Uh oh!
There was an error while loading. Please reload this page.
Document container mount security model and guidance#12384
Conversation
Co-authored-by: Mossaka <5447827+Mossaka@users.noreply.github.com>
Co-authored-by: Mossaka <5447827+Mossaka@users.noreply.github.com>
Co-authored-by: Mossaka <5447827+Mossaka@users.noreply.github.com>
🔍 PR Triage ResultsCategory: docs | Risk: low | Priority: 45/100 Scores Breakdown
📋 Recommended Action: deferLow impact or work in progress Triaged by PR Triage Agent on 2026-01-29
|
🔍 PR Triage ResultsCategory: docs | Risk: low | Priority: 35/100 Scores Breakdown
📋 Recommended Action: batch_reviewPart of Batch #3: Documentation (batch-docs-001) along with PR #12444. Security documentation requires careful review. Triaged by PR Triage Agent on 2026-01-31 | Run #21540069309
|
🔍 PR Triage ResultsCategory: docs | Risk: low | Priority: 40/100 Scores Breakdown
📋 Recommended Action: Batch ReviewThis PR is recommended for batch review with similar PRs. 📦 Batch ProcessingThis PR is part of batch-docs-001 with 1 other PR(s): #12444 Consider reviewing these PRs together for consistency and efficiency. Triaged by PR Triage Agent on 2026-01-31 12:17 UTC
|
This adds security documentation for mounting host paths into agent containers, covering threat modeling, safeguards, and best practices for workflow authors and reviewers.
Security guide additions
Reference updates
Specs and policy
Example (safe vs unsafe mount patterns):
Screenshot
Warning
Firewall rules blocked me from connecting to one or more addresses (expand for details)
I tried to connect to the following addresses, but was blocked by firewall rules:
telemetry.astro.build/opt/hostedtoolcache/node/24.13.0/x64/bin/node node /home/REDACTED/work/gh-aw/gh-aw/docs/node_modules/.bin/astro build iptables -w ithub/workflows security /usr/bin/infocmp OUTPUT -d 168.63.129.16 infocmp -1 k/gh-aw/gh-aw/.github/workflows 53 /usr/bin/infocmp l GO111MODULE 64/bin/go infocmp(dns block)If you need me to access, download, or install something from one of these locations, you can either:
Original prompt
💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.