github / github/copilot-cli

Enterprise policy to allow yolo in CLI sandbox

未关闭
#4,783 2 条评论 1 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

triage
主要语言
Shell
星标
11.2k
派生
1.9k
平均合并
14 小时 16 分钟
30 天内合并 PR
6

描述

Describe the feature or problem you'd like to solve

There should be a separate policy scope for cli sandboxes for yolo mode and other permission related enterprise policies

Proposed solution

Enterprise policies allow restrictive access for setting like yolo mode, and other folder/tool settings. These are generally used because of trust within an enterprise environment, where broad tool access could cause damage. The point of sandbox mode is to create a 'safe place' for developers to work agentically. Currently, when yolo mode is disabled by enterprise policy, it applies to both standard and sandbox mode. Ideally, enterprise policies should have a separate sandbox hierarchy where any policy which could make sense to configure more permissively would allow a separate setting.

Example prompts or workflows

No response

Additional context

No response

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

未指定任何文件、测试或入口点。首先跟踪现有的 enterprise policy 对 yolo mode 和 CLI sandbox 的处理方式,然后确定哪些与权限相关的设置需要单独的 sandbox 作用域。完成的标准是 sandbox 模式可以使用自己的 policy 层级,同时不改变 standard 模式的限制。

由索引模型根据 Issue 内容生成。

评估

技术栈
shell
领域
authorization, cli, security
Issue 类型
功能
难度
5/5
预计耗时
一周以上
活跃度
活跃
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。