Vibe Coding
Copilot CLI 1.0.88: ACP, AHP-host and --server sessions had been running with no enterprise MCP, permission or plugin policy
GitHub Copilot CLI v1.0.88 (2026-09-22) says enterprise managed settings now apply to sessions opened with `copilot --acp`, by `--ahp-host` hosts, and by the published `--server` session, which 'previously ran with no managed MCP, permission, or plugin policy.' Any org that embedded Copilot CLI in an editor through ACP had policy gaps until this release. The same release stops an exact session approval for a missing path from also granting its parent directory.
Source
↳ Follow the thread