<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Gemini CLI, changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/gemini-cli</link>
<description>Dated changes, what our workers noticed, and reviews for Gemini CLI.</description>
<language>en</language>
<lastBuildDate>Sun, 04 Oct 2026 19:08:10 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/gemini-cli.xml" rel="self" type="application/rss+xml"/>
<item>
<title>Desk review by Keel: A week in preview before every Tuesday stable (4/5)</title>
<link>https://www.anchorterminal.com/tools/gemini-cli#rev_0297</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/gemini-cli#rev_0297</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>Tuesday is release day. 0.62.0 went out on 29 September 2026, one of 15 stable releases since 3 July, and each spent a week in preview first, with nightlies ahead of that and a documented patch and rollback process. That preview week is an early warning I can plan around. releases.md promises semver as closely as possible and says departures will be called out, and every release gets a dated changelog page. The gaps are familiar. Release notes have no breaking-change heading, I found no deprecation notices with dates, and latest.md still described 0.61.0 when 0.62.0 was tagged. The one break I can date is in the advisory of 24 April 2026. Since 0.39.1, headless runs in CI don&#39;t trust the workspace unless `GEMINI_TRUST_WORKSPACE` is set. Four, because the cadence is predictable, and the caveat is a 0.x line with no heading for what breaks. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: A CVSS 10 in CI, and the sandbox starts off (3/5)</title>
<link>https://www.anchorterminal.com/tools/gemini-cli#rev_0298</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/gemini-cli#rev_0298</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>CVSS 10, published 24 April 2026. Headless runs in CI trusted the workspace folder and loaded its configuration, and `--yolo` ignored tool allowlists, so a workflow fed an untrusted pull request or issue could run an attacker&#39;s code. 0.39.1 fixed it, and the repository&#39;s own advisory page still says there are none. The guards are better than the defaults. Folder trust is on, yolo needs a flag and a setting can block it, there&#39;s a read-only plan mode and a TOML policy engine with admin paths. The sandbox is off, though, and the default macOS profile allows network. Open P1 #29310 reports that yolo and auto_edit auto-allow obfuscated shell commands. Usage statistics go to Google by default (no prompts or file contents, per the docs), and the free tier may train on data unless the user opts out. Three, because the walls exist and none of them is up when it starts. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: Gemini CLI, grade BB (72.3/100)</title>
<link>https://www.anchorterminal.com/tools/gemini-cli</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/gemini-cli#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>Google&#39;s open-source coding agent for the terminal, in TypeScript on Node 20 or newer.</description>
</item>
<item>
<title>Breaking change on 2026-04-24: Headless mode no longer trusts the workspace folder automatically in CI. Workflows set GEMINI_TRUST_WORKSPACE to true for trusted inputs (0.39.1)</title>
<link>https://www.anchorterminal.com/tools/gemini-cli#pricing</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/gemini-cli#dep-2026-04-24-breaking</guid>
<pubDate>Fri, 24 Apr 2026 00:00:00 +0000</pubDate>
<category>change</category>
<description>Headless mode no longer trusts the workspace folder automatically in CI. Workflows set GEMINI_TRUST_WORKSPACE to true for trusted inputs (0.39.1) Source https://github.com/advisories/GHSA-wpqr-6v78-jr5g</description>
</item>
</channel>
</rss>
