Commercial software intelligenceEvidence checked · 8 September 2026
SkuTrace

Commercial product change, preserved as evidence.

SK-2026-122 · Entitlements & feature gating

GitHub adds strict plugin-marketplace enforcement for managed Copilot clients

GitHub's enterprise managed settings can enforce strictKnownMarketplaces so Copilot Business and Enterprise users install VS Code and Copilot CLI plugins only from explicitly approved marketplaces.

Managed setting generally available

Commercial transition

Previous stateEnterprise-managed Copilot clients lacked the new strict marketplace allow-list setting.
New stateAfter a 25 June preview, enterprise managed-settings.json became generally available on 1 July with strictKnownMarketplaces supported for licensed VS Code and Copilot CLI users.

Who is affected

Enterprises assigning Copilot Business or Enterprise licences and governing plugins in VS Code or Copilot CLI.

Action required

Configure approved marketplaces in managed-settings.json, test client enforcement and communicate allowed plugin sources.

Evidence boundary

The control must be configured and does not block plugins by default. Earlier managed-plugin distribution is predecessor context, not a separate entitlement in this record.

Timeline

  1. Setting enters public preview

    GitHub introduced strictKnownMarketplaces for managed Copilot clients.

  2. Managed settings generally available

    Enterprise managed-settings.json, including the marketplace control, became generally available.

Official sources