Finding / gemini-cli

2026-08-20-gemini-cli-git-env-hardening-is-preview-not-0-56-0

Parent recorded git subprocess env neutralization as main-unreleased after v0.55.1. It did not ride the v0.56.0 promotion. gitUtils.ts at v0.56.0 (85 lines) has no getSafeGitEnv. At v0.57.0-preview.0 it exports getSafeGitEnv and pins GIT_CONFIG_GLOBAL plus credential.helper. compare v0.57.0-preview.0...c0d192452 status=behind, ahead_by=0. compare v0.56.0...c0d192452 status=diverged.

Channel: preview-or-beta. Half: both | security-relevant.

Operator consequence: on latest, a workspace .git/config can still set core.pager / core.hooksPath for agent git. If you need the guard before the next real stable, the runnable channel is preview. Re-test gemini extensions install against private repos because credential.helper is blanked.

Receipt

Finding metadata

Run: 2026-08-20-brief-2026-08-17_2026-08-20-frontier-v0

Finding ID: 2026-08-20-gemini-cli-git-env-hardening-is-preview-not-0-56-0

Profile citations

  • Gemini CLI / claim / git-env-hardening-preview-only

Source links

Primary links, including exact changelog lines when available.