According to DevOps.com; the source materials contain no primary source.
GitHub opened a public preview of centrally managed policies for the Copilot sandbox, a restricted environment for running commands, in JetBrains IDEs. The policies give administrators control over Copilot access to the file system and network.
An administrator can set a proxy, access to developer tools, and Keychain access on macOS. A locked setting appears as managed in the JetBrains plugin, and a developer cannot change it locally.
Claim check:
- GitHub opened a public preview of centrally managed Copilot sandbox policies in JetBrains IDEs. (confirmed only by the carrying publication: evidence; «Enterprise-managed sandbox policies for Copilot in JetBrains are now in public preview»)
- The policies give administrators control over Copilot access to the file system and network. (confirmed only by the carrying publication: evidence; «they let IT teams centrally set what a sandboxed Copilot session can and can’t do: whether sandboxing runs at all, what filesystem and network paths it can reach»)
- An administrator can set a proxy, access to developer tools, and Keychain access on macOS. (confirmed only by the carrying publication: evidence; «which proxy it routes through, whether it can touch developer tools, and — on Mac — whether it gets access to the Keychain»)
- A locked setting appears as managed in the JetBrains plugin, and a developer cannot change it locally. (confirmed only by the carrying publication: evidence; «Once an admin locks a setting, it shows up in the JetBrains plugin marked “(managed),” and developers can’t override it locally.»)
Publications:
- https://devops.com/github-tightens-copilots-billing-and-governance-rules-ahead-of-a-busy-fall
- https://devops.com/github-puts-guardrails-on-copilots-sandbox-inside-jetbrains-ides
score 74.2 · kind release · revision 2 · stories st-15h2ql8