Skip to content
Proposals/Upgrade Gemini CLI nightly for macOS Seatbelt Do
proposaldeveloperP3Worth a lookGCGemini CLI

Upgrade Gemini CLI nightly for macOS Seatbelt Docker socket isolation

Adopt Gemini CLI v0.56.0-nightly.20260822.g5411f113c so macOS Seatbelt sandboxing isolates Docker and container runtime sockets and binaries, tightening CLI sandbox boundaries when containers are present.

Why this loop

Gemini CLI v0.56.0-nightly.20260822.g5411f113c is a prerelease whose only stated change is fix(sandbox): isolate Docker and container runtime sockets and binaries in macOS Seatbelt. On Macs that run Gemini CLI under Seatbelt and also host Docker or another container runtime, that isolation shrinks the sandbox so those sockets and binaries are no longer inside the CLI boundary. Pin this exact nightly (do not float latest) on affected macOS developer machines, then re-check any Seatbelt-sandboxed session that previously talked to a container runtime. Nightly/prerelease: treat the version string as a security pin, not a feature upgrade.

Proposed actions

  1. Pin Gemini CLI to the release version only: npm install -g @google/gemini-cli@0.56.0-nightly.20260822.g5411f113c. If the CLI is installed another way, set the same version string in that installer or lockfile; do not use @latest or an unpinned nightly tag.
  2. Confirm the pin before any sandboxed use: gemini --version must print 0.56.0-nightly.20260822.g5411f113c. If it does not, stop and fix the install path that is still shadowing PATH.
  3. On each macOS host that has Docker or another container runtime, start Gemini CLI in the Seatbelt sandbox with that runtime running, then verify the sandboxed process cannot use isolated Docker/container runtime sockets or binaries (the change this nightly advertises).
  4. If a workflow required Docker/container sockets or binaries from inside a Seatbelt-sandboxed Gemini CLI session, move that work to an unsandboxed host step or a dedicated runner; do not loosen the Seatbelt profile to restore the old access.
  5. Record the adopted identifier v0.56.0-nightly.20260822.g5411f113c and source https://github.com/google-gemini/gemini-cli/releases/tag/v0.56.0-nightly.20260822.g5411f113c in the team CLI version pin so later nightlies cannot silently replace this sandbox fix.

Agent prompt

Paste into your agent or query via MCP (get_agent_prompt) — free, no extra AI cost

Google Antigravity / agent task

DevAgentRadar → Google Antigravity

Goal: turn this release signal into a safe pilot plan for my stack.

Context

Assistant: Gemini CLI Proposal: Upgrade Gemini CLI nightly for macOS Seatbelt Docker socket isolation Summary: Adopt Gemini CLI v0.56.0-nightly.20260822.g5411f113c so macOS Seatbelt sandboxing isolates Docker and container runtime sockets and binaries, tightening CLI sandbox boundaries when containers are present. Primary source: https://github.com/google-gemini/gemini-cli/releases/tag/v0.56.0-nightly.20260822.g5411f113c

Why it matters

Gemini CLI v0.56.0-nightly.20260822.g5411f113c is a prerelease whose only stated change is fix(sandbox): isolate Docker and container runtime sockets and binaries in macOS Seatbelt. On Macs that run Gemini CLI under Seatbelt and also host Docker or another container runtime, that isolation shrinks the sandbox so those sockets and binaries are no longer inside the CLI boundary. Pin this exact nightly (do not float latest) on affected macOS developer machines, then re-check any Seatbelt-sandboxed session that previously talked to a container runtime. Nightly/prerelease: treat the version string as a security pin, not a feature upgrade.

Suggested actions

  1. Pin Gemini CLI to the release version only: npm install -g @google/gemini-cli@0.56.0-nightly.20260822.g5411f113c. If the CLI is installed another way, set the same version string in that installer or lockfile; do not use @latest or an unpinned nightly tag.
  2. Confirm the pin before any sandboxed use: gemini --version must print 0.56.0-nightly.20260822.g5411f113c. If it does not, stop and fix the install path that is still shadowing PATH.
  3. On each macOS host that has Docker or another container runtime, start Gemini CLI in the Seatbelt sandbox with that runtime running, then verify the sandboxed process cannot use isolated Docker/container runtime sockets or binaries (the change this nightly advertises).
  4. If a workflow required Docker/container sockets or binaries from inside a Seatbelt-sandboxed Gemini CLI session, move that work to an unsandboxed host step or a dedicated runner; do not loosen the Seatbelt profile to restore the old access.
  5. Record the adopted identifier v0.56.0-nightly.20260822.g5411f113c and source https://github.com/google-gemini/gemini-cli/releases/tag/v0.56.0-nightly.20260822.g5411f113c in the team CLI version pin so later nightlies cannot silently replace this sandbox fix.

Config surfaces this release may change

  • sandbox settings — check your repo before applying

After you finish

Do not report this as applied to DevAgentRadar. You cannot write the visitor's loop.

Tell the human: open https://devagentradar.com/proposals/gemini-cli-v0-56-0-nightly-20260822-g5411f113c-upgrade-gemini-cli-nightl and mark Applied, Skipped, or Failed. Proposal id: 09a7e301-bf99-46ad-96ce-7f9074f8321d

Please:

  1. Map the change to concrete pilot steps
  2. Flag security / permission implications
  3. Keep the pilot reversible
modelsecuritycliprereleaseRelease source ↗

Your loop

This browser · no sign-in · not shared as “you”

After you run the prompt

Only you can mark this. Agents cannot write your loop.

Your decision stays on this device. A public tally appears after a few votes.

Originating release signal

GCGemini CLIv0.56.0-nightly.20260822.g5411f113cAug 22, 2026

v0.56.0-nightly.20260822.g5411f113c Release v0.56.0-nightly.20260822.g5411f113c

fix(sandbox): isolate Docker and container runtime sockets and binaries in macOS Seatbelt
Verified excerpt — the source's own words

What's Changed

New Contributors

Full Changelog: https://github.com/google-gemini/gemini-cli/compare/v0.56.0-nightly.20260821.g30573d2e4...v0.56.0-nightly.20260822.g5411f113c

Primary source ↗