Fetching from the wire…
Tools2026-09-25 · source-backed
Public preview as of September 23: extra read/write, read-only and denied folder lists, outbound and local network controls, and gating on Git HTTPS and GitHub CLI credentials. If the OS can't enforce the policy, the sandboxed shell errors out instead of running unsandboxed. (changelog) Enabled per project or with /sandbox on, and it doesn't cover cloud or remote-host sessions. Fail-closed is the correct default for this and it's good to see it written down; shipping it off by default means almost nobody will have it on.
Each link below shares sources, entities, or timing with this story.
Enterprise-managed MCP allowlists shipped August 6 across the Copilot app, Copilot CLI and VS Code, configured with allowedMcpServers and deniedMcpServers in copilot/managed-settings.json inside the org's .github-private repo. Match by serverUrl with wildcards for remote HTTP/...
As of September 9, Copilot Business and Enterprise admins set which agent operations are blocked, require human approval, or run unprompted across shell commands, file reads and edits, and network domains. Restrictions can't be weakened by user or workspace settings, auto-appr...
NVD published 28 CVEs against sooperset/mcp-atlassian on September 22, all fixed in 0.22.0 back in July. CVE-2026-77244 lets the HTTP transport accept requests with no verified identity and fall back to the operator's global Jira and Confluence credentials. Others cover upload...
Work Life Panda hit #10 September 12 with 74 votes selling "every task, every calendar, one app, private on-device AI" against Motion and Reclaim. The same window produced Show HN posts for Sheet Insights BI (local Excel and CSV dashboards), Portspan (self-hosted ngrok alterna...
Announced September 2, the Copilot app and CLI now respect exclusion policies configured by enterprise, org and repository administrators. Until this shipped, exclusion policies were enforced in some surfaces but not the agentic app and CLI paths, meaning a policy that looked...
The September 24 changelog says eligible GA features, the Copilot Code Review policy and MCP servers in Copilot among them, flip on for Business and Enterprise orgs that left them unconfigured. Admins get a 28-day window and a new "Default policy for new features" setting unde...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.