Evidence record / gemini-cli
A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.
2026-07-01-gemini-cli-case-insensitive-sensitive-path-blocklist-vscode-human-i
Case-insensitive sensitive-path blocklist + .vscode human-in-the-loop landed on main (nightly-only, not yet stable) (channel: main-unreleased, 2026-06-26). Operator consequence: New agent-execution trust behavior: case-insensitive blocking of sensitive dirs (.git/.env/node_modules incl. .GIT/.Git), Windows trailing-char and NTFS ADS (::$DATA) bypass prevention, ReDoS-safe non-regex trimming, and a new human-in-the-loop confirmation prompt for .vscode modifications (deny outside workspace). NOT in v0.49.0 or v0.50.0-preview.1 — only in v0.51.0 nightlies. Operators should WATCH for it to reach a stable/preview tag; do not assume the hardened blocklist or the .vscode approval gate is present in current stable. Full receipted detail lives in harvest/watchlist.md.
Receipt
Finding metadata
Run: 2026-07-01-weekly-digest-2026-06-24_2026-07-01-frontier-v0
Finding ID: 2026-07-01-gemini-cli-case-insensitive-sensitive-path-blocklist-vscode-human-i
Source links
Primary links, including exact changelog lines when available.
Versioned source: run artifact