Files
vscode/extensions/copilot
Dmitriy VasyuraandCopilot fb964648ff copilot: fix shell argument injection in generated commit messages (#337547)
* Fix shell argument injection in generated commit messages

The commit-message sanitizer escaped `"` before `\`, so the second replace
re-escaped the backslash the first one had just added and turned `"` into
`\\"`. Inside a double-quoted shell string that reads as an escaped backslash
followed by a closing quote, ending the `-m` argument early and leaving the
rest of the message to be parsed as separate shell tokens. Backticks were not
escaped at all, so a message containing `cmd` in backticks still triggered
command substitution.

Quote the message with single quotes instead, which suppress expansion and
substitution outright rather than depending on every metacharacter being
escaped individually. Quoting is shell-aware because `'` is not a quote
character in cmd.exe and PowerShell escapes an embedded `'` by doubling it
rather than with the POSIX `'\''` idiom. This also fixes the previous `\`
doubling silently corrupting backslashes under PowerShell.

The helper lives in its own module so it is covered by the fast unit suite
and can be reused by the other terminal sendText call sites.

Fixes #316995
Fixes #316996

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Harden commit-message quoting per shell, else use the commit box

The first fix still let a generated message break out of its quoted
argument in several shells. Because sendText turns every line break into an
Enter key press, a breakout in a multi-line message ran without the user
pressing Enter.

- PowerShell also ends a single-quoted string at the typographic single
  quotes U+2018, U+2019, U+201A and U+201B, which are common in generated
  text.
- Windows PowerShell 5.1 does not escape an embedded double quote when it
  builds git's command line, so the quote split the argument. PowerShell 5.1
  and 7 both report the shell as pwsh, so a double quote is refused.
- fish treats \' and \\ as escapes inside single quotes, so a backslash
  defeated the POSIX '\'' idiom.
- nu has no escape for a single quote. cmd.exe expands %VAR% inside double
  quotes and runs each line as soon as it is entered. csh expands ! inside
  single quotes and cannot continue them onto a new line.

Typed control characters are also commands to the shell's line editor; for
example, a Backspace can erase the opening quote. A message containing one
is refused for every shell.

quoteShellArgument now uses an allowlist of shells whose quoting rules are
known, and returns undefined when a value cannot be quoted safely. The
command then puts the message in the Source Control commit box instead of
typing it into the terminal.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Shorten comments in commit-message shell quoting

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Strip or replace unsafe characters instead of refusing them

Refusing a message sent it to the Source Control commit box. The Agents
window has no Source Control view, though, and Agent Host terminals never
report a shell type, so there every message was refused and then lost.

buildGitCommitCommand now always builds a command, except for agent CLIs:

- Control characters are stripped for every shell.
- PowerShell gets ' in place of ", and a space after a trailing \. Git's
  message cleanup removes that space again.
- cmd.exe and other or undetected shells get one -m per paragraph, reduced
  to characters that every shell treats literally inside double quotes.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-09-29 15:06:22 +00:00
..
2026-09-21 18:31:24 +00:00
…
…
2026-09-29 08:38:08 +00:00

GitHub Copilot - Your autonomous AI peer programmer

GitHub Copilot is an AI peer programming tool that transforms how you write code in Visual Studio Code.

GitHub Copilot agents handle complete coding tasks end-to-end, autonomously planning work, editing files, running commands, and self-correcting when they hit errors. You can also leverage inline suggestions for quick coding assistance and inline chat for precise, focused edits directly in the editor.

Sign up for GitHub Copilot Free!

Working with GitHub Copilot agent mode to make edits to code in your workspace

Getting access to GitHub Copilot

Sign up for GitHub Copilot Free, or request access from your enterprise admin.

To access GitHub Copilot, an active GitHub Copilot subscription is required. You can read more about our business and individual offerings at github.com/features/copilot.

Build with autonomous agents

Let AI agents implement complex features end-to-end. Give an agent a high-level task and it breaks the work into steps, edits multiple files, runs terminal commands, and self-corrects when it hits errors or failing tests. Agents excel at building new features, debugging and fixing failing tests, refactoring codebases, and collaborating via pull requests.

Manage sessions from a central view. Run multiple agent sessions in parallel and track them in one place. Monitor session status, switch between active work, review file changes, and resume where you left off.

Run agents with your preferred harness. Use agents locally in VS Code, in the background via Copilot CLI, or Cloud via Copilot Coding Agent. You can also work with providers like Claude and Codex, and hand tasks off between agent types with context preserved all within the VS Code.

Video showing an agent session building a complete feature in VS Code.

Use agents to plan before you build with the Plan agent, which breaks tasks into structured implementation plans and asks clarifying questions. When your plan is ready, hand it off to an implementation agent to execute it. You can also delegate tasks to cloud agents that create branches, implement changes, and open pull requests for your team to review.

More ways to code with AI

Receive intelligent inline suggestions as you type with ghost text suggestions and next edit suggestions, helping you write code faster. Copilot predicts your next logical change, and you can accept suggestions with the Tab key.

Video showing Copilot next edit suggestions.

Use inline chat for targeted edits by pressing Ctrl+I/Cmd+I to open a chat prompt directly in the editor. Describe a change and Copilot suggests edits in place for refactoring methods, adding error handling, or explaining complex algorithms without leaving your editor.

Inline chat in VS Code

Customize AI for your workflow

Agents work best when they understand your project's conventions and have the right tools. Tailor Copilot so it generates code that fits your codebase from the start.

Project context. Use custom instructions to specify project-wide or task-specific context and coding guidelines.

Add specialized capabilities. Teach Copilot specialized capabilities with agent skills or define specialized personas with custom agents.

Connect to external tools and services. Extend agents further with tools from MCP servers and extensions to give Copilot a gateway to external data sources, APIs, or specialized tools.

Supported languages and frameworks

GitHub Copilot works on any language, including Java, PHP, Python, JavaScript, Ruby, Go, C#, or C++. Because it’s been trained on languages in public repositories, it works for most popular languages, libraries and frameworks.

Version compatibility

As Copilot Chat releases in lockstep with VS Code due to its deep UI integration, every new version of Copilot Chat is only compatible with the latest and newest release of VS Code. This means that if you are using an older version of VS Code, you will not be able to use the latest Copilot Chat.

Only the latest Copilot Chat versions will use the latest models provided by the Copilot service, as even minor model upgrades require prompt changes and fixes in the extension.

Privacy and preview terms

By using Copilot Chat you agree to GitHub Copilot chat preview terms. Review the transparency note to understand about usage, limitations and ways to improve Copilot Chat during the technical preview.

Please refer to our Privacy Statement to learn about the data we collect, how we use it, and the controls available to you.

To get the latest security fixes, please use the latest version of the Copilot extension and VS Code.

Resources & next steps

Data and telemetry

The GitHub Copilot Extension for Visual Studio Code collects usage data and sends it to Microsoft to help improve our products and services. Read our privacy statement to learn more. This extension respects the telemetry.telemetryLevel setting which you can learn more about at https://code.visualstudio.com/docs/supporting/faq#_how-to-disable-telemetry-reporting.

Trademarks

This project may contain trademarks or logos for projects, products, or services. Authorized use of Microsoft trademarks or logos is subject to and must follow Microsoft's Trademark & Brand Guidelines. Use of Microsoft trademarks or logos in modified versions of this project must not cause confusion or imply Microsoft sponsorship. Any use of third-party trademarks or logos are subject to those third-party's policies.

License

Copyright (c) Microsoft Corporation. All rights reserved.

Licensed under the MIT license.