diff --git a/content/actions/how-tos/reuse-automations/reuse-workflows.md b/content/actions/how-tos/reuse-automations/reuse-workflows.md index 97dd9dbfa421..2522bb371538 100644 --- a/content/actions/how-tos/reuse-automations/reuse-workflows.md +++ b/content/actions/how-tos/reuse-automations/reuse-workflows.md @@ -72,8 +72,14 @@ You can define inputs and secrets, which can be passed from the caller workflow In the example above, `personal_access_token` is a secret that's defined at the repository or organization level. + To use an environment secret in a reusable workflow, set `environment` on the job in the reusable workflow. The job that calls the reusable workflow can't use the `environment` keyword. For more information, see [AUTOTITLE](/actions/how-tos/deploy/configure-and-manage-deployments/manage-environments). + + The caller workflow must still pass the secret. Use `secrets: inherit` or pass the secret by name, for example {% raw %}`MY_SECRET: ${{ secrets.MY_SECRET }}`{% endraw %}. You can pass a secret by name even if it only exists in the environment. + + If an environment secret has the same name as a repository or organization secret, the environment secret takes precedence. This applies when the caller uses either `secrets: inherit` or {% raw %}`${{ secrets.MY_SECRET }}`{% endraw %}. The job that sets `environment` receives the environment secret's value. + > [!WARNING] - > Environment secrets cannot be passed from the caller workflow as `on.workflow_call` does not support the `environment` keyword. If you include `environment` in the reusable workflow at the job level, the environment secret will be used, and not the secret passed from the caller workflow. For more information, see [AUTOTITLE](/actions/how-tos/deploy/configure-and-manage-deployments/manage-environments) and [AUTOTITLE](/actions/reference/workflows-and-actions/workflow-syntax#onworkflow_call). + > If the caller workflow doesn't pass an environment secret, the secret resolves to an empty string in the reusable workflow. The workflow run doesn't show an error. To make the workflow run fail instead, set `required: true` for the secret in [`on.workflow_call.secrets`](/actions/reference/workflows-and-actions/workflow-syntax#onworkflow_callsecrets). This setting only checks whether the caller workflow passes the secret. It doesn't check whether the secret has a value. 1. Pass the input or secret from the caller workflow. diff --git a/content/admin/enforcing-policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-code-security-and-analysis-for-your-enterprise.md b/content/admin/enforcing-policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-code-security-and-analysis-for-your-enterprise.md index 8c5a01aa3b59..32e89c809be1 100644 --- a/content/admin/enforcing-policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-code-security-and-analysis-for-your-enterprise.md +++ b/content/admin/enforcing-policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-code-security-and-analysis-for-your-enterprise.md @@ -109,6 +109,21 @@ Across all of your enterprise's organizations, you can allow or disallow people {% endif %} +{% ifversion secret-scanning-actions-logs %} + +## Enforcing a policy for secret scanning in {% data variables.product.prodname_actions %} workflow logs + +As an enterprise owner, you can choose whether {% data variables.product.github %} scans {% data variables.product.prodname_actions %} workflow logs for secrets. This policy is disabled by default. + +When you enable the policy, {% data variables.product.github %} scans the logs of new workflow runs in all repositories in your enterprise where {% data variables.product.prodname_secret_scanning %} is enabled. + +{% data reusables.enterprise-accounts.access-enterprise %} +{% data reusables.enterprise-accounts.policies-tab %} +{% data reusables.enterprise-accounts.code-security-and-analysis-policies %} +1. Under "Secret scanning for Actions workflow logs", select the **All repositories** dropdown menu, then click **Enabled** or **Disabled**. + +{% endif %} + {% ifversion code-scanning-autofix %} ## Enforcing a policy to manage the use of {% data variables.copilot.copilot_autofix_short %} in your enterprise's repositories diff --git a/content/admin/managing-iam/configuring-authentication-for-enterprise-managed-users/configuring-saml-single-sign-on-for-enterprise-managed-users.md b/content/admin/managing-iam/configuring-authentication-for-enterprise-managed-users/configuring-saml-single-sign-on-for-enterprise-managed-users.md index 9ce536b66f59..85d9b934ec31 100644 --- a/content/admin/managing-iam/configuring-authentication-for-enterprise-managed-users/configuring-saml-single-sign-on-for-enterprise-managed-users.md +++ b/content/admin/managing-iam/configuring-authentication-for-enterprise-managed-users/configuring-saml-single-sign-on-for-enterprise-managed-users.md @@ -103,7 +103,6 @@ After the initial configuration of SAML SSO, the only setting you can update on > [!NOTE] > {% data reusables.enterprise-accounts.emu-password-reset-session %} -1. If you're using a **non-partner IdP** (an IdP other than Okta, PingFederate or Entra ID), before enabling SAML, you must update a setting so that you will be able to set up SCIM using the REST API. See [AUTOTITLE](/admin/managing-iam/provisioning-user-accounts-with-scim/configuring-scim-provisioning-for-users#configuring-provisioning-for-other-identity-management-systems). {% data reusables.enterprise-accounts.access-enterprise %} {% data reusables.enterprise-accounts.identity-provider-tab %} {% data reusables.enterprise-accounts.sso-configuration %} @@ -123,6 +122,7 @@ After the initial configuration of SAML SSO, the only setting you can update on > After you require SAML SSO for your enterprise and save SAML settings, the setup user will continue to have access to the enterprise and will remain signed in to GitHub along with the {% data variables.enterprise.prodname_managed_users %} provisioned by your IdP who will also have access to the enterprise. {% data reusables.enterprise-accounts.download-recovery-codes %} +1. If you're using a **non-partner IdP** (an IdP other than Okta, PingFederate or Entra ID), after enabling SAML, you must update a setting so that you will be able to set up SCIM using the REST API. See [AUTOTITLE](/admin/managing-iam/provisioning-user-accounts-with-scim/configuring-scim-provisioning-for-users#configuring-provisioning-for-other-identity-management-systems). ### Enable provisioning diff --git a/content/billing/how-tos/set-up-payment/connect-azure-sub.md b/content/billing/how-tos/set-up-payment/connect-azure-sub.md index 8ad8db19b748..dcf11ab3814b 100644 --- a/content/billing/how-tos/set-up-payment/connect-azure-sub.md +++ b/content/billing/how-tos/set-up-payment/connect-azure-sub.md @@ -32,6 +32,8 @@ You can pay for metered usage of {% data variables.product.github %} features th * You must be logged into Azure as a user who is able to provide tenant-wide admin consent or arrange to work with a Microsoft Entra Global Administrator to configure an admin consent workflow. See [AUTOTITLE](/billing/concepts/azure-subscriptions). +>[!NOTE] If your organization or enterprise has recently signed up for {% data variables.product.prodname_copilot %} with a credit card or PayPal, you may not be able to change your payment method to an Azure subscription. Please [contact {% data variables.product.github %}'s Sales team](https://github.com/enterprise/contact?ref_product=copilot&ref_type=engagement&ref_style=text). + ## Connecting your Azure subscription to an organization or enterprise account {% data reusables.billing.nav-to-org-or-ent %} diff --git a/content/code-security/concepts/secret-security/secret-scanning-for-partners.md b/content/code-security/concepts/secret-security/secret-scanning-for-partners.md index c3489cc9656d..9872b943df6d 100644 --- a/content/code-security/concepts/secret-security/secret-scanning-for-partners.md +++ b/content/code-security/concepts/secret-security/secret-scanning-for-partners.md @@ -16,7 +16,7 @@ category: ## About {% data variables.secret-scanning.partner_alerts %} -{% data variables.product.github %} scans public repositories and public npm packages for secrets issued by specific service providers who joined our partnership program, and alerts the relevant service provider whenever a secret is detected in a commit. The service provider validates the string and then decides whether they should revoke the secret, issue a new secret, or contact you directly. Their action will depend on the associated risks to you or them. {% data reusables.secret-scanning.partner-program-link %} +{% data variables.product.github %} scans public repositories and public npm packages for secrets issued by specific service providers who joined our partnership program, and alerts the relevant service provider whenever a secret is detected in a supported location. The service provider validates the string and then decides whether they should revoke the secret, issue a new secret, or contact you directly. Their action will depend on the associated risks to you or them. {% data reusables.secret-scanning.partner-program-link %} > [!NOTE]You cannot change the configuration of {% data variables.product.prodname_secret_scanning %} for partner patterns on public repositories. diff --git a/content/code-security/concepts/secret-security/secret-scanning.md b/content/code-security/concepts/secret-security/secret-scanning.md index f76e1faf7f63..48cf1281c3db 100644 --- a/content/code-security/concepts/secret-security/secret-scanning.md +++ b/content/code-security/concepts/secret-security/secret-scanning.md @@ -35,6 +35,25 @@ When credentials like API keys and passwords are committed to repositories as ha {% data reusables.secret-scanning.what-is-scanned %} +{% ifversion secret-scanning-actions-logs %} + +### Secrets detected in {% data variables.product.prodname_actions %} workflow logs + +> [!NOTE] +> Detection of secrets in {% data variables.product.prodname_actions %} workflow logs is in {% data variables.release-phases.public_preview %} and is subject to change. + +{% data variables.product.prodname_actions %} workflow log scanning is disabled by default. Enterprise owners can enable it for all repositories in their enterprise. For more information, see [AUTOTITLE](/admin/enforcing-policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-code-security-and-analysis-for-your-enterprise#enforcing-a-policy-for-secret-scanning-in-github-actions-workflow-logs). + +Once enabled, {% data variables.product.github %} scans the logs of each new workflow run after the run completes, for repositories where {% data variables.product.prodname_secret_scanning %} is enabled. Logs from past workflow runs aren't scanned. + +For {% data variables.product.prodname_actions %} workflow logs, {% data variables.product.prodname_secret_scanning %} only detects provider patterns. It doesn't detect generic patterns, custom patterns, {% data variables.secret-scanning.ai-detected-secrets %}, or values that {% data variables.product.prodname_actions %} masks in the log. + +Alerts for secrets in {% data variables.product.prodname_actions %} workflow logs don't generate notifications during the {% data variables.release-phases.public_preview %}. To review these alerts, check the repository's {% data variables.product.prodname_secret_scanning %} alerts. + +A single alert may reference multiple locations if the same secret appeared across several workflow runs or jobs. For each location, the alert links to the workflow file where the secret originated and the log line where the secret was printed. The alert does not include an inline preview of the log content. + +{% endif %} + ### {% data variables.product.prodname_secret_scanning_caps %} alerts and remediation When {% data variables.product.prodname_secret_scanning %} detects a credential leak, {% data variables.product.github %} generates an alert on your repository's **{% data variables.product.prodname_security_and_quality_tab %}** tab with details about the exposed credential. diff --git a/content/code-security/how-tos/manage-security-alerts/manage-secret-scanning-alerts/resolving-alerts.md b/content/code-security/how-tos/manage-security-alerts/manage-secret-scanning-alerts/resolving-alerts.md index bd97d1dd7400..c7a82aa82beb 100644 --- a/content/code-security/how-tos/manage-security-alerts/manage-secret-scanning-alerts/resolving-alerts.md +++ b/content/code-security/how-tos/manage-security-alerts/manage-secret-scanning-alerts/resolving-alerts.md @@ -24,6 +24,25 @@ Once a secret has been committed to a repository, you should consider the secret 1. Review and update any services that use the old token. For {% data variables.product.github %} {% data variables.product.pat_generic %}s, delete the compromised token and create a new token. See [AUTOTITLE](/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens). 1. Depending on the secret provider, check your security logs for any unauthorized activity. +{% ifversion secret-scanning-actions-logs %} + +### Fixing alerts for secrets in {% data variables.product.prodname_actions %} workflow logs + +> [!NOTE] +> Detection of secrets in {% data variables.product.prodname_actions %} workflow logs is in {% data variables.release-phases.public_preview %} and is subject to change. + +When a secret is detected in a {% data variables.product.prodname_actions %} workflow log, follow these steps in order. + +1. Review the alert and linked job log to identify the credential and the source of the exposure. The secret may have been printed by the workflow, an action, or another dependency. +1. Check whether the credential is still valid. {% ifversion fpt or ghec %}See [Checking a secret's validity](/code-security/tutorials/remediate-leaked-secrets/evaluating-alerts#checking-a-secrets-validity). {% endif %}If the credential is active or you cannot confirm its status, rotate or revoke it immediately using the secret provider's dashboard. +1. Fix the source of the exposure. For example, update the workflow or dependency, remove hardcoded secrets, or store credentials as encrypted secrets. See [AUTOTITLE](/actions/security-for-github-actions/security-guides/using-secrets-in-github-actions). +1. If necessary, add `::add-mask::` to redact the value from future log output. + +> [!WARNING] +> Do not rerun the workflow until you have fixed the exposure source. Rerunning the workflow without addressing the root cause may re-expose the secret. + +{% endif %} + {% ifversion secret-scanning-report-secret-github-pat %} ### Reporting a leaked secret in a private repository diff --git a/content/copilot/concepts/agents/copilot-cli/about-custom-agents.md b/content/copilot/concepts/agents/copilot-cli/about-custom-agents.md index dfb5390d8158..7eb1bd111c43 100644 --- a/content/copilot/concepts/agents/copilot-cli/about-custom-agents.md +++ b/content/copilot/concepts/agents/copilot-cli/about-custom-agents.md @@ -31,7 +31,7 @@ In addition to the main {% data variables.product.prodname_copilot_short %} agen * **code-review** — Reviews code changes with an extremely high signal-to-noise ratio. This agent analyzes staged/unstaged changes and branch diffs, surfacing only issues that genuinely matter: bugs, security vulnerabilities, race conditions, memory leaks, and logic errors. It never comments on style or formatting. It will not make any changes to files. -* **research** — This agent operates as a staff-level software engineer and research specialist. It provides exhaustive, meticulously researched answers about codebases, APIs, libraries, and software architecture. It uses {% data variables.product.github %} search/exploration tools, web fetch/search, and local tools. Unlike the other agents, the research agent can only be invoked by using the `/research` slash command. It cannot be automatically triggered by the main agent. +* **research** — This agent operates as a staff-level software engineer and research specialist. It provides exhaustive, meticulously researched answers about codebases, APIs, libraries, and software architecture. It uses {% data variables.product.github %} search/exploration tools, web fetch/search, and local tools. You can invoke it explicitly using the `/research` slash command. The main agent can also delegate research work to it when appropriate. * **rubber-duck** — A constructive critic that gives {% data variables.product.prodname_copilot_short %} a second opinion on its own plans, code, and tests. It runs on a different model from the one driving your session, so it brings a complementary perspective. It is designed to review proposed changes, not to make file changes itself. For more information, see [AUTOTITLE](/copilot/concepts/agents/copilot-cli/rubber-duck). diff --git a/content/copilot/concepts/agents/copilot-cli/autopilot.md b/content/copilot/concepts/agents/copilot-cli/autopilot.md index af3db81b0499..8a7410d702d7 100644 --- a/content/copilot/concepts/agents/copilot-cli/autopilot.md +++ b/content/copilot/concepts/agents/copilot-cli/autopilot.md @@ -53,11 +53,11 @@ When entering autopilot mode, if you have not already granted {% data variables. ```text 1. Enable all permissions (recommended) -2. Continue with limited permissions +2. Use Manual Approval for this session 3. Cancel (Esc) ``` -You will get the best results from autopilot mode if you enable all permissions. If you choose to continue with limited permissions, {% data variables.product.prodname_copilot_short %} will automatically deny any tool requests that require approval, which may prevent it from completing certain tasks. You can change your mind later and grant full permissions, during an autopilot session, by using the `/allow-all` command (or its alias `/yolo`). +You will get the best results from autopilot mode if you enable all permissions. If you choose manual approval, {% data variables.product.prodname_copilot_short %} will automatically deny any tool requests that require approval, which may prevent it from completing certain tasks. You can change your mind later and grant full permissions, during an autopilot session, by using the `/allow-all` command (or its alias `/yolo`). Before granting {% data variables.product.prodname_copilot_short %} wide-ranging permissions, consider using local sandboxing, or running the session in a cloud sandbox, to limit what {% data variables.product.prodname_copilot_short %} can access. @@ -102,7 +102,7 @@ For example: * When the interactive session starts, if you're prompted to trust the files in the current folder, accept this option. * Press Shift+Tab to switch to plan mode, enter a prompt describing what you want to achieve, then work with {% data variables.product.prodname_copilot_short %} to create a detailed plan. -* Once you have a plan that you are happy with, use the option that the CLI presents to "Accept plan and build on autopilot". +* Once you have a plan that you are happy with, use the option that the CLI presents to "Accept plan and continue in Autopilot execution mode". * If you're prompted about permissions, choose the option to enable all permissions. * Leave {% data variables.product.prodname_copilot_short %} to implement the plan. You can check in on its progress periodically. diff --git a/content/copilot/concepts/agents/copilot-cli/fleet.md b/content/copilot/concepts/agents/copilot-cli/fleet.md index ed0f11065ef3..23b79d1c350e 100644 --- a/content/copilot/concepts/agents/copilot-cli/fleet.md +++ b/content/copilot/concepts/agents/copilot-cli/fleet.md @@ -66,7 +66,7 @@ A typical workflow for using `/fleet` in autopilot mode might look like this: 1. Press Shift+Tab to switch into plan mode and work with {% data variables.copilot.copilot_cli_short %} to create an implementation plan. 1. Recognize that the completed plan contains multiple elements and looks like a good candidate for `/fleet`. -1. Select the **Accept plan and build on autopilot + /fleet** option that's displayed when the plan is complete. +1. Select the **Accept plan and continue in Autopilot execution mode + /fleet** option that's displayed when the plan is complete. For more information about autopilot mode, see [AUTOTITLE](/copilot/concepts/agents/copilot-cli/autopilot). diff --git a/content/copilot/concepts/agents/copilot-cli/rubber-duck.md b/content/copilot/concepts/agents/copilot-cli/rubber-duck.md index 8436584cd772..526399a7aef1 100644 --- a/content/copilot/concepts/agents/copilot-cli/rubber-duck.md +++ b/content/copilot/concepts/agents/copilot-cli/rubber-duck.md @@ -49,24 +49,9 @@ When the rubber duck agent is consulted, it: The rubber duck agent has read-only access to your codebase via the standard exploration tools. It cannot edit files or run commands that change your environment. -## When {% data variables.product.prodname_copilot_short %} consults the rubber duck agent - -When the rubber duck agent is enabled, {% data variables.product.prodname_copilot_short %} is instructed to consult it at high-leverage moments rather than only when stuck. Typical situations include: - -* **After planning a non-trivial change, but before implementing it.** This is the highest-leverage moment to catch design flaws, while course corrections are still cheap. -* **Mid-implementation,** to check for blind spots in a complex piece of work. -* **After writing tests,** to validate that test coverage is comprehensive and that the behavior actually satisfies your original request. -* **Reactively, when {% data variables.product.prodname_copilot_short %} hits repeated failures or unexpected results,** to get an independent analysis of the problem rather than retrying the same approach. - -For small, well-understood changes {% data variables.product.prodname_copilot_short %} typically skips the rubber duck agent. - -When {% data variables.product.prodname_copilot_short %} consults the rubber duck agent, it summarizes the resulting critique for you in the timeline output rather than repeating it verbatim—for example, "The critique pointed out a blind spot in my plan around X, so I updated my plan to address that." - ## Manually invoking the rubber duck agent -Typically {% data variables.copilot.copilot_cli_short %} consults the rubber duck agent automatically. You don't need to do anything. The timeline output shows when the main agent is getting a rubber duck critique. However, sometimes the CLI will not use the rubber duck agent. For example, it may decide that the changes are not extensive enough to warrant a critique. - -You can use a natural language prompt to explicitly ask {% data variables.product.prodname_copilot_short %} to get a second opinion. For example, after asking {% data variables.product.prodname_copilot_short %} to produce a plan of work, you could enter a prompt such as: +By default, the rubber duck agent is not automatically invoked. You need to explicitly ask {% data variables.product.prodname_copilot_short %} for a critique each time you want one. For example, after asking {% data variables.product.prodname_copilot_short %} to produce a plan of work, you could enter a prompt such as: ```copilot Rubber duck your plan. @@ -84,6 +69,40 @@ You can also invoke the rubber duck agent with a slash command: /rubber-duck What edge cases are missing? ``` +## Auto-invoking the rubber duck agent + +If you want {% data variables.product.prodname_copilot_short %} to proactively consult the rubber duck agent without being asked, you can turn on auto-invocation for the agent from the `/subagents` picker. + +1. In an interactive {% data variables.copilot.copilot_cli_short %} session, enter `/subagents`. +1. Use the keyboard arrow keys to select the rubber duck agent, then press Enter. +1. Select **Proactive invocation** then press Enter to toggle the setting between off and on. +1. Use the escape key to exit the `/subagents` picker. + +Turning on auto-invocation for the rubber duck agent in this way updates your {% data variables.product.prodname_copilot_short %} settings file (typically `~/.copilot/settings.json`), so that your choice of setting persists for future sessions: + +```json +{ + "subagents": { + "agents": { + "rubber-duck": { + "autoInvoke": true + } + } + } +} +``` + +When automatic invocation is enabled, {% data variables.product.prodname_copilot_short %} is instructed to consult the rubber duck agent at high-leverage moments rather than only when stuck. Typical situations include: + +* **After planning a non-trivial change, but before implementing it.** This is the highest-leverage moment to catch design flaws, while course corrections are still cheap. +* **Mid-implementation,** to check for blind spots in a complex piece of work. +* **After writing tests,** to validate that test coverage is comprehensive and that the behavior actually satisfies your original request. +* **Reactively, when {% data variables.product.prodname_copilot_short %} hits repeated failures or unexpected results,** to get an independent analysis of the problem rather than retrying the same approach. + +For small, well-understood changes {% data variables.product.prodname_copilot_short %} typically skips the rubber duck agent. + +When {% data variables.product.prodname_copilot_short %} consults the rubber duck agent, it summarizes the resulting critique for you in the timeline output rather than repeating it verbatim—for example, "The critique pointed out a blind spot in my plan around X, so I updated my plan to address that." + ## Benefits of using the rubber duck agent * **Catches issues early.** Most non-trivial tasks that fail have problems that a critique could have caught at the planning stage. Getting feedback before code is written is preferable to fixing problems later in the process. @@ -98,3 +117,4 @@ You can also invoke the rubber duck agent with a slash command: ## Further reading * [AUTOTITLE](/copilot/concepts/agents/copilot-cli/about-custom-agents#built-in-agents) + diff --git a/content/copilot/concepts/billing-and-usage/organizations-and-enterprises/seats-and-billing-cycles.md b/content/copilot/concepts/billing-and-usage/organizations-and-enterprises/seats-and-billing-cycles.md index b314b14cb99e..2905a45956de 100644 --- a/content/copilot/concepts/billing-and-usage/organizations-and-enterprises/seats-and-billing-cycles.md +++ b/content/copilot/concepts/billing-and-usage/organizations-and-enterprises/seats-and-billing-cycles.md @@ -63,6 +63,17 @@ When you remove seats, billing for those seats continues until the end of the cu For more information, see [AUTOTITLE](/copilot/reference/copilot-billing/license-changes). +## Payment dates for credit card or PayPal + +If you pay by credit card or PayPal, you will be charged at the following times: + +* At the beginning of the calendar month, for all assigned {% data variables.product.prodname_copilot %} licenses +* At the beginning of the billing cycle, for any usage from the previous cycle outside your plan's allowance +* Whenever you need to pay to continue using {% data variables.product.prodname_ai_credits_short %} +* Whenever you purchase additional licenses during the billing cycle + +You will receive a receipt and invoice at each point, which you can view on your "Payment history" page. + ## Managing costs You can control {% data variables.product.prodname_ai_credits_short %} spend using budget controls at the user, cost center, and enterprise level. For an overview of how budget controls work, see [AUTOTITLE](/copilot/concepts/billing-and-usage/organizations-and-enterprises/budgets). For guidance on choosing a configuration, see [AUTOTITLE](/copilot/tutorials/budgets/optimizing-your-budget-configuration). diff --git a/content/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-plan/subscribe.md b/content/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-plan/subscribe.md index c0a2ebe4dd5c..b2a10d097e58 100644 --- a/content/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-plan/subscribe.md +++ b/content/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-plan/subscribe.md @@ -20,22 +20,9 @@ category: - Manage Copilot for a team --- -## Paying by credit card or PayPal +{% data reusables.copilot.plans.subscribe-for-enterprise %} ->[!NOTE] {% data reusables.copilot.plans.ghec-trial-note %} - -1. Ensure you are signed in as an enterprise admin on {% data variables.product.github %}. -1. Navigate to the [{% data variables.product.prodname_copilot %} sign up page](https://github.com/github-copilot/purchase?ref_product=copilot&ref_type=purchase&ref_style=button&ref_plan=enterprise). -1. Ensure you are making changes to the right enterprise account. If you are not, click **{% octicon "arrow-switch" aria-hidden="true" aria-label="arrow-switch" %} Switch** and select the enterprise for which you want to purchase {% data variables.product.prodname_copilot %}. You can also append `&enterprise=YOUR-ENTERPRISE` to the URL to pre-select the enterprise. -1. Follow the steps to sign up and enable {% data variables.product.prodname_copilot_short %} for organizations in your enterprise. If you purchased {% data variables.copilot.copilot_enterprise_short %}, you will be able to assign either {% data variables.copilot.copilot_enterprise_short %} or {% data variables.copilot.copilot_business_short %} to each individual organization in the enterprise. - -## Other payment methods - ->[!NOTE] -> {% data reusables.copilot.signup-procedure-enterprise-msft-ea %} - -1. To purchase {% data variables.product.prodname_copilot %} for your enterprise, [contact {% data variables.product.github %}'s Sales team](https://github.com/enterprise/contact?ref_product=copilot&ref_type=engagement&ref_style=text). -1. A member of the Sales team will work with you to set up {% data variables.product.prodname_copilot_short %} for your enterprise. +>[!NOTE] {% data reusables.copilot.signup-procedure-enterprise-msft-ea %} ## Next steps diff --git a/content/copilot/reference/copilot-billing/license-changes.md b/content/copilot/reference/copilot-billing/license-changes.md index c8abe48c18dc..da0051af268a 100644 --- a/content/copilot/reference/copilot-billing/license-changes.md +++ b/content/copilot/reference/copilot-billing/license-changes.md @@ -95,7 +95,7 @@ Additionally: | Scenario | Plan | When is billing affected? | Is proration applied? | When does access change? | Refund for unused time? | |----------------------------------|---------------------|--------------------------|----------------------|--------------------------|-------------------------| -| Add seat/license | {% data variables.copilot.copilot_business_short %}, {% data variables.copilot.copilot_enterprise_short %}| Immediately | Yes | Immediately | N/A | +| Add seat/license | {% data variables.copilot.copilot_business_short %}, {% data variables.copilot.copilot_enterprise_short %}| Immediately (upfront payment for credit card or PayPal) | Yes | Immediately ({% data variables.product.prodname_ai_credits_short %} may be prorated) | N/A | | Remove seat/license | {% data variables.copilot.copilot_business_short %}, {% data variables.copilot.copilot_enterprise_short %}| End of cycle | N/A | End of cycle (immediately if revoked) | No | | Cancel subscription | All plans | End of cycle | N/A | End of cycle | No | | Upgrade plan | {% data variables.copilot.copilot_pro_short %}, {% data variables.copilot.copilot_pro_plus_short %}, and {% data variables.copilot.copilot_max_short %} | Immediate | No | Immediately | N/A | diff --git a/content/copilot/reference/copilot-cli-reference/cli-command-reference.md b/content/copilot/reference/copilot-cli-reference/cli-command-reference.md index e94fc720ef22..474fc624ec19 100644 --- a/content/copilot/reference/copilot-cli-reference/cli-command-reference.md +++ b/content/copilot/reference/copilot-cli-reference/cli-command-reference.md @@ -21,6 +21,7 @@ docsTeamMetrics: | `copilot` | Launch the interactive user interface. | | `copilot app` | Open the {% data variables.copilot.github_copilot_app %} in the current directory, deep-linking straight to a new session. Falls back to opening the app's download page in a browser if the deep link can't be handled, or prints the URL to open manually if no browser is available. | | `copilot completion SHELL` | Print a shell script for the chosen shell that can be used to enable tab completion for {% data variables.copilot.copilot_cli_short %}. Supported shells: `bash`, `zsh`, `fish`. See [Using `copilot completion`](#using-copilot-completion). | +| `copilot config [KEY] [VALUE]` | Read or change {% data variables.product.prodname_copilot_short %} settings from the command line, outside an interactive session. See [Using `copilot config`](#using-copilot-config). | | `copilot help [TOPIC]` | Display help information. Help topics include: `billing`, `config`, `commands`, `environment`, `logging`, `monitoring`, `permissions`, `providers`, and `sandbox`. | | `copilot init` | Initialize {% data variables.product.prodname_copilot_short %} custom instructions for this repository. | | `copilot login [OPTION]` | Authenticate with {% data variables.product.prodname_copilot_short %} via OAuth. See [`copilot login` options](#copilot-login-options). | @@ -77,7 +78,7 @@ COPILOT_GITHUB_TOKEN=github_pat_... copilot The command `copilot completion SHELL` outputs a script for the specified shell (bash, zsh, or fish). -By sourcing this script (or writing it to your shell's completion directory) you can enable tab completion in your terminal for `copilot` subcommands, command options, and known value choices for command options. +By sourcing this script (or writing it to your shell's completion directory) you can enable tab completion in your terminal for `copilot` subcommands, command options, and known value choices for command options. For `copilot config`, completion also covers setting keys, boolean and enum values, and files or directories for path-valued settings. #### Usage examples @@ -109,6 +110,47 @@ copilot completion fish > ~/.config/fish/completions/copilot.fish Use `copilot plugin` to install, list, update, enable, disable, and uninstall plugins from the command line, without opening an interactive session. `copilot plugins` (plural) is a legacy alias for the same command. For the full command and option reference, see [AUTOTITLE](/copilot/reference/copilot-cli-reference/cli-plugin-reference). +### Using `copilot config` + +Run `copilot config` to read and change {% data variables.product.prodname_copilot_short %} settings from the command line, outside an interactive session. This is the non-interactive counterpart to the `/settings` (or `/config`) slash command. For more information about the settings file and its keys, see [AUTOTITLE](/copilot/reference/copilot-cli-reference/cli-config-dir-reference#settingsjson). + +```bash +# Print a setting +copilot config theme + +# Set a nested value (dot notation) +copilot config footer.showQuota off + +# Append an item to a list setting (added only if not already present) +copilot config allowedUrls github.com + +# Append an item that starts with a dash +copilot config powershellFlags -- -NoProfile + +# Remove a key, or one list item +copilot config --rm theme +copilot config --rm allowedUrls github.com + +# List settings as key=value lines, or as JSON +copilot config --list +copilot config --repo --list --json +``` + +| Option/Argument | Description | +| --------------- | -------------------------------------------------------------------------------------------- | +| `KEY` | Setting key in dot notation (for example, `footer.showQuota`). | +| `VALUE` | Value to set, append, or remove from a list with `--rm`. | +| `--list` | List settings as `key=value` lines; conflicts with `KEY`/`VALUE`/`--rm`. | +| `--json` | Output `--list` as JSON; requires `--list`. | +| `--rm` | Remove the key, or only the given item from a list; requires `KEY`. | +| `--global` | Use your user settings file (the default); conflicts with `--repo`/`--local`. | +| `--repo` | Use the repository's `.github/copilot/settings.json`; conflicts with `--global`/`--local`. | +| `--local` | Use the repository's `.github/copilot/settings.local.json`; conflicts with `--global`/`--repo`. | + +Values must match the setting's type: `on`/`off` or `true`/`false` for booleans, a number for numeric settings, or an accepted choice for enums. Reading a list prints one item per line; reading a group prints JSON. An unset key exits with status `1`. Secret values are redacted from output. + +Commands use your user settings file (`settings.json` in `~/.copilot`, or in `$COPILOT_HOME` when set) by default. `--repo` and `--local` accept only the settings a repository can override—see [AUTOTITLE](/copilot/reference/copilot-cli-reference/cli-config-dir-reference#repository-settings-githubcopilotsettingsjson). Run `copilot help config` for the available settings. + ### Using `copilot instruction` Run `copilot instruction list` to non-interactively list custom instruction sources discovered for the current working directory. This replaces the retired `copilot plugins list --kind instruction`. @@ -188,7 +230,7 @@ copilot sandbox ca remove | `copilot sandbox ca rotate` | Replace the authority, preserving its current trust state. | | `copilot sandbox ca remove` | Remove the authority from OS trust; the bundle-based path keeps working. | -Run these commands as the user who runs {% data variables.copilot.copilot_cli_short %}, not elevated, as `SYSTEM`, or as `root`, because the certificate authority is stored in that user's {% data variables.copilot.copilot_cli_short %} home directory. Run `copilot sandbox ca trust --help` for unattended setup guidance. `copilot sandbox ca` does not accept `--config-dir`; set `COPILOT_HOME` instead to target a non-default {% data variables.copilot.copilot_cli_short %} home. +Run these commands as the user who runs {% data variables.copilot.copilot_cli_short %}, not elevated, as `SYSTEM`, or as `root`, because the certificate authority is stored in that user's {% data variables.copilot.copilot_cli_short %} home directory. Run `copilot sandbox ca trust --help` for unattended setup guidance. `--config-dir` (or `COPILOT_HOME`) targets a non-default {% data variables.copilot.copilot_cli_short %} home for these commands, the same as the rest of the CLI. ## The sessions sidebar @@ -390,6 +432,15 @@ Sessions sort by the following modes: Sessions already open in another window float to the top in all non-relevance sort modes. When no working-directory context is available, the `relevance` mode is skipped. +## Pre-conversation environment picker + +Before you send the first message in a new session, press Ctrl+E in an empty prompt box to choose where the conversation will run: on your local machine, or in a cloud environment. The environment is provisioned when you send your first message. + +> [!NOTE] +> The environment picker requires cloud sessions to be available on your account—the same requirement as the `--remote`, `--no-remote`, `--remote-export`, `--no-remote-export`, and `--connect` options. See [Command-line options](#command-line-options). + +Once a conversation has started, Ctrl+E reverts to its other behaviors: moving the cursor to the end of the line while typing, or expanding all items in the timeline on an empty prompt box. See [Navigation shortcuts in the interactive interface](#navigation-shortcuts-in-the-interactive-interface) and [Timeline shortcuts in the interactive interface](#timeline-shortcuts-in-the-interactive-interface). + ## Sidebar and sessions tab shortcuts The current-session sidebar lets you browse and switch between sessions without leaving the one you're in. With an empty prompt box, ←/→ walk a three-state focus cycle: closed, timeline-focused, and sidebar-focused. Disable the sidebar entirely with the `sidebar` setting—see [AUTOTITLE](/copilot/reference/copilot-cli-reference/cli-config-dir-reference#configuration-file-settings). @@ -497,6 +548,7 @@ These are the slash commands you can use from within an interactive CLI session. | `/chronicle ` | Session history tools and insights. The `skills` subcommands draft, review, and track the status of repository skill proposals generated from observed usage. See [AUTOTITLE](/copilot/how-tos/copilot-cli/use-copilot-cli/chronicle#using-the-chronicle-slash-command). | | `/clear [PROMPT]`, `/new [PROMPT]`, `/reset [PROMPT]` | Start a new conversation. `/new worktree` starts an empty session in a new Git worktree instead of clearing the current one, leaving the current conversation and its working directory unchanged. | | `/clikit [COMPONENT]` | Preview CLI business components (for example, quota info). | +| `/collect-debug-logs [file\|gist\|share] [PATH]` | Collect debug logs to an archive, a {% data variables.product.github %} gist, or upload them to {% data variables.product.github %} (`share`). See [Collecting and sharing debug logs](#collecting-and-sharing-debug-logs). | | `/compact [FOCUS-INSTRUCTIONS]` | Summarize the conversation history to reduce context window usage. Optionally provide focus instructions to steer the summary—for example, `/compact focus on the auth module`. See [AUTOTITLE](/copilot/concepts/agents/copilot-cli/context-management#compaction). | | `/context` | Show the context window token usage and visualization. See [AUTOTITLE](/copilot/concepts/agents/copilot-cli/context-management#checking-your-context-usage). | | `/copy` | Copy the last response to the clipboard. | @@ -510,7 +562,7 @@ These are the slash commands you can use from within an interactive CLI session. | `/exit`, `/quit` | Close the current session. If other sessions are running, this foregrounds the newest remaining one instead of quitting. Quits the CLI only when it is the last open session. `/exit print` always tears down the CLI and offers to dump the transcript. `/exit` and `/quit` (including their `print` variant) can also be queued with Ctrl+Q while the agent is running—the CLI closes the session once the current turn, and any queued shell command ahead of it, finishes. | | `/extensions [manage\|mode]`, `/extension` | Manage CLI extensions. {% data reusables.copilot.experimental %} | | `/experimental [on\|off\|show]` | Toggle, set, or show experimental features. | -| `/feedback`, `/bug` | Provide feedback about the CLI. | +| `/feedback`, `/bug` | Provide feedback about the CLI. Can offer a feedback-with-logs route; see [Collecting and sharing debug logs](#collecting-and-sharing-debug-logs). | | `/fleet [PROMPT]` | Enable parallel subagent execution of parts of a task. See [AUTOTITLE](/copilot/concepts/agents/copilot-cli/fleet). | | `/help` | Show the help for interactive commands. | | `/ide` | Connect to an IDE workspace. See [AUTOTITLE](/copilot/how-tos/copilot-cli/use-copilot-cli/connecting-vs-code#managing-the-connection-with-the-ide-slash-command). | @@ -525,7 +577,7 @@ These are the slash commands you can use from within an interactive CLI session. | `/logout` | Log out of {% data variables.product.prodname_copilot_short %}. | | `/lsp [show\|test\|reload\|logs\|help] [SERVER-NAME]` | Manage the language server configuration. The `logs` subcommand opens the live LSP services log panel. | | `/mcp [config\|list\|show\|add\|edit\|delete\|disable\|enable\|auth\|reload\|search] [SERVER-NAME]` | Manage the MCP server configuration. With no subcommand, or with `config`, the plugins dashboard opens pinned to the MCP server list; the add, edit, and authenticate forms open inside that dashboard too, so closing a form returns you to the server list. Use `show` or `show SERVER-NAME` to display all configured servers or open one server's details directly, including its available tools, and to enable or disable it. For a plugin-provided server, `show SERVER-NAME` also displays the source attribution (for example, `Source: Plugin my-plugin (1.2.0)`). `list` (alias `ls`) prints a plain-text list of configured servers with connection status and live state. Bare `/mcp`, `config`, `show`, and `list` (alias `ls`) are read-only or open the dashboard, so they can run while the agent is busy processing a turn. The mutating subcommands (`add`, `edit`, `delete`, `disable`, `enable`, `auth`, `reload`, and `search`) are blocked until the turn finishes. `edit ` rejects a workspace-sourced server (one defined in a repository's `.mcp.json`) instead of opening the user-tier wizard, since saving would silently create a same-name user entry that the workspace one still shadows. The error names the file to edit directly. `delete ` reports the same file when asked to remove a workspace-sourced server. Sandboxed local servers show a `connected (sandboxed)` status. See [AUTOTITLE](/copilot/how-tos/copilot-cli/customize-copilot/add-mcp-servers#managing-mcp-servers). | -| `/model [--session\|--global\|--repo\|--local] [MODEL\|auto TIER]`, `/models` | Select the AI model you want to use, or choose **Auto**. By default (or with `--session`, alias `-s`), changes the model, reasoning effort, or context window for the current session only, without touching saved settings. `--repo`/`--local` pins the default model in repository settings instead; `--global` (or `/config model`) sets the default for future sessions. Press Tab on a model with a long-context variant to toggle its Context column between the default and long-context window. The picker groups models into sections—press Shift+Tab to cycle grouping between recommended (Recent, Recommended, New, and other models), vendor, and category. A model with vendor-specific data retention terms shows a data retention warning banner with a link to the vendor's policy. Usable mid-turn: a change requested while the agent is running is queued as a cancellable (Ctrl+C) command and applied once the current turn finishes, instead of switching the live model mid-request. Use `/model auto TIER` (`efficiency`, `balance`, or `intelligence`) to select a specific Auto routing tier directly, including from the "switch" action on an Auto tier recommendation hint. See [AUTOTITLE](/copilot/concepts/models/auto-model-selection). | +| `/model [--session\|--global\|--repo\|--local] [MODEL\|auto TIER]`, `/models` | Select the AI model you want to use, or choose **Auto**. By default (or with `--session`, alias `-s`), changes the model, reasoning effort, or context window for the current session only, without touching saved settings. `--repo`/`--local` pins the default model in repository settings instead; `--global` (or `/config model`) sets the default for future sessions. Press Tab on a model with a long-context variant to toggle its Context column between the default and long-context window. The picker groups models into sections—press Shift+Tab to cycle grouping between recommended (Recent, Recommended, New, and other models), vendor, and category. A model with vendor-specific data retention terms shows a data retention warning banner with a link to the vendor's policy. Usable mid-turn: a change requested while the agent is running is queued as a cancellable (Ctrl+C) command and applied once the current turn finishes, instead of switching the live model mid-request. Use `/model auto TIER` (`efficiency`, `balance`, or `intelligence`) to select a specific Auto routing tier directly, including from the "switch" action on an Auto tier recommendation hint. When Auto picks a model, the timeline shows the reason for that choice whenever the API provides one. See [AUTOTITLE](/copilot/concepts/models/auto-model-selection). | | `/permissions [default\|assisted\|allow-all\|show]` | Switch between permission modes (`default`, `assisted`, `allow-all`), or show the current mode (`show`). This is the canonical command for permission mode changes; `/allow-all` and `/yolo` remain supported as aliases. | | `/permissions reset` | Reset all in-memory tool and path approvals for the current session (re-prompt on next use). | | `/plan [PROMPT]` | Create an implementation plan before coding. | @@ -571,7 +623,7 @@ These are the slash commands you can use from within an interactive CLI session. | `/undo`, `/rewind` | Open the rewind picker to roll the session back to an earlier user turn. Choose between: **Conversation only** (roll back the conversation, leaving files as they are) or **Conversation + files** (also restore the files {% data variables.product.prodname_copilot_short %} changed in that turn, and later discarded turns, to their pre-change contents, skipping any you have since edited yourself). File changes are tracked per turn across editing tools, shell commands, and sub-agents, so Git is not required. | | `/update`, `/upgrade` | Update the CLI to the latest version. | | `/usage` | Display session usage metrics and statistics, including per-model token totals. For token-based-billing accounts, each model's row also shows its own {% data variables.product.prodname_ai_credit_singular %} consumption (for example, `1 AIC`). Billed models with no token counts show credits only. | -| `/user [show\|list\|switch]` | Manage the current {% data variables.product.github %} user. | +| `/user [show\|list\|switch]` | Manage signed-in accounts. | | `/version` | Display version information and check for updates. | | `/vim` | Toggle Vim mode for the prompt box, enabling Vim-style modal editing: motions (for example, `hjkl`, `w`, `b`, `e`, `0`, `$`, `gg`, `G`), character search (`f`/`F`/`t`/`T`/`;`/`,`), insert commands (`i`/`a`/`o`), edit commands (`r`/`~`/`J`/`x`/`D`/`C`), operators (`d`/`c`/`y`), yank and put (`y`/`p`/`P`), repeat (`.