Releases: github/copilot-sdk
Release list
v1.0.17-preview.3
Feature: replace session tools mid-session (experimental)
A live session's client-supplied tools and handlers can now be replaced in a single call without recreating the session. Built-in, MCP, and plugin tools are unaffected; pass an empty list to remove all of this client's tools. (ef04633)
- TypeScript:
await session.setTools([tool]) - C#:
await session.SetToolsAsync(tools) - Python:
await session.set_tools([tool]) - Go:
session.SetTools(ctx, tools) - Java:
session.setTools(tools).get() - Rust:
session.set_tools([tool]).await?
Other changes
- improvement: update the bundled Copilot CLI version to 1.0.92-3 and regenerate RPC and session event types across all SDKs (ef04633)
Warning
Firewall blocked 2 domains
The following domains were blocked by the firewall during workflow execution:
api.github.comgithub.com
[!TIP]
api.github.com is blocked because GitHub API access uses the built-in GitHub tools by default. Instead of adding api.github.com to network.allowed, use tools.github.mode: gh-proxy for direct pre-authenticated GitHub CLI access without requiring network access to api.github.com:
tools:
github:
mode: gh-proxySee GitHub Tools for more information on gh-proxy mode.
To allow these domains, add them to the network.allowed list in your workflow frontmatter:
network:
allowed:
- defaults
- "api.github.com"
- "github.com"See Network Configuration for more information.
Generated by Release Notes Generator · copilot · auto · 26.9 AIC · ⌖ 5.65 AIC · ⊞ 10.4K
v1.0.17-preview.2
Other changes
- improvement: [C#] add a custom session event JSON converter and updated generated session event types for Copilot CLI 1.0.92-2 (5b2d7cd)
- improvement: update the bundled Copilot CLI version to 1.0.92-2
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
github.com
To allow these domains, add them to the network.allowed list in your workflow frontmatter:
network:
allowed:
- defaults
- "github.com"See Network Configuration for more information.
Generated by Release Notes Generator · copilot · auto · 17.5 AIC · ⌖ 6.05 AIC · ⊞ 10.4K
v1.0.17-preview.1
v1.0.16
Internal dependency updates only: this release refreshes the SDK snapshot for Copilot CLI 1.0.90. It contains no other user-visible SDK changes since v1.0.15.
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
github.com
To allow these domains, add them to the network.allowed list in your workflow frontmatter:
network:
allowed:
- defaults
- "github.com"See Network Configuration for more information.
Generated by Release Notes Generator · copilot · auto · 18.8 AIC · ⌖ 6.11 AIC · ⊞ 10.3K
v1.0.16-preview.0
Internal dependency updates only (SDK snapshot updated for Copilot CLI 1.0.90-6).
Full Changelog: runtime-1.0.89-1.unstable.r36638597907.ge270afd...v1.0.16-preview.0
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
github.com
To allow these domains, add them to the network.allowed list in your workflow frontmatter:
network:
allowed:
- defaults
- "github.com"See Network Configuration for more information.
Generated by Release Notes Generator · copilot · auto · 23.7 AIC · ⌖ 5.81 AIC · ⊞ 10.3K
Runtime 1.0.89-1.unstable.r36793206303.g13aa136
Public unstable runtime 1.0.89-1.unstable.r36793206303.g13aa136
Source: 13aa1367b75fcbaed5e732b92c113b78b9d598a9
Visibility: public
Runtime 1.0.89-1.unstable.r36638597907.ge270afd
Public unstable runtime 1.0.89-1.unstable.r36638597907.ge270afd
Source: e270afdf61628e26a24a8d9fb7b387cfb4ac7b5b
Visibility: public
v1.0.15
Feature: typed structured outputs for all six SDKs
Provide a JSON Schema, or use an idiomatic typed helper, to have the model return typed, validated output instead of free-form text. (#2590)
const answerSchema = z.object({ value: z.number().int() });
const answer = await session.sendAndWait("What is 19 + 23?", answerSchema);answer = await session.send_and_wait_typed("What is 19 + 23?", Answer)Go, Java, C#, and Rust get the same capability via copilot.SendAndWait[Answer], session.sendAndWait(prompt, Answer.class), SendAndWaitAsync<Answer>, and session.send_and_wait_typed(prompt).
Feature: structured JSON-RPC error data in all SDKs
The raw JSON data payload of a JSON-RPC error response can now be inspected in every SDK, so apps can branch on machine-readable error details. (#2664, #2732)
if let Some(data) = error.rpc_data() { println!("{data}"); }catch (JsonRpcException e) { JsonNode data = e.getData(); }Feature: experimental connection-global installation confirmation
All six SDKs expose a connection-global handler for the runtime's installations.confirm callback, letting apps present a human review before an MCP or Skill installation proceeds. The handler must return an explicit confirm/decline/cancel decision.
const client = new CopilotClient({
installationConfirmationHandler: async (request, context) => promptUser(request),
});Java, Python, Rust, C#, and Go get equivalent options (setInstallationConfirmationHandler, installation_confirmation_handler, with_installation_confirmation_handler, InstallationConfirmationHandler). Java also now exposes typed unions for MCP installation review payloads.
Other changes
- feature: [Java] add native runtime support for
darwin-x64(#2701) - feature: [Java] add native runtime support for
linuxmusl-x64(Alpine) (#2715) - feature: [Java] experimental
FusionCriticgenerated diagnostics type - improvement: [Node/Python/Go/.NET/Java] coalesce intercepted HTTP response chunks for better tool-call streaming throughput (#2734)
- improvement: [Rust] coalesce intercepted HTTP response chunks (#2717)
- improvement: [Rust] avoid rebuilding and copying JSON payloads (#2711)
- improvement: [Rust] cut retained runtime-install memory by ~99% (#2676)
- improvement: [.NET] avoid redundant JSON event materialization and reduce allocations (#2733)
- improvement: [Node] pin production dependencies to exact versions with a publish-age policy (#2700)
- bugfix: preserve image replay compatibility across CLI image limits (#2670)
New contributors
@mohamedmansourmade their first contribution in #2676@roblourensmade their first contribution in #2700
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
github.com
To allow these domains, add them to the network.allowed list in your workflow frontmatter:
network:
allowed:
- defaults
- "github.com"See Network Configuration for more information.
Generated by Release Notes Generator · copilot · auto · 17.1 AIC · ⌖ 6.46 AIC · ⊞ 9K
v1.0.15-preview.4
Feature: experimental connection-global installation confirmation
All six SDKs now expose a connection-global handler for the runtime's installations.confirm callback, letting apps present a human review before an MCP or Skill installation proceeds. The handler receives the generated request plus a cancellation signal that fires when the review is retired or the connection closes, and must return an explicit confirm/decline/cancel decision — the SDK never infers approval.
const client = new CopilotClient({
installationConfirmationHandler: async (request, context) => {
return await promptUser(request); // "confirm" | "decline" | "cancel"
},
});var options = new CopilotClientOptions
{
InstallationConfirmationHandler = async (request, context) =>
await PromptUserAsync(request, context.CancellationToken),
};opts := copilot.ClientOptions{
InstallationConfirmationHandler: func(ctx context.Context, req *copilot.InstallationConfirmationRequest) (copilot.InstallationConfirmationDecision, error) {
return promptUser(ctx, req)
},
}Java, Python, and Rust get the equivalent setInstallationConfirmationHandler(...), installation_confirmation_handler, and with_installation_confirmation_handler options. Java additionally converts the previously untyped MCP installation/removal review payloads (InstallationConfirmationRequest.review(), McpInstallPlan.transportChoices(), McpInstallationManagementResultOutcome.getOutcome()) into sealed/typed unions, bringing it into line with the other SDKs.
Other changes
- feature: [Java] experimental
FusionCriticgenerated diagnostics type for execution-phase model/reasoning-effort tracking
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
github.com
To allow these domains, add them to the network.allowed list in your workflow frontmatter:
network:
allowed:
- defaults
- "github.com"See Network Configuration for more information.
Generated by Release Notes Generator · copilot · auto · 169.2 AIC · ⌖ 5.87 AIC · ⊞ 9K
v1.0.15-preview.3
Feature: structured JSON-RPC error data in Go, .NET, and Java
Go, .NET, and Java can now inspect the raw JSON data payload of a JSON-RPC error response instead of only its code and message. This mirrors capabilities already available in TypeScript, Python, and Rust, letting apps branch on machine-readable error details. (#2732)
var rpcErr *copilot.RPCError
if errors.As(err, &rpcErr) {
fmt.Printf("RPC error %d: %s\n", rpcErr.Code, rpcErr.Message)
}catch (IOException ex) when (ex.InnerException is RemoteRpcException remote)
{
Console.Error.WriteLine($"RPC error {remote.ErrorCode}: {remote.Message}");
}catch (JsonRpcException e) {
JsonNode data = e.getData();
}Omitted data and explicit JSON null remain distinguishable in all three APIs, and existing error identity, wrapping, and formatting behavior are unchanged.
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
github.com
To allow these domains, add them to the network.allowed list in your workflow frontmatter:
network:
allowed:
- defaults
- "github.com"See Network Configuration for more information.
Generated by Release Notes Generator · copilot · auto · 163.2 AIC · ⌖ 6.41 AIC · ⊞ 9K