NOW LET US – AI RAG SaaS Studio TP.HCM
NOW LET US
Digital Product Studio
Back to news
DEV-TOOLS...1 min read

A way to exclude sensitive files issue still open for OpenAI Codex

Share
NOW LET US Article – A way to exclude sensitive files issue still open for OpenAI Codex

Developers are pushing for a feature to exclude sensitive files in OpenAI Codex to prevent data leaks of security keys and environment configurations. Despite being proposed earlier, an official solution remains unimplemented.

You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert

A mechanism to explicitly mark files/paths that the agent must not read or send to the model, at both repository and global levels (e.g., a repo-local .codexignore plus a global ignore file).

Example: keep node_modules/ searchable for implementation checks, but never read or send .env, .env.*, .pem, id_, .aws/, .ssh/.

The configuration should be deterministic and shareable across the team/repo, and also support user defaults, rather than relying on project documentation or conventions.

Are you interested in implementing this feature?

Yes — I can contribute and tests.

Additional information

Related: #205. That issue surfaced two primary use cases: preventing sensitive data from being sent to the model and excluding large/irrelevant files. The issue was closed in favor of a Rust (codex-rs) implementation, but as of 2025-08-28 a comparable feature does not appear to exist in codex-rs. I’d like to restart the discussion and converge on a design.

What feature would you like to see?

.pem, id_, .aws/, .ssh/.## Are you interested in implementing this feature?

Additional information

Related: #205. That issue surfaced two primary use cases: preventing sensitive data from being sent to the model and excluding large/irrelevant files. The issue was closed in favor of a Rust (codex-rs) implementation, but as of 2025-08-28 a comparable feature does not appear to exist in codex-rs. I’d like to restart the discussion and converge on a design.

© 2026 Now Let Us. All rights reserved.

Source: Hacker News

Advertisement
Ad slot ready: 5887729102

More in this category

NOW LET US Related – The curious case of the disappearing Polish S

dev-tools

The curious case of the disappearing Polish S

A fascinating deep dive into a bizarre keyboard bug on Medium that prevented Polish users from typing the letter 'ś', tracing its roots back through decades of history, hardware limitations, and OS quirks.

NOW LET US Related – The MUMPS 76 Primer – anniversary edition

dev-tools

The MUMPS 76 Primer – anniversary edition

An introduction to MUMPS 76, a pioneering programming language and integrated NoSQL database system created in 1966 that laid the foundation for modern medical databases.

NOW LET US Related – Show HN: Adrafinil – keep a lid-closed Mac awake only while agents work

dev-tools

Show HN: Adrafinil – keep a lid-closed Mac awake only while agents work

Adrafinil is a macOS menu bar app that keeps your Mac awake—even with the lid closed—exclusively while AI coding agents are actively working. Unlike always-on utilities, it restores normal sleep behavior the moment the agent finishes its task.

NOW LET US Related – Turn your site into a place people can bump into each other

dev-tools

Turn your site into a place people can bump into each other

Town Square is an open-source widget that transforms static websites into interactive spaces where real-time visitors can see each other as avatars and chat, bringing back the nostalgic human connection of the early web.

NOW LET US Related – Anonymous GitHub account mass-dropping undisclosed 0-days

dev-tools

Anonymous GitHub account mass-dropping undisclosed 0-days

An anonymous security researcher has consolidated and released a massive archive of zero-day and one-day vulnerability PoCs affecting major software like Firefox, Docker, and FFmpeg, leveraging AI-driven fuzzing workflows.

NOW LET US Related – Post-Mythos Cybersecurity: Keep calm and carry on

dev-tools

Post-Mythos Cybersecurity: Keep calm and carry on

The emergence of Claude Mythos has sparked concerns over AI-driven automated zero-day hunting and exploitation. However, a closer look reveals that this technology represents a gradual evolution rather than a sudden revolution in the cybersecurity landscape.

EXPLORE TOPICS

Discover All Categories

Deep dive into the specific technology sectors that matter most to you.