Skip to content

fix(core-tools): resolve defensive path resolution for at-reference files and fix macOS tests - #28053

Merged
DavidAPierce merged 4 commits into
google-gemini:mainfrom
luisfelipe-alt:bugfix/WT-engineer_495551283_full
Jun 30, 2026
Merged

fix(core-tools): resolve defensive path resolution for at-reference files and fix macOS tests#28053
DavidAPierce merged 4 commits into
google-gemini:mainfrom
luisfelipe-alt:bugfix/WT-engineer_495551283_full

Conversation

@luisfelipe-alt

@luisfelipe-alt luisfelipe-alt commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

Summary

This PR implements a comprehensive, defensive path resolution fix for a critical production bug where filesystem tools (read_file, replace, write_file) fail with a "File not found" error when the model passes a path prefixed with @ (e.g., @policies/new-policies.txt).

Additionally, this PR resolves macOS-specific test failures in EditTool and WriteFileTool caused by path resolution mismatches (due to the /var -> /private/var symlink on macOS), sanitizes file paths by stripping null bytes to prevent potential crash vulnerabilities, and enhances test stability by generating unique session IDs in trackerTools.test.ts.

Furthermore, this PR incorporates several critical security and robustness enhancements requested during code review, including consistent @ prefix stripping, plan-mode boundary enforcement, and test isolation improvements.

Details

We implemented a centralized, defensive path resolution utility and applied targeted, platform-aware fixes to align the test environment with the production path resolution behavior:

  1. Defensive Path Resolution (packages/core/src/utils/paths.ts):

    • Implemented resolveDefensiveToolPath to strip leading @ reference prefixes if the literal path does not exist but the stripped path does.
    • Consistent @ Prefix Stripping: Updated the logic to consistently strip the @ prefix when creating new files/directories (unless a literal @-prefixed directory already exists on disk), preventing the accidental creation of literal @-prefixed folders (e.g., @src, @policies).
    • Path Alias Support: Added explicit checks for @/ and @\ prefixes to always strip the @ and leading slashes, ensuring that common path aliases are resolved correctly even when the target directory does not exist yet.
    • Null Byte Sanitization: Sanitizes file paths by stripping any null bytes (\0) at the very beginning of resolveDefensiveToolPath to prevent potential crash vulnerabilities (TypeError) in downstream synchronous file system operations.
  2. Tool Integration & Hardening:

    • ReadFileTool (packages/core/src/tools/read-file.ts): Applied resolveDefensiveToolPath in both the constructor and validateToolParamValues.
    • WriteFileTool (packages/core/src/tools/write-file.ts):
      • Applied resolveDefensiveToolPath in the constructor, validateToolParamValues, and getCorrectedFileContent (simplifying and hardening the logic by calling it directly for all paths, including absolute paths).
      • Plan-Mode Boundary Enforcement: Removed the path.isAbsolute check in getCorrectedFileContent to ensure that absolute paths in plan mode do not bypass resolveAndValidatePlanPath, strictly restricting the agent to the plans directory.
      • Plan-Mode Sanitization: Sanitizes null bytes from file paths before resolving the plan path in the constructor, validation, and content correction methods to prevent resolveToRealPath from throwing errors.
    • EditTool (packages/core/src/tools/edit.ts):
      • Applied resolveDefensiveToolPath in the constructor, validateToolParamValues, and getModifyContext.
      • Null Byte Sanitization in Fallbacks: Added explicit null byte sanitization in the absolute path fallback branches (constructor, validation, and context methods) to prevent unsanitized paths from leaking downstream.
      • Plan-Mode Sanitization: Sanitizes null bytes from file paths before resolving the plan path in the constructor, validation, and context methods to prevent resolveToRealPath from throwing errors.
    • Path Corrector (packages/core/src/utils/pathCorrector.ts): Applied resolveDefensiveToolPath at the beginning of correctPath.
  3. macOS Test Fixes & Test Isolation:

    • Mock Workspace Context (packages/core/src/test-utils/mockWorkspaceContext.ts): Updated createMockWorkspaceContext to resolve all input directories to their real paths using fs.realpathSync. This ensures that on macOS, any directory starting with /var/... is correctly resolved to /private/var/..., matching the behavior of the production code and fixing 30 failures in edit.test.ts and boundary failures in write-file.test.ts.
    • WriteFileTool Tests (packages/core/src/tools/write-file.test.ts):
      • Test Isolation: Declared rootDir and plansDir without static global initializers and initialized them with unique temporary directories using fs.mkdtempSync inside beforeEach to prevent race conditions and test interference during concurrent test execution.
      • Updated specific test cases to resolve expected paths to their real paths using resolveToRealPath before asserting.
    • EditTool Tests (packages/core/src/tools/edit.test.ts):
      • Resolved tempDir to its real path using fs.realpathSync in beforeEach to ensure all generated paths are fully resolved, fixing all remaining macOS path mismatches.
  4. Test Stability:

    • Tracker Tools Tests (packages/core/src/tools/trackerTools.test.ts): Replaced the hardcoded sessionId: 'test-session' with a dynamically generated unique session ID using Math.random() to prevent test session leakage and concurrency issues.
  5. Consolidated Test Suite (packages/core/src/tools/at-reference-resolution.test.ts):

    • Created a new consolidated test suite verifying successful path resolution, file updates, new file creation, nested subdirectory creation, path traversal blocking, and symlink loop handling across all three tools.
  6. Build Script Robustness (scripts/build.js):

    • Modified the build script to use npx --no-install npm-run-all to force using the locally installed version and bypass registry/network calls, making the build script robust in corporate environments (Corp Airlock).

Related Issues

How to Validate

Step 1: Run the modified test suites on macOS

Run the following commands on a macOS machine to verify that all tests pass successfully:

npx vitest run packages/core/src/tools/edit.test.ts
npx vitest run packages/core/src/tools/write-file.test.ts
npx vitest run packages/core/src/tools/at-reference-resolution.test.ts
npx vitest run packages/core/src/tools/trackerTools.test.ts

Expected Output: All 125+ tests pass successfully with zero failures.

Step 2: Run the test suites on Linux/Windows (Regression Check)

Run the same commands on Linux or Windows to ensure zero regressions:

npx vitest run packages/core/src/tools/write-file.test.ts packages/core/src/tools/at-reference-resolution.test.ts

Expected Output: All 63 tests pass successfully with zero failures.

