Releases: github/copilot-cli
Releases · github/copilot-cli
Release list
1.0.79-2
Improved
- Pin the current prompt one row higher, in the row the tab bar already reserves, so it keeps the shape of the prompt it copies while costing the timeline one row less
- Leave the pinned prompt off by default on terminals under 30 rows, where it would crowd the output; set pinnedPrompts explicitly to override at any size
Fixed
- A sandbox that cannot start an MCP server now fails in seconds instead of stalling the session, and sandbox startup failures for both MCP and language servers now say the sandbox was at fault and how to fix or opt out of it
- Login links are clickable during web and device-code sign-in
1.0.79-1
Improved
- BREAKING: the sandbox setting
allowDevToolCachesis renamedallowDevToolAccess, since it grants dev-tool config and registries too, not just caches. The old key is no longer read and is ignored silently, so an existingfalseopt-out reverts to the default (on). Rename it in settings.json and in any managed/MDM policy.
Fixed
- Compute /context attribution against the Auto-resolved model so token totals are accurate for Free/Student users
- Disabling an extension no longer breaks elicitation, canvases, or tool permission prompts for other extensions
- A prompt stashed with ctrl+s now stays with the session it was typed for, so switching away and back and pressing ctrl+s restores it instead of finding it gone
- On Linux, searches and most shell commands blocked by the sandbox now offer to re-run outside it
1.0.78
2026-08-03
- Timeline headers show how long each tool call took, right-aligned and ticking live while it runs (for calls of at least 5 seconds). On by default — disable with
/settings showToolDurations. - First-party plugins automatically update to the latest version at session start
- Add the experimental /new-worktree command to create a new worktree and start a new conversation in it
- Copilot login now defaults to the browser flow for local desktop subprocesses without a TTY, including IDE integrations, while remote and headless environments continue using device code
- Interactive shell shortcut now launches on Enter and shows an inline hint when "$" is armed
- Extension slash commands run their handler exactly once per invocation when several extensions are loaded
- Inline images no longer render with their first row repeated down the whole picture after the timeline scrolls
- A run whose prompt is piped over stdin now treats its
sessionEndhook the same way-pdoes: the hook fires once per completed agent turn withreasoncomplete(orerrorif the turn failed), instead of once at shutdown withuser_exit. As with-p, a piped run that exits before completing a turn fires nosessionEndhook - Split-view sidebar: the red close confirmation now reads
x again to close(orx again to exit CLIon the last session) instead ofx close, so a second press is clearly what closes - Expose token usage in ACP prompt results and live usage_update notifications
- Added a forceRemoteSettingsRefresh managed setting that requires a fresh managed-settings fetch on startup
- Disabling the sandbox from a bypass prompt applies only to that session; new sessions start sandboxed again
- Managed settings now fall back to the persistent cache whenever a server-managed settings fetch fails for any reason (network error, a non-success HTTP status, or a malformed/unparseable response), and fail open — starting without the unconfirmed server restriction rather than the prior fail-closed behavior — when no usable cached policy is available
- When the sandbox blocks a shell command and bypass is allowed, CLI offers to re-run it outside the sandbox without asking the model
- /rewind no longer requires git and restores only the files Copilot changed, skipping any file whose contents no longer match what Copilot last wrote, with a conversation-only or conversation + files choice
- Add /permissions to switch between approval modes.
- ACP mode supports closing sessions with the closeSession request.
- Ctrl+Q now enqueues the highlighted mid-text skill completion instead of the partial token
- Switching sessions no longer restarts MCP servers or rebuilds hook state, so a turn running in another session is never halted with a stale-hook error
- Refresh deferred MCP tools after OAuth authentication
- New sandbox setting
allowDevToolCaches(on by default): grants sandboxed builds access to toolchain caches, registries, and installs so builds work without extra setup. Set false to opt out. - Honor explicit GitHub MCP toolset/tool config: keep gh-overlap tools and stop steering to the gh CLI when you opt in
- Warn on startup about unknown top-level keys in user settings.json (e.g. a misspelled setting) instead of silently ignoring them
- Shell completion for --model now suggests auto and supported model names
- Render long session transcripts progressively to keep scrolling responsive
- Resuming a long session is dramatically faster and far lighter on memory, because its history is now read once at startup (in parallel, across CPU cores) instead of being re-read in full for every check the CLI runs before it can paint. In our benchmark a 230MB, 74k-event transcript came back in well under a second instead of about ten, at roughly a quarter of the peak memory; the exact gain depends on your machine's core count and disk
- The /allow-all auto safety-judge model is no longer user-configurable; the judge model is now selected automatically.
