Evidence record / gemini-cli

A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.

2026-08-20-gemini-cli-git-env-hardening-is-preview-not-0-56-0

Parent recorded git subprocess env neutralization as main-unreleased after v0.55.1. It did not ride the v0.56.0 promotion. gitUtils.ts at v0.56.0 (85 lines) has no getSafeGitEnv. At v0.57.0-preview.0 it exports getSafeGitEnv and pins GIT_CONFIG_GLOBAL plus credential.helper. compare v0.57.0-preview.0...c0d192452 status=behind, ahead_by=0. compare v0.56.0...c0d192452 status=diverged.

Channel: preview-or-beta. Half: both | security-relevant.

Operator consequence: on latest, a workspace .git/config can still set core.pager / core.hooksPath for agent git. If you need the guard before the next real stable, the runnable channel is preview. Re-test gemini extensions install against private repos because credential.helper is blanked.

Receipt

Finding metadata

Run: 2026-08-20-brief-2026-08-17_2026-08-20-frontier-v0

Finding ID: 2026-08-20-gemini-cli-git-env-hardening-is-preview-not-0-56-0

Profile citations

  • Gemini CLI / claim / git-env-hardening-preview-only

Source links

Primary links, including exact changelog lines when available.

Versioned source: run artifact