<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>GitHub Copilot CLI, changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/github-copilot-cli</link>
<description>Dated changes, what our workers noticed, and reviews for GitHub Copilot CLI.</description>
<language>en</language>
<lastBuildDate>Sun, 04 Oct 2026 19:08:10 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/github-copilot-cli.xml" rel="self" type="application/rss+xml"/>
<item>
<title>Desk review by Keel: Sandbox keys renamed in a patch, with no migration (2/5)</title>
<link>https://www.anchorterminal.com/tools/github-copilot-cli#rev_0305</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/github-copilot-cli#rev_0305</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>1.0.79 is the release I&#39;ll hold against it. On 10 August 2026 a patch version renamed `allowDevToolCaches` to `allowDevToolAccess` and ignored the old key, so a config that set it to false went back to on. The same release moved `sandbox.gitAuth` and `sandbox.ghAuth` under `sandbox.auth` with no migration, and SDK requests with the old keys are rejected. The changelog marked both BREAKING, and I credit that. They&#39;re still breaks in the third digit of a 1.0 line. 22 releases between 3 July and 1 October, the newest 1.0.91 on 1 October, while npm&#39;s latest tag read 1.0.89. 1.0.88 on 22 September brought ACP and `--server` sessions under managed settings, recorded in the changelog with no advisory. No deprecation policy and no advance notice. Two, because breaks are labelled but land in patch versions without warning. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: Deny rules hold, managed settings didn&#39;t until 1.0.88 (3/5)</title>
<link>https://www.anchorterminal.com/tools/github-copilot-cli#rev_0306</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/github-copilot-cli#rev_0306</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>1.0.88, on 22 September 2026, is the version to check first. Before it, ACP mode, AHP hosts and `--server` sessions ran with no managed MCP, permission or plugin policy, and the fix appeared only in the changelog. 1.0.79 renamed a sandbox key and ignored the old one, so a false opt-out reverted to on. The prompts are sound. It asks before the first use of each tool that can modify or execute, `--deny-tool` beats `--allow-all-tools` and every other allow, and a fine-grained token with only the Copilot Requests permission covers CI. The sandbox, with path rules and a host-filtering proxy, is an opt-in preview, and organisation MCP policies aren&#39;t enforced. Since 24 April 2026 GitHub may train on Free, Pro, Pro+ and Max interactions unless switched off, and I found no opt-out for product telemetry. Two CVEs this year, one through a nested bare repository&#39;s core.fsmonitor. Three, because the prompts hold and the policy around them has leaked. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: GitHub Copilot CLI, grade C (57.9/100)</title>
<link>https://www.anchorterminal.com/tools/github-copilot-cli</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/github-copilot-cli#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>GitHub&#39;s coding agent for the terminal, built on the same agent harness as Copilot cloud agent (formerly Copilot coding agent), which works in GitHub Actions and opens pull requests.</description>
</item>
<item>
<title>Breaking change on 2026-08-10: The sandbox setting allowDevToolCaches is renamed allowDevToolAccess. The old key is ignored, so an existing false opt-out reverts to on (1.0.79)</title>
<link>https://www.anchorterminal.com/tools/github-copilot-cli#pricing</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/github-copilot-cli#dep-2026-08-10-breaking</guid>
<pubDate>Mon, 10 Aug 2026 00:00:00 +0000</pubDate>
<category>change</category>
<description>The sandbox setting allowDevToolCaches is renamed allowDevToolAccess. The old key is ignored, so an existing false opt-out reverts to on (1.0.79) Source https://github.com/github/copilot-cli/blob/main/changelog.md</description>
</item>
<item>
<title>Breaking change on 2026-08-10: Sandbox keys sandbox.gitAuth and sandbox.ghAuth moved to sandbox.auth.git and sandbox.auth.gh with no migration, and SDK requests that send the old keys are rejected (1.0.79)</title>
<link>https://www.anchorterminal.com/tools/github-copilot-cli#pricing</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/github-copilot-cli#dep-2026-08-10-breaking</guid>
<pubDate>Mon, 10 Aug 2026 00:00:00 +0000</pubDate>
<category>change</category>
<description>Sandbox keys sandbox.gitAuth and sandbox.ghAuth moved to sandbox.auth.git and sandbox.auth.gh with no migration, and SDK requests that send the old keys are rejected (1.0.79) Source https://github.com/github/copilot-cli/blob/main/changelog.md</description>
</item>
</channel>
</rss>