Step 3: Run linting and type checking

Verify that the codebase remains fully compliant with the project's engineering standards:

npm run lint && npm run typecheck

Expected Output: Zero linting or type-checking errors.

Pre-Merge Checklist

  • Updated relevant documentation and README (if needed)
  • Added/updated tests (if needed)
  • Noted breaking changes (if any)
  • Validated on required platforms/methods:
    • MacOS
      • npm run
      • npx
    • Windows
      • npm run
      • npx
    • Linux
      • npm run
      • npx

@luisfelipe-alt
luisfelipe-alt requested review from a team as code owners June 19, 2026 21:59
@github-actions github-actions Bot added the size/xl An extra large PR label Jun 19, 2026
@github-actions

github-actions Bot commented Jun 19, 2026

Copy link
Copy Markdown

📊 PR Size: size/XL

  • Lines changed: 1288
  • Additions: +1196
  • Deletions: -92
  • Files changed: 21

@luisfelipe-alt

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request introduces a robust, defensive path resolution mechanism to handle @ prefixed file paths, preventing production errors where tools fail to locate files. It also addresses platform-specific test instabilities on macOS by ensuring consistent real-path resolution and adds a new consolidated test suite to verify path handling across all filesystem tools.

Highlights

  • Defensive Path Resolution: Implemented resolveDefensiveToolPath to handle @ prefixed paths and sanitize inputs by stripping null bytes, preventing potential crashes.
  • macOS Test Fixes: Standardized path resolution using fs.realpathSync across test suites to resolve symlink mismatches (e.g., /var vs /private/var) on macOS.
  • Tool Integration: Updated ReadFileTool, WriteFileTool, EditTool, and pathCorrector to utilize the new defensive resolution and real-path validation logic.
  • Consolidated Testing: Added a comprehensive test suite for @ reference resolution and improved overall test stability by using dynamic session IDs.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces defensive path resolution and sanitization across several tools (EditTool, ReadFileTool, WriteFileTool, and pathCorrector) by implementing and utilizing resolveDefensiveToolPath and resolveToRealPath. This helps handle LLM-generated paths safely, stripping null bytes and reference prefixes (like @), and resolving symlinks. Corresponding tests have been updated or added to verify these behaviors. The reviewer pointed out a potential vulnerability in packages/core/src/tools/edit.ts where a fallback branch for absolute paths could leak unsanitized null bytes if resolveToRealPath throws an error, and suggested sanitizing the path before fallback.

Comment thread packages/core/src/tools/edit.ts
@gemini-cli gemini-cli Bot added the status/need-issue Pull requests that need to have an associated issue. label Jun 19, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces defensive path resolution and sanitization (such as stripping null bytes and handling '@' prefixes) across the EditTool, ReadFileTool, and WriteFileTool to prevent path traversal and ensure safe workspace access. The review feedback highlights a critical edge case where paths like @/ or @\ can resolve to the workspace root, and points out an inconsistency in stripping the @ prefix when creating new directories, which could lead to the accidental creation of literal @-prefixed folders. Suggestions were provided to consistently strip the prefix and update the corresponding tests.

Comment thread packages/core/src/utils/paths.ts
Comment thread packages/core/src/utils/paths.ts
Comment thread packages/core/src/tools/at-reference-resolution.test.ts
Comment thread packages/core/src/tools/at-reference-resolution.test.ts
@luisfelipe-alt

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces defensive path resolution and sanitization across several tools (EditTool, ReadFileTool, WriteFileTool) and utilities. It implements resolveDefensiveToolPath to strip null bytes and handle @ reference prefixes safely, and resolves paths to their real paths using resolveToRealPath to prevent path traversal vulnerabilities and handle symlinks gracefully. The review feedback highlights that in write-file.test.ts, rootDir and plansDir are declared as module-level variables with static paths, which can cause race conditions and test interference during concurrent test execution. The reviewer suggests initializing these variables with unique temporary directories inside beforeEach to ensure proper test isolation.

Comment thread packages/core/src/tools/write-file.test.ts Outdated
Comment thread packages/core/src/tools/write-file.test.ts Outdated
@luisfelipe-alt

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces defensive path resolution and sanitization across various tools (Edit, ReadFile, WriteFile) to prevent path traversal and null byte injection vulnerabilities, notably by implementing resolveDefensiveToolPath and resolving paths to their real paths. It also adds comprehensive tests for at-reference path resolution, null byte sanitization, and symlink loops. The feedback highlights an inconsistency in packages/core/src/tools/write-file.ts where absolute paths are not sanitized using resolveDefensiveToolPath in getCorrectedFileContent, and suggests simplifying this by calling the sanitization function directly.

Comment thread packages/core/src/tools/write-file.ts Outdated
@luisfelipe-alt

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces defensive path resolution and sanitization across file tools (such as edit, read, and write tools) to prevent path traversal, null byte injection, and accidental creation of literal '@'-prefixed directories. The feedback highlights several locations in plan-mode resolution within edit.ts and write-file.ts where raw file paths containing null bytes could still cause resolveToRealPath to throw errors, recommending that these paths be sanitized before resolving the plan path.

Comment thread packages/core/src/tools/edit.ts
Comment thread packages/core/src/tools/edit.ts
Comment thread packages/core/src/tools/edit.ts
Comment thread packages/core/src/tools/write-file.ts
Comment thread packages/core/src/tools/write-file.ts
Comment thread packages/core/src/tools/write-file.ts
@DavidAPierce

DavidAPierce commented Jun 26, 2026

Copy link
Copy Markdown
Contributor

Overall, LGTM, however there are some test failures. Here's a breakdown of the Mac os failures and a potential way forward with them:

Root Cause

The test failures occur because of a prefix mismatch when verifying path
ownership in test environments on macOS. On macOS, the temporary directory
/var is a symbolic link to /private/var.

  1. Path Generation: The test suite creates a temporary directory using the
    fsPromises.mkdtemp function. This returns a path beginning with /var/....
  2. Canonical Real Path Resolution: Under the changes introduced in this PR,
    core tools resolve paths to their canonical real paths. Specifically,
    GlobTool resolves search directories using fs.realpathSync. This converts
    the directory path from /var/... to /private/var/....
  3. Prefix Validation Failure: The test suite implements verification in
    isPathAllowed using a direct startsWith check:
    const directories = workspaceContext.getDirectories(); // returns ['/var/folders/...']
    if (directories.some((dir) => absolutePath.startsWith(dir))) { ... }
    Because absolutePath is /private/var/... (canonical) and dir is
    /var/... (unresolved), the prefix match fails.
  4. Bypassed Debug Messages: Due to this permission failure, GlobTool
    raises an access error. This error is caught by the catch block in
    handleAtCommand rather than generating the expected debug message:
    `Glob search for '**/*nonexistent.txt*' found no files or an error. Path nonexistent.txt will be skipped.`
    As a result, the test assertion for mockOnDebugMessage fails.

Solution

To resolve this issue, you must update the test setup so that all generated
temporary directories are resolved to their canonical real paths before storing
them.

Apply the following modifications to atCommandProcessor.test.ts:

  1. In the first beforeEach block (around line 66):

    const rawTestRootDir = await fsPromises.mkdtemp(
      path.join(os.tmpdir(), "folder-structure-test-"),
    );
    testRootDir = await fsPromises.realpath(rawTestRootDir);
  2. In the it("should resolve files in multiple workspace directories") test (around line 1470):

    const rawSecondRootDir = await fsPromises.mkdtemp(
      path.join(os.tmpdir(), "second-root-"),
    );
    const secondRootDir = await fsPromises.realpath(rawSecondRootDir);
  3. In the describe("checkPermissions") beforeEach block (around line 1652):

    const rawTestRootDir = await fsPromises.mkdtemp(
      path.join(os.tmpdir(), "check-permissions-test-"),
    );
    testRootDir = await fsPromises.realpath(rawTestRootDir);

Converting temporary paths using realpath ensures that they consistently begin
with the /private prefix on macOS, aligning the test assertions with the
canonical resolutions of the core tools.

Once these tests are passing, we're good to LGTM and merge.

@gemini-cli

gemini-cli Bot commented Jun 27, 2026

Copy link
Copy Markdown
Contributor

Hi there! Thank you for your interest in contributing to Gemini CLI.

To ensure we maintain high code quality and focus on our prioritized roadmap, we only guarantee review and consideration of pull requests for issues that are explicitly labeled as 'help wanted'.

This PR will be closed in 7 days if it remains without that designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding.

@luisfelipe-alt

Copy link
Copy Markdown
Contributor Author

Overall, LGTM, however there are some test failures. Here's a breakdown of the Mac os failures and a potential way forward with them:

Root Cause

The test failures occur because of a prefix mismatch when verifying path ownership in test environments on macOS. On macOS, the temporary directory /var is a symbolic link to /private/var.
...

The complete suite of unit tests for the others shard was executed on a macOS environment to validate compatibility and ensure the correct resolution of temporary directories and symbolic links.
Command executed:

npm run test:ci --workspace "@google/gemini-cli-core" --workspace "@google/gemini-cli-a2a-server" --workspace "gemini-cli-vscode-ide-companion" --workspace  "@google/gemini-cli-test-utils" --if-present -- --overage.enabled=false >> mac-ci-test_04.txt 2>> mac-ci-test_04.txt

Execution Results (Sanitized):

* **`@google/gemini-cli-core`**:

RUN  v3.2.4 <WORKSPACE_ROOT>/packages/core
   Test Files  402 passed | 1 skipped (403)
        Tests  7667 passed | 50 skipped (7717)
     Duration  44.33s

* **`@google/gemini-cli-a2a-server`**:
   RUN  v3.1.1 <WORKSPACE_ROOT>/packages/a2a-server
   Test Files  14 passed (14)
        Tests  138 passed (138)
     Duration  3.53s

* **`gemini-cli-vscode-ide-companion`**:
   RUN  v3.2.4 <WORKSPACE_ROOT>/packages/vscode-ide-companion
   Test Files  3 passed (3)
        Tests  40 passed | 1 skipped (41)
     Duration  1.98s

Conclusion: 100% of the executed tests completed successfully. No failures or regressions were detected in the macOS environment.

The following output is only to show how I verified no errors in Mac environment:

$ grep -E "Test Files.*passed" mac-ci-test_04.txt
 Test Files  402 passed | 1 skipped (403)
 Test Files  14 passed (14)
 Test Files  3 passed (3)
$ grep -E "Test Files.*failed" mac-ci-test_04.txt
$ 

Next steps

@DavidAPierce , I am working to fix the other tests failing in the Mac environment detected in GitHub Pipeline. I will try to validate all CI suites before the next round of code review and I will add a comment with the details about how I verified that.

@luisfelipe-alt

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces defensive path resolution and sanitization across multiple tools (Edit, Glob, Grep, ReadFile, RipGrep, and WriteFile) and utilities. It implements resolveDefensiveToolPath to strip null bytes and handle @ prefixes safely, and consistently resolves paths to their real paths using resolveToRealPath to prevent issues with symlinks. Test suites have been updated to reflect these changes, and a new consolidated test suite for At-Reference path resolution has been added. I have no feedback to provide as there are no review comments.

Note: Security Review did not run due to the size of the PR.

@luisfelipe-alt

Copy link
Copy Markdown
Contributor Author

I have completed the changes, and I ran the following commands in a Mac in order to validate them:

# 1. Clear or create the results file
> mac-results.txt

# 2. Run the CLI shard tests (where the current failure is)
echo "=== RUNNING CLI SHARD TESTS ===" >> mac-results.txt
LANG=en_US.UTF-8 npm run test:ci --workspace "@google/gemini-cli" -- --coverage.enabled=false  >> mac-results.txt 2>&1

# 3. Run the OTHERS shard tests (where the previous failures were)
echo "=== RUNNING OTHERS SHARD TESTS ===" >> mac-results.txt
LANG=en_US.UTF-8 npm run test:ci --workspace "@google/gemini-cli-core" --workspace "@google/gemini-cli-a2a-server" --workspace "gemini-cli-vscode-ide-companion" --workspace "@google/gemini-cli-test-utils" --if-present -- --coverage.enabled=false  >> mac-results.txt 2>&1

# 4. Run the scripts tests
echo "=== RUNNING SCRIPTS TESTS ===" >> mac-results.txt
LANG=en_US.UTF-8 npm run test:scripts --  >> mac-results.txt 2>&1

# 5. Validation
npm run lint >> mac-results.txt 2>&1
npm run typecheck >> mac-results.txt 2>&1

I have validated the success of the changes:

$ grep -E "Test Files.*passed" mac-results.txt 
 Test Files  463 passed (463)
 Test Files  402 passed | 1 skipped (403)
 Test Files  14 passed (14)
 Test Files  3 passed (3)
 Test Files  11 passed (11)
$ grep -E "Test Files.*failed" mac-results.txt 
$ 

@DavidAPierce , the PR is ready for the next round of code review.

@github-actions

Copy link
Copy Markdown

70 tests passed successfully on gemini-3-flash-preview.

🧠 Model Steering Guidance

This PR modifies files that affect the model's behavior (prompts, tools, or instructions).

  • ⚠️ Consider adding Evals: No behavioral evaluations (evals/*.eval.ts) were added or updated in this PR. Consider adding a test case to verify the new behavior and prevent regressions.

This is an automated guidance message triggered by steering logic signatures.

@DavidAPierce
DavidAPierce added this pull request to the merge queue Jun 30, 2026
Merged via the queue into google-gemini:main with commit b5fc06e Jun 30, 2026
35 checks passed
software-0ficial pushed a commit to software-0ficial/gemini-cli that referenced this pull request Jul 9, 2026
…iles and fix macOS tests (google-gemini#28053)

Co-authored-by: David Pierce <davidapierce@google.com>
Cleanskiier27 added a commit to Cleanskiier27/gemini-cli that referenced this pull request Jul 25, 2026
* fix(core): Fix hysteresis in async context management pipelines. (google-gemini#26452)

* Tighten private Auto Memory patch allowlist (google-gemini#26535)

* fix(cli): hide read-only settings scopes (google-gemini#26249)

* fix(ci): preserve executable bit for mac binaries (google-gemini#26600)

* fix(cli): improve mcp list UX in untrusted folders (google-gemini#26457)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>

* fix(core): prevent silent hang during OAuth auth on headless Linux (google-gemini#26571)

Co-authored-by: Jack Wotherspoon <jackwoth@google.com>

* Changelog for v0.42.0-preview.0 (google-gemini#26537)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* ci: fix Argument list too long in triage workflows (google-gemini#26603)

* refactor(cli): migrate core tools to native ToolDisplay property and fix UI rendering (google-gemini#25186)

* don't wrap args unnecessarily (google-gemini#26599)

* fix(core): preserve system PATH in Git environment to fix ENOENT (google-gemini#25034) (google-gemini#26587)

* fix(routing): fix resolveClassifierModel argument mismatch in ApprovalModeStrategy (google-gemini#26658)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* docs: add vi mode shortcuts and clarify MCP/custom sandbox setup (google-gemini#23853)

Co-authored-by: Sam Roberts <158088236+g-samroberts@users.noreply.github.com>

* fix(ux): fixed issue with transcribed text not showing after releasing space (google-gemini#26609)

* ci: fix json parsing in scheduled triage workflow (google-gemini#26656)

* fix(cli): hide /memory add subcommand when memoryV2 is enabled (google-gemini#26605)

* fix: prevent false command conflicts when launching from home directory (google-gemini#23069)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* fix(core): cache model routing decision in LocalAgentExecutor (google-gemini#26548)

* Changelog for v0.42.0-preview.2 (google-gemini#26597)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>
Co-authored-by: Sam Roberts <158088236+g-samroberts@users.noreply.github.com>

* skip broken test (google-gemini#26705)

* feat: export session to file and import via flag (google-gemini#26514)

* Feat: Add Machine Hostname to CLI interface (google-gemini#25637)

Signed-off-by: M-DEV-1 <mahadevankizhakkedathu@gmail.com>
Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* docs(extensions): refactor releasing guide and add update mechanisms (google-gemini#26595)

* fix(ci): fix maintainer identification in lifecycle manager (google-gemini#26706)

* fix(ui): added quotes around session id in resume tip (google-gemini#26669)

* Changelog for v0.41.0 (google-gemini#26670)

Co-authored-by: g-samroberts <158088236+g-samroberts@users.noreply.github.com>

* refactor(core): agent session protocol changes (google-gemini#26661)

* fix(context): implement loose boundary policy for gc backstop. (google-gemini#26594)

* fix(core): throw explicit error on dropped tool responses (google-gemini#26668)

* fix: resolve "function response turn must come immediately after function call" error (google-gemini#26691)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* fix(core): resolve parallel tool call streaming ID collision (google-gemini#26646)

* feat(core): add LocalSubagentProtocol behind AgentProtocol (google-gemini#25302)

* fix(cli): remove noisy theme registration logs from terminal (google-gemini#25858)

Co-authored-by: Jack Wotherspoon <jackwoth@google.com>

* ci: implement codebase-aware effort level triage (google-gemini#26666)

* feat(acp/core): prefix tool call IDs with tool names to support tool rendering in ACP compliant IDEs. (google-gemini#26676)

* fix(mcp): treat GET 404 as 405 in StreamableHTTPClientTransport (google-gemini#24847)

Co-authored-by: Coco Sheng <cocosheng@google.com>
Co-authored-by: Spencer <spencertang@google.com>
Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* feat(core): add RemoteSubagentProtocol behind AgentProtocol (google-gemini#25303)

* feat(context): Improvements to the snapshotter. (google-gemini#26655)

* fix(context): Change snapshotter model config. (google-gemini#26745)

* fix(cli): allow installing extensions from ssh repo (google-gemini#26274)

Signed-off-by: Daniel Finimundi <danielrf@motorola.com>
Co-authored-by: Dev Randalpura <devrandalpura@google.com>

* fix(cli): prevent duplicate SessionStart systemMessage render (google-gemini#25827)

Co-authored-by: Jacob Richman <jacob314@gmail.com>

* fix(cli/acp): prevent infinite thought loop in ACP mode by disablig nextSpeakerCheck (google-gemini#26874)

* fix(cli): use static tool name in confirmation prompt to avoid parsing errors (google-gemini#26866)

* fix(routing): Refactor tool turn handling for the conversation history in NumericalClassifierStrategy to prevent 400 Bad Request (google-gemini#26761)

* fix(core): handle malformed projects.json in ProjectRegistry (google-gemini#26885)

* fix(ui): added a gutter width to the input prompt width calculation (google-gemini#26882)

* fix: prevent EISDIR crash when customIgnoreFilePaths contains directories (google-gemini#19868) (google-gemini#19898)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* revert 6b9b778 (google-gemini#26893)

* Fix/vscode run current file ts (google-gemini#22894)

Co-authored-by: Spencer <spencertang@google.com>

* Allow Enter to select session while in search mode in /resume (google-gemini#21523)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* fix(core): ignore .pak and .rpa game archive formats by default (google-gemini#26884)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* fix(cli): enable adk non-interactive session (google-gemini#26895)

* fix(cli): restore resume for legacy sessions (google-gemini#26577)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* fix: respect explicit model selection after Flash quota exhaustion (google-gemini#26759) (google-gemini#26872)

* feat(context): Introduce adaptive token calculator to more accurately calculate content sizes. (google-gemini#26888)

* chore: update checkout action configuration in workflows (google-gemini#26897)

* fix (telemetry): inject quota_project_id to prevent fallback to default oauth client (google-gemini#26698)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* Exclude extension context from skill extraction agent (google-gemini#26879)

* Enable NumericalRouter when using dynamic model configs (google-gemini#26929)

* ci: actively triage missing priority labels and intelligently clean up conflicting labels (google-gemini#26865)

* refactor(core): introduce SubagentState enum for progress (google-gemini#26934)

* fix(ci): replace brittle --no-tag with explicit staging-tmp tag (google-gemini#26940)

* Incremental refactor repo agent towards skills-based composition (google-gemini#26717)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>

* fix(ui): fixed line wrap padding for selection lists (google-gemini#26944)

* fix(core): update read_file schema for v1 compatibility (google-gemini#22183) (google-gemini#26922)

* fix(ci): configure git remote with token for authentication (google-gemini#26949)

* chore(release): bump version to 0.44.0-nightly.20260512.g022e8baef (google-gemini#26957)

* Changelog for v0.42.0 (google-gemini#26958)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* Refactor: Eliminate `no-unsafe-return` suppressions via strict type validation (google-gemini#20668)

Signed-off-by: M-DEV-1 <mahadevankizhakkedathu@gmail.com>
Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* Changelog for v0.43.0-preview.0 (google-gemini#26959)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* feat(core): change agent registration to first-wins and prioritize project (google-gemini#26953)

* feat(cli): merge Auto modes into a single Auto mode (google-gemini#26714)

* fix(core): preserve OAuth refresh tokens during rotation and retrieval (google-gemini#26924)

* fix(cli): allow keychain auth for --list-sessions and non-interactive mode (google-gemini#26921)

* fix(core): handle EISDIR on virtual drives in memory discovery (google-gemini#26985)

* fix(cli): auto-approve shell redirections in AUTO_EDIT mode (google-gemini#27003)

* ci: suppress bot comments during standard triage maintenance (google-gemini#27006)

* fix(core): isolate subagent thread context (google-gemini#26449)

* fix(core): refresh MCP OAuth token usage after re-auth (google-gemini#26312)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* fix(ui): clamped table column widths (google-gemini#26991)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>

* chore: add execution permission to scripts/review.sh (google-gemini#27009)

* fix(core): made context files append instead of replace (google-gemini#26950)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>

* fix: add system PATH fallback for ripgrep resolution (google-gemini#26777) (google-gemini#26868)

* chore: clean up launched memory features (google-gemini#26941)

Co-authored-by: Jenna Inouye <jinouye@google.com>

* fix(core): throttle shell text output and bound live UI buffer (google-gemini#26955)

* fix(cli): don't crash when an @-mention captures a non-path blob (google-gemini#25980)

* fix(core): ensure stable fallback for restricted preview models (google-gemini#26999)

* feat(core): expose RAG snippets to local log file for debugging (google-gemini#27016)

* fix(acp/auth): prevent conflicting credentials on enterprise gateways and support optional API keys natively (google-gemini#27021)

* fix(core): respect NO_PROXY for network-based MCP servers (google-gemini#27012)

* fix(cli): resolve permission denied in sandbox on NixOS and other distros (google-gemini#27004)

* fix(ui): preserve new line at the end of edit window (google-gemini#27057)

* fix(core): ensure Vertex AI sets hasAccessToPreviewModels and remove aggressive 404 fallback revocation (google-gemini#27067)

* fix(core): ensure stable admin settings comparison across IPC to prevent restart loop (google-gemini#27066)

* fix(deps): update vulnerable dependencies (google-gemini#27062)

* fix(core): resolve EISDIR errors during file processing (google-gemini#21527) (google-gemini#27041)

* docs(extensions): clarify env var sanitization policy for MCP and ext… (google-gemini#22854)

Co-authored-by: Jack Wotherspoon <jackwoth@google.com>
Co-authored-by: Jenna Inouye <jinouye@google.com>

* fix(ui): add ENAMETOOLONG and ENOTDIR to exceptions for file parsing errors (google-gemini#27069)

* fix(cli): explicitly clear entrypoint when spawning sandbox container (google-gemini#27059)

* docs: update sandbox image command (google-gemini#26774)

* fix(core): externalize https-proxy-agent to fix proxy support (google-gemini#26361)

* security: update dependencies to fix critical and high vulnerabilities (google-gemini#27077)

* Fix/web fetch ctrl c abort (google-gemini#24320)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>

* fix(core): add aliases and thinking config for gemini-3.1 models (google-gemini#27007)

* fix(core): use hasAccessToPreview for auto model resolution and fix disappearing models (google-gemini#27112)

* feat(core): add adk.agentSessionSubagentEnabled flag (google-gemini#26947)

* fix(core): enforce compile-time exhaustiveness in content-utils (google-gemini#27207)

* feat(skills): add agent-tui and tui-tester skills (google-gemini#27121)

* fix(context): Fix snapshot recovery across sessions. (google-gemini#26939)

* fix(core): add unit tests for stableStringify (google-gemini#27212)

* fix(core): prefer pwsh.exe over Windows PowerShell 5.1 (google-gemini#25859) (google-gemini#25900)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* feat(core): add LocalSessionInvocation (google-gemini#26665)

* refactor: decouple auto model description and configuration from releaseChannel (google-gemini#27227)

Co-authored-by: David Pierce <davidapierce@google.com>

* fix(core): prevent isBinary false-positive on Windows PTY streams (google-gemini#26565)

* fix(cli): Prevent unmapped keys in Vim Normal mode from inserting text into prompt Input. (google-gemini#25139)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* fix(a2a-server): Implement default policy loading for parity with CLI (google-gemini#27073)

* feat(core): add RemoteSessionInvocation (google-gemini#26937)

* fix: allow configured MCP servers in non-interactive mode (google-gemini#27215)

* fix(core): add exception handling to migrateFromFileStorage (google-gemini#27229)

* fix(cli): bundle ink worker-entry.js (google-gemini#27249)

* feat(core): wire AgentSession invocations into agent-tool (google-gemini#26948)

* fix(core): prevent path traversal in custome command file injection (google-gemini#27234)

* fix(core): respect NO_PROXY in global fetch dispatcher (google-gemini#27216)

* fix(core): correctly handle nullable array types in MCP tools (google-gemini#27228)

* Proposal: deterministic encoding for child-process I/O (google-gemini#27247)

* fix(cli): preserve proxy-agent named exports in ESM bundle (google-gemini#27145)

* feat(cli): add Sublime Text and Emacs Client editors, improve error messages and documentation (google-gemini#21090)

Co-authored-by: Ananth Kini <ananthkini1@gmail.com>

* Changelog for v0.43.0-preview.1 (google-gemini#27297)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* fix(devtools): bundle devtools package to avoid resolution errors (google-gemini#27250)

* fix(cli): integrate PolicyEngine into ACP session to prevent deadlocks (google-gemini#23507) (google-gemini#27252)

* fix: robust ripgrep path resolution and 1p hermetic execution support (google-gemini#27253)

* refactor: decouple stored session deletion from ChatRecordingService (google-gemini#22920) (google-gemini#27039)

* fix(core): improve Alpine shell compatibility (google-gemini#26770)

* fix(core): generalize MCP compliance fix for tool results (google-gemini#27045)

* fix(scripts): scrub CI env vars in dev to keep interactive mode (google-gemini#27159)

* fix(core): Added date field for the GCal MCP (google-gemini#27251)

* fix(core): centralize path validation to prevent crashes from malformed prompts (google-gemini#27211)

* fix(core): prevent SIGHUP kills in PTY environments (WSL2/Kitty/Alacritty) (google-gemini#27267)

* fix(core): dynamic fallback routing for exhausted quota models (google-gemini#27315)

* Auto detect pnpm global installation path for macOS and Windows (google-gemini#22748)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: Coco Sheng <cocosheng@google.com>

* fix(windows): resolve interactive shell arrow-key navigation on Windows (google-gemini#23505)

* ci: robust stale issue lifecycle and consolidated triage labels (google-gemini#27015)

* fix(context): Ensure last message is processed. (google-gemini#27232)

* chore/release: bump version to 0.44.0-nightly.20260521.g57c42a5c4 (google-gemini#27324)

* fix(ui): added volta to auto update check (google-gemini#27353)

* perf: optimize issue triage and lifecycle management (google-gemini#27346)

* chore(release): bump version to 0.45.0-nightly.20260521.g854f811be (google-gemini#27362)

* fix(cli): prevent Termux relaunch and resize remount loops (google-gemini#27110)

Co-authored-by: Spencer <spencertang@google.com>

* Feat/a2a expose usage metadata (google-gemini#27288)

* feat(context): Complete simplification work. (google-gemini#27345)

* fix(core): force update_topic tool to execute sequentially (google-gemini#27357)

* Changelog for v0.44.0-preview.0 (google-gemini#27360)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* Changelog for v0.43.0 (google-gemini#27361)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* Revert "fix(core): prevent SIGHUP kills in PTY environments" (google-gemini#27401)

* fix(cli): filter internal session context from history during resumption (google-gemini#27391)

* Update default auto routing (google-gemini#27071)

* fix(core): bypass routing classifiers to prevent orphaned function response errors (google-gemini#27389)

* fix(core): suppress PTY resize EBADF errors (google-gemini#27461)

* fix(core): prevent blacklist bypass in mcp list (google-gemini#27377)

Co-authored-by: Gal Zahavi <38544478+galz10@users.noreply.github.com>

* fix(cli): ignore unmapped vim normal keys (google-gemini#27102)

* fix(core): harden PTY resize against native crashes (google-gemini#27496)

* Changelog for v0.45.0-preview.0 (google-gemini#27495)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* Changelog for v0.44.0 (google-gemini#27569)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* fix(cli): prevent spam loop when preferredEditor is invalid (google-gemini#25324)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* Adding quote (google-gemini#27571)

* Transition to flash GA model when experiment flag is present. (google-gemini#27570)

* chore(ci): add optimized PR size labeler and batch workflows (google-gemini#27616)

* fix(ci): use pull_request_target trigger to grant write access on fork PRs (google-gemini#27637)

* chore(release): bump version to 0.47.0-nightly.20260602.gcfcecebe8 (google-gemini#27644)

* Changelog for v0.46.0-preview.0 (google-gemini#27641)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* Respect backend definitions for 3.5 flash and Update auto mode to use 3.5 flash when the flag is enabled. (google-gemini#27645)

* fix(policy): add EBUSY fallback and TOML parse recovery (google-gemini#19919) (google-gemini#21541)

Signed-off-by: krishdef7 <gargkrish06@gmail.com>
Co-authored-by: Sikandar <ma5161310@gmail.com>
Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* Changelog for v0.45.0 (google-gemini#27642)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* update the max amount of times the Antigravity transition banner can be displayed. (google-gemini#27676)

* chore: remove experimental text from browser agent docs (google-gemini#27746)

* fix(core): implement atomic update in MCP tool discovery (google-gemini#27619)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: Gal Zahavi <38544478+galz10@users.noreply.github.com>

* Vertex ai model mapping fix (google-gemini#27749)

* Add documentation and migration commands for Antigravity CLI (google-gemini#27765)

Co-authored-by: Gal Zahavi <38544478+galz10@users.noreply.github.com>

* Avoid persisting empty resume sessions (google-gemini#27770)

* chore(release): bump version to 0.48.0-nightly.20260609.g3a13b8eeb (google-gemini#27779)

* ci(dependabot): enable cooldown period for npm packages (google-gemini#27743)

* refactor(core): standardize tool output formatting (google-gemini#27772)

* ci: update workflow logging and policy configurations (google-gemini#27853)

* fix(core): Ensure zero-quota limits fail fast to prevent retry loop hang (google-gemini#27698)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>

* fix(core): handle multi-line escaped quotes in stripShellWrapper (google-gemini#27467)

Co-authored-by: luisfelipe-alt <luisfelipe@google.com>

* fix(cli): prevent path traversal vulnerabilities during skill install… (google-gemini#27767)

* Fix/pending tools and trust overrides (google-gemini#27854)

* ci: use internal environment for scheduled nightly releases (google-gemini#27865) (google-gemini#27939)

* feat(core): Support GDC air-gapped Service Identity after auth library update (google-gemini#27956)

* fix(cli): handle tmux false positive background detection (google-gemini#27572)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: Gal Zahavi <38544478+galz10@users.noreply.github.com>

* Add static eval source analyzer (google-gemini#27631)

* fix(config): migrate coreTools setting to tools.core (google-gemini#27947)

* fix(core-tools): resolve defensive path resolution for at-reference files (google-gemini#27943)

* Revert "fix(core-tools): resolve defensive path resolution for at-reference files" (google-gemini#27992)

* chore(release): bump version to 0.49.0-nightly.20260617.g4d3dcdce1 (google-gemini#28003)

* Changelog for v0.48.0-preview.0 (google-gemini#27999)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* fix(ci): provide fallbacks for package variables in nightly release (google-gemini#28016)

* chore(deps): pin dependencies and enforce 14-day update cooldown (google-gemini#27948)

* fix(ci): append trailing slash to registry url in npmrc (google-gemini#28038)

* feat: add eval:inventory CLI command and reporting logic (google-gemini#28009)

* fix: resolve workspace publish failures and scheduler event loop starvation (google-gemini#28063)

* fix(ci): use wombat dressing room fallback in nightly release to prevent ENEEDAUTH (google-gemini#28104)

* Add JSON output for eval inventory (google-gemini#28058)

* fix/verify release npm ci ignore scripts (google-gemini#28116)

* fix(ci): prevent workspace binary shadowing in release verification (google-gemini#28132)

* Feat/tool registry discovery (google-gemini#28113)

* fix(ci): prevent bad NPM releases and promote job crashes (google-gemini#28147)

* Changelog for v0.50.0-preview.1 (google-gemini#28150)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* chore(release): bump version to 0.51.0-nightly.20260625.g3fbf93e26 (google-gemini#28151)

* Fix no_proxy test (google-gemini#28131)

Co-authored-by: Jerry Lin <jerrysf@google.com>

* Vertex base url update (google-gemini#28145)

* fix(security): enforce case-insensitive sensitive path blocklist and vscode hitl (google-gemini#27966)

Co-authored-by: David Pierce <davidapierce@google.com>

* fix(core-tools): resolve defensive path resolution for at-reference files and fix macOS tests (google-gemini#28053)

Co-authored-by: David Pierce <davidapierce@google.com>

* feat(caretaker): implement Cloud Run webhook ingestion service (google-gemini#28015)

Co-authored-by: Christian Gunderman <gundermanc@google.com>

* fix(core): resolve symbolic link directory escape in memory import processor (google-gemini#28233)

* feat(caretaker): egress cloud run service skeleton (google-gemini#28167)

* fix(sandbox): make ~/.gitconfig read-only in the macOS sandbox (google-gemini#28221)

Co-authored-by: David Pierce <davidapierce@google.com>

* fix(core): preserve escape sequences in string literals for modern models (google-gemini#28299)

Co-authored-by: David Pierce <davidapierce@google.com>

* fix(core): strip thoughts from scrubbed history turns and resolve thought leakage (google-gemini#27971)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: Gal Zahavi <38544478+galz10@users.noreply.github.com>
Co-authored-by: David Pierce <davidapierce@google.com>

* Refactor: exclude transient CI configuration files from workspace context (google-gemini#28216)

* feat(caretaker): add triage worker core foundational modules (google-gemini#28163)

* feat(caretaker-egress): implement octokit github action handler for egress service (google-gemini#28303)

* chore(release): bump version to 0.52.0-nightly.20260707.g27a3da3e8 (google-gemini#28323)

* Changelog for v0.51.0-preview.0 (google-gemini#28320)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* Changelog for v0.50.0 (google-gemini#28322)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>
Co-authored-by: David Pierce <davidapierce@google.com>

* fix(core-tools): bypass LLM correction for JSON and IPYNB files in write_file and replace (google-gemini#28223)

Co-authored-by: David Pierce <davidapierce@google.com>

* fix(core): use unambiguous previous intent label in fallback summary (google-gemini#28343)

* feat(caretaker-triage): implement main worker execution loop and egress action publisher (google-gemini#28306)

* fix(privacy): show a clear message when the account has no Code Assist tier (google-gemini#28304)

* fix(core): enrich shared project quota limit errors with setup hint (google-gemini#28391)

* fix(a2a-server): ensure task cancellation aborts execution loop (google-gemini#28316)

* fix(core): simplify plan mode write policy to support relative paths (google-gemini#28398)

* feat(core): Bump node google-auth-library version to 10.9.0 (google-gemini#28385)

Co-authored-by: Jerry Lin <jerrysf@google.com>

* chore/release: bump version to 0.52.0-nightly.20260715.gfa975395b (google-gemini#28402)

* fix(core,a2a): group cancelled tool responses and coalesce consecutive roles to prevent 400 Bad Request (google-gemini#28407)

* feat(caretaker-triage): implement LLM triage orchestrator and container build (google-gemini#28345)

* refactor(cli): align macOS permissive Seatbelt profiles with deny-default model (google-gemini#28424)

* fix(core): mitigate infinite ReAct loops and prompt injection loops (google-gemini#28429)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>

* fix(a2a-server): enforce workspace trust and task isolation to prevent RCE (google-gemini#28470)

* fix(core): sequentially verify cached credentials and restore GOOGLE_APPLICATION_CREDENTIALS fallback (google-gemini#28472)

Co-authored-by: David Pierce <davidapierce@google.com>

* feat(evals): add eval coverage report command (google-gemini#28169)

* Changelog for v0.53.0-preview.0 (google-gemini#28507)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* Changelog for v0.52.0 (google-gemini#28508)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* chore(release): bump version to 0.54.0-nightly.20260722.gf743ab579 (google-gemini#28510)

* fix(caretaker): sanitize and wrap issue title in untrusted_context (google-gemini#28352)

* chore(caretaker): update vitest to v3.2.4 and add package-lock.json files (google-gemini#28409)

* fix(core): rotate session ID on model fallback to prevent stateful API errors (google-gemini#28469)

* feat(caretaker-triage): post comment before auto-closing issues (google-gemini#28411)

* fix(core): enforce HTTPS for GoogleCredentialsAuthProvider to prevent cleartext leakage (google-gemini#28517)

* fix(core): filter out thought parts from getHistoryTurns when context management is disabled (google-gemini#28509)

---------

Signed-off-by: M-DEV-1 <mahadevankizhakkedathu@gmail.com>
Signed-off-by: Daniel Finimundi <danielrf@motorola.com>
Signed-off-by: krishdef7 <gargkrish06@gmail.com>
Co-authored-by: joshualitt <joshualitt@google.com>
Co-authored-by: Sandy Tao <sandytao520@icloud.com>
Co-authored-by: Christian Van <113378434+cvan20191@users.noreply.github.com>
Co-authored-by: ruomeng <ruomeng@google.com>
Co-authored-by: Adib234 <30782825+Adib234@users.noreply.github.com>
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: Rhys Sullivan <39114868+RhysSullivan@users.noreply.github.com>
Co-authored-by: Jack Wotherspoon <jackwoth@google.com>
Co-authored-by: gemini-cli-robot <gemini-cli-robot@google.com>
Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>
Co-authored-by: Coco Sheng <cocosheng@google.com>
Co-authored-by: Michael Bleigh <mbleigh@mbleigh.com>
Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>
Co-authored-by: Daniel Weis <danielweis@users.noreply.github.com>
Co-authored-by: Christopher Thomas <cobekgn@gmail.com>
Co-authored-by: Sam Roberts <158088236+g-samroberts@users.noreply.github.com>
Co-authored-by: Dev Randalpura <devrandalpura@google.com>
Co-authored-by: Br1an <932039080@qq.com>
Co-authored-by: AK <akhilbussiness@gmail.com>
Co-authored-by: mahadevan <135952571+M-DEV-1@users.noreply.github.com>
Co-authored-by: Christian Gunderman <gundermanc@google.com>
Co-authored-by: Adam Weidman <65992621+adamfweidman@users.noreply.github.com>
Co-authored-by: Aishanee Shah <aishaneeshah@google.com>
Co-authored-by: JAYADITYA <96861162+JayadityaGit@users.noreply.github.com>
Co-authored-by: Sri Pasumarthi <111310667+sripasg@users.noreply.github.com>
Co-authored-by: krishdef7 <157892833+krishdef7@users.noreply.github.com>
Co-authored-by: Spencer <spencertang@google.com>
Co-authored-by: Daniel Finimundi <daniel@finimundi.com>
Co-authored-by: Aryan Singh <146713101+dimssu@users.noreply.github.com>
Co-authored-by: Jacob Richman <jacob314@gmail.com>
Co-authored-by: Suhaan Raqeeb Khavas <suhaanrk73@gmail.com>
Co-authored-by: Neil Nair <65729206+Neil-N4@users.noreply.github.com>
Co-authored-by: Franco Pieri <geo22therm@gmail.com>
Co-authored-by: Eswar809 <deevieswar44@gmail.com>
Co-authored-by: Kuroda Kayn <kurodakayn@outlook.com>
Co-authored-by: Gal Zahavi <38544478+galz10@users.noreply.github.com>
Co-authored-by: Yulong Wu <50110323+TNTCompany@users.noreply.github.com>
Co-authored-by: kevinjwang1 <kevinjwang@google.com>
Co-authored-by: David Pierce <davidapierce@google.com>
Co-authored-by: Sahil Kirad <167863755+sahilkirad@users.noreply.github.com>
Co-authored-by: Jenna Inouye <jinouye@google.com>
Co-authored-by: EMERSON BUSSON <93008583+emersonbusson@users.noreply.github.com>
Co-authored-by: ifitisit <90478348+ifitisit@users.noreply.github.com>
Co-authored-by: PROTHAM <155388736+ProthamD@users.noreply.github.com>
Co-authored-by: 7. Sun <jhao.sun@gmail.com>
Co-authored-by: sotokisehiro <101786086+sotokisehiro@users.noreply.github.com>
Co-authored-by: Anish Sabharwal <anishs1207@gmail.com>
Co-authored-by: kaluchi <kaluchi@gmail.com>
Co-authored-by: Tirth Naik <naik.ti@northeastern.edu>
Co-authored-by: Rajesh patel <145205731+Rajeshpatel07@users.noreply.github.com>
Co-authored-by: Keith Schaab <keith.schaab@gmail.com>
Co-authored-by: Ramón Medrano Llamas <45878745+rmedranollamas@users.noreply.github.com>
Co-authored-by: Om Patel <ompatel.aiml@gmail.com>
Co-authored-by: ashishch432 <55024632+ashishch432@users.noreply.github.com>
Co-authored-by: Andrea Alberti <a.alberti82@gmail.com>
Co-authored-by: Ananth Kini <ananthkini1@gmail.com>
Co-authored-by: Yuvraj Angad Singh <36276913+yuvrajangadsingh@users.noreply.github.com>
Co-authored-by: Debasish <90102437+dibyx@users.noreply.github.com>
Co-authored-by: Hashaam Zahid <68606886+Hashaam101@users.noreply.github.com>
Co-authored-by: tison <wander4096@gmail.com>
Co-authored-by: adithya32 <163162210+KumarADITHYA123@users.noreply.github.com>
Co-authored-by: Syed Ayman Quadri <87442765+saymanq@users.noreply.github.com>
Co-authored-by: jvargassanchez-dot <jvargassanchez@google.com>
Co-authored-by: Billy Biggs <bbiggs@google.com>
Co-authored-by: Om Patel <ompatel@google.com>
Co-authored-by: Mukunda Rao Katta <mukunda.vjcs6@gmail.com>
Co-authored-by: nirali <124287834+Niralisj@users.noreply.github.com>
Co-authored-by: Sikandar <ma5161310@gmail.com>
Co-authored-by: Gaurav <39389231+gsquared94@users.noreply.github.com>
Co-authored-by: luisfelipe-alt <luisfelipe@google.com>
Co-authored-by: Cesar Sanchez Coraspe <sanchezcoraspe@google.com>
Co-authored-by: sidhantgoyal-droid <sidhantgoyal@google.com>
Co-authored-by: amelidev <ameliesther@google.com>
Co-authored-by: Vedant Mahajan <vedant.04.mahajan@gmail.com>
Co-authored-by: Jerry Lin <44830071+jerrylin3321@users.noreply.github.com>
Co-authored-by: Jerry Lin <jerrysf@google.com>
Co-authored-by: Chad <chaddiao0@gmail.com>
Co-authored-by: Chad <chaddiao@google.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xl An extra large PR status/need-issue Pull requests that need to have an associated issue. status/pr-nudge-sent

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants