Add a CLI flag to temporarily trust a workspace in non-interactive sessions (e.g. --temporarily-trust-workspace)
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 58/100
Línea de trabajo
Empieza rastreando cómo las sesiones no interactivas -p gestionan el aviso de confianza del workspace y cómo la carga de workspace .mcp.json depende de la confianza; revisa issue #4542 para ver el contexto relacionado. Se considera terminado cuando un flag documentado concede confianza para una sola invocación, permite cargar la configuración del workspace confirmada sin un TTY y no persiste la decisión de confianza.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Describe the feature or problem you'd like to solve
Workspace .mcp.json config is only honored once a workspace has been marked "trusted," and the only way to grant that trust today is by starting an interactive session and answering "Yes" to the trust prompt. There is currently no way to trust a workspace from a non-interactive (-p) session, a scripted/CI environment, or any headless context. This was confirmed by a maintainer on #4542: workspace .mcp.json loading was fixed in 1.0.85, but only takes effect if the workspace is already trusted, and there's no CLI-only way to establish that trust. This makes committed, repo-scoped .mcp.json files effectively unusable in automated or headless workflows (CI pipelines, containers, scripted invocations) even though the underlying loading bug is fixed, because there's no non-interactive path to the trust step.
Proposed solution
Add a flag (e.g. --temporarily-trust-workspace, name open to maintainer preference) that grants the current working directory workspace trust for the duration of that single invocation, without requiring the interactive TUI trust prompt.
This would let users and CI systems opt into trusting a specific workspace explicitly and auditably per-invocation, rather than requiring either a persisted trust decision made interactively beforehand, or the --additional-mcp-config workaround that duplicates the already-committed .mcp.json.
Benefits:
- Unblocks CI/automation and headless use of workspace-scoped .mcp.json
- Avoids requiring users to persist trust ahead of time via the interactive flow
- Avoids the --additional-mcp-config duplication workaround
- Keeps trust explicit and scoped to one invocation, rather than silently trusting all workspaces
Example prompts or workflows
-
CI pipeline step:
copilot --temporarily-trust-workspace --allow-all-tools -p "Run the test suite and summarize failures"— using the repo's committed .mcp.json without a prior interactive trust step. -
Docker/headless container: running scripted
copilot -p "..."invocations where no TTY is available to answer the interactive trust prompt. -
One-off automation script that clones a repo, trusts it for a single non-interactive Copilot invocation, and never persists that trust decision to the user's config.
Additional context
#4542
- Lenguaje dominante
- Shell
- Estrellas
- 11.2k
- Forks
- 1.9k
- Merge medio
- 14 h 16 min
- PR fusionados (30 d)
- 6
Guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de github/copilot-cli
-
triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
github/copilot-cli#4932 ·
-
triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
github/copilot-cli#4909 ·
-
triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
github/copilot-cli#4906 ·
-
triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
github/copilot-cli#4848 ·
-
area:agents area:mcp
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
github/copilot-cli#4729 ·
Todos los issues de github/copilot-cli
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
elastic/gradle-plugins#156 ·
-
Priority/High ready-for-agent Severity/Major Type/Bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
-
comp/cli P3 type/docs
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
NousResearch/hermes-agent#119756 · 1 comentario ·
-
comp: build/pipeline type: bug version: current (v17+)
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
angular/angularfire#3766 ·
-
out-of-date
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
CachyOS/CachyOS-PKGBUILDS#1903 ·