Skip to content

Commit 2494c72

Browse files
authored
Merge pull request #46083 from github/repo-sync
Repo sync
2 parents 4dd05e9 + c51c0ef commit 2494c72

8 files changed

Lines changed: 193 additions & 46 deletions

File tree

‎content/copilot/how-tos/administer-copilot/manage-for-enterprise/use-managed-settings/override-settings-for-teams.md‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -18,9 +18,9 @@ To make a key eligible for team overrides, you will mark it as `overridable` in
1818

1919
## Supported keys
2020

21-
The `{ "overridable": <VALUE> }` syntax applies to the `model`, `permissions.disableBypassPermissionsMode`, `permissions.deny`, `permissions.ask`, `permissions.allow`, `allowedMcpServers`, and `deniedMcpServers` keys.
21+
The `{ "overridable": <VALUE> }` syntax applies to the `model`, `permissions.disableBypassPermissionsMode`, `permissions.deny`, `permissions.ask`, `permissions.allow`, `allowedMcpServers`, `deniedMcpServers`, `extraKnownMarketplaces`, `strictKnownMarketplaces`, and `sandbox` keys.
2222

23-
`enabledPlugins` and `extraKnownMarketplaces` work additively. The enterprise `{% data variables.copilot.managed_setting_file %}` sets a baseline, and an enterprise team file can add more plugins and marketplaces on top of it.
23+
`enabledPlugins` works additively. The enterprise `{% data variables.copilot.managed_setting_file %}` sets a baseline, and an enterprise team file can add more plugins on top of it.
2424

2525
For a full description of these keys and their syntax, see [AUTOTITLE](/copilot/reference/enterprise-administrators/enterprise-managed-settings).
2626

@@ -64,7 +64,7 @@ You will use `copilot/{% data variables.copilot.team_mappings_file %}` and the `
6464
}
6565
```
6666

67-
1. Create the team settings file under `copilot/{% data variables.copilot.team_settings_directory %}`. You can include any keys you marked as overridable, plus the additive keys `enabledPlugins` and `extraKnownMarketplaces`. Every other key stays governed by your enterprise default.
67+
1. Create the team settings file under `copilot/{% data variables.copilot.team_settings_directory %}`. You can include any keys you marked as overridable, plus the additive key `enabledPlugins`. Every other key stays governed by your enterprise default.
6868

6969
```json
7070
{

‎content/copilot/reference/enterprise-administrators/enterprise-managed-settings.md‎

Lines changed: 48 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -144,6 +144,25 @@ The following source types are supported:
144144

145145
See [AUTOTITLE](/copilot/concepts/enterprise/plugin-standards).
146146

147+
For server-managed enterprise team overrides, wrap the complete marketplace map in `overridable`:
148+
149+
```json
150+
{
151+
"extraKnownMarketplaces": {
152+
"overridable": {
153+
"enterprise-plugins": {
154+
"source": {
155+
"source": "github",
156+
"repo": "OWNER/REPO"
157+
}
158+
}
159+
}
160+
}
161+
}
162+
```
163+
164+
A team file can then provide a regular marketplace map to replace this default. Include any default marketplaces that the team should retain. If the team omits the key, the enterprise default remains.
165+
147166
## strictKnownMarketplaces
148167

149168
Restricts plugin installation to only the marketplaces explicitly defined by the enterprise. An empty array means complete lockdown. Each entry is a marketplace object with a `source` property indicating the source type. The following source types are supported:
@@ -157,6 +176,20 @@ Restricts plugin installation to only the marketplaces explicitly defined by the
157176
* `"hostPattern"` — requires `hostPattern` (regex matching marketplace hosts)
158177
* `"pathPattern"` — requires `pathPattern` (regex matching marketplace paths)
159178

179+
This key is overridable for enterprise teams. Wrap the complete allowlist in `overridable` at the enterprise level:
180+
181+
```json
182+
{
183+
"strictKnownMarketplaces": {
184+
"overridable": [
185+
{ "source": "github", "repo": "OWNER/REPO" }
186+
]
187+
}
188+
}
189+
```
190+
191+
Use a regular array in the team file to replace the default allowlist. Omitting the key retains the enterprise default. An explicit empty array, `[]`, means complete lockdown, not an unmanaged policy.
192+
160193
## model
161194

162195
Sets your preferred model as the default for new conversations. This lets you choose the default model that best fits your enterprise's workflows. Users can still select a different model on a per-conversation basis.
@@ -288,6 +321,21 @@ The following sub-properties are supported:
288321
* `allowDevToolAccess`: `false` prevents automatic access to development-tool configuration, caches, registries, and toolchains. These locations can contain package registry credentials or tokens. Disabling access can cause package restoration, authenticated registry operations, or builds that use shared caches to fail unless you explicitly grant the required paths.
289322
* `userPolicy`: An object that configures filesystem, network, and macOS-specific Seatbelt restrictions. The supported properties are described in the following sections.
290323

324+
For server-managed enterprise team overrides, wrap the entire sandbox object in `overridable`:
325+
326+
```json
327+
{
328+
"sandbox": {
329+
"overridable": {
330+
"enabled": true,
331+
"allowBypass": false
332+
}
333+
}
334+
}
335+
```
336+
337+
The wrapper must be the only property directly inside `sandbox`. Individual sub-properties, such as `sandbox.enabled`, cannot use their own `overridable` wrappers. A team file's regular sandbox object replaces the entire wrapped default, so include every restriction that should remain. Omitting `sandbox` retains the enterprise default.
338+
291339
### `sandbox.userPolicy.filesystem`
292340

293341
Configures filesystem access for sandboxed processes. Paths should be absolute. Managed grant lists are matched against user-configured lists by exact path string, not by parent or child path coverage.

‎package-lock.json‎

Lines changed: 129 additions & 40 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -296,7 +296,7 @@
296296
"commander": "^15.0.0",
297297
"cross-env": "^10.1.0",
298298
"csv-parse": "7.0.0",
299-
"domhandler": "^5.0.3",
299+
"domhandler": "^6.0.1",
300300
"eslint": "^9.39.3",
301301
"eslint-config-prettier": "^10.1.8",
302302
"eslint-import-resolver-typescript": "^4.4.4",

‎src/graphql/data/fpt/schema-pulls.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -615,7 +615,7 @@
615615
"name": "mergePullRequest",
616616
"id": "mergepullrequest",
617617
"href": "/graphql/reference/pulls#mutation-mergepullrequest",
618-
"description": "<p>Merge a pull request.</p>",
618+
"description": "<p>Merge a pull request.</p>\n<div class=\"ghd-alert ghd-alert-accent\" data-container=\"alert\"><p class=\"ghd-alert-title\"><svg version=\"1.1\" width=\"16\" height=\"16\" viewBox=\"0 0 16 16\" class=\"octicon mr-2\" aria-hidden><path d=\"M0 8a8 8 0 1 1 16 0A8 8 0 0 1 0 8Zm8-6.5a6.5 6.5 0 1 0 0 13 6.5 6.5 0 0 0 0-13ZM6.5 7.75A.75.75 0 0 1 7.25 7h1a.75.75 0 0 1 .75.75v2.75h.25a.75.75 0 0 1 0 1.5h-2a.75.75 0 0 1 0-1.5h.25v-2h-.25a.75.75 0 0 1-.75-.75ZM8 6a1 1 0 1 1 0-2 1 1 0 0 1 0 2Z\"></path></svg></p>\n<p>\nWe recommend using the <a href=\"/en/rest/pulls/pulls#merge-a-pull-request-asynchronously\">asynchronous merge REST\nAPI</a> instead.\nThis mutation does not support stacked pull requests.</p>\n</div>",
619619
"isDeprecated": false,
620620
"inputFields": [
621621
{

‎src/graphql/data/fpt/schema.docs.graphql‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -28648,6 +28648,11 @@ type Mutation @docsCategory(name: "meta") {
2864828648

2864928649
"""
2865028650
Merge a pull request.
28651+
28652+
> [!NOTE]
28653+
> We recommend using the [asynchronous merge REST
28654+
API](${externalDocsUrl}/rest/pulls/pulls#merge-a-pull-request-asynchronously) instead.
28655+
> This mutation does not support stacked pull requests.
2865128656
"""
2865228657
mergePullRequest(
2865328658
"""

‎src/graphql/data/ghec/schema-pulls.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -615,7 +615,7 @@
615615
"name": "mergePullRequest",
616616
"id": "mergepullrequest",
617617
"href": "/graphql/reference/pulls#mutation-mergepullrequest",
618-
"description": "<p>Merge a pull request.</p>",
618+
"description": "<p>Merge a pull request.</p>\n<div class=\"ghd-alert ghd-alert-accent\" data-container=\"alert\"><p class=\"ghd-alert-title\"><svg version=\"1.1\" width=\"16\" height=\"16\" viewBox=\"0 0 16 16\" class=\"octicon mr-2\" aria-hidden><path d=\"M0 8a8 8 0 1 1 16 0A8 8 0 0 1 0 8Zm8-6.5a6.5 6.5 0 1 0 0 13 6.5 6.5 0 0 0 0-13ZM6.5 7.75A.75.75 0 0 1 7.25 7h1a.75.75 0 0 1 .75.75v2.75h.25a.75.75 0 0 1 0 1.5h-2a.75.75 0 0 1 0-1.5h.25v-2h-.25a.75.75 0 0 1-.75-.75ZM8 6a1 1 0 1 1 0-2 1 1 0 0 1 0 2Z\"></path></svg></p>\n<p>\nWe recommend using the <a href=\"/en/enterprise-cloud@latest/rest/pulls/pulls#merge-a-pull-request-asynchronously\">asynchronous merge REST\nAPI</a> instead.\nThis mutation does not support stacked pull requests.</p>\n</div>",
619619
"isDeprecated": false,
620620
"inputFields": [
621621
{

‎src/graphql/data/ghec/schema.docs.graphql‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -28648,6 +28648,11 @@ type Mutation @docsCategory(name: "meta") {
2864828648

2864928649
"""
2865028650
Merge a pull request.
28651+
28652+
> [!NOTE]
28653+
> We recommend using the [asynchronous merge REST
28654+
API](${externalDocsUrl}/rest/pulls/pulls#merge-a-pull-request-asynchronously) instead.
28655+
> This mutation does not support stacked pull requests.
2865128656
"""
2865228657
mergePullRequest(
2865328658
"""

0 commit comments

Comments
 (0)