release aidev SIG 4/5

Codex CLI 0.149.0: agents dashboard, codex queue, working-directory commands

Codex CLI 0.149.0 adds an interactive codex agents dashboard for managing tasks, a codex queue command for messaging existing local or remote sessions, and TUI commands for changing the working directory. It also expands codex doctor diagnostics and hardens several MCP, auth-token, and managed-config paths.

PUBLISHED2026-08-20
OBSERVED2026-08-21
AGE5d
SOURCES1
  • New interactive codex agents dashboard: search, start, open, rename, stop tasks; configurable shortcuts.
  • New /cd, /pwd, /cwd TUI commands for managing the session working directory.
  • New codex queue for sending messages into existing local or remote sessions.
  • Vim editing expanded with character replacement and change motions (cw, c$, cc).
  • codex doctor now diagnoses endpoint protection, network/proxy failures, desktop app state, and update connectivity.
  • TypeScript SDK can pass raw CLI config overrides and select max or ultra reasoning effort.
  • Resumed and forked threads restore their active permission profile instead of falling back to current defaults.
  • Fixes: queued messages wake idle sessions, duplicate sub-agent activity in the TUI, WebRTC sideband reconnect after transport loss, inline TUI history in Windows Terminal scrollback, bounded replay buffers for inactive threads.
  • Hardening: Noise auth tokens no longer reach child processes, MCP HTTP redirects restricted to the configured origin, MCP resource headers isolated during OAuth, Windows IDE pipe client impersonation restricted, external editor buffers isolated from sandbox-writable paths.
  • Guardian v2 changes: bounded parent compaction context, images in transcripts, defaults sourced from the model catalog, disabled for managed automatic reviewers.
  • Docs: external contributions should go through issues and design discussion rather than pull requests; DNS exfiltration risks and trust limits documented for secure devcontainers.

COMMUNITY

No curated reactions recorded for this event. Facts and takes are kept in separate layers — community context is added by hand, never blended into the record above.