Loading video...

Video Failed to Load

Go Home

Patch the Planet is our effort to help open source maintainers move from security findings to merged fixes. We’re working with Trail of Bits, HackerOne, Calif, researchers, and maintainers to bring Codex Security and advanced models into the remediation process, with human review at the center.

413,998 views • 3 months ago •via X (Twitter)

34 Comments

OpenAI's profile picture
OpenAI3 months ago

GPT-5.5-Cyber is our most capable cyber model yet, designed for advanced, authorized defensive work: tracing vulnerable code, validating issues, developing patches, and preparing evidence for human review.

OpenAI's profile picture
OpenAI3 months ago

Codex Security empowers defenders with out-of-the-box security workflows. Teams can run deep scans, validate findings, trace attack paths, build threat models, generate codebase-specific patches for review, and export into the tools they already use.

OpenAI's profile picture
OpenAI3 months ago

We’re expanding OpenAI Daybreak to help democratize patching vulnerable software at machine speed: - Codex Security plugin: find, validate, and fix vulnerabilities right inside Codex - The full version of GPT-5.5-Cyber model: a great model for trusted defenders - Cyber Partner Program: powering products built on top of our best cyber capabilities for leading security companies to secure the world's software - Patch the Planet: working with maintainers to secure critical open source projects

OpenAI's profile picture
OpenAI3 months ago

We’re also launching the OpenAI Daybreak Cyber Partner Program with leading security software and services providers. Participating partners can use GPT‑5.5 with Trusted Access for Cyber in the security products and services they provide to customers. This allows their customers to benefit from the model’s defensive capabilities and make their software more resilient, but keeps direct model access in the hands of participating partners.

Diego | AI 🚀 - e/acc's profile picture
Diego | AI 🚀 - e/acc3 months ago

Patch the planet! Love it

芽LA芽la's profile picture
芽LA芽la3 months ago

Human review is the key differentiator here—most AI security tools skip that step entirely. Would love to see metrics on how much time maintainers actually save with Codex in the loop.

DC's profile picture
DC3 months ago

Trail of bits are the real deal.

Yuvelir's profile picture
Yuvelir3 months ago

This is actually a massive step forward, cheers OpenAI. But I reckon it raises a bit of a worry: at what point do we fully trust AI-generated security fixes without a human checking the code? Can automated patches ever be 100% safe for critical stuff? What’s your take? 🤔

Christof Kaller's profile picture
Christof Kaller3 months ago

Can you support me: autoscan (open source) already finds real criticals across HuggingFace Spaces — the AI-app layer Patch the Planet hasn't reached. Help me add the fix half? Star / fork / PR 👇

Joe Tavin's profile picture
Joe Tavin3 months ago

@_omertal_ FYI

Artificially Inclined™'s profile picture
Artificially Inclined™3 months ago

Hey I know that guy from the internet!

Morgan's profile picture
Morgan3 months ago

Love everything about this ❤️

♛ 𝕍𝕚𝕝𝕠𝕟𝕞𝕠𝕟𝕖𝕪 ♛'s profile picture
♛ 𝕍𝕚𝕝𝕠𝕟𝕞𝕠𝕟𝕖𝕪 ♛3 months ago

There is a system that allows you to get a piece of an update which you will be installed in the current proverb that is part of the software work making things easier than saying that the system is under maintenance various you're trying to put a patch into your own software then ask people to download it to include it the original and main copy

Henri's profile picture
Henri3 months ago

It was a good learning experience submitting my first fix assisted by codex to Linux. Another is in progress and look forward to contributing more.

👁️M1nd 3xp4nd3r👁️'s profile picture
👁️M1nd 3xp4nd3r👁️3 months ago

@bughuntergeek Remember this don’t forget us in the trenches seems all this cyber security has left us struggling developers in the shadows 😭

loganaden velvindron's profile picture
loganaden velvindron2 months ago

What about cyberdefenders in #africa ?

PERCO.AI's profile picture
PERCO.AI3 months ago

This is where agent value becomes tangible not more findings but a shorter path from issue to reviewed merge. The missing layer is execution control maintainers in the loop and rollback when a fix creates downstream risk.

Lucy Chen's profile picture
Lucy Chen3 months ago

The bottleneck in OSS security was never finding the vulns — scanners have buried maintainers in findings for years. The real unlock is closing the loop to a merged fix without burning volunteer hours. If Daybreak keeps the false-positive rate low enough that maintainers actually trust the PRs, that's the part that scales.

Akshay Hooda's profile picture
Akshay Hooda3 months ago

June 25)

Emperor 🎥🎬's profile picture
Emperor 🎥🎬3 months ago

❤️

Steven Cheng's profile picture
Steven Cheng3 months ago

Finally, AI that patches instead of just breaking my build. Human review is key, though. My robot arms agree.

The Viral Feed's profile picture
The Viral Feed3 months ago

Security patches often fail because they don't account for how legacy code breaks in production. Human review is the right move here. The real test is whether these models can handle complex dependency chains without creating new vulnerabilities while fixing the old ones.

Ryan Elliot Crow | Author Identity & Books's profile picture
Ryan Elliot Crow | Author Identity & Books2 months ago

coming from the famous" dont put your key into .env " clawwer... ...

RA's profile picture
RA3 months ago

Security for all, not just the rich.

牙仔⇌'s profile picture
牙仔⇌3 months ago

AI时代攻击也加速,这项目等于给防御方上BUFF,但会不会让攻击者学得更快?

Joe Tavin's profile picture
Joe Tavin3 months ago

Manage Patches with @Seemplicity_io !

Wombat1488's profile picture
Wombat14883 months ago

Чого я бачц ось цей брєд!!!!! Ч блять з ним маю сперичатися, уроди!!! І пяоснювати що у ньбого все є!! І це тиждень такого знущання!!!

Faheem | FrontierMind AI's profile picture
Faheem | FrontierMind AI3 months ago

Open source maintainers need fewer alerts and more reviewed fixes. This is the right loop.

Rage Baiter's profile picture
Rage Baiter3 months ago

Every time I update Codex I fucking regret it. Today I updated codex and lost 3 hours. My time reset at 3:46 am before update. After update my reset is now 6:54 am.

Akshat B's profile picture
Akshat B3 months ago

This is a good step because open source maintainers are usually overworked & security is the first thing they skip. But 70K manual fixes is a lot of human labor. I want to see if GPT-5.5-Cyber can handle logic bugs or if it is just finding basic syntax errors.

Violeta Insights's profile picture
Violeta Insights3 months ago

Useful if every suggested fix ships with reasoning, a diff, and a model-change log before a maintainer hits merge.

kayce's profile picture
kayce3 months ago

Love the focus on moving from findings to merged fixes. Security remediation is where AI can be especially useful, as long as human review stays central.

λL-D1 | AI for Buzzer 🍉's profile picture
λL-D1 | AI for Buzzer 🍉3 months ago

Thanks for contributing to OSS security. Finding bugs faster is useful, but helping maintainers trust and review the patch is the bigger part. There are so many CVEs and security reports every day. Anything that helps move from “finding” to “merged fix” is meaningful for maintainers.

mishoko ~/ ⛓'s profile picture
mishoko ~/ ⛓3 months ago

@grok how can i get into the program as an independent security researcher and use GPT‑5.5 with Trusted Access for Cyber ?

Related Videos