AI觉醒星球
Awakening is here
Knowledge File / 全球热点解读
2026-06-26 6 浏览 公开

企业托管设置现支持在 VS Code 和 GitHub Copilot CLI 中使用 strictKnownMarketplaces

企业现可通过严格已知市场设置,控制用户安装插件的来源,提升安全性。

SOURCE / 全球热点解读 MIN / 9 ACCESS / 公开 POST / 2026-06-26 05:30:42

原贴

查看原文
作者:Allison 来源站点:github.blog 原贴时间:

原文

Enterprises can now control which plugins their users can install in GitHub Copilot CLI and VS Code. This setting is now available in public preview. Add strictKnownMarketplaces to your enterprise-managed settings.json , and Copilot will only allow plugins to be installed from the marketplaces you’ve explicitly defined. GitHub Copilot automatically pulls and applies these settings for users licensed through your Copilot Business or Copilot Enterprise account. This is a direct way to enforce your client governance strategy prior to tool execution by removing the risk of users installing untrusted plugins. This update builds on the enterprise-managed plugins for Copilot CLI and VS Code capabilities we launched earlier. To learn more, see our documentation on Enterprise managed client settings . Join the discussion within GitHub Community .

中文翻译

企业现在可以控制其用户在 GitHub Copilot CLI 和 VS Code 中安装哪些插件。此设置现已公开预览。将 strictKnownMarketplaces 添加到您的企业托管 settings.json 中,Copilot 将只允许从您明确定义的市场安装插件。GitHub Copilot 会自动拉取并为通过您的 Copilot Business 或 Copilot Enterprise 账户许可的用户应用这些设置。这是一种在执行工具前强制执行客户端治理策略的直接方式,通过消除用户安装不受信任插件的风险。此更新基于我们之前推出的 Copilot CLI 和 VS Code 功能的企业托管插件。要了解更多,请参阅我们的企业托管客户端设置文档。在 GitHub 社区内加入讨论。

核心信息

企业现可通过严格已知市场设置,控制用户安装插件的来源,提升安全性。

  • 企业现可通过严格已知市场设置,控制用户安装插件的来源,提升安全性。
  • 原贴提到:Enterprises can now control which plugins their users can install in Git
  • 来源:github.blog

详细解读

信号:GitHub 正在加强企业级 AI 工具的安全管控能力,将插件安装限制集成到 Copilot 生态中。

重要性:VS Code 和 Copilot CLI 是开发者日常高频使用的工具,开放插件生态带来便利的同时也引入安全风险。企业无法确保用户安装的每个插件都是可信的,该功能让 IT 管理员能在工具执行前就锁定安装源,从源头防止供应链攻击或数据泄露。

价值人群:对使用 Copilot Business/Enterprise 的企业安全团队、IT 管理员、DevOps 负责人最有价值。他们可以直接配置策略,无需依赖用户自觉。

行动建议:1. 立即在 enterprise-managed settings.json 中添加 strictKnownMarketplaces 声明。2. 定义显式的可信市场列表(如官方 VS Code Marketplace、GitHub Marketplace)。3. 通知开发者新策略生效,并测试常用插件兼容性。

风险与限制:过于严格的限制可能影响开发效率,若开发依赖的插件未在列表中,需走审批流程。此外,该功能目前为公开预览,可能存在配置不生效或兼容性问题。

信息差价值

这条内容的真正价值,不只是“有人发布了一个新功能”,而是它揭示了 github.blog 背后的产品方向、工作流变化或竞争信号。对 OPC 来说,这种信息可以转化成持续追踪的栏目选题。

如果把《企业托管设置现支持在 VS Code 和 GitHub Copilot CLI 中使用 strictKnownMarketplaces》放到你的内容系统里,它最大的价值在于帮助读者更快看懂“为什么值得关注”,而不是只看到一条碎片化动态。

参考来源

上一篇 Copilot代码审查:分析深度与效率更新 下一篇 Codex 在 ChatGPT 移动 App 正式可用