Repository navigation
Conversation
|
📊 PR Size: size/S
|
🛑 Action Required: Evaluation ApprovalSteering changes have been detected in this PR. To prevent regressions, a maintainer must approve the evaluation run before this PR can be merged. Maintainers:
Once approved, the evaluation results will be posted here automatically. |
Summary of ChangesHello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request focuses on maintaining the security posture of the project by upgrading the Node.js runtime environment to version 22 across all Docker-based services. Additionally, it improves the robustness of the web-fetch tool by migrating host validation to an asynchronous pattern and strengthening the filtering of private and loopback IP addresses. Highlights
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here. Footnotes
|
There was a problem hiding this comment.
Code Review
This pull request updates the Node.js runtime version from 20 to 22 across several Dockerfiles. Additionally, it refactors the private IP checking logic in WebFetchTool to be asynchronous by utilizing isPrivateIpAsync instead of isPrivateIp, and fixes a bug in isPrivateIpAsync where loopback hosts were incorrectly allowed. The review feedback correctly identifies a performance bottleneck in filterAndValidateUrls where asynchronous DNS lookups are executed sequentially in a loop, and suggests parallelizing these checks using Promise.all to avoid blocking the agent loop.
| private async filterAndValidateUrls(urls: string[]): Promise<{ | ||
| toFetch: string[]; | ||
| skipped: string[]; | ||
| } { | ||
| }> { | ||
| const uniqueUrls = [...new Set(urls.map(normalizeUrl))]; | ||
| const toFetch: string[] = []; | ||
| const skipped: string[] = []; | ||
|
|
||
| for (const url of uniqueUrls) { | ||
| if (this.isBlockedHost(url)) { | ||
| if (await this.isBlockedHost(url)) { | ||
| debugLogger.warn( | ||
| `[WebFetchTool] Skipped private or local host: ${url}`, | ||
| ); |
There was a problem hiding this comment.
Performance Bottleneck: Sequential DNS Lookups in Loop
The filterAndValidateUrls method performs sequential await this.isBlockedHost(url) calls inside a for loop. Since isBlockedHost performs an asynchronous DNS lookup via isPrivateIpAsync, checking multiple URLs (up to 20) sequentially will introduce significant latency overhead, blocking the agent loop.
We should resolve these checks in parallel using Promise.all to optimize performance.
private async filterAndValidateUrls(urls: string[]): Promise<{
toFetch: string[];
skipped: string[];
}> {
const uniqueUrls = [...new Set(urls.map(normalizeUrl))];
const toFetch: string[] = [];
const skipped: string[] = [];
const blockChecks = await Promise.all(
uniqueUrls.map(async (url) => ({
url,
isBlocked: await this.isBlockedHost(url),
}))
);
for (const { url, isBlocked } of blockChecks) {
if (isBlocked) {
debugLogger.warn(1886a67 to
3ac5159
Compare
|
Hi there! Thank you for your interest in contributing to Gemini CLI. To ensure we maintain high code quality and focus on our prioritized roadmap, we only guarantee review and consideration of pull requests for issues that are explicitly labeled as 'help wanted'. This PR will be closed in 7 days if it remains without that designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding. |
|
This pull request is being closed as it has been open for 14 days without a 'help wanted' designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding. |
Fixes #28584
Description
This PR updates the Sandbox
Dockerfileand all othertools/caretaker-agent/cloudrun/*/Dockerfileinstances fromnode:20-slimtonode:22-slim.Node 20 is reaching EOL and is no longer receiving security fixes (e.g. recent CVEs are only patched in Node 22/24/26). Upgrading to Node 22 ensures the sandbox runtime boundary remains secure with supported Node.js versions.
This re-aligns the Dockerfiles with the intent introduced in PR #1038 (which originally moved to Node 22).
Changes made
Dockerfilebuilder and runtime stages tonode:22-slimtools/caretaker-agent/cloudrun/egress-service/Dockerfiletonode:22-slimtools/caretaker-agent/cloudrun/ingestion-service/Dockerfiletonode:22-slimtools/caretaker-agent/cloudrun/pr-generator/Dockerfilereferences tonode:22-slim