Skip to content

fix: publish history-safe Codex plugin v0.3.2 - #9

Merged
TerminallyLazy merged 1 commit into
mainfrom
codex/security-guidance-v0.3.2
Aug 24, 2026
Merged

fix: publish history-safe Codex plugin v0.3.2#9
TerminallyLazy merged 1 commit into
mainfrom
codex/security-guidance-v0.3.2

Conversation

@TerminallyLazy

@TerminallyLazy TerminallyLazy commented Aug 24, 2026

Copy link
Copy Markdown
Owner

Summary

  • remove token-bearing export examples and require shell-appropriate no-echo or secret-manager injection
  • route support and vulnerability reporting through the canonical repository
  • bump the Codex wrapper to v0.3.2 and add regression validation

Validation

  • sh scripts/validate-plugin.sh
  • Codex plugin package validator
  • JSON validation
  • git diff --check

Carries the reviewed fixes from TerminallyLazy/Tree-Ring-Memory#48 into the public ZIP source.

High-level PR Summary

This PR publishes version 0.3.2 of the Tree Ring Memory Codex plugin with security improvements that prevent coordinator tokens from being exposed in shell history. The changes replace direct export command examples with guidance to use history-safe, no-echo prompts or approved secret managers, consolidate support and vulnerability reporting links to point to the canonical repository, and add validation checks to ensure these security requirements are enforced in the plugin package. The version bump is accompanied by regression validation to maintain compatibility with Tree Ring Memory CLI v0.14.0+.

⏱️ Estimated Review Time: 15-30 minutes

💡 Review Order Suggestion
Order File Path
1 scripts/validate-plugin.sh
2 .codex-plugin/plugin.json
3 README.md
4 skills/tree-ring-memory/SKILL.md
5 SECURITY.md
6 PRIVACY.md
7 TERMS.md
8 SUBMISSION.md

Need help? Join our Discord

@coderabbitai

coderabbitai Bot commented Aug 24, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: d7bd3e1d-d980-44a7-a9c2-e58a66c1a8a4


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@qodo-code-review

Copy link
Copy Markdown

Qodo reviews are paused for this user.

Troubleshooting steps vary by plan Learn more →

On a Teams plan?
Reviews resume once this user has a paid seat and their Git account is linked in Qodo.
Link Git account →

Using GitHub Enterprise Server, GitLab Self-Managed, or Bitbucket Data Center?
These require an Enterprise plan - Contact us
Contact us →

@TerminallyLazy
TerminallyLazy merged commit ca85464 into main Aug 24, 2026
4 of 5 checks passed
@TerminallyLazy
TerminallyLazy deleted the codex/security-guidance-v0.3.2 branch August 24, 2026 04:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant