Skip to content

fix(core): externalize https-proxy-agent to fix proxy support - #26361

Merged
scidomino merged 4 commits into
google-gemini:mainfrom
sotokisehiro:main
May 14, 2026
Merged

fix(core): externalize https-proxy-agent to fix proxy support#26361
scidomino merged 4 commits into
google-gemini:mainfrom
sotokisehiro:main

Conversation

@sotokisehiro

@sotokisehiro sotokisehiro commented May 2, 2026

Copy link
Copy Markdown
Contributor

fix(core): inject proxy agent statically to fix Vertex AI proxy support

Summary

Fix TypeError: HttpsProxyAgent is not a constructor that occurs when calling Vertex AI / Gemini API through an HTTP/HTTPS proxy (HTTPS_PROXY / HTTP_PROXY). The bug is a P1 blocker for proxy users — particularly enterprise Vertex AI users.

This PR is a follow-up to the original review feedback by @scidomino: instead of externalizing the proxy package from the esbuild bundle, we statically import HttpsProxyAgent / HttpProxyAgent and inject the pre-instantiated agent into GoogleGenAI's underlying transporter.

Root cause

esbuild's splitting: true + format: 'esm' causes CJS packages resolved via dynamic import() to lose named exports. gaxios@7.x (used by google-auth-library@google/genai) dynamically imports https-proxy-agent:

this.#proxyAgent ||= (await import('https-proxy-agent')).HttpsProxyAgent;

esbuild generates an ESM chunk with only a default export, so .HttpsProxyAgent resolves to undefined, and new this.#proxyAgent(...) throws.

Fix

Statically import both proxy agents in packages/core/src/core/contentGenerator.ts and pre-instantiate the agent before constructing GoogleGenAI. The agent is injected via googleAuthOptions.clientOptions.transporterOptions.agent, which causes gaxios to skip its dynamic import path entirely (gaxios checks opts.agent and uses it if present, falling through to dynamic import only when absent).

import { HttpProxyAgent } from 'http-proxy-agent';
import { HttpsProxyAgent } from 'https-proxy-agent';

// inside createContentGenerator (GoogleGenAI branch):
const proxyUrl = config.proxy?.trim();
const proxyAgent = proxyUrl
  ? baseUrl?.startsWith('http://')
    ? new HttpProxyAgent(proxyUrl)
    : new HttpsProxyAgent(proxyUrl)
  : undefined;

const googleGenAI = new GoogleGenAI({
  apiKey,
  vertexai,
  httpOptions,
  ...(proxyAgent && {
    googleAuthOptions: {
      clientOptions: {
        transporterOptions: { agent: proxyAgent },
      },
    },
  }),
});

Agent selection is based on the destination URL (baseUrl), not the proxy URL — HttpsProxyAgent is required for HTTPS destinations (which both Gemini API and Vertex AI use by default), regardless of the proxy's own scheme.

Changed files

File Change
packages/core/src/core/contentGenerator.ts Static imports + agent construction + injection via googleAuthOptions
packages/core/src/core/contentGenerator.test.ts 5 new test cases covering https/http proxy URL, http baseUrl, whitespace trimming, and no-proxy case
packages/core/package.json Add http-proxy-agent: ^7.0.2 (was already a transitive dep; making it explicit)
package.json Add http-proxy-agent and https-proxy-agent to root dependencies for consistency
package-lock.json Regenerated

No esbuild or bundle script changes are needed with this approach — by avoiding the dynamic import path entirely, we don't need to externalize anything from the bundle.

Related issues

How to validate

  1. Build:
    npm run bundle
  2. Verify under proxy (should succeed without TypeError):
    HTTPS_PROXY=http://<your-proxy>:<port> npm start -- --prompt "hello"
  3. Verify without proxy (regression check):
    npm start -- --prompt "hello"
  4. Run unit tests for the proxy injection:
    cd packages/core && npx vitest run src/core/contentGenerator.test.ts
    Expected: all 39 tests pass (5 new + 34 existing).

Pre-Merge Checklist

  • Updated relevant documentation and README (N/A — internal implementation only)
  • Added/updated tests (5 new unit tests in contentGenerator.test.ts)
  • Noted breaking changes (none)
  • Validated on required platforms/methods:
    • MacOS
      • npm run
      • npx
      • Docker
      • Podman
      • Seatbelt
    • Windows
      • npm run
      • npx
      • Docker
    • Linux
      • npm run
      • npx
      • Docker

This PR unblocks all users who are currently unable to access Vertex AI due to proxy issues.

@sotokisehiro
sotokisehiro requested review from a team as code owners May 2, 2026 03:01
@google-cla

google-cla Bot commented May 2, 2026

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request addresses a critical issue where proxy support fails due to how esbuild handles dynamic imports of CommonJS modules in an ESM bundle. By externalizing the proxy agent and ensuring its dependencies are included in the final distribution, the fix restores functionality for users operating behind HTTP/HTTPS proxies.

Highlights

  • Externalize https-proxy-agent: Added 'https-proxy-agent' to the esbuild external configuration to prevent runtime errors caused by dynamic import resolution issues in the bundled ESM output.
  • Dependency Management: Included 'https-proxy-agent' as a direct dependency in package.json to ensure it is available for the application.
  • Build Script Update: Updated the bundle asset copy script to include 'https-proxy-agent' and its transitive dependencies, ensuring they are correctly packaged for binary distribution.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces proxy support by adding https-proxy-agent as a dependency and updating the build scripts to externalize and copy it into the bundle. Feedback indicates that the a2a-server bundle may fail at runtime due to missing dependencies, the hardcoded list of transitive dependencies in the copy script is fragile, and the build should fail explicitly if these required packages are not found.

Comment thread esbuild.config.js Outdated
Comment thread scripts/copy_bundle_assets.js Outdated
Comment thread scripts/copy_bundle_assets.js Outdated
Comment on lines +133 to +137
if (existsSync(pkgSrc)) {
mkdirSync(pkgDest, { recursive: true });
cpSync(pkgSrc, pkgDest, { recursive: true, dereference: true });
console.log(`Copied ${pkg} to bundle/node_modules/`);
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

The script currently skips copying if a package is missing from node_modules. Since these packages are required for proxy support (a P1 fix), the build should fail explicitly if they cannot be found to prevent shipping a broken bundle.

  if (!existsSync(pkgSrc)) {
    console.error("Error: Required package " + pkg + " not found in node_modules. Ensure dependencies are installed.");
    process.exit(1);
  }
  mkdirSync(pkgDest, { recursive: true });
  cpSync(pkgSrc, pkgDest, { recursive: true, dereference: true });
  console.log("Copied " + pkg + " to bundle/node_modules/");

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed — this is a critical dependency for proxy support, so the build should fail explicitly if these packages are missing. Updated to use console.error + process.exit(1), consistent with the chrome-devtools-mcp copy in section 6.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This comment was on the previous externalize-based approach. The PR has since been reworked to use static imports (per @scidomino's suggestion); the external entries and the bundle-copy script changes have been removed entirely. No longer applicable.

@sotokisehiro

Copy link
Copy Markdown
Contributor Author

@google-cla check

@sotokisehiro

Copy link
Copy Markdown
Contributor Author

I have confirmed that it works in a Windows environment.

@sotokisehiro

Copy link
Copy Markdown
Contributor Author

@gemini-cli-robot This PR unblocks all users who are currently unable to access Vertex AI due to proxy issues.

@sotokisehiro

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces proxy support by adding https-proxy-agent as an external dependency and updating the asset copying script to include it and its transitive dependencies in the bundle. Feedback indicates that hardcoding transitive dependencies is fragile and suggests using dynamic resolution instead. Additionally, there is a concern that the a2a-server distribution will lack these dependencies at runtime since they are currently only copied to the CLI bundle directory.

Comment thread esbuild.config.js Outdated
Comment thread scripts/copy_bundle_assets.js Outdated
@sotokisehiro

Copy link
Copy Markdown
Contributor Author

@gemini-code-assist
My pull request and the other pull request (#26551) seem to be duplicates, don't they?

@gemini-code-assist

Copy link
Copy Markdown
Contributor

I do not have access to view other pull requests, so I am unable to confirm if your PR is a duplicate of #26551. I recommend comparing the changes in both pull requests to see if they address the same issue in the same way. If you find that they are indeed duplicates, it would be best to reach out to the repository maintainers to discuss which PR should be merged.

@sotokisehiro

Copy link
Copy Markdown
Contributor Author

@gemini-code-assist I got it.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Understood. Since you are now aware of the potential duplication, please proceed with comparing the two pull requests. If you determine that they are indeed duplicates, it is best to coordinate with the repository maintainers to decide which one should move forward. If you have any further questions or need assistance with the code in this PR, feel free to ask.

@sotokisehiro

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces proxy support by adding 'https-proxy-agent' as a dependency and configuring the build system to include it in the bundle. Changes include marking the package as external in the esbuild configuration and updating the asset copying script to manually move the package and its dependencies into the bundle's node_modules. A review comment suggests refactoring the asset copying script to dynamically traverse the dependency tree instead of using a hardcoded list of packages, which would make the build process more resilient to dependency updates.

Comment thread scripts/copy_bundle_assets.js Outdated
レビュー指摘 (PR #26361) を反映。直接 dependency として root と
packages/core 両方に http-proxy-agent ^7.0.2 を declared 済みのため、
overrides による version pinning は不要。重複削除で package.json を整理。

teeny-request が要求する v5 は nested に分離されたままで、本コードの
静的 import (HttpProxyAgent / HttpsProxyAgent) は root の v7 に解決される。
@sotokisehiro

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces proxy support for the GoogleGenAI client by integrating http-proxy-agent and https-proxy-agent, including logic to select the appropriate agent based on the destination protocol and unit tests for verification. Feedback suggests externalizing the new http-proxy-agent dependency in the build configuration to prevent runtime errors. Additionally, it is recommended to define a local interface for the undocumented googleAuthOptions property and to consider using a custom httpClient to ensure consistent proxy behavior across all API calls.

Comment thread packages/core/src/core/contentGenerator.ts
Comment thread packages/core/src/core/contentGenerator.ts
@sotokisehiro

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces proxy support for the Gemini CLI by adding http-proxy-agent and https-proxy-agent as dependencies. The createContentGenerator function in packages/core was updated to detect and configure the appropriate proxy agent based on the destination URL's protocol, ensuring that requests are correctly routed when a proxy is configured. Additionally, new unit tests were implemented to verify the proxy agent injection logic, including handling of different protocols and whitespace trimming in proxy URLs. I have no feedback to provide as there were no review comments.

@sotokisehiro

Copy link
Copy Markdown
Contributor Author

@gemini-code-assist Thanks for the review. Both indications are based on premises that no longer apply to this PR. I'd like to address them inline rather than changing the code:

Re: contentGenerator.ts:344 — externalize http-proxy-agent in esbuild.config.js

This indication is based on the older externalization strategy described in the PR description (which I'll update separately). The current implementation does not externalize either proxy package. We instead statically import them in contentGenerator.ts and inject a pre-instantiated agent into GoogleGenAI. With this approach:

  • esbuild bundles both http-proxy-agent and https-proxy-agent inline as part of the chunks (verified via grep "HttpsProxyAgent" bundle/chunk-*.js).
  • gaxios's dynamic import('https-proxy-agent') path is never reached (because we provide agent upfront, satisfying gaxios's if (opts.agent) skip branch).
  • No external entry or asset-copy step is needed for SEA distribution.

Adding either package to external and copying it via copy_bundle_assets.js would re-introduce exactly the brittleness that maintainer @scidomino flagged in the previous revision. The PR description will be revised to reflect the current design.

Re: contentGenerator.ts:359googleAuthOptions undocumented + Gemini API path

Two sub-points to address:

1. googleAuthOptions is a documented public option, not internal.

It's declared on GoogleGenAIOptions in @google/genai@1.30.0's exported type definitions:

class GoogleGenAI {
  constructor(options: GoogleGenAIOptions);
}

interface GoogleGenAIOptions {
  apiKey?: string;
  vertexai?: boolean;
  httpOptions?: HttpOptions;
  googleAuthOptions?: GoogleAuthOptions;  // re-exported from google-auth-library
  // ...
}

The nested chain clientOptions.transporterOptions.agent comes from the google-auth-library types (GoogleAuthOptionsclientOptions: AuthClientOptionstransporterOptions). All of these are public, typed APIs — no as any or local interface workaround is needed.

2. Vertex AI vs Gemini API key path.

You're correct that googleAuthOptions only configures the auth/transporter layer, which is the path used by Vertex AI auth. For Gemini API key auth, the request goes through httpOptions → fetch directly without the gaxios layer.

This is intentional and matches the original bug scope:

I'll update the PR description to make the scope and the no-externalize design explicit.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Thank you for the detailed explanation. Your reasoning for moving away from the externalization strategy is sound. By statically importing the proxy agents and injecting them directly into googleAuthOptions, you effectively bypass the dynamic import path that was causing the TypeError in the ESM bundle, while also avoiding the complexity and potential brittleness of managing external dependencies in the build configuration.

Your analysis of the scope—specifically that this fix targets the Vertex AI auth flow where the gaxios dynamic import is triggered—is correct. This approach is a cleaner, more maintainable solution for the reported issue.

Updating the PR description to reflect this design and scope is a great next step. Once that is done, the changes appear to be well-aligned with the goal of unblocking Vertex AI users behind proxies.

@sotokisehiro

Copy link
Copy Markdown
Contributor Author

@scidomino Thanks for your earlier review and the suggested approach — you were right that the original external + bundle-copy approach was hacky. The PR has been reworked to use static imports as you recommended (current HEAD: 8e563e199).

A short summary of where it landed and why a couple of details differ slightly from your snippet.

What's in the PR now

The Vertex AI / proxy fix is now contained to 5 files, +192 / -0 — purely the proxy work, nothing unrelated:

packages/core/src/core/contentGenerator.ts       | +16
packages/core/src/core/contentGenerator.test.ts  | +170
packages/core/package.json                       |  +1
package.json                                     |  +2
package-lock.json                                |  +3

The core change in contentGenerator.ts:

import { HttpProxyAgent } from 'http-proxy-agent';
import { HttpsProxyAgent } from 'https-proxy-agent';

// inside createContentGenerator, GoogleGenAI branch:
const proxyUrl = config.proxy?.trim();
const proxyAgent = proxyUrl
  ? baseUrl?.startsWith('http://')
    ? new HttpProxyAgent(proxyUrl)
    : new HttpsProxyAgent(proxyUrl)
  : undefined;

const googleGenAI = new GoogleGenAI({
  apiKey: config.apiKey === '' ? undefined : config.apiKey,
  vertexai: config.vertexai ?? config.authType === AuthType.USE_VERTEX_AI,
  httpOptions,
  ...(apiVersionEnv && { apiVersion: apiVersionEnv }),
  ...(proxyAgent && {
    googleAuthOptions: {
      clientOptions: {
        transporterOptions: { agent: proxyAgent },
      },
    },
  }),
});

The external entries in esbuild.config.js, the Step 8 in copy_bundle_assets.js, and the proxy-agent entries in root package.json dependencies from the previous revision have all been removed — none of them are needed once the agent is provided statically.

Two minor deviations from your snippet (and why)

1. Agent selection is keyed on baseUrl, not proxyUrl.

Your snippet picks the agent class from proxyUrl.startsWith('http://'), but the protocol that actually matters for HTTP-CONNECT semantics is the destination scheme. Both Vertex AI and Gemini API endpoints are HTTPS by default, so HttpsProxyAgent is needed (it tunnels via CONNECT) regardless of whether the proxy itself is reached over http:// or https://. Using HttpProxyAgent for an HTTPS destination would fail the TLS handshake. So the picker reads baseUrl (destination override or default) and falls through to HttpsProxyAgent whenever the destination is HTTPS — which is the common case.

(gemini-code-assist flagged the same point in its automated review, with a clear explanation.)

2. Agent is injected via googleAuthOptions.clientOptions.transporterOptions.agent, not httpOptions.agent.

HttpOptions in @google/genai@1.30.0 doesn't expose an agent field, but the dynamic-import bug actually originates one layer down in google-auth-librarygaxios. Passing the agent via googleAuthOptions propagates it to gaxios.defaults.agent, which makes gaxios skip the await import('https-proxy-agent') branch entirely — so no dynamic import is attempted at runtime and the esbuild ESM bundle issue can't trigger. Net effect is the same as your suggestion (no dynamic import path), it's just hooked into the layer where the bug actually lives.

This intentionally scopes the fix to the Vertex AI / Google Auth path, which is where the original TypeError: HttpsProxyAgent is not a constructor reproduces. Generic proxy support for the Gemini API key path (which doesn't go through gaxios) is a separate concern and would belong in a different PR.

Test coverage

packages/core/src/core/contentGenerator.test.ts gains 5 cases for createContentGenerator (the Vertex AI branch):

  • https:// proxy URL → HttpsProxyAgent injected
  • http:// proxy URL with default (HTTPS) destination → still HttpsProxyAgent (deviation docs: Add setup instructions for API key to README #1 above)
  • http:// baseUrl with http:// proxy URL → HttpProxyAgent
  • proxy URL with surrounding whitespace → trimmed before instantiation
  • no proxy → no googleAuthOptions on the call

Total contentGenerator.test.ts is 39 / 39 passing.

Verification

  • npm run build, npm run bundle
  • vitest run on contentGenerator.test.ts → 39/39
  • proxy-agent code is bundled inline into chunk files (no bundle/node_modules/{http,https}-proxy-agent left over from the old approach)
  • E2E confirmed on Windows under HTTPS_PROXY against Vertex AI

Re: CLA

CLA is now signed and the cla/google check is green.

Could you take another look when you get a chance? Happy to adjust further if anything else jumps out.

@scidomino

Copy link
Copy Markdown
Collaborator

There are a bunch of comments left by Gemini. Please address them and mark them as "resolved". Then I will review.

@scidomino

Copy link
Copy Markdown
Collaborator

ping me when you are done

@sotokisehiro

Copy link
Copy Markdown
Contributor Author

@scidomino All Gemini review comments have been addressed and marked as resolved. Ready for your review.

Thanks also for your earlier suggestion — you were right that the original external + bundle-copy approach was hacky. The PR has been reworked to use static imports as you recommended (current HEAD: 8e563e199).

A short summary of where it landed and why a couple of details differ slightly from your snippet.

What's in the PR now

The Vertex AI / proxy fix is now contained to 5 files, +192 / -0 — purely the proxy work, nothing unrelated:

packages/core/src/core/contentGenerator.ts       | +16
packages/core/src/core/contentGenerator.test.ts  | +170
packages/core/package.json                       |  +1
package.json                                     |  +2
package-lock.json                                |  +3

The core change in contentGenerator.ts:

import { HttpProxyAgent } from 'http-proxy-agent';
import { HttpsProxyAgent } from 'https-proxy-agent';

// inside createContentGenerator, GoogleGenAI branch:
const proxyUrl = config.proxy?.trim();
const proxyAgent = proxyUrl
  ? baseUrl?.startsWith('http://')
    ? new HttpProxyAgent(proxyUrl)
    : new HttpsProxyAgent(proxyUrl)
  : undefined;

const googleGenAI = new GoogleGenAI({
  apiKey: config.apiKey === '' ? undefined : config.apiKey,
  vertexai: config.vertexai ?? config.authType === AuthType.USE_VERTEX_AI,
  httpOptions,
  ...(apiVersionEnv && { apiVersion: apiVersionEnv }),
  ...(proxyAgent && {
    googleAuthOptions: {
      clientOptions: {
        transporterOptions: { agent: proxyAgent },
      },
    },
  }),
});

The external entries in esbuild.config.js, the Step 8 in copy_bundle_assets.js, and the proxy-agent entries in root package.json dependencies from the previous revision have all been removed — none of them are needed once the agent is provided statically.

