Sr. Content Developer at Microsoft, working remotely in PA, TechBash conference organizer, former Microsoft MVP, Husband, Dad and Geek.
162451 stories
·
33 followers

v1.0.17

1 Share

Feature: replace session tools mid-session (experimental)

A live session's client-supplied tools and handlers can now be replaced in a single call without recreating the session. Built-in, MCP, and plugin tools are unaffected; pass an empty list to remove all of this client's tools. (ef04633)

  • TypeScript: await session.setTools([tool])
  • C#: await session.SetToolsAsync(tools)
  • Python: await session.set_tools([tool])
  • Go: session.SetTools(ctx, tools)
  • Java: session.setTools(tools).get()
  • Rust: session.set_tools([tool]).await?

Feature: sub-agent lifecycle hooks

Register OnSubagentStart and OnSubagentStop hooks on the parent session. Start hooks can prepend context to a sub-agent's first prompt. Stop hooks can inspect the response, replace it, or block the stop with a follow-up instruction. (6b4f3a3)

Hooks = new SessionHooks { OnSubagentStart = (input, inv) =>
    Task.FromResult(new() { AdditionalContext = "Read the file first." }) }
Hooks: &copilot.SessionHooks{OnSubagentStart: func(in copilot.SubagentStartHookInput, inv copilot.HookInvocation) (*copilot.SubagentStartHookOutput, error) {
    return &copilot.SubagentStartHookOutput{AdditionalContext: "Read the file first."}, nil }}

Feature: binary session filesystem providers

A session filesystem provider can now serve exact file bytes, so the view tool can read provider-only images. Implement the binary provider interface and set Capabilities.Binary. Reads and writes are capped at about 48 MiB. (6b4f3a3)

  • C#: implement ISessionFsBinaryProvider (ReadFileBytesAsync, WriteFileBytesAsync)
  • Go: implement SessionFSBinaryProvider (ReadFileBytes, WriteFileBytes)

Other changes

  • improvement: update the bundled Copilot CLI to 1.0.93-4 and regenerate RPC and session event types across all SDKs
  • improvement: [C#] add a custom session event JSON converter and updated generated session event types (5b2d7cd)
  • feature: new session events tool.shell_output and human_response.recorded, plus file-edit details on tool.execution_complete (6b4f3a3)
  • feature: new customization reload RPC result types and model discovery types (6b4f3a3)

Full Changelog: v1.0.16...v1.0.17

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by Release Notes Generator · copilot · auto · 30.3 AIC · ⌖ 5.15 AIC · ⊞ 10.5K

Read the whole story
alvinashcraft
27 seconds ago
reply
Pennsylvania, USA
Share this story
Delete

1.0.93

1 Share

2026-10-07

  • Add enterprise permissions.limitTo to enforce managed domain boundaries for network requests
  • Run safe /user commands immediately during active turns, reject unsafe remote commands during active turns without opening dialogs, and queue commands advertised by relay hosts
  • Plugin skill commands stay available after reloading enabled plugins
  • Sandbox local-network allowlists now include localhost and loopback hosts.
  • GitHub.com Connector users can expand GitHub CLI permissions in place and retry connections without switching sign-in methods.
  • Honor --context long_context at startup and show accurate context allowance in /context
  • Connecting a Connector without the required GitHub scope now prompts to update your authorization instead of failing with an authentication error
  • Warmed language servers stay running across LSP requests when sandboxing is disabled
  • Clicking a truncated compact shell command expands it
  • Command sandboxing is available to all users via /sandbox and --sandbox.
  • MCP server configuration changes apply between turns without restarting the session.
  • Model picker updates the recommended list to prioritize GPT-6.1 Sol, GPT-6 Astra/Luna, and Claude 5.5 models.
  • Read user settings only from ~/.copilot/settings.json; user-setting keys in ~/.copilot/config.json are ignored.
Read the whole story
alvinashcraft
33 seconds ago
reply
Pennsylvania, USA
Share this story
Delete

dotnet-1.24.0

1 Share

Changes:

