Skip to content

Conversation

@FIoannides
Copy link
Collaborator

Enable gemini cli workflows

@github-actions
Copy link

🤖 Hi @FIoannides, I've received your request, and I'm working on it now! You can track my progress in the logs for more details.

Copy link
Member

@scaliby scaliby left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Have you reviewed this against https://securitylab.github.com/resources/github-actions-preventing-pwn-requests/ and other chapters of this guide? I see huge surface for vulnerabilities in that change.

@scaliby scaliby changed the base branch from develop to main October 28, 2025 10:01
@FIoannides
Copy link
Collaborator Author

Have you reviewed this against https://securitylab.github.com/resources/github-actions-preventing-pwn-requests/ and other chapters of this guide? I see huge surface for vulnerabilities in that change.

This is not from an untrusted source, they are provided directly by the installation process of Gemini CLI GitHub action https://github.com/marketplace/actions/run-gemini-cli#3-update-your-gitignore, which I believe we can trust.

I have also asked Gemini to do an analysis if there could be a potential issue here, but seems to consider everything being safe and the evaluation seems reasonable to me, http://screen/7HndCzXGAGqwJbV

@FIoannides FIoannides requested a review from scaliby October 31, 2025 13:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants