating workflows.
Developers on Codex should track whether Ultrafast and the $500/month Pro tier changes latency budgets for agentic coding sessions.
Enterprise operators with OpenAI commitments should watch Baseten integration announcements for whether open-model routing reduces lock-in without new procurement cycles.
What to watch
OpenAI or third-party disclosures on false-positive rates, supported languages, and fix-merge workflows for Codex Security Cloud.
Publication of Baseten partnership terms and which open models count against existing OpenAI enterprise commitments.
Independent benchmarks of GPT-6.1 Sol versus Astra on agentic coding tasks cited in Techmeme excerpts.