[deps-release-notes] copilot-cli — upstream release action items
维护者通常 6 天内回复
还没有人认领这个 Issue。
评估
调研方向
这是一个用于跟踪依赖项更新的 issue。工作内容包括阅读 copilot-cli 版本 1.0.88 的链接发布说明,理解与托管设置和 OAuth 相关的安全修复,并确认是否有任何 ado-aw 功能使用了受影响的 CLI 模式(--acp、--ahp-host、--server)。首先查看标题为 'chore(deps): update COPILOT_CLI_VERSION to 1.0.88' 的配套版本更新 PR 以及仓库的工作流配置。当发布中的行动项被评估且所有必要的更新被记录或实施后,即视为完成。
由索引模型根据 Issue 内容生成。
描述
Rolling upstream release action items — copilot-cli
This is the single canonical tracking issue for action items arising from
new releases of the copilot-cli dependency. The update-awf-version workflow
appends a new comment to this issue for each version bump going forward, so
the most recent activity lives in the comments below. This body is a
consolidated history of everything filed so far.
Latest pinned version covered: 1.0.88
Consolidated history (earliest → latest)
1.0.48 → 1.0.56 (was #803)
- Security: secret scanning covers commit messages + PR descriptions (v1.0.51): Redacts secrets before publishing.
- Security:
permissions.disableBypassPermissionsMode(v1.0.55): Prevents enabling allow-all/yolo mode; relevant for sandboxed pipelines. --session-id=<id>flag (v1.0.51): Resume/start sessions with a specific UUID — useful for pipeline correlation.postToolUsehookadditionalContextinjected as system message (v1.0.49): Instead of being discarded.preMcpToolCallhook (v1.0.51): Control outgoing MCP request metadata.deferred-tool-loadingfrontmatter for custom agents (v1.0.52): Reduces initial token overhead.- MCP tools with both
content+structuredContentsurface both (v1.0.56): Review ado-aw MCP tools to ensure dual output is intentional. - Context window tier selection (v1.0.52): Default ~200K vs 1M tokens enforced end-to-end.
- Claude Opus 4.8 support (v1.0.55).
- Deprecation:
oauth.clientId/oauth.callbackPort→oauthClientId/auth.redirectPort(v1.0.52).
1.0.48 → 1.0.59 (was #843)
- Breaking:
preToolUsehook errors now deny the tool call (v1.0.57): Previously hook errors silently allowed execution; now they block the call. - Breaking: Remote JSON RPC enabled by default (v1.0.58): Verify this doesn't open unexpected network surface in AWF-sandboxed environments.
- Breaking:
--plugin-dirskills take precedence over personal-home skills (v1.0.55): Skill resolution order: project > plugin-dir > personal > custom. - ADO-only repos: built-in GitHub MCP server exposes only
web_search(v1.0.57): Directly relevant to ado-aw; consider whether the GitHub MCP extension should account for ADO-repository detection.
1.0.48 → 1.0.60 (was #881)
- Alpine Linux (musl libc) support (v1.0.49): Now runs on Alpine-based containers.
- Rubber Duck agent enabled by default (v1.0.58): Check whether this adds unexpected turn overhead in automated runs.
1.0.60 → 1.0.61 (was #951)
- Auto-load MCP servers from
.github/mcp.json(v1.0.61): ado-aw uses--additional-mcp-config; consider guarding against auto-loading interference. - Claude Fable 5 model support (v1.0.61): Add to validated models in
src/engine.rs/docs/engine.md. - mTLS + private-CA for OTLP telemetry (v1.0.61): Added
http/protobufOTLP export via OTel env vars. - Bug fix:
grep/globsingle-path fix (v1.0.61): Previously missed results with single path argument. - Bug fix: shell validation false positives (v1.0.61): Fixed blocking of harmless commands with words like "kill" in string literals/heredocs.
1.0.60 → 1.0.62 (was #1002)
- Breaking:
write_bashinteractive input removed (v1.0.62): Shell commands now use lightweight process spawning; interactive input no longer supported. ado-aw exposeswrite_bashas a first-class tool — assess whether tool surface/docs need updating. - Configure subagent model, reasoning effort, context tier (v1.0.62): Consider surfacing
reasoning_effort/context-tier as front-matter fields. - Kerberos/SPNEGO proxy auth (v1.0.62): Auto-auth through corporate forward proxies; relevant for enterprise ADO environments.
1.0.62 → 1.0.63 (was #1057)
deferToolsMCP server config option (v1.0.63): Keeps server tools available even when tool search is enabled. ado-aw could use this for safe-outputs and GitHub MCP servers to prevent them from being filtered out.
1.0.62 → 1.0.64 (was #1183)
- New OTel cache + reasoning token fields (v1.0.64):
gen_ai.usage.cache_read.input_tokens,gen_ai.usage.cache_creation.input_tokens,gen_ai.usage.reasoning.output_tokensper GenAI semconv (old underscore-separated names gone). Updatesrc/agent_stats.rsto parse new attribute names. - Static OAuth client overrides for MCP server auth (v1.0.64): ado-aw could expose in MCP server config front-matter.
- Autopilot mode auto-handles
ask_user, elicitation, sampling, permission prompts (v1.0.64): Reliability improvement for unattended pipeline runs. - Deprecation:
report_intenttool removed (v1.0.64):INTERNAL_TOOL_NAMESexclusion insrc/agent_stats.rscontaining"execute_tool report_intent"is now dead code; can be cleaned up.
1.0.64 → 1.0.67 (was #1272)
- Claude Sonnet 5 model support (v1.0.67): Add to
src/engine.rsmodel allowlist + docs. - Subagent sessions inherit parent tool restrictions (v1.0.67): Security-relevant behavior change; verify against expected security model.
- MCP OAuth against Microsoft Entra vanity domain servers (v1.0.67): Fixes
AADSTSauth failures for Entra vanity domains; relevant for enterprise Azure AD MCP tools. copilot skillsubcommand (v1.0.65): New/skillalias for listing/adding/removing skills; may be relevant for agency plugin scaffolding.- Deprecation: Claude Opus 4.6 Fast → Claude Opus 4.8 Fast (v1.0.66): Update any ado-aw references to
claude-opus-4.6-fast.
1.0.64 → 1.0.68 (was #1305)
- Breaking: session limits require minimum 30 AI credits (v1.0.67): Pipelines with
session-limit:below 30 AI credits will be rejected at runtime. Review compiler defaults. - Claude Opus 4.8 Fast model support (v1.0.66): Add
claude-opus-4.8-fasttosrc/engine.rsallowlist. - kimi-k2.7-code model support (v1.0.68): Add to model allowlist.
1.0.70 → 1.0.81 (was #2041)
- Breaking (v1.0.79): Sandbox settings keys renamed from
sandbox.gitAuth/sandbox.ghAuthtosandbox.auth.git/sandbox.auth.gh, with no migration path. Old keys are silently ignored, and SDK requests using the old keys are rejected as invalid. Any ado-aw-generated engine config or docs referencing the old sandbox setting names need to be updated. See the v1.0.79 release. - Breaking (v1.0.79):
--worktreedefault behavior changed —worktreeBaseRefnow defaults toHEADinstead of the remote default branch. Could change output for any ado-aw workflow relying on worktree creation defaults. See the v1.0.79 release. - Security (v1.0.78): The
/allow-all autosafety-judge model is no longer user-configurable — hardens against downgrade to a weaker safety judge. See the v1.0.78 release. - Security (v1.0.78): Managed-settings fetch failure behavior changed from fail-closed to fail-open — worth confirming this doesn't weaken ado-aw's sandboxed-agent posture when managed settings can't be reached. See the v1.0.78 release.
- Security (v1.0.72): Sandbox macOS keychain access now defaults to off, reducing default credential exposure inside the sandboxed agent. See the v1.0.72 release.
- v1.0.81: Support for MCP protocol version 2026-07-28, OpenTelemetry trace-context propagation (
traceparent/tracestate) into hooks, and per-agent usage metrics via--usage-output-file— could improve ado-aw's OTel-based agent stats correlation (src/agent_stats.rs). See the v1.0.81 release. - v1.0.81: Windows Entra ID broker-based MCP auth (no-prompt sign-in) — relevant if ado-aw ever needs Windows-hosted agent auth flows.
- v1.0.81: Plan mode now hard-blocks mutating tool calls — a safety property ado-aw could rely on/document for plan-only agent configurations.
- v1.0.76/v1.0.77: Enterprise admins can enforce a restrictive sandbox floor and managed sandbox policy via macOS/Windows native MDM — relevant to ado-aw's OneBranch sandboxing story for enterprise consumers. See the v1.0.76 release and v1.0.77 release.
- v1.0.72: Opt-in git/gh auth inside the OS sandbox — worth evaluating against ado-aw's own credential-isolation model (
ado-proxy).
1.0.87 → 1.0.88 (was #2232) — canonical
- None identified. This is a routine point release with terminal/UX and MCP reliability fixes.
- Security: Enterprise managed settings now apply to sessions opened in ACP mode (
copilot --acp), by AHP hosts (copilot --ahp-host), and by the published--serversession, which previously ran with no managed MCP, permission, or plugin policy (v1.0.88). ado-aw invokes the CLI in its default sandboxed one-shot mode, not--acp/--ahp-host/--server, so no immediate action, but worth confirming if any future ado-aw feature drives the CLI through one of those modes. - Security: GitHub MCP scope escalation now uses the CLI OAuth app's registered
/callbackredirect URI (v1.0.88) — tightens an OAuth flow ado-aw does not directly configure. - No notable features identified as directly adoptable by ado-aw in this range. No deprecations identified in this range.
Consolidated by the Deps Release-Notes Consolidator workflow. Superseded per-release issues were closed and point here.> Generated by Deps Release-Notes Consolidator · auto · 74.6 AIC · ⌖ 4.15 AIC · ⊞ 9.6K · ◷
- 主要语言
- Rust
- 星标
- 27
- 派生
- 8
- 平均合并
- 2 天 21 小时
- 30 天内合并 PR
- 9
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 没有贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
githubnext/ado-aw 的其他 Issue
-
docs documentation
难度 1/5 1 小时以内 新手友好度 85/100
githubnext/ado-aw#1766 ·
维护者通常 6 天内回复
-
agentic-workflows
难度 2/5 1-3 小时 新手友好度 68/100
githubnext/ado-aw#1041 ·
维护者通常 6 天内回复
-
security
难度 2/5 1-3 小时 新手友好度 76/100
githubnext/ado-aw#855 ·
维护者通常 6 天内回复
-
refactor rust
难度 2/5 1-3 小时 新手友好度 68/100
githubnext/ado-aw#384 ·
维护者通常 6 天内回复
-
agentic-workflows
难度 4/5 3-5 天 新手友好度 45/100
githubnext/ado-aw#2295 ·
维护者通常 6 天内回复
查看 githubnext/ado-aw 的全部 Issue
相似的 Issue
-
documentation
难度 1/5 1 小时以内 新手友好度 90/100
fastrevmd-lab/rustmistmcp#161 ·
-
arch-audit refactor
难度 2/5 1-3 小时 新手友好度 82/100
SocketDev/socket-patch#1011 ·
维护者通常 1 天内回复
-
bug user-priority/P2
难度 1/5 1 小时以内 新手友好度 92/100
维护者通常 1 天内回复
-
opencode: an unanswered --version probe launches opencode 2 without per-session service isolation未关闭
难度 2/5 1-3 小时 新手友好度 84/100
维护者通常 1 天内回复
-
security-advisory
难度 2/5 1-3 小时 新手友好度 85/100
MinBZK/regelrecht#1686 ·
维护者通常 1 天内回复