Evidence record / github-copilot-cli
A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.
2026-09-21-github-copilot-cli-1-0-81-fail-closed-managed-settings-acp-allow-all-revoke-fixed-per-entry-managed-plugins
1.0.81: fail-closed managed settings, ACP allow-all revoke fixed, per-entry managed plugins. forceRemoteSettingsRefresh now fails closed: no cached policy on fetch failure; the session applies the restrictive undetermined-policy posture (non-default MCP servers blocked, bypass-permissions mode unavailable, plugin mutations blocked) (L249). Turning allow-all off from an ACP client now actually reaches the permission engine; before, it could report success while permissions stayed on (a launch-flag --allow-all-* baseline is still left intact) (L228). Managed settings win per entry for enabledPlugins and extraKnownMarketplaces (L252). New defaultMode and defaultPermissionMode settings choose startup approval behavior (L210). MCP spec 2026-07-28 support (L203). Hooks receive OpenTelemetry traceparent (L204). Removed /plugins; hook and LSP enable/disable toggles are “temporarily unavailable” (L256-L257).
Channel: tagged-release. Half: both. Date: 2026-08-27.
Operator consequence: If you drive Copilot over ACP (Omnigent or any other ACP client), a revoke of allow-all before 1.0.81 may have been cosmetic; upgrade and do not rely on revoke when the session was launched with --allow-all-*. That also answers the contract’s ACP question: ACP is a shipping, versioned surface, and the launch flags, not the ACP client, set the floor. Admins using forceRemoteSettingsRefresh should expect sessions to start restricted when GitHub is unreachable. Anyone who toggled hooks from /plugins lost that UI in 1.0.81; edit settings instead.
Receipt
Finding metadata
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Finding ID: 2026-09-21-github-copilot-cli-1-0-81-fail-closed-managed-settings-acp-allow-all-revoke-fixed-per-entry-managed-plugins
Profile citations
- github-copilot-cli / claim / fail-closed-managed-settings-acp-revoke
Source links
Primary links, including exact changelog lines when available.
- tagged commit file2026-09-21-github-copilot-cli-1-0-81-fail-closed-managed-settings-acp-allow-all-revoke-fixed-per-entry-managed-pluginsgithub/copilot-cli / changelog.md#L200-L257github release2026-09-21-github-copilot-cli-1-0-81-fail-closed-managed-settings-acp-allow-all-revoke-fixed-per-entry-managed-pluginsgithub/copilot-cli / v1.0.81
Versioned source: run artifact