`), undo and redo (`u`/Ctrl+R), counts, and Esc to return to normal mode. Also configurable with the `editorMode` setting. See [AUTOTITLE](/copilot/reference/copilot-cli-reference/cli-config-dir-reference#user-settings-copilotsettingsjson). | | `/voice [on\|off\|models\|devices]` | Toggle voice mode, browse available voice models, or choose the input device (microphone). | @@ -594,6 +646,18 @@ The footer shows an "N scheduled" indicator by default whenever the session has > [!NOTE] > The experimental `/plugins` command was removed. Its resources have been moved to `/plugin`, `/mcp`, and `/skills`. Use `/subagents` and `/instructions` for agents and instructions. +### Collecting and sharing debug logs + +Use `/collect-debug-logs [file|gist|share] [PATH]` to gather debug logs for troubleshooting: + +| Target | Description | +|---------|-------------| +| `file` | Save the logs to a local archive at `PATH` (default location used when `PATH` is omitted). | +| `gist` | Upload the logs to a secret {% data variables.product.github %} gist. | +| `share` | Save a local archive, then upload it to {% data variables.product.github %}. | + +`/collect-debug-logs share`, and the feedback-with-logs route offered from `/feedback`, first save a local archive, then ask for fresh consent (defaulting to **No**) before uploading it to {% data variables.product.github %}. Uploading is currently available only to {% data variables.product.github %} staff and internal users, and isn't generally available yet. Users outside {% data variables.product.github %} continue to use the existing archive and gist routes, and the existing public feedback route. + ## Command-line options | Option | Purpose | @@ -726,15 +790,16 @@ Use `--model=MODEL` or the `COPILOT_MODEL` environment variable to select the AI | Model | Best for | |-------|----------| -| `claude-sonnet-4.6` | General-purpose coding (default) | +| `claude-sonnet-5.5` | General-purpose coding (default) | | `gpt-5.4` | Complex reasoning tasks | -| `gpt-6-astra` | New model, opt-in (not the automatic default) | -| `gpt-6-sol` | New model, opt-in (not the automatic default) | -| `gpt-6-luna` | New model, opt-in (not the automatic default) | -| `claude-opus-5.5` | New model, high-capability complex tasks | +| `gpt-6.1-sol` | Recommended, opt-in (not the automatic default) | +| `gpt-6-astra` | Recommended, opt-in (not the automatic default) | +| `gpt-6-luna` | Recommended, opt-in (not the automatic default) | +| `claude-opus-5.5` | Recommended, high-capability complex tasks | | `claude-haiku-4.5` | Fast, lightweight operations | | `gpt-5.3-codex` | Code-focused tasks | | `gemini-3.7-flash` | Fast Google Gemini responses | +| `gemini-3.8-flash` | Fast Google Gemini responses | You can also switch models during an interactive session using the `/model` slash command. @@ -1046,7 +1111,13 @@ The `--registry` option and other npm configuration options (`--userconfig`, `-- Remote MCP servers that use OAuth may show a `needs-auth` status when a token expires or when a different account is required. Use `/mcp auth ` to trigger a fresh OAuth flow. This opens a browser authentication prompt, allowing you to sign in or switch accounts. After completing the flow, the server reconnects automatically. -On Windows, remote MCP servers protected by Microsoft Entra ID authenticate through the OS authentication broker (Web Account Manager) instead, usually with no prompt. On other platforms, and on Windows machines without the broker library, sign-in falls back to the browser flow described above. Passing `--device-code` bypasses the broker and forces the OAuth device code flow rather than the browser flow. +On Windows, remote MCP servers protected by Microsoft Entra ID authenticate through the OS authentication broker (Web Account Manager) instead, usually with no prompt. On Linux and macOS, where no OS broker exists, the CLI instead silently mints a per-resource token from the Entra account established via `/login` → Microsoft Entra. If that account can't silently satisfy the request—for example, no signed-in Entra identity, an ambiguous account, or a resource pre-authorized for a different client—sign-in falls back to the browser flow described above. Passing `--device-code` bypasses the broker and forces the OAuth device code flow rather than the browser flow, and Windows machines without the broker library also fall back to the browser flow. + +### Account-derived WorkIQ + +Signing in with a Microsoft Entra account makes the hosted WorkIQ MCP server available in `/mcp`. It's disabled by default. Discovery alone doesn't connect, acquire a token, or expose tools—enable it with the normal MCP controls (`/mcp enable WorkIQ` or `copilot mcp enable WorkIQ`) to try silent authentication first. `/mcp auth WorkIQ` remains available for recovery. + +The server uses a credential tied to the Entra account that signed in, not a token issued for another service, and its enablement follows that Entra identity rather than transferring to a different account. Explicit server configuration and disablement, and organization allowlist or denylist policy, still take precedence. No WorkIQ entry is written to `mcp-config.json`. This is unrelated to running `npx @microsoft/workiq mcp` as an independently authenticated stdio server. ### Headless OAuth (`client_credentials` grant) diff --git a/content/copilot/reference/copilot-cli-reference/cli-config-dir-reference.md b/content/copilot/reference/copilot-cli-reference/cli-config-dir-reference.md index 3489e65c6c28..b8da1253bdc8 100644 --- a/content/copilot/reference/copilot-cli-reference/cli-config-dir-reference.md +++ b/content/copilot/reference/copilot-cli-reference/cli-config-dir-reference.md @@ -72,6 +72,8 @@ For the full list of settings and how they interact with repository-level config > [!TIP] > Run `copilot help config` in your terminal for a quick reference. +Use `copilot config` from your shell, outside a session, to read or change settings non-interactively—the scripting counterpart to the `/settings` slash command. Add `--repo` or `--local` to target `.github/copilot/settings.json` or `.github/copilot/settings.local.json` instead of your user settings file; only [repo-overridable keys](#repository-settings-githubcopilotsettingsjson) can be written there. See [AUTOTITLE](/copilot/reference/copilot-cli-reference/cli-command-reference#using-copilot-config) for the full command reference. + ### `copilot-instructions.md` Personal custom instructions that apply to all your sessions, regardless of which project you're working in. This file works the same way as a repository-level `copilot-instructions.md` but applies globally. @@ -453,8 +455,6 @@ These settings apply across all your sessions and repositories. You can use the | `bashEnv` | `boolean` | `false` | Enable `BASH_ENV` support for bash shells. Can also be set with `--bash-env` or `--no-bash-env`. | | `beep` | `boolean` | `true` | Play an audible beep when attention is required. | | `beepOnSchedule` | `boolean` | `true` | Play an audible beep when a scheduled `/every` or `/after` run finishes. | -| `builtInAgents.rubberDuck` | `boolean` | `true` | Enable the rubber-duck subagent that provides adversarial feedback on agent plans. | -| `builtInAgents.rubberDuckAutoInvoke` | `boolean` | `false` | Include proactive prompting for automatic rubber-duck invocation. Set to `true` to opt into additional rubber-duck nudges during agent turns. | | `colorMode` | `"default"` \| `"github"` \| `"dim"` \| `"high-contrast"` \| `"colorblind"` | `"github"` | Deprecated alias for `theme`. Prefer `theme`. | | `commandHistoryMaxSize` | `number` | `50` | Maximum number of recent commands retained for input history and reverse search. Must be an integer between `1` and `1000`. | | `compactPaste` | `boolean` | `true` | Collapse large pastes (more than 10 lines) into compact tokens. | @@ -518,7 +518,8 @@ These settings apply across all your sessions and repositories. You can use the | `stream` | `boolean` | `true` | Enable streaming responses. | | `streamerMode` | `boolean` | `false` | Hide preview model names, quota details, prompt timestamps, and the update-available notice. Useful when demonstrating {% data variables.copilot.copilot_cli_short %} or screen sharing. | | `subagents.agents` | `object` | `{}` | Per-agent model configuration, keyed by