Gemini CLI hardens sandbox: read-only config mounts, tmpfs runtime state, and secrets stripping

diegogodinezr · ghdev · 2026-09-11

A PR in google-gemini/gemini-cli (#29283) strengthens filesystem isolation for --sandbox runs under Docker, Podman, runsc, LXC, and macOS Seatbelt.

Original post →

More from coding & agent

coding & agent channel →