github / github/copilot-cli

autoUpdate: false in settings.json is ignored — CLI re-execs a cached prerelease build over the stable version installed via npm

Open
#4,534 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

area:configuration area:installation
Dominant language
Shell
Stars
11.2k
Forks
1.9k
Avg merge
14h 16m
Merged PRs (30d)
6

Description

Summary

Once a prerelease build has been cached under ~/.copilot/pkg/<platform>/, the
CLI keeps re-execing it on every launch, even when:

  • a stable version is installed via npm, and
  • "autoUpdate": false is set in ~/.copilot/settings.json.

The documented setting has no effect, because the re-exec into the newer cached
build happens before settings are read. Only the COPILOT_AUTO_UPDATE=false
environment variable changes the behaviour.

The practical result: a user who tries the prerelease channel once cannot get
back to stable through any documented mechanism, and cannot tell they are still
on a prerelease unless they check --version.

Environment

  • Cached prerelease build: 1.0.81-5
  • Stable installed via npm: 1.0.80
  • Node.js v22.21.1, Linux x64

Steps to reproduce

  1. Be on a prerelease build (so it is cached under ~/.copilot/pkg/<platform>/).
  2. npm install -g @github/copilot — installs the current stable release.
    Confirm node_modules/@github/copilot-<platform>/package.json reports the
    stable version.
  3. Set "autoUpdate": false in ~/.copilot/settings.json.
  4. Run copilot --version.

Expected: the stable version, since that is what is installed and
auto-update is disabled.

Actual: the cached prerelease version.

$ copilot --version
GitHub Copilot CLI 1.0.81-5.

The env var behaves differently from the setting

Running the npm-installed platform binary directly:

$ ./copilot --version
GitHub Copilot CLI 1.0.81-5.            # re-execs the cached prerelease

$ COPILOT_AUTO_UPDATE=false ./copilot --version
Package extraction took 7995ms
GitHub Copilot CLI 1.0.80.              # runs the installed stable build

Same binary, same settings file, opposite results — so autoUpdate in
settings.json and COPILOT_AUTO_UPDATE are not equivalent, though
copilot update --help presents them as alternatives:

Use --no-auto-update or set COPILOT_AUTO_UPDATE=false to disable it manually.

and copilot help config documents:

autoUpdate: whether to automatically download updated CLI versions; defaults to true.

There is no documented way back to stable

copilot update stable refuses, because it only compares version ordering and
will not move backwards:

$ copilot update stable
Checking for updates...
Checking GitHub for the latest release...
No update needed, current version is 1.0.81-5, fetched latest release is v1.0.80

Since prerelease versions sort above the current stable release, anyone on
a prerelease is pinned there until a higher stable ships. Combined with the
ignored autoUpdate setting, the only working escape routes are undocumented:
set COPILOT_AUTO_UPDATE=false, or manually delete the cached build
directories.

Also, COPILOT_PKG_CACHE_HOME pointed at an empty directory did not change
resolution — the cached prerelease was still selected.

Suggested fixes

  1. Make "autoUpdate": false in settings.json honoured by the re-exec path,
    or document that it does not cover it.
  2. Give copilot update <channel> a way to switch channels downward
    (e.g. --allow-downgrade, or treat an explicit channel argument as
    authoritative over version ordering).
  3. Surface the channel in --version output, so it is obvious when a
    prerelease is being used.

Found while trying to move off the prerelease channel after hitting #4533 (a
separate defect). This report is only about being unable to leave the
prerelease channel.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by tracing the CLI launch and re-exec path that selects ~/.copilot/pkg// before settings.json is read, then inspect copilot update handling and version comparison. Reproduce with a cached prerelease, stable npm package, and autoUpdate false; done when documented configuration prevents unintended re-exec or explicit channel switching works.

Written by the indexing model from the issue text.

Assessment

Tech stack
node.js
Domain
cli, release
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.