[docs] Add security boundaries reference in SECURITY.md (#17848)

## Summary
1. Add a Security Boundaries section to `SECURITY.md`.
2. Point readers to the Codex Agent approvals and security documentation
for sandboxing, approvals, and network controls.

## Validation
1. Reviewed the `SECURITY.md` diff in a clean worktree.
2. No tests run. Docs only change.
This commit is contained in:
evawong-oai
2026-04-15 13:12:46 -07:00
committed by GitHub
Unverified
parent f2a4925f63
commit 0bb438bca6
6 changed files with 131 additions and 8 deletions
+54 -1
View File
@@ -1,4 +1,4 @@
load("//:defs.bzl", "codex_rust_crate")
load("//:defs.bzl", "codex_rust_crate", "workspace_root_test")
filegroup(
name = "model_availability_nux_fixtures",
@@ -31,6 +31,15 @@ codex_rust_crate(
"//codex-rs/apply-patch:apply_patch_tool_instructions.md",
"templates/realtime/backend_prompt.md",
],
integration_test_flaky_by_stem = {
"all": [
"suite::abort_tasks::interrupt_tool_records_history_entries",
"suite::apply_patch_cli::apply_patch_cli_rejects_invalid_hunk_header::applypatchmodeloutput_function_expects",
],
"responses_headers": [
"responses_stream_includes_turn_metadata_header_for_git_workspace_e2e",
],
},
integration_test_timeout = "long",
test_data_extra = [
"config.schema.json",
@@ -48,6 +57,12 @@ codex_rust_crate(
"//:AGENTS.md",
],
test_tags = ["no-sandbox"],
unit_test_args = [
"--skip",
"guardian::tests::guardian_parallel_reviews_fork_from_last_committed_trunk_history",
"--skip",
"agent::control::tests::completion_watcher_notifies_parent_when_child_is_missing",
],
unit_test_timeout = "long",
extra_binaries = [
"//codex-rs/linux-sandbox:codex-linux-sandbox",
@@ -57,3 +72,41 @@ codex_rust_crate(
"//codex-rs/cli:codex",
],
)
workspace_root_test(
name = "core-guardian-parallel-reviews-flaky-test",
env = {
"INSTA_WORKSPACE_ROOT": ".",
"INSTA_SNAPSHOT_PATH": "src",
},
test_bin = ":core-unit-tests-bin",
workspace_root_marker = "//codex-rs/utils/cargo-bin:repo_root.marker",
args = [
"--exact",
"guardian::tests::guardian_parallel_reviews_fork_from_last_committed_trunk_history",
],
tags = [
"flaky",
"no-sandbox",
],
timeout = "long",
)
workspace_root_test(
name = "core-completion-watcher-missing-child-flaky-test",
env = {
"INSTA_WORKSPACE_ROOT": ".",
"INSTA_SNAPSHOT_PATH": "src",
},
test_bin = ":core-unit-tests-bin",
workspace_root_marker = "//codex-rs/utils/cargo-bin:repo_root.marker",
args = [
"--exact",
"agent::control::tests::completion_watcher_notifies_parent_when_child_is_missing",
],
tags = [
"flaky",
"no-sandbox",
],
timeout = "long",
)