Skip to content
worth noting Tools and apps

GitHub Copilot app adds local sandboxing in public preview

clearly official source

The GitHub Copilot app offers optional local sandboxing in public preview, which restricts the agent's access to files, network, and credentials. It is disabled by default and configured per project.

GitHub has added a local sandboxing feature to the GitHub Copilot app, now in public preview. According to the company, the feature limits the potential impact of unintended commands by restricting access to files, network resources, and credentials on the user's machine. It is configured per project, for sessions working with a local repository and working tree.

Sandboxing is disabled by default. It is enabled in the app settings via the "Sandbox new sessions" option in the "Sandbox" section for the given project, with the change affecting new sessions, not already running ones. For an active local session, sandboxing can be turned on with the /sandbox on command, which only modifies that session without changing the project's default setting. If the operating system is unable to enforce the requested policy, the sandboxed shell will, according to the company, fail with an error rather than run unprotected.

Local sandboxing does not apply to cloud sandbox sessions or sessions running on a remote host — sandbox settings for the GitHub Copilot app and Copilot CLI are configured separately. The effective policy may be stricter if the organization's enterprise-managed settings apply.

What changed

Why it matters

For developers working with the agentic features of the GitHub Copilot app, this is a tool to reduce the risk of the agent unintentionally accessing sensitive files, the network, or stored credentials when running commands. For companies deploying Copilot across teams, the feature adds a control point that can be enforced more strictly via enterprise-managed settings than an individual developer would set up.

Two audiences, two different impacts

What this means

01

For individuals

Developers using the GitHub Copilot app can restrict the agent's access to files, network, and credentials for an entire project, or just for the current session using the /sandbox on command.

What to do In the GitHub Copilot app settings, enable the "Sandbox new sessions" option for projects where the agent works with sensitive files or credentials, or use /sandbox on for a one-off session.
More practical updates →
02

For a business

Companies deploying the GitHub Copilot app gain a control point over the agent's access to files, network, and credentials when running commands, which can be enforced more strictly across projects via enterprise-managed settings than an individual developer would choose.

Risks and compliance
What to decide Verify whether the enterprise-managed settings for GitHub Copilot enforce local sandboxing for teams working with sensitive repositories, and set it as the default policy if needed.
More business impacts →
aplikace security GitHub Copilot IDE sandboxing

Check the original

Event sources

clearly official source · 1 publisher, 0 independent. We count feeds from the same owner only once.

1
GitHub Copilot Changelog primary source · first detected Local sandboxing in the GitHub Copilot app