megachangelog
Announcement

Local sandboxing for GitHub Copilot now generally available

GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.

Local sandboxing for GitHub Copilot is now generally available in GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host.

Local sandboxes give developers a secure execution boundary for agentic workflows on their own machines. Tools and commands initiated by Copilot run with restricted access to the filesystem, network, credentials, and other system capabilities, based on policies defined by the developer or their organization.

Local sandboxing is powered by Microsoft eXecution Container (MXC), which translates a common sandbox policy into native operating-system controls across Windows, macOS, and Linux.

With local sandboxing, developers and organizations can:

  • Limit the files and directories that agent-run commands can read or modify.
  • Control access to the internet, local networks, Git credentials, and GitHub CLI credentials.
  • Apply sandboxing to local tools and services, including local MCP and language servers where supported.
  • Use enterprise-managed settings to require sandboxing and enforce policies that developers cannot weaken.
  • Adopt more autonomous agent workflows while maintaining clear boundaries around what Copilot can access.

Model execution and tool isolation are separate concerns. Sandbox policies apply to tool execution regardless of which model Copilot uses.

Local sandboxing is included with GitHub Copilot at no additional cost. To get started, see About cloud and local sandboxes for GitHub Copilot.

The post Local sandboxing for GitHub Copilot now generally available appeared first on The GitHub Blog.

copilotaisecuritysandboxvscode

Source: original entry ↗

More from GitHub

Follow GitHub to get its new changes in your feed and email digest.

Announcement

Claude Haiku 5.5 now available in GitHub Copilot

Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.

copilotaimodelsannouncement
Feature

Purpose-built model for leaked secret detection

GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.

securitysecret-detectionaiprotection
Feature1.0.94-0

Discover local models in GitHub Copilot CLI

GitHub Copilot CLI version 1.0.94-0 adds the /model command to discover and select supported local models without leaving your existing workflow.

copilotclilocal-modelsai
See all GitHub changes →