Live
Microsoft‑Decision‑1 Arrives on Foundry: What Engineers Need to KnowIntegrating Production Feedback into the AI Agent Lifecycle: Practical Architecture and Ops GuidanceOpenTelemetry tracing expands across Cloudflare’s proxy stack in betaDynamic Model Triage: Engineering Implications of Grok Bot’s Multi‑Model BackendAccess Cloudflare Skills Directly Through the API MCP ServerCodeQL 2.27.2 expands language models and tightens macOS build support – what engineers need to knowTangible Certification: Turning a Kubernetes Badge into a Gold NecklaceGoogle Data Cloud GA updates: agent‑centric tooling, hybrid Spanner, and expanded Lakehouse catalogMicrosoft‑Decision‑1 Arrives on Foundry: What Engineers Need to KnowIntegrating Production Feedback into the AI Agent Lifecycle: Practical Architecture and Ops GuidanceOpenTelemetry tracing expands across Cloudflare’s proxy stack in betaDynamic Model Triage: Engineering Implications of Grok Bot’s Multi‑Model BackendAccess Cloudflare Skills Directly Through the API MCP ServerCodeQL 2.27.2 expands language models and tightens macOS build support – what engineers need to knowTangible Certification: Turning a Kubernetes Badge into a Gold NecklaceGoogle Data Cloud GA updates: agent‑centric tooling, hybrid Spanner, and expanded Lakehouse catalog
GitHub

Local Sandboxing and Multi‑Account Support Arrive in GitHub Copilot CLI, App, and VS Code

AI SummaryPowered by AI

GitHub Copilot now ships local sandboxing for agents across the CLI, desktop app, and VS Code, adds Claude Haiku 5.5 to all paid tiers, and lets the Copilot app use a different GitHub account for licensing versus repository access. These changes give engineers tighter control over code‑generation agents, simplify model selection, and reduce storage overhead, which directly impacts security posture and operational efficiency.

GitHub Copilot has introduced three notable updates: a generally available local sandbox for agents across the CLI, desktop app, and VS Code; the ability for the Copilot app to separate the GitHub account used for licensing from the account used to access repositories; and a new model‑discovery command in the CLI that surfaces both local Ollama models and cloud‑provided models. Together these changes tighten control over code‑generation agents, simplify model selection, and give operators tools to manage storage consumption.

Local Sandboxing for Agent Isolation

The sandbox limits an agent’s ability to read files, open network connections, and retrieve credentials. It is now the default in the Copilot CLI, the Copilot desktop application, and VS Code sessions that use the Agent Host. Because the feature is included at no extra cost, teams can enable it without budgeting for additional licenses. The practical implication is a reduced attack surface for any code‑generation process that runs on developer machines or CI runners, helping security engineers meet data‑handling policies.

Multi‑Account Licensing in the Copilot App

The Copilot app now supports distinct GitHub accounts for the Copilot subscription and for repository access. For example, an organization can provision a corporate Copilot license while developers continue to work from their personal or project‑specific accounts. This decoupling simplifies compliance with corporate licensing policies and avoids the need to grant repository‑level permissions to the account that holds the license.

CLI Model Discovery and Local Ollama Integration

Within the Copilot CLI, the /model command lists all available models, including those served by a local Ollama instance and the cloud models provided by GitHub Copilot. This eliminates the need to leave the terminal to check model availability, streamlining the workflow for AI engineers who experiment with on‑premise models alongside the hosted offering.

VS Code Session Management Improvements

The 1.141 release adds an Agents window that can display multiple agent sessions side‑by‑side in a grid, making it easier to compare outputs or run concurrent tasks. A new "Open worktree cleanup" option in chat reveals the disk usage of inactive session worktrees and lets users delete them selectively, directly addressing storage bloat on developer machines.

Related CloudNinjas coverage: AI engineering.

What This Means For Practitioners

Teams should enable local sandboxing wherever Copilot agents run to enforce isolation of file and network access. Review licensing configurations to ensure the appropriate account is used for billing versus repository access. Use the /model command to inventory local and cloud models, and benchmark any on‑premise model before adopting it in production pipelines. Finally, monitor VS Code worktree usage and schedule regular clean‑up to keep developer environments lean. By incorporating these steps, engineers can maintain tighter security controls, reduce operational friction, and better align Copilot usage with organizational policies.

Originally published atGitHub Changelog