-
Notifications
You must be signed in to change notification settings - Fork 10.5k
fix(patch): cherry-pick edbe548 to release/v0.20.1-pr-15007 [CONFLICTS] #15016
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(patch): cherry-pick edbe548 to release/v0.20.1-pr-15007 [CONFLICTS] #15016
Conversation
Summary of ChangesHello @gemini-cli-robot, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request facilitates an automated patch release by attempting to cherry-pick a specific commit into the stable branch. However, due to detected merge conflicts, manual intervention is necessary to integrate the changes, which primarily involve adjusting a policy for subagent invocation, before the new patch version can be released. Highlights
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here. You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension. Footnotes
|
|
Size Change: -2 B (0%) Total Size: 21.5 MB ℹ️ View Unchanged
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Code Review
This pull request includes a file with unresolved merge conflict markers in packages/core/src/policy/policies/read-only.toml, which must be resolved as it will cause application failures. Additionally, a security audit identified two high-severity vulnerabilities: a Broken Access Control issue in the policy engine's wildcard tool matching, potentially allowing tool impersonation, and a Stored Cross-Site Scripting (XSS) vulnerability due to unsanitized output from a subagent. Addressing these findings is crucial before merging.
| <<<<<<< HEAD | ||
| ======= | ||
|
|
||
| [[rule]] | ||
| toolName = "SubagentInvocation" | ||
| decision = "allow" | ||
| priority = 50 | ||
| >>>>>>> edbe5480c (fix: temp fix for subagent invocation until subagent delegation is merged to stable (#15007)) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This file contains unresolved merge conflict markers (<<<<<<<, =======, >>>>>>>). These markers make the TOML file invalid and will cause parsing failures at runtime. Please resolve the conflict by removing the markers and keeping the intended changes.
[[rule]]
toolName = "SubagentInvocation"
decision = "allow"
priority = 50
3e02e48 to
5df6379
Compare
This PR automatically cherry-picks commit edbe548 to patch version v0.20.1 in the stable release to create version 0.20.2.
This cherry-pick resulted in merge conflicts that need manual resolution.
🔧 Next Steps:
📋 Files with conflicts:
The commit has been created with conflict markers for easier manual resolution.
🚨 Important: