From fd24cea5cb11da4e630485ff2d9269318b8c2a4e Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Thu, 16 Jul 2026 01:54:36 +0000 Subject: [PATCH 01/27] Update changelog.md for version 1.0.71 --- changelog.md | 93 ++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 93 insertions(+) diff --git a/changelog.md b/changelog.md index adef233a..7c7ca0a8 100644 --- a/changelog.md +++ b/changelog.md @@ -1,3 +1,96 @@ +## 1.0.71 - 2026-07-16 + +- `copilot -p --autopilot` no longer hangs when a background shell or agent outlives the turn; it now honors the COPILOT_TASK_WAIT_TIMEOUT_SECONDS timeout the same way plain `-p` does. +- Reopening the /subagents model picker keeps each agent's reasoning effort and context tier +- Refresh memory context after 30 minutes in long-lived sessions +- Keep MCP tool lists up to date when servers change +- Avoid leaving long-running background git processes after exit +- Add a configurable maximum for Ctrl+R command history +- On startup, an invalid settings.json now shows a warning identifying the offending value instead of silently ignoring your settings +- /terminal-setup no longer skips setup on terminals without real kitty keyboard support +- Add /voice devices to choose and persist the microphone for voice mode +- Limit which built-in agents are available to tasks and subagents +- Add canvas support in the CLI for extension-driven interactions +- Enforce the sandbox filesystem policy on LSP file reads and rename edits +- Allow empty owner and author emails in marketplace metadata +- Keep all MCP Server Type options visible on short terminals +- Mark disabled skills in `copilot skill list` and its JSON output +- Plan mode now hard-blocks built-in tool calls that would modify the workspace, so the agent can no longer edit files or run mutating shell commands while planning (built-in mutators like opening a pull request are blocked; MCP and external tools are still allowed) +- Improve /chronicle cost-tips recommendations with richer cost profiles +- Highlight standalone hex colors inline in Markdown +- Persist GitHub MCP toolset/tool config via settings.json (githubMcpToolsets, githubMcpTools, etc.) +- Add `plugins marketplace` subcommands to list, add, and remove plugin marketplaces +- Persist sidebar sessions across restarts +- Add plugins marketplace browse and update commands +- Split /worktree and /move: /worktree now creates a new worktree and leaves your uncommitted changes behind, while the new /move carries them into the new worktree +- Add local and cloud cost profiles to /chronicle cost-tips +- Switching to autopilot mid-turn now auto-answers questions asked during that same turn +- Custom agents that request a shell tool by alias now also receive the matching read, list, and stop shell tools +- Slash commands and their autocomplete now match regardless of case (e.g. /SESSION works like /session) +- Show repo-enabled plugins in /plugin list and skill pickers +- Press ? twice to dismiss quick help and start a prompt with a literal ? +- Shell completions suggest positional-argument choices +- Show the /app launch message and download link immediately on Linux +- Validate --max-autopilot-continues rejects NaN, negative, and fractional values +- Honor NO_COLOR in the CLI even when chalk cached a color level +- Apply updated session options (shell flags, streaming, custom agent defaults) immediately after /settings changes +- Announce the focused /model row for screen readers +- Announce the focused picker row to screen readers +- Show selected custom agents once in /agent and keep their source label when the file name differs from the display name +- Clear the /model pricing banner when no models match +- Keep /share file session and /share html session from using the full-session selector as an output path +- Honor --context in fresh interactive sessions +- Fixed the model picker changing a hidden model's reasoning effort or context window when the search matched no results, and hid the inert key hints shown in that empty state +- Display plugin root skills as /plugin instead of /plugin:plugin +- Keep valid hooks in a config file when one hook entry is malformed +- Denying write(path) now blocks only the specified path +- Using --add-github-mcp-tool "\*" now enables all GitHub MCP tools +- Render empty untracked files without a phantom added line +- Show clean failure messages when copilot skill add fails +- Press Enter on a blank settings array item to show an error instead of saving an empty value +- Press Enter once to toggle booleans with a registered default in /settings +- Declining folder trust in /cwd keeps your live session open and returns to the previous folder +- Show a warning when a workspace MCP config is malformed or cannot be loaded +- Make bare `copilot mcp` and `copilot skill` print help and exit 0, matching `copilot plugin`. Consistent with `plugin`, the implicit `help ` form is not supported for these groups; use `copilot mcp --help` (or `copilot skill --help`) instead. +- Show malformed allowed_models.txt policy errors cleanly in -p mode +- Resume synced sessions by name without a false multiple matches error +- Show an error when --name is used with --session-id for an existing session +- Show --plugin-dir plugins in copilot plugin list +- Keep backgrounded sessions alive when you switch away from them +- Link bare #number GitHub refs in -p --stream off output +- Show the startup banner only on the first launch when set to once +- Allow `copilot update` and `/update` to accept `stable` as a channel +- Surface --plugin-dir warnings in the terminal +- Surface the real load error for malformed custom agents +- Reject --continue when used with --resume +- Prompt mode now exits non-zero when a `--share` or `--share-gist` export fails +- Server mode reconnects OAuth MCP servers from cached tokens +- Keep stored Git credential helpers available for marketplace plugin installs +- The /model picker shows the Auto model description as markdown with a clickable Learn More link +- Keep sessions tied to their working directory across prompts, restarts, and workspace tools +- Always offer a custom answer in ask_user choice prompts +- Lower the default maximum sub-agent nesting depth from 6 to 4 to curb runaway recursive sub-agent delegation. Usage-based billing users can still adjust `subagents.maxDepth` (up to 128). +- Add a pinned prompts setting in /settings to control prompt pinning +- Add Repo and Repo (local) scope tabs to the /settings dashboard +- Interactive shell commands now fail with a retryable "reconfiguring" message instead of an "unknown shellManager handle" error after the shell manager is disposed, and a detached command's completion notification is no longer lost when the shell context is reconfigured while a read is in progress +- Reject custom-agent names that would create hidden files +- Reject malformed --allow-tool and --deny-tool patterns with an error message +- Show retained shell output in /tasks Shell Details for finished tasks +- Remove duplicate Error: prefixes from plugin command failures +- Shell completions stop suggesting subcommands as flag values +- Show singular message counts in /usage activity graph +- Keep /cd from switching to files or inaccessible directories +- Dismissing the quick-help overlay with ? no longer leaves a stray ? in the prompt +- --sandbox and --no-sandbox now show their "ignored" warning during interactive startup when the sandbox feature is unavailable (previously it was only visible in non-interactive mode) +- Show the full command with its arguments (not just the wrapper) in the /mcp server detail view +- Hide the inert navigate and view-log hints in the empty /lsp logs (LSP Services) panel +- Exit non-interactive prompt runs with a failure code when a prompt is blocked before responding +- Show the Auto discount in the redesigned inline model picker +- New sessions start in the default directory instead of the active session's cwd +- Fish completion only offers enum values for closed-choice flags +- Use targeted validation commands and lighter install guidance by default +- Use ctrl+x → x to close a session and ctrl+x → h to hide the split sidebar + ## 1.0.70 - 2026-07-09 - Add GPT-5.6 model support From cb0467f0a59ed96dcfab71310294d5c69cce545a Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Mon, 20 Jul 2026 17:51:16 +0000 Subject: [PATCH 02/27] Update changelog.md for version 1.0.72 --- changelog.md | 47 +++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 47 insertions(+) diff --git a/changelog.md b/changelog.md index 7c7ca0a8..eb490bdf 100644 --- a/changelog.md +++ b/changelog.md @@ -1,3 +1,50 @@ +## 1.0.72 - 2026-07-20 + +- An `agentStop` hook that always blocks no longer loops indefinitely: the CLI now ends the turn after 8 consecutive blocks, and `agentStop` hooks receive a `stop_hook_active` flag so they can detect a forced continuation and self-limit +- Add opt-in git and gh authentication inside the OS sandbox +- Sandbox macOS keychain access now defaults off for tighter isolation; re-enable it in /sandbox if a command needs it +- Lifecycle and subagent hook commands run in the current session directory after /cd +- Deleting an MCP server with /mcp delete stops its running background process +- Toggling /sandbox restarts only local MCP servers and leaves remote servers connected +- Command approvals no longer carry over to another repository after you switch with /cd +- The GitHub tab's Open in web action now reliably launches your browser on Windows +- Preserve pasted prompt content when changing models through Ctrl+X /model +- Corrected the added-line count shown when creating a file so files ending in a trailing newline no longer report one extra line +- /worktree and /move no longer fail to create a worktree for an auto-generated branch name when many similarly-named branches or a leftover worktree directory already exist: the numeric-suffix search is no longer capped at 5 and now skips stale unregistered worktree directories (an explicitly supplied branch name still errors on a collision) +- /worktree no longer intermittently runs the kickoff task in the main repo instead of the new worktree +- /worktree and /move now propagate folder trust to the new worktree before switching when the source is already trusted (avoiding a spurious folder-trust prompt in that case), /move addresses its git stash precisely so a concurrent stash can't misplace changes, and worktree creation skips a leftover directory instead of failing +- Show the exit resume hint for a renamed session with no messages when its workspace is only available as a cached snapshot +- Show a connected message after a slow MCP server eventually connects +- Add `update`/`uninstall` verbs to `/plugins`, let `enable`/`disable`/`remove` target plugins, MCP servers, or skills via `--plugin`/`--mcp`/`--skill` flags or a positional kind, and support installing skills with `/plugins install --skill` +- Add a /plugins help command plus skill, MCP, and marketplace management for full /plugin parity +- Session exports keep angle brackets intact in inline code and top-level fenced code blocks +- Show MCP server status correctly for names like constructor and **proto** +- Keep the session highlight on the nearest live row when closing a session, in both the Sessions split view and the standalone Sessions tab +- Pad inline hex color swatches once inside Markdown lists +- Type $ at the prompt to open an interactive shell in the current session directory (enable it with `/settings shellShortcut on`; off by default) +- Nested markdown lists render correctly in buffered output (`-p --stream off` and detail screens): sub-bullets are no longer glued onto the parent item's line or flattened, and are indented under their parent +- `copilot skill list` now strips terminal control characters from skill names and descriptions, so a crafted skill can no longer inject ANSI escape sequences into the listing output. +- Install skills from the CLI with `copilot plugins install --skill ` (add `--scope project` to a file or URL install to install into the repository) +- Show default values in /settings and let booleans cycle back to default +- Require SSO for remote control when managed settings demand it +- Mask secret values in /settings show output +- Show hex color codes written as inline code (e.g. `#FF0000`) as color swatches, and add a renderHexColors setting (on by default) to toggle hex-color swatches +- Add /model --session (-s) to change the model, reasoning effort, or context window for just the current session, leaving global settings unchanged. +- Detect VS Code, Cursor, and Windsurf through parent processes in /terminal-setup +- The Sessions sidebar is now navigable with the keyboard and mouse (arrows open and focus it and move the selection, and Enter or a click switches to a session; press n to spawn a session or x twice to close one from the keyboard); /settings can disable it or stop restoring remembered sessions +- Add --plugin, --mcp, and --skill flags for plugin mutations +- Add skill removal support to `copilot plugins remove --skill` +- Wrap ask-user and elicitation inputs in the split-pane chat view +- Modified vim keys (Ctrl+K, uppercase J/K) no longer move the selection in tool-permission prompts and other text-input select menus; only unmodified j/k, the arrow keys, and Ctrl+P/Ctrl+N navigate. +- `/terminal-setup` now refuses to modify a VS Code keybindings.json that contains a JSON syntax error (instead of rewriting it and reporting success), matching its documented invalid-JSON handling. +- Reveal full file paths when expanding compact editing rows +- Make the plan-approval menu deterministic across models +- Keep /add-dir directories visible in the agent context across turns +- Multi-turn subagents are always enabled, so you can send follow-up messages to running agents +- Enable tool search for Claude Haiku 4.5+ +- Emoji shortcodes like :tada: no longer render with a spurious trailing space in printed and PR/issue/gist output +- Deliver scheduled prompts as steering messages when the agent is busy + ## 1.0.71 - 2026-07-16 - `copilot -p --autopilot` no longer hangs when a background shell or agent outlives the turn; it now honors the COPILOT_TASK_WAIT_TIMEOUT_SECONDS timeout the same way plain `-p` does. From 2b809c84e87dbcc88f897cb4f3fb97c43b77af95 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Tue, 21 Jul 2026 00:11:43 +0000 Subject: [PATCH 03/27] Update changelog.md for version 1.0.73 --- changelog.md | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/changelog.md b/changelog.md index eb490bdf..9a8619a3 100644 --- a/changelog.md +++ b/changelog.md @@ -1,3 +1,8 @@ +## 1.0.73 - 2026-07-20 + +- Anthropic subagents continue working when additional directories are configured +- Resolve relative links in custom agent instructions from the agent file location + ## 1.0.72 - 2026-07-20 - An `agentStop` hook that always blocks no longer loops indefinitely: the CLI now ends the turn after 8 consecutive blocks, and `agentStop` hooks receive a `stop_hook_active` flag so they can detect a forced continuation and self-limit From 05cdbb3ae04a839ffc465facdc0e0f207e37dbe0 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Thu, 23 Jul 2026 22:05:57 +0000 Subject: [PATCH 04/27] Update changelog.md for version 1.0.74 --- changelog.md | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) diff --git a/changelog.md b/changelog.md index 9a8619a3..ea2a2336 100644 --- a/changelog.md +++ b/changelog.md @@ -1,3 +1,26 @@ +## 1.0.74 - 2026-07-23 + +- Typing `?` while the /search bar is open enters it as text instead of opening quick help +- Add support for Open Plugin Spec v1 plugin manifests and mcp.json configuration +- IDE integration reconnects reliably when the CLI reloads MCP servers or changes directory +- Multi-turn subagent timelines show every prompt and response in the correct order after reopening /tasks +- Subagent timelines identify whether prompts came from the main agent or another subagent +- Show a first-run splash to opt into the default sandbox +- Adding support for gemini-3.6-flash +- The `/mcp add` and `/mcp edit` wizard now preserves `=` characters in environment variable values (such as base64 padding), so secrets and tokens are stored correctly. +- Remote session uploads stop retrying permanent Mission Control 400/404 responses +- Show Tab in /settings footer to switch scope tabs +- Downscale oversized tool-result images so CAPI Responses requests continue +- When multiplexing sessions, a session's open dialog no longer leaks into another session; eligible pickers reopen when you switch back +- The `$` interactive shell shortcut now opens a shell even while the agent is working +- Fully honor the skill disable-model-invocation flag +- Warn when a participating language server reports a different symbol than the one requested +- Steering interrupts shell output waits without stopping the running command +- Increase the Responses request size limit +- Plan mode now allows session-folder planning artifacts while still blocking clear file mutations outside the session folder. +- Add `/model plan` (or `/model --plan`) to pick a model used while in plan mode; pass a model id, `off` to clear, or no id to open the picker. Reverts to the session model when you leave plan mode. +- Resume search matches session titles even when whitespace differs + ## 1.0.73 - 2026-07-20 - Anthropic subagents continue working when additional directories are configured From 425b68cdb22db404eb9e9978f72a8f4c425bee45 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Fri, 24 Jul 2026 19:54:04 +0000 Subject: [PATCH 05/27] Update changelog.md for version 1.0.75 --- changelog.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/changelog.md b/changelog.md index ea2a2336..d3df51e1 100644 --- a/changelog.md +++ b/changelog.md @@ -1,3 +1,7 @@ +## 1.0.75 - 2026-07-24 + +- Add support for Claude Opus 5 + ## 1.0.74 - 2026-07-23 - Typing `?` while the /search bar is open enters it as text instead of opening quick help From aee1edd29ef0f2058425bf399bcc9e5002a2b8f2 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Thu, 30 Jul 2026 01:09:31 +0000 Subject: [PATCH 06/27] Update changelog.md for version 1.0.76 --- changelog.md | 36 ++++++++++++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) diff --git a/changelog.md b/changelog.md index d3df51e1..0650749b 100644 --- a/changelog.md +++ b/changelog.md @@ -1,3 +1,39 @@ +## 1.0.76 - 2026-07-29 + +- Add enable/disable controls in /plugins for plugins, instructions, agents, LSP servers, and hooks +- Add support for the grok-4.5 model +- Sandbox denied paths are enforced for relative and symlinked entries on macOS and Linux (Windows cannot deny per path) +- Unsent prompt text now stays with the session it was typed for (for the rest of the CLI session) instead of following you to the session you switch to +- Resuming a session now restores its autopilot or plan mode instead of reverting to interactive, so the autopilot-only `task_complete` tool stays available and the mode matches the session you left +- URL permission prompts now keep their sandbox-bypass warning and the model's reason when a host integration rebuilds the prompt, so an elevated fetch is no longer shown as an ordinary one +- When an update is auto-downloaded, the notification suggests /restart and drops the warning color +- /diff scrolls and syntax-highlights large multi-file diffs faster +- Split-view sidebar: hover-to-focus is now off by default (opt in with `sidebar.hoverFocus`), the active session card is accented by default (opt out with `sidebar.accentActiveSession`), and the closed-state `open sidebar` hint always renders in the neutral hint color +- `web_fetch` now follows HTTP redirects instead of failing, asking permission for the redirect target when it is on a different origin and showing where the redirect came from +- Add a directable queue manager (staff) to reorder, edit, remove, repeat, and immediately send queued messages +- New Sessions sidebar for managing multiple concurrent sessions: switch between them, spawn new ones, and see their status at a glance. Turn it on with experimental mode (`/experimental on`). +- Enterprise administrators can enforce a restrictive sandbox floor: managed settings tighten (but never loosen) the user's sandbox policy, and the `/sandbox` dialog surfaces the org-configured managed values with locked fields and managed filesystem paths so admins can confirm what is enforced. +- Sessions no longer fail every turn with "Holder terminated during creation" after a subagent finishes +- Startup tips only suggest /init in repositories that don't already have Copilot instructions +- A `userPromptSubmitted` hook returning a non-string value for `modifiedPrompt`, `modifiedTransformedPrompt`, or a handled `responseContent` no longer corrupts the session; the value is ignored, a type-only warning naming the field is logged, an empty-string replacement is rejected instead of blanking the model-facing content, a hook that sets `handled` without a usable `responseContent` is now diagnosed instead of silently falling through to the model, and a `null` `additionalContext` is treated as absent instead of being injected as the literal text `null`; hook output is also bounded at 10 MiB per invocation, so an HTTP or command hook returning an unbounded response can no longer exhaust memory or leave an oversized session behind +- Show recent shell output for large commands that write to a file +- The /instructions picker now respects --no-custom-instructions. +- Render inline images in Rio terminals that support Kitty graphics +- Sandboxed searches now offer an immediate bypass prompt and avoid duplicate bypass prompts. +- Voice mode pauses playing media before recording and resumes it afterward, where supported (macOS and Windows) +- Show the number of active scheduled prompts in the footer +- Add /limits predict to suggest a session AI-credit limit from similar sessions. +- Add configurable timed refreshes for custom status-line commands +- Queued messages list no longer shows a blank row or inflated count, and Ctrl+C removes your own newest queued message +- Changing the `mouse` setting mid-session now takes effect immediately, from both `/settings mouse on|off` and the `/settings` dialog, instead of being saved but ignored until the CLI restarted +- web_fetch routes through the configured sandbox proxy when outbound is allowed, and denies egress when network.allowOutbound is false (a proxy no longer overrides the user's outbound policy); when a proxied fetch fails it warns that curl/wget share the same proxy, and suggests requestSandboxBypass only when the sandbox proxy itself is unreachable +- Improve subagent delegation for small tasks and parallel work +- Queue mid-turn /model changes and apply them after the current response finishes +- Restore the early warning when unreclaimable system and tool context nears the limit, before automatic compaction is blocked +- Session working directory no longer reverts to the original checkout shortly after `/worktree` switches into a new worktree +- MCP tools load faster from definition-scoped snapshots, with process-wide and per-server cache opt-outs. +- Autopilot stays selected after task_complete by default; set stayInAutopilot to false to return to interactive mode after each task + ## 1.0.75 - 2026-07-24 - Add support for Claude Opus 5 From 2392889bf7d2d3f3f9a7ad354c6017a21e4f9928 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Thu, 30 Jul 2026 23:36:02 +0000 Subject: [PATCH 07/27] Update changelog.md for version 1.0.77 --- changelog.md | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/changelog.md b/changelog.md index 0650749b..7e5e11af 100644 --- a/changelog.md +++ b/changelog.md @@ -1,3 +1,11 @@ +## 1.0.77 - 2026-07-30 + +- Unconditional autopilot approval now disables sandbox for the current session when bypass is allowed +- Ctrl+G opens your editor to edit ask_user freeform answers without closing the prompt +- Add a browser-based (web) OAuth login flow, now the default for `copilot login` on local interactive terminals (device code remains the default on remote/headless terminals). Use `--web-flow`/`--device-code` to force a mode, or pick one in the interactive `/login` command +- Support enforcing managed sandbox policy via macOS and Windows native MDM settings +- Allow reasoning effort to be omitted so the server can select the default + ## 1.0.76 - 2026-07-29 - Add enable/disable controls in /plugins for plugins, instructions, agents, LSP servers, and hooks From 9532bdacf5a343c3dcc444337f7b25e88fc7372c Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Mon, 3 Aug 2026 23:30:26 +0000 Subject: [PATCH 08/27] Update changelog.md for version 1.0.78 --- changelog.md | 30 ++++++++++++++++++++++++++++++ 1 file changed, 30 insertions(+) diff --git a/changelog.md b/changelog.md index 7e5e11af..ce39e0f3 100644 --- a/changelog.md +++ b/changelog.md @@ -1,3 +1,33 @@ +## 1.0.78 - 2026-08-03 + +- Timeline headers show how long each tool call took, right-aligned and ticking live while it runs (for calls of at least 5 seconds). On by default — disable with `/settings showToolDurations`. +- First-party plugins automatically update to the latest version at session start +- Add the experimental /new-worktree command to create a new worktree and start a new conversation in it +- Copilot login now defaults to the browser flow for local desktop subprocesses without a TTY, including IDE integrations, while remote and headless environments continue using device code +- Interactive shell shortcut now launches on Enter and shows an inline hint when "$" is armed +- Extension slash commands run their handler exactly once per invocation when several extensions are loaded +- Inline images no longer render with their first row repeated down the whole picture after the timeline scrolls +- A run whose prompt is piped over stdin now treats its `sessionEnd` hook the same way `-p` does: the hook fires once per completed agent turn with `reason` `complete` (or `error` if the turn failed), instead of once at shutdown with `user_exit`. As with `-p`, a piped run that exits before completing a turn fires no `sessionEnd` hook +- Split-view sidebar: the red close confirmation now reads `x again to close` (or `x again to exit CLI` on the last session) instead of `x close`, so a second press is clearly what closes +- Expose token usage in ACP prompt results and live usage_update notifications +- Added a forceRemoteSettingsRefresh managed setting that requires a fresh managed-settings fetch on startup +- Disabling the sandbox from a bypass prompt applies only to that session; new sessions start sandboxed again +- Managed settings now fall back to the persistent cache whenever a server-managed settings fetch fails for any reason (network error, a non-success HTTP status, or a malformed/unparseable response), and fail open — starting without the unconfirmed server restriction rather than the prior fail-closed behavior — when no usable cached policy is available +- When the sandbox blocks a shell command and bypass is allowed, CLI offers to re-run it outside the sandbox without asking the model +- /rewind no longer requires git and restores only the files Copilot changed, skipping any file whose contents no longer match what Copilot last wrote, with a conversation-only or conversation + files choice +- Add /permissions to switch between approval modes. +- ACP mode supports closing sessions with the closeSession request. +- Ctrl+Q now enqueues the highlighted mid-text skill completion instead of the partial token +- Switching sessions no longer restarts MCP servers or rebuilds hook state, so a turn running in another session is never halted with a stale-hook error +- Refresh deferred MCP tools after OAuth authentication +- New sandbox setting `allowDevToolCaches` (on by default): grants sandboxed builds access to toolchain caches, registries, and installs so builds work without extra setup. Set false to opt out. +- Honor explicit GitHub MCP toolset/tool config: keep gh-overlap tools and stop steering to the gh CLI when you opt in +- Warn on startup about unknown top-level keys in user settings.json (e.g. a misspelled setting) instead of silently ignoring them +- Shell completion for --model now suggests auto and supported model names +- Render long session transcripts progressively to keep scrolling responsive +- Resuming a long session is dramatically faster and far lighter on memory, because its history is now read once at startup (in parallel, across CPU cores) instead of being re-read in full for every check the CLI runs before it can paint. In our benchmark a 230MB, 74k-event transcript came back in well under a second instead of about ten, at roughly a quarter of the peak memory; the exact gain depends on your machine's core count and disk +- The /allow-all auto safety-judge model is no longer user-configurable; the judge model is now selected automatically. + ## 1.0.77 - 2026-07-30 - Unconditional autopilot approval now disables sandbox for the current session when bypass is allowed From ef627e1baad937d3c8da45f8a5541c6fc3c97b6a Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Mon, 10 Aug 2026 16:19:17 +0000 Subject: [PATCH 09/27] Update changelog.md for version 1.0.79 --- changelog.md | 47 +++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 47 insertions(+) diff --git a/changelog.md b/changelog.md index ce39e0f3..48f07df8 100644 --- a/changelog.md +++ b/changelog.md @@ -1,3 +1,50 @@ +## 1.0.79 - 2026-08-10 + +- The /sandbox configuration dialog shows where sandbox settings are stored in settings.json +- Add support for enterprise allow-auto-only policy so /allow-all auto works while full allow-all remains blocked. +- Allow enterprise-managed sandbox policy to enforce a proxy URL while credentials remain user-controlled +- A tool directory inside your workspace that is on PATH (.venv/bin, node_modules/.bin, an in-repo GOPATH) no longer turns that part of the workspace read-only in the sandbox +- The /sandbox configuration dialog groups the git, gh, and (on macOS) keychain settings under a new Auth tab, and the settings keys moved from `sandbox.gitAuth`/`sandbox.ghAuth` to `sandbox.auth.git`/`sandbox.auth.gh`. There is no migration: the old keys are ignored in settings files, and SDK requests that still send them are rejected as invalid rather than ignored +- Added a `worktreeBaseRef` setting that controls whether `/worktree`, `/worktree new`, and `--worktree` start from HEAD or the remote default branch. All three now default to HEAD; previously `--worktree` started from the remote default branch. +- Model picker groups models into Recent, Recommended, New, and other sections, and Shift+Tab switches grouping views. +- Large monorepos now use tgrep ([trigram-indexed grep for fast regex search in large codebases](https://github.com/microsoft/tgrep)) instead of ripgrep +- Agent Plugins spec plugins can now ship extensions under a com.github.copilot/extensions/ directory +- Add support for the kimi-k3 model +- Combine `--plan` with `--mode autopilot` to plan first and then implement without waiting for approval +- The `/app` command now opens the current session in the GitHub Copilot desktop app instead of landing on Home with the wrong folder (requires GitHub Copilot app 1.1.3 or later) +- On macOS, a sandbox read-only path nested inside a writable one now stays read-only instead of inheriting the write permission from the wider path +- On macOS, sandboxed commands can use UNIX-domain sockets again, so tools that talk over a local IPC pipe (tsx, vite, esbuild, jest workers) no longer fail with `listen EPERM` +- Sandboxed commands work when the working directory lives on a Windows Dev Drive +- `/theme` now only shows its deprecation notice for a valid color mode, so a mistyped mode no longer suggests an invalid command or hides the notice from your next valid `/theme`. +- Sandboxed git now authenticates to Azure DevOps, GitHub Enterprise Server, GitLab, and other non-GitHub remotes you have stored HTTPS credentials for +- Ask user multi-select prompts include an Other option for free-text answers +- Improve teleported subagent /tasks navigation with nested tree browsing, current/all and finished-task filters, and a live timeline you can steer +- A rare internal delay no longer prints a diagnostic warning on top of the interactive UI +- A failed session-history load no longer leaves the timeline permanently empty: the failure was silently discarded, so the transcript stayed blank for the rest of the session with nothing logged. It is now retried, and reported in the transcript and the log if it still fails +- Resuming a long session no longer collapses the timeline's scroll range while history renders in the background: entries that had not finished rendering were published as if they did not exist, so the scrollbar and scroll position jumped until the background render caught up +- Manage multiple concurrent sessions from the Sessions tab and sidebar +- Sandboxed wrapper builds (make and friends) get the dev tool caches their recipes need, based on the build manifests in the working directory +- Prompt pinning is off by default; set pinnedPrompts to true to enable it. +- Sandboxed commands can reach the network again on recent Windows builds, where every outbound connection was blocked even with outbound access enabled and no proxy configured +- Plugin custom agents honor deferred-tool-loading frontmatter +- Use `/worktree new` to start a new session in a new worktree +- A sandbox that cannot start an MCP server now fails in seconds instead of stalling the session, and sandbox startup failures for both MCP and language servers now say the sandbox was at fault and how to fix or opt out of it +- Login links are clickable during web and device-code sign-in +- Pin the current prompt one row higher, in the row the tab bar already reserves, so it keeps the shape of the prompt it copies while costing the timeline one row less +- Leave the pinned prompt off by default on terminals under 30 rows, where it would crowd the output; set pinnedPrompts explicitly to override at any size +- Compute /context attribution against the Auto-resolved model so token totals are accurate for Free/Student users +- Disabling an extension no longer breaks elicitation, canvases, or tool permission prompts for other extensions +- A prompt stashed with ctrl+s now stays with the session it was typed for, so switching away and back and pressing ctrl+s restores it instead of finding it gone +- On Linux, searches and most shell commands blocked by the sandbox now offer to re-run outside it +- BREAKING: the sandbox setting `allowDevToolCaches` is renamed `allowDevToolAccess`, since it grants dev-tool config and registries too, not just caches. The old key is no longer read and is ignored silently, so an existing `false` opt-out reverts to the default (on). Rename it in settings.json and in any managed/MDM policy. +- Add /sandbox policy to show effective sandbox paths, denials, and network access +- Queue prompts, shell commands, and supported slash commands in local sessions to run in order after the current task finishes +- Set "autoUpdate": true on an extraKnownMarketplaces entry in your user settings to auto-update its plugins at session start +- /sandbox tags inactive settings as (disabled) and explains why they are locked, and documents dev tool caches in copilot help sandbox +- Show "pending · ctrl+c to cancel" for in-flight steering prompts +- Make /model session-scoped by default, and use /config model to set defaults for future sessions. +- Pin the current prompt as a single line instead of a three-row framed block, so it reads as chrome and returns rows to the timeline; with the tab bar on it sits directly below the tabs and costs the timeline nothing + ## 1.0.78 - 2026-08-03 - Timeline headers show how long each tool call took, right-aligned and ticking live while it runs (for calls of at least 5 seconds). On by default — disable with `/settings showToolDurations`. From 476581ccde7d596ded05d2b77b36edb57762a2c4 Mon Sep 17 00:00:00 2001 From: Michael Recachinas Date: Tue, 11 Aug 2026 10:58:35 -0400 Subject: [PATCH 10/27] Migrate close-on-PR workflow off pull_request_target Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- .github/workflows/close-invalid-pr-writer.yml | 51 +++++++++++++++++++ .github/workflows/close-invalid.yml | 46 +++++++++-------- 2 files changed, 76 insertions(+), 21 deletions(-) create mode 100644 .github/workflows/close-invalid-pr-writer.yml diff --git a/.github/workflows/close-invalid-pr-writer.yml b/.github/workflows/close-invalid-pr-writer.yml new file mode 100644 index 00000000..7cfc6a70 --- /dev/null +++ b/.github/workflows/close-invalid-pr-writer.yml @@ -0,0 +1,51 @@ +name: Close invalid PR writer + +on: + workflow_run: + workflows: [Close issue/PR on adding invalid label] + types: [completed] + +permissions: + issues: read + pull-requests: write + +jobs: + close-invalid-pr: + if: > + github.repository == 'github/copilot-cli' && + github.event.workflow_run.event == 'pull_request' && + github.event.workflow_run.conclusion == 'success' && + github.event.workflow_run.repository.full_name == github.repository + runs-on: ubuntu-latest + steps: + - name: Close invalid PR + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GH_REPO: ${{ github.repository }} + HEAD_OWNER: ${{ github.event.workflow_run.head_repository.owner.login }} + HEAD_BRANCH: ${{ github.event.workflow_run.head_branch }} + PR_NUMBER: ${{ github.event.workflow_run.pull_requests[0].number }} + run: | + set -euo pipefail + + if [ -z "${PR_NUMBER:-}" ] || [ "$PR_NUMBER" = "null" ]; then + PR_NUMBER="$(gh api --method GET "repos/$GH_REPO/pulls" -f state=open -f head="$HEAD_OWNER:$HEAD_BRANCH" --jq 'if length == 1 then .[0].number else empty end')" + fi + + if [ -z "${PR_NUMBER:-}" ]; then + echo "Unable to identify a single open PR for workflow run; skipping." + exit 0 + fi + + pr_state="$(gh api "repos/$GH_REPO/pulls/$PR_NUMBER" --jq .state)" + if [ "$pr_state" != "open" ]; then + echo "PR #$PR_NUMBER is $pr_state; skipping." + exit 0 + fi + + if ! gh api "repos/$GH_REPO/issues/$PR_NUMBER/labels" --jq '.[].name' | grep -Fxq invalid; then + echo "PR #$PR_NUMBER does not currently have the invalid label; skipping." + exit 0 + fi + + gh api -X PATCH "repos/$GH_REPO/pulls/$PR_NUMBER" -f state=closed diff --git a/.github/workflows/close-invalid.yml b/.github/workflows/close-invalid.yml index 4078bd87..b1fa4801 100644 --- a/.github/workflows/close-invalid.yml +++ b/.github/workflows/close-invalid.yml @@ -1,36 +1,40 @@ name: Close issue/PR on adding invalid label -# **What it does**: This action closes issues that are labeled as invalid in the repo. +# **What it does**: This action closes issues and PRs that are labeled as invalid in the repo. on: issues: types: [labeled] - pull_request_target: + pull_request: types: [labeled] -permissions: - contents: read - issues: write - pull-requests: write +permissions: {} jobs: - close-on-adding-invalid-label: - if: - github.repository == 'github/copilot-cli' && github.event.label.name == - 'invalid' + close-issue-on-adding-invalid-label: + if: > + github.repository == 'github/copilot-cli' && + github.event_name == 'issues' && + github.event.label.name == 'invalid' runs-on: ubuntu-latest - + permissions: + issues: write steps: - name: Close issue - if: ${{ github.event_name == 'issues' }} env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - URL: ${{ github.event.issue.html_url }} - run: gh issue close $URL + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GH_REPOSITORY: ${{ github.repository }} + ISSUE_NUMBER: ${{ github.event.issue.number }} + run: gh api -X PATCH "repos/$GH_REPOSITORY/issues/$ISSUE_NUMBER" -f state=closed - - name: Close PR - if: ${{ github.event_name == 'pull_request_target' }} - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - URL: ${{ github.event.pull_request.html_url }} - run: gh pr close $URL + signal-invalid-pr-label: + if: > + github.repository == 'github/copilot-cli' && + github.event_name == 'pull_request' && + github.event.label.name == 'invalid' + runs-on: ubuntu-latest + permissions: + pull-requests: read + steps: + - name: Record invalid PR label signal + run: echo "Invalid label signal for PR #${{ github.event.pull_request.number }}" From 132979e761a234a7061126488c1d4f7e2960c076 Mon Sep 17 00:00:00 2001 From: Michael Recachinas Date: Wed, 12 Aug 2026 09:51:29 -0400 Subject: [PATCH 11/27] Harden invalid PR close dispatcher Bind privileged closure to the trusted workflow identity and exact PR head, and reconcile invalid conflicted PRs from the default branch. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 512eb347-ec89-4250-8bf1-87048974b01d --- .github/workflows/close-invalid-pr-writer.yml | 85 +++++++++++++++---- .github/workflows/close-invalid.yml | 10 ++- 2 files changed, 73 insertions(+), 22 deletions(-) diff --git a/.github/workflows/close-invalid-pr-writer.yml b/.github/workflows/close-invalid-pr-writer.yml index 7cfc6a70..1094d6f4 100644 --- a/.github/workflows/close-invalid-pr-writer.yml +++ b/.github/workflows/close-invalid-pr-writer.yml @@ -4,48 +4,97 @@ on: workflow_run: workflows: [Close issue/PR on adding invalid label] types: [completed] + # pull_request does not run for conflicted PRs, so reconcile from the trusted default branch. + schedule: + - cron: '*/5 * * * *' + workflow_dispatch: -permissions: - issues: read - pull-requests: write +permissions: {} jobs: - close-invalid-pr: + close-invalid-pr-from-workflow-run: if: > github.repository == 'github/copilot-cli' && + github.event_name == 'workflow_run' && github.event.workflow_run.event == 'pull_request' && - github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.repository.full_name == github.repository runs-on: ubuntu-latest + permissions: + actions: read + pull-requests: write + concurrency: + group: close-invalid-pr-${{ github.event.workflow_run.pull_requests[0].number || github.run_id }} + cancel-in-progress: false steps: - name: Close invalid PR env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GH_REPO: ${{ github.repository }} - HEAD_OWNER: ${{ github.event.workflow_run.head_repository.owner.login }} - HEAD_BRANCH: ${{ github.event.workflow_run.head_branch }} - PR_NUMBER: ${{ github.event.workflow_run.pull_requests[0].number }} + WORKFLOW_RUN_ID: ${{ github.event.workflow_run.id }} run: | set -euo pipefail - if [ -z "${PR_NUMBER:-}" ] || [ "$PR_NUMBER" = "null" ]; then - PR_NUMBER="$(gh api --method GET "repos/$GH_REPO/pulls" -f state=open -f head="$HEAD_OWNER:$HEAD_BRANCH" --jq 'if length == 1 then .[0].number else empty end')" + trusted_workflow_id="$(gh api "repos/$GH_REPO/actions/workflows/close-invalid.yml" --jq .id)" + workflow_run="$(gh api "repos/$GH_REPO/actions/runs/$WORKFLOW_RUN_ID")" + + if [ "$(jq -r .workflow_id <<<"$workflow_run")" != "$trusted_workflow_id" ] || + [ "$(jq -r .event <<<"$workflow_run")" != "pull_request" ] || + [ "$(jq -r .repository.full_name <<<"$workflow_run")" != "$GH_REPO" ]; then + echo "Workflow run is not a trusted pull_request run from $GH_REPO; skipping." + exit 0 fi - if [ -z "${PR_NUMBER:-}" ]; then - echo "Unable to identify a single open PR for workflow run; skipping." + if [ "$(jq '.pull_requests | length' <<<"$workflow_run")" -ne 1 ]; then + echo "Workflow run is not associated with exactly one PR; skipping." exit 0 fi - pr_state="$(gh api "repos/$GH_REPO/pulls/$PR_NUMBER" --jq .state)" - if [ "$pr_state" != "open" ]; then - echo "PR #$PR_NUMBER is $pr_state; skipping." + pr_number="$(jq -r .pull_requests[0].number <<<"$workflow_run")" + run_head_sha="$(jq -r .head_sha <<<"$workflow_run")" + run_head_repo="$(jq -r '.head_repository.full_name // empty' <<<"$workflow_run")" + pr="$(gh api "repos/$GH_REPO/pulls/$pr_number")" + + if [ -z "$run_head_repo" ] || + [ "$(jq -r .base.repo.full_name <<<"$pr")" != "$GH_REPO" ] || + [ "$(jq -r '.head.repo.full_name // empty' <<<"$pr")" != "$run_head_repo" ] || + [ "$(jq -r .head.sha <<<"$pr")" != "$run_head_sha" ]; then + echo "PR #$pr_number no longer matches the workflow run head; skipping." exit 0 fi - if ! gh api "repos/$GH_REPO/issues/$PR_NUMBER/labels" --jq '.[].name' | grep -Fxq invalid; then - echo "PR #$PR_NUMBER does not currently have the invalid label; skipping." + if [ "$(jq -r .state <<<"$pr")" != "open" ] || + ! jq -e 'any(.labels[]?; .name == "invalid")' >/dev/null <<<"$pr"; then + echo "PR #$pr_number is not open with the invalid label; skipping." exit 0 fi - gh api -X PATCH "repos/$GH_REPO/pulls/$PR_NUMBER" -f state=closed + gh api -X PATCH "repos/$GH_REPO/pulls/$pr_number" -f state=closed + + reconcile-invalid-prs: + if: > + github.repository == 'github/copilot-cli' && + (github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') + runs-on: ubuntu-latest + permissions: + pull-requests: write + concurrency: + group: close-invalid-pr-reconciliation + cancel-in-progress: false + steps: + - name: Close open PRs with the invalid label + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GH_REPO: ${{ github.repository }} + run: | + set -euo pipefail + + gh api --paginate "repos/$GH_REPO/pulls?state=open&per_page=100" \ + --jq '.[] | select(any(.labels[]?; .name == "invalid")) | .number' | + while read -r pr_number; do + pr="$(gh api "repos/$GH_REPO/pulls/$pr_number")" + + if [ "$(jq -r .state <<<"$pr")" = "open" ] && + jq -e 'any(.labels[]?; .name == "invalid")' >/dev/null <<<"$pr"; then + gh api -X PATCH "repos/$GH_REPO/pulls/$pr_number" -f state=closed + fi + done diff --git a/.github/workflows/close-invalid.yml b/.github/workflows/close-invalid.yml index b1fa4801..18288ff0 100644 --- a/.github/workflows/close-invalid.yml +++ b/.github/workflows/close-invalid.yml @@ -1,6 +1,6 @@ name: Close issue/PR on adding invalid label -# **What it does**: This action closes issues and PRs that are labeled as invalid in the repo. +# **What it does**: This action closes invalid issues and signals invalid PRs to a trusted writer. on: issues: @@ -33,8 +33,10 @@ jobs: github.event_name == 'pull_request' && github.event.label.name == 'invalid' runs-on: ubuntu-latest - permissions: - pull-requests: read + permissions: {} steps: - name: Record invalid PR label signal - run: echo "Invalid label signal for PR #${{ github.event.pull_request.number }}" + env: + PR_NUMBER: ${{ github.event.pull_request.number }} + run: | + echo "Invalid label signal for PR #$PR_NUMBER" From da6329cc64f78f2ea9643e5d4b121f3b2bcfe8a4 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Fri, 14 Aug 2026 02:28:40 +0000 Subject: [PATCH 12/27] Update changelog.md for version 1.0.80 --- changelog.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/changelog.md b/changelog.md index 48f07df8..381986dd 100644 --- a/changelog.md +++ b/changelog.md @@ -1,3 +1,7 @@ +## 1.0.80 - 2026-08-14 + +- Update model configurations + ## 1.0.79 - 2026-08-10 - The /sandbox configuration dialog shows where sandbox settings are stored in settings.json From efb1c23cad3891429bd1447e4ba7cbdbe0ff9ee1 Mon Sep 17 00:00:00 2001 From: Michael Recachinas Date: Fri, 14 Aug 2026 16:39:54 -0400 Subject: [PATCH 13/27] Handle fork PR associations in invalid-label writer Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 512eb347-ec89-4250-8bf1-87048974b01d --- .github/workflows/close-invalid-pr-writer.yml | 62 ++++++++++++++++--- 1 file changed, 55 insertions(+), 7 deletions(-) diff --git a/.github/workflows/close-invalid-pr-writer.yml b/.github/workflows/close-invalid-pr-writer.yml index 1094d6f4..a8f3f98f 100644 --- a/.github/workflows/close-invalid-pr-writer.yml +++ b/.github/workflows/close-invalid-pr-writer.yml @@ -44,19 +44,67 @@ jobs: exit 0 fi - if [ "$(jq '.pull_requests | length' <<<"$workflow_run")" -ne 1 ]; then - echo "Workflow run is not associated with exactly one PR; skipping." + run_head_sha="$(jq -r .head_sha <<<"$workflow_run")" + run_head_repo="$(jq -r '.head_repository.full_name // empty' <<<"$workflow_run")" + run_head_branch="$(jq -r '.head_branch // empty' <<<"$workflow_run")" + + if [ -z "$run_head_repo" ] || + [ -z "$run_head_branch" ] || + [[ ! "$run_head_sha" =~ ^[0-9a-f]{40}$ ]] || + [ "${run_head_repo#*/}" = "$run_head_repo" ] || + [ -z "${run_head_repo%%/*}" ] || + [ -z "${run_head_repo#*/}" ]; then + echo "Workflow run is missing valid head repository, branch, or SHA metadata; skipping." + exit 0 + fi + + pull_request_count="$(jq '.pull_requests | length' <<<"$workflow_run")" + if [ "$pull_request_count" -eq 1 ]; then + pr_number="$(jq -r .pull_requests[0].number <<<"$workflow_run")" + elif [ "$pull_request_count" -eq 0 ]; then + run_head_owner="${run_head_repo%%/*}" + matching_prs="$( + gh api --method GET --paginate "repos/$GH_REPO/pulls" \ + -f state=open \ + -f head="$run_head_owner:$run_head_branch" \ + -f per_page=100 | + jq -cs \ + --arg repo "$GH_REPO" \ + --arg head_repo "$run_head_repo" \ + --arg head_branch "$run_head_branch" \ + --arg head_sha "$run_head_sha" \ + 'add | [ + .[] | + select( + .state == "open" and + .base.repo.full_name == $repo and + .head.repo.full_name == $head_repo and + .head.ref == $head_branch and + .head.sha == $head_sha + ) + ]' + )" + + if [ "$(jq 'length' <<<"$matching_prs")" -ne 1 ]; then + echo "Workflow run could not be uniquely associated with an open PR; skipping." + exit 0 + fi + pr_number="$(jq -r '.[0].number' <<<"$matching_prs")" + else + echo "Workflow run is associated with multiple PRs; skipping." + exit 0 + fi + + if [[ ! "$pr_number" =~ ^[1-9][0-9]*$ ]]; then + echo "Workflow run produced an invalid PR number; skipping." exit 0 fi - pr_number="$(jq -r .pull_requests[0].number <<<"$workflow_run")" - run_head_sha="$(jq -r .head_sha <<<"$workflow_run")" - run_head_repo="$(jq -r '.head_repository.full_name // empty' <<<"$workflow_run")" pr="$(gh api "repos/$GH_REPO/pulls/$pr_number")" - if [ -z "$run_head_repo" ] || - [ "$(jq -r .base.repo.full_name <<<"$pr")" != "$GH_REPO" ] || + if [ "$(jq -r .base.repo.full_name <<<"$pr")" != "$GH_REPO" ] || [ "$(jq -r '.head.repo.full_name // empty' <<<"$pr")" != "$run_head_repo" ] || + [ "$(jq -r .head.ref <<<"$pr")" != "$run_head_branch" ] || [ "$(jq -r .head.sha <<<"$pr")" != "$run_head_sha" ]; then echo "PR #$pr_number no longer matches the workflow run head; skipping." exit 0 From ab097e5b3e75c2da1658385c5d8c970ebabb38c0 Mon Sep 17 00:00:00 2001 From: Derek Legenzoff Date: Tue, 25 Aug 2026 17:19:31 -0700 Subject: [PATCH 14/27] Prepare public prerelease v1.0.81-11 From 4ab8707dbf12f8fc15e8bac2cb5c38d18341b494 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Thu, 27 Aug 2026 17:10:10 +0000 Subject: [PATCH 15/27] Update changelog.md for version 1.0.81 --- changelog.md | 92 ++++++++++++++++++++++++++++++++++++++++++---------- 1 file changed, 75 insertions(+), 17 deletions(-) diff --git a/changelog.md b/changelog.md index 381986dd..14f3c671 100644 --- a/changelog.md +++ b/changelog.md @@ -1,49 +1,107 @@ +## 1.0.81 - 2026-08-27 + +- The plugins dashboard is available to everyone: run `/plugin`, `/mcp`, or `/skills`. Set `PLUGINS_DASHBOARD=false` to opt out of it and the `copilot plugins` command. +- Ship MCP 2026-07-28 support to CLI, SDK, IDE, and in-memory clients +- Hooks can now receive the current OpenTelemetry trace context and emit correlated spans: inputs gain `traceparent` (plus `tracestate` when the span has vendor state); command hooks also get env vars. +- Windows: remote MCP servers protected by Microsoft Entra ID can now sign in through the OS authentication broker (WAM), usually with no prompt at all. Other platforms, `--device-code`, and machines without the broker library keep the existing browser flow. +- Add xhigh reasoning effort support for Grok 4.6 +- Startup now offers to restore sessions that were still open when their CLI went away, so a crash or a machine restart no longer means reopening each terminal by hand +- models.list now includes service-published infoMessages and warningMessages per model +- Add `copilot app` to open the GitHub Copilot app in the current directory +- Add defaultMode and defaultPermissionMode settings to choose startup mode and approval behavior for new interactive sessions +- Add --with-token to copilot login to read an auth token from stdin +- Add support for Gemini 3.7 Flash +- Add Ctrl+E in /sandbox to open settings.json in your editor +- Add per-agent usage metrics to --usage-output-file JSON output +- Repeated read_agent calls now consistently return the full turn history unless since_turn is provided +- Hook lifecycle events (`hook.start`/`hook.end`) from hooks inside a subagent are now recorded on that subagent's session and re-emitted on its parent, instead of being dropped on an internal session. +- Repeatedly resuming the same session no longer crashes while telemetry is being replaced +- An MCP server blocked by an enterprise policy now shows as blocked in /mcp instead of spinning as pending forever +- Fixed an indefinite "Loading…/Resuming…" hang at startup when a repository plugin activates a contributed extension (or another extension reload races the initial load), which previously left the environment stuck on "still waiting on extensions" +- Vim mode badge stays visible beside the activity indicator during turns +- The startup status finishes after extension configuration during plugin reconciliation +- Signing out of an account now clears its cached enterprise managed settings, so signing back in generally re-fetches the policy rather than re-applying the one cached before sign-out +- An enterprise managed-settings policy is no longer rejected when `permissions.disableBypassPermissionsMode` carries an unrecognized value; it is now logged and enforced as `disable`. +- Sandboxed builds on Windows create their scratch caches on first run, so cargo, go, Gradle, and ccache work without a warm cache +- On macOS and Linux, shell commands resolve the same tools a bash login shell does, including project environments activated from a profile +- Canvas windows open and refresh in the background instead of stealing focus from your terminal +- A prompt sent while the agent is working no longer leaves a second copy of itself stuck as `(pending)` at the bottom of the transcript after it has been answered +- Turning allow-all off from an ACP client now reaches the permission engine whenever there is a runtime override or auto-approval to revoke, so the setting can no longer report success while permissions stay enabled (a baseline granted by --allow-all-\* launch flags is still deliberately left intact) +- A failed tool call no longer stacks its `(MCP: server)` label one character per line down the timeline — the label and the error now share the row, with the longer side truncating +- Agents, skills and MCP servers contributed by installed plugins are no longer dropped in non-interactive (-p) runs, so --agent : works headlessly without --plugin-dir +- Typing `$` and pressing Enter opens the interactive shell again, instead of clearing the prompt and doing nothing +- The prompt frame now renders in terminals it previously skipped, such as foot and alacritty, instead of a fixed list +- A prompt queued while the agent is working stays visible instead of vanishing when you send another one +- The sessions sidebar's keyboard cursor is visible again, and selected rows in the Select family, the diff viewer and custom picker rows now pair the selection fill with the text color derived for it. +- Keys sent to an unfocused terminal pane are no longer dropped: Enter and other keystrokes are handled even after a terminal focus-out report, so tmux and agent multiplexers can drive a background pane +- Compact the autopilot goal panel to its identity row on a short terminal (a paused goal keeps its resume note), with ctrl+x → g to expand or collapse it by hand +- Render the autopilot goal panel as a pinned prompt frame, drop its progress bar for the exact todo count, fold the subagent hint into the row it toggles, and keep its metrics on a narrow pane +- Resume large sessions faster by showing recent history first while older messages load. +- `x` is now the delete key everywhere: /sandbox config, /settings, /mcp, the sessions dialog and the diff comments summary move off `d` +- Auto mode now adapts model selection as your task evolves during a conversation +- /plugin now flags installed plugins and marketplaces that have a newer version upstream, and offers an Update action to pull it +- Show your last prompt as the inferred objective in the Autopilot status panel +- When --no-sandbox is ignored because enterprise policy could not be determined, the notice now says so, and no longer points at an administrator, instead of claiming a policy requires the sandbox. The unsupported-host warning says the same rather than contradicting it. +- Show model data retention warnings with links in the /model picker +- Path-sourced plugins in a local (directory-source) marketplace now load live from their real directory, so editing one takes effect on `/restart` or a new session — no `/plugin update` +- Skills and custom agents are discovered from directories added with --add-dir +- Use Ctrl+Space to toggle voice dictation. +- A session sandboxed by an enterprise managed policy now says so on the timeline, including when the policy arrives mid-session, instead of leaving the footer's sandbox chip as the only hint that commands are being restricted +- forceRemoteSettingsRefresh now fails closed: when set, the cached managed-settings policy is never served or used as a fetch-failure fallback (skipping both the 1h fast path and the 24h stale fallback), so a failed startup fetch blocks on the unconfirmed policy instead of reverting to a possibly-stale cached one. Concretely, until a fresh policy is fetched the session applies the restrictive undetermined-policy posture: non-default MCP servers are blocked, bypass-permissions mode cannot be enabled, and policy-gated plugin install/update mutations are blocked +- ACP clients receive subagent IDs, raw event subscriptions, and live title, mode, command, and plan updates +- Show each user instruction file separately in /instructions +- Managed settings now win per entry for enabledPlugins and extraKnownMarketplaces, so a plugin or marketplace your organization pins can't be overridden locally +- Use x to remove scheduled /every and /after prompts in Schedule Manager +- Update model configurations +- Removed the `PLUGINS_DASHBOARD` opt-out and the legacy skills picker it kept alive. `/skills`, bare `/mcp`, and `/mcp show` (with no server name) always open the dashboard; `/mcp config` still opens the dedicated MCP wizard. +- Removed `/plugins`; its resources moved to `/plugin`, `/mcp` and `/skills`, with `/subagents` and `/instructions` for agents and instructions. +- Enabling and disabling hooks and LSP servers is temporarily unavailable: those toggles existed only in the `/plugins` dashboard that this release removes. + ## 1.0.80 - 2026-08-14 - Update model configurations ## 1.0.79 - 2026-08-10 -- The /sandbox configuration dialog shows where sandbox settings are stored in settings.json - Add support for enterprise allow-auto-only policy so /allow-all auto works while full allow-all remains blocked. - Allow enterprise-managed sandbox policy to enforce a proxy URL while credentials remain user-controlled -- A tool directory inside your workspace that is on PATH (.venv/bin, node_modules/.bin, an in-repo GOPATH) no longer turns that part of the workspace read-only in the sandbox -- The /sandbox configuration dialog groups the git, gh, and (on macOS) keychain settings under a new Auth tab, and the settings keys moved from `sandbox.gitAuth`/`sandbox.ghAuth` to `sandbox.auth.git`/`sandbox.auth.gh`. There is no migration: the old keys are ignored in settings files, and SDK requests that still send them are rejected as invalid rather than ignored -- Added a `worktreeBaseRef` setting that controls whether `/worktree`, `/worktree new`, and `--worktree` start from HEAD or the remote default branch. All three now default to HEAD; previously `--worktree` started from the remote default branch. -- Model picker groups models into Recent, Recommended, New, and other sections, and Shift+Tab switches grouping views. -- Large monorepos now use tgrep ([trigram-indexed grep for fast regex search in large codebases](https://github.com/microsoft/tgrep)) instead of ripgrep - Agent Plugins spec plugins can now ship extensions under a com.github.copilot/extensions/ directory - Add support for the kimi-k3 model - Combine `--plan` with `--mode autopilot` to plan first and then implement without waiting for approval +- Manage multiple concurrent sessions from the Sessions tab and sidebar +- Add /sandbox policy to show effective sandbox paths, denials, and network access +- Queue prompts, shell commands, and supported slash commands in local sessions to run in order after the current task finishes +- Set "autoUpdate": true on an extraKnownMarketplaces entry in your user settings to auto-update its plugins at session start +- A tool directory inside your workspace that is on PATH (.venv/bin, node_modules/.bin, an in-repo GOPATH) no longer turns that part of the workspace read-only in the sandbox - The `/app` command now opens the current session in the GitHub Copilot desktop app instead of landing on Home with the wrong folder (requires GitHub Copilot app 1.1.3 or later) - On macOS, a sandbox read-only path nested inside a writable one now stays read-only instead of inheriting the write permission from the wider path - On macOS, sandboxed commands can use UNIX-domain sockets again, so tools that talk over a local IPC pipe (tsx, vite, esbuild, jest workers) no longer fail with `listen EPERM` - Sandboxed commands work when the working directory lives on a Windows Dev Drive - `/theme` now only shows its deprecation notice for a valid color mode, so a mistyped mode no longer suggests an invalid command or hides the notice from your next valid `/theme`. - Sandboxed git now authenticates to Azure DevOps, GitHub Enterprise Server, GitLab, and other non-GitHub remotes you have stored HTTPS credentials for -- Ask user multi-select prompts include an Other option for free-text answers -- Improve teleported subagent /tasks navigation with nested tree browsing, current/all and finished-task filters, and a live timeline you can steer - A rare internal delay no longer prints a diagnostic warning on top of the interactive UI - A failed session-history load no longer leaves the timeline permanently empty: the failure was silently discarded, so the transcript stayed blank for the rest of the session with nothing logged. It is now retried, and reported in the transcript and the log if it still fails - Resuming a long session no longer collapses the timeline's scroll range while history renders in the background: entries that had not finished rendering were published as if they did not exist, so the scrollbar and scroll position jumped until the background render caught up -- Manage multiple concurrent sessions from the Sessions tab and sidebar - Sandboxed wrapper builds (make and friends) get the dev tool caches their recipes need, based on the build manifests in the working directory -- Prompt pinning is off by default; set pinnedPrompts to true to enable it. - Sandboxed commands can reach the network again on recent Windows builds, where every outbound connection was blocked even with outbound access enabled and no proxy configured - Plugin custom agents honor deferred-tool-loading frontmatter -- Use `/worktree new` to start a new session in a new worktree - A sandbox that cannot start an MCP server now fails in seconds instead of stalling the session, and sandbox startup failures for both MCP and language servers now say the sandbox was at fault and how to fix or opt out of it - Login links are clickable during web and device-code sign-in -- Pin the current prompt one row higher, in the row the tab bar already reserves, so it keeps the shape of the prompt it copies while costing the timeline one row less -- Leave the pinned prompt off by default on terminals under 30 rows, where it would crowd the output; set pinnedPrompts explicitly to override at any size - Compute /context attribution against the Auto-resolved model so token totals are accurate for Free/Student users - Disabling an extension no longer breaks elicitation, canvases, or tool permission prompts for other extensions - A prompt stashed with ctrl+s now stays with the session it was typed for, so switching away and back and pressing ctrl+s restores it instead of finding it gone - On Linux, searches and most shell commands blocked by the sandbox now offer to re-run outside it +- The /sandbox configuration dialog shows where sandbox settings are stored in settings.json +- The /sandbox configuration dialog groups the git, gh, and (on macOS) keychain settings under a new Auth tab, and the settings keys moved from `sandbox.gitAuth`/`sandbox.ghAuth` to `sandbox.auth.git`/`sandbox.auth.gh`. There is no migration: the old keys are ignored in settings files, and SDK requests that still send them are rejected as invalid rather than ignored +- Added a `worktreeBaseRef` setting that controls whether `/worktree`, `/worktree new`, and `--worktree` start from HEAD or the remote default branch. All three now default to HEAD; previously `--worktree` started from the remote default branch. +- Model picker groups models into Recent, Recommended, New, and other sections, and Shift+Tab switches grouping views. +- Large monorepos now use tgrep ([trigram-indexed grep for fast regex search in large codebases](https://github.com/microsoft/tgrep)) instead of ripgrep +- Ask user multi-select prompts include an Other option for free-text answers +- Improve teleported subagent /tasks navigation with nested tree browsing, current/all and finished-task filters, and a live timeline you can steer +- Prompt pinning is off by default; set pinnedPrompts to true to enable it. +- Use `/worktree new` to start a new session in a new worktree +- Pin the current prompt one row higher, in the row the tab bar already reserves, so it keeps the shape of the prompt it copies while costing the timeline one row less - BREAKING: the sandbox setting `allowDevToolCaches` is renamed `allowDevToolAccess`, since it grants dev-tool config and registries too, not just caches. The old key is no longer read and is ignored silently, so an existing `false` opt-out reverts to the default (on). Rename it in settings.json and in any managed/MDM policy. -- Add /sandbox policy to show effective sandbox paths, denials, and network access -- Queue prompts, shell commands, and supported slash commands in local sessions to run in order after the current task finishes -- Set "autoUpdate": true on an extraKnownMarketplaces entry in your user settings to auto-update its plugins at session start - /sandbox tags inactive settings as (disabled) and explains why they are locked, and documents dev tool caches in copilot help sandbox - Show "pending · ctrl+c to cancel" for in-flight steering prompts - Make /model session-scoped by default, and use /config model to set defaults for future sessions. @@ -61,7 +119,7 @@ - A run whose prompt is piped over stdin now treats its `sessionEnd` hook the same way `-p` does: the hook fires once per completed agent turn with `reason` `complete` (or `error` if the turn failed), instead of once at shutdown with `user_exit`. As with `-p`, a piped run that exits before completing a turn fires no `sessionEnd` hook - Split-view sidebar: the red close confirmation now reads `x again to close` (or `x again to exit CLI` on the last session) instead of `x close`, so a second press is clearly what closes - Expose token usage in ACP prompt results and live usage_update notifications -- Added a forceRemoteSettingsRefresh managed setting that requires a fresh managed-settings fetch on startup +- Added a forceRemoteSettingsRefresh managed setting that requires a fresh managed-settings fetch on startup; when the setting is in effect and that refresh cannot be confirmed, plugin mutations and read-only marketplace operations alike (including `plugins marketplace` list, browse, and refresh) fail closed rather than proceeding without the server-managed policy - Disabling the sandbox from a bypass prompt applies only to that session; new sessions start sandboxed again - Managed settings now fall back to the persistent cache whenever a server-managed settings fetch fails for any reason (network error, a non-success HTTP status, or a malformed/unparseable response), and fail open — starting without the unconfirmed server restriction rather than the prior fail-closed behavior — when no usable cached policy is available - When the sandbox blocks a shell command and bypass is allowed, CLI offers to re-run it outside the sandbox without asking the model From be82101e70f0253b57519bebb9cc9d0f6dfb2ed2 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Sat, 29 Aug 2026 23:39:32 +0000 Subject: [PATCH 16/27] Update changelog.md for version 1.0.82 --- changelog.md | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/changelog.md b/changelog.md index 14f3c671..4a93ecd1 100644 --- a/changelog.md +++ b/changelog.md @@ -1,3 +1,9 @@ +## 1.0.82 - 2026-08-29 + +- A message typed while /worktree or /move is preparing the worktree no longer breaks the switch into it +- Ctrl+E expands the plan approval card to show the full plan again +- Show the specific authentication failure (such as 401 Bad credentials) instead of only the /login prompt + ## 1.0.81 - 2026-08-27 - The plugins dashboard is available to everyone: run `/plugin`, `/mcp`, or `/skills`. Set `PLUGINS_DASHBOARD=false` to opt out of it and the `copilot plugins` command. From d7ede79b9cbd4a76f64bb4b18a5731c4d008704b Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Fri, 4 Sep 2026 15:38:09 +0000 Subject: [PATCH 17/27] Update changelog.md for version 1.0.83 --- changelog.md | 40 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 40 insertions(+) diff --git a/changelog.md b/changelog.md index 4a93ecd1..cb1d40ed 100644 --- a/changelog.md +++ b/changelog.md @@ -1,3 +1,43 @@ +## 1.0.83 - 2026-09-04 + +- Show running Copilot sessions in the Windows 11 taskbar with live hover status cards +- Add Client ID Metadata Document (CIMD) support for MCP OAuth sign-in +- Custom agents can list several models in `model`, tried in order until one is available to you, and `model-policy: required` keeps model changes on that list +- Adding support for claude-fable-5.1 +- Add Recent, Created, Name, and classic None sorting to the split Sessions sidebar, with the selected order saved across restarts +- Enterprise admins can pin sign-in to approved GitHub organizations with the forceLoginOrgs managed setting +- Add automatic HTTPS proxy mTLS client certificate support for model and web requests +- Detect the herdr terminal multiplexer instead of mistaking it for tmux, so the Kitty keyboard protocol, color scheme following, terminal progress, `/copy` and notifications work in herdr panes +- A session lock that is re-entered on the same thread now fails with a reported error instead of freezing the CLI. +- Kerberos proxy authentication reconnects when the initial challenge answers with `Connection: close` +- Sandboxed `gh` commands now authenticate as the account configured for the repository instead of the Copilot CLI login +- MCP tools remain callable after MCP server restarts +- Sandboxed file tools now read the same developer-tool paths as sandboxed shell commands, including token-bearing registry config such as ~/.npmrc; set sandbox.allowDevToolAccess to false to turn these grants off +- Stopping a timed-out shell command now lets queued messages run and sessions return to idle +- A follow-up prompt typed while autopilot is running no longer disappears from the timeline +- Restart provides clearer update guidance when automatic restart cannot be completed +- MCP servers configured by your agent stay available after built-in sub-agent turns. +- Anthropic sessions continue after temporary fallback instead of failing on invalid thinking signatures +- Long-running sessions on Linux return freed memory to the system instead of holding gigabytes of it +- Enterprise-denied MCP servers can no longer start before the managed allow/deny policy resolves; server startup now waits for the managed-settings fetch instead of racing it +- Host-provided plugin customizations can be read without redundant path permission prompts +- A relative `--add-dir` or `--plugin-dir` path now resolves against the session's working directory under `--resume=` and `--worktree`, instead of the directory the CLI was launched from. Relative values are also resolved after `-C` is applied, so `-C` no longer has to precede either option on the command line +- MCP servers contributed by a plugin are no longer labelled "User" in the MCP dashboard, and a server from a bundled plugin is now shown as built-in and names the plugin it came from. +- The newest line of output stays visible above the input box instead of hiding behind it, except while a prompt is pinned to the top of the transcript +- Exporting a resumed session with --share or --share-gist writes the whole transcript instead of only the latest run +- On macOS and Linux, sandboxed commands can no longer reach services running on your machine. On macOS this also blocks a server the command itself starts on 127.0.0.1, so test suites that bind a local port will fail; turn on Allow local network in /sandbox to reach localhost again. +- Linux sandboxing now needs slirp4netns, nsenter, iptables, ip6tables, iptables-restore and ip6tables-restore on PATH. Install them if sandboxed commands start failing to launch. +- CLI starts without the interrupted-session restore prompt by default. +- Resuming large sessions keeps the input prompt responsive sooner. +- Linux sandboxes now restrict network egress to the configured proxy; proxy mode requires slirp4netns, util-linux 2.35+, iptables, and /dev/net/tun access +- `/mcp config` and the MCP add/edit/authenticate forms now open in the plugins dashboard instead of a separate MCP manager, so closing a form returns to the server list. +- File path autocomplete stays fast in large repositories +- Plugin list commands and /plugin now show bundled built-in plugins. +- Improve sandboxed Bazel and Bazelisk runs by granting required cache and output paths; macOS requires a future Bazel release or additional sandbox capabilities +- The collapsed autopilot goal panel now reads as a single-line pinned prompt, keeping the frame it shares with a pinned prompt instead of compressing into a bare band wedged against the chrome above it +- Improve /sandbox policy by grouping path grants by source and showing detected developer tools +- Remove retired Claude and Gemini models from /model picker results + ## 1.0.82 - 2026-08-29 - A message typed while /worktree or /move is preparing the worktree no longer breaks the switch into it From 34539015812412e4c6c8399efd084027b3e4740e Mon Sep 17 00:00:00 2001 From: devm33 <1682753+devm33@users.noreply.github.com> Date: Tue, 8 Sep 2026 01:25:59 +0000 Subject: [PATCH 18/27] install: report unsupported operating systems Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- install.sh | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/install.sh b/install.sh index b63486dd..f99f63a5 100755 --- a/install.sh +++ b/install.sh @@ -15,7 +15,7 @@ echo "Installing GitHub Copilot CLI..." case "$(uname -s || echo "")" in Darwin*) PLATFORM="darwin" ;; Linux*) PLATFORM="linux" ;; - *) + CYGWIN*|MINGW*|MSYS*) if command -v winget >/dev/null 2>&1; then echo "Windows detected. Installing via winget..." winget install GitHub.Copilot @@ -25,6 +25,7 @@ case "$(uname -s || echo "")" in exit 1 fi ;; + *) echo "Error: Unsupported operating system $(uname -s)" >&2 ; exit 1 ;; esac # Detect architecture From 752496d8c1e5db3ff9e7ff2dc460edc3e86d38c2 Mon Sep 17 00:00:00 2001 From: devm33 <1682753+devm33@users.noreply.github.com> Date: Tue, 8 Sep 2026 01:33:55 +0000 Subject: [PATCH 19/27] install: cache detected operating system Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- install.sh | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/install.sh b/install.sh index f99f63a5..8a135265 100755 --- a/install.sh +++ b/install.sh @@ -12,7 +12,8 @@ set -e echo "Installing GitHub Copilot CLI..." # Detect platform -case "$(uname -s || echo "")" in +OS="$(uname -s || echo "")" +case "$OS" in Darwin*) PLATFORM="darwin" ;; Linux*) PLATFORM="linux" ;; CYGWIN*|MINGW*|MSYS*) @@ -25,7 +26,7 @@ case "$(uname -s || echo "")" in exit 1 fi ;; - *) echo "Error: Unsupported operating system $(uname -s)" >&2 ; exit 1 ;; + *) echo "Error: Unsupported operating system $OS" >&2 ; exit 1 ;; esac # Detect architecture From 6c98eb0bd64f43c068b9fbf7c3187a7a06ed41a3 Mon Sep 17 00:00:00 2001 From: nkasuku <58227175+nkasuku@users.noreply.github.com> Date: Wed, 9 Sep 2026 13:40:28 -0500 Subject: [PATCH 20/27] Revise notice regarding third-party services Updated section on third-party services to clarify access requirements and terms. --- LICENSE.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/LICENSE.md b/LICENSE.md index 49e10861..4826459a 100644 --- a/LICENSE.md +++ b/LICENSE.md @@ -31,5 +31,6 @@ TO THE MAXIMUM EXTENT PERMITTED BY LAW, IN NO EVENT SHALL GITHUB OR ITS LICENSOR 7. Termination This License terminates automatically if you fail to comply with its terms. Upon termination, you must cease all use and distribution of the Software. -8. Notice Regarding GitHub Services (Informational Only) -Use of the Software may require access to GitHub services and is subject to the applicable GitHub Terms of Service and GitHub Copilot terms. This License governs only rights related to the Software and does not grant any rights to access or use GitHub services. +8. Third-Party Services.  +The Software may enable access to or interaction with services provided by GitHub, Microsoft, or other third parties. Access to a service may require a separate account, subscription, license, authorization, or other entitlement. Your use of each service is subject to the terms, agreements, and privacy notices applicable to that service and your relationship with the relevant service provider.   +For example, if you access the Software using a Microsoft 365 account or entitlement, the Microsoft 365 services made available through the Software—including any applicable data-access or AI-inference services—are provided under, and subject to, the Microsoft Product Terms and the agreement under which you or your organization obtained the applicable Microsoft 365 subscription. This License governs only your rights to use the Software and does not grant any right to access or use Microsoft 365 services or other third-party services. From 7ea621658b521884401c71acedc979fd89936fdc Mon Sep 17 00:00:00 2001 From: GitHub Security Bot <88103841+github-security-bot@users.noreply.github.com> Date: Sat, 12 Sep 2026 11:46:35 -0400 Subject: [PATCH 21/27] Merge pull request #4808 from github/pinner/actions-sha-pins-2026-09-10 Pin GitHub Actions to commit SHAs --- .github/dependabot.yml | 8 ++++++++ .github/workflows/close-single-word-issues.yml | 2 +- .github/workflows/no-response.yml | 2 +- .github/workflows/stale-issues.yml | 2 +- 4 files changed, 11 insertions(+), 3 deletions(-) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 00000000..6cc00712 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,8 @@ +version: 2 +updates: + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly" + cooldown: + default-days: 7 diff --git a/.github/workflows/close-single-word-issues.yml b/.github/workflows/close-single-word-issues.yml index f2ef0dae..4a69cff8 100644 --- a/.github/workflows/close-single-word-issues.yml +++ b/.github/workflows/close-single-word-issues.yml @@ -14,7 +14,7 @@ jobs: steps: - name: Close Single-Word Issue - uses: actions/github-script@v7 + uses: actions/github-script@f28e40c7f34bde8b3046d885e986cb6290c5673b # v7.1.0 with: github-token: ${{ secrets.GITHUB_TOKEN }} script: | diff --git a/.github/workflows/no-response.yml b/.github/workflows/no-response.yml index 2a864ddd..79385fe9 100644 --- a/.github/workflows/no-response.yml +++ b/.github/workflows/no-response.yml @@ -13,7 +13,7 @@ jobs: noResponse: runs-on: ubuntu-latest steps: - - uses: actions/stale@v9 + - uses: actions/stale@5bef64f19d7facfb25b37b414482c7164d639639 # v9.1.0 with: repo-token: ${{ secrets.GITHUB_TOKEN }} only-issue-labels: 'more-info-needed' diff --git a/.github/workflows/stale-issues.yml b/.github/workflows/stale-issues.yml index 3ec537c4..6ceed656 100644 --- a/.github/workflows/stale-issues.yml +++ b/.github/workflows/stale-issues.yml @@ -10,7 +10,7 @@ jobs: stale: runs-on: ubuntu-latest steps: - - uses: actions/stale@v9 + - uses: actions/stale@5bef64f19d7facfb25b37b414482c7164d639639 # v9.1.0 with: stale-issue-label: 'stale, triage' # The label that will be added to the issues when automatically marked as stale start-date: '2025-01-01T00:00:00Z' # Skip stale action for issues created before it From a08a6e9612db24dd64ac2c862bf939074f8d57c9 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sat, 12 Sep 2026 22:06:37 -0400 Subject: [PATCH 22/27] build(deps): bump actions/github-script from 7.1.0 to 9.0.0 (#4828) Bumps [actions/github-script](https://github.com/actions/github-script) from 7.1.0 to 9.0.0. - [Release notes](https://github.com/actions/github-script/releases) - [Commits](https://github.com/actions/github-script/compare/f28e40c7f34bde8b3046d885e986cb6290c5673b...3a2844b7e9c422d3c10d287c895573f7108da1b3) --- updated-dependencies: - dependency-name: actions/github-script dependency-version: 9.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/close-single-word-issues.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/close-single-word-issues.yml b/.github/workflows/close-single-word-issues.yml index 4a69cff8..559d67db 100644 --- a/.github/workflows/close-single-word-issues.yml +++ b/.github/workflows/close-single-word-issues.yml @@ -14,7 +14,7 @@ jobs: steps: - name: Close Single-Word Issue - uses: actions/github-script@f28e40c7f34bde8b3046d885e986cb6290c5673b # v7.1.0 + uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: github-token: ${{ secrets.GITHUB_TOKEN }} script: | From b49df25cafe802d2012876c8703332064237c7e3 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sat, 12 Sep 2026 22:07:59 -0400 Subject: [PATCH 23/27] build(deps): bump actions/stale from 9.1.0 to 11.0.0 (#4827) Bumps [actions/stale](https://github.com/actions/stale) from 9.1.0 to 11.0.0. - [Release notes](https://github.com/actions/stale/releases) - [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/stale/compare/5bef64f19d7facfb25b37b414482c7164d639639...4391f3da665fdf50b6810c1a66712fb9ba21aa93) --- updated-dependencies: - dependency-name: actions/stale dependency-version: 11.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/no-response.yml | 2 +- .github/workflows/stale-issues.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/no-response.yml b/.github/workflows/no-response.yml index 79385fe9..7d257a5a 100644 --- a/.github/workflows/no-response.yml +++ b/.github/workflows/no-response.yml @@ -13,7 +13,7 @@ jobs: noResponse: runs-on: ubuntu-latest steps: - - uses: actions/stale@5bef64f19d7facfb25b37b414482c7164d639639 # v9.1.0 + - uses: actions/stale@4391f3da665fdf50b6810c1a66712fb9ba21aa93 # v11.0.0 with: repo-token: ${{ secrets.GITHUB_TOKEN }} only-issue-labels: 'more-info-needed' diff --git a/.github/workflows/stale-issues.yml b/.github/workflows/stale-issues.yml index 6ceed656..b3b9793d 100644 --- a/.github/workflows/stale-issues.yml +++ b/.github/workflows/stale-issues.yml @@ -10,7 +10,7 @@ jobs: stale: runs-on: ubuntu-latest steps: - - uses: actions/stale@5bef64f19d7facfb25b37b414482c7164d639639 # v9.1.0 + - uses: actions/stale@4391f3da665fdf50b6810c1a66712fb9ba21aa93 # v11.0.0 with: stale-issue-label: 'stale, triage' # The label that will be added to the issues when automatically marked as stale start-date: '2025-01-01T00:00:00Z' # Skip stale action for issues created before it From ab6139c694ba09ab4e8ac76b6046daa6b5d89616 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Wed, 16 Sep 2026 02:44:46 +0000 Subject: [PATCH 24/27] Update changelog.md for version 1.0.85 --- changelog.md | 115 +++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 115 insertions(+) diff --git a/changelog.md b/changelog.md index cb1d40ed..a985aaef 100644 --- a/changelog.md +++ b/changelog.md @@ -1,3 +1,118 @@ +## 1.0.85 - 2026-09-16 + +- Vim mode is now available to everyone. Turn it on with `/vim` or by setting `editorMode` to `vim` for modal editing in the composer, with the current mode shown while you type. +- Add /settings options to opt in to context management tools for agents and subagents +- Set transcriptView to "concise" to group tool activity into expandable work summaries. +- Add /config to open a sidebar configuration screen in the CLI +- Add /sandbox Network host allow/deny rules without replacing your configured upstream proxy +- Add session and memory import commands for the semantic JSONL interchange format +- Add `copilot instruction list` and `copilot lsp list`, replacing `copilot plugins list --kind instruction` and `--kind lsp` +- Add `--json` to `copilot plugin list`, `copilot plugin marketplace list` and `copilot plugin marketplace browse` +- Add `enable` and `disable` to `copilot plugin`, `copilot mcp` and `copilot skill`, replacing `copilot plugins enable/disable --plugin|--mcp|--skill` +- Add support for GPT-6 Astra +- Managed sandbox sessions can now be disabled for the rest of the session from an approved bypass prompt. +- --add-dir rejects non-directory and inaccessible paths uniformly and aborts startup before session initialization +- Streamer mode masks internal model names in /model, the footer, and startup diagnostics without restarting model initialization on toggles +- Fixed the one-command sandbox bypass on Windows: when the sandbox container refuses a policy-blocked write for want of a privilege, approving the bypass now runs the command instead of stopping after the permissive retry, so it no longer takes disabling the sandbox for the whole session +- Respect terminal color themes even when palettes are incomplete +- Failed new-session handoffs stop unused clients from polling and preserve the current session, schedules, and unsent prompt. +- Earlier messages remain visible when switching back to a background session with frequent hooks. +- End and Ctrl+E move the cursor to the true end of a wrapped line, so typing or Ctrl+K no longer edits one character early inside a long word or URL. On such a line the landing spot is the wrap boundary, so pressing End or Ctrl+E again advances to the end of the next visual row +- `--share=~/notes.md` now writes the exported session to your home directory instead of creating a folder named `~` in the current directory +- Modified chords such as Ctrl+X, Alt+X or capital X no longer trigger the /tasks letter shortcuts; only unmodified a, f, x, r, b, j and k respond. Enter, Escape, the arrow keys and Ctrl+G / Ctrl+P / Ctrl+N are unaffected +- Scheduled prompts show an error when they fail at runtime +- CLI retries image prompts without images when providers reject image-limit requests +- Authenticated model lists refresh after startup auth hydration +- MCP servers no longer fail to load when the CLI is connected to a running IDE. The in-process IDE bridge was rejected by config validation, which failed the plugin reload and restricted the session +- `copilot init` now removes the `.github` directory it created when the run exits without writing an instructions file. +- MCP turns continue even if tool list refresh fails after a tool change +- MCP servers keep correct workspace source labels after trusting a folder +- An editor or shell that leaves mouse tracking on no longer leaves your terminal reporting clicks, during the session or after the CLI exits +- The /permissions picker marks Allow all when --allow-all-tools, --allow-all-paths and --allow-all-urls are all set +- Resumed sessions show completed reasoning as Thought instead of Thinking… +- copilot --help describes the --no-\* options again, and --no-auto-update says it runs the version bundled in the binary. --no-auto-login and --no-sandbox stay supported but remain hidden from help, as they were before the clap port +- Restore keyboard input and screen output on macOS and Linux when you return from an external editor that reset the terminal +- Model lists refresh after signing in, switching accounts, or signing out +- Fixed the thinking shape sent to Claude models classified as adaptive-only: they now stay adaptive instead of failing (turning thinking off lowers reasoning effort instead), and reasoning effort is capped at high whenever thinking is disabled +- Run sessionEnd hooks when /clear closes an interactive session +- Plugin agents expand ${PLUGIN_ROOT} placeholders in mcp-servers frontmatter +- Skills from directories added with --add-dir are no longer missing when a skills load races the directory registration +- A relative `--additional-mcp-config @` path now resolves against the session working directory under `--resume=` and `--worktree` instead of the launch directory, and `~/` expands. +- Windows sandbox denials of loopback and local network access prompt to re-run the command outside the sandbox +- Approved sandbox retries are labeled sandbox relaxed while network policy stays enforced, or sandbox bypassed when fully unsandboxed; failed bypasses explain that host permissions still apply +- Cancelling an MCP tool call now notifies the MCP server and cleanly ends the turn. +- Scrolling the wheel with mouse capture off no longer walks backwards through prompt history in terminals that report DEC private mode 1007 (alternate scroll), such as Ghostty +- MCP OAuth requests additional scopes when needed and retries the tool call +- Changing reasoning effort now takes effect before the next logical request in an active turn, while retries keep their original effort +- Automatic compaction now saves a checkpoint that appears in /session checkpoints +- Windows CLI artifacts run without requiring the Visual C++ Redistributable +- Keep terminal theme colors consistent at startup and during live appearance changes +- Interactive mode submits startup prompts even when model discovery is still loading. +- MCP tools with boolean property or array-item schemas work with Gemini instead of causing a 400 error +- An enterprise-managed sandbox policy delivered by MDM or a managed settings file no longer discards sandbox.allowBypass, so bypass prompts and /sandbox disable work as the policy intends +- The managed sandbox startup notice no longer says sandboxing can't be turned off when your organization's policy allows a session opt-out; it names /sandbox disable instead +- Viewing or attaching an image in a format the model cannot read, such as BMP or TIFF, no longer leaves the session unable to send any further message; the image is now reported as an unsupported format that you can convert to PNG, JPEG, WebP or GIF +- The YOLO status indicator reflects the active session after switching sessions +- Computer Use now stays in sync across /computer and whole-plugin /plugin toggles. +- Pressing Enter in the Sessions tab now foregrounds the highlighted session, even when a background refresh rebuilds the list at that moment, instead of sometimes opening a different session +- Indexed search on Windows prevents new disk-space leaks when updating indexes +- Keep long /ask responses visible after generation completes +- When session history is truncated or compacted just as a turn finishes, the "Working" indicator now clears instead of staying up for the rest of the session +- COPILOT_ALLOW_ALL no longer refuses to start the CLI on values such as 1, 0, yes or an empty string, and falsey values now disable automatic tool approval instead of enabling it +- Subagent launches honor explicit model, reasoning effort, and context tier preferences from applicable global and custom instructions +- A failed command whose EPERM or EACCES diagnostic names a sandbox-blocked path now offers to run outside the sandbox, even when the command line never named that path +- A write blocked by a read-only sandbox path, and a Node or Go network failure blocked by the sandbox, are now recognized as sandbox denials instead of surfacing as raw errors +- Report in-memory MCP servers as memory instead of local in copilot mcp list +- /compact no longer reports an empty model response when a valid summary was returned +- Streaming responses preserve message chunk ordering before final output. +- Retry responses keep the correct streamed message and reasoning after mid-stream model failures +- Workspace .mcp.json servers load correctly after trusting a folder on startup +- When image-heavy requests exceed model limits, user-provided images are prioritized over tool-generated images, newer messages are kept first, and the CLI reports any removals. +- Plugin-contributed agents discovered by the CLI can now be selected and run. +- Fixed same-turn MCP tool-list refresh after received change notifications, including modern subscription-based servers. +- The remote session timeline entry now advertises ctrl+o to show or hide the QR code, matching the key that actually toggles it +- Show when sandboxing is only enabled for the current session in /sandbox status and settings. +- Interactive --yolo startup remains available before authentication when no managed policy evidence is present +- Indexed search shows when enabled, works on Windows ReFS volumes, supports explicit cloud-sync overrides, and keeps refreshing on Linux when native file watches are exhausted. +- /copy includes task completion messages when available +- OAuth-authenticated MCP servers connect reliably during session startup +- `ctrl+h` no longer deletes a whole word in tmux, screen, and remote sessions that carry a Windows Terminal `WT_SESSION` from elsewhere. As an accepted tradeoff, `ctrl+backspace` now deletes a single character in those sessions — including a genuinely local Windows tmux or screen pane — where `ctrl+w` still deletes a word +- MCP servers now see the same copilot-cli client identity when you add a server and when a session connects, carrying the shipped CLI version instead of 0.0.0 +- Interactive mode