Skip to content
Oday Bakkour
Back to Knowledge Hub

Copilot Sandboxing Goes GA, OpenCode 1.19 and Claude Code 2.1.296 Land

Oday Bakkour profile photo
Oday Bakkour
3 min read
Share
Copilot Sandboxing Goes GA, OpenCode 1.19 and Claude Code 2.1.296 Land

A quiet-looking weekend on the changelogs hides one genuinely important shift: sandboxing is becoming a default expectation for coding agents. GitHub shipped local sandboxing for Copilot to general availability, OpenCode changed how it updates itself, and both Claude Code and Codex pushed new point releases. Here is the roundup, with sources.

GitHub Copilot: local sandboxing is generally available

According to the GitHub changelog, local sandboxing is now GA in Copilot CLI, the Copilot app, and VS Code sessions using Agent Host. Sandboxes restrict what Copilot-initiated tools and commands can reach: files, network and credentials, based on policies set by developers or their organization.

It is powered by Microsoft eXecution Container (MXC), which applies one policy model through native controls on Windows, macOS and Linux. Enterprises can require sandboxing and enforce settings developers cannot weaken. It comes at no extra cost and applies regardless of which model Copilot is using.

Also this week: Claude Haiku 5.5 arrived in Copilot, Copilot CLI can now discover local models, and Copilot for JetBrains got new controls and chat improvements.

OpenCode 1.19: updates are now opt-in, and OpenCode 2 is in sight

The OpenCode v1.19.0 release makes TUI updates go through an explicit /update command; updates are no longer installed automatically. It also adds opencode upgrade --major to move to OpenCode 2, permits the OpenAI ultrafast service tier, and validates PTY connection origins and tickets before checking whether a PTY exists, a small but welcome hardening step.

The pattern matches the Copilot news: teams want predictable, controlled agent tooling rather than silent changes.

Claude Code 2.1.296

Per the Claude Code changelog, 2.1.296 adds a code policy key for the Claude apps gateway, an autoCompactWindow setting for subagents, and new environment variables such as CLAUDE_CODE_WORKFLOW_SUBAGENT_MODEL and CLAUDE_CODE_OVERLOADED_RETRY_MAX_DELAY_MS. The Read tool gains an allow_large option for reading big text files in one call, the default MCP tool description limit rises from 2,048 to 4,096 characters, and several managed-settings hook issues are fixed.

The larger MCP description limit is useful if your servers ship detailed tool docs that were previously truncated.

OpenAI Codex 0.162.1

The latest Codex release is a bug-fix update: it fixes a TUI crash when asynchronous questions span multiple lines (preserving line breaks and full hyperlink destinations) and startup failures caused by mismatches between a running background server's feature settings and CLI defaults. Compatibility checks now apply only to explicit command-line feature overrides. Alpha builds of 0.163.0 are already circulating.

What to do this week

  • Copilot users: review your organization's sandbox policy and decide whether to require it.
  • OpenCode users: run /update deliberately, and read the OpenCode 2 notes before using --major.
  • Claude Code and Codex users: update to 2.1.296 and 0.162.1 for the fixes above.

References

Add Oday Bakkour as a preferred source on Google

Comments

Share your thoughts and join the conversation

Leave a Comment

Loading comments...
RELATED