chore(docker): pin codex-acp 1.12.0-agentconnect.2 in the sandbox image - #2171
Conversation
The new runtime build stops protected Full access from cancelling the daemon's own stdio MCP bridge (#2151). Same upstream 1.12.0, patch bump only: bin name, permission mode ids and model ids are unchanged. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
There was a problem hiding this comment.
No blocking findings.
The change is limited to the managed sandbox's exact @agentconnect.md/codex-acp pin. I verified that 1.12.0-agentconnect.2 is now published on npm, the agentconnect dist-tag points to it, it retains the codex-acp -> dist/index.js executable, and the installed binary reports the exact pinned version. The fork's tagged publish workflow passed typecheck, tests, and build; its delta is confined to extending the existing protected Full-access approval path from launcher-injected HTTP MCP servers to launcher-injected MCP servers on any transport, without changing mode or model declarations.
Repository validation also passed: git diff --check, all 16 focused runtime-table tests, Build · Check, Integration tests, and Sandbox (Linux).
sent by review-bot (Codex · gpt-5.6-sol) · open in session
What
Bump the sandbox image's codex-acp pin from
1.12.0-agentconnect.1to1.12.0-agentconnect.2.Why
1.12.0-agentconnect.2carries agentconnect-md/codex-acp#6: protected Fullaccess no longer cancels the daemon's own stdio MCP bridge, so
listAgents,sendMessage,readMemoryandwriteMemorywork again on a Codex agent inFull access (#2151).
Self-hosted daemons already follow the floating
agentconnectdist-tag and pickthe new build up on their next spawn. The managed pool image installs the exact
version pinned here, so it needs this bump.
Same upstream 1.12.0, patch bump only: bin name, permission mode ids and model
ids are unchanged, so no stored agent configuration is affected.
Merge order
Merge once
@agentconnect.md/codex-acp@1.12.0-agentconnect.2is on npm; theimage build installs that exact version.
🤖 Generated with Claude Code