Skip to content

refactor(plugin): simplify artifact projections - #1227

Merged
mldangelo-oai merged 1 commit into
mainfrom
mdangelo/codex/simplify-07-artifacts
Oct 4, 2026
Merged

mldangelo-oai merged 1 commit into
mainfrom
mdangelo/codex/simplify-07-artifacts

Conversation

@mldangelo-oai

Copy link
Copy Markdown
Collaborator

Summary

Artifact projection repeats evidence filtering, JSON sizing and report formatting work. Consolidate those operations while preserving saved-artifact compatibility and rendered output.

Changes

  • Merge and bound code evidence in one pass, and share JSON-size calculations without changing preview budgets.
  • Reuse the retained evidence-ID set during legacy validation and remove repeated sealed-finding validation.
  • Simplify Markdown escaping/title deduplication and iterate explicit little-endian UTF-16 units for SARIF hashes.

Testing

Passed on commit b5579aeb7797:

  • python -m pytest plugins/codex-security/tests/test_finalize_scan_contract.py plugins/codex-security/tests/test_finding_preview.py plugins/codex-security/tests/test_report_projection.py -q -n 4 --dist worksteal --max-worker-restart 0 — 215 passed, 2 skipped, and 55 subtests passed.
  • python -m pytest plugins/codex-security/tests -q -n 4 --dist worksteal --max-worker-restart 0 — 1,587 passed, 6 skipped, and 162 subtests passed.

All five portable plugin checks passed:

python -m ruff check --config plugins/codex-security/pyproject.toml plugins/codex-security
python -m ruff format --check --config plugins/codex-security/pyproject.toml plugins/codex-security
pnpm --dir sdk/typescript run build:ci
node .github/scripts/check_plugin_source_compatibility.mjs
node --test .github/scripts/test_check_plugin_source_compatibility.mjs

Three independent Codex reviews and separate verification completed without findings.

Risk and rollout

Compatibility depends on evidence order, exact truncation boundaries, Unicode handling and historical sealed artifacts. Preserve those behaviors, streaming reads and the supported Python recursion boundary; no artifact schema or output policy changes are intended.

Public disclosure review

  • No customer, partner, prospect, or user identities, data, or identifying details are included.
  • No credentials, personal data, private source, scan findings, or nonpublic links or tickets are included.
  • I reviewed the branch name, title, description, commits, changes, comments, logs, screenshots, attachments, and links for public disclosure.

@mldangelo-oai

Copy link
Copy Markdown
Collaborator Author

@codex review the current head SHA.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-04T18:46:17.089417Z b5579ae Manual request
🔒 Security Review ✅ Completed 2026-10-04T18:46:51.862614Z b5579ae PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The refactors preserve observable behavior and are supported by comprehensive targeted and repository-wide tests.

Review effort: Balanced
Findings: None

What changed in this PR

Simplifies artifact projection internals while preserving compatibility, output formatting, size budgets, and SARIF hashing behavior.

Changes:

  • Consolidates code-evidence merging, validation, deduplication, and bounding.
  • Reuses JSON sizing and validation data structures.
  • Simplifies Markdown formatting and UTF-16 iteration.
File Description
plugins/​codex-security/​scripts/​report_projection.py Simplifies Markdown escaping and title deduplication.
plugins/​codex-security/​scripts/​finding_preview.py Consolidates evidence projection and JSON-size calculations.
plugins/​codex-security/​scripts/​finalize_scan_contract.py Streamlines legacy validation and SARIF UTF-16 hashing.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. You're on a roll.

Reviewed commit: b5579aeb77

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@alandelong-oai alandelong-oai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the actual PR contribution at b5579aeb77978c7c9adc04736f98d7082e30fd44 against 1fb0e5fbf8684c926cac2a36d08389b212d28d5a with three independent full-diff review passes and root synthesis, including every changed test and fixture. No actionable introduced issue was identified.

Read the full contribution. Shared evidence merge preserves ordering/first-wins and size constraints; shared JSON/Markdown output and validation order reveal no supported introduced discrepancy. No runtime or renderer execution.

Static source review only; tests and builds were not run locally. This approval does not establish whole-stack integration or deployment.

@mldangelo-oai
mldangelo-oai merged commit 9703469 into main Oct 4, 2026
62 checks passed
@mldangelo-oai
mldangelo-oai deleted the mdangelo/codex/simplify-07-artifacts branch October 4, 2026 22:07
@github-actions github-actions Bot mentioned this pull request Oct 4, 2026
3 tasks done
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants