Skip to content
Proposals/Upgrade Copilot CLI to v1.0.92 and grant sandbox
proposalteamP5High impactGCGitHub Copilot CLI

Upgrade Copilot CLI to v1.0.92 and grant sandbox GITHUB_TOKEN explicitly

Copilot CLI v1.0.92 withholds ambient GITHUB_TOKEN in sandboxed shells, adds copilot config list/read/set/remove, and a Ctrl+E local-vs-cloud picker. Upgrade, list settings, and grant the token only for sandboxes that need GitHub access.

Why this loop

v1.0.92 changes default sandbox credentials: sandboxed shells no longer inherit ambient GITHUB_TOKEN unless you configure it. That blocks accidental token leakage and will break GitHub API or git-over-HTTPS flows that previously worked by inheritance. Use the new copilot config list/read/set/remove subcommands to inspect and pin settings instead of editing files by hand. Point copilot sandbox ca at the same directory with --config-dir (and -C when you change the working tree) so per-repo CA setup matches the session. Press Ctrl+E before a conversation to pick local vs cloud and avoid mixed environments. MCP is more reliable: Entra-protected servers silently renew access-token-only credentials, idle Streamable HTTP sessions reconnect, and legacy HTTP+SSE POSTs honor the server timeout instead of hanging. After upgrade, grant GITHUB_TOKEN only where sandboxed GitHub access is required.

Proposed actions

  1. Upgrade GitHub Copilot CLI to v1.0.92 from https://github.com/github/copilot-cli/releases/tag/v1.0.92, then run copilot config list and paste the output into the team agent runbook.
  2. For every Copilot CLI sandbox that must call GitHub, explicitly configure GITHUB_TOKEN for that sandbox; do not rely on the ambient environment—v1.0.92 withholds it unless granted.
  3. Before starting a Copilot CLI conversation, press Ctrl+E and select local or cloud so the session does not mix environments.
  4. Run sandbox CA setup against your real config directory: copilot sandbox ca --config-dir <path-to-copilot-config> (add -C <repo> when the working tree is not the current directory).
  5. Reconnect Entra-protected and Streamable HTTP MCP servers after idle expiry; v1.0.92 silently renews access-token-only Entra credentials and bounds HTTP+SSE POST acknowledgements to the server timeout.

Agent prompt

Paste into your agent or query via MCP (get_agent_prompt) — free, no extra AI cost

AGENTS.md / CLAUDE.md / GEMINI.md rule update

DevAgentRadar → Repo Harness Rule Patch

Goal: update our repository's permanent harness instructions based on this release.

Update the file that tool actually reads. Do not dump everything into one file.

  • Claude Code → CLAUDE.md plus .claude/ (skills, hooks, settings, agents, commands). It does not read AGENTS.md natively; start CLAUDE.md with @AGENTS.md.
  • Codex, Copilot, Cursor, Factory Droid, Grok Build, Roo Code, Goose, OpenCode, Amp, Zed, Aider → AGENTS.md.
  • Gemini CLI / Antigravity → GEMINI.md. AGENTS.md only if context.fileName is set.
  • Cursor glob-scoped rules → .cursor/rules/*.mdc (plain .md is ignored), not a second constitution.
  • Codex MCP → .codex/config.toml, not .mcp.json.
  • Copilot extra instructions → .github/copilot-instructions.md; custom agents → .github/agents/.
  • Windsurf → .windsurf/rules (do not assume AGENTS.md).
  • Cline → .clinerules.
  • Procedures → a skill (SKILL.md). Enforcement the model must not skip → a hook. Isolated roles → subagents.
  • Do not fork the same rule into three tool files.

Context

Assistant: GitHub Copilot CLI Proposal: Upgrade Copilot CLI to v1.0.92 and grant sandbox GITHUB_TOKEN explicitly Summary: Copilot CLI v1.0.92 withholds ambient GITHUB_TOKEN in sandboxed shells, adds copilot config list/read/set/remove, and a Ctrl+E local-vs-cloud picker. Upgrade, list settings, and grant the token only for sandboxes that need GitHub access. Primary source: https://github.com/github/copilot-cli/releases/tag/v1.0.92

Why it matters

v1.0.92 changes default sandbox credentials: sandboxed shells no longer inherit ambient GITHUB_TOKEN unless you configure it. That blocks accidental token leakage and will break GitHub API or git-over-HTTPS flows that previously worked by inheritance. Use the new copilot config list/read/set/remove subcommands to inspect and pin settings instead of editing files by hand. Point copilot sandbox ca at the same directory with --config-dir (and -C when you change the working tree) so per-repo CA setup matches the session. Press Ctrl+E before a conversation to pick local vs cloud and avoid mixed environments. MCP is more reliable: Entra-protected servers silently renew access-token-only credentials, idle Streamable HTTP sessions reconnect, and legacy HTTP+SSE POSTs honor the server timeout instead of hanging. After upgrade, grant GITHUB_TOKEN only where sandboxed GitHub access is required.

Suggested actions

  1. Upgrade GitHub Copilot CLI to v1.0.92 from https://github.com/github/copilot-cli/releases/tag/v1.0.92, then run copilot config list and paste the output into the team agent runbook.
  2. For every Copilot CLI sandbox that must call GitHub, explicitly configure GITHUB_TOKEN for that sandbox; do not rely on the ambient environment—v1.0.92 withholds it unless granted.
  3. Before starting a Copilot CLI conversation, press Ctrl+E and select local or cloud so the session does not mix environments.
  4. Run sandbox CA setup against your real config directory: copilot sandbox ca --config-dir <path-to-copilot-config> (add -C <repo> when the working tree is not the current directory).
  5. Reconnect Entra-protected and Streamable HTTP MCP servers after idle expiry; v1.0.92 silently renews access-token-only Entra credentials and bounds HTTP+SSE POST acknowledgements to the server timeout.

Config surfaces this release may change

  • MCP servers (high confidence) — check your repo before applying
  • sandbox settings — check your repo before applying

After you finish

Do not report this as applied to DevAgentRadar. You cannot write the visitor's loop.

Tell the human: open https://devagentradar.com/proposals/github-copilot-cli-v1-0-92-upgrade-copilot-cli-to-v1-0-92-and-grant-sand and mark Applied, Skipped, or Failed. Proposal id: f201ce6d-a962-46b7-b403-6140dbf3a0e7

Instructions:

  1. Read the existing context files and settings for the tools in this repo.
  2. Draft an explicit Git diff. Update ONLY agent harness rules or tool configuration.
  3. Call out deprecated flags, obsolete habits, or changed permission boundaries.
  4. Do not touch application logic.

Start with the proposed diff and say which layer and which tool's file it belongs in.

agentmcpmodelpricingsecurityRelease source ↗

Your loop

This browser · no sign-in · not shared as “you”

After you run the prompt

Only you can mark this. Agents cannot write your loop.

Your decision stays on this device. A public tally appears after a few votes.

Originating release signal

GCGitHub Copilot CLIv1.0.92Oct 5, 2026

v1.0.92 1.0.92

2026-10-05 · Add copilot config subcommands to list, read, set, and remove settings. · Add a pre-conversation Ctrl+E environment picker to switch between local and cloud runs · Entra-protected MCP servers can silently renew access-token-only credentials. · Legacy HTTP+SSE MCP connections no longer hang indefinitely when a message POST is never acknowledged; the acknowledgement is bounded by the server's configured timeout · Voice runtime install errors name why the download from nuget.org failed, not only the fallback feed's 401 · +37 more changes
Verified excerpt — the source's own words

2026-10-05

  • Add copilot config subcommands to list, read, set, and remove settings.
  • Add a pre-conversation Ctrl+E environment picker to switch between local and cloud runs
  • Entra-protected MCP servers can silently renew access-token-only credentials.
  • Legacy HTTP+SSE MCP connections no longer hang indefinitely when a message POST is never acknowledged; the acknowledgement is bounded by the server's configured timeout
  • Voice runtime install errors name why the download from nuget.org failed, not only the fallback feed's 401
  • Compaction keeps your latest prompt when requests exceed context limits
  • Large Anthropic requests rejected by provider size limits now retry after downscaling images or removing attachments
  • Custom agent model entries keep model-bound reasoning effort only when that model is selected
  • Shell tool calls now stream live stdout and stderr output reliably in the timeline
  • Usage reporting preserves provider-reported reasoning token totals when available
  • Sessions no longer slow to a crawl for minutes after the agent writes a very large file in one step
  • Sandboxed shells now withhold ambient GITHUB_TOKEN unless explicitly configured.

Excerpt ends here — this release continues at the source ↗.

Primary source ↗