>>simonw+(OP)
Codex Web actually lacks the most basic PR integration, it's so useless. Codex Web refuses to push any binary file to your PR (like images, jars, lock files, etc). It can't check your GH Actions' logs for failures to try to fix them. Replying to one of the PR comments to accept a fix requires replying to a
different GitHub bot than the one that opens your PR. And though there's a "Secrets" configuration to add secret vars for a Codex repo,
Codex can't access them, so you can't even work around these bugs by asking Codex to make API calls. It's like nobody at the company has tried their own product.