From 3cb6f4460509e0c0e4fd0e9bd5b1225b78b446f0 Mon Sep 17 00:00:00 2001 From: Tiago Pascoal Date: Fri, 2 Oct 2026 07:57:19 +0000 Subject: [PATCH 1/6] Updated CCR instruction files list in the custom instructions support reference page (#63625) --- content/copilot/reference/custom-instructions-support.md | 2 +- data/reusables/copilot/ci-support-ccr-only.md | 1 + 2 files changed, 2 insertions(+), 1 deletion(-) create mode 100644 data/reusables/copilot/ci-support-ccr-only.md diff --git a/content/copilot/reference/custom-instructions-support.md b/content/copilot/reference/custom-instructions-support.md index b36a4d378b1f..7c997f3375f6 100644 --- a/content/copilot/reference/custom-instructions-support.md +++ b/content/copilot/reference/custom-instructions-support.md @@ -52,7 +52,7 @@ WRITING NOTE: The following tables have been written using HTML rather than Mark diff --git a/data/reusables/copilot/ci-support-ccr-only.md b/data/reusables/copilot/ci-support-ccr-only.md new file mode 100644 index 000000000000..72223948e2b1 --- /dev/null +++ b/data/reusables/copilot/ci-support-ccr-only.md @@ -0,0 +1 @@ +
  •  Agent instructions (using AGENTS.md, CLAUDE.md, GEMINI.md or REVIEW.md files).
  • From a82210c0a5c08dfdcc4bb49632abb0e1072cca6f Mon Sep 17 00:00:00 2001 From: Jeff Widman Date: Fri, 2 Oct 2026 08:06:59 +0000 Subject: [PATCH 2/6] Document Dependabot registry configuration limits (#63643) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- .../supply-chain-security/dependabot-options-reference.md | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/content/code-security/reference/supply-chain-security/dependabot-options-reference.md b/content/code-security/reference/supply-chain-security/dependabot-options-reference.md index b8ecf39c3ef4..36ad91220774 100644 --- a/content/code-security/reference/supply-chain-security/dependabot-options-reference.md +++ b/content/code-security/reference/supply-chain-security/dependabot-options-reference.md @@ -758,6 +758,8 @@ There are 2 locations in the `dependabot.yml` file where you can use the `regist 1. At the top level, where you define the private registries you want to use and their access information, see [AUTOTITLE](/code-security/how-tos/secure-your-supply-chain/manage-your-dependency-security/configure-access-to-private-registries). 1. Within the `updates` blocks, where you can specify which private registries each package manager should use. +Each `updates` block can reference up to 100 registries from the top-level `registries` section. + {% data variables.product.prodname_dependabot %} default behavior is to raise pull requests only to update dependencies stored in publicly accessible registries. When the {% data variables.product.prodname_dependabot %} configuration file has a top-level `registries` section, defining access to one or more private registries, you can configure each `package-ecosystem` to use one or more of these private registries. @@ -1056,7 +1058,9 @@ Specify authentication details that {% data variables.product.prodname_dependabo {% endif %} -The value of the `registries` key is an associative array, each element of which consists of a key that identifies a particular registry and a value which is an associative array that specifies the settings required to access that registry. The following `dependabot.yml` file configures a registry identified as `dockerhub` in the `registries` section of the file and then references this in the `updates` section of the file. +The value of the `registries` key is an associative array, each element of which consists of a key that identifies a particular registry and a value which is an associative array that specifies the settings required to access that registry. You can define up to 100 registries in the top-level `registries` section. + +The following `dependabot.yml` file configures a registry identified as `dockerhub` in the `registries` section of the file and then references this in the `updates` section of the file. {% raw %} From fd963ab690caa4bf29bd5fc5c09f4e40044ec7e0 Mon Sep 17 00:00:00 2001 From: docs-bot <77750099+docs-bot@users.noreply.github.com> Date: Fri, 2 Oct 2026 08:45:20 +0000 Subject: [PATCH 3/6] Copilot CLI: Update integrations and remote control articles (#63644) Co-authored-by: github-actions[bot] Co-authored-by: hubwriter Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- .../set-up-copilot-cli/add-lsp-servers.md | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/content/copilot/how-tos/copilot-cli/set-up-copilot-cli/add-lsp-servers.md b/content/copilot/how-tos/copilot-cli/set-up-copilot-cli/add-lsp-servers.md index 09ce7588aa6f..f9e6e4cd37fc 100644 --- a/content/copilot/how-tos/copilot-cli/set-up-copilot-cli/add-lsp-servers.md +++ b/content/copilot/how-tos/copilot-cli/set-up-copilot-cli/add-lsp-servers.md @@ -194,9 +194,26 @@ Within each server definition, the following fields are available/required: No The timeout for server requests in milliseconds (default: 90 seconds). + + initializationTimeoutMs + No + The timeout for the server's startup handshake in milliseconds (default: 60 seconds). If a server needs more time for initial project analysis, increase this value. + +To disable an LSP server for everyone who uses the repository, add an entry to the repository's `.github/lsp.json` file. This entry can override a server configured by a lower-priority source, such as a plugin or user configuration. Use the existing server name and set `"disabled": true` instead of providing a full server definition: + +```json +{ + "lspServers": { + "SERVER-NAME": { + "disabled": true + } + } +} +``` + ### Example server definition: `typescript-language-server` LSP server ```json copy From 8a92080e1619d20a9fee37aad6c40c8afb68342e Mon Sep 17 00:00:00 2001 From: Anne-Marie <102995847+am-stead@users.noreply.github.com> Date: Fri, 2 Oct 2026 09:08:03 +0000 Subject: [PATCH 4/6] [Improvement]: Copilot Upgrade document has knowledge gaps #24393 (#63333) --- .../concepts/product-billing/github-copilot-licenses.md | 2 +- .../copilot/reference/copilot-billing/license-changes.md | 7 ++++--- 2 files changed, 5 insertions(+), 4 deletions(-) diff --git a/content/billing/concepts/product-billing/github-copilot-licenses.md b/content/billing/concepts/product-billing/github-copilot-licenses.md index 6bac3655ab1b..b1b282db9f8b 100644 --- a/content/billing/concepts/product-billing/github-copilot-licenses.md +++ b/content/billing/concepts/product-billing/github-copilot-licenses.md @@ -51,7 +51,7 @@ Usage of {% data variables.product.prodname_copilot_short %} licenses is measure ### Personal accounts -* Upgrades take effect immediately, with proration applied for the remainder of the current billing cycle. +* Upgrades take effect immediately. You are charged the full price of the new plan, minus the amount you already paid for your current plan. * Downgrades take effect at the start of the next billing cycle and are generally not prorated. * Canceling a monthly plan keeps access until the end of the current billing cycle, with no proration. diff --git a/content/copilot/reference/copilot-billing/license-changes.md b/content/copilot/reference/copilot-billing/license-changes.md index d0e0d38992ff..c8abe48c18dc 100644 --- a/content/copilot/reference/copilot-billing/license-changes.md +++ b/content/copilot/reference/copilot-billing/license-changes.md @@ -27,7 +27,7 @@ This article focuses on how those rules apply specifically to {% data variables. What you need to know about the following actions: -* **Upgrading:** If you upgrade your plan (for example, from {% data variables.copilot.copilot_pro_short %} to {% data variables.copilot.copilot_pro_plus_short %}), the change is **immediate**. You are charged a prorated amount for the new plan. +* **Upgrading:** If you upgrade your plan (for example, from {% data variables.copilot.copilot_pro_short %} to {% data variables.copilot.copilot_pro_plus_short %}), the change is **immediate**. You are charged the full price of the new plan, minus the amount you already paid for your current plan. * **Downgrading/canceling:** Access remains until the end of the current billing cycle. **No refund for unused time**. ### Included monthly allowance reset @@ -88,7 +88,8 @@ Additionally: ## In summary -* **Proration:** Applies when adding seats/licenses or upgrading plans. You pay only for the portion of the billing cycle remaining. Included {% data variables.product.prodname_ai_credits_short %} may also be prorated. +* **Proration:** Applies when adding seats/licenses. You pay only for the portion of the billing cycle remaining. Included {% data variables.product.prodname_ai_credits_short %} may also be prorated. +* **Upgrading a personal plan:** You are charged the full price of the new plan, minus the amount you already paid for your current plan. * **Access:** Assignments and upgrades are effective immediately for affected users. Downgrades take effect at the end of the billing cycle. * **Removing or canceling:** No refunds are issued for unused time; access continues until the end of the cycle paid for, unless a seat/license is revoked. @@ -97,5 +98,5 @@ Additionally: | Add seat/license | {% data variables.copilot.copilot_business_short %}, {% data variables.copilot.copilot_enterprise_short %}| Immediately | Yes | Immediately | N/A | | Remove seat/license | {% data variables.copilot.copilot_business_short %}, {% data variables.copilot.copilot_enterprise_short %}| End of cycle | N/A | End of cycle (immediately if revoked) | No | | Cancel subscription | All plans | End of cycle | N/A | End of cycle | No | -| Upgrade plan | All plans | Immediate | Yes | Immediately | N/A (proration instead) | +| Upgrade plan | {% data variables.copilot.copilot_pro_short %}, {% data variables.copilot.copilot_pro_plus_short %}, and {% data variables.copilot.copilot_max_short %} | Immediate | No | Immediately | N/A | | Downgrade plan | All plans | End of cycle | No | End of cycle | No | From 612c08d1a237afb6473a2b902130f4306947ece7 Mon Sep 17 00:00:00 2001 From: docs-bot <77750099+docs-bot@users.noreply.github.com> Date: Fri, 2 Oct 2026 09:40:29 +0000 Subject: [PATCH 5/6] docs: update copilot-cli content from source docs (#63620) Co-authored-by: github-actions[bot] Co-authored-by: hubwriter Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --- .../cli-command-reference.md | 25 +++++++++++++++++++ .../cli-config-dir-reference.md | 3 ++- content/copilot/reference/hooks-reference.md | 13 +++++++++- src/content-pipelines/state/copilot-cli.sha | 2 +- 4 files changed, 40 insertions(+), 3 deletions(-) diff --git a/content/copilot/reference/copilot-cli-reference/cli-command-reference.md b/content/copilot/reference/copilot-cli-reference/cli-command-reference.md index 67c66f042c34..e16f6d1728c6 100644 --- a/content/copilot/reference/copilot-cli-reference/cli-command-reference.md +++ b/content/copilot/reference/copilot-cli-reference/cli-command-reference.md @@ -28,6 +28,7 @@ docsTeamMetrics: | `copilot plugin` | Manage plugins and plugin marketplaces, including listing, enabling, disabling, and uninstalling them. `copilot plugins` (plural) is a legacy alias. See [AUTOTITLE](/copilot/reference/copilot-cli-reference/cli-plugin-reference). | | `copilot instruction` | Non-interactively list custom instruction sources discovered for the current working directory. See [Using `copilot instruction`](#using-copilot-instruction). | | `copilot lsp` | Non-interactively list configured language servers. See [Using `copilot lsp`](#using-copilot-lsp). | +| `copilot sandbox ca` | Manage the sandbox's proxy certificate authority from outside an interactive session. See [Using `copilot sandbox ca`](#using-copilot-sandbox-ca). | | `copilot skill` | Manage agent skills from the command line (list, add, remove, enable, and disable skills). See [Managing skills non-interactively](#managing-skills-non-interactively). | | `copilot update` | Download and install the latest version. | | `copilot version` | Display version information and check for updates. | @@ -167,6 +168,28 @@ Prompt and session-mode options cannot be combined with this command. Examples i For more information, see [AUTOTITLE](/copilot/how-tos/use-copilot-agents/use-dynamic-workflows#running-a-dynamic-workflow-from-the-command-line) and [AUTOTITLE](/copilot/reference/copilot-cli-reference/cli-programmatic-reference#running-dynamic-workflows). +### Using `copilot sandbox ca` + +Run `copilot sandbox ca` to manage the sandbox's proxy certificate authority from outside an interactive session—for example, when provisioning managed devices without a TTY. This mirrors the `/sandbox ca` slash commands (`create`, `trust`, `rotate`, `remove`), plus a `status` check. + +```bash +copilot sandbox ca status +copilot sandbox ca create +copilot sandbox ca trust +copilot sandbox ca rotate +copilot sandbox ca remove +``` + +| Subcommand | Description | +|---------------------------------|-----------------------------------------------------------------------------| +| `copilot sandbox ca status` | Report trust state without changing anything. | +| `copilot sandbox ca create` | Create the certificate authority if needed, without trusting it. | +| `copilot sandbox ca trust [CA.PEM]` | Add the authority (default: your own) to OS trust. | +| `copilot sandbox ca rotate` | Replace the authority, preserving its current trust state. | +| `copilot sandbox ca remove` | Remove the authority from OS trust; the bundle-based path keeps working. | + +Run these commands as the user who runs {% data variables.copilot.copilot_cli_short %}, not elevated, as `SYSTEM`, or as `root`, because the certificate authority is stored in that user's {% data variables.copilot.copilot_cli_short %} home directory. Run `copilot sandbox ca trust --help` for unattended setup guidance. `copilot sandbox ca` does not accept `--config-dir`; set `COPILOT_HOME` instead to target a non-default {% data variables.copilot.copilot_cli_short %} home. + ## The sessions sidebar The sessions sidebar is a panel docked beside your current conversation that provides a quick way of working with your local {% data variables.copilot.copilot_cli %} sessions. @@ -527,6 +550,7 @@ These are the slash commands you can use from within an interactive CLI session. | `/review [PROMPT]` | Run the code review agent to analyze changes. See [AUTOTITLE](/copilot/how-tos/copilot-cli/use-copilot-cli/agentic-code-review). | | `/rubber-duck [PROMPT]` | Consult the rubber duck agent for a second opinion on plans, code, and tests. See [AUTOTITLE](/copilot/concepts/agents/copilot-cli/rubber-duck). | | `/sandbox [config\|status\|policy\|enable\|disable]` | Manage OS-level sandboxing that restricts filesystem and network access for shell commands, MCP/LSP servers, and built-in file/web tools. `config` (or bare `/sandbox`) opens the sandbox settings dialog. `status` shows whether sandboxing is enabled. `policy` shows the effective policy, with path grants grouped by source (user-configured, system, working directory, current session, and `~/.copilot`) and access type, plus the network stance and any detected developer tools. `enable`/`disable` turn sandboxing on or off directly. `status` and `policy` are read-only and can run while the agent is busy processing a turn. `config`, `enable`, and `disable` are queued until the turn finishes. {% data reusables.copilot.experimental %} | +| `/sandbox ca [create\|trust\|rotate\|remove]` | Manage the sandbox's proxy certificate authority. `create` writes it without trusting it. `trust` adds it to OS trust. `rotate` replaces it while preserving its trust state. `remove` drops OS trust. See [Using `copilot sandbox ca`](#using-copilot-sandbox-ca) to run the same operations outside a session, for example on managed devices. | | `/search [QUERY]`, `/find [QUERY]` | Search the conversation timeline. | | `/security-review [PROMPT]` | Run a focused security review of active local code changes and return prioritized vulnerability findings with remediation suggestions. This command is not a full repository security audit. | | `/session [info\|checkpoints [n]\|files\|plan\|rename [NAME]\|cleanup\|prune\|delete [ID]\|delete-all]`, `/sessions [info\|checkpoints [n]\|files\|plan\|rename [NAME]\|cleanup\|prune\|delete [ID]\|delete-all]` | Show session information and manage sessions. The `info` subcommand shows session details including the session link (when available). Subcommands: `info`, `checkpoints`, `files`, `plan`, `rename`, `cleanup`, `prune`, `delete`, `delete-all`. | @@ -551,6 +575,7 @@ These are the slash commands you can use from within an interactive CLI session. | `/version` | Display version information and check for updates. | | `/vim` | Toggle Vim mode for the prompt box, enabling Vim-style modal editing: motions (for example, `hjkl`, `w`, `b`, `e`, `0`, `$`, `gg`, `G`), character search (`f`/`F`/`t`/`T`/`;`/`,`), insert commands (`i`/`a`/`o`), edit commands (`r`/`~`/`J`/`x`/`D`/`C`), operators (`d`/`c`/`y`), yank and put (`y`/`p`/`P`), repeat (`.`), undo and redo (`u`/Ctrl+R), counts, and Esc to return to normal mode. Also configurable with the `editorMode` setting. See [AUTOTITLE](/copilot/reference/copilot-cli-reference/cli-config-dir-reference#user-settings-copilotsettingsjson). | | `/voice [on\|off\|models\|devices]` | Toggle voice mode, browse available voice models, or choose the input device (microphone). | +| `/workflows` | Observe workflow runs, phases, agents, and progress. Requires a token-based-billing plan. See [Using `copilot workflow run`](#using-copilot-workflow-run) to run a registered workflow directly. | | `/fork [NAME]`, `/branch [NAME]` | Fork the current session into a new session, optionally with a name. Usable while the agent is running—the source session keeps working in the background. `/fork worktree` forks the current session, preserving its conversation context, into a new Git worktree branched off `HEAD`. | | `/worktree [branch\|task]` | Create a new Git worktree and switch to it, leaving uncommitted changes behind in the current worktree. Pass a branch name, a task description (multiline supported, used as the opening prompt in the new worktree), or omit the argument to auto-generate a branch name from the conversation. By default, branches off the current checkout (`HEAD`); set the `worktreeBaseRef` setting to `"defaultBranch"` to branch off the remote default branch instead. See [AUTOTITLE](/copilot/reference/copilot-cli-reference/cli-config-dir-reference#user-settings-copilotsettingsjson). Requires a Git repository. | | `/worktree new [PROMPT]` | Deprecated—use `/new worktree` instead. Starts a new conversation in a new Git worktree, leaving the current conversation and its working directory unchanged. Optionally provide the first prompt. `new` is reserved as the subcommand keyword and can't be used as a literal branch name. Follows the same `worktreeBaseRef` setting as `/worktree`. | diff --git a/content/copilot/reference/copilot-cli-reference/cli-config-dir-reference.md b/content/copilot/reference/copilot-cli-reference/cli-config-dir-reference.md index 95581a98cb38..3489e65c6c28 100644 --- a/content/copilot/reference/copilot-cli-reference/cli-config-dir-reference.md +++ b/content/copilot/reference/copilot-cli-reference/cli-config-dir-reference.md @@ -663,7 +663,7 @@ Only the following keys are supported in MDM managed settings. | `permissions` | Set managed permissions, including `disableBypassPermissionsMode` and `deny` / `ask` / `allow` rule arrays. See [Managed permission rules](#managed-permission-rules). | | `policyHelper` | Register an executable that supplies the lowest-priority managed-settings layer. Fields: `path` (required), plus optional `args`, `timeoutMs`, and `refreshIntervalMs`. If both a device (MDM) and a server policy register a `policyHelper`, the device registration wins. | | `remoteControl` | Control whether sessions on this device can be controlled from other devices. `mode` is `"enabled"`, `"disabled"`, or `"requireSSO"` (requires `githubDotComOrganizations` when set). | -| `sandbox` | Set a sandbox policy floor that users cannot relax. Supported settings include `enabled`, `failIfUnavailable`, `allowBypass`, `addCurrentWorkingDirectory`, `sandboxMcpServers`, `sandboxLspServers`, `auth.git`, `auth.gh`, `allowDevToolAccess`, and the `userPolicy.*` filesystem and network rules. The managed value always takes precedence over a user's own value in the safer direction. Turning the sandbox on, requiring it to succeed, and sandboxing MCP and LSP servers cannot be turned off. Disabling bypass or credential injection cannot be re-enabled. Filesystem allow lists can only be narrowed, and denied paths can only be added to. `failIfUnavailable` can only be set by an administrator and blocks the session when the sandbox cannot be established. For the settings users can set themselves, see [User settings](#user-settings-copilotsettingsjson) or run `copilot help sandbox`. | +| `sandbox` | Set a sandbox policy floor that users cannot relax. Supported settings include `enabled`, `failIfUnavailable`, `allowBypass`, `addCurrentWorkingDirectory`, `sandboxMcpServers`, `sandboxLspServers`, `auth.git`, `auth.gh`, `allowDevToolAccess`, `learningMode`, and the `userPolicy.*` filesystem and network rules. The managed value always takes precedence over a user's own value in the safer direction. Turning the sandbox on, requiring it to succeed, and sandboxing MCP and LSP servers cannot be turned off. Disabling bypass or credential injection cannot be re-enabled. Filesystem allow lists can only be narrowed, and denied paths can only be added to. `failIfUnavailable` can only be set by an administrator and blocks the session when the sandbox cannot be established. For the settings users can set themselves, see [User settings](#user-settings-copilotsettingsjson) or run `copilot help sandbox`. | | `shellShortcut` | Force-enable or force-disable the `$` interactive shell shortcut for all users. A managed value always overrides the user's own `shellShortcut` setting. | | `strictKnownMarketplaces` | Restrict plugins to an allowlist of known marketplaces (a JSON array of marketplace specs). The allowlist also governs built-in marketplaces once set—an empty array (`[]`) hides and blocks every marketplace, including built-ins, not just user- or repository-added ones. | | `telemetry` | Push baseline OpenTelemetry export configuration: `enabled`, `endpoint`, `protocol`, `headers`, `resourceAttributes`, `captureContent`, `lockCaptureContent`, and `serviceName`. See [AUTOTITLE](/copilot/reference/copilot-cli-reference/cli-command-reference#opentelemetry-monitoring). | @@ -673,6 +673,7 @@ Only the following keys are supported in MDM managed settings. > * When `remoteControl.mode` is `"requireSSO"`, list the allowed organizations in `remoteControl.githubDotComOrganizations`. The client must be SSO-authorized for at least one listed {% data variables.product.prodname_dotcom_the_website %} organization—it no longer needs to be authorized for all of them. > * Set `permissions.disableBypassPermissionsMode` to `"disable"` in MDM managed settings to enforce the restriction at the device level. Account switches cannot override this policy. Set it to `"allow-auto-only"` to block full allow-all escalation while still permitting `/permissions assisted` (LLM-assisted permission approval). If an unrecognized value is set, the CLI logs the issue and enforces `"disable"` as a fail-closed default, so a malformed managed policy still restricts the allow-all options instead of silently allowing them. See [AUTOTITLE](/copilot/reference/copilot-cli-reference/cli-command-reference#restricting-the---allow-all-options). > * Most managed keys lock the entire row: a local edit is silently overridden by the managed value on the next load. `enabledPlugins` and `extraKnownMarketplaces` are the exception—the managed layer merges these maps with your own entries field-by-field instead of replacing them outright. This means the lock applies **per entry**, not to the whole key: a plugin or marketplace pinned by a managed policy can't be re-enabled, disabled, or repointed locally, but other entries in the same map remain fully user-controlled. +> * `sandbox.learningMode` is Windows-only and can only be set through native MDM (for example, through Intune or the registry)—a `managed-settings.json` file value is ignored. On a host with denial capture, set it to `"allow"` to start sandboxed shell commands in record-and-allow mode instead of the default record-and-deny mode, recording each filesystem or process access and allowing it rather than refusing it (network policy is still enforced). This lets an administrator observe what a cohort's commands need before locking them down; it is not a containment mode. The status line shows `sandbox relaxed` and shell calls show `(sandbox relaxed)` while it applies. A `deny` value (the default), or removing the key, returns the cohort to the ordinary enforced sandbox, and `deny` from any managed channel always wins over `allow`. User settings and SDK hosts cannot set this key. ### Managed permission rules diff --git a/content/copilot/reference/hooks-reference.md b/content/copilot/reference/hooks-reference.md index 047d988b1d01..31cfe8dbc1b0 100644 --- a/content/copilot/reference/hooks-reference.md +++ b/content/copilot/reference/hooks-reference.md @@ -59,7 +59,7 @@ Policy hooks are discovered from two sources: Policy hook files use the same hook configuration format as user and project hooks (`{ "version": 1, "hooks": { ... } }`). On POSIX systems, policy files must be owned by root and must not be group- or world-writable. -Policy hooks are intended for use by enterprise IT administrators and require elevated privileges to install. End users cannot modify them. +Policy hooks are intended for use by enterprise IT administrators and require elevated privileges to install. End users cannot modify them. Policy hooks always run on the host, even when the session sandbox is enabled—see [Sandboxed sessions](#sandboxed-sessions). ## Cloud agent execution environment @@ -172,6 +172,17 @@ Progress messages are display-only and do not affect hook output or decision log * The final decision object, by contrast, may span multiple lines—only progress *recognition* is line-oriented; what remains after progress stripping is parsed as one JSON document, not as line-delimited JSON. * If the leftover output is empty, or fails to parse as JSON, the hook is treated as having produced no output and falls through to default behavior. Two or more non-progress JSON objects on stdout (for example, two `echo '{"permissionDecision": ...}'` calls) will therefore concatenate into invalid JSON and be ignored—emit exactly one final decision object. +#### Sandboxed sessions + +> [!NOTE] +> **{% data variables.copilot.copilot_cli_short %} only.** + +When the session sandbox is enabled, command hooks from the repository, your user settings, and plugins run inside it, with the same access as the agent's shell commands. A hook can also read the directory it was loaded from, so a plugin can run the scripts it ships, and a plugin hook can write to its data directory (`$COPILOT_PLUGIN_DATA`). + +A hook's `cwd` and `env` fields don't widen that access: a `cwd` outside the session's grants gives the hook no access there, and variables such as `TMPDIR` or `PATH` set in the hook's `env` grant nothing. When a hook fails in the sandbox, {% data variables.product.prodname_copilot_short %} shows a warning once per hook and session. To give a hook more access, add the required paths to `sandbox.userPolicy` in your settings. See [AUTOTITLE](/copilot/reference/copilot-cli-reference/cli-config-dir-reference#user-settings-copilotsettingsjson). + +Policy hooks always run on the host, outside the sandbox, even when the session sandbox is enabled. A policy hook should not run scripts from the workspace. + ### HTTP hooks HTTP hooks send the input payload as a JSON `POST` to a URL. diff --git a/src/content-pipelines/state/copilot-cli.sha b/src/content-pipelines/state/copilot-cli.sha index 0bb981347760..af8d41bdc4e7 100644 --- a/src/content-pipelines/state/copilot-cli.sha +++ b/src/content-pipelines/state/copilot-cli.sha @@ -1 +1 @@ -69e17eb6083943638905b6891d96e2c90ecab505 +c0a42716d53bd457fd54fe47719b05d2a7c21ee6 From e85b5032f062ca8a54c489139c221d25e31db885 Mon Sep 17 00:00:00 2001 From: Sophie <29382425+sophietheking@users.noreply.github.com> Date: Fri, 2 Oct 2026 14:05:00 +0000 Subject: [PATCH 6/6] Structured, required proof-of-concept fields + Confidential team-only comments for private vulnerability reports (#63552) Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Laura Coursen --- .../configure-for-a-repository.md | 50 +++++++++++++++++++ .../manage-vulnerability-reports.md | 18 ++++++- .../report-privately.md | 2 +- .../repository-security-advisory.md | 2 + ...reating-a-default-community-health-file.md | 11 +++- .../syntax-for-githubs-form-schema.md | 4 ++ data/reusables/form-schema/min-length-key.md | 1 + .../private-vulnerability-api.md | 4 +- .../reporting-a-vulnerability-non-admin.md | 8 +-- 9 files changed, 91 insertions(+), 9 deletions(-) create mode 100644 data/reusables/form-schema/min-length-key.md diff --git a/content/code-security/how-tos/report-and-fix-vulnerabilities/configure-vulnerability-reporting/configure-for-a-repository.md b/content/code-security/how-tos/report-and-fix-vulnerabilities/configure-vulnerability-reporting/configure-for-a-repository.md index 1caa1add20d6..eab1bb0a6d04 100644 --- a/content/code-security/how-tos/report-and-fix-vulnerabilities/configure-vulnerability-reporting/configure-for-a-repository.md +++ b/content/code-security/how-tos/report-and-fix-vulnerabilities/configure-vulnerability-reporting/configure-for-a-repository.md @@ -31,6 +31,56 @@ The instructions in this article refer to enablement at repository level. For in {% data reusables.security-advisory.private-vulnerability-api %} +## Customizing the vulnerability reporting form + +By default, the private vulnerability reporting form requires reporters to provide a summary, details, proof of concept, and impact statement. This structured information helps maintainers assess reports consistently and reduces the need to request missing details. + +To customize the form, add a `VULNERABILITY_REPORT.yml` or `VULNERABILITY_REPORT.yaml` file to the repository's `.github` directory. You can also define a default form for an organization or personal account in the `.github` repository owned by that account. A form in an individual repository takes precedence over the form in the owner's `.github` repository. + +Private vulnerability reporting forms use the same YAML syntax as issue forms. The forms support `checkboxes`, `dropdown`, `input`, `markdown`, and `textarea` elements. You can mark fields as required and use `min_length` to require a minimum number of characters for `input` and `textarea` elements. For information about the supported keys for each element, see [AUTOTITLE](/communities/using-templates-to-encourage-useful-issues-and-pull-requests/syntax-for-githubs-form-schema). + +For example, the following form requires a detailed proof of concept of at least 100 characters. + +```yaml copy +name: Private vulnerability report +description: Provide the information maintainers need to assess the report. +body: + - type: textarea + id: summary + attributes: + label: Summary + description: Summarize the vulnerability and its potential severity. + validations: + required: true + - type: textarea + id: proof_of_concept + attributes: + label: Proof of concept + description: Provide complete instructions for reproducing the vulnerability. + validations: + required: true + min_length: 100 + - type: textarea + id: impact + attributes: + label: Impact + description: Explain who is affected and how. + validations: + required: true +``` + +If {% data variables.product.prodname_dotcom %} cannot parse or validate a custom form, reporters see the default form instead. + +## Requiring reporters to assign a CWE + +You can require reporters to associate at least one Common Weakness Enumeration (CWE) with each new report. This repository-level setting applies to reports submitted in the web interface and with the REST API. It does not apply to repository maintainers who create advisories or to edits of existing reports. + +{% data reusables.repositories.navigate-to-repo %} +{% data reusables.repositories.sidebar-settings %} +{% data reusables.repositories.navigate-to-code-security-and-analysis %} +1. Under **{% data variables.product.UI_advanced_security %}**, to the right of **Private vulnerability reporting**, click **Settings**. +1. Under **Submission requirements**, enable **Require a CWE assignment**. + ## Configuring notifications for private vulnerability reporting {% data reusables.security-advisory.private-vulnerability-reporting-configure-notifications %} diff --git a/content/code-security/how-tos/report-and-fix-vulnerabilities/fix-reported-vulnerabilities/manage-vulnerability-reports.md b/content/code-security/how-tos/report-and-fix-vulnerabilities/fix-reported-vulnerabilities/manage-vulnerability-reports.md index 5e916e691d6a..13a9b2a4f664 100644 --- a/content/code-security/how-tos/report-and-fix-vulnerabilities/fix-reported-vulnerabilities/manage-vulnerability-reports.md +++ b/content/code-security/how-tos/report-and-fix-vulnerabilities/fix-reported-vulnerabilities/manage-vulnerability-reports.md @@ -21,6 +21,8 @@ When a security researcher reports a vulnerability privately, you are notified a For more information about configuring notification preferences, see [AUTOTITLE](/code-security/how-tos/report-and-fix-vulnerabilities/configure-vulnerability-reporting/configure-for-a-repository#configuring-notifications-for-private-vulnerability-reporting). +## Reviewing a vulnerability report + {% data reusables.repositories.navigate-to-repo %} {% data reusables.repositories.sidebar-security %} {% data reusables.repositories.sidebar-advisories %} @@ -28,13 +30,25 @@ For more information about configuring notification preferences, see [AUTOTITLE] ![Screenshot of a "Security Advisories" list.](/assets/images/help/security/advisory-list.png) -1. Carefully review the report, then choose how to proceed. +1. Carefully review the report details and any disclosure of AI assistance. Then choose how to proceed. * To collaborate on a patch in private, click **Start a temporary private fork** to create a place for further discussions with the contributor. This does not change the status of the proposed advisory from `Triage`. * To accept the reported vulnerability, click **Accept and open as draft** to accept the vulnerability report as a draft advisory on {% data variables.product.prodname_dotcom %}. If you choose this option: * This doesn't make the report public. * The report becomes a draft repository security advisory and you can work on it in the same way as any draft advisory that you create. For more information on security advisories, see [AUTOTITLE](/code-security/concepts/vulnerability-reporting-and-management/repository-security-advisories). - * To ask for more information, or to open a discussion with the reporter, you can comment on the advisory. Any comments are visible only to the reporter and to any collaborators on the advisory. + * To ask for more information, or to open a discussion with the reporter, you can comment on the advisory. A regular comment is visible to the reporter and all collaborators on the advisory. * If you have enough information to determine that the problem the reporter describes is not a security risk, click **Close security advisory**. Where possible, you should add a comment explaining why you don't consider the report a security risk before you close the advisory. ![Screenshot showing the options available to the repository maintainer when reviewing an externally submitted vulnerability report.](/assets/images/help/security/advisory-maintainer-options.png) + +## Discussing a report with people who have write access + +People with write access to the repository can use confidential comments to coordinate with each other. These comments are hidden from the reporter and invited advisory collaborators who do not have write access. + +Access to confidential comments is based on current repository permissions. If a person's write access is removed, they can no longer read confidential comments. People who gain write access can read existing confidential comments. + +1. In the advisory, type your comment. +1. Below the comment field, select **Confidential. Only maintainers will see this comment**. +1. Click **Comment**. + +You can edit or delete a confidential comment if you still have write access to the repository. You cannot change a comment from regular to confidential, or from confidential to regular, after posting it. diff --git a/content/code-security/how-tos/report-and-fix-vulnerabilities/report-privately.md b/content/code-security/how-tos/report-and-fix-vulnerabilities/report-privately.md index fdf947b2f880..11e7cb4dd9d3 100644 --- a/content/code-security/how-tos/report-and-fix-vulnerabilities/report-privately.md +++ b/content/code-security/how-tos/report-and-fix-vulnerabilities/report-privately.md @@ -24,7 +24,7 @@ category: > [!NOTE] > * If you have admin or security permissions for a public repository, you don’t need to submit a vulnerability report. Instead, create a draft security advisory directly. See [AUTOTITLE](/code-security/how-tos/report-and-fix-vulnerabilities/fix-reported-vulnerabilities/create-repository-advisory). -> * Private vulnerability reporting is separate from a repository’s `SECURITY.md` file. You can only report vulnerabilities privately for repositories where this feature is enabled, and you don’t need to follow the instructions in `SECURITY.md`. +> * Private vulnerability reporting is separate from a repository’s `SECURITY.md` file. You can only report vulnerabilities privately for repositories where this feature is enabled. If the repository has a security policy, the policy is displayed above the reporting form so you can review the maintainer's guidance before submitting. If a public repository has private vulnerability reporting enabled, anyone can submit a private vulnerability report to the repository maintainers. diff --git a/content/code-security/reference/permissions/repository-security-advisory.md b/content/code-security/reference/permissions/repository-security-advisory.md index 1d5a111510c6..abb713d91833 100644 --- a/content/code-security/reference/permissions/repository-security-advisory.md +++ b/content/code-security/reference/permissions/repository-security-advisory.md @@ -40,6 +40,8 @@ Add and remove credits for a security advisory (see [AUTOTITLE](/code-security/h Close the draft security advisory | {% octicon "x" aria-label="No" %} | {% octicon "check" aria-label="Yes" %} | Publish the security advisory (see [AUTOTITLE](/code-security/how-tos/report-and-fix-vulnerabilities/fix-reported-vulnerabilities/publish-repository-advisory)) | {% octicon "x" aria-label="No" %} | {% octicon "check" aria-label="Yes" %} | +Repository security advisory collaborators without write access to the repository cannot create or view confidential comments. This restriction includes the reporter of a privately reported vulnerability unless they also have write access. See [AUTOTITLE](/code-security/how-tos/report-and-fix-vulnerabilities/fix-reported-vulnerabilities/manage-vulnerability-reports#discussing-a-report-with-people-who-have-write-access). + ### Permission differences for global security advisories Unlike repository security advisories, anyone can contribute to **global security advisories** in the {% data variables.product.prodname_advisory_database %} at [github.com/advisories](https://github.com/advisories). Edits to global advisories will not change or affect how the advisory appears on the repository. See [AUTOTITLE](/code-security/how-tos/report-and-fix-vulnerabilities/fix-reported-vulnerabilities/edit-advisory-database). diff --git a/content/communities/setting-up-your-project-for-healthy-contributions/creating-a-default-community-health-file.md b/content/communities/setting-up-your-project-for-healthy-contributions/creating-a-default-community-health-file.md index bc92bcda2a4d..11008213e4e3 100644 --- a/content/communities/setting-up-your-project-for-healthy-contributions/creating-a-default-community-health-file.md +++ b/content/communities/setting-up-your-project-for-healthy-contributions/creating-a-default-community-health-file.md @@ -72,6 +72,9 @@ You can create defaults in your organization or personal account for the followi | {% endif %} | | Issue and pull request templates and _config.yml_ | Issue and pull request templates customize and standardize the information you'd like contributors to include when they open issues and pull requests in your repository. For more information, see [AUTOTITLE](/communities/using-templates-to-encourage-useful-issues-and-pull-requests/about-issue-and-pull-request-templates).

    If an issue template sets a label, that label must be created in your `.github` repository and any repositories where the template will be used. | | _SECURITY.md_ | A SECURITY file gives instructions on how to report a security vulnerability in your project and description that hyperlinks the file. For more information, see [AUTOTITLE](/code-security/how-tos/report-and-fix-vulnerabilities/configure-vulnerability-reporting/add-security-policy). | +| {% ifversion fpt or ghec %} | +| _VULNERABILITY_REPORT.yml_ or _VULNERABILITY_REPORT.yaml_ | A vulnerability report form customizes the information that reporters must provide when they privately report a vulnerability. For more information, see [AUTOTITLE](/code-security/how-tos/report-and-fix-vulnerabilities/configure-vulnerability-reporting/configure-for-a-repository#customizing-the-vulnerability-reporting-form). | +| {% endif %} | | _SUPPORT.md_ | A SUPPORT file lets people know about ways to get help with your project. For more information, see [AUTOTITLE](/communities/setting-up-your-project-for-healthy-contributions/adding-support-resources-to-your-project). | You cannot create a default license file. License files must be added to individual repositories so the file will be included when a project is cloned, packaged, or downloaded. @@ -86,4 +89,10 @@ You cannot create a default license file. License files must be added to individ 1. {% ifversion ghec %}If you are creating the repository for an {% data variables.enterprise.prodname_emu_org %}, set the repository status to **Internal**. For any other eligible account, set the status to **Public**.{% else %}Make sure the repository status is set to **Public**.{% endif %} A repository for default files cannot be private. {% data reusables.repositories.initialize-with-readme %} {% data reusables.repositories.create-repo %} -1. In the repository, create one of the supported community health files. Discussion category forms must be in a folder called `.github/DISCUSSION_TEMPLATE`. Issue templates and their configuration file must be in a folder called `.github/ISSUE_TEMPLATE`. {% ifversion fpt or ghec %}A `FUNDING.yml` file must be in the `.github` folder. {% endif %}All other supported files may be in the root of the repository, the `.github` folder, or the `docs` folder. For more information, see [AUTOTITLE](/repositories/working-with-files/managing-files/creating-new-files). +1. In the repository, create one of the supported community health files. Store the file in the required location: + * Store discussion category forms in `.github/DISCUSSION_TEMPLATE`. + * Store issue templates and their configuration file in `.github/ISSUE_TEMPLATE`. + {% ifversion fpt or ghec %}* Store `FUNDING.yml`, `VULNERABILITY_REPORT.yml`, and `VULNERABILITY_REPORT.yaml` in the `.github` folder.{% endif %} + * Store all other supported files in the root of the repository, the `.github` folder, or the `docs` folder. + + For more information, see [AUTOTITLE](/repositories/working-with-files/managing-files/creating-new-files). diff --git a/content/communities/using-templates-to-encourage-useful-issues-and-pull-requests/syntax-for-githubs-form-schema.md b/content/communities/using-templates-to-encourage-useful-issues-and-pull-requests/syntax-for-githubs-form-schema.md index 4e618e41b544..e9e66289738f 100644 --- a/content/communities/using-templates-to-encourage-useful-issues-and-pull-requests/syntax-for-githubs-form-schema.md +++ b/content/communities/using-templates-to-encourage-useful-issues-and-pull-requests/syntax-for-githubs-form-schema.md @@ -132,6 +132,7 @@ You can use a `textarea` element to add a multi-line text field to your form. Co | Key | Description | Required | Type | Default | Valid values | | --- | ----------- | -------- | ---- | ------- | ------- | {% data reusables.form-schema.required-key %} +{% data reusables.form-schema.min-length-key %} #### Example of `textarea` @@ -150,6 +151,7 @@ body: render: bash validations: required: true + min_length: 100 ``` ### `input` @@ -174,6 +176,7 @@ You can use an `input` element to add a single-line text field to your form. | Key | Description | Required | Type | Default | Valid values | | --- | ----------- | -------- | ---- | ------- | ------- | {% data reusables.form-schema.required-key %} +{% data reusables.form-schema.min-length-key %} #### Example of `input` @@ -187,6 +190,7 @@ body: placeholder: "Example: Whenever I visit the personal account page (1-2 times a week)" validations: required: true + min_length: 20 ``` ### `dropdown` diff --git a/data/reusables/form-schema/min-length-key.md b/data/reusables/form-schema/min-length-key.md new file mode 100644 index 000000000000..312400f4105f --- /dev/null +++ b/data/reusables/form-schema/min-length-key.md @@ -0,0 +1 @@ +| `min_length` | Prevents form submission until the response contains at least the specified number of characters. | {% octicon "x" aria-label="Optional" %} | Integer | {% octicon "dash" aria-label="Not applicable" %} | A non-negative integer | diff --git a/data/reusables/security-advisory/private-vulnerability-api.md b/data/reusables/security-advisory/private-vulnerability-api.md index b59163921a3a..81fd17f7a27b 100644 --- a/data/reusables/security-advisory/private-vulnerability-api.md +++ b/data/reusables/security-advisory/private-vulnerability-api.md @@ -1 +1,3 @@ -Security researchers can also use the REST API to privately report security vulnerabilities. See [AUTOTITLE](/rest/security-advisories/repository-advisories#privately-report-a-security-vulnerability). +Security researchers can also use the REST API to privately report security vulnerabilities. API submissions use a Markdown `description`. If the repository or its owner's `.github` repository defines a custom vulnerability reporting form, the API description must contain the required sections and responses from that form. The built-in default form is not enforced for API submissions. + +You can use the REST API to retrieve the custom form that applies to a repository. See [AUTOTITLE](/rest/security-advisories/repository-advisories). diff --git a/data/reusables/security-advisory/reporting-a-vulnerability-non-admin.md b/data/reusables/security-advisory/reporting-a-vulnerability-non-admin.md index 2a9338b2df67..dbd21289a917 100644 --- a/data/reusables/security-advisory/reporting-a-vulnerability-non-admin.md +++ b/data/reusables/security-advisory/reporting-a-vulnerability-non-admin.md @@ -1,13 +1,13 @@ {% data reusables.repositories.navigate-to-repo %} {% data reusables.repositories.sidebar-security %} 1. Click **Report a vulnerability** to open the advisory form. -1. Fill in the advisory details form. +1. If the repository has a security policy, review the policy displayed above the form. +1. Fill in the vulnerability reporting form. > [!TIP] - > In this form, only the title and description are mandatory. (In the general draft security advisory form, which the repository maintainer initiates, specifying the ecosystem is also required.) However, we recommend security researchers provide as much information as possible on the form so that the maintainers can make an informed decision about the submitted report. You can adopt the template used by our security researchers from the {% data variables.product.prodname_security %}, which is available on the [`github/securitylab` repository](https://github.com/github/securitylab/blob/main/docs/report-template.md). - - For more information about the fields available and guidance on filling in the form, see [AUTOTITLE](/code-security/how-tos/report-and-fix-vulnerabilities/fix-reported-vulnerabilities/create-repository-advisory) and [AUTOTITLE](/code-security/tutorials/fix-reported-vulnerabilities/write-security-advisories). + > By default, you must provide a summary, details, proof of concept, and impact statement. Maintainers can customize the form and require other information. Provide enough detail for the maintainers to reproduce and assess the vulnerability. +1. Optionally, select **I used AI assistance to find or write up this report**. 1. At the bottom of the form, click **Submit report**. {% data variables.product.prodname_dotcom %} will display a message letting you know that maintainers have been notified and that you have a pending credit for this security advisory. > [!TIP]