Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: google-github-actions/run-gemini-cli
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v0.1.21
Choose a base ref
...
head repository: google-github-actions/run-gemini-cli
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v0
Choose a head ref
  • 12 commits
  • 37 files changed
  • 7 contributors

Commits on Mar 2, 2026

  1. feat: expand eval dataset with edge and complex cases and refine prom…

    …pts (#458)
    
    This PR continues the work on issue #219 by expanding the evaluation
    datasets and refining the workflow prompts.
    
    ### 📊 Evaluation Results (Post-Tuning)
    
    | Workflow | Previous Pass Rate | **Current Pass Rate** | Improvement |
    | :--- | :--- | :--- | :--- |
    | **Issue Triage** | 75% | **100% (20/20)** | +25% |
    | **Issue Fixer** | ~73% | **100% (Confirmed Validation)** | Improved
    Guardrails | | **PR Review** | 100% | **100% (10/10)** | Stable | |
    **Assistant** | - | **100% (2/2)** | Initial Baseline |
    ### Changes:
    **Expanded Evaluation Datasets**: Added 30+ edge, complex, and real-life
    cases across triage, fixer, and pr-review.
    
    **Prompt Refinements**:
    
    - **Issue Triage**: Improved robustness against spam and ambiguous
    reports. Now correctly handles "It broke" (bug) vs "Help" (ignore).
    - **Issue Fixer**: Added a validation step (Step 1.5) to proactively
    identify impossible or out-of-scope requests (e.g., IE6 support).
    - **Mock Infrastructure**: Updated the mock MCP server to provide
    realistic data for new evaluation scenarios (race conditions,
    architectural violations, security risks).
    
    **Verification**: All evaluations have been verified to pass.
    
    ---------
    
    Signed-off-by: Coco Sheng <[email protected]>
    cocosheng-g authored Mar 2, 2026
    Configuration menu
    Copy the full SHA
    f4d3932 View commit details
    Browse the repository at this point in the history

Commits on Mar 5, 2026

  1. chore: parallelize nightly evaluations and fix suite timeouts (#472)

    This PR overhauls the nightly evaluations suite to run significantly
    faster and eliminates several sources of non-deterministic timeouts and
    endless loops.
    
    ### 🚀 Enhancements
    * **Parallel Execution**: Refactored `evals-nightly.yml` to dynamically
    generate a matrix of all `.eval.ts` files and run them concurrently,
    drastically reducing the total suite execution time.
    * **Aggregated Reporting**: Enhanced `scripts/aggregate_evals.ts` to
    collect artifacts from parallel jobs and output a unified, structured
    Markdown table with pass rates, latencies, and detailed collapsible
    failure logs.
    
    ### 🛠️ Stability & Bug Fixes
    * **Issue Fixer Search Loops**: Scaffolded missing mock source files
    (e.g., `src/index.js`), a `package.json` with a valid `test` script, and
    a mock `gh` CLI executable in the `TestRig`. This prevents the agent
    from infinitely searching for non-existent files or trying to repair a
    broken mock testing environment.
    * **Assistant Polling Loops**: Injected the mock MCP server into
    `gemini-assistant.eval.ts` so it can successfully execute
    `add_issue_comment`. Updated the system prompt to explicitly instruct
    the agent to exit immediately after posting its plan, rather than
    infinitely polling the issue for an `@gemini-cli /approve` comment. Also
    explicitly defined the typo in `fix-typo` to stop the agent from
    hopelessly guessing.
    * **JSON Quoting Flakes**: Updated `gemini-scheduled-triage.toml` to
    output its JSON array to `$GITHUB_ENV` using a heredoc (`cat << 'EOF'`)
    instead of `echo '...'`. This prevents bash syntax errors when the
    model's generated text naturally contains single quotes.
    * **Global Timeout Boundaries**: Increased the `TestRig` hard-kill
    timeout from 3 to 10 minutes to safely accommodate complex, high-turn
    fixes (e.g., `fix-flaky-test`).
    * **Security Warnings**: Added a top-level `permissions: contents: read`
    block to the nightly workflow to resolve CodeQL linting warnings.
    
    Successful run:
    https://github.com/google-github-actions/run-gemini-cli/actions/runs/22689405186
    cocosheng-g authored Mar 5, 2026
    Configuration menu
    Copy the full SHA
    52c365d View commit details
    Browse the repository at this point in the history

Commits on Mar 9, 2026

  1. docs: update an authentication documentation link (#445)

    ## Summary
    
    Update Gemini CLI authentication documentation links to the new
    get-started path.
    
    Documentation:
    - Refresh README references to Gemini CLI authentication docs to point
    to the updated get-started URL.
    
    Chores:
    - Align action input descriptions with the new Gemini CLI authentication
    documentation URL.
    
    | Before | After |
    |--------|--------|
    | <img width="818" height="383" alt="before" src="/web-api/iframe-proxy?url=https://github.comhttps://github.com/user-attachments/assets/3702e4ca-e7c7-4eae-92b6-e87f7ae943cc"
    /> | <img width="1533" height="614" alt="after" src="/web-api/iframe-proxy?url=https://github.comhttps://github.com/user-attachments/assets/c9bccadb-85ff-4cff-933e-2072ccbfa8fa"
    /> |
    Marukome0743 authored Mar 9, 2026
    Configuration menu
    Copy the full SHA
    c836b8d View commit details
    Browse the repository at this point in the history
  2. Fix summary Markdown formatting (#474)

    Title (##) is not rendered correctly if it's just after `<SUMMARY>` tag
    
    <!--
    Thank you for proposing a pull request! Please note that SOME TESTS WILL
    LIKELY FAIL due to how GitHub exposes secrets in Pull Requests from
    forks.
    Someone from the team will review your Pull Request and respond.
    
    Please describe your change and any implementation details below.
    -->
    
    <img width="675" height="370" alt="image" src="/web-api/iframe-proxy?url=https://github.comhttps://github.com/user-attachments/assets/e33775b2-2c6d-4b26-a5f8-4493e42fd58c"
    />
    
    If we add a new line between:
    
    <img width="699" height="474" alt="image" src="/web-api/iframe-proxy?url=https://github.comhttps://github.com/user-attachments/assets/931524cd-6d8f-4e33-a857-75befc565553"
    />
    
    Signed-off-by: Kevin Robatel <[email protected]>
    Kevinrob authored Mar 9, 2026
    Configuration menu
    Copy the full SHA
    f34369a View commit details
    Browse the repository at this point in the history

Commits on Mar 10, 2026

  1. fix: typo workflow_name on gemini-plan-execute (#476)

    ## Summary
    
    Enhancements:
    - Align the workflow_name metadata in the Gemini plan-execute GitHub
    workflow and example with the actual workflow file name.
    
    Follow up #465
    Marukome0743 authored Mar 10, 2026
    Configuration menu
    Copy the full SHA
    e342208 View commit details
    Browse the repository at this point in the history

Commits on Mar 11, 2026

  1. Feat: integrate code review extension in PR workflow instead of using…

    … customized review prompt (#471)
    
    ## Overview
    
    This PR integrates code review extension
    (https://github.com/gemini-cli-extensions/code-review) in the PR
    workflow.
    
    fixes #468 
    
    ## Changes
    
    - Update gemini-review.yml to install code-review extension and prompt
    to point to code-review instructions
    - Update PR workflow readme
    - Update related eval tests
    
    ## Next step
    
    - Cleanup e.g. SetupGithubCommands, generate_examples.sh, gemini-review
    prompts
    
    ---------
    
    Signed-off-by: cynthialong0-0 <[email protected]>
    cynthialong0-0 authored Mar 11, 2026
    Configuration menu
    Copy the full SHA
    d87bfa2 View commit details
    Browse the repository at this point in the history
  2. feat: add GitHub Action usage metrics for telemetry (#475)

    ## Description
    
    This PR implements the necessary infrastructure in the
    \`run-gemini-cli\` GitHub Action to support the Gemini CLI usage metrics
    (P0 requirements).
    
    It aligns with the core CLI telemetry changes introduced in
    [google-gemini/gemini-cli#21129](google-gemini/gemini-cli#21129).
    
    ### Changes Made:
    * **Strongly-Typed Telemetry Tracking:** Replaced the generic
    \`github_item_number\` with three specific inputs: \`github_pr_number\`,
    \`github_issue_number\`, and \`github_custom_tracking_id\`. This ensures
    that Pull Requests, Issues, and custom batch IDs are logged to distinct
    fields, providing maximum accuracy for downstream analytics without
    overlapping ID spaces.
    * **Installation Telemetry:** Added \`GH_WORKFLOW_NAME\`,
    \`GH_PR_NUMBER\`, \`GH_ISSUE_NUMBER\`, and \`GH_CUSTOM_TRACKING_ID\` to
    the \`Install Gemini CLI\` step to ensure extension installations are
    properly tracked.
    * **OTEL Collector Enhancement:** Updated the
    \`scripts/collector-gcp.yaml.template\` to include specific resource
    attributes for \`github.pr.number\`, \`github.issue.number\`, and
    \`github.custom_tracking.id\`.
    * **Example Workflow Updates:** Updated all example workflows (Review,
    Triage, Assistant, Scheduled Triage) to explicitly pass the correct IDs
    to the action, improving clarity and ensuring accurate telemetry.
    
