VS Code 1.141: What's New, Agent Sandboxing and How to Update
Microsoft's October 7 stable release adds worktree cleanup, cross-platform agent sandboxing, a session grid, and support for continuing Copilot and Codex sessions.

VS Code 1.141, the stable release Microsoft shipped on October 7, 2026, focuses almost entirely on agent sessions: cleaning up disk space left behind by inactive worktrees, sandboxing agent terminals on all three desktop platforms, a new split-pane "session grid" for watching several agents at once, and the ability to pick up Copilot CLI or Codex conversations that were started outside the editor. A smaller set of editor and authentication changes rounds out the release, including a block-paste mode and support for signing in to multiple GitHub Enterprise accounts at once.
- Released: October 7, 2026 (stable)
- Follows: VS Code 1.140 (October 1, 2026)
- Headline features: worktree cleanup, cross-platform agent sandboxing, session grid, external session continuation, block pasting, multiple GitHub Enterprise accounts
- Biggest status change: agent terminal sandboxing is now available in some form on Windows, macOS, and Linux
- How to get it: VS Code auto-updates by default, or check manually from the Help menu (Code menu on macOS)
What's new in VS Code 1.141
Most of 1.141's changes live inside the Agents window, where Visual Studio Code now runs Copilot coding-agent sessions, background shells, and multi-step tasks. According to the official 1.141 release notes, the update groups its changes into a few themes: tidying up after agent sessions, restricting what a sandboxed agent can touch, making it easier to monitor several sessions at once, letting sessions started in other apps continue inside VS Code, and a handful of editor and authentication additions. None of the headline items are described as fully stable defaults yet — several ship as preview or experimental settings people have to turn on.
The release lands six days after VS Code 1.140 introduced the shared Copilot harness and multi-folder sessions, and it reads as a direct follow-through on that work: 1.140 made it possible to run more agent sessions at once across more folders, and 1.141 spends most of its effort on the housekeeping, safety, and visibility problems that follow from actually doing that — where the disk space goes, what an agent's terminal is allowed to touch, and how you keep track of several sessions running in parallel.
Worktree cleanup: reclaim disk space from old agent sessions
When VS Code runs an agent session in its own git worktree, that worktree's checked-out files stick around on disk even after the session is done. In 1.141, running the Chat: Open Worktree Cleanup command opens a view that shows how much space those inactive session worktrees are using, so you can remove the ones you no longer need. The release notes describe an automatic option too: VS Code can clean up worktrees for sessions whose pull request has already been merged, without you having to go looking for them.
Cleanup has guardrails. Sessions that are active, currently running, waiting on your input, or pinned are left alone, and the notes say a cleaned-up session can still be restored afterward if you need to go back to it.
The feature addresses a problem that's largely a side effect of 1.140's own multi-folder sessions: once an agent can spin up a dedicated worktree per session, and a developer can have several sessions running or paused at once, those checked-out copies of a repository accumulate quietly in the background. Worktree Cleanup is VS Code's way of surfacing that accumulated disk usage directly instead of leaving developers to track it down themselves with git commands or a file-size scan.
Cross-platform sandboxing for agent terminals
Agent sandboxing — restricting what an agent's terminal commands can read, write, or reach over the network — is no longer a Mac-only or Linux-only feature. Per the release notes and VS Code's own agent-sandboxing documentation, 1.141 extends it to Windows, macOS, and Linux, toggled through the chat.agent.sandbox.enabled setting or a per-session "Sandboxing for terminal" toggle. Locally launched MCP servers and language servers are sandboxed by default whenever the setting is on.
The three platforms aren't at the same maturity level: the docs list the feature as Preview on macOS and on Linux/WSL2 (where it depends on the bubblewrap and socat packages), and Experimental on Windows, where it requires a recent Windows security update. The documentation also notes that WSL version 1 isn't supported, because it doesn't expose the Linux kernel features bubblewrap needs. Even with the sandbox on, VS Code says terminal restrictions still apply even if you've picked "Allow all" for that session — sandboxing is enforced independently of the permission level you've granted the agent.
VS Code's documentation also describes a middle ground between a fully open terminal and a fully isolated one: administrators or individual users can keep file-system isolation turned on while still allowing an agent's sandboxed commands unrestricted network access, a combination the docs describe as managed at the organization level. That sits alongside VS Code's separate network domain filtering, which applies to both agent tools — the fetch tool and the integrated browser — and to sandboxed terminal commands, letting a team allow or block specific domains regardless of whether the sandbox itself is on. VS Code's broader trust-and-safety documentation frames sandboxing as one layer of a wider permissions model that also covers which tools an agent can call and which actions still require explicit approval.
Session grid: watch multiple agents side by side
The Agents window gains a grid layout for comparing sessions. The release notes describe dragging sessions into horizontal or vertical splits, resizing the resulting panes, and maximizing a single session when you need to focus on it. It pairs with two smaller additions in the same window: a "Background Shells" pill above the chat input that lists shells currently running inside Copilot harness sessions and can stream their output, and a Filter Sessions menu that can narrow the list by environment, harness, or the application a session was "Created In" — including a new "Created Externally" option.
Picking up Copilot and Codex sessions started elsewhere
1.141 extends how far VS Code reaches outside its own window. New conversations started in the Copilot CLI or the GitHub Copilot mobile/desktop app now show up automatically as external sessions inside VS Code after their first request, without needing a reload. Separately, chats started in the ChatGPT app or the Codex CLI on the same machine can now be continued from the Agents window. If another application still has that Codex chat open, VS Code shows a banner explaining why sending a message is blocked, with a Retry option that re-checks access.
It's a continuation feature rather than a sync feature — the point, per the notes, is not losing context when you move between a terminal-based agent tool and the editor, not running the same conversation in two places simultaneously.
Combined with the new "Created Externally" filter in the Filter Sessions menu, this makes the Agents window less of a VS Code-only space and more of a shared surface for agent work that may have started in a terminal, a phone, or a web app. For teams standardizing on Copilot or OpenAI's Codex tooling across multiple surfaces, it removes one of the more common complaints about agent workflows: starting a conversation in one tool and having to re-explain the task from scratch after switching to another.
Block pasting and other editor changes
On the editor side, 1.141 adds a new multi-cursor paste behavior. Setting editor.multiCursorPaste to spread makes a copied block distribute its rows across successive lines starting from a single cursor, instead of repeating the whole block at every cursor; the existing full value still pastes the entire block at each one. The release also mentions several interface-level changes still gated behind settings: a "frosted glass" blurred background for menus and pop-ups in the desktop Agents window (opacity set via workbench.modernUIFrostedGlassOpacity), experimental connected and pill tab styles when the modernized UI is on, and a persistent progress indicator with several icon variants rolling out more broadly. A chat pet called "Blobby" — summoned with /vscode-pet and customized with /blobby — is also listed among the chat additions. The release notes file several other items under "Experimental": a simplified composer for starting new sessions, an agent picker added to the Add Context menu, customizable welcome messages, a set of Dev Container samples covering Go, .NET, Node.js, PHP, Python, and Rust, and a more compact layout density option for the Agents window.
Multiple GitHub Enterprise instances in one window
Developers who juggle more than one GitHub Enterprise account have a new setting, github-enterprise.uris, which accepts a list of GHE.com and GitHub Enterprise Server instances; accounts are labeled by host so it's clear which one you're signed in to. The release notes break down extension support: GitHub Copilot works across multiple GHE.com instances, GitHub Pull Requests still works with only one GHES account at a time, and GitHub Repositories supports multiple GHE.com instances but not multiple GHES ones. If you were already using the older, singular github-enterprise.uri setting, VS Code keeps you signed in — that setting is now deprecated in favor of the plural version.
Other notable changes in 1.141
A few smaller items round out the release, according to the notes and the GitHub release for tag 1.141.0:
- The Agent Customizations editor's MCP Servers section now shows discovered servers from extensions, plugins, and built-in integrations, marked Preview.
- The GitHub Pull Requests extension updated to version 0.168.0, adding an experimental stacked-pull-request workflow behind
githubPullRequests.experimental.stacks. - On the enterprise-policy side, legacy sandbox policies are translated into managed settings at runtime,
ChatAgentSandboxEnabledis now an overridable managed default, and administrators can require sandboxing or enable identity capture for telemetry. - A new Copilot harness, selectable from the harness picker, runs in a dedicated process built on the Agent Host Protocol, which the notes say lets one session be opened from multiple VS Code windows.
- Agents can now steer an in-progress conversation via
send_messagecontrols — queuing a follow-up, replacing a queued message, or canceling one before it's processed. - The thank-you section of the release notes credits community contributors with a number of memory-leak fixes in this release.
The GitHub release page itself is thin on changelog detail beyond confirming the tag and a verified commit; the fuller breakdown lives in the dedicated release notes. Developers who want to track individual commits and pull requests behind these changes can follow them directly in the main vscode repository on GitHub, which Microsoft develops in the open.
| Feature | In 1.140 | In 1.141 |
|---|---|---|
| Agent terminal sandboxing | Not available | New — Preview on macOS/Linux/WSL2, Experimental on Windows |
| Agent session worktrees | Introduced with multi-folder sessions | New cleanup tooling, manual or automatic |
| Viewing multiple sessions | Single session view | New — split-pane session grid |
| External agent sessions | Remote delegation to another machine | New — continue Copilot CLI/app and Codex sessions locally |
| Multi-cursor paste | Default paste only | New spread option alongside full |
| GitHub Enterprise accounts | Single github-enterprise.uri | New plural github-enterprise.uris setting for multiple accounts |
How to update to VS Code 1.141
VS Code checks for and installs updates automatically on most installs, then prompts for a restart to apply them. To check manually: open the Help menu (or the Code menu on macOS) and choose Check for Updates. If you installed VS Code through a Linux package manager (apt, snap, dnf, or a distribution's own repository), update through that package manager instead of VS Code's built-in updater, since the app won't self-update in that setup. You can confirm you're on the new build afterward from Help > About, which should report version 1.141.0.
Anyone already running VS Code Insiders will have seen most of these changes land incrementally over the preceding weeks; 1.141 stable is where they're consolidated into the main release channel. If a feature mentioned here doesn't appear immediately after updating, check that it isn't gated behind one of the settings called out above — several of 1.141's additions, including sandboxing on Windows and the modernized tab styles, are opt-in rather than on by default.
What's next
1.141's feature list leans on the same themes Microsoft has been building toward across the last couple of releases covered on this site — more agent sessions running at once, more guardrails around what they can touch, and tighter interoperability with Copilot and Codex tooling outside the editor itself. With sandboxing still Preview or Experimental on every platform and several interface changes gated behind settings, the next few monthly releases are likely to focus on graduating those features to defaults rather than introducing an entirely new category of functionality. As always, the fastest way to see what Microsoft prioritizes next is the VS Code updates page, which also publishes the Insiders notes ahead of each stable release.
For more on how VS Code's agent tooling stacks up against dedicated coding agents, see Pandromeda's explainer on Claude Code and its price comparison of Cursor, GitHub Copilot, Claude Code, and Codex. And for the two releases that led up to this one, read Pandromeda's coverage of VS Code 1.140's Copilot harness and VS Code 1.139's Linux launcher fix.
Frequently asked questions
When was VS Code 1.141 released?
Microsoft released VS Code 1.141 as a stable update on October 7, 2026, roughly a week after VS Code 1.140.
What is Worktree Cleanup in VS Code 1.141?
Worktree Cleanup is a new view, opened with the Chat: Open Worktree Cleanup command, that shows how much disk space inactive agent session worktrees are using and lets you remove them manually or set up automatic cleanup for sessions whose pull request has already merged.
Does VS Code 1.141 support agent sandboxing on Windows?
Yes, though it is labeled Experimental on Windows and requires a recent Windows security update. Sandboxing is Preview on macOS and on Linux/WSL2, where it depends on the bubblewrap and socat packages.
Can I continue a Codex or Copilot CLI conversation inside VS Code 1.141?
Yes. New Copilot CLI and GitHub Copilot app conversations appear automatically as external sessions in VS Code, and Codex chats started in the ChatGPT app or Codex CLI on the same machine can be continued from the Agents window.
What does editor.multiCursorPaste 'spread' do in VS Code 1.141?
Setting editor.multiCursorPaste to spread makes a copied block of text distribute its rows across successive lines from a single cursor, instead of pasting the full block at every cursor position, which the existing 'full' value still does.
How do I update to VS Code 1.141?
VS Code updates automatically by default and will prompt for a restart. You can also check manually from the Help menu (the Code menu on macOS) by choosing Check for Updates; Linux users who installed via a package manager should update through that manager instead.
Sources
- Visual Studio Code: October 2026 (version 1.141) release notescode.visualstudio.com
- Visual Studio Code: Updates hubcode.visualstudio.com
- GitHub: microsoft/vscode release 1.141.0github.com
- VS Code docs: Sandbox agent terminal commandscode.visualstudio.com
- VS Code docs: Trust and safety for agentscode.visualstudio.com
- GitHub: microsoft/vscode repositorygithub.com
Felix Moreau writes Pandromeda's software coverage and how-to guides. He covers Windows, macOS and Linux updates, the apps people rely on, emulators and developer tools, and turns official documentation into clear, numbered steps that work on the current version.


