Chronicle/Defense & research

OpenAI relaunches Aardvark as Codex Security, reporting 1.2M commits scanned and 14 CVEs

DefenseTool releaseSignificance assistant-drafted

OpenAI renamed Aardvark to Codex Security and opened a research preview to ChatGPT Pro, Enterprise, Business and Edu customers. OpenAI reports that in 30 days it scanned over 1.2 million commits in its beta cohort and flagged 792 critical and 10,561 high-severity findings, that beta changes cut false positives by more than 50%, and that its open-source reports led to 14 CVEs.

Why it matters

It gives rare operational-scale figures, self-reported by the vendor, on AI code-scanning volume and false-positive reduction, alongside a program for open-source maintainers.

Key facts

As stated in the sources, with where to find them.

  • Over the last 30 days, Codex Security scanned more than 1.2 million commits and identified 792 critical and 10,561 high-severity findings; critical issues appeared in under 0.1% of scanned commits.Section 'How Codex Security works'
  • During beta, noise on one repository fell 84%, over-reported severity fell by more than 90%, and false positive rates fell by more than 50% across repositories.Introduction
  • OpenAI says it reported critical vulnerabilities to open-source projects including OpenSSH, GnuTLS, GOGS, Thorium, libssh, PHP and Chromium, and that 14 CVEs have been assigned (two co-reported); appendix examples include CVE-2025-32990 in GnuTLS.Section 'Supporting the open source community' and Appendix

Findings that cite this record

No tracked finding cites this record yet.

Sources

Related records