Skip to content

Update Copilot SDK to 1.0.13-preview.1 - #194

Merged
SIkebe merged 1 commit into
mainfrom
sikebe-update-copilot-sdk-1-0-13
Aug 27, 2026
Merged

SIkebe merged 1 commit into
mainfrom
sikebe-update-copilot-sdk-1-0-13

Conversation

@SIkebe

@SIkebe SIkebe commented Aug 27, 2026

Copy link
Copy Markdown
Owner

Summary

  • Update GitHub.Copilot.SDK from 1.0.12-preview.0 to 1.0.13-preview.1 and synchronize the bundled Copilot CLI release from 1.0.81-5 to 1.0.81-10 with the official Windows x64/arm64 SHA-256 digests.
  • Follow the preview.1 managed-settings API change from DisableBypassPermissionsMode.Disable to DisableBypassPermissionsModes.Disable.
  • Explicitly set IncludedBuiltinSkills = [] for every RepoSyncRadar session so runtime-bundled skills remain unavailable alongside the existing radar-only tool filter, disabled tool search, custom instructions, memory, scheduler, and session store.
  • Update the third-party notice and tests, and document the stable SDK isolation contract.

SDK evidence:

  • NuGet 1.0.13-preview.1 identifies repository commit f0a575aaad366e93e93349544d91035d0fb2e511; its generated props specify Copilot CLI 1.0.81-10.
  • Compared SDK tags v1.0.12-preview.0 (23dcc2e7afd1f06107a7af261d1fc2a25539773e) through v1.0.13-preview.0 and v1.0.13-preview.1.
  • Reviewed the .NET source and tests for session creation/resume, managed settings, permission decision attribution, MCP resume behavior, generated RPC/event contracts, and Empty-mode built-in skill isolation.
  • Reviewed Default ClientMode::Empty to no built-in skills github/copilot-sdk#2410: Empty mode now sends an empty includedBuiltinSkills list by default while preserving explicit allowlists on create and resume.

The package also brings regenerated RPC/event contracts and the newer Copilot runtime without app source changes. RepoSyncRadar does not adopt CopilotClientMode.Empty in this PR because changing CLI home/session filesystem behavior requires a separately designed state migration; explicit built-in skill exclusion provides the relevant isolation improvement without that lifecycle risk.

Related Issues

N/A - no issue to close.

Scope

  • App UI / workflow
  • Core services / data model
  • Copilot SDK / agent behavior
  • Preview / WebView2
  • Documentation / release readiness
  • Tests / tooling
  • Other:

Validation

  • dotnet build RepoSyncRadar.sln -warnaserror
  • dotnet test RepoSyncRadar.sln -- --filter-not-trait Category=Manual
  • Focused tests: SDK configuration assertions are covered by SessionConfigBuilderTests; the full non-manual suite passed (1,304 tests).
  • N/A - no UI/WebView changes, so no manual smoke or screenshots were required.

NuGet.org is disabled in the local environment and the approved proxy had not synchronized preview.1. Restore used a temporary NuGet CDN fallback with exact package source mapping, CDN SHA-512 verification, repository signature verification, and the existing approved proxy for all other packages. The temporary source, config, package cache, and audit checkout were removed after validation.

Risk And Rollback

  • User impact: Copilot sessions use the newer SDK/runtime and no longer allow runtime-bundled skills; registered radar_* tools continue to work unchanged.
  • Operational risk: Preview SDK wire contracts can change, and the new CLI runtime may expose regressions not represented by unit tests. Existing explicit permission, tool, telemetry, auth, and lifecycle settings remain intact.
  • Rollback plan: Revert this commit to restore SDK 1.0.12-preview.0, CLI 1.0.81-5, and the previous managed-settings constant.

Release Notes

  • User-facing change
  • Internal-only change
  • No release note needed

Release note draft:

  • Updated the embedded GitHub Copilot SDK/runtime and tightened session isolation by disabling runtime-bundled skills.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0af29f05-3b75-479f-bcd8-aac72d05744d
Copilot AI balanced review requested due to automatic review settings August 27, 2026 05:10

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The versions, runtime hashes, API migration, isolation behavior, tests, and documentation are consistent.

Pull request overview

Updates the Copilot SDK/runtime while strengthening session isolation.

Changes:

  • Upgrades SDK to 1.0.13-preview.1 and CLI to 1.0.81-10.
  • Disables runtime-bundled skills and adopts the renamed permissions constant.
  • Synchronizes notices, tests, hashes, and guidance.
File summaries
File Description
Directory.Packages.props Updates the SDK package version.
scripts/CopilotCliRelease.props Updates CLI version and verified hashes.
src/RepoSyncRadar.App/Copilot/SessionConfigBuilder.cs Excludes built-in skills and updates permissions API usage.
src/RepoSyncRadar.App/Settings/ThirdPartyNotices.cs Updates the SDK notice version.
tests/RepoSyncRadar.App.Tests/Copilot/SessionConfigBuilderTests.cs Verifies session isolation settings.
tests/RepoSyncRadar.App.Tests/Components/ThirdPartyNoticesPanelTests.cs Updates notice expectations.
.github/copilot-instructions.md Documents the isolation contract.
.github/skills/copilot-sdk-dotnet-audit/SKILL.md Improves release-diff auditing guidance.
Review details
  • Files reviewed: 8/8 changed files
  • Comments generated: 0
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@SIkebe
SIkebe merged commit 18a2fc8 into main Aug 27, 2026
10 checks passed
@SIkebe
SIkebe deleted the sikebe-update-copilot-sdk-1-0-13 branch August 27, 2026 06:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants