Allow Traditional Application Installation - Solve Root Cause Of Windows Defender Problems / Improve Guardrail Clarity
What variant of Codex are you using?
Windows App
What feature would you like to see?
Just let me install Codex the traditional way -
- .exe or .msi to a fixed path like c:\program files\codex
- define my own config path / default location for all Codex system-generated folders
Because
A) I want to define exemptions in Windows Defender (which really doesn't like Codex)
B) I want to give Codex complete unfettered file system access - but only within a clearly defined scope.
Why does this improve safety?
I no longer need to play whack-a-mole with Windows Defender - I only need to exempt one root path and one executable.
Limiting the configuration to %homepath% complicates guardrails substantially by preventing a clear boundary between those files Codex touches and everything else. That entire directory is heavily relied on by many Windows applications and is typically not backed up or snapshotted in its entirety. Typically work lives in a path like network NAS with a mounted drive, OneDrive/Sharepoint/other cloud-synced folders that benefit from snapshots & file versioning.
Windows 11's exemption only allows picking an executable using a file-picker, which makes defining exemptions a challenge. Microsoft app delivery makes it impossible to navigate to the executable.
<img width="385" height="346" alt="Image" src="https://github.com/user-attachments/assets/c401a906-941d-47d0-95de-ead07dbb4b17" />
Additional information
_No response_
This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