Gemini CLI v0.61.0 adds Gemini 3.8 Flash and guards build files

33 minutes ago

@gemini-cliSubscribe

Ask

Ask about this presentation

Answers are generated from this presentation.

Chapters

  1. 0:00Gemini CLI v0.61.0
  2. 0:1401: The new Flash models
  3. 0:16Gemini API keys, Vertex AI and gateways get Gemini 3.8 Flash right away
  4. 0:28The flash alias now resolves to Gemini 3.8 Flash
  5. 0:39The fallback model moves up from 2.5 Flash to 3.5 Flash
  6. 0:54Two model-config conditions have new names
  7. 1:0602: Pinning a model
  8. 1:08--model gemini-3.8-flash now reaches the API as written
  9. 1:2003: Build files and outside content
  10. 1:23Editing a build file always asks you first
  11. 1:37After a build file changes, the next build or test command asks too
  12. 1:48Flags copied from outside content trigger a critical warning
  13. 2:0104: The sandbox
  14. 2:02The sandbox refuses to start from your home folder
  15. 2:14Containers get a cleaned copy of your settings
  16. 2:26macOS Seatbelt blocks your credential files
  17. 2:36Seatbelt sessions keep their history in ~/.cache/.gemini
  18. 2:47Your own commands load in untrusted workspaces
  19. 2:58Install it from npm
Show transcript

Gemini CLI v0.61.0

Gemini CLI

Gemini CLI v0.61.0 adds Gemini 3.8 Flash

Plus Gemini 3.5 Flash Lite, guarded build files, and a tighter sandbox.

Gemini CLI running in a terminal
github.com/google-gemini/gemini-cli, release v0.61.0

Gemini CLI now supports Gemini 3.8 Flash as its newest Flash model. Gemini 3.5 Flash Lite joins it, and Gemini 3.5 Flash and 3.1 Flash Lite become the base tier.

01: The new Flash models

> the new flash models2026-09-23
01
The new Flash models

The new Flash models.

Gemini API keys, Vertex AI and gateways get Gemini 3.8 Flash right away

> the new Flash models2026-09-23
USE_GEMINI · USE_VERTEX_AI · GATEWAY → available on upgrade LOGIN_WITH_GOOGLE → waits for the rollout flag
packages/core/src/config/config.ts

With a Gemini API key, Vertex AI, or a gateway, both new models are available as soon as you upgrade. With Login with Google, they arrive when the rollout flag switches on for you.

The flash alias now resolves to Gemini 3.8 Flash

> the new Flash models2026-09-23
flash  →  gemini-3.8-flash flash-lite  →  gemini-3.5-flash-lite
docs/reference/configuration.md

The short model names follow them. Once you have access, asking for flash gets you Gemini 3.8 Flash, and asking for flash lite gets you Gemini 3.5 Flash Lite.

The fallback model moves up from 2.5 Flash to 3.5 Flash

> the new Flash models2026-09-23
gemini-2.5-flash gemini-3.5-flash flash without preview access · last-resort retry
docs/reference/configuration.md

When Gemini CLI falls back to an older model, it now lands on Gemini 3.5 Flash instead of 2.5 Flash. That covers the flash alias without preview access, and the last resort after retries.

Two model-config conditions have new names

> the new Flash models2026-09-23
useGemini3_5Flash  →  useLatestFlash useGemini3_1FlashLite  →  useLatestFlashLite old names still accepted, deprecated
packages/cli/src/config/settingsSchema.ts

If you write your own model configs, useGemini3_5Flash is now useLatestFlash, and the Flash Lite condition is renamed to match. The old names still work as deprecated aliases.

02: Pinning a model

> pinning a model2026-09-23
02
Pinning a model

Pinning a model.

--model gemini-3.8-flash now reaches the API as written

> pinning a model2026-09-23
explicit versioned Flash ID → rollout default explicit versioned Flash ID → sent unchanged
packages/core/src/config/models.ts

Pin a versioned Flash model with the model flag, and that exact ID now goes out with the request. Before, Gemini CLI quietly swapped it for the Gemini 3.5 Flash rollout default.

03: Build files and outside content

> build files and outside content2026-09-23
03
Build files and outside content

Build files and outside content.

Editing a build file always asks you first

> build files and outside content2026-09-23
package.json · Makefile · build.gradle interactive → ask, with a security warning non-interactive → deny
packages/core/src/policy/policy-engine.ts

When the agent edits a build file, such as package.json, a Makefile, or build dot gradle, Gemini CLI now always stops to ask, with a security warning. In a non-interactive run, the edit is denied.

After a build file changes, the next build or test command asks too

> build files and outside content2026-09-23
npm · make · cargo · bazel · pytest Allow for this session Allow once
packages/core/src/tools/shell.ts

Once a build file has changed in a session, the next build or test command, like npm, make, or cargo, asks before it runs. Allow for this session is no longer offered for it.

Flags copied from outside content trigger a critical warning

> build files and outside content2026-09-23
web fetch · MCP server responses · Google Docs blaze test //foo --test_arg=malicious_flag flags listed, approval required
packages/core/src/utils/untrustedContextTracker.ts

If a command's flags came from outside content, like a fetched web page, an MCP server response, or a Google Doc, Gemini CLI lists those flags in a critical warning and waits for your approval.

04: The sandbox

> the sandbox2026-09-23
04
The sandbox

The sandbox.

The sandbox refuses to start from your home folder

> the sandbox2026-09-23
~   /   ~/.gemini start and mount from a project folder
packages/cli/src/utils/sandboxUtils.ts

Start a sandboxed session from the root of your home folder, from the filesystem root, or from the dot gemini folder, and it now refuses. Those folders can't be mounted into a container either.

Containers get a cleaned copy of your settings

> the sandbox2026-09-23
hooks custom tool commands API keys /home/node/.gemini ← sanitized settings.json
packages/cli/src/utils/sandbox.ts

Docker and Podman sandboxes now get a sanitized copy of your settings file, with hooks, custom tool commands, and API keys stripped out. Your real settings folder stays on the host.

macOS Seatbelt blocks your credential files

> the sandbox2026-09-23
deny file-read* file-write* oauth_creds.json · google_accounts.json trusted_hooks.json · .env
packages/cli/src/utils/sandbox-macos-permissive-open.sb

On macOS, the Seatbelt profiles now deny reading and writing your OAuth credentials, your Google accounts file, your trusted hooks, and any dot env file.

Seatbelt sessions keep their history in ~/.cache/.gemini

> the sandbox2026-09-23
~/.gemini   write denied under Seatbelt ~/.cache/.gemini   history · session state
packages/core/src/config/storage.ts

Seatbelt now blocks writes to the dot gemini folder, so a sandboxed session keeps its history in a dot gemini folder under dot cache, and it still carries over between runs.

Your own commands load in untrusted workspaces

> the sandbox2026-09-23
~/.gemini/commands   always loaded workspace and extension commands   still need folder trust
packages/cli/src/services/FileCommandLoader.ts

Your personal commands in the dot gemini commands folder now load even in an untrusted workspace. Commands from the workspace and from extensions still depend on folder trust.

Install it from npm

> upgrade2026-09-23
npm install -g @google/gemini-cli@0.61.0
packages/cli/package.json

To upgrade, install the Gemini CLI package globally from npm, pinned to this release.