16 × AIAI signal, amplified
AI newsTopicsAboutSources
TelegramFollow on Telegram
AI newsTopicsAboutSources
16 × AIAI signal, amplified

An AI news engine that ingests trusted sources, scores with Claude, and posts only what clears the bar.

Follow on Telegram →

Subscribe

  • Telegram
  • RSS
  • All channels

Newsletter

Used only to send this newsletter. Privacy

Legal

  • Privacy
  • Imprint
© 2026 16 × AI. All rights reserved.A new issue every two days.
Home/Coding Tools
Coding Tools

GitHub Copilot adds local sandboxing for agents

GitHub Changelog·October 7, 2026·high confidence

Why it matters

  • →Enables safer autonomous coding by isolating agent actions from the host system.
  • →Allows enterprises to enforce security policies on AI-generated code execution.
  • →Reduces risk of accidental data exposure or unauthorized network access by agents.
GitHub Copilot adds local sandboxing for agents
©GitHub Changelog

GitHub has made local sandboxing generally available for GitHub Copilot CLI, the standalone app, and VS Code sessions via Agent Host. The feature uses Microsoft eXecution Container (MXC) to enforce restricted access boundaries for agent-run commands, limiting permissions for filesystem, network, and credential usage. Policies can be defined by individual developers or enforced centrally by enterprises through managed settings. This capability is included at no additional cost with existing Copilot subscriptions.

Read original

The story around this

Earlier coverage that leads up to this article, and what followed. Lines connect each piece to the closest one after it, converging here.

GitHub Introduces Managed Permissions for Copilot — GitHub Changelog1GitHub Copilot adds local sandboxing — GitHub Changelog2GitHub Copilot adds local sandboxing for agentsMicrosoft Copilot gains local file access and OS actions — The Verge AI3Sep 9You are hereOct 7

How we got here

  1. 1
    GitHub Introduces Managed Permissions for Copilot

    GitHub Changelog · September 9, 2026 · Same story

  2. 2
    GitHub Copilot adds local sandboxing

    GitHub Changelog · September 23, 2026 · Same story

What happened next

  1. 3
    Microsoft Copilot gains local file access and OS actions

    The Verge AI · October 7, 2026 · Related

More from GitHub Changelog

Claude Haiku 5.5 arrives in GitHub Copilot© GitHub Changelog
Models & Labscoding

Claude Haiku 5.5 arrives in GitHub Copilot

Anthropic’s latest lightweight model is now live inside GitHub Copilot, targeting high-volume coding tasks like subagents and terminal work. Early benchmarks suggest it matches Sonnet 5 on many coding challenges while consuming significantly fewer tokens and steps. This availability across VS Code, JetBrains, and mobile apps gives developers a faster, cheaper option for routine edits without sacrificing quality. The gradual rollout means most users will see it soon, with admin controls allowing enterprises to manage access via model policies.

GitHub Changelog·Oct 7, 2026
GitHub deploys fine-tuned model for secret detection© GitHub Changelog
Coding Toolscoding

GitHub deploys fine-tuned model for secret detection

GitHub is replacing its regex-based secret scanning with a purpose-built AI model that understands code context to catch unstructured credentials like passwords without standard token formats. This shift moves security from pattern matching to semantic understanding, catching leaks that traditional tools miss before they hit repository history via push protection. The upgrade is automatic for existing GHSP/GHAS customers, but new opt-in features in Copilot and push protection will consume AI Credits, introducing a usage-based cost layer to what was previously free. This marks a significant pivot in how developers handle security, blending LLM capabilities directly into the CI/CD pipeline.

GitHub Changelog·Oct 7, 2026
GitHub Copilot CLI v1.0.94 adds local Ollama model discovery© GitHub Changelog
Coding Toolscoding

GitHub Copilot CLI v1.0.94 adds local Ollama model discovery

GitHub finally bridges the gap between cloud-heavy Copilot and local inference by letting the CLI discover models from a running Ollama instance. Version 1.0.94-0 introduces a /model command that surfaces supported local weights alongside cloud options, allowing developers to switch contexts without restarting the session. This isn't just a toggle; it requires tool calling and streaming support, forcing a quality baseline for local providers. The move signals GitHub's recognition that enterprise workflows increasingly demand hybrid setups where sensitive code stays on-prem while general assistance remains in the cloud.

GitHub Changelog·Oct 7, 2026

More in Coding Tools

Microsoft Surface RTX Spark Dev Box Preorders Open© The Verge AI
Coding Toolscoding

Microsoft Surface RTX Spark Dev Box Preorders Open

Microsoft is selling a dedicated AI development rig for $5,999, targeting developers who need local inference power without building their own hardware. The device pairs Nvidia’s Arm-based RTX Spark platform with 128GB of unified memory, enabling it to run models exceeding 120B parameters on-device. It ships pre-configured with Windows 11 Pro and essential dev tools like VS Code and GitHub Copilot, effectively bundling the software stack with the silicon. This moves local AI from a DIY enthusiast project to a standardized enterprise-grade appliance, albeit at a premium price point that limits it to professional workflows rather than consumer hobbyists.

The Verge AI·Oct 7, 2026
Coding Toolscoding

Claude Code v2.1.290: Plugin hooks and agent stability fixes

This release significantly tightens the security model for Claude Code plugins by exposing server tool IDs and approval ceilings to hook functions, allowing developers to build more granular permission checks. It also stabilizes long-running agent sessions by fixing critical bugs in subagent resume logic and scheduled task persistence after compaction. For plugin authors, the new validation flags ensure gating hooks are properly configured before deployment. These changes make the platform safer for enterprise use while reducing friction for complex automated workflows.

Claude Code Releases·Oct 6, 2026
Coding Toolscoding

llama.cpp b11424 adds CUDA 13 and ROCm 10.0

This release quietly closes the hardware gap for local inference by adding default support for CUDA 13 and ROCm 10.0 alongside existing CUDA 12 builds. NVIDIA users can now leverage newer driver stacks without manual configuration, while AMD GPU owners finally get first-class parity with the same ease of use previously reserved for CUDA. Apple Silicon KleidiAI is disabled in this specific build, a notable regression for Mac users who rely on that optimization. The inclusion of Snapdragon and OpenVINO binaries further broadens the reach to edge devices and Intel hardware. It’s less about new features and more about llama.cpp solidifying its position as the universal runtime for every major accelerator.

llama.cpp Releases·Oct 6, 2026