We break down the latest codex exec security hardening, including persistent hook trust across thread yields, strict PostToolUse rejection blocks, and configuration tips for local .codex setups.
We also cover enterprise-ready TLS support for P-521 proxies, smarter TUI auto-resolve behavior for unattended runs, and a new cap on prompt-image caching to keep long sessions stable.