Gemini CLI cli
ComponentUpdates related to the cli component of Gemini CLI.
All CLI Features
- Introduced hardened path resolution and boundary validation in the extension loader to improve security and reliability.(v0.60.0-nightly.20260904.g87a9c71d5)
- Added tool call formatter and integrated failure summaries for evaluations.(v0.57.0)
- Enabled context-aware silent retries and availability TTL for capacity errors.(v0.57.0)
- Introduced rollback of entire multi-turn requests on cancellation or abort.(v0.57.0)
- Introduced tool call formatting and integration of failure summaries for evaluations.(v0.57.0-preview.0)
- Enabled dynamic resolution of Cloud Workstations proxy redirect URIs for OAuth flows.(v0.57.0-preview.0)
- Implemented context-aware silent retries and availability TTL for capacity errors.(v0.57.0-preview.0)
- Added Vertex AI locations documentation link.(v0.57.0-preview.0)
- Added tool call formatting for evaluations.(v0.56.0-nightly.20260813.g1ac337739)
- Integrated failure summaries into evaluations.(v0.56.0-nightly.20260813.g1ac337739)
- Added a local report command for evaluations, along with developer documentation.(v0.56.0-nightly.20260812.g5024443c7)
- Introduced tool registry discovery capabilities.(v0.55.1)
- Implemented Cloud Run webhook ingestion service for the caretaker.(v0.55.1)
- Added egress cloud run service skeleton for the caretaker.(v0.55.1)
- Implemented foundational modules for the caretaker triage worker.(v0.55.1)
- Implemented Octokit GitHub action handler for the caretaker egress service.(v0.55.1)
- Implemented the main worker execution loop and egress action publisher for caretaker triage.(v0.55.1)
- Implemented LLM triage orchestrator and container build for caretaker triage.(v0.55.1)
- Added an eval coverage report command.(v0.55.1)
- Implemented Firestore concurrency dual-locking and test ingestion utilities for the PR generator database.(v0.55.1)
- Implemented Antigravity agent runner and prompt templates for the PR generator agent.(v0.55.1)
- Added functionality to post a comment before auto-closing issues in the caretaker triage system.(v0.55.1)
- Introduced a new triage Cloud Run job workflow for the caretaker agent.(v0.56.0-preview.1)
- Added a triage evaluation framework and judge runner for caretaker evaluations.(v0.56.0-preview.1)
- Enabled local golden issue collection and Firestore sync tools for caretaker evaluations.(v0.56.0-preview.1)
- Enabled the caretaker agent to publish workable spec events to a ready-for-code Pub/Sub topic.(v0.56.0-preview.1)
- Added a GCP deployment script for caretaker agent services.(v0.56.0-preview.1)
- Added a Cloud Run job entrypoint for the evaluation runner.(v0.56.0-preview.1)
- Added issue comment handling and a re-triage workflow for ingestion.(v0.56.0-preview.1)
- Added a local report command and developer documentation for evaluations.(v0.56.0-preview.1)
- Added issue comment handling and a re-triage workflow for ingestion.(v0.56.0-nightly.20260808.gcf22ac7e8)
- Introduced a triage Cloud Run job workflow for the caretaker.(v0.56.0-nightly.20260808.gcf22ac7e8)
- Enabled prompt hill-climbing and orchestrator updates for caretaker triage.(v0.56.0-nightly.20260808.gcf22ac7e8)
- Added a triage evaluation framework and judge runner for caretaker evaluations.(v0.56.0-nightly.20260808.gcf22ac7e8)
- Included local golden issue collection and Firestore sync tools for caretaker evaluations.(v0.56.0-nightly.20260808.gcf22ac7e8)
- Published workable spec events to a ready-for-code Pub/Sub topic by the caretaker.(v0.56.0-nightly.20260808.gcf22ac7e8)
- Added a GCP deployment script for caretaker agent services.(v0.56.0-nightly.20260808.gcf22ac7e8)
- Added a Cloud Run job entrypoint for the evaluation runner in caretaker evaluations.(v0.56.0-nightly.20260808.gcf22ac7e8)
- Introduced the ability for the caretaker triage to post a comment before automatically closing issues.(v0.54.0)
- Implemented Firestore concurrency dual-locking and test ingestion utilities for the PR generator database.(v0.54.0)
- Implemented the Antigravity agent runner and prompt templates for the PR generator agent.(v0.54.0)
- Added environment configuration parsing, command execution, and GitHub integration for the PR generator.(v0.55.0-preview.1)
- Implemented an iterative bug-fixing state machine and container worker entrypoint for the PR generator.(v0.55.0-preview.1)
- Configured Cloud Run jobs, Workflows definitions, and Dockerfiles for the PR generator infrastructure.(v0.55.0-preview.1)
- Introduced a new PR generator core with environment configuration parsing, command execution, and GitHub integration.(v0.55.0-nightly.20260806.g761f604c1)
- Implemented an iterative bug-fixing state machine and container worker entrypoint for the PR generator orchestrator.(v0.55.0-nightly.20260806.g761f604c1)
- Configured Cloud Run job, Workflows definition, and Dockerfile for the PR generator infrastructure.(v0.55.0-nightly.20260806.g761f604c1)
- Introduced tool registry discovery functionality.(v0.50.0)
- Implemented the Cloud Run webhook ingestion service for caretaker functionality.(v0.51.0-preview.0)
- Created the egress cloud run service skeleton for caretaker functionality.(v0.51.0-preview.0)
- Added egress cloud run service skeleton for caretaker functionality.(v0.51.0-nightly.20260703.gf7af4e518)
- Implemented Cloud Run webhook ingestion service for caretaker functionality.(v0.51.0-nightly.20260701.g7f00c5fe5)
- Support GDC air-gapped Service Identity after auth library update.(v0.49.0)
- Added eval:inventory CLI command and reporting logic.(v0.49.0)
- Added JSON output format option for eval inventory.(v0.49.0)
- Introduced new functionality for tool registry discovery.(v0.50.0-preview.1)
- Enabled support for GDC air-gapped Service Identity after an authentication library update.(v0.49.0-nightly.20260625.gd845bc5d4)
- Introduced the "eval:inventory" CLI command and associated reporting logic.(v0.49.0-nightly.20260625.gd845bc5d4)
- Added JSON output format capability for the eval inventory report.(v0.49.0-nightly.20260625.gd845bc5d4)
- Enabled tool registry discovery functionality.(v0.49.0-nightly.20260625.gd845bc5d4)
- Enabled automatic selection of the 3.5 flash model when the corresponding flag is enabled, respecting backend definitions.(v0.47.0)
- Enabled support for GDC air-gapped Service Identity following an authentication library update.(v0.48.0-preview.0)
- Added documentation and migration commands for Antigravity CLI.(v0.48.0-nightly.20260613.g9e5599c32)
- Added the ability to include quotes in interactions.(v0.46.0)
- Enabled transition to the flash GA model when the corresponding experiment flag is present.(v0.46.0)
- Enabled automatic selection of the 3.5 flash model when the corresponding flag is enabled, respecting backend definitions.(v0.47.0-preview.0)
- Enabled auto mode to use Gemini 1.5 Flash when the corresponding flag is active.(v0.47.0-nightly.20260604.g4196596f7)
- Ensured backend definitions are respected for the Gemini 1.5 Flash model.(v0.47.0-nightly.20260604.g4196596f7)
All CLI Bug Fixes
- Fixed an issue where extensions would not prompt for consent on environment changes and sanitized runtime-altering environment variables.(v0.60.0-nightly.20260905.g85aca163f)
- Enhanced workspace path boundary checks and symlink resolution for improved command safety and file discovery.(v0.60.0-nightly.20260905.g85aca163f)
- Enforced strict permission and ownership checks on system-wide configuration paths.(v0.60.0-nightly.20260905.g85aca163f)
- Fixed an issue where the MCP OAuth flow did not correctly enforce RFC 9207 issuer identification.(v0.60.0-nightly.20260904.g87a9c71d5)
- Resolved a problem with the macOS Seatbelt sandbox by isolating the temporary directory, preventing potential conflicts.(v0.60.0-nightly.20260904.g87a9c71d5)
- Removed a hardcoded Google CrUX API key from chrome-devtools-mcp, enhancing security by sanitizing sensitive information.(v0.60.0-nightly.20260904.g87a9c71d5)
- Improved destination validation and connection routing in web fetch utilities.(v0.59.0-nightly.20260902.g4963a4456)
- Fixed inconsistent symlink evaluation in ignore path handling.(v0.58.0)
- Isolated Docker and container runtime sockets and binaries in macOS Seatbelt to prevent issues.(v0.58.0)
- Cleared stale cancellation errors on new message turns in the A2A server.(v0.58.0)
- Declared top-level safety checkers in write policy configuration.(v0.58.0)
- Optimized history rollback and retry nudges.(v0.58.0)
- Fixed Server-Side Request Forgery (SSRF) vulnerability during MCP OAuth metadata discovery and authentication.(v0.59.0-preview.0)
- Enforced fail-closed behavior for workspace trust and filtered MCP servers in restricted mode to enhance security.(v0.59.0-preview.0)
- Fixed an issue where workspace trust was not enforced in fail-closed mode, and MCP servers were incorrectly filtered in restricted mode.(v0.59.0-nightly.20260829.g0bd1d4397)
- Fixed Server-Side Request Forgery (SSRF) vulnerability during MCP OAuth metadata discovery and authentication.(v0.59.0-nightly.20260827.g3c311beac)
- Fixed dynamically resolving Cloud Workstations proxy redirect URI for OAuth flows.(v0.57.0)
- Resolved swallowed directory mismatch in IDE connections.(v0.57.0)
- Stabilized file-system-interactive test on slow runners.(v0.57.0)
- Normalized git environment and resolved workspace state mismatch.(v0.57.0)
- Migrated process.env to vi.stubEnv in a2a-server tests.(v0.57.0)
- Added composite flag to packages/cli tsconfig.(v0.57.0)
- Clarified privacy notice wording and selection options.(v0.57.0)
- Fixed TypeScript strict-null errors in integration tests.(v0.57.0)
- Prevented indefinite TUI hang by adding execution timeouts.(v0.57.0)
- Updated /clear command docs to include context reset.(v0.57.0)
- Fixed misleading admin error for personal accounts.(v0.57.0)
- Formatted cli_help subagent output as markdown.(v0.57.0)
- Added Vertex AI locations documentation link.(v0.57.0)
- Prevented subagents from running when agents mode is disabled.(v0.57.0)
- Added trailing space to autocomplete suggestions.(v0.57.0)
- Forced terminal buffer rerender after exiting external editors.(v0.57.0)
- Fixed sub-agent handoff token regression on startup.(v0.57.0)
- Preserved empty text turns with tools or media.(v0.57.0)
- Fixed inconsistent symlink evaluation in ignore path handling.(v0.58.0-preview.0)
- Isolated Docker and container runtime sockets and binaries in macOS Seatbelt to prevent interference.(v0.58.0-preview.0)
- Cleared stale cancellation errors when new message turns occur in the a2a-server.(v0.58.0-preview.0)
- Ensured top-level safety checkers are declared in write policy configuration.(v0.58.0-preview.0)
- Optimized history rollback and retry nudges.(v0.58.0-preview.0)
- Fixed stale cancellation errors in the a2a-server when a new message turn occurs.(v0.56.0-nightly.20260825.g812f7a2bc)
- Ensured top-level safety checkers are declared in write policy configuration.(v0.56.0-nightly.20260825.g812f7a2bc)
- Optimized history rollback and retry nudges.(v0.56.0-nightly.20260825.g812f7a2bc)
- Applied a patch to release version v0.57.0-preview.1 to address issues in v0.57.0-preview.0.(v0.57.0-preview.1)
- Fixed an issue on macOS where Docker and container runtime sockets and binaries were not properly isolated in the Seatbelt sandbox.(v0.56.0-nightly.20260822.g5411f113c)
- Fixed inconsistent symlink evaluation in ignore path handling.(v0.56.0-nightly.20260821.g30573d2e4)
- Fixed an issue where empty text turns were not preserved when using tools or media.(v0.56.0-nightly.20260820.ge90c63fa1)
- Fixed swallowed directory mismatch in IDE connections.(v0.57.0-preview.0)
- Rolled back entire multi-turn request on cancellation or abort.(v0.57.0-preview.0)
- Normalized git environment and resolved workspace state mismatch.(v0.57.0-preview.0)
- Fixed TypeScript strict-null errors in integration tests.(v0.57.0-preview.0)
- Prevented indefinite TUI hang by adding execution timeouts.(v0.57.0-preview.0)
- Fixed misleading admin error for personal accounts.(v0.57.0-preview.0)
- Prevented subagents from running when agents mode is disabled.(v0.57.0-preview.0)
- Fixed sub-agent handoff token regression on startup.(v0.57.0-preview.0)
- Preserved empty text turns with tools or media.(v0.57.0-preview.0)
- Prevented subagents from running when agents mode is disabled.(v0.56.0-nightly.20260819.g571851b10)
- Added a trailing space to autocomplete suggestions for better usability.(v0.56.0-nightly.20260819.g571851b10)
- Ensured terminal buffer rerenders correctly after exiting external editors.(v0.56.0-nightly.20260819.g571851b10)
- Fixed a regression in sub-agent handoff tokens that occurred on startup.(v0.56.0-nightly.20260819.g571851b10)
- Fixed an indefinite TUI hang by adding execution timeouts for the SSR Agent.(v0.56.0-nightly.20260818.g194edea47)
- Fixed a misleading admin error message for personal accounts in the SSR Agent.(v0.56.0-nightly.20260818.g194edea47)
- Fixed TypeScript strict-null errors in integration tests for the SSR Agent.(v0.56.0-nightly.20260818.g194edea47)
- Fixed an issue with the SSR Agent by adding a composite flag to packages/cli tsconfig.(v0.56.0-nightly.20260817.g9a15c45fb)
- Fixed an issue in SSR Agent tests where process.env was not correctly migrated, now using vi.stubEnv for proper handling.(v0.56.0-nightly.20260815.g2a87e7be1)
- Implemented context-aware silent retries and availability TTL for capacity errors.(v0.56.0-nightly.20260814.gc0d192452)
- Rolled back entire multi-turn requests on cancellation or abort.(v0.56.0-nightly.20260814.gc0d192452)
- Normalized git environment and resolved workspace state mismatches.(v0.56.0-nightly.20260814.gc0d192452)
- Resolved false model capacity exhaustion and fixed core quota lookup model mapping.(v0.56.0-nightly.20260812.g5024443c7)
- Dynamically resolved Cloud Workstations proxy redirect URI for OAuth flows.(v0.56.0-nightly.20260812.g5024443c7)
- Resolved swallowed directory mismatch in IDE connections.(v0.56.0-nightly.20260812.g5024443c7)
- Fixed an issue where npm ci ignore scripts were not being correctly handled during release verification.(v0.55.1)
- Prevented workspace binary shadowing in release verification.(v0.55.1)
- Prevented bad NPM releases and promoted job crashes in CI.(v0.55.1)
- Fixed a test case related to the no_proxy setting.(v0.55.1)
- Enforced case-insensitive blocking of sensitive paths and VS Code hitl to improve security.(v0.55.1)
- Resolved defensive path resolution for at-reference files and fixed macOS tests.(v0.55.1)
- Resolved symbolic link directory escape issues in the memory import processor.(v0.55.1)
- Made ~/.gitconfig read-only in the macOS sandbox to enhance security.(v0.55.1)
- Preserved escape sequences in string literals for modern models.(v0.55.1)
- Stripped thoughts from scrubbed history turns and resolved thought leakage.(v0.55.1)
- Bypassed LLM correction for JSON and IPYNB files in write_file and replace operations.(v0.55.1)
- Used an unambiguous previous intent label in fallback summaries.(v0.55.1)
- Ensured task cancellation aborts the execution loop in the a2a server.(v0.55.1)
- Simplified the plan mode write policy to support relative paths.(v0.55.1)
- Grouped cancelled tool responses and coalesced consecutive roles to prevent 400 Bad Request errors.(v0.55.1)
- Aligned macOS permissive Seatbelt profiles with the deny-default model.(v0.55.1)
- Mitigated infinite ReAct loops and prompt injection loops.(v0.55.1)
- Enforced workspace trust and task isolation in the a2a server to prevent RCE.(v0.55.1)
- Sequentially verified cached credentials and restored GOOGLE_APPLICATION_CREDENTIALS fallback.(v0.55.1)
- Sanitized and wrapped issue titles in untrusted_context for the caretaker.(v0.55.1)
- Rotated session ID on model fallback to prevent stateful API errors.(v0.55.1)
- Enforced HTTPS for GoogleCredentialsAuthProvider to prevent cleartext leakage.(v0.55.1)
- Filtered out thought parts from getHistoryTurns when context management is disabled.(v0.55.1)
- Normalized CRLF line endings to LF in getProposedContent.(v0.55.1)
- Enforced explicit tag length and validation in the file keychain.(v0.55.1)
- Skipped merged function-response turns when finding the active loop.(v0.55.1)
- Fixed the caretaker agent to clear the lock on NEEDS_HUMAN transition.(v0.56.0-preview.1)
- Fixed the core to refresh MCP OAuth tokens using the stored client ID.(v0.56.0-preview.1)
- Resolved false model capacity exhaustion errors and fixed core quota lookup model mapping.(v0.56.0-preview.1)
- Fixed an issue where MCP OAuth tokens were not being refreshed with the stored client ID.(v0.56.0-nightly.20260811.geef19f25c)
- Fixed an issue where the lock was not cleared on NEEDS_HUMAN transition in the caretaker.(v0.56.0-nightly.20260808.gcf22ac7e8)
- Patched version v0.54.0 to v0.54.1 to address an issue.(v0.54.4)
- Fixed an issue where issue titles in untrusted contexts were not properly sanitized and wrapped.(v0.54.0)
- Resolved an issue where rotating the session ID on model fallback prevented stateful API errors.(v0.54.0)
- Ensured HTTPS is enforced for GoogleCredentialsAuthProvider to prevent cleartext leakage.(v0.54.0)
- Fixed an issue where thought parts were filtered out from getHistoryTurns when context management was disabled.(v0.54.0)
- Normalized CRLF line endings to LF in getProposedContent for the a2a-server.(v0.54.0)
- Enforced explicit tag length and validation in the file keychain.(v0.54.0)
- Skipped merged function-response turns when finding the active loop.(v0.54.0)
- Fixed retry hangs by classifying capacity exhaustion as a terminal error.(v0.55.0-preview.1)
- Propagated InvalidStreamError details to the UI for better guidance on specific empty responses.(v0.55.0-preview.1)
- Ensured fallback to embedded macOS seatbelt profiles when they are missing.(v0.55.0-preview.1)
- Handled npm dist-tag deletion failures on registries that do not permit it.(v0.55.0-preview.1)
- Prevented new user messages from fusing into unanswered tool responses.(v0.55.0-preview.1)
- Repaired session reloads for /compress and restored lost quota-fallback tool responses.(v0.55.0-preview.1)
- Preserved functionCall thoughtSignature when stripping thought parts.(v0.55.0-preview.1)
- Unwrapped and parsed nested gaxios streaming errors from the cause message.(v0.55.0-preview.1)
- Fixed an issue where the CLI would fall back to embedded macOS seatbelt profiles if they were missing.(v0.55.0-nightly.20260806.g761f604c1)
- Resolved failures when deleting npm dist-tags on registries that forbid this operation.(v0.55.0-nightly.20260806.g761f604c1)
- Prevented a new user message from fusing into an unanswered tool response.(v0.55.0-nightly.20260806.g761f604c1)
- Repaired session reload for the /compress command and loss of quota-fallback tool responses.(v0.55.0-nightly.20260806.g761f604c1)
- Preserved the functionCall thoughtSignature when stripping thought parts.(v0.55.0-nightly.20260806.g761f604c1)
- Unwrapped and parsed nested gaxios streaming errors from the cause message.(v0.55.0-nightly.20260806.g761f604c1)
- Fixed issue where npm ci ignore scripts were not being verified during release.(v0.50.0)
- Prevented workspace binary shadowing during release verification.(v0.50.0)
- Prevented bad NPM releases and subsequent job crashes during the release process.(v0.50.0)
- Fixed an issue where the no_proxy test was failing.(v0.51.0-preview.0)
- Enforced case-insensitive blocking for sensitive paths and fixed VSCode hitl issues.(v0.51.0-preview.0)
- Resolved defensive path resolution for at-reference files and fixed macOS tests in core-tools.(v0.51.0-preview.0)
- Resolved symbolic link directory escape issues within the memory import processor.(v0.51.0-preview.0)
- Fixed an issue where escape sequences were not being preserved in string literals for modern models.(v0.51.0-preview.0)
- Stripped thoughts from scrubbed history turns and resolved thought leakage in core processing.(v0.51.0-preview.0)
- Made ~/.gitconfig read-only within the macOS sandbox environment.(v0.51.0-preview.0)
- Fixed an issue where escape sequences in string literals were not being preserved when interacting with modern models.(v0.51.0-nightly.20260707.g15a9429b6)
- Prevented the tool from writing to ~/.gitconfig within the macOS sandbox environment.(v0.51.0-nightly.20260707.g15a9429b6)
- Fixed an issue where the memory import processor could escape symbolic link directories.(v0.51.0-nightly.20260702.gff00dacd9)
- Resolved an issue with defensive path resolution for at-reference files.(v0.51.0-nightly.20260701.g7f00c5fe5)
- Fixed macOS tests that were failing due to path resolution issues.(v0.51.0-nightly.20260701.g7f00c5fe5)
- Fixed security vulnerability by enforcing case-insensitive sensitive path blocklist and improving VS Code HITL handling.(v0.51.0-nightly.20260628.gae0a3aa7b)
- Fixed issue that could cause bad NPM releases and job crashes during CI.(v0.51.0-nightly.20260626.gb14416447)
- Resolved an issue where the no_proxy test was failing.(v0.51.0-nightly.20260626.gb14416447)
- Fixed zero-quota limits failing fast to prevent retry loop hangs.(v0.49.0)
- Fixed handling of multi-line escaped quotes in stripShellWrapper.(v0.49.0)
- Prevented path traversal vulnerabilities during skill installation.(v0.49.0)
- Fixed issues related to pending tools and trust overrides.(v0.49.0)
- Fixed tmux false positive background detection.(v0.49.0)
- Fixed configuration migration for coreTools setting to tools.core.(v0.49.0)
- Resolved workspace publish failures and scheduler event loop starvation.(v0.49.0)
- Fixed CI issues by providing fallbacks for package variables in nightly releases.(v0.49.0)
- Fixed CI issues by appending trailing slash to registry URL in npmrc.(v0.49.0)
- Fixed CI issues by using wombat dressing room fallback in nightly release to prevent ENEEDAUTH errors.(v0.49.0)
- Fixed issue where npm ci ignore scripts were not being verified during release.(v0.50.0-preview.1)
- Prevented workspace binary shadowing during release verification.(v0.50.0-preview.1)
- Resolved issue that caused bad NPM releases and promoted job crashes.(v0.50.0-preview.1)
- Prevented path traversal vulnerabilities during skill installation in the CLI.(v0.49.0-nightly.20260625.gd845bc5d4)
- Fixed issues related to pending tools and trust overrides.(v0.49.0-nightly.20260625.gd845bc5d4)
- Resolved a false positive background detection issue when using tmux.(v0.49.0-nightly.20260625.gd845bc5d4)
- Fixed configuration migration where the coreTools setting was incorrectly handled; now correctly migrates to tools.core.(v0.49.0-nightly.20260625.gd845bc5d4)
- Resolved an issue where defensive path resolution for at-reference files was failing (though this was later reverted, indicating a fix attempt).(v0.49.0-nightly.20260625.gd845bc5d4)
- Fixed workspace publish failures and scheduler event loop starvation issues.(v0.49.0-nightly.20260625.gd845bc5d4)
- Fixed CI issues by providing fallbacks for package variables during nightly releases.(v0.49.0-nightly.20260625.gd845bc5d4)
- Fixed CI issues by appending a trailing slash to the registry URL in npmrc.(v0.49.0-nightly.20260625.gd845bc5d4)
- Fixed CI issues by using a wombat dressing room fallback in nightly releases to prevent ENEEDAUTH errors.(v0.49.0-nightly.20260625.gd845bc5d4)
- Fixed verification issues by ensuring npm ci ignores scripts during release verification.(v0.49.0-nightly.20260625.gd845bc5d4)
- Prevented workspace binary shadowing during release verification in CI.(v0.49.0-nightly.20260625.gd845bc5d4)
- Fixed an issue where TOML parsing could fail by adding an EBUSY fallback mechanism.(v0.47.0)
- Fixed the Vertex AI model mapping configuration.(v0.47.0)
- Prevented the system from persisting resume sessions that are empty.(v0.47.0)
- Fixed an issue where zero-quota limits caused a hang due to an infinite retry loop.(v0.48.0-preview.0)
- Fixed handling of multi-line escaped quotes within the stripShellWrapper function.(v0.48.0-preview.0)
- Prevented path traversal vulnerabilities during skill installation.(v0.48.0-preview.0)
- Fixed an issue where pending tools and trust overrides were not being handled correctly.(v0.48.0-preview.0)
- Fixed incorrect background detection when running within tmux sessions.(v0.48.0-preview.0)
- Fixed configuration migration to move the coreTools setting to tools.core.(v0.48.0-preview.0)
- Resolved defensive path resolution issues for at-reference files in core tools (Note: This fix was subsequently reverted, but is listed as a change attempt).(v0.48.0-preview.0)
- Fixed an issue where zero-quota limits caused a retry loop hang by ensuring they fail fast.(v0.48.0-nightly.20260613.g9e5599c32)
- Fixed incorrect handling of multi-line escaped quotes within the stripShellWrapper function.(v0.48.0-nightly.20260613.g9e5599c32)
- Fixed incorrect Vertex AI model mapping.(v0.48.0-nightly.20260613.g9e5599c32)
- Fixed native crashes that occurred when resizing the PTY (Pseudo-Terminal).(v0.46.0)
- Prevented a spam loop when the configured preferredEditor setting was invalid.(v0.46.0)
- Fixed an issue where TOML parsing could fail by adding an EBUSY fallback mechanism.(v0.47.0-preview.0)
- Fixed incorrect mapping for Vertex AI models.(v0.47.0-preview.0)
- Prevented the system from persisting empty resume sessions.(v0.47.0-preview.0)
- Fixed policy parsing issues by adding an EBUSY fallback and TOML parse recovery.(v0.47.0-nightly.20260604.g4196596f7)
Releases with CLI Changes
v0.60.0-nightly.20260906.g85aca163fThis release includes updates to the Gemini CLI. Please refer to the full changelog for detailed information on any changes or fixes implemented in this version.
v0.60.0-nightly.20260905.g85aca163f3 fixesThis release focuses on security and stability improvements. It includes fixes for environment variable handling, workspace path checks, and configuration file permissions. These updates enhance the safety and reliability of the command-line interface.
v0.60.0-nightly.20260904.g87a9c71d51 feature3 fixesThis release enhances security and reliability with improvements to the extension loader and fixes for OAuth flow and macOS sandbox issues. A hardcoded API key has also been removed from chrome-devtools-mcp.
v0.59.0-nightly.20260902.g4963a44561 fixThis release includes improvements to web fetch utilities, specifically enhancing destination validation and connection routing. These changes aim to make network requests more robust and reliable.
v0.58.05 fixesThis release focuses on several bug fixes to improve stability and reliability. Key fixes include ensuring consistent symlink evaluation, isolating container runtime components on macOS, and clearing stale cancellation errors for smoother conversation turns. Additionally, optimizations have been made to history rollback and retry nudges.
v0.59.0-preview.02 fixesThis release addresses critical security vulnerabilities by preventing SSRF attacks and enforcing stricter workspace trust policies. It also ensures that MCP servers are properly filtered in restricted modes, enhancing the overall security posture of the CLI.
v0.59.0-nightly.20260901.g0bd1d4397This release focuses on internal updates and does not introduce new user-facing features or bug fixes. The primary change is the update to a new nightly build, with a full changelog available via the provided GitHub link for detailed technical information.
v0.59.0-nightly.20260831.g0bd1d4397This release focuses on internal updates and maintenance. No new user-facing features or bug fixes are highlighted in these notes.
v0.59.0-nightly.20260830.g0bd1d4397This release includes updates to the Gemini CLI. Please refer to the full changelog for detailed information on any new features, bug fixes, or improvements introduced in this version.
v0.59.0-nightly.20260829.g0bd1d43971 fixThis release addresses a critical bug related to workspace trust enforcement in fail-closed and restricted modes. It ensures that MCP servers are correctly filtered, enhancing security and reliability.
v0.59.0-nightly.20260828.g3c311beacThis release focuses on internal updates and maintenance. No new user-facing features or bug fixes are highlighted in these notes.
v0.59.0-nightly.20260827.g3c311beac1 fixThis release addresses a critical security vulnerability related to Server-Side Request Forgery (SSRF) in the MCP OAuth authentication process. The fix ensures more secure handling of metadata discovery and authentication.
v0.59.0-nightly.20260826.g64b5b79a6This release includes updates to the Gemini CLI, bumping the version to 0.59.0-nightly.20260825.g812f7a2bc. A full changelog detailing the comparison between versions is available for review.
v0.57.03 features18 fixesThis release introduces enhanced evaluation capabilities with a new tool call formatter and integrated failure summaries. Several bug fixes have been implemented to improve reliability, including better handling of OAuth flows, IDE connections, and multi-turn request rollbacks. Additionally, the SSR Agent has seen numerous fixes and improvements, such as execution timeouts and clearer privacy notices.
v0.58.0-preview.05 fixesThis release focuses on stability and reliability with several bug fixes. Key improvements include better handling of symlinks, enhanced isolation for container runtimes on macOS, and optimizations for history rollback and retry nudges.
v0.56.0-nightly.20260825.g812f7a2bc3 fixesThis release focuses on stability and reliability. Several bug fixes have been implemented, including addressing stale cancellation errors and optimizing history rollback and retry nudges. Safety checker declarations have also been improved.
v0.57.0-preview.11 fixThis release primarily focuses on patching and stabilizing the v0.57.0-preview.0 version. A new preview version, v0.57.0-preview.1, has been created to incorporate these fixes.
v0.56.0-nightly.20260824.g5411f113cThis release focuses on internal changes and updates to the Gemini CLI. While no new user-facing features or bug fixes are explicitly detailed in these notes, the provided changelog link offers a comprehensive view of all modifications made during this development cycle.
v0.56.0-nightly.20260823.g5411f113cThis release contains only internal changes and no user-facing features or bug fixes.
v0.56.0-nightly.20260822.g5411f113c1 fixThis release includes a bug fix for macOS users, improving the isolation of Docker and container runtime components within the Seatbelt sandbox. This enhances security and stability for users running containerized workloads on macOS.
v0.56.0-nightly.20260821.g30573d2e41 fixThis release includes a fix for inconsistent symlink evaluation in ignore path handling, ensuring more reliable behavior. Internal code refactoring was also performed to improve maintainability.
v0.56.0-nightly.20260820.ge90c63fa11 fixThis release includes a bug fix that ensures empty text turns are correctly preserved when interacting with tools or media. The changelog for the latest preview version is also available.
v0.56.0This release focuses on internal updates and dependency management. While no new user-facing features or bug fixes are explicitly detailed, the underlying components have been updated to ensure continued stability and performance of the Gemini CLI.
v0.57.0-preview.04 features9 fixesThis release enhances the Gemini CLI with improved evaluation capabilities, including tool call formatting and failure summaries. It also addresses several bug fixes related to IDE connections, request handling, and environment normalization. Additionally, various improvements have been made to stability, user experience, and documentation.
v0.56.0-nightly.20260819.g571851b104 fixesThis release focuses on several bug fixes for the SSR Agent. It addresses issues with subagent execution, autocomplete suggestions, terminal rendering after external editor use, and a token regression on startup. Documentation links for Vertex AI locations have also been added.
v0.56.0-nightly.20260818.g194edea473 fixesThis release focuses on improving the SSR Agent by fixing issues that caused indefinite hangs and misleading error messages. Documentation for commands has also been updated, and privacy notices have been clarified.
v0.56.0-nightly.20260817.g9a15c45fb1 fixThis release includes a bug fix for the SSR Agent, addressing an issue related to tsconfig settings. The fix ensures proper configuration for the agent's packages.
v0.56.0-nightly.20260816.g2a87e7be1This release contains a changelog link to the full comparison between two nightly builds. It details the specific code changes and commits made between these versions.
v0.56.0-nightly.20260815.g2a87e7be11 fixThis release includes a fix for the SSR Agent, ensuring proper environment variable handling in tests. This resolves a specific issue related to process.env migration within the a2a-server tests.
v0.56.0-nightly.20260814.gc0d1924523 fixesThis release focuses on core stability and reliability. It includes fixes for multi-turn request handling, git environment normalization, and capacity error management with silent retries. Additionally, tests related to file system interactions have been stabilized.
v0.56.0-nightly.20260813.g1ac3377392 featuresThis release introduces enhancements to the evaluation system, including the addition of tool call formatting and the integration of failure summaries. These changes aim to provide more detailed and structured feedback during evaluations.
v0.56.0-nightly.20260812.g5024443c71 feature3 fixesThis release introduces a new local report command for evaluations, enhancing developer capabilities. Several bugs have been fixed, including issues with model capacity, quota lookup, Cloud Workstations proxy redirects, and IDE connection directory mismatches.
