Upgrade Gemini CLI to v0.55.1 for tool registry discovery and path security hardening
Move teams to Gemini CLI v0.55.1 to pick up tool registry discovery, case-insensitive sensitive-path blocklists, symlink escape fixes, read-only ~/.gitconfig in the macOS sandbox, and scrubbed-history thought-leakage fixes.Why this loop
v0.55.1 is the Gemini CLI tag that adds tool registry discovery and closes path, sandbox, and history holes still present on older nightlies. Sensitive-path blocking is now case-insensitive (with vscode HITL); at-reference files use defensive path resolution; the memory import processor no longer follows symlink directory escapes; the macOS sandbox mounts ~/.gitconfig read-only and Seatbelt permissive profiles follow deny-default, falling back to embedded copies if profiles are missing. Scrubbed history strips thought parts so they cannot leak (including when context management is off) while preserving functionCall thoughtSignature. Same tag also ships MCP OAuth refresh with the stored client ID, HTTPS-only GoogleCredentialsAuthProvider, A2A workspace trust/task isolation plus cancel-abort, capacity exhaustion treated as terminal (false-exhaustion quota lookup fixed), session-ID rotation on model fallback, /compress reload repair, Vertex base URL update, and google-auth-library 10.9.0. Release verification now runs npm ci with ignore-scripts and no longer shadows workspace binaries—pin local agents and CI to 0.55.1 together.
Proposed actions
- npm install -g @google/gemini-cli@0.55.1 && gemini --version
- In every repo, image, and CI job that pins Gemini CLI, set "@google/gemini-cli": "0.55.1" (package.json, Dockerfiles, setup scripts), delete any workspace node_modules/.bin/gemini that could shadow the release binary, then run npm ci --ignore-scripts && npm ls @google/gemini-cli.
- On macOS after upgrade, start Gemini CLI in the sandbox and confirm ~/.gitconfig is read-only and Seatbelt is deny-default (missing profiles must load the embedded copies shipped in 0.55.1, not fail open).
- Regression-check path security on 0.55.1: import memory from a tree with a symlink pointing outside the workspace; @-reference mixed-case sensitive paths; run write_file/replace on .json and .ipynb. Expect blocked symlink escape, case-insensitive blocklist hits, and no LLM rewrite of JSON/IPYNB.
- Restart long-lived Gemini CLI, A2A, and MCP sessions so MCP OAuth refreshes with the stored client ID, thought parts stay stripped from scrubbed history, and A2A task cancellation aborts the execution loop under workspace trust isolation.
Agent prompt
Paste into your agent or query via MCP (get_agent_prompt) — free, no extra AI costGoogle Antigravity / agent task
DevAgentRadar → Google Antigravity
Goal: turn this release signal into a safe pilot plan for my stack.
Context
Assistant: Gemini CLI Proposal: Upgrade Gemini CLI to v0.55.1 for tool registry discovery and path security hardening Summary: Move teams to Gemini CLI v0.55.1 to pick up tool registry discovery, case-insensitive sensitive-path blocklists, symlink escape fixes, read-only ~/.gitconfig in the macOS sandbox, and scrubbed-history thought-leakage fixes. Primary source: https://github.com/google-gemini/gemini-cli/releases/tag/v0.55.1
Why it matters
v0.55.1 is the Gemini CLI tag that adds tool registry discovery and closes path, sandbox, and history holes still present on older nightlies. Sensitive-path blocking is now case-insensitive (with vscode HITL); at-reference files use defensive path resolution; the memory import processor no longer follows symlink directory escapes; the macOS sandbox mounts ~/.gitconfig read-only and Seatbelt permissive profiles follow deny-default, falling back to embedded copies if profiles are missing. Scrubbed history strips thought parts so they cannot leak (including when context management is off) while preserving functionCall thoughtSignature. Same tag also ships MCP OAuth refresh with the stored client ID, HTTPS-only GoogleCredentialsAuthProvider, A2A workspace trust/task isolation plus cancel-abort, capacity exhaustion treated as terminal (false-exhaustion quota lookup fixed), session-ID rotation on model fallback, /compress reload repair, Vertex base URL update, and google-auth-library 10.9.0. Release verification now runs npm ci with ignore-scripts and no longer shadows workspace binaries—pin local agents and CI to 0.55.1 together.
Suggested actions
- npm install -g @google/gemini-cli@0.55.1 && gemini --version
- In every repo, image, and CI job that pins Gemini CLI, set "@google/gemini-cli": "0.55.1" (package.json, Dockerfiles, setup scripts), delete any workspace node_modules/.bin/gemini that could shadow the release binary, then run npm ci --ignore-scripts && npm ls @google/gemini-cli.
- On macOS after upgrade, start Gemini CLI in the sandbox and confirm ~/.gitconfig is read-only and Seatbelt is deny-default (missing profiles must load the embedded copies shipped in 0.55.1, not fail open).
- Regression-check path security on 0.55.1: import memory from a tree with a symlink pointing outside the workspace; @-reference mixed-case sensitive paths; run write_file/replace on .json and .ipynb. Expect blocked symlink escape, case-insensitive blocklist hits, and no LLM rewrite of JSON/IPYNB.
- Restart long-lived Gemini CLI, A2A, and MCP sessions so MCP OAuth refreshes with the stored client ID, thought parts stay stripped from scrubbed history, and A2A task cancellation aborts the execution loop under workspace trust isolation.
Config surfaces this release may change
- sandbox settings — check your repo before applying
- MCP servers — check your repo before applying
After you finish
Do not report this as applied to DevAgentRadar. You cannot write the visitor's loop.
Tell the human: open https://devagentradar.com/proposals/gemini-cli-v0-55-1-upgrade-gemini-cli-to-v0-55-1-for-tool-registry-disco and mark Applied, Skipped, or Failed. Proposal id: 751d2f2a-3547-4678-9ca9-09ba3239476b
Please:
- Map the change to concrete pilot steps
- Flag security / permission implications
- Keep the pilot reversible
Your loop
This browser · no sign-in · not shared as “you”After you run the prompt
Only you can mark this. Agents cannot write your loop.
Your decision stays on this device. A public tally appears after a few votes.