1.0.78-3
Added
- Add the experimental /new-worktree command to create a new worktree and start a new conversation in it
Improved
- Interactive shell shortcut now launches on Enter and shows an inline hint when "$" is armed
Fixed
- Copilot login now defaults to the browser flow for local desktop subprocesses without a TTY, including IDE integrations, while remote and headless environments continue using device code
1.0.78-2
Improved
- Split-view sidebar: the red close confirmation now reads
x again to close(orx again to exit CLIon the last session) instead ofx close, so a second press is clearly what closes
Fixed
- Extension slash commands run their handler exactly once per invocation when several extensions are loaded
- Inline images no longer render with their first row repeated down the whole picture after the timeline scrolls
- A run whose prompt is piped over stdin now treats its
sessionEndhook the same way-pdoes: the hook fires once per completed agent turn withreasoncomplete(orerrorif the turn failed), instead of once at shutdown withuser_exit. As with-p, a piped run that exits before completing a turn fires nosessionEndhook
1.0.78-0
Added
- Add /permissions to switch between approval modes.
- ACP mode supports closing sessions with the closeSession request.
Improved
- New sandbox setting
allowDevToolCaches(on by default): grants sandboxed builds access to toolchain caches, registries, and installs so builds work without extra setup. Set false to opt out. - Honor explicit GitHub MCP toolset/tool config: keep gh-overlap tools and stop steering to the gh CLI when you opt in
- Warn on startup about unknown top-level keys in user settings.json (e.g. a misspelled setting) instead of silently ignoring them
- Shell completion for --model now suggests auto and supported model names
- Render long session transcripts progressively to keep scrolling responsive
- Resuming a long session is dramatically faster and far lighter on memory, because its history is now read once at startup (in parallel, across CPU cores) instead of being re-read in full for every check the CLI runs before it can paint. In our benchmark a 230MB, 74k-event transcript came back in well under a second instead of about ten, at roughly a quarter of the peak memory; the exact gain depends on your machine's core count and disk
Fixed
- Ctrl+Q now enqueues the highlighted mid-text skill completion instead of the partial token
- Switching sessions no longer restarts MCP servers or rebuilds hook state, so a turn running in another session is never halted with a stale-hook error
- Refresh deferred MCP tools after OAuth authentication
Removed
- The /allow-all auto safety-judge model is no longer user-configurable; the judge model is now selected automatically.
1.0.77
2026-07-30
- Unconditional autopilot approval now disables sandbox for the current session when bypass is allowed
- Ctrl+G opens your editor to edit ask_user freeform answers without closing the prompt
- Add a browser-based (web) OAuth login flow, now the default for
copilot loginon local interactive terminals (device code remains the default on remote/headless terminals). Use--web-flow/--device-codeto force a mode, or pick one in the interactive/logincommand - Support enforcing managed sandbox policy via macOS and Windows native MDM settings
- Allow reasoning effort to be omitted so the server can select the default
1.0.77-0
Added
- Add a browser-based (web) OAuth login flow, now the default for
copilot loginon local interactive terminals (device code remains the default on remote/headless terminals). Use--web-flow/--device-codeto force a mode, or pick one in the interactive/logincommand - Support enforcing managed sandbox policy via macOS and Windows native MDM settings
Improved
- Allow reasoning effort to be omitted so the server can select the default
1.0.76
2026-07-29
- Add enable/disable controls in /plugins for plugins, instructions, agents, LSP servers, and hooks
- Add support for the grok-4.5 model
- Sandbox denied paths are enforced for relative and symlinked entries on macOS and Linux (Windows cannot deny per path)
- Unsent prompt text now stays with the session it was typed for (for the rest of the CLI session) instead of following you to the session you switch to
- Resuming a session now restores its autopilot or plan mode instead of reverting to interactive, so the autopilot-only
task_completetool stays available and the mode matches the session you left - URL permission prompts now keep their sandbox-bypass warning and the model's reason when a host integration rebuilds the prompt, so an elevated fetch is no longer shown as an ordinary one
- When an update is auto-downloaded, the notification suggests /restart and drops the warning color
- /diff scrolls and syntax-highlights large multi-file diffs faster
- Split-view sidebar: hover-to-focus is now off by default (opt in with
sidebar.hoverFocus), the active session card is accented by default (opt out withsidebar.accentActiveSession), and the closed-stateopen sidebarhint always renders in the neutral hint color web_fetchnow follows HTTP redirects instead of failing, asking permission for the redirect target when it is on a different origin and showing where the redirect came from- Add a directable queue manager (staff) to reorder, edit, remove, repeat, and immediately send queued messages
- New Sessions sidebar for managing multiple concurrent sessions: switch between them, spawn new ones, and see their status at a glance. Turn it on with experimental mode (
/experimental on). - Enterprise administrators can enforce a restrictive sandbox floor: managed settings tighten (but never loosen) the user's sandbox policy, and the
/sandboxdialog surfaces the org-configured managed values with locked fields and managed filesystem paths so admins can confirm what is enforced. - Sessions no longer fail every turn with "Holder terminated during creation" after a subagent finishes
- Startup tips only suggest /init in repositories that don't already have Copilot instructions
- A
userPromptSubmittedhook returning a non-string value formodifiedPrompt,modifiedTransformedPrompt, or a handledresponseContentno longer corrupts the session; the value is ignored, a type-only warning naming the field is logged, an empty-string replacement is rejected instead of blanking the model-facing content, a hook that setshandledwithout a usableresponseContentis now diagnosed instead of silently falling through to the model, and anulladditionalContextis treated as absent instead of being injected as the literal textnull; hook output is also bounded at 10 MiB per invocation, so an HTTP or command hook returning an unbounded response can no longer exhaust memory or leave an oversized session behind - Show recent shell output for large commands that write to a file
- The /instructions picker now respects --no-custom-instructions.
- Render inline images in Rio terminals that support Kitty graphics
- Sandboxed searches now offer an immediate bypass prompt and avoid duplicate bypass prompts.
- Voice mode pauses playing media before recording and resumes it afterward, where supported (macOS and Windows)
- Show the number of active scheduled prompts in the footer
- Add /limits predict to suggest a session AI-credit limit from similar sessions.
- Add configurable timed refreshes for custom status-line commands
- Queued messages list no longer shows a blank row or inflated count, and Ctrl+C removes your own newest queued message
- Changing the
mousesetting mid-session now takes effect immediately, from both/settings mouse on|offand the/settingsdialog, instead of being saved but ignored until the CLI restarted - web_fetch routes through the configured sandbox proxy when outbound is allowed, and denies egress when network.allowOutbound is false (a proxy no longer overrides the user's outbound policy); when a proxied fetch fails it warns that curl/wget share the same proxy, and suggests requestSandboxBypass only when the sandbox proxy itself is unreachable
- Improve subagent delegation for small tasks and parallel work
- Queue mid-turn /model changes and apply them after the current response finishes
- Restore the early warning when unreclaimable system and tool context nears the limit, before automatic compaction is blocked
- Session working directory no longer reverts to the original checkout shortly after
/worktreeswitches into a new worktree - MCP tools load faster from definition-scoped snapshots, with process-wide and per-server cache opt-outs.
- Autopilot stays selected after task_complete by default; set stayInAutopilot to false to return to interactive mode after each task
1.0.76-5
Added
- Add enable/disable controls in /plugins for plugins, instructions, agents, LSP servers, and hooks
- Add support for the grok-4.5 model