133 wires and counting

$ follow OpenAI

Keep up with OpenAI in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-09-23
stories 143

© 2026 RepoJournal Home Showcase Explore How it works Privacy

$ the-wire · showcase

Codex hardens WebSocket auth and network policy as SDKs add GCP storage

By RepoJournal · Filed · About OpenAI · Composed from the cited sources · methodology

Codex's authentication and network-policy plumbing got extracted and tightened while openai-node and openai-python both shipped GCP external storage support and a new research model behind GPT-Rosalind.

Enforce network policy throughout HTTP and WebSocket requests openai/codex

by copyberry

Managed HTTP clients now run through a shared RequestBuilder that checks each redirect destination before following it, and policy denials survive error handling so callers can't retry them or record a revoked operation as a success. The stated purpose is keeping destination restrictions effective during redirects, response body reads, and established WebSocket traffic.

Retry transient OpenAI file blob upload failures openai/codex

by copyberry

A single failed blob upload used to abort the whole file upload even on a temporary 503 or an interrupted stream. Uploads now retry 503s plus timeout, connection, body, and request errors, at most five attempts inside a shared five-minute deadline, honoring x-ms-retry-after-ms and Retry-After and reopening contents for each attempt.

Extract WebSocket authentication into `codex-websocket-auth` (#47447) openai/codex

by Ruslan Nigmatullin

WebSocket auth arguments, settings, credential loading, and upgrade authorization moved into a shared codex-websocket-auth crate built on http types, consumed directly by the app server, transport, and CLI, with the AppServer prefix dropped from shared types. Token digests and JWT verification secrets are no longer printed in authentication policy Debug output.

v7.22.0 openai/openai-node

by openai-sdks[bot]

openai-node 7.22.0 adds GPT-6 Sol and Luna model identifiers to the API's known model set. Same-day releases also landed GCP as a supported external storage provider for organizations and gpt-rosalind-research in the Responses model union.

fix(helpers): use asyncio.get_running_loop() inside async methods (#3289) openai/openai-python

by Rolly Calma

LocalAudioPlayer.play, LocalAudioPlayer.play_stream, and Microphone.record called asyncio.get_event_loop() from inside a running coroutine, deprecated since Python 3.10; they now use asyncio.get_running_loop(). The same release, openai-python 3.19.0, carries the GCP external storage and GPT-Rosalind additions.

Quick answers

What shipped in OpenAI on September 23, 2026?
Codex's authentication and network-policy plumbing got extracted and tightened while openai-node and openai-python both shipped GCP external storage support and a new research model behind GPT-Rosalind. In total, 66 commits, 66 pull requests, and 11 releases landed.
Who contributed to OpenAI on September 23, 2026?
7 developers shipped this update, including Ruslan Nigmatullin, copyberry, Owen Lin, openai-sdks[bot], jbeckwith-oai, Rolly Calma, and Hughhhhcoder.
What were the notable OpenAI updates?
Enforce network policy throughout HTTP and WebSocket requests, Retry transient OpenAI file blob upload failures, and Extract WebSocket authentication into `codex-websocket-auth` (#47447).