agent name. Each value is an object with optional `model` (string), `modelPolicy` (`"preferred"` or `"required"`), `effortLevel` (string), and `contextTier` (`"default"`, `"long_context"`, or `"inherit"`) fields. Set `model`, `effortLevel`, or `contextTier` to `"inherit"` to use the parent session's value at dispatch time. `modelPolicy` has no effect when the agent definition itself sets `modelPolicy: "required"`—that lock can't be overridden here. Use the `/subagents` slash command to configure these settings interactively. | -| `subagents.disabledSubagents` | `string[]` | `[]` | Agent names to prevent from being dispatched. Only the `rubber-duck` agent cannot be disabled via this setting. All other built-in agents—including `explore`, `task`, `code-review`, `general-purpose`, `research`, and `security-review`—can be disabled. | +| `subagents.agents["rubber-duck"].autoInvoke` | `boolean` | `false` | Allow Copilot to proactively consult the rubber duck agent without being asked. To change this, run `/subagents`, select `rubber-duck`, press **Enter**, then toggle **Proactive invocation**. | +| `subagents.disabledSubagents` | `string[]` | `[]` | Names of subagents that are turned off. Manage this list using the **On/Off** control for each agent in the `/subagents` picker in an interactive session. | | `subagents.maxConcurrency` | `number` | plan-based | Maximum concurrent subagents for this session. Only honored for usage-based billing users; ignored for all other plans. Capped at `32`. See [AUTOTITLE](/copilot/reference/copilot-cli-reference/cli-command-reference#subagent-limits). | | `subagents.maxDepth` | `number` | `6` | Maximum subagent nesting depth. Only honored for usage-based billing users; ignored for all other plans. Capped at `256`. See [AUTOTITLE](/copilot/reference/copilot-cli-reference/cli-command-reference#subagent-limits). | | `tabs.enabled` | `boolean` | `true` | Show the home tab bar. Set to `false` to hide it entirely. | @@ -660,7 +661,7 @@ Only the following keys are supported in MDM managed settings. | `forceLoginOrgs` | Pin sign-in to an approved set of {% data variables.product.github %} organizations (an array of organization logins, matched case-insensitively). {% data variables.product.prodname_copilot_short %} only runs for an account belonging to at least one listed organization; a personal account, an account that belongs only to some other enterprise, or BYOK/API-key authentication is refused with an actionable error. Set an empty array to turn the pin off without deleting the key. Deploy this key through the device channel (MDM plist/registry, or `managed-settings.json`) since it must be able to redirect a developer's first sign-in—the server-managed channel only reaches accounts that have already authenticated into the organization. This key fails closed: an unusable value, or a managed policy that can't be read on a known-managed device, blocks all sign-in until fixed. | | `forceRemoteSettingsRefresh` | Require a fresh server-managed settings fetch on startup, even when a fresh cached policy exists. The cached entry is still kept as a fallback if the fetch fails. The device (MDM) value takes precedence over a cached server value. | | `model` | Set a default model for all users (overridden by the `--model` flag or a resumed-session model). `effortLevel` and `contextTier` set alongside `model` apply the same managed reasoning effort and context tier as the corresponding [repository settings](#repository-settings-githubcopilotsettingsjson) keys, but only when the managed model supports explicit effort/context options. | -| `permissions` | Set managed permissions, including `disableBypassPermissionsMode` and `deny` / `ask` / `allow` rule arrays. See [Managed permission rules](#managed-permission-rules). | +| `permissions` | Set managed permissions, including `disableBypassPermissionsMode`, `deny` / `ask` / `allow` rule arrays, and the `limitTo` domain boundary array. See [Managed permission rules](#managed-permission-rules) and [Domain boundary (`limitTo`)](#domain-boundary-limitto). | | `policyHelper` | Register an executable that supplies the lowest-priority managed-settings layer. Fields: `path` (required), plus optional `args`, `timeoutMs`, and `refreshIntervalMs`. If both a device (MDM) and a server policy register a `policyHelper`, the device registration wins. | | `remoteControl` | Control whether sessions on this device can be controlled from other devices. `mode` is `"enabled"`, `"disabled"`, or `"requireSSO"` (requires `githubDotComOrganizations` when set). | | `sandbox` | Set a sandbox policy floor that users cannot relax. Supported settings include `enabled`, `failIfUnavailable`, `allowBypass`, `addCurrentWorkingDirectory`, `sandboxMcpServers`, `sandboxLspServers`, `auth.git`, `auth.gh`, `allowDevToolAccess`, `learningMode`, and the `userPolicy.*` filesystem and network rules. The managed value always takes precedence over a user's own value in the safer direction. Turning the sandbox on, requiring it to succeed, and sandboxing MCP and LSP servers cannot be turned off. Disabling bypass or credential injection cannot be re-enabled. Filesystem allow lists can only be narrowed, and denied paths can only be added to. `failIfUnavailable` can only be set by an administrator and blocks the session when the sandbox cannot be established. For the settings users can set themselves, see [User settings](#user-settings-copilotsettingsjson) or run `copilot help sandbox`. | @@ -701,6 +702,24 @@ Rules are combined across managed sources with a fixed precedence: deny always w `Edit(...)` and `Write(...)` rules apply to more than the built-in file tools. They also cover files written directly by a shell command. {% data variables.copilot.copilot_cli_short %} recognizes a fixed set of these writes. It covers Bash output redirections (`>`, `>>`, `>|`, `&>`, `&>>`), PowerShell output redirections (`>`, `>>`, `*>`, `*>>`), and a small set of in-place `sed` edits (`sed -i` or `--in-place`, and the BSD forms `-i ''` and `-I ''`). When {% data variables.copilot.copilot_cli_short %} can work out the target file from the command, a matching `deny` rule blocks the write and a matching `ask` rule prompts you first. This applies even when a broad rule like `Shell(*)` would otherwise allow the command. Sometimes the target file cannot be worked out ahead of time, for example when the path comes from a variable. In that case these path rules do not apply, and the command is checked by the normal shell command rules instead. +### Domain boundary (`limitTo`) + +Add a `limitTo` array alongside `deny`, `ask`, and `allow` under the managed `permissions` key to enforce a closed-world domain allowlist: + +```json +{ + "permissions": { + "limitTo": ["github.com", "*.github.com"] + } +} +``` + +Only `Domain(...)` entries are supported in `limitTo`. Any agent network request to a domain outside the list is denied without prompting, and user rules, saved approvals, and allow-all modes can't widen it. URLs detected in shell requests are treated as `Domain` requests and must also satisfy the boundary. `limitTo` doesn't restrict `shell`, `read`, or `write` operations by themselves. + +An empty `limitTo` list denies every domain request. An invalid list, or an invalid entry, is enforced as an empty list (and reported as a configuration error) rather than discarding the rest of the managed policy. + +`deny` still takes precedence over `limitTo`. `ask` and `allow` only refine requests that are already inside the boundary. Like `allow`, `limitTo` is an intersection across managed sources—every managed source that declares a `limitTo` list must admit the request. + ## Managed MCP server allow/deny list Administrators can govern MCP servers directly through MDM managed settings, independent of the [enterprise MCP allowlist](/copilot/reference/copilot-cli-reference/cli-command-reference#enterprise-mcp-allowlist). diff --git a/content/copilot/reference/copilot-cli-reference/cli-plugin-reference.md b/content/copilot/reference/copilot-cli-reference/cli-plugin-reference.md index a209b5307eca..10788cf78811 100644 --- a/content/copilot/reference/copilot-cli-reference/cli-plugin-reference.md +++ b/content/copilot/reference/copilot-cli-reference/cli-plugin-reference.md @@ -89,7 +89,10 @@ MCP servers install from a policy-configured registry, which requires authentica > [!NOTE] > Path-sourced plugins in a local (directory-source) marketplace load live from their real directory—editing one takes effect on `/restart` or in a new session, with no `copilot plugin update` needed. -First-party plugins—those installed from the built-in `copilot-plugins` and `awesome-copilot` marketplaces—automatically update at the start of each session in a trusted working directory. Disable this behavior with the `autoUpdate` setting (set to `false`) or the `COPILOT_AUTO_UPDATE=false` environment variable. Auto-update is also skipped by default in CI. See [AUTOTITLE](/copilot/reference/copilot-cli-reference/cli-config-dir-reference#configuration-file-settings). +First-party plugins—those installed from the built-in `awesome-copilot` marketplace—automatically update at the start of each session in a trusted working directory. Disable this behavior with the `autoUpdate` setting (set to `false`) or the `COPILOT_AUTO_UPDATE=false` environment variable. Auto-update is also skipped by default in CI. See [AUTOTITLE](/copilot/reference/copilot-cli-reference/cli-config-dir-reference#configuration-file-settings). + +> [!NOTE] +> `copilot-plugins` previously shipped as a second built-in default marketplace alongside `awesome-copilot`. It's