Gemini CLI 0.61.0 asks before editing build files
Gemini CLI 0.61.0 (Sept 24) now requires confirmation before editing recognized build files (package.json, Makefile, pyproject.toml, Bazel BUILD), before later build/test commands after those edits, and before shell commands whose args match untrusted web/MCP content—with no “always allow.” The same release stops mounting ~/.gemini into the sandbox and strips API keys and hooks from the in-sandbox settings copy.