  • 245d428 .NET: Restore source-only release solution filter (#9140) [ #8537 ]
  • d0ccaa6 .NET: Preserve explicit null session state across roundtrips (#9012)
  • 279d97f .NET: Honor disabled recent search memory (#9013)
  • 41e785f .NET: Preserve lazy request messages through agent invocation (#9017)
  • 9251bc9 .NET: Update version for 1.24.0 release (#9120)
  • 73a96cb .NET: Stabilize Anthropic agent package (#9111) [ #9110 ]
  • 0774607 .NET: Reject sensitive declarative identifiers (#9071)
  • 41c4f1c .NET: Harden LocalCodeAct capability validation (#9057)
See More
  • b9d24c8 .NET: test: add loopback destination regression coverage (#9064)
  • bd5ab48 .NET: Validate handoff request lifecycle before routing (#8855)
  • 636e856 .NET: Synchronize background task metadata and defer publication until session creation (#8933)
  • 6ef0b73 .NET: Isolate GitHub Copilot attachment staging (#8846)
  • 52fed57 .NET: Preserve atomic cache creation across factory failures (#8931)
  • a2f4506 .NET: Skip empty Foundry memory context messages (#8932)
  • 5019894 Improve MCP skill archive loading consistency (#8937)
  • 2e8b58c .NET: Return only the items between 'after' and 'before' when listing response input items (#8872) [ #8871 ]
  • a15c019 .NET: document A2A authentication and tool authorization (#8491)
  • d52db94 .NET: Reject a MaxBatchSize outside 1..100 in CosmosChatHistoryProvider (#8870) [ #8869 ]
  • 99215f9 .NET: Update retired Claude model in 04_MultiModelService sample (#8879) [ #5074, #8878 ]
  • 7634356 .NET: Fix Foundry MCP approval replay IDs (#8873)
  • 2f5713f .NET: Preserve A2A run errors when session save fails (#8877)
  • 2a7470a .NET: Publish synthetic terminal responses with their events (#8885)
  • e23f3c8 .NET: Validate HTTP header delimiters (#8847)
  • 5343347 .NET: Allow compaction for per-service-call local chat history (#8845)
  • 71e84a0 .NET: Propagate ChatHistoryMemoryProvider caller cancellation (#8813)
  • e626cef .NET: Bind MCP approval headers to approved invocation (#8834)
  • ba32033 .NET: Reject protected values in declarative MCP invocations (#8832)
  • 77f832f .NET: fix(harness): honor cancellation while waiting for background agents (#8805)
  • 202e85d .NET: Remove unused GitTag property (#8827)
  • 7638874 .NET: Dispose AI context streaming enumerators (#8812)
  • 7a98aa9 .NET: Honor a zero message limit in ValkeyChatHistoryProvider (#8809)
  • 06e9b48 .NET: Python: Add optional OAuth consent origin allowlist to Foundry hosting (#8713)

This list of changes was auto generated.

Read the whole story
alvinashcraft
39 seconds ago
reply
Pennsylvania, USA
Share this story
Delete

What is middleware in ASP.NET Core and the gotchas

1 Share

What is middleware in ASP.NET Core and the gotchas
6 minutes by David Grace

Middleware in ASP.NET Core runs on every HTTP request and response. You can write it as a class, but watch out for common mistakes. Forgetting to call next stops the rest of the pipeline from running. Scoped services must be injected into InvokeAsync, not the constructor, since middleware itself lives for the whole app lifetime. You also cannot modify a response after it has started, and background tasks need their own fresh scope to avoid using disposed services.

Beyond grep: Testing codebase memory MCP on .NET
12 minutes by Marek Sirkovský

Most AI coding tools waste tokens by scanning entire codebases when asked simple questions. Codebase Memory MCP tries to fix this by building a local knowledge graph of your code using tree-sitter, then exposing it to AI assistants through MCP. It works well for navigating within a single repository, but struggles with newer C# features and fails to trace relationships across repositories or NuGet package boundaries, a limitation shared by similar tools like GitNexus and Grafel.

Automatic CSRF protection based on fetch metadata headers
14 minutes by Andrew Lock

Andrew takes a look at the new Cross-Site Request Forgery protection added to ASP.NET Core in .NET 11 preview 6, which relies on the Fetch Metadata HTTP headers, instead of the "traditional" anti-CSRF tokens used in earlier versions of .NET Core. He talks about CSRF attacks, the existing protections in ASP.NET Core, discusses why a new approach is possible, and provides a brief recap on Fetch Metadata headers. He also shows how this works in ASP.NET Core as of .NET 11 preview 6, and finally, he takes a look at the implementation behind the feature, as well as dives into why the new feature doesn't really help you if you're using MVC or Razor Pages.

The hidden trap of fixed buffers in C#
7 minutes by Kevin Gosse

Adding a constructor to a struct with a fixed buffer changes how memory is initialized. Without a constructor, the compiler zeroes all memory automatically. With one, fixed buffers are exempt from that zeroing rule, so they retain whatever values were in memory before. This is by design in the C# spec but easy to miss. The fix is to manually clear the buffer inside the constructor.

Guid.CreateVersion7 is NOT a sequential guid for SQL server
5 minutes by Bart Wullems

Using version 7 GUIDs in SQL Server causes index fragmentation, just like random GUIDs do. This happens because SQL Server sorts GUID bytes in a different order than the RFC standard, putting the timestamp in the least significant position. Bart says the fix is to let EF Core or SQL Server generate the ID, or use a library that reorders the bytes to match SQL Server's sorting rules.

And the most popular article from the last issue was:

Read the whole story
alvinashcraft
52 seconds ago
reply
Pennsylvania, USA
Share this story
Delete

100 days later: Microsoft still steers Windows and Copilot users to Edge, everywhere the law lets it

1 Share

One hundred days ago, Mozilla released Over The Edge 2.0, the second independent report from leading experts on deceptive design Dr. Harry Brignull and Cennydd Bowles, on how Windows, Edge, Bing, and Copilot are designed to steer people away from the browser they chose. 

We published the report, and the researchers published the evidence for anyone to analyze. 

Browsers are a powerful tool. So it’s no surprise that the history of the web has many examples of powerful platforms trying to deny people browser choice. Now, as AI reshapes our online experiences, the stakes couldn’t be higher. Browsers are a key distribution layer for AI tools and services, while still determining many of the privacy and security functionality people rely on every day. Steering people toward one browser can therefore shape which AI services reach users and the protections that come with it. 

We also shared the report with Microsoft and talked to them about the issues raised in the report. We knew that an immediate change was unlikely, but we hoped that, when faced with independent evidence of harmful design practices impacting Windows users, they would also want better for people.

Instead, it became clear that Microsoft will respect user choice only when it is forced to. It is important to think about what that means for a company whose operating system runs on more than a billion machines. Microsoft’s standard for respecting people’s choices is legal compliance. Not what’s best for its users. Not its own published principles. Not what’s technically feasible. Not even what it already does for users in Europe.

That’s the most shocking part. Not that Microsoft engages in such tactics – we’ve seen that before. It’s the fact that a better version of Windows already exists, and it is already available today – but only if you live in the European Economic Area (EEA), where the Digital Markets Act (DMA) forced the issue. If you live in the United States, India, the United Kingdom, or most other locations around the world, your experience and your freedom to choose for yourself are worse.

One hundred days later, here is what people outside of the EEA still get: 

  • The Windows 10 message “You’re almost done setting up your PC” uses tricky wording to pull people off the default they picked. 
  • Windows Search and Widgets open links in Edge instead of the browser set as default. 
  • Windows keeps Edge as the default for common browser file types like PDFs and SVG images, even after another browser has been set as default.

And people in the EEA also deserve better:

  • Edge remains pre-pinned to the taskbar; this seems to directly violate the “principled approach to app pinning and app defaults.” 
  • Copilot, Microsoft’s AI tool opens web links in a side-panel instead of the browser people chose, in every region tested, Europe included.
  • Windows Backup, the tool Microsoft uses to guide people through the migration to Windows 11, silently tries to set Edge as the default when it restores a PC and fails to properly bring the user’s own browser along. 

Most of the 2024 patterns are still there. The 2026 patterns are worse. Microsoft is using new surfaces like Copilot and the migration to Windows 11 to further undermine user choice.

Our ask has always been simple: First, give all Windows users the fairer designs that are live in the EEA – regardless of where they are located. Second, stop the remaining harmful design practices that persist in the EEA. That means:

  • Stopping the remaining harmful design tactics in the EEA and ship that standard worldwide.
  • Honoring people’s browser choice everywhere it is currently ignored, including Windows Search, Widgets, Copilot, and Windows Backup restoration. 
  • Applying Microsoft’s own 2023 app pinning principles to Edge itself. 

The Mozilla-commissioned report has never been about intent. It’s about accountability and Microsoft’s responsibility to stop undermining people’s choices. The practices we documented need to change. Statements about intent are not a substitute for action.

In the past 100 days, we’ve stopped waiting for Microsoft to act. Instead, we’ve stepped up public pressure on the company to respect people’s choices.

We are also taking the report’s findings to regulators and policymakers. In Europe, the DMA is the only thing that has moved Microsoft. Everywhere else, the lesson is the same: Microsoft ships only when a regulator requires fairer design. 

We hope that regulators in the US, the UK, India, and Brazil are paying attention. 

Microsoft can do better. It already has, for people in the EEA.

Until it does the same in all jurisdictions, we will keep pointing out the company’s choices and the impact they have on hundreds of millions of users who want something different.

The post 100 days later: Microsoft still steers Windows and Copilot users to Edge, everywhere the law lets it appeared first on The Mozilla Blog.

Read the whole story
alvinashcraft
5 hours ago
reply
Pennsylvania, USA
Share this story
Delete

What’s up, Docsy? Google’s docs project joins the Linux Foundation as AI agents become readers

1 Share
Docsy sticker on a laptop keyboard

Technical documentation is increasingly being read by AI agents, creating a new set of demands around how that information is published and structured. Docsy, the Google-created documentation project used by major cloud native projects, is now moving to the Linux Foundation as it adds features aimed specifically at that machine audience.

Erin McKean, senior developer relations engineer at Google and a member of the Docsy steering committee, announced the move in a keynote on Wednesday at the Linux Foundation’s Open Source Summit Europe in Prague.

First announced by Google in 2019, Docsy is an open source theme for the Hugo static site generator designed for technical documentation. It can be used for documentation generally, including proprietary projects, though it has become particularly widely used in the open source sphere. By the end of 2024, some 2,200 projects were using Docsy, with adopters across the Cloud Native Computing Foundation (CNCF) including Kubernetes, OpenTelemetry, gRPC and Jaeger.

That existing footprint inside Linux Foundation communities is part of the rationale behind the move. Speaking to The New Stack after the keynote, McKean says bringing Docsy into the foundation puts it closer to many of the projects already using it.

“Open source projects work best when they are close to the users,” she says.

“Open source projects work best when they are close to the users.”

AI needs good documentation, too

In her keynote, McKean focused heavily on the arrival of AI as a new consumer of technical documentation. Some technical writers, she acknowledges, are “a little bit salty” that it took AI to bring more resources to documentation. But the important part, she argues, is whether the information ultimately reaches and helps developers, regardless of the route it takes.

“When we’re making technical documentation, it really doesn’t matter how the information becomes useful to humans, as long as it does it.”

“When we’re making technical documentation, it really doesn’t matter how the information becomes useful to humans, as long as it does it,” McKean says. “If someone told me that there was evidence that said opera is the best way to reach your project users, I’d be writing operas.”

Docsy has already begun adapting its output for AI tools. Since version 0.15.0 in May, it can generate a Markdown copy of each page alongside the regular HTML, as well as an llms.txt file that gives AI tools an index of a site’s content. Both features are opt-in and remain experimental.

The broader idea is to give AI systems a more direct route to the information projects want them to use.

“You can redirect your LLMs and agents to the text that tells them how to use the project.”

“You can redirect your LLMs and agents to the text that tells them how to use the project,” McKean says.

Docsy has continued adding features around that basic concept. Version 0.16.0, released in July, included an upgrade guide written so that it could also be followed by an AI assistant, with conditions, steps and checks built into the instructions. And with version 0.17.0, released in August, Docsy went further on helping agents consume the documentation itself. Sites that enable llms.txt now automatically include a hidden directive at the top of each page pointing visiting agents toward the site’s llms.txt index. That feature is also experimental.

Scoring docs for agents

Next on the roadmap are “AF,” or agent-friendly, “documentation scores,” designed to give maintainers a way to assess how easily AI tools can find, navigate and consume their documentation. McKean says that should give projects a benchmark to work toward.

“You won’t have to guess,” she says. “You can measure how agent friendly your docs are.”

There is a more conventional payoff to better documentation too: fewer routine questions landing on maintainers. McKean says good docs can answer those questions before someone has to step in manually.

“When you have good docs, it reduces the number of questions that can be easily answered by documentation, reducing the burden on maintainers,” she says.

The post What’s up, Docsy? Google’s docs project joins the Linux Foundation as AI agents become readers appeared first on The New Stack.

Read the whole story
alvinashcraft
5 hours ago
reply
Pennsylvania, USA
Share this story
Delete
Next Page of Stories