chore(deps): bump openai/codex-action from 1.11 to 1.12 (#3768)
Update the scheduled Python-review Codex action to v1.12. The existing unprivileged-user strategy, named permission profile, and --ephemeral argument remain supported; the drop-sudo restrictions do not apply to this workflow. Verified the upstream argument-validation logic accepts these inputs and preserves the named profile. No SDK runtime or package dependency changes. Merged current main. Verified full upstream release SHA pins and the repository Python-policy check. No new tests added for these pin-only updates. The scheduled workflow cannot be exercised by ordinary PR CI; its live execution remains a post-merge validation. --- Bumps [openai/codex-action](https://github.com/openai/codex-action) from 1.11 to 1.12. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/openai/codex-action/blob/main/CHANGELOG.md">openai/codex-action's changelog</a>.</em></p> <blockquote> <h1>codex-action Changelog</h1> <h2><a href="https://github.com/openai/codex-action/tree/v1.12">v1.12</a> (2026-08-20)</h2> <ul> <li>Strengthen Linux runner privilege isolation and Responses API proxy credential handling.</li> <li>Reject Codex arguments and configuration overrides that conflict with protected execution settings.</li> <li>Require unprivileged user namespaces for Linux <code>drop-sudo</code>; run the action after steps that need <code>sudo</code>, Docker, or privileged service sockets.</li> <li>Document runner requirements, permission-profile behavior, and trusted configuration boundaries.</li> </ul> <h2><a href="https://github.com/openai/codex-action/tree/v1.11">v1.11</a> (2026-07-04)</h2> <ul> <li><a href="https://redirect.github.com/openai/codex-action/pull/116">#116</a> keep the permission profile helper backward compatible</li> </ul> <h2><a href="https://github.com/openai/codex-action/tree/v1.10">v1.10</a> (2026-07-02)</h2> <ul> <li><a href="https://redirect.github.com/openai/codex-action/pull/113">#113</a> add Codex permission profile support</li> </ul> <h2><a href="https://github.com/openai/codex-action/tree/v1.9">v1.9</a> (2026-06-22)</h2> <ul> <li><a href="https://redirect.github.com/openai/codex-action/pull/85">#85</a> update the internal <code>setup-node</code> pin to <code>v6.3.0</code></li> </ul> <h2><a href="https://github.com/openai/codex-action/tree/v1.8">v1.8</a> (2026-04-29)</h2> <ul> <li><a href="https://redirect.github.com/openai/codex-action/pull/91">#91</a> tighten what bots are allowed</li> </ul> <h2><a href="https://github.com/openai/codex-action/tree/v1.7">v1.7</a> (2026-04-24)</h2> <ul> <li><a href="https://redirect.github.com/openai/codex-action/pull/89">#89</a> restrict bot permission bypass</li> </ul> <h2><a href="https://github.com/openai/codex-action/tree/v1.6">v1.6</a> (2026-03-16)</h2> <ul> <li><a href="https://redirect.github.com/openai/codex-action/pull/77">#77</a> enable GitHub-hosted Linux bubblewrap support</li> </ul> <h2><a href="https://github.com/openai/codex-action/tree/v1.5">v1.5</a> (2026-03-16)</h2> <ul> <li><a href="https://redirect.github.com/openai/codex-action/pull/74">#74</a> harden shell interpolation in action workflows</li> </ul> <h2><a href="https://github.com/openai/codex-action/tree/v1.4">v1.4</a> (2025-11-19)</h2> <ul> <li><a href="https://redirect.github.com/openai/codex-action/pull/58">#58</a> revert <a href="https://redirect.github.com/openai/codex-action/issues/56">#56</a> and use the latest stable version of Codex CLI again</li> </ul> <h2><a href="https://github.com/openai/codex-action/tree/v1.3">v1.3</a> (2025-11-19)</h2> <ul> <li><a href="https://redirect.github.com/openai/codex-action/pull/56">#56</a> temporarily set the default version of Codex CLI to <code>0.58.0</code></li> </ul> <h2><a href="https://github.com/openai/codex-action/tree/v1.2">v1.2</a> (2025-11-07)</h2> <ul> <li><a href="https://redirect.github.com/openai/codex-action/pull/52">#52</a> add <code>baseUrl</code> to <code>Octokit</code> constructor, if appropriate, for GHE</li> </ul> <h2><a href="https://github.com/openai/codex-action/tree/v1.1">v1.1</a> (2025-11-05)</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/openai/codex-action/commit/86365089eb2b84e0a8fb0717b304f8bdcb13b20e"><code>8636508</code></a> fix: improve runner setup and configuration handling</li> <li><a href="https://github.com/openai/codex-action/commit/c385816875cc2fc8e033ed9d1cba96f8c331210e"><code>c385816</code></a> Retry network errors/transient HTTP errors in GitHub API requests (<a href="https://redirect.github.com/openai/codex-action/issues/128">#128</a>)</li> <li><a href="https://github.com/openai/codex-action/commit/dd78cb653811af44014baa08fe954e28d32c1bf9"><code>dd78cb6</code></a> docs: update CHANGELOG for v1.11 (<a href="https://redirect.github.com/openai/codex-action/issues/117">#117</a>)</li> <li>See full diff in <a href="https://github.com/openai/codex-action/compare/52fe01ec70a42f454c9d2ebd47598f9fd6893d56...86365089eb2b84e0a8fb0717b304f8bdcb13b20e">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Marcus Wood <marcuswood@openai.com>
D
dependabot[bot] committed
9c1579b43dba640d2586bd2f6936fa7159385821
Parent: b413abe
Committed by GitHub <noreply@github.com>
on 9/21/2026, 8:53:55 PM