Your GitHub Actions might be a bigger security risk than your code.
In 2025, a compromised GitHub Action affected 23,000+ repositories.
I found zizmor — an open-source tool that scans your GitHub Actions for leaked credentials, excessive permissions, injection vulnerabilities, and unsafe third-party Actions.
The scary part?
Your CI has access to your secrets, and every third-party Action is code you’re trusting to run inside it.
Check your YAML. 👀
https://t.co/nIhKU3Ov4G
Hiding the reasoning made Codex way less fun to use.
So I switched to DeepSeek Harness.
My setup: Codex account → sub2api → DeepSeek Harness
It’s fast, responsive, and honestly feels much lighter for most tasks.
Codex can feel a bit overengineered sometimes.
Simple tools win.