Codex CLI 0.162.0 Adds Managed Git Worktree Tools and Tightens Linux Sandbox Handling of ripgrep Config and Writable Executables
OpenAI's Codex 0.162.0 adds worktree tools, task pinning and clickable URLs, plus sandbox fixes; 0.161.0 a day earlier made GPT-6.1 Sol the default model.
Overview
OpenAI shipped Codex CLI 0.162.0 on October 8, 2026, according to its GitHub release page. The release adds tools for managed Git worktrees, shared task pinning in the agent Command Center and a group of Linux sandbox fixes. It followed 0.161.0, published a day earlier, which changed the default model and added in-terminal sign-in for MCP servers. Both releases are documented only in OpenAI’s own release notes; this briefing relies on those notes and on no independent testing.
What 0.162.0 Adds
The release notes list these new features:
- Worktree tools. Codex gains tools to create and list managed Git worktrees. The notes say they work on “trusted local projects when the worktrees feature is enabled.” The release does not say the feature is on by default.
- Task pinning. Users can pin tasks in the agent Command Center with the
pkey, and pinned tasks are kept in a shared Pinned group “when supported by the server.” - Transcript navigation. The notes describe
/copyfor navigating and copying transcript blocks,Ctrl+Insertfor copying selections, and atui.mouse_scroll_speedsetting for mouse-wheel scrolling. - Clickable URLs. URLs in approval headers, questions, MCP prompts, warnings, banners and verification prompts are now clickable, including when a link wraps across lines.
- Custom providers. Live web access and remote compaction can be configured for custom Responses-compatible model providers.
- Code Mode. The release adds JavaScript helpers for streaming promise results as they settle, along with opt-in ranked tool search.
Sandbox Fixes
The bug-fix section includes several items that concern the Linux sandbox. According to the 0.162.0 notes, the release fixes Linux sandbox startup with multiple denied files, rejects writable sandbox-construction executables, and keeps ripgrep configuration from weakening deny-glob masks. The changelog entries behind those lines are titled “Reject sandbox-writable bubblewrap executables from PATH,” “Protect ripgrep lookup during Linux sandbox construction” and “Ignore ripgrep configuration when expanding sandbox deny globs.”
The release notes do not describe an attack scenario, assign a vulnerability identifier or say whether any of these issues was exploited. The entries show only that the sandbox’s handling of its helper executables and of file-deny patterns was changed.
Other fixes in the same release, per the notes:
- Windows 10 drive-letter file access is restored, and Windows sandbox temp permissions now match the child process environment.
apply_patchnow preserves existing CRLF line endings without an opt-in.- Server
Retry-Afteradvice is honored for retryable Responses and WebSocket failures. - Windows releases now ship a signed PowerShell installer.
- The changelog also lists a change titled “Protect the guardian decisions API key from environment forwarding.”
What 0.161.0 Changed a Day Earlier
The 0.161.0 release notes state that “GPT-6.1 Sol is now the default model in the bundled and Amazon Bedrock catalogs.” The same notes add a /mcp login <name> command to sign in to MCP servers from an active terminal session, and say Amazon Bedrock now supports multi-agent V2 and Ultra reasoning on compatible models.
The notes also say that “Daybreak is opt-in through --enable cli_daybreak or features.cli_daybreak=true; daybreak=true alone is insufficient.” A separate entry says a Cyber access program can be selected per turn with codex exec --cyber-access-program or the TypeScript SDK’s cyberAccessProgram option. The notes do not explain what the Daybreak or Cyber access programs involve beyond those configuration details.
In the permissions area, the 0.161.0 notes say that approved filesystem escalation “can now grant broader write access while preserving denied reads and network restrictions.” Voice conversations also gained microphone, speaker and input-channel selection, with preferences saved locally.
What We Don’t Know
- Whether the sandbox fixes address issues that users could encounter in practice. OpenAI’s notes give no impact description.
- Whether the worktree tools will be enabled by default; the notes describe them as available when the worktrees feature is enabled.
- How the Command Center pinning behaves on servers that do not support the shared Pinned group; the notes say only that it depends on server support.
- Independent verification. No outlet other than the project’s own release notes was available for these two releases at the time of writing.
Related Coverage
The Herald has previously reported on OpenAI’s DevDay Codex announcements, and covered worktree support in agent sessions in VS Code 1.140.