SIGN IN SIGN UP

chore(deps): bump openai/codex-action from 1.11 to 1.12 (#3768)

Update the scheduled Python-review Codex action to v1.12. The existing
unprivileged-user strategy, named permission profile, and --ephemeral
argument remain supported; the drop-sudo restrictions do not apply to
this workflow. Verified the upstream argument-validation logic accepts
these inputs and preserves the named profile. No SDK runtime or package
dependency changes.

Merged current main. Verified full upstream release SHA pins and the
repository Python-policy check. No new tests added for these pin-only
updates.

The scheduled workflow cannot be exercised by ordinary PR CI; its live
execution remains a post-merge validation.

---

Bumps [openai/codex-action](https://github.com/openai/codex-action) from
1.11 to 1.12.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/openai/codex-action/blob/main/CHANGELOG.md">openai/codex-action's
changelog</a>.</em></p>
<blockquote>
<h1>codex-action Changelog</h1>
<h2><a
href="https://github.com/openai/codex-action/tree/v1.12">v1.12</a>
(2026-08-20)</h2>
<ul>
<li>Strengthen Linux runner privilege isolation and Responses API proxy
credential handling.</li>
<li>Reject Codex arguments and configuration overrides that conflict
with protected execution settings.</li>
<li>Require unprivileged user namespaces for Linux
<code>drop-sudo</code>; run the action after steps that need
<code>sudo</code>, Docker, or privileged service sockets.</li>
<li>Document runner requirements, permission-profile behavior, and
trusted configuration boundaries.</li>
</ul>
<h2><a
href="https://github.com/openai/codex-action/tree/v1.11">v1.11</a>
(2026-07-04)</h2>
<ul>
<li><a
href="https://redirect.github.com/openai/codex-action/pull/116">#116</a>
keep the permission profile helper backward compatible</li>
</ul>
<h2><a
href="https://github.com/openai/codex-action/tree/v1.10">v1.10</a>
(2026-07-02)</h2>
<ul>
<li><a
href="https://redirect.github.com/openai/codex-action/pull/113">#113</a>
add Codex permission profile support</li>
</ul>
<h2><a href="https://github.com/openai/codex-action/tree/v1.9">v1.9</a>
(2026-06-22)</h2>
<ul>
<li><a
href="https://redirect.github.com/openai/codex-action/pull/85">#85</a>
update the internal <code>setup-node</code> pin to
<code>v6.3.0</code></li>
</ul>
<h2><a href="https://github.com/openai/codex-action/tree/v1.8">v1.8</a>
(2026-04-29)</h2>
<ul>
<li><a
href="https://redirect.github.com/openai/codex-action/pull/91">#91</a>
tighten what bots are allowed</li>
</ul>
<h2><a href="https://github.com/openai/codex-action/tree/v1.7">v1.7</a>
(2026-04-24)</h2>
<ul>
<li><a
href="https://redirect.github.com/openai/codex-action/pull/89">#89</a>
restrict bot permission bypass</li>
</ul>
<h2><a href="https://github.com/openai/codex-action/tree/v1.6">v1.6</a>
(2026-03-16)</h2>
<ul>
<li><a
href="https://redirect.github.com/openai/codex-action/pull/77">#77</a>
enable GitHub-hosted Linux bubblewrap support</li>
</ul>
<h2><a href="https://github.com/openai/codex-action/tree/v1.5">v1.5</a>
(2026-03-16)</h2>
<ul>
<li><a
href="https://redirect.github.com/openai/codex-action/pull/74">#74</a>
harden shell interpolation in action workflows</li>
</ul>
<h2><a href="https://github.com/openai/codex-action/tree/v1.4">v1.4</a>
(2025-11-19)</h2>
<ul>
<li><a
href="https://redirect.github.com/openai/codex-action/pull/58">#58</a>
revert <a
href="https://redirect.github.com/openai/codex-action/issues/56">#56</a>
and use the latest stable version of Codex CLI again</li>
</ul>
<h2><a href="https://github.com/openai/codex-action/tree/v1.3">v1.3</a>
(2025-11-19)</h2>
<ul>
<li><a
href="https://redirect.github.com/openai/codex-action/pull/56">#56</a>
temporarily set the default version of Codex CLI to
<code>0.58.0</code></li>
</ul>
<h2><a href="https://github.com/openai/codex-action/tree/v1.2">v1.2</a>
(2025-11-07)</h2>
<ul>
<li><a
href="https://redirect.github.com/openai/codex-action/pull/52">#52</a>
add <code>baseUrl</code> to <code>Octokit</code> constructor, if
appropriate, for GHE</li>
</ul>
<h2><a href="https://github.com/openai/codex-action/tree/v1.1">v1.1</a>
(2025-11-05)</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/openai/codex-action/commit/86365089eb2b84e0a8fb0717b304f8bdcb13b20e"><code>8636508</code></a>
fix: improve runner setup and configuration handling</li>
<li><a
href="https://github.com/openai/codex-action/commit/c385816875cc2fc8e033ed9d1cba96f8c331210e"><code>c385816</code></a>
Retry network errors/transient HTTP errors in GitHub API requests (<a
href="https://redirect.github.com/openai/codex-action/issues/128">#128</a>)</li>
<li><a
href="https://github.com/openai/codex-action/commit/dd78cb653811af44014baa08fe954e28d32c1bf9"><code>dd78cb6</code></a>
docs: update CHANGELOG for v1.11 (<a
href="https://redirect.github.com/openai/codex-action/issues/117">#117</a>)</li>
<li>See full diff in <a
href="https://github.com/openai/codex-action/compare/52fe01ec70a42f454c9d2ebd47598f9fd6893d56...86365089eb2b84e0a8fb0717b304f8bdcb13b20e">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=openai/codex-action&package-manager=github_actions&previous-version=1.11&new-version=1.12)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Marcus Wood <marcuswood@openai.com>
D
dependabot[bot] committed
9c1579b43dba640d2586bd2f6936fa7159385821
Parent: b413abe
Committed by GitHub <noreply@github.com> on 9/21/2026, 8:53:55 PM