Angaben zum Datum
Datum aus der Quelle.
Erstmals gesehen am .
Orca 1.4.221: Copilot-Config gesichert, Codex-Ordner unter Windows
Orca setzt nach dem Schreiben von ~/.copilot/config.json nun Zugriffsrechte nur für den Besitzer (Sicherheitsfix für Copilot-Tokens), nutzt unter Windows für Codex den eigenen Ordner ~/.codex und akzeptiert bei worker-start für unbekannte Codex-Modelle max und ultra als Effort.
Thank you so much for using Orca and for your continued support! ❤️
Remote Server is an experimental feature and may have bugs. Remote Server 2.0 is coming this week and will eliminate most of them.
The short version
- Security fix for Copilot: When Orca marked a folder as trusted for GitHub Copilot, it could leave
~/.copilot/config.jsonreadable by other users on the same machine. That file can hold your Copilot login tokens. v1.4.219 and v1.4.220 did this on SSH hosts too, where other people often share the machine. The file is now owner-only after Orca writes to it. A file an older Orca already opened up is fixed the next time Orca adds a new folder to it. - Codex on Windows uses your own
~/.codex: Codex in Orca now uses the same folder as Codex outside Orca, as it already did on macOS and Linux. If you only signed in inside Orca, that sign-in is copied over so you stay logged in. Codex may ask again to trust a folder or approve a command, and MCP servers you added only inside Orca need to be added again; a one-time message explains this. Codex terminals that were open before the update keep working on Orca's old folder, keep their Orca-only MCP servers, and no longer show a restart dialog. - Codex workers:
worker-startnow acceptsmaxandultraeffort for Codex models Orca doesn't list yet, such as the gpt-6.x models, instead of refusing them. …