migrate: snake_case -> kebab-case (#10)
This commit is contained in:
@@ -23,59 +23,60 @@ jobs:
|
||||
uses: openai/codex-action@main
|
||||
id: codex
|
||||
with:
|
||||
openai_api_key: ${{ secrets.OPENAI_API_KEY }}
|
||||
openai-api-key: ${{ secrets.OPENAI_API_KEY }}
|
||||
prompt: ${{ github.event.inputs.prompt }}
|
||||
```
|
||||
|
||||
Provide either `prompt` or `prompt_file`; the other may be left empty. The action streams Codex output to the job logs and exposes the final message as an output named `final_message` for downstream steps.
|
||||
Provide either `prompt` or `prompt-file`; the other may be left empty. The action streams Codex output to the job logs and exposes the final message as an output named `final-message` for downstream steps.
|
||||
|
||||
## Inputs
|
||||
|
||||
| Name | Required | Description | Default |
|
||||
| -------------------- | ------------- | --------------------------------------------------------------------------------------------------------------------------------------- | ---------------- |
|
||||
| `openai_api_key` | Yes | Secret used to authenticate the helper proxy with OpenAI. Store it in `secrets` and never hardcode it. | — |
|
||||
| `prompt` | Conditionally | Inline prompt text. Provide this or `prompt_file`. | `""` |
|
||||
| `prompt_file` | Conditionally | Path (relative to the repository root) of a file that contains the prompt. Provide this or `prompt`. | `""` |
|
||||
| `output_file` | No | File where the final Codex message is written. Leave empty to skip writing a file. | `""` |
|
||||
| `working_directory` | No | Directory passed to `codex exec --cd`. Defaults to the repository root. | `""` |
|
||||
| `openai-api-key` | Yes | Secret used to authenticate the helper proxy with OpenAI. Store it in `secrets` and never hardcode it. | — |
|
||||
| `prompt` | Conditionally | Inline prompt text. Provide this or `prompt-file`. | `""` |
|
||||
| `prompt-file` | Conditionally | Path (relative to the repository root) of a file that contains the prompt. Provide this or `prompt`. | `""` |
|
||||
| `output-file` | No | File where the final Codex message is written. Leave empty to skip writing a file. | `""` |
|
||||
| `working-directory` | No | Directory passed to `codex exec --cd`. Defaults to the repository root. | `""` |
|
||||
| `sandbox` | No | Sandbox mode for Codex. One of `workspace-write` (default), `read-only` or `danger-full-access`. | `""` |
|
||||
| `codex_version` | No | Version of `@openai/codex` to install. | `0.42.0-alpha.3` |
|
||||
| `codex_args` | No | Extra arguments forwarded to `codex exec`. Accepts JSON arrays (`["--flag", "value"]`) or shell-style strings. | `""` |
|
||||
| `output_schema` | No | Inline schema contents written to a temp file and passed to `codex exec --output-schema`. Mutually exclusive with `output_schema_file`. | `""` |
|
||||
| `output_schema_file` | No | Schema file forwarded to `codex exec --output-schema`. Leave empty to skip passing the option. | `""` |
|
||||
| `codex-version` | No | Version of `@openai/codex` to install. | `0.42.0-alpha.3` |
|
||||
| `codex-args` | No | Extra arguments forwarded to `codex exec`. Accepts JSON arrays (`["--flag", "value"]`) or shell-style strings. | `""` |
|
||||
| `output-schema` | No | Inline schema contents written to a temp file and passed to `codex exec --output-schema`. Mutually exclusive with `output-schema-file`. | `""` |
|
||||
| `output-schema-file` | No | Schema file forwarded to `codex exec --output-schema`. Leave empty to skip passing the option. | `""` |
|
||||
| `model` | No | Model the agent should use. Leave empty to let Codex pick its default. | `""` |
|
||||
| `codex_home` | No | Directory to use as the Codex CLI home (config/cache). Uses the CLI default when empty. | `""` |
|
||||
| `safety_strategy` | No | Controls how the action restricts Codex privileges. See [Safety strategy](#safety-strategy). | `drop_sudo` |
|
||||
| `codex_user` | No | Username to run Codex as when `safety_strategy` is `unprivileged_user`. | `""` |
|
||||
| `require_repo_write` | No | Whether to require the triggering actor to have write access to the repository before running. | "true" |
|
||||
| `allow_bots` | No | Allow runs triggered by GitHub Apps/bot accounts to bypass the write-access check. | "false" |
|
||||
| `codex-home` | No | Directory to use as the Codex CLI home (config/cache). Uses the CLI default when empty. | `""` |
|
||||
| `safety-strategy` | No | Controls how the action restricts Codex privileges. See [Safety strategy](#safety-strategy). | `drop-sudo` |
|
||||
| `codex-user` | No | Username to run Codex as when `safety-strategy` is `unprivileged-user`. | `""` |
|
||||
| `require-repo-write` | No | Whether to require the triggering actor to have write access to the repository before running. | "true" |
|
||||
| `allow-bots` | No | Allow runs triggered by GitHub Apps/bot accounts to bypass the write-access check. | "false" |
|
||||
|
||||
## Safety Strategy
|
||||
|
||||
The `safety_strategy` input determines how much access Codex receives on the runner. Choosing the right option is critical, especially when sensitive secrets (like your OpenAI API key) are present.
|
||||
- The `safety-strategy` input determines how much access Codex receives on the runner. Choosing the right option is critical, especially when sensitive secrets (like your OpenAI API key) are present.
|
||||
|
||||
- **`drop_sudo` (default)** — On Linux and macOS runners, the action revokes the default user’s `sudo` membership before invoking Codex. Codex then runs as that user without superuser privileges. This change lasts for the rest of the job, so subsequent steps cannot rely on `sudo`. This is usually the safest choice on GitHub-hosted runners.
|
||||
- **`unprivileged_user`** — Runs Codex as the user provided via `codex_user`. Use this if you manage your own runner with a pre-created unprivileged account. Ensure the user can read the repository checkout and any files Codex needs.
|
||||
- **`read_only`** — Executes Codex in a read-only sandbox. Codex can view files but cannot mutate the filesystem or access the network directly. The OpenAI API key still flows through the proxy, so Codex could read it if it can reach process memory.
|
||||
- **`drop-sudo` (default)** — On Linux and macOS runners, the action revokes the default user’s `sudo` membership before invoking Codex. Codex then runs as that user without superuser privileges. This change lasts for the rest of the job, so subsequent steps cannot rely on `sudo`. This is usually the safest choice on GitHub-hosted runners.
|
||||
- **`unprivileged-user`** — Runs Codex as the user provided via `codex-user`. Use this if you manage your own runner with a pre-created unprivileged account. Ensure the user can read the repository checkout and any files Codex needs.
|
||||
- **`read-only`** — Executes Codex in a read-only sandbox. Codex can view files but cannot mutate the filesystem or access the network directly. The OpenAI API key still flows through the proxy, so Codex could read it if it can reach process memory.
|
||||
- **`unsafe`** — No privilege reduction. Codex runs as the default `runner` user (which typically has `sudo`). Only use this when you fully trust the prompt. On Windows runners this is the only supported choice and the action will fail if another option is provided.
|
||||
|
||||
### Operating system support
|
||||
|
||||
- **Windows**: GitHub-hosted Windows runners lack a supported sandbox. Set `safety_strategy: unsafe`. The action validates this and exits early otherwise.
|
||||
- **Linux/macOS**: All options for `safety_strategy` are supported. Again, if you pick `drop_sudo`, remember that later steps in your `job` that rely on `sudo` will fail. If you do need to run code that requires `sudo` after `openai/codex-action` has run, one option is to pipe the output of `openai/codex-action` to a fresh `job` on a new host and to continue your workflow from there.
|
||||
- **Windows**: GitHub-hosted Windows runners lack a supported sandbox. Set `safety-strategy: unsafe`. The action validates this and exits early otherwise.
|
||||
- **Linux/macOS**: All options for `safety-strategy` are supported. Again, if you pick `drop-sudo`, remember that later steps in your `job` that rely on `sudo` will fail. If you do need to run code that requires `sudo` after `openai/codex-action` has run, one option is to pipe the output of `openai/codex-action` to a fresh `job` on a new host and to continue your workflow from there.
|
||||
|
||||
## Outputs
|
||||
|
||||
| Name | Description |
|
||||
| --------------- | --------------------------------------- |
|
||||
| `final_message` | Final message returned by `codex exec`. |
|
||||
| `final-message` | Final message returned by `codex exec`. |
|
||||
|
||||
You can reference the output from later steps:
|
||||
|
||||
```yaml
|
||||
# steps.codex refers to the `id: codex` step in the above example.
|
||||
- name: Capture Codex result
|
||||
run: echo "Codex said: ${{ steps.codex.outputs.final_message }}"
|
||||
run: |
|
||||
echo "New Codex said: ${{ steps.codex.outputs.final-message }}"
|
||||
```
|
||||
|
||||
Replace `steps.codex` with the `id` assigned to your action step.
|
||||
@@ -84,7 +85,7 @@ Replace `steps.codex` with the `id` assigned to your action step.
|
||||
|
||||
- Run this action after `actions/checkout@v5` so Codex has access to your repository contents.
|
||||
- If you want Codex to have access to a narrow set of privileged functionality, consider running a local MCP server that can perform these actions and configure Codex to use it.
|
||||
- If you need more control over the CLI invocation, pass flags through `codex_args` or create a `config.toml` in `codex_home`.
|
||||
- If you need more control over the CLI invocation, pass flags through `codex-args` or create a `config.toml` in `codex-home`.
|
||||
|
||||
## License
|
||||
|
||||
|
||||
+48
-48
@@ -3,22 +3,22 @@ description: "Run `codex exec` with a prompt."
|
||||
author: "OpenAI"
|
||||
inputs:
|
||||
prompt:
|
||||
description: "Prompt to pass to `codex exec`. `prompt` or `prompt_file` must be provided."
|
||||
description: "Prompt to pass to Codex. `prompt` or `prompt-file` must be provided."
|
||||
required: false
|
||||
default: ""
|
||||
prompt_file:
|
||||
description: "Path to file that contains the prompt to pass to `codex exec`. `prompt` or `prompt_file` must be provided."
|
||||
prompt-file:
|
||||
description: "Path to file that contains the prompt to pass to Codex. `prompt` or `prompt-file` must be provided."
|
||||
required: false
|
||||
default: ""
|
||||
output_file:
|
||||
description: "Path to a JSON Schema file describing the model's final response shape."
|
||||
output-file:
|
||||
description: "File where the final Codex message is written. Leave empty to skip writing a file."
|
||||
required: false
|
||||
default: ""
|
||||
openai_api_key:
|
||||
description: "OpenAI API key used by the Codex CLI."
|
||||
openai-api-key:
|
||||
description: "OpenAI API key used by Codex."
|
||||
required: true
|
||||
working_directory:
|
||||
description: "Optional working directory to `cd` into before running `codex exec`."
|
||||
working-directory:
|
||||
description: "Working directory that Codex should use. Defaults to the repository root."
|
||||
required: false
|
||||
default: ""
|
||||
sandbox:
|
||||
@@ -26,72 +26,72 @@ inputs:
|
||||
Sandbox mode for Codex. One of `workspace-write` (default), `read-only` or `danger-full-access`.
|
||||
required: false
|
||||
default: "workspace-write"
|
||||
codex_version:
|
||||
codex-version:
|
||||
description: "Version of `@openai/codex` to install."
|
||||
required: false
|
||||
default: "0.43.0-alpha.17"
|
||||
codex_args:
|
||||
codex-args:
|
||||
description: "Additional args to pass through to `codex exec`. If this value starts with `[`, it will be parsed as a JSON array; otherwise, it will be parsed as a shell-like string."
|
||||
required: false
|
||||
default: ""
|
||||
output_schema:
|
||||
output-schema:
|
||||
description: "Inline schema contents to use with `codex exec --output-schema`."
|
||||
required: false
|
||||
default: ""
|
||||
output_schema_file:
|
||||
output-schema-file:
|
||||
description: "File path to the schema that should be passed to `codex exec --output-schema`."
|
||||
required: false
|
||||
default: ""
|
||||
model:
|
||||
description: "Model the agent should use"
|
||||
description: "Model the agent should use."
|
||||
required: false
|
||||
default: ""
|
||||
codex_home:
|
||||
codex-home:
|
||||
description: "Directory to use as the Codex home directory. If empty, the default Codex home directory will be used."
|
||||
required: false
|
||||
default: ""
|
||||
safety_strategy:
|
||||
safety-strategy:
|
||||
description: |
|
||||
Specify one of the following options (on Windows, the only supported option is `unsafe`):
|
||||
|
||||
* `drop_sudo` (default, IRREVERSIBLE) Drop sudo privileges (if any) from
|
||||
* `drop-sudo` (default, IRREVERSIBLE) Drop sudo privileges (if any) from
|
||||
the default user before running Codex, and run Codex as that user. This
|
||||
is only supported on Linux and macOS runners. This option is
|
||||
irreversible: if the default user has sudo privileges, they will be
|
||||
removed permanently for the duration of the job.
|
||||
* `unprivileged_user` Run Codex as the specified user specified by the
|
||||
`codex_user` option (the user must already exist). Note the caller is
|
||||
* `unprivileged-user` Run Codex as the specified user specified by the
|
||||
`codex-user` option (the user must already exist). Note the caller is
|
||||
responsible for ensuring the specified user has the privileges it needs
|
||||
to perform the requested actions. For example, the copy of the repo
|
||||
created by `actions/checkout` is not world-readable by default.
|
||||
* `read_only` Run Codex in a sandbox that can read any file on disk,
|
||||
* `read-only` Run Codex in a sandbox that can read any file on disk,
|
||||
but cannot write to disk or access the network. Note Codex will still
|
||||
run as the default user for this Action, which likely has sudo
|
||||
privileges, so it could read `openai_api_key` from memory and reveal it
|
||||
privileges, so it could read `openai-api-key` from memory and reveal it
|
||||
by printing it to the output of the GitHub Action.
|
||||
* `unsafe` (NOT RECOMMENDED) Do not try to restrict Codex's privileges at all.
|
||||
This is extremely dangerous, as the default user for this Action likely
|
||||
has sudo privileges, which means it can read secrets stored in memory
|
||||
(such as the value of `openai_api_key`) and print them to the output
|
||||
(such as the value of `openai-api-key`) and print them to the output
|
||||
of the GitHub Action or exfiltrate them in other ways.
|
||||
required: false
|
||||
default: "drop_sudo"
|
||||
codex_user:
|
||||
description: "If `safety_strategy` is set to `unprivileged_user`, this specifies the UNIX username to run Codex as."
|
||||
default: "drop-sudo"
|
||||
codex-user:
|
||||
description: "If `safety-strategy` is set to `unprivileged-user`, this specifies the UNIX username to run Codex as."
|
||||
required: false
|
||||
default: ""
|
||||
require_repo_write:
|
||||
require-repo-write:
|
||||
description: "Whether to require the triggering actor to have write access to the repository before running."
|
||||
required: false
|
||||
default: "true"
|
||||
allow_bots:
|
||||
allow-bots:
|
||||
description: "Allow runs triggered by GitHub Apps/bot accounts to bypass the write-access check."
|
||||
required: false
|
||||
default: "false"
|
||||
outputs:
|
||||
final_message:
|
||||
final-message:
|
||||
description: "Raw output emitted by `codex exec`."
|
||||
value: ${{ steps.run_codex.outputs.final_message }}
|
||||
value: ${{ steps.run_codex.outputs['final-message'] }}
|
||||
runs:
|
||||
using: "composite"
|
||||
steps:
|
||||
@@ -99,8 +99,8 @@ runs:
|
||||
if: ${{ runner.os == 'Windows' }}
|
||||
shell: bash
|
||||
run: |
|
||||
if [ "${{ inputs.safety_strategy }}" != "unsafe" ]; then
|
||||
echo "On Windows, inputs.safety_strategy must be 'unsafe'" >&2
|
||||
if [ "${{ inputs['safety-strategy'] }}" != "unsafe" ]; then
|
||||
echo "On Windows, inputs['safety-strategy'] must be 'unsafe'" >&2
|
||||
echo "because no viable sandboxing options are available at this time." >&2
|
||||
exit 1
|
||||
fi
|
||||
@@ -111,9 +111,9 @@ runs:
|
||||
node-version: "20"
|
||||
|
||||
- name: Check repository write access
|
||||
if: ${{ inputs.require_repo_write == 'true' }}
|
||||
if: ${{ inputs['require-repo-write'] == 'true' }}
|
||||
env:
|
||||
ALLOW_BOTS: ${{ inputs.allow_bots }}
|
||||
ALLOW_BOTS: ${{ inputs['allow-bots'] }}
|
||||
GITHUB_TOKEN: ${{ github.token }}
|
||||
shell: bash
|
||||
run: |
|
||||
@@ -121,16 +121,16 @@ runs:
|
||||
|
||||
- name: Install Codex CLI
|
||||
shell: bash
|
||||
run: npm install -g "@openai/codex@${{ inputs.codex_version }}"
|
||||
run: npm install -g "@openai/codex@${{ inputs['codex-version'] }}"
|
||||
|
||||
- name: Install Codex Responses API proxy
|
||||
shell: bash
|
||||
run: npm install -g "@openai/codex-responses-api-proxy@${{ inputs.codex_version }}"
|
||||
run: npm install -g "@openai/codex-responses-api-proxy@${{ inputs['codex-version'] }}"
|
||||
|
||||
- name: Start Responses API proxy
|
||||
id: start_proxy
|
||||
env:
|
||||
OPENAI_API_KEY: ${{ inputs.openai_api_key }}
|
||||
OPENAI_API_KEY: ${{ inputs['openai-api-key'] }}
|
||||
shell: bash
|
||||
run: |
|
||||
tmpfile=$(mktemp)
|
||||
@@ -156,7 +156,7 @@ runs:
|
||||
run: node "${{ github.action_path }}/dist/main.js" read-server-info "${{ steps.start_proxy.outputs.server_info_file }}"
|
||||
|
||||
- name: Drop sudo privilege, if appropriate
|
||||
if: ${{ inputs.safety_strategy == 'drop_sudo' }}
|
||||
if: ${{ inputs['safety-strategy'] == 'drop-sudo' }}
|
||||
shell: bash
|
||||
run: |
|
||||
case "${RUNNER_OS}" in
|
||||
@@ -167,13 +167,13 @@ runs:
|
||||
node "${{ github.action_path }}/dist/main.js" drop-sudo --user runner --group admin
|
||||
;;
|
||||
*)
|
||||
echo "Unsupported OS for drop_sudo: ${RUNNER_OS}" >&2
|
||||
echo "Unsupported OS for drop-sudo: ${RUNNER_OS}" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
- name: Verify sudo privilege removed
|
||||
if: ${{ inputs.safety_strategy == 'drop_sudo' }}
|
||||
if: ${{ inputs['safety-strategy'] == 'drop-sudo' }}
|
||||
shell: bash
|
||||
run: |
|
||||
if sudo -n true 2>/dev/null; then
|
||||
@@ -186,17 +186,17 @@ runs:
|
||||
id: run_codex
|
||||
env:
|
||||
CODEX_PROMPT: ${{ inputs.prompt }}
|
||||
CODEX_PROMPT_FILE: ${{ inputs.prompt_file }}
|
||||
CODEX_OUTPUT_FILE: ${{ inputs.output_file }}
|
||||
CODEX_HOME: ${{ inputs.codex_home }}
|
||||
CODEX_WORKING_DIRECTORY: ${{ inputs.working_directory || github.workspace }}
|
||||
CODEX_PROMPT_FILE: ${{ inputs['prompt-file'] }}
|
||||
CODEX_OUTPUT_FILE: ${{ inputs['output-file'] }}
|
||||
CODEX_HOME: ${{ inputs['codex-home'] }}
|
||||
CODEX_WORKING_DIRECTORY: ${{ inputs['working-directory'] || github.workspace }}
|
||||
CODEX_SANDBOX: ${{ inputs.sandbox }}
|
||||
CODEX_ARGS: ${{ inputs.codex_args }}
|
||||
CODEX_OUTPUT_SCHEMA: ${{ inputs.output_schema }}
|
||||
CODEX_OUTPUT_SCHEMA_FILE: ${{ inputs.output_schema_file }}
|
||||
CODEX_ARGS: ${{ inputs['codex-args'] }}
|
||||
CODEX_OUTPUT_SCHEMA: ${{ inputs['output-schema'] }}
|
||||
CODEX_OUTPUT_SCHEMA_FILE: ${{ inputs['output-schema-file'] }}
|
||||
CODEX_MODEL: ${{ inputs.model }}
|
||||
CODEX_SAFETY_STRATEGY: ${{ inputs.safety_strategy }}
|
||||
CODEX_USER: ${{ inputs.codex_user }}
|
||||
CODEX_SAFETY_STRATEGY: ${{ inputs['safety-strategy'] }}
|
||||
CODEX_USER: ${{ inputs['codex-user'] }}
|
||||
FORCE_COLOR: 1
|
||||
shell: bash
|
||||
run: |
|
||||
|
||||
Vendored
+15
-15
File diff suppressed because one or more lines are too long
+2
-2
@@ -26,7 +26,7 @@ export async function dropSudo(options: DropSudoOptions): Promise<void> {
|
||||
const platform = process.platform;
|
||||
if (![LINUX_PLATFORM, MACOS_PLATFORM].includes(platform)) {
|
||||
throw new Error(
|
||||
`Unsupported OS for drop_sudo safety strategy: ${platform}`
|
||||
`Unsupported OS for drop-sudo safety strategy: ${platform}`
|
||||
);
|
||||
}
|
||||
|
||||
@@ -118,7 +118,7 @@ async function dropSudoWithPrivileges(options: DropSudoOptions): Promise<void> {
|
||||
}
|
||||
default: {
|
||||
throw new Error(
|
||||
`Unsupported OS for drop_sudo safety strategy: ${process.platform}`
|
||||
`Unsupported OS for drop-sudo safety strategy: ${process.platform}`
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
+8
-8
@@ -91,11 +91,11 @@ export async function main() {
|
||||
.requiredOption("--model <model>", "Model the agent should use")
|
||||
.requiredOption(
|
||||
"--safety-strategy <strategy>",
|
||||
"Safety strategy to use. One of 'drop_sudo', 'read_only', 'unprivileged_user', or 'unsafe'."
|
||||
"Safety strategy to use. One of 'drop-sudo', 'read-only', 'unprivileged-user', or 'unsafe'."
