Skip to content

Configure the organization Copilot coding-agent network allowlist #17

Description

@szmyty

Outcome

Establish a reviewed organization baseline for outbound network access used by GitHub Copilot coding agents, starting from GitHub's recommended allowlist and adding Ego Hygiene-specific exceptions only when justified.

Scope

  • Adopt GitHub's current Copilot coding-agent recommended allowlist as the baseline.
  • Document organization-specific additions, removals, and rationale.
  • Prefer minimum necessary outbound access over unrestricted networking.
  • Define how repositories request exceptions and how those exceptions are reviewed.
  • Document how changes to GitHub's recommended list are detected and evaluated.
  • Keep this policy separate from organization Copilot custom instructions; this issue governs network access, not coding style or agent behavior.
  • Record any security/privacy constraints for package registries, documentation domains, APIs, and external services.

Acceptance criteria

  • The organization has a documented coding-agent network allowlist baseline.
  • GitHub's recommended Copilot coding-agent allowlist is explicitly referenced and reviewed.
  • Ego Hygiene-specific entries have an owner and rationale.
  • An exception/request process exists for repository-specific needs.
  • The policy defines a review/update cadence for upstream GitHub changes.
  • Unrestricted outbound network access is not the default.
  • The relationship to organization Copilot instructions is documented.

References

Related

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions