GitHub's Copilot weekly roundup was published on October 9, 2026, covering updates from the week beginning October 5. The most useful changes include local sandboxing for agent sessions, Claude Haiku 5.5 access across paid Copilot plans, discovery of supported local Ollama models in Copilot CLI, and side-by-side agent sessions in VS Code. The roundup date is October 9; some individual features have their own October 7 release notes.
At a glance
| Update | Where it applies | What to know |
|---|---|---|
| Local sandboxing | Copilot CLI, Copilot app and VS Code sessions using Agent Host | Generally available and included with Copilot at no extra charge, but local sandboxing is off by default. |
| Claude Haiku 5.5 | Copilot Pro, Pro+, Max, Business and Enterprise | Availability is plan-specific; check your model picker and organization policies. |
| Local Ollama models | Copilot CLI | Use /model to discover supported models from a running local Ollama instance. |
| Agent sessions | VS Code 1.141 | View sessions side by side and clean up inactive session worktrees. |
| Separate accounts | GitHub Copilot app | The account providing the Copilot license can differ from the account used to access repositories. |
Local sandboxing is the main security change
Local sandboxing restricts the filesystem, network and system capabilities available to commands that Copilot runs. GitHub says it is now generally available in Copilot CLI, the Copilot app and VS Code sessions using Agent Host, with no extra Copilot charge for local sandboxing.
There is an important setup detail: GitHub's documentation says local sandboxing is turned off by default. Until it is enabled, shell commands run with the same access as your user account. In Copilot CLI, you can enable it with /sandbox enable; in the Copilot app, project settings define the default for new local sessions and can be changed for an active session. The CLI and app settings are separate, so changing one does not change the other.
Local sandboxing is not a full virtual machine or container. GitHub describes it as lighter-weight operating-system isolation that restricts what a process can read, write or reach on the network. That can reduce risk, but teams with stricter isolation requirements should review the implementation and test the policy against their threat model. Cloud sandboxing is a separate option and is billed based on usage.
Claude Haiku 5.5 is available across paid Copilot plans
The October 9 roundup says Claude Haiku 5.5 is available to Copilot Pro, Pro+, Max, Business and Enterprise users. This is a model-availability update, not a claim that every account will automatically select the model. Availability can still depend on the plan, organization policy and the current model picker.
For teams choosing a model, test it on the tasks that matter: code explanation, focused edits, test generation and multi-file changes. Do not assume a smaller or faster model will perform equally well on every repository. Keep your normal tests and code review process regardless of which model is selected.
Copilot CLI can discover supported local Ollama models
GitHub says Copilot CLI can use /model to discover supported models from a running local Ollama instance alongside configured models and cloud models supplied by Copilot. This can make it easier to compare a local workflow with a hosted model without leaving the CLI.
The word supported matters: the announcement does not promise that every model available through Ollama works with Copilot CLI. You need a running local Ollama service and a compatible model. Local inference also uses your machine's CPU, GPU and memory, so performance depends on your hardware and model size. Do not treat “local” as proof that every part of a workflow stays on-device; review the configuration and any tools or services the agent can call.
Account separation and VS Code session management
The Copilot app now supports separate GitHub accounts for the Copilot license and the repositories being accessed. For example, a developer may use an employer-provided Copilot license while opening repositories through another account. This is useful for some multi-account setups, but it does not bypass repository permissions or an organization's access policies.
In VS Code 1.141, agent sessions can be arranged side by side in a grid. That helps when you want to compare separate tasks or watch more than one session. The release also adds a worktree cleanup view so you can see how much disk space inactive session worktrees use and choose which ones to remove. Review a worktree before deleting it if it contains uncommitted work you may still need.
A safe rollout checklist
- Enable local sandboxing deliberately and test the filesystem and network rules with a low-risk repository.
- Confirm that credentials, private keys and production data are not unnecessarily available to an agent.
- Check the eligible Copilot plan and organization settings before relying on Claude Haiku 5.5.
- Use
/modelto inspect supported Ollama models, then test quality and latency on a fixed set of tasks. - Keep code review and automated tests in place, and inspect diffs before merging.
- Clean up inactive worktrees only after checking for uncommitted changes.
For a separate view of static security analysis, see our CodeQL 2.27.2 release guide and our Copilot Code Review API guide. Those tools complement agent assistance rather than replacing it.
Frequently asked questions
Is local sandboxing enabled automatically?
No. GitHub's documentation says local sandboxing is off by default. Enable it and review the policy for the environment you use.
Does local sandboxing cost extra?
GitHub says local sandboxing is included with Copilot at no extra charge. Cloud sandboxing is separate and billed based on usage.
Can Copilot CLI use any Ollama model?
GitHub describes discovery of supported models from a running Ollama instance. It does not promise compatibility with every Ollama model.
Sources
- GitHub Changelog: Copilot weekly releases — October 5 (published October 9, 2026).
- GitHub Docs: About cloud and local sandboxes for GitHub Copilot.
- GitHub Changelog: Discover local models in GitHub Copilot CLI (October 7, 2026).