- Sources: primary, discussion
- Summary: GitHub added local sandboxing to the Copilot app, bounding filesystem, network, and git and GitHub CLI credential access per project. When the operating system cannot enforce the requested policy the app errors out rather than running unsandboxed. The feature is off by default, in public preview, and does not cover cloud or remote-host sessions.
- Why it matters: Failing closed on an unenforceable policy is the behaviour agent sandboxes have generally lacked, though the default-off preview scope limits who gets it today.
- Follow-up: Track whether sandboxing becomes the default, and whether cloud and remote-host sessions gain equivalent enforcement.
send feedback on this story