|
||||
)
|
||||
.requiredOption(
|
||||
"--codex-user <user>",
|
||||
"User to run codex exec as when using the 'unprivileged_user' safety strategy."
|
||||
"User to run codex exec as when using the 'unprivileged-user' safety strategy."
|
||||
)
|
||||
.action(
|
||||
async (options: {
|
||||
@@ -138,7 +138,7 @@ export async function main() {
|
||||
promptSource = { type: "file", path: normalizedPromptFile };
|
||||
} else {
|
||||
throw new Error(
|
||||
"Either `prompt` or `prompt_file` must be specified."
|
||||
"Either `prompt` or `prompt-file` must be specified."
|
||||
);
|
||||
}
|
||||
|
||||
@@ -152,7 +152,7 @@ export async function main() {
|
||||
normalizedOutputSchema != null
|
||||
) {
|
||||
throw new Error(
|
||||
"Only one of `output_schema` or `output_schema_file` may be specified."
|
||||
"Only one of `output-schema` or `output-schema-file` may be specified."
|
||||
);
|
||||
}
|
||||
|
||||
@@ -238,14 +238,14 @@ function parseExtraArgs(value: string): Array<string> {
|
||||
|
||||
function toSafetyStrategy(value: string): SafetyStrategy {
|
||||
switch (value) {
|
||||
case "drop_sudo":
|
||||
case "read_only":
|
||||
case "unprivileged_user":
|
||||
case "drop-sudo":
|
||||
case "read-only":
|
||||
case "unprivileged-user":
|
||||
case "unsafe":
|
||||
return value;
|
||||
default:
|
||||
throw new Error(
|
||||
`Invalid safety strategy: ${value}. Must be one of 'drop_sudo', 'read_only', 'unprivileged_user', or 'unsafe'.`
|
||||
`Invalid safety strategy: ${value}. Must be one of 'drop-sudo', 'read-only', 'unprivileged-user', or 'unsafe'.`
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
+7
-7
@@ -14,9 +14,9 @@ export type PromptSource =
|
||||
};
|
||||
|
||||
export type SafetyStrategy =
|
||||
| "drop_sudo"
|
||||
| "read_only"
|
||||
| "unprivileged_user"
|
||||
| "drop-sudo"
|
||||
| "read-only"
|
||||
| "unprivileged-user"
|
||||
| "unsafe";
|
||||
|
||||
export type SandboxMode =
|
||||
@@ -84,10 +84,10 @@ export async function runCodexExec({
|
||||
|
||||
const command: Array<string> = [];
|
||||
|
||||
if (safetyStrategy === "unprivileged_user") {
|
||||
if (safetyStrategy === "unprivileged-user") {
|
||||
if (codexUser == null) {
|
||||
throw new Error(
|
||||
"codexUser must be specified when using the 'unprivileged_user' safety strategy."
|
||||
"codexUser must be specified when using the 'unprivileged-user' safety strategy."
|
||||
);
|
||||
}
|
||||
|
||||
@@ -171,7 +171,7 @@ export async function runCodexExec({
|
||||
async function finalizeExecution(outputFile: OutputFile): Promise<void> {
|
||||
try {
|
||||
const lastMessage = await readFile(outputFile.file, "utf8");
|
||||
setOutput("final_message", lastMessage);
|
||||
setOutput("final-message", lastMessage);
|
||||
} finally {
|
||||
await cleanupTempOutput(outputFile);
|
||||
}
|
||||
@@ -259,7 +259,7 @@ async function determineSandboxMode({
|
||||
safetyStrategy: SafetyStrategy;
|
||||
requestedSandbox: SandboxMode;
|
||||
}): Promise<SandboxMode> {
|
||||
if (safetyStrategy === "read_only") {
|
||||
if (safetyStrategy === "read-only") {
|
||||
return "read-only";
|
||||
} else {
|
||||
return requestedSandbox;
|
||||
|
||||
Reference in New Issue
Block a user