Repository navigation
🤖 feat: artifact versions, the artifact tool and pinned files - #5427
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
Security findingsAdvisory findings (3)
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
259785f to
6231a7d
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 259785fba1
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
6231a7d to
add2a88
Compare
|
@codex review |
There was a problem hiding this comment.
🛡️ Codex Security Review · Automatically triggered
Here are some automated security review suggestions for this pull request.
Reviewed commit: add2a88ee7
ℹ️ About Codex security reviews in GitHub
This is an experimental Codex feature. Security reviews are triggered when:
- You comment "@codex security review"
- A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review
Once complete, Codex will leave suggestions, or a comment if no findings are found.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: add2a88ee7
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
add2a88 to
ff9a600
Compare
|
@codex review |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ff9a60007a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
ff9a600 to
c951c69
Compare
|
@codex review |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c951c690b1
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
c951c69 to
0933cb3
Compare
|
@codex review |
There was a problem hiding this comment.
🛡️ Codex Security Review · Automatically triggered
Here are some automated security review suggestions for this pull request.
Reviewed commit: 0933cb3de4
ℹ️ About Codex security reviews in GitHub
This is an experimental Codex feature. Security reviews are triggered when:
- You comment "@codex security review"
- A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review
Once complete, Codex will leave suggestions, or a comment if no findings are found.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0933cb3de4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
0933cb3 to
04f4f58
Compare
|
@codex review |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
bf46a41 to
af61a8e
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: af61a8e191
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
af61a8e to
8ad3721
Compare
|
@codex review |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8ad372117f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
8ad3721 to
2acda01
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2acda01786
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
- Artifact version store per workspace (`artifact-versions/<id>/vN`, content-hash dedupe) with list/read routes and a version menu in the Artifacts tab - `artifact` tool to publish a version (title, focus, pin request); attach_file registers files inside the artifacts dir via `ui_only.artifact` - Turn-end snapshots: one version per changed file per logical turn when nothing was published (goal board excluded) - Pinned workspace files (`pinFile` / `readPinned`) and a Pinned files picker group - Artifact chat card, "Open in Artifacts" on attach_file and file cards, "Open as artifact" in Review and the command palette - Post-compaction `artifacts_index` note; chat cards stay inert in hosts without an Artifacts surface (VS Code) - Stories for the chat cards and version menu (Pixel budget +6 snapshots, +1 file) - Codex review round 1 fixes: selection map gains scope (artifact or pinned) and version, the turn-end hook gets an abort signal at its timeout, the post-compaction artifacts index only with the experiment on, size+mtime shortcut only 1 s after mtime, deleted artifacts stay selectable at their latest stored version, pinFile relativeTo the tool cwd and refuses missing files, folders and symlinks, host path rules for the artifact tool, listVersions and listing errors shown inline, only the latest pin-and-open request opens the tab, Artifacts buttons hidden on hosts without the surface - Codex review round 2 fixes: the post-compaction index states only a count, pinned checkout files read on SSH and Docker again (requireArtifactsBasename), unchanged republishes rewrite the kind, the turn-end fast path needs an equal stored sourceModifiedMs, U unpins the selected pinned file, panel keys ignore the version menu, a publish cancelled during its read records nothing, a failed preview read retries on the next refresh - Codex review round 3 fixes: a new version re-checks the abort signal before the index commit, attach_file passes its abort signal to recordArtifactVersion and registers nothing once cancelled, artifact_list also lists deleted artifacts with stored versions, a finished unpin clears the selection only if it is still selected, the artifact card opens the tab only while the experiment is on, host pinned-file reads use the checkout root's real path, the live preview read key includes the file size --- _Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high` • Cost: `$123.74`_ <!-- mux-attribution: model=anthropic:claude-opus-5-5 thinking=high costs=123.74 -->
The turn-end fast path skipped reading files whose size and mtime matched the stored version. Its ambiguity check compares a runtime mtime with the host clock, so on an SSH runtime whose clock lags the host a same-size rewrite in the same remote second was skipped and never got a version. Runtime files are now always read and hashed; host files keep the fast path. --- _Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high` • Cost: `$158.12`_ <!-- mux-attribution: model=anthropic:claude-opus-5-5 thinking=high costs=158.12 -->
…ng (Codex r4 QjUz) A truncated listing may simply not reach a file, so only a complete listing marks versioned artifacts absent from it as deleted (as artifact_list does). Explicitly chosen stored versions stay viewable. --- _Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high` • Cost: `$158.12`_ <!-- mux-attribution: model=anthropic:claude-opus-5-5 thinking=high costs=158.12 -->
Pin path resolution no longer trims the path: `.env ` and `.env` are different files, and trimming pinned and showed the sibling. A blank path is still refused. --- _Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high` • Cost: `$158.12`_ <!-- mux-attribution: model=anthropic:claude-opus-5-5 thinking=high costs=158.12 -->
…e completion hook (Codex r5 ZZo) --- _Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high` • Cost: `$123.74`_ <!-- mux-attribution: model=anthropic:claude-opus-5-5 thinking=high costs=123.74 -->
… admitted during it (Codex r5 ZZo) --- _Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high` • Cost: `$123.74`_ <!-- mux-attribution: model=anthropic:claude-opus-5-5 thinking=high costs=123.74 -->
…odex r5 ZZf) --- _Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high` • Cost: `$123.74`_ <!-- mux-attribution: model=anthropic:claude-opus-5-5 thinking=high costs=123.74 -->
…r5 ZZj) --- _Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high` • Cost: `$123.74`_ <!-- mux-attribution: model=anthropic:claude-opus-5-5 thinking=high costs=123.74 -->
… mtime match (Codex r5 ZZs) --- _Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high` • Cost: `$123.74`_ <!-- mux-attribution: model=anthropic:claude-opus-5-5 thinking=high costs=123.74 -->
…ication (Codex r5 zNT) --- _Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high` • Cost: `$123.74`_ <!-- mux-attribution: model=anthropic:claude-opus-5-5 thinking=high costs=123.74 -->
--- _Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high` • Cost: `$123.74`_ <!-- mux-attribution: model=anthropic:claude-opus-5-5 thinking=high costs=123.74 -->
…safe reads (Codex r6 Tasd) --- _Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high` • Cost: `$123.74`_ <!-- mux-attribution: model=anthropic:claude-opus-5-5 thinking=high costs=123.74 -->
…oss backends (Codex r6 Tasl) --- _Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high` • Cost: `$123.74`_ <!-- mux-attribution: model=anthropic:claude-opus-5-5 thinking=high costs=123.74 -->
… mtime, ctime and inode (Codex r9 9P) --- _Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high` • Cost: `$123.74`_ <!-- mux-attribution: model=anthropic:claude-opus-5-5 thinking=high costs=123.74 -->
2acda01 to
af5cbe9
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: af5cbe91e8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Summary
Adds versions and explicit publishing: the
artifacttool, chat cards, a version menu, turn-end snapshots and "open any file as an artifact".Implementation
<sessionDir>/artifact-versions/<id>/(index.json+ byte copies), content-hash dedupe; versions survive edits, restarts and container loss.artifacttool{path, title?, kind?, focus?, pin?}publishes a labeled version; republishing bumps it. Chat cards (dashed border, kind tag,name · vN · title) open that exact version and render from the tool result alone.attach_fileinputs are unchanged; attaching a file inside the artifacts folder registers a version and returnsui_only.artifact(stripped before the model sees it).agentSessionbeforefinishTurnwith a bounded wait.vN ▾, "Latest (live)"),CUSTOM_EVENTS.OPEN_ARTIFACT, pinned workspace files (readPinnedonly reads pinned paths) from the Review header, file tool cards and the palette.Stack: part 6 of 9 of the Artifacts stack (each PR shows only its own layer). Everything is behind the Artifacts experiment (Settings → Experiments, off by default). The user-facing page lands in part 9 (
docs/workspaces/artifacts.mdx).Generated with
xum• Model:anthropic:claude-opus-5-5• Thinking:high• Cost:$98.34