Evidence record / github-copilot-cli
A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.
2026-09-21-github-copilot-cli-1-0-85-allowmanagedhooksonly-was-bypassable-by-extension-callbacks
1.0.85: allowManagedHooksOnly was bypassable by extension callbacks. The allowManagedHooksOnly policy now also blocks extension-registered preToolUse, postToolUse and postToolUseFailure callbacks, which “previously bypassed the managed-only lockdown.” Same release: configured hooks now keep running after an extension restart instead of silently stopping and later denying every tool call (L126); managed Edit and Write rules now apply to recognized shell redirections and in-place sed (L135); an MDM or managed-settings sandbox policy no longer discards sandbox.allowBypass (L90).
Channel: tagged-release. Half: defect. Date: 2026-09-16.
Operator consequence: Enterprise admins who rely on managed-only hooks as a control should treat every version before 1.0.85 as not enforcing it against extensions, and require 1.0.85+ fleet-wide. The Edit/Write-via-redirection change means a deny rule on writes to a path now also catches echo > path and sed -i; expect new prompts in scripts that wrote that way.
Receipt
Finding metadata
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Finding ID: 2026-09-21-github-copilot-cli-1-0-85-allowmanagedhooksonly-was-bypassable-by-extension-callbacks
Profile citations
- github-copilot-cli / claim / managed-hooks-bypass
Source links
Primary links, including exact changelog lines when available.
Versioned source: run artifact