v0.55.111 features26 fixesThis release introduces significant new capabilities in the caretaker system, including webhook ingestion, egress services, and advanced triage features with LLM orchestration. Several bug fixes enhance security and stability, such as mitigating ReAct loops, enforcing workspace trust, and improving path resolution. Additionally, new features like tool registry discovery and an eval coverage report command are now available.
v0.56.0-preview.18 features3 fixesThis release introduces significant enhancements to the caretaker agent, including new triage workflows, evaluation frameworks, and GCP deployment capabilities. Several bugs have been fixed, such as resolving false model capacity exhaustion errors and improving OAuth token refresh. Additionally, the system now handles issue comments and re-triage, and capacity exhaustion is correctly classified as a terminal error.
v0.55.0-preview.3This release is a patch update to version v0.55.0-preview.2, creating version 0.55.0-preview.3. It includes a cherry-pick of a specific commit to address a patch.
v0.56.0-nightly.20260811.geef19f25c1 fixThis release includes a fix for refreshing MCP OAuth tokens, ensuring better authentication stability. It addresses a specific issue related to token refresh using the stored client ID.
v0.56.0-nightly.20260810.gcf22ac7e8This release focuses on internal updates and does not introduce new user-facing features or bug fixes. The primary change is the update to a new nightly build, indicated by the version number. Users can refer to the full changelog for detailed technical information.
v0.56.0-nightly.20260809.gcf22ac7e8This release focuses on internal updates and bug fixes. While no new user-facing features are highlighted, the changelog provides a link to the full commit history for detailed technical information.
v0.56.0-nightly.20260808.gcf22ac7e88 features1 fixThis release introduces several new features for the caretaker, including enhanced triage workflows, evaluation frameworks, and GCP deployment capabilities. It also adds issue comment handling for ingestion and re-triage. Additionally, a bug fix ensures locks are cleared correctly on specific transitions.
v0.54.41 fixThis release includes a patch to version v0.54.1 to address an issue. The version has also been updated to 0.54.2 and then reverted and fixed.
v0.55.0-preview.2This release is a patch update to address specific issues. It includes a cherry-pick of a commit to ensure stability and create a new preview version.
v0.56.0-nightly.20260807.gd5c9a97dcThis release includes updates to the changelog for various versions, including v0.55.0-preview.1 and v0.54.0. It also bumps the version to 0.56.0-nightly.20260806.g761f604c1. A full changelog is available for comparing versions.
v0.54.03 features7 fixesThis release introduces new capabilities for the caretaker triage to post comments before closing issues and enhances the PR generator with Firestore concurrency and an Antigravity agent runner. Several bug fixes have been implemented, including improved security for credentials and better handling of session states and context management.
v0.55.0-preview.13 features8 fixesThis release introduces significant enhancements to the PR generator, including environment configuration, command execution, and iterative bug-fixing capabilities. Several bugs have also been addressed, such as preventing retry hangs due to capacity exhaustion and improving error handling for empty responses.
v0.55.0-nightly.20260806.g761f604c13 features6 fixesThis release introduces significant enhancements to the PR generator, including new core capabilities for environment configuration and GitHub integration, along with an iterative bug-fixing state machine. Several bugs have been fixed, such as issues with seatbelt profiles, npm dist-tag deletion, and tool response handling.
v0.55.0-nightly.20260803.gf47d6c6f7This release focuses on performance improvements for code generation. Users should experience faster and more efficient code snippet creation.
v0.55.0-nightly.20260802.gf47d6c6f7v0.55.0-nightly.20260801.gf47d6c6f7v0.54.0-preview.1v0.53.1v0.55.0-nightly.20260729.g3499c84f7v0.53.0v0.54.0-preview.0v0.54.0-nightly.20260728.gbef611950v0.54.0-nightly.20260727.g3818efbbfv0.54.0-nightly.20260726.g3818efbbfv0.52.0-nightly.20260723.g9681621c6v0.52.0v0.53.0-preview.0v0.52.0-nightly.20260722.gc776c665bv0.52.0-nightly.20260721.gacae7124bv0.52.0-nightly.20260720.gacae7124bv0.52.0-nightly.20260719.gacae7124bv0.52.0-nightly.20260718.gacae7124bv0.51.0v0.52.0-preview.0v0.52.0-nightly.20260716.g3ff5ba20fv0.52.0-nightly.20260715.gfa975395bv0.52.0-nightly.20260714.gfa975395bv0.52.0-nightly.20260713.gf354eebafv0.52.0-nightly.20260710.ga4c91ce19v0.50.01 feature3 fixesThis release introduces tool registry discovery capabilities for enhanced functionality. Several critical fixes were implemented to stabilize the release pipeline, including preventing bad NPM releases and resolving binary shadowing issues during verification.
v0.51.0-preview.02 features7 fixesThis release introduces new caretaker functionality with the implementation of a Cloud Run webhook ingestion service and an egress service skeleton. Key fixes address security concerns by enforcing case-insensitive path blocking and resolve several core processing issues related to symbolic links and history scrubbing. Additionally, the Vertex base URL has been updated.
v0.51.0-nightly.20260707.g15a9429b62 fixesThis release focuses on stability and correctness, primarily by ensuring escape sequences are correctly handled for modern models. Additionally, security within the macOS sandbox has been improved by making ~/.gitconfig read-only.
v0.51.0-nightly.20260706.gf7af4e518This release primarily consists of internal updates and bug fixes, as indicated by the nightly build nature. Users should refer to the detailed comparison link for specific changes between these two nightly versions.
v0.51.0-nightly.20260705.gf7af4e518This release primarily consists of internal updates and maintenance, as indicated by the provided changelog link focusing on a comparison between two nightly builds. Users should refer to the linked comparison for detailed, low-level changes between these specific versions.
v0.51.0-nightly.20260704.gf7af4e518This release primarily consists of internal updates and maintenance, as indicated by the provided changelog link focusing on the comparison between two nightly builds. Users should refer to the linked GitHub comparison for detailed technical changes.
