GitHub Copilot app adds local sandboxing in public preview
The GitHub Copilot app offers optional local sandboxing in public preview, which restricts the agent's access to files, network, and credentials. It is disabled by default and configured per project.
GitHub has added a local sandboxing feature to the GitHub Copilot app, now in public preview. According to the company, the feature limits the potential impact of unintended commands by restricting access to files, network resources, and credentials on the user's machine. It is configured per project, for sessions working with a local repository and working tree.
Sandboxing is disabled by default. It is enabled in the app settings via the "Sandbox new sessions" option in the "Sandbox" section for the given project, with the change affecting new sessions, not already running ones. For an active local session, sandboxing can be turned on with the /sandbox on command, which only modifies that session without changing the project's default setting. If the operating system is unable to enforce the requested policy, the sandboxed shell will, according to the company, fail with an error rather than run unprotected.
Local sandboxing does not apply to cloud sandbox sessions or sessions running on a remote host — sandbox settings for the GitHub Copilot app and Copilot CLI are configured separately. The effective policy may be stricter if the organization's enterprise-managed settings apply.
Why it matters
For developers working with the agentic features of the GitHub Copilot app, this is a tool to reduce the risk of the agent unintentionally accessing sensitive files, the network, or stored credentials when running commands. For companies deploying Copilot across teams, the feature adds a control point that can be enforced more strictly via enterprise-managed settings than an individual developer would set up.
Two audiences, two different impacts
What this means
For individuals
Developers using the GitHub Copilot app can restrict the agent's access to files, network, and credentials for an entire project, or just for the current session using the /sandbox on command.
For a business
Companies deploying the GitHub Copilot app gain a control point over the agent's access to files, network, and credentials when running commands, which can be enforced more strictly across projects via enterprise-managed settings than an individual developer would choose.
Risks and complianceCheck the original
Event sources
clearly official source · 1 publisher, 0 independent. We count feeds from the same owner only once.