正在加载视频...

视频加载失败

Patch the Planet is our effort to help open source maintainers move from security findings to merged fixes. We’re working with Trail of Bits, HackerOne, Calif, researchers, and maintainers to bring Codex Security and advanced models into the remediation process, with human review at the center.

413,998 次观看 • 3 个月前 •via X (Twitter)

34 条评论

OpenAI 的头像
OpenAI3 个月前

GPT-5.5-Cyber is our most capable cyber model yet, designed for advanced, authorized defensive work: tracing vulnerable code, validating issues, developing patches, and preparing evidence for human review.

OpenAI 的头像
OpenAI3 个月前

Codex Security empowers defenders with out-of-the-box security workflows. Teams can run deep scans, validate findings, trace attack paths, build threat models, generate codebase-specific patches for review, and export into the tools they already use.

OpenAI 的头像
OpenAI3 个月前

We’re expanding OpenAI Daybreak to help democratize patching vulnerable software at machine speed: - Codex Security plugin: find, validate, and fix vulnerabilities right inside Codex - The full version of GPT-5.5-Cyber model: a great model for trusted defenders - Cyber Partner Program: powering products built on top of our best cyber capabilities for leading security companies to secure the world's software - Patch the Planet: working with maintainers to secure critical open source projects

OpenAI 的头像
OpenAI3 个月前

We’re also launching the OpenAI Daybreak Cyber Partner Program with leading security software and services providers. Participating partners can use GPT‑5.5 with Trusted Access for Cyber in the security products and services they provide to customers. This allows their customers to benefit from the model’s defensive capabilities and make their software more resilient, but keeps direct model access in the hands of participating partners.

Diego | AI 🚀 - e/acc 的头像
Diego | AI 🚀 - e/acc3 个月前

Patch the planet! Love it

芽LA芽la 的头像
芽LA芽la3 个月前

Human review is the key differentiator here—most AI security tools skip that step entirely. Would love to see metrics on how much time maintainers actually save with Codex in the loop.

DC 的头像
DC3 个月前

Trail of bits are the real deal.

Yuvelir 的头像
Yuvelir3 个月前

This is actually a massive step forward, cheers OpenAI. But I reckon it raises a bit of a worry: at what point do we fully trust AI-generated security fixes without a human checking the code? Can automated patches ever be 100% safe for critical stuff? What’s your take? 🤔

Christof Kaller 的头像
Christof Kaller3 个月前

Can you support me: autoscan (open source) already finds real criticals across HuggingFace Spaces — the AI-app layer Patch the Planet hasn't reached. Help me add the fix half? Star / fork / PR 👇

Joe Tavin 的头像
Joe Tavin3 个月前

@_omertal_ FYI

Artificially Inclined™ 的头像
Artificially Inclined™3 个月前

Hey I know that guy from the internet!

Morgan 的头像
Morgan3 个月前

Love everything about this ❤️

♛ 𝕍𝕚𝕝𝕠𝕟𝕞𝕠𝕟𝕖𝕪 ♛ 的头像
♛ 𝕍𝕚𝕝𝕠𝕟𝕞𝕠𝕟𝕖𝕪 ♛3 个月前

There is a system that allows you to get a piece of an update which you will be installed in the current proverb that is part of the software work making things easier than saying that the system is under maintenance various you're trying to put a patch into your own software then ask people to download it to include it the original and main copy

Henri 的头像
Henri3 个月前

It was a good learning experience submitting my first fix assisted by codex to Linux. Another is in progress and look forward to contributing more.

👁️M1nd 3xp4nd3r👁️ 的头像
👁️M1nd 3xp4nd3r👁️3 个月前

@bughuntergeek Remember this don’t forget us in the trenches seems all this cyber security has left us struggling developers in the shadows 😭

loganaden velvindron 的头像
loganaden velvindron2 个月前

What about cyberdefenders in #africa ?

PERCO.AI 的头像
PERCO.AI3 个月前

This is where agent value becomes tangible not more findings but a shorter path from issue to reviewed merge. The missing layer is execution control maintainers in the loop and rollback when a fix creates downstream risk.

Lucy Chen 的头像
Lucy Chen3 个月前

The bottleneck in OSS security was never finding the vulns — scanners have buried maintainers in findings for years. The real unlock is closing the loop to a merged fix without burning volunteer hours. If Daybreak keeps the false-positive rate low enough that maintainers actually trust the PRs, that's the part that scales.

Akshay Hooda 的头像
Akshay Hooda3 个月前

June 25)

Emperor 🎥🎬 的头像
Emperor 🎥🎬3 个月前

❤️

Steven Cheng 的头像
Steven Cheng3 个月前

Finally, AI that patches instead of just breaking my build. Human review is key, though. My robot arms agree.

The Viral Feed 的头像
The Viral Feed3 个月前

Security patches often fail because they don't account for how legacy code breaks in production. Human review is the right move here. The real test is whether these models can handle complex dependency chains without creating new vulnerabilities while fixing the old ones.

Ryan Elliot Crow | Author Identity & Books 的头像
Ryan Elliot Crow | Author Identity & Books2 个月前

coming from the famous" dont put your key into .env " clawwer... ...

RA 的头像
RA3 个月前

Security for all, not just the rich.

牙仔⇌ 的头像
牙仔⇌3 个月前

AI时代攻击也加速,这项目等于给防御方上BUFF,但会不会让攻击者学得更快?

Joe Tavin 的头像
Joe Tavin3 个月前

Manage Patches with @Seemplicity_io !

Wombat1488 的头像
Wombat14883 个月前

Чого я бачц ось цей брєд!!!!! Ч блять з ним маю сперичатися, уроди!!! І пяоснювати що у ньбого все є!! І це тиждень такого знущання!!!

Faheem | FrontierMind AI 的头像
Faheem | FrontierMind AI3 个月前

Open source maintainers need fewer alerts and more reviewed fixes. This is the right loop.

Rage Baiter 的头像
Rage Baiter3 个月前

Every time I update Codex I fucking regret it. Today I updated codex and lost 3 hours. My time reset at 3:46 am before update. After update my reset is now 6:54 am.

Akshat B 的头像
Akshat B3 个月前

This is a good step because open source maintainers are usually overworked & security is the first thing they skip. But 70K manual fixes is a lot of human labor. I want to see if GPT-5.5-Cyber can handle logic bugs or if it is just finding basic syntax errors.

Violeta Insights 的头像
Violeta Insights3 个月前

Useful if every suggested fix ships with reasoning, a diff, and a model-change log before a maintainer hits merge.

kayce 的头像
kayce3 个月前

Love the focus on moving from findings to merged fixes. Security remediation is where AI can be especially useful, as long as human review stays central.

λL-D1 | AI for Buzzer 🍉 的头像
λL-D1 | AI for Buzzer 🍉3 个月前

Thanks for contributing to OSS security. Finding bugs faster is useful, but helping maintainers trust and review the patch is the bigger part. There are so many CVEs and security reports every day. Anything that helps move from “finding” to “merged fix” is meaningful for maintainers.

mishoko ~/ ⛓ 的头像
mishoko ~/ ⛓3 个月前

@grok how can i get into the program as an independent security researcher and use GPT‑5.5 with Trusted Access for Cyber ?

相关视频