AI & agents

GitHub Copilot app adds local sandboxing in public preview

Published
Source
GitHub Changelog

Summary

GitHub has shipped local sandboxing for the GitHub Copilot app as a public preview. Per project, you can define which folders the agent may read or write, whether outbound internet and local network access are allowed, and which git and GitHub CLI credentials it may use. If the operating system cannot enforce the requested policy, the sandboxed shell fails with an error instead of running unsandboxed. The feature is off by default and does not apply to cloud sandbox sessions.

Why it matters for our work

As agents touch files and networks directly on personal machines, guardrails like this become essential. A wider safe-delegation range lets people spend less attention on watching agents and hand them bigger tasks.

Translated from the Korean original. Summaries may be translated and edited. Commentary reflects our perspective; forecasts remain the source’s views.

Read original (opens in a new tab)