---
collection: coding-agents
collection_name: Coding Agents
week_start: 2026-09-21
title: GPT-6 lands in Codex as the agents grow review and governance features
release_count: 14
generated: 2026-09-28
canonical: https://releases.sh/collections/coding-agents/digest/2026-09-21
---

# GPT-6 lands in Codex as the agents grow review and governance features

OpenAI brought GPT-6 Sol and Luna to Codex and ChatGPT Work at lower token prices than GPT-5.6, while Cursor launched deploy-monitoring and security-review bots and Devin reworked how automatic reviews get triggered.

### GPT-6 arrives in Codex

The week's biggest shift was OpenAI's model lineup: [GPT-6 Sol and Luna began rolling out to Codex and ChatGPT Work](https://developers.openai.com/codex/changelog/#codex-2026-09-22-gpt-6-sol-luna), priced below GPT-5.6, with Sol pitched at complex coding and agentic workflows and Luna at focused, high-volume work. Both reach Plus, Pro, Business, Enterprise, and Edu accounts, and Enterprise admins have to switch them on before anyone sees them.

The CLI caught up quickly. [Codex made both models selectable from the model picker](https://developers.openai.com/codex/changelog/#github-release-394258789), including adding them to the model catalog and having the rate-limit switch prompt recommend Luna when you hit a ceiling. Then [Sol and Luna landed alongside Amazon Bedrock support](https://developers.openai.com/codex/changelog/#github-release-396234532), with migration prompts nudging users off older models, fullscreen transcripts on by default, and Shift-click to extend text selections. That same stretch of work tightened networking — proxy routing for realtime connections and web search, restrictions that now hold across redirects and ongoing HTTP/WebSocket traffic — and fixed tmux mouse settings and voice conversations being dropped when you switch threads.

Codex also [arrived on iOS](https://developers.openai.com/codex/changelog/#codex-2026-09-23-mobile) with a redesigned home screen, an iPad split view that keeps the task list beside the open task in landscape, and support for browsing changes in nested Git repositories. Side chats now carry over attachments, selected text, and review comments, and a batch of fixes covers blank or incomplete replies when a queued prompt starts and SSH connection trouble on Mac and Linux.

### Review bots move into the last mile

Cursor went after the post-merge half of shipping with [Rollouts and Security Review for Teams and Enterprise](https://cursor.com/changelog/rollouts-and-security-reviewer). Rollouts attaches a monitor to every pull request, reads the diff and affected systems to write a monitoring plan as a PR comment, then tracks deploy events per environment and reports back verified healthy, regression detected, or inconclusive. Security Review reads each PR against the codebase and posts one comment listing exploitable bugs with severity, attack path, and a proposed fix — injection, auth bypasses, committed secrets, SSRF, unsafe deserialization, and vulnerable dependency changes.

Devin spent the week making its own review machinery more programmable. [Automatic reviews can now be triggered by composable rules](https://docs.devin.ai/release-notes/overview#september-23-2026) that enroll accounts, SCM orgs, repos, repo prefixes, or individual members, each narrowed by filters on PR author, reviewer, label, title, branch, changed files, author type, and diff size, with exclusions overriding triggers. Devin Review also now works from Helix Swarm reviews, reading the shelved or submitted changelist straight from the Perforce depot. In the same vein, [code scan findings can be selected in bulk](https://docs.devin.ai/release-notes/overview#september-4-2026) to assign several to one session or update their status at once, and scan-new-commits runs skip starting a session entirely when there are no new commits.

Devin also cleaned house: [the standalone npx devin-review CLI is retired](https://docs.devin.ai/release-notes/overview#september-21-2026) — installed copies will stop working — while Bitbucket Data Center repositories gained Devin Review support, Microsoft 365 Mail, Calendar, Teams, and Directory MCP servers arrived in the marketplace, and automatic merge-conflict fixes on Devin's PRs now fire more often.

### Model defaults and guardrails

Claude Code made [Opus 5.5 the default Opus model](https://code.claude.com/docs/en/changelog#2-1-280), bringing 1M context at $4/$20 per Mtok, and closed a real safety hole: writes through a symlinked path are now judged by where they actually land, so acceptEdits, allow rules, and auto mode no longer approve a write that escapes the working tree. The same stretch of work fixed [recursive rm commands whose target is only command-substitution output](https://code.claude.com/docs/en/changelog#2-1-281) — think `rm -rf "$(pwd)"` — running unprompted in auto mode, and stopped proxy and gateway streams from showing truncated responses as complete.

For admins, Claude Code added [managed settings for model governance](https://code.claude.com/docs/en/changelog#2-1-283): `availableModelsMatch: "exact"` blocks any model version not explicitly listed, and `deniedModels` blocks specific models even when `availableModels` allows them. A new `/doctor` prompt-audit command flags CLAUDE.md files, skills, agents, and commands written for older models. Fixes in that stretch address SDK sessions losing deferred tool calls or held approvals, stateless MCP servers left unusable after a brief 404, and a Windows PowerShell tool that let `cmd /c rd` target drive roots and the home folder. Terminal comfort got attention too, via a [setting that caps Claude's prose width](https://code.claude.com/docs/en/changelog#2-1-282) in wide terminals while tables and code keep full width, plus a fix for conversations whose history held undecryptable web search results and failed every request with a 400.

## Releases covered

### Anthropic

- [Claude Code v2.1.280 defaults to Opus 5.5 and fixes symlink write approval](https://code.claude.com/docs/en/changelog#2-1-280)
- [Claude Code 2.1.281 hardens resume, proxy stream, and auto-mode permission handling](https://code.claude.com/docs/en/changelog#2-1-281)
- [Claude Code v2.1.283 adds model governance settings and prompt-audit command](https://code.claude.com/docs/en/changelog#2-1-283)
- [Claude Code v2.1.282 adds maxProseWidth and fixes 400 errors from web search history](https://code.claude.com/docs/en/changelog#2-1-282)

### Cognition

- [Devin adds composable Autoreview triggers and Helix Swarm review support](https://docs.devin.ai/release-notes/overview#september-23-2026)
- [Devin adds code scan multi-select and skips no-op scans with no new commits](https://docs.devin.ai/release-notes/overview#september-4-2026)
- [Devin retires npx devin-review CLI, expands Bitbucket Data Center and Microsoft 365 support](https://docs.devin.ai/release-notes/overview#september-21-2026)

### Cursor

- [Cursor launches Rollouts and Security Review bots for Teams and Enterprise](https://cursor.com/changelog/rollouts-and-security-reviewer)

### OpenAI

- [Codex adds GPT-6 Sol and Luna models at lower token prices](https://developers.openai.com/codex/changelog/#codex-2026-09-22-gpt-6-sol-luna)
- [Codex CLI 0.156.1 adds GPT-6 Sol and Luna to model picker](https://developers.openai.com/codex/changelog/#github-release-394258789)
- [Codex CLI 0.157.0 adds GPT-6 Sol and Luna models](https://developers.openai.com/codex/changelog/#github-release-396234532)
- [OpenAI Codex ships ChatGPT for iOS with iPad split view and redesigned home](https://developers.openai.com/codex/changelog/#codex-2026-09-23-mobile)
