Repository navigation
refactor: remove the old Deep Scan result and merge tools - #1127
mldangelo-oai wants to merge 1 commit into
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
@codex review |
|
Codex Review: Didn't find any major issues. 🎉 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The broad cleanup changes scan-draft persistence, checkpoint recovery, artifact writing, and packaging, warranting final human validation.
Review effort: Balanced
Findings: None
What changed in this PR
Removes the retired worker artifact server, reducer paging implementation, related schemas, evaluations, and dependencies while simplifying the remaining scan artifact pipeline.
Changes:
- Deletes obsolete worker/reducer tools, templates, validation logic, and tests.
- Simplifies artifact contexts and routes draft publication through the locked workbench writer.
- Supports nested finding report paths and removes unused runtime dependencies.
| File | Description |
|---|---|
plugins/codex-security/tests/test_scan_contract_examples.py |
Removes reducer schema assertions. |
plugins/codex-security/schemas/tools/worker-threat-model.schema.json |
Deletes worker threat-model schema. |
plugins/codex-security/schemas/tools/scan-draft.schema.json |
Allows nested report paths. |
plugins/codex-security/schemas/tools/review-items.schema.json |
Removes worker paging input. |
plugins/codex-security/schemas/tools/deep-reducer.schema.json |
Deletes reducer schemas. |
plugins/codex-security/plugin-files.json |
Updates shipped-file inventory. |
plugins/codex-security/mcp-app/tsconfig.json |
Excludes removed worker entrypoint. |
plugins/codex-security/mcp-app/tests/test_deep_scan_templates.mjs |
Deletes old prompt tests. |
plugins/codex-security/mcp-app/tests/test_deep_scan_artifact_validation.mjs |
Deletes worker artifact validation tests. |
plugins/codex-security/mcp-app/tests/test_deep_reducer_paging_eval.mjs |
Deletes paging evaluation test. |
plugins/codex-security/mcp-app/tests/test_artifact_worker_threat_model.mjs |
Deletes worker threat-model tests. |
plugins/codex-security/mcp-app/tests/test_artifact_validation_phase.mjs |
Uses scan binding instead of layouts. |
plugins/codex-security/mcp-app/tests/test_artifact_storage.mjs |
Shares production bundle options. |
plugins/codex-security/mcp-app/tests/test_artifact_storage_regressions.mjs |
Updates bundling and contexts. |
plugins/codex-security/mcp-app/tests/test_artifact_inventory.mjs |
Removes worker inventory cases. |
plugins/codex-security/mcp-app/tests/test_artifact_foundation.mjs |
Tests simplified atomic replacement. |
plugins/codex-security/mcp-app/tests/test_artifact_discovery.mjs |
Removes worker-context coverage. |
plugins/codex-security/mcp-app/tests/test_artifact_deep_reducer.mjs |
Deletes reducer artifact tests. |
plugins/codex-security/mcp-app/tests/test_artifact_deep_reducer_pages.mjs |
Deletes reducer pagination tests. |
plugins/codex-security/mcp-app/tests/test_artifact_attack_path.mjs |
Uses scan binding instead of layouts. |
plugins/codex-security/mcp-app/tests/support/reducer-paging/deep-reducer-paging.mjs |
Deletes paging harness. |
plugins/codex-security/mcp-app/tests/support/reducer-paging/deep-reducer-paging-server.mjs |
Deletes evaluation server. |
plugins/codex-security/mcp-app/tests/support/reducer-paging/deep-reducer-paging-fixture.mjs |
Deletes paging fixture. |
plugins/codex-security/mcp-app/tests/support/reducer-paging/controlled-code-mode.mjs |
Deletes controlled runner. |
plugins/codex-security/mcp-app/templates/deep-scan/discovery.md |
Deletes old worker prompt. |
plugins/codex-security/mcp-app/templates/deep-scan/dedup.md |
Deletes old reducer prompt. |
plugins/codex-security/mcp-app/src/server/compact-artifact-tools.ts |
Removes worker/reducer tool registration. |
plugins/codex-security/mcp-app/src/deep-scan/templates.ts |
Deletes old prompt renderer. |
plugins/codex-security/mcp-app/src/deep-scan/artifacts.ts |
Deletes old artifact helpers. |
plugins/codex-security/mcp-app/src/deep-scan/artifact-validation.ts |
Deletes worker/reducer validation. |
plugins/codex-security/mcp-app/src/deep-scan/artifact-contracts.ts |
Removes relocated candidate contract. |
plugins/codex-security/mcp-app/src/artifact-validation-phase.ts |
Uses shared candidate schema and scan binding. |
plugins/codex-security/mcp-app/src/artifact-threat-model.ts |
Deletes worker threat-model writer. |
plugins/codex-security/mcp-app/src/artifact-storage.ts |
Removes layout metadata. |
plugins/codex-security/mcp-app/src/artifact-scan-draft.ts |
Simplifies locked draft publication and recovery. |
plugins/codex-security/mcp-app/src/artifact-io.ts |
Removes worker contexts, append support, and locks. |
plugins/codex-security/mcp-app/src/artifact-inventory.ts |
Removes worker schema and layout checks. |
plugins/codex-security/mcp-app/src/artifact-discovery.ts |
Removes unused schema export. |
plugins/codex-security/mcp-app/src/artifact-deep-reducer.ts |
Deletes reducer implementation. |
plugins/codex-security/mcp-app/src/artifact-deep-reducer-pages.ts |
Deletes reducer pagination. |
plugins/codex-security/mcp-app/src/artifact-context.ts |
Removes worker/reducer context construction. |
plugins/codex-security/mcp-app/src/artifact-attack-path.ts |
Uses shared candidate schema and scan binding. |
plugins/codex-security/mcp-app/pnpm-lock.yaml |
Removes SDK packages and relocates TOML dependency. |
plugins/codex-security/mcp-app/package.json |
Removes unused runtime dependencies. |
plugins/codex-security/mcp-app/artifact-writer-main.ts |
Deletes worker MCP entrypoint. |
evals/README.md |
Removes reducer evaluation documentation. |
evals/deep-reducer/run.mjs |
Deletes reducer evaluation runner. |
evals/deep-reducer/README.md |
Deletes reducer evaluation guide. |
evals/deep-reducer/.gitignore |
Removes obsolete report exclusion. |
CONTRIBUTING.md |
Removes reducer CI reference. |
Files not reviewed (1)
- plugins/codex-security/mcp-app/pnpm-lock.yaml: Generated file
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
alandelong-oai
left a comment
There was a problem hiding this comment.
Reviewed 4eca17aa897c93228418b297c05fd6121f58f440 against mdangelo/codex/pr939-stack-21-retire-engine at 63c90a2461d5770963e56e17027b2e0b426aca82, scoped to this PR's diff and touched files.
Reviewed worker/reducer tool removal, remaining artifact I/O and registrations, schemas, package inventory, and changed tests/docs. No new actionable findings. The exact base/head diff passed git diff --check.
Review included simplification/deletion opportunities. Full repository and platform test suites were not run.
4eca17a to
e30421d
Compare
13d62a5 to
6c4d367
Compare
e30421d to
2348b94
Compare
6c4d367 to
ac334c3
Compare
2348b94 to
e29cdc2
Compare
faizan-oai
left a comment
There was a problem hiding this comment.
Reviewed the retired protocol/tool removals and remaining main-server draft path, together with nested report-path support and dependency changes. No issue found in this deletion layer. Integrated type checks and focused result/merge tests passed at the final stack tip.
Summary
The old Deep Scan processes used a separate server to save draft findings and read results in pages for merging. With those processes removed in part 21, remove their server, tools, schemas, and evaluation harness.
Changes
Remove
get_codex_security_deep_reducer_inputsandrecord_codex_security_deep_reduction, the tools used to read and combine the old workers' findings. Also remove the worker server'srecord_codex_security_scan_draftregistration. The main scan server keeps that draft tool and uses the existing database writer and its lock to save results.Delete readers and context types specific to the old worker directories. Allow findings combined from multiple scans to reference reports in nested directories. Remove the plugin server's unused Codex SDK dependency and move its remaining test-only TOML dependency to development dependencies.
Testing
Ruff lint and formatting, the CI script build, SDK and plugin type checks, and the plugin source compatibility check and tests passed on this rebuilt commit.
Full SDK test results are reported on the final PR in the stack, #1095.
Risk and rollout
Callers of the retired server must use the main scan tools. Completed scan documents remain readable; the new result-saving code does not import partial results from the old workers or merge process. Tools for storing extra scan files remain available.
Part 22 of 23. Previous PR · Next PR · Stack index. Review against the base branch.
Public disclosure review