Prewire · case file · public copy of the record
FILE P340 PREWIRE receipts archive the live wire
CATCH #1240 DETECTED SEP 8, 2026 21:17 UTC
THE CATCHscore 7/10
EXHIBIT 1240 · URGENT
Sep 8, 2026 21:17 UTC github google-gemini/gemini-cli
Gemini CLI releases v0.60.0-preview.0 with significant security and hardening improvements, including new path validation and sandbox isolation features.

READY TO POST:

gemini cli just dropped v0.60.0-preview.0. lots of security fixes and hardening around path validation and sandbox isolation. good stuff!

looks like the gemini cli is getting a big security upgrade in v0.60.0-preview.0. focusing on isolating temp dirs and stricter config permissions.

EVIDENCE — the receipts
[MERGED across 2 sources: github_releases]
shared signal: gemini-cli, gemini-cli-robot

--- github_releases :: google-gemini/gemini-cli ---
google-gemini/gemini-cli pre-release: v0.60.0-preview.0
name: Release v0.60.0-preview.0
published: 2026-09-08T21:04:17Z
url: https://github.com/google-gemini/gemini-cli/releases/tag/v0.60.0-preview.0

## What's Changed
* fix(core): improve destination validation and connection routing in web fetch utilities by @diegogodinezr in https://github.com/google-gemini/gemini-cli/pull/29120
* fix(core): enforce RFC 9207 issuer identification in MCP OAuth flow by @jvargassanchez-dot in https://github.com/google-gemini/gemini-cli/pull/29117
* chore(release): bump version to 0.60.0-nightly.20260901.g0bd1d4397 by @gemini-cli-robot in https://github.com/google-gemini/gemini-cli/pull/29162
* Changelog for v0.58.0 by @gemini-cli-robot in https://github.com/google-gemini/gemini-cli/pull/29161
* fix(cli): isolate temporary directory for macOS Seatbelt sandbox by @jvargassanchez-dot in https://github.com/google-gemini/gemini-cli/pull/29171
* feat(extensions): harden path resolution and boundary validation in extension loader by @diegogodinezr in https://github.com/google-gemini/gemini-cli/pull/29169
* Changelog for v0.59.0-preview.0 by @gemini-cli-robot in https://github.com/google-gemini/gemini-cli/pull/29159
* fix(core): sanitize and remove hardcoded Google CrUX API key in chrome-devtools-mcp by @amelidev in https://github.com/google-gemini/gemini-cli/pull/29158
* fix(extensions): prompt for consent on environment changes and sanitize runtime-altering environment variables by @amelidev in https://github.com/google-gemini/gemini-cli/pull/28863
* fix(core): enhance workspace path boundary checks and symlink resolution in command safety and file discovery by @jesussamuel-byte in https://github.com/google-gemini/gemini-cli/pull/29170
* fix(config): enforce strict permission and ownership checks on system-wide configuration paths by @jesussamuel-byte

caught by the 20-minute sweep · the live wire · all receipts

THE WIRE RECEIPTS ACCESS @VEDOLOS TERMS PRIVACY break the story before it breaks