Skip to content

Allow user to whitelist / allow for "npm test" or more complex commands #217

Description

@yookoala

Describe the feature or problem you'd like to solve

When CLI wants to run "npm test", I am only given the option to whitelist all "npm" command. But I want to only whitelist "npm test"

Proposed solution

The CLI would show a question with 3 options to user when running a new command.

Do you want to run this command?

  1. Yes (run the exact command once)
  2. Yes, and approve npm for the rest of the running session (allow CLI to run every npm commands in the future)
  3. No, and tell Copilot what to do differently (Esc)

There are many way to solve the problem:

A. Detect special tools and provide extra option

For some tools (e.g. npm, cargo, composer), they are the door to access a list of very diverse subcommands. If CLI detects that the requested command to be in this category, then it should provide another option:

  • Yes, and approve [application] [subcommand] for the rest of the running session

B. Allow user to declare command whitelist interactively

A more generic solution would be for CLI to have an extra option:

  • Yes, and let me determine what similar command pattern to approve for the rest of the running session.

Then, before running the command, work interactively with user to whitelist similar command to approve.

Example prompts or workflows

  • In a new repository, write a simple SPEC.md file that specifies
    • the multiple requirements to a fiction in a text file.
    • the script to test the fiction file with npm test: runs npx cspell
    • outline a workflow to produce every paragraphs:
      1. Write a paragraph.
      2. Commit to git.
      3. Run test on the fiction file.
      4. Fix the typo or incorrect spells.
      5. Commit to git.
      6. Wait for users next instruction.
  • In this repository, also write a simple TASK.md file that specifies multiple paragraphs to write as separated task.
  • Tell GitHub Copilot CLI to implement the fiction.

Additional context

No response

Activity

  1. added theissue type on Oct 6, 2025
  2. changed the title [-]Allow user to whitelist / allow for more complex commands[/-] [+]Allow user to whitelist / allow for "npm test" or more complex commands[/+] on Oct 6, 2025
  3. williammartin commented on Oct 6, 2025

    @williammartin

    Yeh we already special case git and gh like this, so it's totally reasonable to continue extending this into the other common use cases. Are npm, cargo and composer sufficient for your use cases, are there others that matter to you, or just npm ?

  4. yookoala commented on Oct 8, 2025

    @yookoala
    Author

    @williammartin: These are the tools that I would use:

    • go
    • npm
    • npx
    • cargo
    • composer
    • pip

    I guess the list can be very long given that there are many similar CLI tools out there.

  5. williammartin commented on Oct 8, 2025

    @williammartin

    I have an open PR for this so it might go in today, or maybe tomorrow once I get some other work done. In any case, I'll update you here when it goes out in a release.

  6. oasisfeng commented on Oct 12, 2025

    @oasisfeng

    @williammartin Hope "gradlew" also get this whitelist treat.

  7. williammartin commented on Oct 15, 2025

    @williammartin

    This should go out in today's release 👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions