Copilot CLI 1.0.93
Update3 days agoUnverifiedAdded Oct 10, 2026
2026-10-07 Add enterprise permissions.limitTo to enforce managed domain boundaries for network requests Run safe /user commands immediately during active turns, reject unsafe remote commands during active turns without opening dialogs, and queue commands advertised by relay hosts Plugin skill commands stay available after reloading enabled plugins Sandbox...
Topics: LLMs, MCP, Security, Data integration, Observability
More GitHub Copilot releases
Every GitHub Copilot releaseClaude Haiku 5.5 in GitHub Copilot
Claude Haiku 5.5, Anthropic’s newest lightweight model, is now generally available in GitHub Copilot. It is designed for fast, high-volume work like subagents, quick edits, and terminal tasks. In early testing, Haiku 5.5 matched Claude Sonnet 5 on many coding tasks while using significantly fewer tokens and steps.
Purpose-built model for leaked secret detection
Secret protection should keep pace with the way you build software, whether you write code yourself or work with an AI agent. With our new purpose-built model, we’re bringing context-aware detection into more developer workflows to help you catch secrets before they’re exposed.
Local sandboxing for GitHub Copilot now generally available
Local sandboxing for GitHub Copilot is now generally available in GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host. Local sandboxes give developers a secure execution boundary for agentic workflows on their own machines.
Discover local models in GitHub Copilot CLI
GitHub Copilot CLI makes it easier to choose a local model without leaving your existing workflow. Starting in CLI version 1.0.94-0, use /model to discover supported models from a running local Ollama instance, alongside your configured models and cloud models provided by GitHub Copilot. Discovery doesn’t automatically add models.
Copilot CLI 1.0.94
2026-10-08 Add Claude Haiku 5.5 to model selection and --model completions copilot mcp add recovers cleanly after interrupted MCP config initialization MCP enable/disable now works before server discovery without starting MCP servers Assisted permissions send visible shell code to the permission judge instead of requiring unnecessary manual approval Show a...
Copilot code review: New organization billing options and controls
This release adds new billing and license controls for Copilot code review admins: Billing: Organization owners can bill Copilot code reviews from members with a Copilot license to the organization’s cost center instead of using up those members’ Copilot quotas.
Update your IDE to restore agent activity in Copilot usage metrics
If your Copilot usage metrics have shown agent activity or agent lines of code falling while Copilot usage kept growing, we’ve found the cause, and a fix is rolling out to each IDE. Several IDEs recently moved Copilot agent sessions to the Copilot SDK.
Copilot CLI 1.0.95
2026-10-09 Use native Microsoft Entra broker authentication on macOS when available, with browser fallback. copilot config supports sandbox credential injectHosts keys, with key completion in Bash, Zsh, and Fish.
Also shipped on Oct 7, 2026
GitHub in October 2026The microVM sandbox type is now Generally Available (GA) with GKE Sandbox in clusters that run version...
The microVM sandbox type is now Generally Available (GA) with GKE Sandbox in clusters that run version 1.37.0-gke.4713000 and later. MicroVM sandboxes provide hardware virtualization and isolation for untrusted workloads, AI agent runtimes, and multi-tenant environments.
SSH for Cloud Run services and instances is in Preview
SSH for Cloud Run services and instances is in Preview . Use this feature to establish a secure, interactive shell connection to your running instances.
Set credit usage limits and alerts for your workspace
Workspace admins and owners on paid plans can now set usage limits and alerts that keep shared credits under control. Set a credit threshold for the whole workspace, a project, a member, or, on Business and Enterprise plans, a group or an access token, and choose what happens when usage reaches it: an email or in-app alert, or a block that stops building or...
Faster inline text edits
Simple text changes you make with Edit text inline in the preview toolbar now apply in a few seconds. Text that your app builds from data or translates still takes a little longer.
Gemini 3.7 Flash is deprecated for your app's AI features
Google is retiring Gemini 3.7 Flash ( google/gemini-3.7-flash ), so it is now marked deprecated for your app's AI features and stops working on January 28, 2027. Apps that use it keep working until then, and Lovable no longer picks it for new AI features.
The Cost Analysis tab of the Billing page now includes Serverless Inference Live Usage, which lists the...
The Cost Analysis tab of the Billing page now includes Serverless Inference Live Usage, which lists the estimated cost and token counts of your Serverless Inference requests by model and model access key, for both teams and organizations. …