Skip to content

deps: Bump GitHub.Copilot.SDK from 1.0.14 to 1.0.16 - #2170

Merged
bradygaster merged 2 commits into
devfrom
dependabot/nuget/GitHub.Copilot.SDK-1.0.16
Oct 8, 2026
Merged

bradygaster merged 2 commits into
devfrom
dependabot/nuget/GitHub.Copilot.SDK-1.0.16

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Updated GitHub.Copilot.SDK from 1.0.14 to 1.0.16.

Release notes

Sourced from GitHub.Copilot.SDK's releases.

1.0.16

Internal dependency updates only: this release refreshes the SDK snapshot for Copilot CLI 1.0.90. It contains no other user-visible SDK changes since v1.0.15.

[!WARNING]

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by Release Notes Generator · copilot · auto · 18.8 AIC · ⌖ 6.11 AIC · ⊞ 10.3K

1.0.16-preview.0

Internal dependency updates only (SDK snapshot updated for Copilot CLI 1.0.90-6).

Full Changelog: github/copilot-sdk@runtime-1.0.89-1.unstable.r36638597907.ge270afd...v1.0.16-preview.0

[!WARNING]

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by Release Notes Generator · copilot · auto · 23.7 AIC · ⌖ 5.81 AIC · ⊞ 10.3K

1.0.15

Feature: typed structured outputs for all six SDKs

Provide a JSON Schema, or use an idiomatic typed helper, to have the model return typed, validated output instead of free-form text. (#​2590)

const answerSchema = z.object({ value: z.number().int() });
const answer = await session.sendAndWait("What is 19 + 23?", answerSchema);
answer = await session.send_and_wait_typed("What is 19 + 23?", Answer)

Go, Java, C#, and Rust get the same capability via copilot.SendAndWait[Answer], session.sendAndWait(prompt, Answer.class), SendAndWaitAsync<Answer>, and session.send_and_wait_typed(prompt).

Feature: structured JSON-RPC error data in all SDKs

The raw JSON data payload of a JSON-RPC error response can now be inspected in every SDK, so apps can branch on machine-readable error details. (#​2664, #​2732)

if let Some(data) = error.rpc_data() { println!("{data}"); }
catch (JsonRpcException e) { JsonNode data = e.getData(); }

Feature: experimental connection-global installation confirmation

All six SDKs expose a connection-global handler for the runtime's installations.confirm callback, letting apps present a human review before an MCP or Skill installation proceeds. The handler must return an explicit confirm/decline/cancel decision.

const client = new CopilotClient({
  installationConfirmationHandler: async (request, context) => promptUser(request),
});

Java, Python, Rust, C#, and Go get equivalent options (setInstallationConfirmationHandler, installation_confirmation_handler, with_installation_confirmation_handler, InstallationConfirmationHandler). Java also now exposes typed unions for MCP installation review payloads.

Other changes

  • feature: [Java] add native runtime support for darwin-x64 (#​2701)
  • feature: [Java] add native runtime support for linuxmusl-x64 (Alpine) (#​2715)
  • feature: [Java] experimental FusionCritic generated diagnostics type
  • improvement: [Node/Python/Go/.NET/Java] coalesce intercepted HTTP response chunks for better tool-call streaming throughput (#​2734)
  • improvement: [Rust] coalesce intercepted HTTP response chunks (#​2717)
  • improvement: [Rust] avoid rebuilding and copying JSON payloads (#​2711)
  • improvement: [Rust] cut retained runtime-install memory by ~99% (#​2676)
  • improvement: [.NET] avoid redundant JSON event materialization and reduce allocations (#​2733)
  • improvement: [Node] pin production dependencies to exact versions with a publish-age policy (#​2700)
    ... (truncated)

1.0.15-preview.4

Feature: experimental connection-global installation confirmation

All six SDKs now expose a connection-global handler for the runtime's installations.confirm callback, letting apps present a human review before an MCP or Skill installation proceeds. The handler receives the generated request plus a cancellation signal that fires when the review is retired or the connection closes, and must return an explicit confirm/decline/cancel decision — the SDK never infers approval.

const client = new CopilotClient({
  installationConfirmationHandler: async (request, context) => {
    return await promptUser(request); // "confirm" | "decline" | "cancel"
  },
});
var options = new CopilotClientOptions
{
    InstallationConfirmationHandler = async (request, context) =>
        await PromptUserAsync(request, context.CancellationToken),
};
opts := copilot.ClientOptions{
    InstallationConfirmationHandler: func(ctx context.Context, req *copilot.InstallationConfirmationRequest) (copilot.InstallationConfirmationDecision, error) {
        return promptUser(ctx, req)
    },
}

Java, Python, and Rust get the equivalent setInstallationConfirmationHandler(...), installation_confirmation_handler, and with_installation_confirmation_handler options. Java additionally converts the previously untyped MCP installation/removal review payloads (InstallationConfirmationRequest.review(), McpInstallPlan.transportChoices(), McpInstallationManagementResultOutcome.getOutcome()) into sealed/typed unions, bringing it into line with the other SDKs.