v0.51.0-nightly.20260703.gf7af4e5181 featureThis nightly release introduces the egress cloud run service skeleton as part of the caretaker functionality. There are no reported bug fixes or user-facing improvements in this update.
v0.51.0-nightly.20260702.gff00dacd91 fixThis release focuses on a critical security and stability fix within the core memory import processor. Specifically, it resolves an issue related to symbolic link directory handling during memory imports.
v0.51.0-nightly.20260701.g7f00c5fe51 feature2 fixesThis release introduces a new Cloud Run webhook ingestion service for caretaker operations. Additionally, it resolves a critical bug related to defensive path resolution, which also fixed failing macOS tests.
v0.51.0-nightly.20260630.gae0a3aa7bThis release primarily provides an update to the internal build version, linking to the full comparison log for detailed changes. Users should refer to the provided GitHub link for a complete breakdown of all modifications in this nightly update.
v0.51.0-nightly.20260629.gae0a3aa7bThis release primarily consists of internal updates and maintenance, as indicated by the provided changelog link focusing on a specific nightly build comparison. Users should refer to the linked comparison for detailed commit-level changes between the two nightly versions.
v0.51.0-nightly.20260628.gae0a3aa7b1 fixThis nightly release focuses primarily on a security enhancement. It enforces case-insensitive handling for sensitive path blocklists and improves the VS Code HITL mechanism.
v0.51.0-nightly.20260626.gb144164472 fixesThis release focuses on stability and infrastructure updates. Key fixes include preventing bad NPM releases during CI and resolving a failing no_proxy test. Additionally, the Vertex AI base URL configuration has been updated.
v0.49.03 features10 fixesThis release introduces new capabilities, including support for GDC air-gapped Service Identity and the new eval:inventory CLI command with JSON output. Several critical bugs were fixed, addressing issues like zero-quota hang loops, path traversal vulnerabilities during skill install, and various CI/CD stability problems.
v0.50.0-preview.11 feature3 fixesThis release introduces the capability for tool registry discovery, enhancing how tools are managed. Several critical fixes were implemented to stabilize the release process, including preventing bad NPM releases and resolving binary shadowing issues during CI verification.
v0.49.0-nightly.20260625.gd845bc5d44 features11 fixesThis release introduces significant new capabilities, including support for GDC air-gapped Service Identity and new CLI commands like "eval:inventory" with JSON output. Several critical bug fixes address path traversal vulnerabilities, resolve issues with pending tools and trust overrides, and stabilize the nightly release process.
v0.47.01 feature3 fixesThis release introduces automatic selection of the 3.5 flash model when enabled via a flag, improving model routing efficiency. Key fixes include improved TOML parsing recovery and corrections to Vertex AI model mapping. Additionally, the display frequency of the Antigravity transition banner has been limited.
v0.48.0-preview.01 feature7 fixesThis release introduces support for GDC air-gapped Service Identity and includes a static evaluation source analyzer. Several critical bugs were addressed, including fixing infinite retry loops on zero-quota limits and preventing path traversal vulnerabilities during skill installation.
v0.48.0-nightly.20260613.g9e5599c321 feature3 fixesThis release introduces new documentation and migration commands for the Antigravity CLI. Key fixes include ensuring zero-quota limits fail fast to prevent hangs and correcting multi-line escaped quote handling. Additionally, the tool now avoids persisting empty resume sessions and standardizes tool output formatting.
v0.46.02 features2 fixesThis release introduces the ability to include quotes in your interactions and enables the use of the flash GA model under specific experiment flags. Key fixes include hardening PTY resizing against native crashes and preventing spam loops caused by invalid editor configurations.
v0.47.0-preview.01 feature3 fixesThis release introduces automatic model selection, enabling the use of the 3.5 flash model when configured. Key fixes include improved TOML parsing recovery and corrected Vertex AI model mappings. Additionally, usability is enhanced by limiting the Antigravity banner display count and updating related documentation.
v0.46.0-preview.3This release primarily consists of a patch update, cherry-picking a specific commit to stabilize the v0.46.0-preview.2 branch into the new v0.46.0-preview.3 version. No new user-facing features or specific bug fixes were detailed in this summary section.
v0.45.3This release appears to be a patch update (v0.45.3) created via a cherry-pick operation. No user-facing features or specific bug fixes are detailed in these brief notes.
v0.47.0-nightly.20260609.g0567b25a2This release focuses on minor housekeeping and user experience refinements. The primary change is limiting the display frequency of the Antigravity transition banner. Additionally, experimental text has been removed from the browser agent documentation.
v0.45.2This release appears to be a patch update (v0.45.2) based on cherry-picking a specific commit from the previous version branch. No user-facing features or specific bug fixes are detailed in this summary section.
v0.46.0-preview.2This release primarily consists of a patch update (v0.46.0-preview.2) created by cherry-picking a specific commit (f40498d) from the previous preview version. There are no new user-facing features or specific bug fixes detailed in this summary section.
v0.47.0-nightly.20260605.g4196596f7This release primarily consists of internal updates and minor refinements, as indicated by the focus on a comparison link without specific feature or fix descriptions in the main body. Users should refer to the provided link for detailed commit-level changes.
v0.45.1This release appears to be a patch update (v0.45.1) focused on cherry-picking a specific commit to stabilize the current version. No new user-facing features or specific bug fixes were detailed in the provided notes beyond the patch application.
v0.47.0-nightly.20260604.g4196596f72 features1 fixThis release introduces support for using the Gemini 1.5 Flash model automatically when enabled via a flag. It also includes stability improvements by adding recovery mechanisms for policy parsing errors. Additionally, the continuous integration process has been optimized with new labeling and batching workflows.