GitHub has introduced a new flag in enterprise‑managed settings that lets admins turn on automatic updates for specific plugin marketplaces. By adding autoUpdate: true to an extraKnownMarketplaces entry, supported clients will periodically poll the marketplace and refresh any installed plugins sourced from it. This change removes the need for manual version bumps of custom plugins across Copilot Business, Copilot Enterprise, the CLI, and Visual Studio Code, which directly affects engineers responsible for keeping toolchains current.
autoUpdate plugin marketplaces – new configuration option
The only required change is to modify the enterprise‑managed settings JSON. An entry in the extraKnownMarketplaces array now accepts an autoUpdate boolean. When set to true, the client automatically checks the marketplace and applies updates to plugins that originated there. The marketplace must already be allowed by the strictKnownMarketplaces allowlist, so the existing approval workflow remains unchanged.
{
"extraKnownMarketplaces": [
{
"url": "https://my.custom.marketplace",
"autoUpdate": true
}
]
}
Operational impact
From an operations perspective, the auto‑update feature shifts the responsibility for plugin version management from a manual process to the client runtime. Teams can expect fewer tickets related to outdated or mismatched plugin versions, and the cadence of updates will align with the client’s built‑in check schedule. However, the automatic nature means that any breaking change published to the marketplace will propagate without explicit approval, so monitoring the marketplace release notes remains advisable.
Security and compliance considerations
Because the marketplace must already be on the strictKnownMarketplaces allowlist, the auto‑update path does not broaden the attack surface beyond what is already permitted. Nevertheless, organizations should verify that the marketplace’s update process follows their internal security review cadence, as automatic updates could introduce new code without a dedicated review step. Auditing the extraKnownMarketplaces configuration and correlating it with change‑management logs can provide visibility into when and how plugins are refreshed.
Related CloudNinjas coverage: AI engineering.
What This Means For Practitioners
Evaluate the plugin marketplaces you currently rely on and decide whether automatic updates align with your release governance. If you enable autoUpdate, establish monitoring for marketplace releases and incorporate the update events into your observability stack. Finally, confirm that the marketplace remains listed in strictKnownMarketplaces to avoid unintended exposure.

