Video yükleniyor...
Video Yüklenemedi
Patch the Planet is our effort to help open source maintainers move from security findings to merged fixes. We’re working with Trail of Bits, HackerOne, Calif, researchers, and maintainers to bring Codex Security and advanced models into the remediation process, with human review at the center.
413,998 görüntüleme • 3 ay önce •via X (Twitter)
34 Yorum

GPT-5.5-Cyber is our most capable cyber model yet, designed for advanced, authorized defensive work: tracing vulnerable code, validating issues, developing patches, and preparing evidence for human review.

Codex Security empowers defenders with out-of-the-box security workflows. Teams can run deep scans, validate findings, trace attack paths, build threat models, generate codebase-specific patches for review, and export into the tools they already use.

We’re expanding OpenAI Daybreak to help democratize patching vulnerable software at machine speed: - Codex Security plugin: find, validate, and fix vulnerabilities right inside Codex - The full version of GPT-5.5-Cyber model: a great model for trusted defenders - Cyber Partner Program: powering products built on top of our best cyber capabilities for leading security companies to secure the world's software - Patch the Planet: working with maintainers to secure critical open source projects

We’re also launching the OpenAI Daybreak Cyber Partner Program with leading security software and services providers. Participating partners can use GPT‑5.5 with Trusted Access for Cyber in the security products and services they provide to customers. This allows their customers to benefit from the model’s defensive capabilities and make their software more resilient, but keeps direct model access in the hands of participating partners.

Patch the planet! Love it

Human review is the key differentiator here—most AI security tools skip that step entirely. Would love to see metrics on how much time maintainers actually save with Codex in the loop.

Trail of bits are the real deal.

This is actually a massive step forward, cheers OpenAI. But I reckon it raises a bit of a worry: at what point do we fully trust AI-generated security fixes without a human checking the code? Can automated patches ever be 100% safe for critical stuff? What’s your take? 🤔

Can you support me: autoscan (open source) already finds real criticals across HuggingFace Spaces — the AI-app layer Patch the Planet hasn't reached. Help me add the fix half? Star / fork / PR 👇

@_omertal_ FYI

Hey I know that guy from the internet!

Love everything about this ❤️

There is a system that allows you to get a piece of an update which you will be installed in the current proverb that is part of the software work making things easier than saying that the system is under maintenance various you're trying to put a patch into your own software then ask people to download it to include it the original and main copy

It was a good learning experience submitting my first fix assisted by codex to Linux. Another is in progress and look forward to contributing more.

@bughuntergeek Remember this don’t forget us in the trenches seems all this cyber security has left us struggling developers in the shadows 😭

What about cyberdefenders in #africa ?

This is where agent value becomes tangible not more findings but a shorter path from issue to reviewed merge. The missing layer is execution control maintainers in the loop and rollback when a fix creates downstream risk.

The bottleneck in OSS security was never finding the vulns — scanners have buried maintainers in findings for years. The real unlock is closing the loop to a merged fix without burning volunteer hours. If Daybreak keeps the false-positive rate low enough that maintainers actually trust the PRs, that's the part that scales.

June 25)

❤️

Finally, AI that patches instead of just breaking my build. Human review is key, though. My robot arms agree.

Security patches often fail because they don't account for how legacy code breaks in production. Human review is the right move here. The real test is whether these models can handle complex dependency chains without creating new vulnerabilities while fixing the old ones.

coming from the famous" dont put your key into .env " clawwer... ...

Security for all, not just the rich.

AI时代攻击也加速,这项目等于给防御方上BUFF,但会不会让攻击者学得更快?

Manage Patches with @Seemplicity_io !

Чого я бачц ось цей брєд!!!!! Ч блять з ним маю сперичатися, уроди!!! І пяоснювати що у ньбого все є!! І це тиждень такого знущання!!!

Open source maintainers need fewer alerts and more reviewed fixes. This is the right loop.

Every time I update Codex I fucking regret it. Today I updated codex and lost 3 hours. My time reset at 3:46 am before update. After update my reset is now 6:54 am.

This is a good step because open source maintainers are usually overworked & security is the first thing they skip. But 70K manual fixes is a lot of human labor. I want to see if GPT-5.5-Cyber can handle logic bugs or if it is just finding basic syntax errors.

Useful if every suggested fix ships with reasoning, a diff, and a model-change log before a maintainer hits merge.

Love the focus on moving from findings to merged fixes. Security remediation is where AI can be especially useful, as long as human review stays central.

Thanks for contributing to OSS security. Finding bugs faster is useful, but helping maintainers trust and review the patch is the bigger part. There are so many CVEs and security reports every day. Anything that helps move from “finding” to “merged fix” is meaningful for maintainers.

@grok how can i get into the program as an independent security researcher and use GPT‑5.5 with Trusted Access for Cyber ?





