Skip to main content

AI Launch Profile

strictKnownMarketplaces for Copilot CLI and VS Code

GitHub launched public-preview strictKnownMarketplaces support in enterprise-managed settings for Copilot CLI and Visual Studio Code, restricting plugin installation to explicitly configured marketplace sources.

A central policy plate routes approved source capsules to two coding-client devices while empty lanes remain closed

At a glance

Launch Snapshot

Company
GitHub
Launch date
June 25, 2026
Launch type
Not classified
Category
AI Coding Tools, AI Developer Tools, AI Infrastructure, AI Security Tools
Audience
AI Platform Teams, Enterprise IT, Enterprises, Security Teams
Pricing
The setting is an enterprise-management capability rather than a separately priced product. Access follows applicable GitHub enterprise and Copilot plans, and preview availability must be confirmed.
Free plan
No
API
No
Open weights/source
No

Verification & Sources

Evidence state
Recheck due
Source links
5
Freshness
Needs recheck: checked July 28, 2026
Last updated
July 28, 2026
What this evidence state means
Definition
The claim was previously checked, but its review window expired or a material change may have invalidated it.
Required provenance
The prior evidence and check date are retained, together with the expiry or change signal that triggered recheck.
Owner
Kingy freshness queue owner and assigned editorial reviewer
Freshness rule
This is already outside its freshness rule. It must not be presented as current until reviewed against current evidence.
Disputes and corrections
Use “Suggest a correction” on the record. Kingy editorial reviews the cited evidence, records material corrections, and changes or removes the state when it is not supported.
Suggest a correction

Form submissions, correction notes, score details, URLs, and analytics events may be stored for editorial review, spam prevention, product improvement, and follow-up. Do not submit secrets, unreleased financials, private customer data, or regulated personal data through these forms.

Kingy AI Take

strictKnownMarketplaces for Copilot CLI and VS Code provides a useful fail-closed plugin-source boundary, including complete lockdown with an empty list. The public preview does not attest to package safety, pin versions or replace provenance and runtime controls. Kingy did not deploy it, so enterprises should test exact and near-miss marketplace sources, managed-setting precedence, update timing and emergency exceptions in both supported clients.

Who it is for

Enterprise security, platform, developer-experience and IT teams centrally governing plugin sources for GitHub Copilot CLI and Visual Studio Code clients.

What feels promising

One managed setting can reduce unapproved plugin-source sprawl across two widely used coding clients and supports an explicit empty-list lockdown state.

What feels unproven

Kingy did not test pattern matching, redirects, repository transfers, symlinks, installed-plugin behavior, MDM and server precedence, update latency, logging or bypass resistance.

Editorial submissions and sponsor-fit reviews are separate. Payment does not influence Kingy scores, verdicts, rankings, evidence labels, or publication decisions.