Other changes

  • feature: [Java] experimental FusionCritic generated diagnostics type for execution-phase model/reasoning-effort tracking

[!WARNING]

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

... (truncated)

1.0.15-preview.3

Feature: structured JSON-RPC error data in Go, .NET, and Java

Go, .NET, and Java can now inspect the raw JSON data payload of a JSON-RPC error response instead of only its code and message. This mirrors capabilities already available in TypeScript, Python, and Rust, letting apps branch on machine-readable error details. (#​2732)

var rpcErr *copilot.RPCError
if errors.As(err, &rpcErr) {
    fmt.Printf("RPC error %d: %s\n", rpcErr.Code, rpcErr.Message)
}
catch (IOException ex) when (ex.InnerException is RemoteRpcException remote)
{
    Console.Error.WriteLine($"RPC error {remote.ErrorCode}: {remote.Message}");
}
catch (JsonRpcException e) {
    JsonNode data = e.getData();
}

Omitted data and explicit JSON null remain distinguishable in all three APIs, and existing error identity, wrapping, and formatting behavior are unchanged.

[!WARNING]

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by Release Notes Generator · copilot · auto · 163.2 AIC · ⌖ 6.41 AIC · ⊞ 9K

1.0.15-preview.2

Internal dependency updates only — this prerelease contains no user-visible SDK changes since v1.0.15-preview.1. The only changes are automated Copilot CLI snapshot updates for internal testing.

Full Changelog: github/copilot-sdk@v1.0.15-preview.1...v1.0.15-preview.2

[!WARNING]

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by Release Notes Generator · copilot · auto · 59.3 AIC · ⌖ 8.22 AIC · ⊞ 9K

1.0.15-preview.1

Internal dependency updates only — this prerelease contains no user-visible SDK changes since v1.0.15-preview.0. The only changes are automated Copilot CLI snapshot updates for internal testing.

Full Changelog: github/copilot-sdk@v1.0.15-preview.0...v1.0.15-preview.1

[!WARNING]

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by Release Notes Generator · copilot · auto · 42.6 AIC · ⌖ 5.58 AIC · ⊞ 9K

1.0.15-preview.0

Feature: typed structured outputs for all six SDKs

Provide a JSON Schema, or use an idiomatic typed helper, to have the model return typed, validated output instead of free-form text. (#​2590)

const answerSchema = z.object({ value: z.number().int() });
const answer = await session.sendAndWait("What is 19 + 23?", answerSchema);
class Answer(BaseModel):
    value: int

answer = await session.send_and_wait_typed("What is 19 + 23?", Answer)
var answer = await session.SendAndWaitAsync("What is 19 + 23?");
public sealed record Answer(int Value);

Go, Java, and Rust get the same capability via copilot.SendAndWait[Answer], session.sendAndWait(prompt, Answer.class), and session.send_and_wait_typed(prompt) respectively.

Feature: structured JSON-RPC error data in Rust

copilot::Error now preserves the optional data payload from JSON-RPC errors so callers can inspect machine-readable error details instead of just the message. (#​2664)

if let Some(data) = error.rpc_data() {
    println!("{data}");
}

Other changes

  • feature: [Java] add native runtime support for darwin-x64 (#​2701)
  • feature: [Java] add native runtime support for linuxmusl-x64 (Alpine) (#​2715)
  • improvement: [Node/Python/Go/.NET/Java] coalesce intercepted HTTP response chunks with bounded read-ahead for better tool-call streaming throughput (#​2734)
  • improvement: [.NET] reduce allocations when processing inbound session events (#​2733)
  • improvement: [Node] pin production dependencies to exact versions and require a 7-day publish-age check across the resolved dependency graph (#​2700)

New contributors

  • @​roblourens made their first contribution in #​2700

[!WARNING]

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:
... (truncated)

Commits viewable in compare view.

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

---
updated-dependencies:
- dependency-name: GitHub.Copilot.SDK
  dependency-version: 1.0.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 5, 2026
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 5, 2026
@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

🛫 PR Readiness Check

ℹ️ This comment updates on each push. Last checked: commit d5876e8

PR Scope: 🔧 Infrastructure

⚠️ 2 item(s) to address before review

Status Check Details
❌ Single commit 2 commits — consider squashing before review
✅ Not in draft Ready for review
✅ Branch up to date Up to date with dev
❌ Copilot review No Copilot review yet — it may still be processing
✅ Changeset present No source files changed — changeset not required
✅ Scope clean No .squad/ or docs/proposals/ files
✅ No merge conflicts No merge conflicts
✅ Copilot threads resolved No Copilot review threads
✅ CI passing All checks passing

Files Changed (1 file, +1 −1)

File +/−
Directory.Build.props +1 −1

Total: +1 −1


This check runs automatically on every push. Fix any ❌ items and push again.
See CONTRIBUTING.md and PR Requirements for details.

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

🟢 Impact Analysis — PR #2170

Risk tier: 🟢 LOW

📊 Summary

Metric Count
Files changed 1
Files added 0
Files modified 1
Files deleted 0
Modules touched 1

🎯 Risk Factors

  • 1 files changed (≤5 → LOW)
  • 1 module(s) touched (≤1 → LOW)

📦 Modules Affected

root (1 file)
  • Directory.Build.props

This report is generated automatically for every PR. See #733 for details.

@bradygaster
bradygaster merged commit 2387146 into dev Oct 8, 2026
19 checks passed
@dependabot
dependabot Bot deleted the dependabot/nuget/GitHub.Copilot.SDK-1.0.16 branch October 8, 2026 02:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant