01
Set up the CLI
Install the project into its managed Python environment. Browsing belongs on this website; the CLI is only for operational work.
uv sync --extra test --python 3.12
02
Reproduce and submit
Draft advisory pages provide Discuss and Submit actions. Discuss opens the report in Codex for questions and analysis without changing or advancing the advisory. Submit opens Codex with the repository and prompt for the local $submit-ghsa-advisory skill, which validates the selected report and runs the guarded workflow below.
The Skill first runs the report's self-contained reproduction against a shallow clone of the target's latest default branch and records the tested HEAD. Matching sanitizer or behavior evidence is the fast path; it does not repeat a broad static-analysis pass. If the report has no usable reproducer, Codex Security performs targeted validation and a review PR records the repaired command and evidence before any later submission.
uv run ghsa submit ADVISORY_UUID
03
Prepare a private patch
After submission, the advisory page shows the latest pull request from GitHub's temporary private fork. Repair remains available whether or not a patch PR already exists, so Codex can create a patch or continue debugging the existing one with $fix-ghsa-advisory. It uses the local report as context, works in the fixed sibling ghsa-fixes/UUID checkout, verifies the remediation, and creates or updates a draft PR without exposing the report publicly.
Patch state is fetched during sync; it is not stored as local workflow metadata. The homepage marks submitted advisories as Patched or Unpatched from that remote state. GitHub deletes temporary private forks when an advisory is published, so private patch work must finish first.
04
Sync the website
sync fetches canonical origin/main, refreshes remote advisory facts and temporary-fork patch PR state, then rebuilds dist/. GitHub Actions runs it every six hours and deploys the result automatically.
uv run ghsa sync
05
What happened to the rest?
list and show duplicated this website, so they were removed. Report formatting, review, and reproduction live entirely in repository-local Codex Skills rather than Python commands or modules. The refresh Skill batch-checks drafts and closes one only when current upstream evidence proves it obsolete or invalid. validate remains an internal module used by CI.
06
How status changes
Remote status is derived during sync. The normal progression is Draft → Submitted → Published. A local draft or a submitted GHSA can instead be closed; the dashboard groups both under Closed and labels their source explicitly.
submit returns a GHSA ID.closed: true records an intentionally closed local draft.Final local state.