starts and submits the initial prompt when using --auth-token-env +- Use /settings taskbarPresence false to disable Windows taskbar session status. Loader-managed sessions restart immediately; standalone sessions require a manual restart. +- Pressing Escape once cancels MCP inference approval prompts once +- MCP reload summary shows servers still starting after timeout +- Initial prompts start immediately for Entra-authenticated sessions while token refresh runs in the background. +- Choosing approve-for-location now persists tool approval to avoid repeat prompts +- Large sessions resume without freezing the interface during context token counting +- Configured hooks keep running after an extension restarts instead of silently stopping and later denying every tool call; the extension's own callback hooks resume once it re-registers +- The `allowManagedHooksOnly` policy now also blocks extension-registered `preToolUse`, `postToolUse` and `postToolUseFailure` callbacks, which previously bypassed the managed-only lockdown that every other hook event already applied +- A PowerShell write the sandbox blocks offers to run the command outside the sandbox +- When you have more than one GitHub account in your credential store, a sandboxed gh command now acts as the account gh is logged in as instead of an arbitrary one. +- The `/rubber-duck` command is hidden after a model refresh removes its compatible critic +- Sandboxed runs now use relocated developer-tool caches from env vars and tool config files +- On Windows, a sandboxed command that runs git without naming it — a hook, a build tool, or an npm install that clones over HTTPS — no longer dies inside the credential helper's MSYS2 shell. +- Reduce metadata scanning time for large local session histories, with increased thread and memory use +- Pause and resume Agent Factory runs from the /factories dialog +- Apply managed Edit and Write rules to recognized native shell redirections and supported in-place sed operations +- Show active scheduled prompts in the CLI footer by default +- Use /worktree, /move, and --worktree without enabling experimental mode +- Make /collect-debug-logs and --collect-debug-logs available to all users +- /sandbox disable turns the sandbox off for the current session when your organization's policy allows bypass +- Shell completions are generated from the same grammar the CLI parses with, so `copilot ` offers root flags alongside subcommands and each subcommand offers only its own options +- Command-line parsing moved from Commander to a Rust grammar; error and help wording changed, `copilot login --host` now works, and `--max-autopilot-continues` no longer accepts scientific notation +- Show /sandbox filesystem paths as absolute paths; typing ~/path still expands to your home directory +- Move the /sandbox Filesystem paths into their own list, opened from a Paths row +- Show trust status, tier, and eligibility details for online resource catalogue results +- /usage shows per-model AI Credit consumption in usage breakdowns +- Improve /sandbox guidance and show /sandbox policy in command help +- On supported Windows sandbox policies, interactive shell commands now record blocked accesses. One approved escalation retries with file and process restrictions recording instead of blocking while network policy remains active, then falls back to the disclosed full bypass only if still blocked +- Speed up startup when resuming an existing local session by its exact UUID with `--resume` +- Replace `copilot plugins install --skill [--scope project]` with `copilot skill add [--project]`; the `--scope` spelling is gone +- Remove the cross-kind `--kind`, `--scope`, `--mcp` and `--skill` flags from `copilot plugins`; use `copilot mcp` and `copilot skill` +- `copilot plugins list --json` now emits a flat array of plugins instead of the cross-kind `{ plugins, errors }` object; scripts reading `.plugins` must be updated +- `copilot plugins list` is now an alias of `copilot plugin list` and reports only plugins, no longer MCP servers, skills, instructions or LSP servers + ## 1.0.83 - 2026-09-04 - Show running Copilot sessions in the Windows 11 taskbar with live hover status cards From d418dbf1061152afa17500cbc69478f8dce153d8 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Thu, 17 Sep 2026 22:57:48 +0000 Subject: [PATCH 25/27] Update changelog.md for version 1.0.86 --- changelog.md | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/changelog.md b/changelog.md index a985aaef..65334fa8 100644 --- a/changelog.md +++ b/changelog.md @@ -1,3 +1,13 @@ +## 1.0.86 - 2026-09-17 + +- Custom agents can opt into repository instruction files (AGENTS.md, copilot-instructions.md, CLAUDE.md) by setting `include-custom-instructions: true` in their frontmatter. +- Resuming an active session without plugin-directory, discovery, or working-directory overrides preserves marketplace plugins and skills after reload. Configuration read or validation failures no longer discard active plugins; missing-file and intentional-removal behavior is unchanged. +- /sandbox policy now reports local-network access using your configured setting +- The status row now says it is waiting for background shells, instead of "Working", when a turn ends while an attached background shell such as a dev server is still running. +- Resume sessions even when transcript files contain recoverable corruption +- Expanded reasoning text in the compact timeline is no longer dimmed, so it is as readable as the rest of the timeline. +- Autopilot stops after accepted task completion instead of continuing unexpectedly + ## 1.0.85 - 2026-09-16 - Vim mode is now available to everyone. Turn it on with `/vim` or by setting `editorMode` to `vim` for modal editing in the composer, with the current mode shown while you type. From c13b3dcae4f1e176c5a074c0d063a6e9f258081f Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Mon, 21 Sep 2026 15:31:10 +0000 Subject: [PATCH 26/27] Update changelog.md for version 1.0.87 --- changelog.md | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) diff --git a/changelog.md b/changelog.md index 65334fa8..143cbe68 100644 --- a/changelog.md +++ b/changelog.md @@ -1,3 +1,31 @@ +## 1.0.87 - 2026-09-21 + +- Add user and managed startup defaults for the Auto routing tier, including strict and user-overridable organization policy +- Consecutive steering prompts in the same mode combine into one pending message. Press Up in an empty chat input to take it back for editing, including pasted text and attachments. The recall hint appears in the pending message. Ctrl+C stops the running turn instead of removing pending prompts one at a time. Ctrl+Q queued prompts remain separate. Use Ctrl+P to browse history without withdrawing prompts. Available for local sessions; commands and prompts already being processed cannot be recalled. +- A `worktreePathTemplate` setting decides where `/worktree`, `/move`, `/new` and `--worktree` create worktrees. Set for example `~/src/worktrees/{repo}/{branch}`; `{repoPath}`, `{repo}`, `{branch}` and `{branchSlug}` are supported. Unset keeps the current layout, `.worktrees/` with slashes in the branch name flattened to dashes. +- Number-key selection in the question dialog works for choices 10 and beyond +- Sandbox proxies work on Windows, and a proxy with a username and password works on every platform +- `/keep-alive` (and `/caffeinate`) no longer reports that sleep is prevented when the sleep inhibitor exits immediately on startup instead of acquiring the lock (e.g. no session bus on WSL/containers/headless); it now reports the failure. +- Prompt mode exits successfully when a child task fails but the parent recovers. +- Resume very large local sessions and continue with new prompts reliably. +- Keep --yolo enabled after startup policy checks for authenticated unmanaged sessions +- Empty strictKnownMarketplaces allowlists now hide and block built-in plugin marketplaces. +- Mouse-selected text is visibly highlighted in /help and /mcp show screens +- Tear down the processes an internal git command started when it times out, so a slow repository status check no longer leaves them running and consuming memory. +- MCP auth status warnings stay accurate during reconnects and startup refreshes +- Pull request badge and GitHub status tabs remain available after auth or branch refreshes +- A failing MCP server no longer removes other servers' tools +- `copilot mcp list` and `copilot mcp get` now report the built-in `github-mcp-server` when you are signed in, instead of showing it only in the interactive `/mcp` view +- MCP servers that advertise list-change capabilities but do not implement subscriptions now connect instead of failing +- Extension permission handlers approve subagent tool requests without leaving duplicate CLI prompts +- Secrets exported in the launching shell are no longer written to debug logs when a session is created or resumed +- Managed plugin commands load organization marketplace policy with environment, GitHub CLI, broker, and persisted authentication +- Session resume no longer hangs while reconnecting MCP servers +- Configure per-server MCP slow-connection warning thresholds with slowConnectionThresholdMs +- Show live elapsed time for execution subagents in timeline entries +- Enable the rubber-duck agent for every model family and for low-cost-tier session models +- Reduce allocation overhead when repainting blank terminal areas. + ## 1.0.86 - 2026-09-17 - Custom agents can opt into repository instruction files (AGENTS.md, copilot-instructions.md, CLAUDE.md) by setting `include-custom-instructions: true` in their frontmatter. From 57dd2440141be0b7d6d628472890f861e3b3ca55 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Tue, 22 Sep 2026 20:00:59 +0000 Subject: [PATCH 27/27] Update changelog.md for version 1.0.88 --- changelog.md | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) diff --git a/changelog.md b/changelog.md index 143cbe68..8feb4e4d 100644 --- a/changelog.md +++ b/changelog.md @@ -1,3 +1,31 @@ +## 1.0.88 - 2026-09-22 + +- Add optional OSC 777 terminal notifications for direct Ghostty and WezTerm sessions. +- Text selection now works in bottom-anchored dialogs, including login device codes +- Preserve /allow-all during managed-settings refresh failures, and remember exact session approvals for missing paths without granting their parent directory; exact grants are visible in /list-dirs and cleared by /reset-allowed-tools +- Sandboxed network denials from proxy tunnel failures now show bypass guidance +- Custom-agent startup now distinguishes model-list load failures from an empty catalog, preventing false unavailable warnings and silent required-agent deselection +- Pressing Enter in freeform ask_user prompts adds a new line; submit with Ctrl+Enter or Ctrl+S as a fallback +- A custom agent's `reasoning-effort` now applies when the agent is selected, instead of only its model. An explicit `--reasoning-effort` still wins, and a level the selected model does not offer is reported and left unapplied +- Deferred MCP tools whose registered name needed sanitizing or shortening are now listed under that name, so tool search can find them, and deferred MCP tools with no resolvable server name are now listed with the other tools instead of being left out of the reminder +- Prompt mode now warns when it stops waiting for background tasks and explains how to change the timeout limit. +- Resuming sessions no longer stalls when MCP permission prompts are pending +- MCP tools recover more reliably from transient listing, connection, and OAuth failures +- Hook commands without an explicit `cwd` again run in the project root instead of the session's current directory, so repo-relative hook scripts still resolve from a subdirectory. +- Enterprise managed settings now apply to sessions opened in ACP mode (`copilot --acp`), by AHP hosts (`copilot --ahp-host`), and by the published `--server` session, which previously ran with no managed MCP, permission, or plugin policy. +- GitHub MCP scope escalation now uses the CLI OAuth app's registered /callback redirect URI +- Agents from a plugin mounted with --plugin-dir now appear in server-mode sessions +- Session and subagent start hooks combine successful additional-context contributions within the hook-output limit +- Cached MCP tools stay scoped to environment-resolved server addresses and headers +- Session resume preserves pending conversation events when saving fails and explains that retrying is safe +- Support namespaced custom skills and ignored skill directories during skill discovery +- MCP and plugin views show server display names and plugin descriptions for clearer status. +- Resuming large local sessions keeps transcript memory bounded for smoother CLI performance. +- Prompt to update GitHub authorization when Connectors need reauthorization +- Indexed search supports glob filtering and --files listings with accurate ripgrep fallback behavior. +- Run /fork during active turns to branch work without waiting. +- In the Sessions tab, rows you can dismiss now take x then x again to confirm: a local session is permanently deleted, while a session backed by a server is only closed and its conversation is left on the server. The footer says which of the two the highlighted row will do, and shows no x hint for rows that cannot be dismissed. + ## 1.0.87 - 2026-09-21 - Add user and managed startup defaults for the Auto routing tier, including strict and user-overridable organization policy