now an ordinary, non-default marketplace (`github/copilot-plugins`) that you register yourself with `copilot plugin marketplace add github/copilot-plugins`. If you installed plugins from it before this change, a one-time migration adds it to your own `extraKnownMarketplaces` with `autoUpdate: true` so those plugins keep updating. A fresh install that never used `copilot-plugins` must register it manually before installing plugins from it. A marketplace you've added yourself can opt into the same session-start auto-update by setting `autoUpdate: true` on its `extraKnownMarketplaces` entry in your user settings. This opt-in applies only to interactive and `-p` sessions—SDK and server sessions don't auto-update. It is honored from your own user settings or from managed (MDM/server) settings, but a repository-level `autoUpdate` setting is accepted and ignored—it can't enable or redirect auto-update for a marketplace. On a same-name collision, a built-in first-party marketplace wins, then a managed entry (which replaces the whole same-named user entry, so a managed entry without `"autoUpdate": true` removes the user's opt-in), then the user's own entry. See [Repository settings](/copilot/reference/copilot-cli-reference/cli-config-dir-reference#repository-settings-githubcopilotsettingsjson). @@ -97,11 +100,11 @@ In interactive mode, `/plugin` flags an installed plugin or marketplace when a n ### `copilot plugin marketplace` (alias `marketplaces`) subcommands -Built-in default marketplaces ship with the runtime and can't be removed. +The built-in `awesome-copilot` default marketplace ships with the runtime and can't be removed. | Subcommand | Description | |--------------------------|-------------------------------------------------------------------------------| -| `list [--json]` | List every registered marketplace, including built-in defaults | +| `list [--json]` | List every registered marketplace, including the built-in default | | `add SOURCE` | Add a marketplace (`owner/repo`, `owner/repo#ref`, a URL, or a local path) | | `remove NAME [--force]` | Remove a marketplace; `--force` also uninstalls plugins sourced from it | | `browse NAME [--json]` | List the plugins offered by a marketplace's catalog | diff --git a/content/copilot/reference/hooks-reference.md b/content/copilot/reference/hooks-reference.md index 31cfe8dbc1b0..de0d7465a47d 100644 --- a/content/copilot/reference/hooks-reference.md +++ b/content/copilot/reference/hooks-reference.md @@ -718,6 +718,8 @@ When {% data variables.copilot.copilot_cli_short %} can show the hook-permission * A valid `block` decision wins over `modifiedResponse`: if a hook returns both, the subagent continues and the rewrite is discarded. * Rewrites do not compose across multiple matching hooks. Every hook receives the same original `response`, and the last hook to return `modifiedResponse` wins—chaining a redactor and a formatter does not feed the redacted text into the formatter. * The output field names (`decision`, `reason`, `modifiedResponse`) are the same for both the camelCase and {% data variables.product.prodname_vscode_shortname %} compatible configs. +* Command and HTTP hooks keep the permissive behavior of other hook events: unsupported verdict fields and non-object JSON outputs are ignored, and `reason` only takes effect alongside a `block` decision with a nonempty string. +* SDK callback outputs are validated before merging: an invalid `decision`, a `reason` without `block`, a `block` without a nonempty `reason`, or a non-object output fails the subagent hook. An explicit `null` in an optional field is treated as absent. > [!NOTE] > **Runaway guard.** After 8 consecutive `block` continuations, the CLI overrides the hook and ends the turn anyway, to prevent an unbounded loop. Use the `stop_hook_active` input field on `agentStop` to detect that this turn was already forced to continue, and self-limit before hitting the cap. diff --git a/data/features/secret-scanning-actions-logs.yml b/data/features/secret-scanning-actions-logs.yml new file mode 100644 index 000000000000..3567c7dfcd47 --- /dev/null +++ b/data/features/secret-scanning-actions-logs.yml @@ -0,0 +1,4 @@ +# Reference: docs-content#23361 +# Secret scanning detection for GitHub Actions workflow logs +versions: + ghec: '*' diff --git a/data/release-notes/enterprise-server/3-21/6.yml b/data/release-notes/enterprise-server/3-21/6.yml index aa2bf3bf469f..83b786cdb55b 100644 --- a/data/release-notes/enterprise-server/3-21/6.yml +++ b/data/release-notes/enterprise-server/3-21/6.yml @@ -71,6 +71,8 @@ sections: On an instance using Redis 7, AOF (append-only file) recovery did not detect or repair corruption in Redis data volumes. This occurred because recovery only checked the legacy single-file AOF path and did not account for Redis 7s multi-part AOF format, which uses a manifest to track data across multiple files. - | When an administrator ran a configured restore that changed the appliances identity (UUID), the restore could skip the storage tier and still report success, resulting in an incomplete restore of repository data. + - | + {% data reusables.release-notes.2026-10-merge-bypass-required-status-checks %} [Updated: 2026-10-07] changes: - | Enterprise Live Migrations skip branch protection rules by default because only part of each rule can be migrated. Partial migration of branch protection rules is opt in with `ghe-config app.elm-exporter.migrate-protected-branches true`. diff --git a/data/reusables/copilot/plans/ghec-trial-note.md b/data/reusables/copilot/plans/ghec-trial-note.md index 57bf35300379..2ef838b6765a 100644 --- a/data/reusables/copilot/plans/ghec-trial-note.md +++ b/data/reusables/copilot/plans/ghec-trial-note.md @@ -1 +1 @@ -If you are currently in a trial of {% data variables.product.prodname_ghe_cloud %}, you must convert to a paid enterprise before you can purchase {% data variables.product.prodname_copilot %}. \ No newline at end of file +If you are currently in a trial of {% data variables.product.prodname_ghe_cloud %}, you must convert to a paid enterprise before you can purchase {% data variables.product.prodname_copilot %}. diff --git a/data/reusables/copilot/plans/subscribe-for-enterprise.md b/data/reusables/copilot/plans/subscribe-for-enterprise.md index d88aee29677d..10dd6423a792 100644 --- a/data/reusables/copilot/plans/subscribe-for-enterprise.md +++ b/data/reusables/copilot/plans/subscribe-for-enterprise.md @@ -1,7 +1,7 @@ **Enterprise owners** can set up {% data variables.copilot.copilot_business_short %} or {% data variables.copilot.copilot_enterprise_short %} for their enterprise. -* If you want to pay by credit card or PayPal, [subscribe here](https://github.com/github-copilot/purchase?ref_product=copilot&ref_type=purchase&ref_style=button). +* If **you're on {% data variables.product.prodname_dotcom_the_website %} and pay by credit card or PayPal**, you can [subscribe here](https://github.com/github-copilot/purchase?ref_product=copilot&ref_type=purchase&ref_style=button). - >[!NOTE] {% data reusables.copilot.plans.ghec-trial-note %} + >[!NOTE] If you are currently in a trial of {% data variables.product.prodname_ghe_cloud %}, you must convert to a paid enterprise before you can purchase {% data variables.product.prodname_copilot %}. -* For other payment methods, [contact {% data variables.product.github %}'s Sales team](https://github.com/enterprise/contact?ref_product=copilot&ref_type=engagement&ref_style=text). +* For **any other payment method and enterprises on {% data variables.enterprise.data_residency_site %}**, [contact {% data variables.product.github %}'s Sales team](https://github.com/enterprise/contact?ref_product=copilot&ref_type=engagement&ref_style=text). diff --git a/data/reusables/release-notes/2026-10-merge-bypass-required-status-checks.md b/data/reusables/release-notes/2026-10-merge-bypass-required-status-checks.md new file mode 100644 index 000000000000..18ba7c6831c9 --- /dev/null +++ b/data/reusables/release-notes/2026-10-merge-bypass-required-status-checks.md @@ -0,0 +1 @@ +When force pushes were disabled, users with bypass permission in repositories with branch protections and rulesets could lose the option to bypass required status checks after a pull request's base branch advanced. diff --git a/src/content-pipelines/state/copilot-cli.sha b/src/content-pipelines/state/copilot-cli.sha index af8d41bdc4e7..7b85eb400bca 100644 --- a/src/content-pipelines/state/copilot-cli.sha +++ b/src/content-pipelines/state/copilot-cli.sha @@ -1 +1 @@ -c0a42716d53bd457fd54fe47719b05d2a7c21ee6 +30a0296ab534a607252fca1fe8384331e348632b diff --git a/src/github-apps/lib/config.json b/src/github-apps/lib/config.json index 9f66214934fd..94f7df0695e8 100644 --- a/src/github-apps/lib/config.json +++ b/src/github-apps/lib/config.json @@ -60,5 +60,5 @@ "2022-11-28" ] }, - "sha": "836ce198db13a6fb194547e53eea99c6ddae495b" + "sha": "af807acc4fad29afba3a2d47227cdc6cdb22d69f" } \ No newline at end of file diff --git a/src/rest/lib/config.json b/src/rest/lib/config.json index cd61bf0d2ba3..c3e5b6445952 100644 --- a/src/rest/lib/config.json +++ b/src/rest/lib/config.json @@ -48,5 +48,5 @@ ] } }, - "sha": "836ce198db13a6fb194547e53eea99c6ddae495b" + "sha": "af807acc4fad29afba3a2d47227cdc6cdb22d69f" } \ No newline at end of file diff --git a/src/webhooks/lib/config.json b/src/webhooks/lib/config.json index bc2cc8087a64..08679d6884dc 100644 --- a/src/webhooks/lib/config.json +++ b/src/webhooks/lib/config.json @@ -1,3 +1,3 @@ { - "sha": "836ce198db13a6fb194547e53eea99c6ddae495b" + "sha": "af807acc4fad29afba3a2d47227cdc6cdb22d69f" } \ No newline at end of file