Skip to content

[codex] Publish Codeck v0.4.4 with Gemini 3.8 - #5

Merged
isdou merged 1 commit into
mainfrom
codex/codeck-0.4.4-gemini-3.8
Oct 4, 2026
Merged

isdou merged 1 commit into
mainfrom
codex/codeck-0.4.4-gemini-3.8

Conversation

@isdou

@isdou isdou commented Sep 26, 2026

Copy link
Copy Markdown
Owner

What changed

This publishes the pending Codeck 0.4.4/plugin overhaul and updates the maintained Google/Agy default to gemini-3.8-flash-high.

  • Make MCP routing project-scoped and explicit: require projectPath and a user-named executor, while adding focused host briefs and an opt-in repository context boundary.
  • Harden context and executor handling with project path validation, CLI readiness/setup guidance, restricted environment inheritance, empty-output failures, automatic first-use initialization, and non-blocking update notices.
  • Keep Gemini, Gemini CLI, Gemini API, Gemini Image, and Antigravity/Agy as distinct paths; pass the configured Agy model through --model with plan/sandbox read-only execution and inline task context.
  • Ship the bundled MCP runtime, plugin metadata, bilingual documentation, skill guidance, tests, and launch materials.

User impact and root cause

The previous package assumed a shared process working directory, allowed MCP calls to rely on implicit routing, and used a file-backed Agy context handoff that could require an extra file-read grant. That made Codex/plugin calls fragile across projects and blurred the boundary between a named external specialist and automatic routing.

The fix moves the project path and executor identity into the MCP contract, validates every project-scoped file at the boundary, packages the selected context inline for Agy, and preserves Codex as the host and final decision-maker. The default Agy model now follows the locally available Gemini 3.8 model.

Validation

  • npm test — 17/17 passing.
  • npm run test:gemini-image — passing.
  • npm ci on Node 22 — completed successfully.
  • Local agy models confirmed gemini-3.8-flash-high is available.
  • git diff --check passed for source and non-bundled generated files.

Known follow-up

npm audit --omit=dev reports two existing production dependency advisories: qs (moderate) and smol-toml (high). Dependency upgrades were intentionally not mixed into this release; they should be handled in a focused follow-up after compatibility review.

@isdou
isdou marked this pull request as ready for review October 4, 2026 10:06
@isdou
isdou merged commit b3d67d1 into main Oct 4, 2026
2 checks passed
@isdou
isdou deleted the codex/codeck-0.4.4-gemini-3.8 branch October 4, 2026 10:06
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-04T10:08:39.677544Z 5ea1207 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5ea1207d3a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/mcp.ts
let run;
try {
run = await routeTask(input, { caller: 'mcp', allowOverBudget: Boolean(fullContext) });
run = await routeTask(input, { cwd, caller: 'mcp', allowOverBudget: Boolean(fullContext) });

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Isolate dotenv credentials per project

When one long-lived MCP server routes project A and then project B, passing each requested cwd into routeTask causes loadConfig to load both projects in the same process, but loadDotenv writes A's values into global process.env and refuses to overwrite existing keys (src/config.ts:339-360). Consequently, B's .env/.codeck/.env credentials are ignored and its API request can be sent using A's key, leaking credentials and billing across projects; load project-specific variables without mutating shared process state, or restore them after each call.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant