github / github/copilot-cli

The Copilot CLI ignore "exclude content" of organization settings

未關閉
#221 2 則留言 11 個 reaction 已指派 1 人 已被 @williammartin 認領 在 GitHub 檢視
主要語言
Shell
星號
11.2k
分支
1.9k
平均合併
14 小時 16 分鐘
30 天內合併 PR
6

描述

### Describe the bug

Organization administrators don't allow users to transmit confidential company data to the cloud.
"excluding content" is an extremely important feature for this purpose.

Many companies likely use this tool under the assumption this feature works properly.
Information leakage incidents are occurring worldwide due to this tool.

## detail

I set below yaml to "exclude-content" of our organization settings.
(https://docs.github.com/en/copilot/how-tos/configure-content-exclusion/exclude-content-from-copilot)

This setting will keep the contents of “.env” files confidential across all repositories.
```yaml
"*":
- "**/.env"
```

Then, launch The Copilot CLI in any repository.
Instructs the system to read the .env file located in this repository.

### prompt

```plain
Check a .env file content. # in Japanese
```

### response

```plain
The contents of the env file are as follows.
1. hogehoge 2.
2nd line is blank (or unset).
# in Japanese
```
Image

Copilot CLI can access files that should be excluded.

When making a same request in GitHub Copilot Chat for VS Code, you'll receive a response stating that the file cannot be read (or that its existence is not recognized).

### Affected version

Version 0.0.334 Commit 26896a6

### Steps to reproduce the behavior

_No response_

### Expected behavior

The contents of the “.env” file cannot be read. Or, the file's existence is not recognized.

### Additional context

_No response_

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。