    ### Example Telemetry Scenarios
    
    Because the CLI appends these context fields to the \`baseMetadata\` of
    all events (API Request, Response, Error), downstream analytics can
    perfectly distinguish and count unique issues vs. PRs based on the
    specific fields.
    
    #### Scenario A: Automated PR Review
    When PR 42 triggers the \`gemini-review\` workflow, the CLI logs:
    ```json
    {
      \"event_name\": \"api_request\",
      \"event_metadata\": [
        [
          { \"gemini_cli_key\": 130, \"value\": \"gemini-review\" },
          { \"gemini_cli_key\": 172, \"value\": \"pull_request\" },
          { \"gemini_cli_key\": 173, \"value\": \"42\" } // GH_PR_NUMBER
        ]
      ]
    }
    ```
    *Analysts can count \`DISTINCT gh_pr_number WHERE gh_workflow_name LIKE
    '%review%'\` to satisfy the P0 PR metric.*
    
    #### Scenario B: Automated Issue Triage
    When Issue 88 triggers the \`gemini-triage\` workflow, the CLI logs:
    ```json
    {
      \"event_name\": \"api_request\",
      \"event_metadata\": [
        [
          { \"gemini_cli_key\": 130, \"value\": \"gemini-triage\" },
          { \"gemini_cli_key\": 172, \"value\": \"issues\" },
          { \"gemini_cli_key\": 174, \"value\": \"88\" } // GH_ISSUE_NUMBER
        ]
      ]
    }
    ```
    *Analysts can count \`DISTINCT gh_issue_number WHERE gh_workflow_name
    LIKE '%triage%' AND gh_event_name = 'issues'\` to satisfy the P0
    Automated Issue metric.*
    
    #### Scenario C: Scheduled Batch Triage
    When a cron job runs and triages 3 issues (IDs 101, 102, 103) in a
    single CLI invocation, the CLI logs:
    ```json
    {
      \"event_name\": \"api_request\",
      \"event_metadata\": [
        [
          { \"gemini_cli_key\": 130, \"value\": \"gemini-scheduled-triage\" },
          { \"gemini_cli_key\": 172, \"value\": \"schedule\" },
          { \"gemini_cli_key\": 175, \"value\": \"101,102,103\" } // GH_CUSTOM_TRACKING_ID
        ]
      ]
    }
    ```
    *Analysts can split the \`gh_custom_tracking_id\` string by commas to
    count exactly 3 unique issues processed during a scheduled invocation.*
    
    ## Related Issues
    * Fixes P0 metrics requirements for GitHub Action usage.
    * Depends on
    [google-gemini/gemini-cli#21129](google-gemini/gemini-cli#21129)
    cocosheng-g authored Mar 11, 2026
    Configuration menu
    Copy the full SHA
    b0c9501 View commit details
    Browse the repository at this point in the history

Commits on Mar 19, 2026

  1. fix: remove unused service and redundant IAM bindings in workload ide…

    …ntity setup script (#481)
    
    The original fix for
    #444 dated
    in January is incomplete.
    
    This change removes an unused Google internal service
    `cloudcode-pa.googleapis.com` for users in the setup script for Workload
    Identity Federation.
    
    It also removes redundant IAM bindings on the Workload Identity Pool's
    principal in Step 4. These IAM bindings are added in Step 5 on a
    connected service account to the Workload Identity Pool, different from
    its principal. GitHub Actions "impersonates" this connected service
    account, which has access to Google Cloud resources and services.
    
    Lastly, it updates the description to correctly reflect the content of
    the shell script.
    
    I have published this
    [codelab](https://codelabs.developers.google.com/gemini-cli/gemini-cli-security-review#0)
    that teaches about this setup.
    
    Signed-off-by: Tianzi Cai <[email protected]>
    anguillanneuf authored Mar 19, 2026
    Configuration menu
    Copy the full SHA
    642deeb View commit details
    Browse the repository at this point in the history

Commits on Apr 1, 2026

  1. Fix: Add workflow name to telemetry resource attributes (#493)

    This PR adds the workflow name to the OpenTelemetry resource attributes
    in the collector configuration. This fixes the issue where
    GEMINI_CLI_WORKFLOW_NAME is null in metric events for customer-triggered
    runs. Closes #492
    cocosheng-g authored Apr 1, 2026
    Configuration menu
    Copy the full SHA
    41f4f29 View commit details
    Browse the repository at this point in the history
  2. fix(evals): stabilize nightly evaluation suite (#494)

    ## Description
    
    This PR stabilizes the nightly evaluation suite by resolving several
    persistent failures, timeouts, and environment issues across different
    evaluation scripts. All tests are now passing 100%.
    
    Closes #491
    
    ## Summary of Fixes
    
    ### gemini-plan-execute
    - **Dataset Cleanup**: Removed the `"plan with approval"` testcase from
    `evals/data/gemini-plan-execute.json` as it was consistently failing due
    to timeout and was redundant.
    
    ### gemini-scheduled-triage
    - Fixed `ReferenceError: stdout is not defined` in
    `gemini-scheduled-triage.eval.ts` by properly capturing command output.
    - Loosened environment file parsing logic to accept both key-value pairs
    and raw JSON arrays, and made it safer by searching line-by-line for
    `TRIAGED_ISSUES=`.
    
    ### issue-fixer
    - Handled the `mcp_github_` prefix in expected tool calls to match the
    actual output of the CLI.
    - Added a prompt hint for `fix-flaky-test` in `issue-fixer.eval.ts` to
    guide the model to the `test/` directory, preventing exhaustive searches
    and timeouts.
    - Updated test data for `migrate-deprecated-api` in `issue-fixer.json`
    to be more specific, mentioning `scripts/deploy.js` to avoid exhaustive
    searching.
    - Added realistic content to `test/UserProfile.test.js` to prevent the
    model from failing on `replace` tool calls and timing out.
    - **Investigation**: Tests for `security-vulnerability` and
    `cross-file-refactor` timed out in CI but passed locally, suggesting CI
    environment performance or specific flakiness (e.g., `pgrep` failure).
    
    ### pr-review
    - Resolved `Connection closed` errors by replacing the heavy `tsx` based
    mock MCP server with a pure JavaScript version (`mock-mcp-server.mjs`).
    - Expanded the allowed tools list to include `activate_skill` and
    `list_directory`.
    - Implemented proper folder-based mocking for skill activation by
    creating a dummy skill file.
    - Expanded expected findings for `empty-diff` to include synonyms like
    "no modifications" and "empty".
    - Expanded expected findings for `architectural-violation` to include
    synonyms like "layering" and "violates" to prevent false negatives.
    - Made the findings assertion conditional in `pr-review.eval.ts` to
    handle cases where valid reviews might not contain specific keywords.
    - Made the prompt replacement in `pr-review.eval.ts` more robust by
    checking if the string exists before replacing.
    
    ### issue-triage
    - Reinforced the prompt in `.github/commands/gemini-triage.toml` for
    Step 4 to state that the model **MUST EXECUTE** the command to save
    labels, resolving failures where it only outputted the command text.
    
    ## Verification
    
    All tests have been verified to pass locally. Some timeouts persist in
    CI likely due to environment constraints.
    cocosheng-g authored Apr 1, 2026
    Configuration menu
    Copy the full SHA
    921e068 View commit details
    Browse the repository at this point in the history

Commits on Apr 23, 2026

  1. create trust guidance docs (#501)

    Add trust guidance documentation.
    emilyhedlund authored Apr 23, 2026
    Configuration menu
    Copy the full SHA
    d7a38ec View commit details
    Browse the repository at this point in the history

Commits on Apr 24, 2026

  1. Release: v0.1.22 (#502)

    ## What's Changed
    * feat: expand eval dataset with edge and complex cases and refine
    prompts by @cocosheng-g in
    #458
    * chore: parallelize nightly evaluations and fix suite timeouts by
    @cocosheng-g in
    #472
    * docs: update an authentication documentation link by @Marukome0743 in
    #445
    * Fix summary Markdown formatting by @Kevinrob in
    #474
    * fix: typo workflow_name on gemini-plan-execute by @Marukome0743 in
    #476
    * Feat: integrate code review extension in PR workflow instead of using
    customized review prompt by @cynthialong0-0 in
    #471
    * feat: add GitHub Action usage metrics for telemetry by @cocosheng-g in
    #475
    * fix: remove unused service and redundant IAM bindings in workload
    identity setup script by @anguillanneuf in
    #481
    * Fix: Add workflow name to telemetry resource attributes by
    @cocosheng-g in
    #493
    * fix(evals): stabilize nightly evaluation suite by @cocosheng-g in
    #494
    * create trust guidance docs by @ehedlund in
    #501
    
    ## New Contributors
    * @Kevinrob made their first contribution in
    #474
    * @anguillanneuf made their first contribution in
    #481
    * @ehedlund made their first contribution in
    #501
    
    **Full Changelog**:
    v0.1.21...v0.1.22
    google-github-actions-bot authored Apr 24, 2026
    Configuration menu
    Copy the full SHA
    f77273f View commit details
    Browse the repository at this point in the history
Loading