Two minor deviations from your snippet (and why)

1. Agent selection is keyed on baseUrl, not proxyUrl.

Your snippet picks the agent class from proxyUrl.startsWith('http://'), but the protocol that actually matters for HTTP-CONNECT semantics is the destination scheme. Both Vertex AI and Gemini API endpoints are HTTPS by default, so HttpsProxyAgent is needed (it tunnels via CONNECT) regardless of whether the proxy itself is reached over http:// or https://. Using HttpProxyAgent for an HTTPS destination would fail the TLS handshake. So the picker reads baseUrl (destination override or default) and falls through to HttpsProxyAgent whenever the destination is HTTPS — which is the common case.

(gemini-code-assist flagged the same point in its automated review, with a clear explanation.)

2. Agent is injected via googleAuthOptions.clientOptions.transporterOptions.agent, not httpOptions.agent.

HttpOptions in @google/genai@1.30.0 doesn't expose an agent field, but the dynamic-import bug actually originates one layer down in google-auth-librarygaxios. Passing the agent via googleAuthOptions propagates it to gaxios.defaults.agent, which makes gaxios skip the await import('https-proxy-agent') branch entirely — so no dynamic import is attempted at runtime and the esbuild ESM bundle issue can't trigger. Net effect is the same as your suggestion (no dynamic import path), it's just hooked into the layer where the bug actually lives.

This intentionally scopes the fix to the Vertex AI / Google Auth path, which is where the original TypeError: HttpsProxyAgent is not a constructor reproduces. Generic proxy support for the Gemini API key path (which doesn't go through gaxios) is a separate concern and would belong in a different PR.

Test coverage

packages/core/src/core/contentGenerator.test.ts gains 5 cases for createContentGenerator (the Vertex AI branch):

  • https:// proxy URL → HttpsProxyAgent injected
  • http:// proxy URL with default (HTTPS) destination → still HttpsProxyAgent (deviation docs: Add setup instructions for API key to README #1 above)
  • http:// baseUrl with http:// proxy URL → HttpProxyAgent
  • proxy URL with surrounding whitespace → trimmed before instantiation
  • no proxy → no googleAuthOptions on the call

Total contentGenerator.test.ts is 39 / 39 passing.

Verification

  • npm run build, npm run bundle
  • vitest run on contentGenerator.test.ts → 39/39
  • proxy-agent code is bundled inline into chunk files (no bundle/node_modules/{http,https}-proxy-agent left over from the old approach)
  • E2E confirmed on Windows under HTTPS_PROXY against Vertex AI

Re: CLA

CLA is now signed and the cla/google check is green.

Could you take another look when you get a chance? Happy to adjust further if anything else jumps out.

@scidomino

Copy link
Copy Markdown
Collaborator

You mentioned that the proxy-agent entries in the root package.json dependencies were removed, but they are still present in the current diff for package.json. Since this is a monorepo, we only need these dependencies defined in the workspace that uses them (packages/core/package.json). Please remove them from the root package.json and regenerate the lockfile.

Also, try to keep the PR comments concise. I can only read so much text in one sitting 😄

メンテナレビュー (PR #26361) を反映。monorepo では proxy-agent は
実際に使う workspace (packages/core) でのみ declared すれば十分のため、
root の dependencies から http-proxy-agent / https-proxy-agent を撤去。
package-lock.json も再生成。
@sotokisehiro

Copy link
Copy Markdown
Contributor Author

Sorry about the inconsistency in my last comment — you're right. Removed both http-proxy-agent and https-proxy-agent from the root package.json and regenerated the lockfile in 4f796edc1. They remain only in packages/core/package.json where they're actually imported.

Will keep replies tight from here on 👍

@scidomino
scidomino enabled auto-merge May 14, 2026 22:21
@scidomino
scidomino added this pull request to the merge queue May 14, 2026
Merged via the queue into google-gemini:main with commit 928a311 May 14, 2026
27 checks passed
@sotokisehiro

Copy link
Copy Markdown
Contributor Author

Thank you for your cooperation!

@sripasg sripasg added the size/m A medium sized PR label Jun 2, 2026
software-0ficial pushed a commit to software-0ficial/gemini-cli that referenced this pull request Jul 9, 2026
Cleanskiier27 added a commit to Cleanskiier27/gemini-cli that referenced this pull request Jul 25, 2026
* fix(core): Fix hysteresis in async context management pipelines. (google-gemini#26452)

* Tighten private Auto Memory patch allowlist (google-gemini#26535)

* fix(cli): hide read-only settings scopes (google-gemini#26249)

* fix(ci): preserve executable bit for mac binaries (google-gemini#26600)

* fix(cli): improve mcp list UX in untrusted folders (google-gemini#26457)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>

* fix(core): prevent silent hang during OAuth auth on headless Linux (google-gemini#26571)

Co-authored-by: Jack Wotherspoon <jackwoth@google.com>

* Changelog for v0.42.0-preview.0 (google-gemini#26537)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* ci: fix Argument list too long in triage workflows (google-gemini#26603)

* refactor(cli): migrate core tools to native ToolDisplay property and fix UI rendering (google-gemini#25186)

* don't wrap args unnecessarily (google-gemini#26599)

* fix(core): preserve system PATH in Git environment to fix ENOENT (google-gemini#25034) (google-gemini#26587)

* fix(routing): fix resolveClassifierModel argument mismatch in ApprovalModeStrategy (google-gemini#26658)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* docs: add vi mode shortcuts and clarify MCP/custom sandbox setup (google-gemini#23853)

Co-authored-by: Sam Roberts <158088236+g-samroberts@users.noreply.github.com>

* fix(ux): fixed issue with transcribed text not showing after releasing space (google-gemini#26609)

* ci: fix json parsing in scheduled triage workflow (google-gemini#26656)

* fix(cli): hide /memory add subcommand when memoryV2 is enabled (google-gemini#26605)

* fix: prevent false command conflicts when launching from home directory (google-gemini#23069)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* fix(core): cache model routing decision in LocalAgentExecutor (google-gemini#26548)

* Changelog for v0.42.0-preview.2 (google-gemini#26597)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>
Co-authored-by: Sam Roberts <158088236+g-samroberts@users.noreply.github.com>

* skip broken test (google-gemini#26705)

* feat: export session to file and import via flag (google-gemini#26514)

* Feat: Add Machine Hostname to CLI interface (google-gemini#25637)

Signed-off-by: M-DEV-1 <mahadevankizhakkedathu@gmail.com>
Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* docs(extensions): refactor releasing guide and add update mechanisms (google-gemini#26595)

* fix(ci): fix maintainer identification in lifecycle manager (google-gemini#26706)

* fix(ui): added quotes around session id in resume tip (google-gemini#26669)

* Changelog for v0.41.0 (google-gemini#26670)

Co-authored-by: g-samroberts <158088236+g-samroberts@users.noreply.github.com>

* refactor(core): agent session protocol changes (google-gemini#26661)

* fix(context): implement loose boundary policy for gc backstop. (google-gemini#26594)

* fix(core): throw explicit error on dropped tool responses (google-gemini#26668)

* fix: resolve "function response turn must come immediately after function call" error (google-gemini#26691)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* fix(core): resolve parallel tool call streaming ID collision (google-gemini#26646)

* feat(core): add LocalSubagentProtocol behind AgentProtocol (google-gemini#25302)

* fix(cli): remove noisy theme registration logs from terminal (google-gemini#25858)

Co-authored-by: Jack Wotherspoon <jackwoth@google.com>

* ci: implement codebase-aware effort level triage (google-gemini#26666)

* feat(acp/core): prefix tool call IDs with tool names to support tool rendering in ACP compliant IDEs. (google-gemini#26676)

* fix(mcp): treat GET 404 as 405 in StreamableHTTPClientTransport (google-gemini#24847)

Co-authored-by: Coco Sheng <cocosheng@google.com>
Co-authored-by: Spencer <spencertang@google.com>
Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* feat(core): add RemoteSubagentProtocol behind AgentProtocol (google-gemini#25303)

* feat(context): Improvements to the snapshotter. (google-gemini#26655)

* fix(context): Change snapshotter model config. (google-gemini#26745)

* fix(cli): allow installing extensions from ssh repo (google-gemini#26274)

Signed-off-by: Daniel Finimundi <danielrf@motorola.com>
Co-authored-by: Dev Randalpura <devrandalpura@google.com>

* fix(cli): prevent duplicate SessionStart systemMessage render (google-gemini#25827)

Co-authored-by: Jacob Richman <jacob314@gmail.com>

* fix(cli/acp): prevent infinite thought loop in ACP mode by disablig nextSpeakerCheck (google-gemini#26874)

* fix(cli): use static tool name in confirmation prompt to avoid parsing errors (google-gemini#26866)

* fix(routing): Refactor tool turn handling for the conversation history in NumericalClassifierStrategy to prevent 400 Bad Request (google-gemini#26761)

* fix(core): handle malformed projects.json in ProjectRegistry (google-gemini#26885)

* fix(ui): added a gutter width to the input prompt width calculation (google-gemini#26882)

* fix: prevent EISDIR crash when customIgnoreFilePaths contains directories (google-gemini#19868) (google-gemini#19898)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* revert 6b9b778 (google-gemini#26893)

* Fix/vscode run current file ts (google-gemini#22894)

Co-authored-by: Spencer <spencertang@google.com>

* Allow Enter to select session while in search mode in /resume (google-gemini#21523)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* fix(core): ignore .pak and .rpa game archive formats by default (google-gemini#26884)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* fix(cli): enable adk non-interactive session (google-gemini#26895)

* fix(cli): restore resume for legacy sessions (google-gemini#26577)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* fix: respect explicit model selection after Flash quota exhaustion (google-gemini#26759) (google-gemini#26872)

* feat(context): Introduce adaptive token calculator to more accurately calculate content sizes. (google-gemini#26888)

* chore: update checkout action configuration in workflows (google-gemini#26897)

* fix (telemetry): inject quota_project_id to prevent fallback to default oauth client (google-gemini#26698)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* Exclude extension context from skill extraction agent (google-gemini#26879)

* Enable NumericalRouter when using dynamic model configs (google-gemini#26929)

* ci: actively triage missing priority labels and intelligently clean up conflicting labels (google-gemini#26865)

* refactor(core): introduce SubagentState enum for progress (google-gemini#26934)

* fix(ci): replace brittle --no-tag with explicit staging-tmp tag (google-gemini#26940)

* Incremental refactor repo agent towards skills-based composition (google-gemini#26717)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>

* fix(ui): fixed line wrap padding for selection lists (google-gemini#26944)

* fix(core): update read_file schema for v1 compatibility (google-gemini#22183) (google-gemini#26922)

* fix(ci): configure git remote with token for authentication (google-gemini#26949)

* chore(release): bump version to 0.44.0-nightly.20260512.g022e8baef (google-gemini#26957)

* Changelog for v0.42.0 (google-gemini#26958)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* Refactor: Eliminate `no-unsafe-return` suppressions via strict type validation (google-gemini#20668)

Signed-off-by: M-DEV-1 <mahadevankizhakkedathu@gmail.com>
Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* Changelog for v0.43.0-preview.0 (google-gemini#26959)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* feat(core): change agent registration to first-wins and prioritize project (google-gemini#26953)

* feat(cli): merge Auto modes into a single Auto mode (google-gemini#26714)

* fix(core): preserve OAuth refresh tokens during rotation and retrieval (google-gemini#26924)

* fix(cli): allow keychain auth for --list-sessions and non-interactive mode (google-gemini#26921)

* fix(core): handle EISDIR on virtual drives in memory discovery (google-gemini#26985)

* fix(cli): auto-approve shell redirections in AUTO_EDIT mode (google-gemini#27003)

* ci: suppress bot comments during standard triage maintenance (google-gemini#27006)

* fix(core): isolate subagent thread context (google-gemini#26449)

* fix(core): refresh MCP OAuth token usage after re-auth (google-gemini#26312)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* fix(ui): clamped table column widths (google-gemini#26991)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>

* chore: add execution permission to scripts/review.sh (google-gemini#27009)

* fix(core): made context files append instead of replace (google-gemini#26950)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>

* fix: add system PATH fallback for ripgrep resolution (google-gemini#26777) (google-gemini#26868)

* chore: clean up launched memory features (google-gemini#26941)

Co-authored-by: Jenna Inouye <jinouye@google.com>

* fix(core): throttle shell text output and bound live UI buffer (google-gemini#26955)

* fix(cli): don't crash when an @-mention captures a non-path blob (google-gemini#25980)

* fix(core): ensure stable fallback for restricted preview models (google-gemini#26999)

* feat(core): expose RAG snippets to local log file for debugging (google-gemini#27016)

* fix(acp/auth): prevent conflicting credentials on enterprise gateways and support optional API keys natively (google-gemini#27021)

* fix(core): respect NO_PROXY for network-based MCP servers (google-gemini#27012)

* fix(cli): resolve permission denied in sandbox on NixOS and other distros (google-gemini#27004)

* fix(ui): preserve new line at the end of edit window (google-gemini#27057)

* fix(core): ensure Vertex AI sets hasAccessToPreviewModels and remove aggressive 404 fallback revocation (google-gemini#27067)

* fix(core): ensure stable admin settings comparison across IPC to prevent restart loop (google-gemini#27066)

* fix(deps): update vulnerable dependencies (google-gemini#27062)

* fix(core): resolve EISDIR errors during file processing (google-gemini#21527) (google-gemini#27041)

* docs(extensions): clarify env var sanitization policy for MCP and ext… (google-gemini#22854)

Co-authored-by: Jack Wotherspoon <jackwoth@google.com>
Co-authored-by: Jenna Inouye <jinouye@google.com>

* fix(ui): add ENAMETOOLONG and ENOTDIR to exceptions for file parsing errors (google-gemini#27069)

* fix(cli): explicitly clear entrypoint when spawning sandbox container (google-gemini#27059)

* docs: update sandbox image command (google-gemini#26774)

* fix(core): externalize https-proxy-agent to fix proxy support (google-gemini#26361)

* security: update dependencies to fix critical and high vulnerabilities (google-gemini#27077)

* Fix/web fetch ctrl c abort (google-gemini#24320)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>

* fix(core): add aliases and thinking config for gemini-3.1 models (google-gemini#27007)

* fix(core): use hasAccessToPreview for auto model resolution and fix disappearing models (google-gemini#27112)

* feat(core): add adk.agentSessionSubagentEnabled flag (google-gemini#26947)

* fix(core): enforce compile-time exhaustiveness in content-utils (google-gemini#27207)

* feat(skills): add agent-tui and tui-tester skills (google-gemini#27121)

* fix(context): Fix snapshot recovery across sessions. (google-gemini#26939)

* fix(core): add unit tests for stableStringify (google-gemini#27212)

* fix(core): prefer pwsh.exe over Windows PowerShell 5.1 (google-gemini#25859) (google-gemini#25900)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* feat(core): add LocalSessionInvocation (google-gemini#26665)

* refactor: decouple auto model description and configuration from releaseChannel (google-gemini#27227)

Co-authored-by: David Pierce <davidapierce@google.com>

* fix(core): prevent isBinary false-positive on Windows PTY streams (google-gemini#26565)

* fix(cli): Prevent unmapped keys in Vim Normal mode from inserting text into prompt Input. (google-gemini#25139)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* fix(a2a-server): Implement default policy loading for parity with CLI (google-gemini#27073)

* feat(core): add RemoteSessionInvocation (google-gemini#26937)

* fix: allow configured MCP servers in non-interactive mode (google-gemini#27215)

* fix(core): add exception handling to migrateFromFileStorage (google-gemini#27229)

* fix(cli): bundle ink worker-entry.js (google-gemini#27249)

* feat(core): wire AgentSession invocations into agent-tool (google-gemini#26948)

* fix(core): prevent path traversal in custome command file injection (google-gemini#27234)

* fix(core): respect NO_PROXY in global fetch dispatcher (google-gemini#27216)

* fix(core): correctly handle nullable array types in MCP tools (google-gemini#27228)

* Proposal: deterministic encoding for child-process I/O (google-gemini#27247)

* fix(cli): preserve proxy-agent named exports in ESM bundle (google-gemini#27145)

* feat(cli): add Sublime Text and Emacs Client editors, improve error messages and documentation (google-gemini#21090)

Co-authored-by: Ananth Kini <ananthkini1@gmail.com>

* Changelog for v0.43.0-preview.1 (google-gemini#27297)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* fix(devtools): bundle devtools package to avoid resolution errors (google-gemini#27250)

* fix(cli): integrate PolicyEngine into ACP session to prevent deadlocks (google-gemini#23507) (google-gemini#27252)

* fix: robust ripgrep path resolution and 1p hermetic execution support (google-gemini#27253)

* refactor: decouple stored session deletion from ChatRecordingService (google-gemini#22920) (google-gemini#27039)

* fix(core): improve Alpine shell compatibility (google-gemini#26770)

* fix(core): generalize MCP compliance fix for tool results (google-gemini#27045)

* fix(scripts): scrub CI env vars in dev to keep interactive mode (google-gemini#27159)

* fix(core): Added date field for the GCal MCP (google-gemini#27251)

* fix(core): centralize path validation to prevent crashes from malformed prompts (google-gemini#27211)

* fix(core): prevent SIGHUP kills in PTY environments (WSL2/Kitty/Alacritty) (google-gemini#27267)

* fix(core): dynamic fallback routing for exhausted quota models (google-gemini#27315)

* Auto detect pnpm global installation path for macOS and Windows (google-gemini#22748)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: Coco Sheng <cocosheng@google.com>

* fix(windows): resolve interactive shell arrow-key navigation on Windows (google-gemini#23505)

* ci: robust stale issue lifecycle and consolidated triage labels (google-gemini#27015)

* fix(context): Ensure last message is processed. (google-gemini#27232)

* chore/release: bump version to 0.44.0-nightly.20260521.g57c42a5c4 (google-gemini#27324)

* fix(ui): added volta to auto update check (google-gemini#27353)

* perf: optimize issue triage and lifecycle management (google-gemini#27346)

* chore(release): bump version to 0.45.0-nightly.20260521.g854f811be (google-gemini#27362)

* fix(cli): prevent Termux relaunch and resize remount loops (google-gemini#27110)

Co-authored-by: Spencer <spencertang@google.com>

* Feat/a2a expose usage metadata (google-gemini#27288)

* feat(context): Complete simplification work. (google-gemini#27345)

* fix(core): force update_topic tool to execute sequentially (google-gemini#27357)

* Changelog for v0.44.0-preview.0 (google-gemini#27360)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* Changelog for v0.43.0 (google-gemini#27361)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* Revert "fix(core): prevent SIGHUP kills in PTY environments" (google-gemini#27401)

* fix(cli): filter internal session context from history during resumption (google-gemini#27391)

* Update default auto routing (google-gemini#27071)

* fix(core): bypass routing classifiers to prevent orphaned function response errors (google-gemini#27389)

* fix(core): suppress PTY resize EBADF errors (google-gemini#27461)

* fix(core): prevent blacklist bypass in mcp list (google-gemini#27377)

Co-authored-by: Gal Zahavi <38544478+galz10@users.noreply.github.com>

* fix(cli): ignore unmapped vim normal keys (google-gemini#27102)

* fix(core): harden PTY resize against native crashes (google-gemini#27496)

* Changelog for v0.45.0-preview.0 (google-gemini#27495)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* Changelog for v0.44.0 (google-gemini#27569)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* fix(cli): prevent spam loop when preferredEditor is invalid (google-gemini#25324)

Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* Adding quote (google-gemini#27571)

* Transition to flash GA model when experiment flag is present. (google-gemini#27570)

* chore(ci): add optimized PR size labeler and batch workflows (google-gemini#27616)

* fix(ci): use pull_request_target trigger to grant write access on fork PRs (google-gemini#27637)

* chore(release): bump version to 0.47.0-nightly.20260602.gcfcecebe8 (google-gemini#27644)

* Changelog for v0.46.0-preview.0 (google-gemini#27641)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* Respect backend definitions for 3.5 flash and Update auto mode to use 3.5 flash when the flag is enabled. (google-gemini#27645)

* fix(policy): add EBUSY fallback and TOML parse recovery (google-gemini#19919) (google-gemini#21541)

Signed-off-by: krishdef7 <gargkrish06@gmail.com>
Co-authored-by: Sikandar <ma5161310@gmail.com>
Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>

* Changelog for v0.45.0 (google-gemini#27642)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* update the max amount of times the Antigravity transition banner can be displayed. (google-gemini#27676)

* chore: remove experimental text from browser agent docs (google-gemini#27746)

* fix(core): implement atomic update in MCP tool discovery (google-gemini#27619)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: Gal Zahavi <38544478+galz10@users.noreply.github.com>

* Vertex ai model mapping fix (google-gemini#27749)

* Add documentation and migration commands for Antigravity CLI (google-gemini#27765)

Co-authored-by: Gal Zahavi <38544478+galz10@users.noreply.github.com>

* Avoid persisting empty resume sessions (google-gemini#27770)

* chore(release): bump version to 0.48.0-nightly.20260609.g3a13b8eeb (google-gemini#27779)

* ci(dependabot): enable cooldown period for npm packages (google-gemini#27743)

* refactor(core): standardize tool output formatting (google-gemini#27772)

* ci: update workflow logging and policy configurations (google-gemini#27853)

* fix(core): Ensure zero-quota limits fail fast to prevent retry loop hang (google-gemini#27698)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>

* fix(core): handle multi-line escaped quotes in stripShellWrapper (google-gemini#27467)

Co-authored-by: luisfelipe-alt <luisfelipe@google.com>

* fix(cli): prevent path traversal vulnerabilities during skill install… (google-gemini#27767)

* Fix/pending tools and trust overrides (google-gemini#27854)

* ci: use internal environment for scheduled nightly releases (google-gemini#27865) (google-gemini#27939)

* feat(core): Support GDC air-gapped Service Identity after auth library update (google-gemini#27956)

* fix(cli): handle tmux false positive background detection (google-gemini#27572)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: Gal Zahavi <38544478+galz10@users.noreply.github.com>

* Add static eval source analyzer (google-gemini#27631)

* fix(config): migrate coreTools setting to tools.core (google-gemini#27947)

* fix(core-tools): resolve defensive path resolution for at-reference files (google-gemini#27943)

* Revert "fix(core-tools): resolve defensive path resolution for at-reference files" (google-gemini#27992)

* chore(release): bump version to 0.49.0-nightly.20260617.g4d3dcdce1 (google-gemini#28003)

* Changelog for v0.48.0-preview.0 (google-gemini#27999)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* fix(ci): provide fallbacks for package variables in nightly release (google-gemini#28016)

* chore(deps): pin dependencies and enforce 14-day update cooldown (google-gemini#27948)

* fix(ci): append trailing slash to registry url in npmrc (google-gemini#28038)

* feat: add eval:inventory CLI command and reporting logic (google-gemini#28009)

* fix: resolve workspace publish failures and scheduler event loop starvation (google-gemini#28063)

* fix(ci): use wombat dressing room fallback in nightly release to prevent ENEEDAUTH (google-gemini#28104)

* Add JSON output for eval inventory (google-gemini#28058)

* fix/verify release npm ci ignore scripts (google-gemini#28116)

* fix(ci): prevent workspace binary shadowing in release verification (google-gemini#28132)

* Feat/tool registry discovery (google-gemini#28113)

* fix(ci): prevent bad NPM releases and promote job crashes (google-gemini#28147)

* Changelog for v0.50.0-preview.1 (google-gemini#28150)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* chore(release): bump version to 0.51.0-nightly.20260625.g3fbf93e26 (google-gemini#28151)

* Fix no_proxy test (google-gemini#28131)

Co-authored-by: Jerry Lin <jerrysf@google.com>

* Vertex base url update (google-gemini#28145)

* fix(security): enforce case-insensitive sensitive path blocklist and vscode hitl (google-gemini#27966)

Co-authored-by: David Pierce <davidapierce@google.com>

* fix(core-tools): resolve defensive path resolution for at-reference files and fix macOS tests (google-gemini#28053)

Co-authored-by: David Pierce <davidapierce@google.com>

* feat(caretaker): implement Cloud Run webhook ingestion service (google-gemini#28015)

Co-authored-by: Christian Gunderman <gundermanc@google.com>

* fix(core): resolve symbolic link directory escape in memory import processor (google-gemini#28233)

* feat(caretaker): egress cloud run service skeleton (google-gemini#28167)

* fix(sandbox): make ~/.gitconfig read-only in the macOS sandbox (google-gemini#28221)

Co-authored-by: David Pierce <davidapierce@google.com>

* fix(core): preserve escape sequences in string literals for modern models (google-gemini#28299)

Co-authored-by: David Pierce <davidapierce@google.com>

* fix(core): strip thoughts from scrubbed history turns and resolve thought leakage (google-gemini#27971)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: Gal Zahavi <38544478+galz10@users.noreply.github.com>
Co-authored-by: David Pierce <davidapierce@google.com>

* Refactor: exclude transient CI configuration files from workspace context (google-gemini#28216)

* feat(caretaker): add triage worker core foundational modules (google-gemini#28163)

* feat(caretaker-egress): implement octokit github action handler for egress service (google-gemini#28303)

* chore(release): bump version to 0.52.0-nightly.20260707.g27a3da3e8 (google-gemini#28323)

* Changelog for v0.51.0-preview.0 (google-gemini#28320)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* Changelog for v0.50.0 (google-gemini#28322)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>
Co-authored-by: David Pierce <davidapierce@google.com>

* fix(core-tools): bypass LLM correction for JSON and IPYNB files in write_file and replace (google-gemini#28223)

Co-authored-by: David Pierce <davidapierce@google.com>

* fix(core): use unambiguous previous intent label in fallback summary (google-gemini#28343)

* feat(caretaker-triage): implement main worker execution loop and egress action publisher (google-gemini#28306)

* fix(privacy): show a clear message when the account has no Code Assist tier (google-gemini#28304)

* fix(core): enrich shared project quota limit errors with setup hint (google-gemini#28391)

* fix(a2a-server): ensure task cancellation aborts execution loop (google-gemini#28316)

* fix(core): simplify plan mode write policy to support relative paths (google-gemini#28398)

* feat(core): Bump node google-auth-library version to 10.9.0 (google-gemini#28385)

Co-authored-by: Jerry Lin <jerrysf@google.com>

* chore/release: bump version to 0.52.0-nightly.20260715.gfa975395b (google-gemini#28402)

* fix(core,a2a): group cancelled tool responses and coalesce consecutive roles to prevent 400 Bad Request (google-gemini#28407)

* feat(caretaker-triage): implement LLM triage orchestrator and container build (google-gemini#28345)

* refactor(cli): align macOS permissive Seatbelt profiles with deny-default model (google-gemini#28424)

* fix(core): mitigate infinite ReAct loops and prompt injection loops (google-gemini#28429)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>

* fix(a2a-server): enforce workspace trust and task isolation to prevent RCE (google-gemini#28470)

* fix(core): sequentially verify cached credentials and restore GOOGLE_APPLICATION_CREDENTIALS fallback (google-gemini#28472)

Co-authored-by: David Pierce <davidapierce@google.com>

* feat(evals): add eval coverage report command (google-gemini#28169)

* Changelog for v0.53.0-preview.0 (google-gemini#28507)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* Changelog for v0.52.0 (google-gemini#28508)

Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>

* chore(release): bump version to 0.54.0-nightly.20260722.gf743ab579 (google-gemini#28510)

* fix(caretaker): sanitize and wrap issue title in untrusted_context (google-gemini#28352)

* chore(caretaker): update vitest to v3.2.4 and add package-lock.json files (google-gemini#28409)

* fix(core): rotate session ID on model fallback to prevent stateful API errors (google-gemini#28469)

* feat(caretaker-triage): post comment before auto-closing issues (google-gemini#28411)

* fix(core): enforce HTTPS for GoogleCredentialsAuthProvider to prevent cleartext leakage (google-gemini#28517)

* fix(core): filter out thought parts from getHistoryTurns when context management is disabled (google-gemini#28509)

---------

Signed-off-by: M-DEV-1 <mahadevankizhakkedathu@gmail.com>
Signed-off-by: Daniel Finimundi <danielrf@motorola.com>
Signed-off-by: krishdef7 <gargkrish06@gmail.com>
Co-authored-by: joshualitt <joshualitt@google.com>
Co-authored-by: Sandy Tao <sandytao520@icloud.com>
Co-authored-by: Christian Van <113378434+cvan20191@users.noreply.github.com>
Co-authored-by: ruomeng <ruomeng@google.com>
Co-authored-by: Adib234 <30782825+Adib234@users.noreply.github.com>
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: Rhys Sullivan <39114868+RhysSullivan@users.noreply.github.com>
Co-authored-by: Jack Wotherspoon <jackwoth@google.com>
Co-authored-by: gemini-cli-robot <gemini-cli-robot@google.com>
Co-authored-by: gemini-cli-robot <224641728+gemini-cli-robot@users.noreply.github.com>
Co-authored-by: Coco Sheng <cocosheng@google.com>
Co-authored-by: Michael Bleigh <mbleigh@mbleigh.com>
Co-authored-by: Tommaso Sciortino <sciortino@gmail.com>
Co-authored-by: Daniel Weis <danielweis@users.noreply.github.com>
Co-authored-by: Christopher Thomas <cobekgn@gmail.com>
Co-authored-by: Sam Roberts <158088236+g-samroberts@users.noreply.github.com>
Co-authored-by: Dev Randalpura <devrandalpura@google.com>
Co-authored-by: Br1an <932039080@qq.com>
Co-authored-by: AK <akhilbussiness@gmail.com>
Co-authored-by: mahadevan <135952571+M-DEV-1@users.noreply.github.com>
Co-authored-by: Christian Gunderman <gundermanc@google.com>
Co-authored-by: Adam Weidman <65992621+adamfweidman@users.noreply.github.com>
Co-authored-by: Aishanee Shah <aishaneeshah@google.com>
Co-authored-by: JAYADITYA <96861162+JayadityaGit@users.noreply.github.com>
Co-authored-by: Sri Pasumarthi <111310667+sripasg@users.noreply.github.com>
Co-authored-by: krishdef7 <157892833+krishdef7@users.noreply.github.com>
Co-authored-by: Spencer <spencertang@google.com>
Co-authored-by: Daniel Finimundi <daniel@finimundi.com>
Co-authored-by: Aryan Singh <146713101+dimssu@users.noreply.github.com>
Co-authored-by: Jacob Richman <jacob314@gmail.com>
Co-authored-by: Suhaan Raqeeb Khavas <suhaanrk73@gmail.com>
Co-authored-by: Neil Nair <65729206+Neil-N4@users.noreply.github.com>
Co-authored-by: Franco Pieri <geo22therm@gmail.com>
Co-authored-by: Eswar809 <deevieswar44@gmail.com>
Co-authored-by: Kuroda Kayn <kurodakayn@outlook.com>
Co-authored-by: Gal Zahavi <38544478+galz10@users.noreply.github.com>
Co-authored-by: Yulong Wu <50110323+TNTCompany@users.noreply.github.com>
Co-authored-by: kevinjwang1 <kevinjwang@google.com>
Co-authored-by: David Pierce <davidapierce@google.com>
Co-authored-by: Sahil Kirad <167863755+sahilkirad@users.noreply.github.com>
Co-authored-by: Jenna Inouye <jinouye@google.com>
Co-authored-by: EMERSON BUSSON <93008583+emersonbusson@users.noreply.github.com>
Co-authored-by: ifitisit <90478348+ifitisit@users.noreply.github.com>
Co-authored-by: PROTHAM <155388736+ProthamD@users.noreply.github.com>
Co-authored-by: 7. Sun <jhao.sun@gmail.com>
Co-authored-by: sotokisehiro <101786086+sotokisehiro@users.noreply.github.com>
Co-authored-by: Anish Sabharwal <anishs1207@gmail.com>
Co-authored-by: kaluchi <kaluchi@gmail.com>
Co-authored-by: Tirth Naik <naik.ti@northeastern.edu>
Co-authored-by: Rajesh patel <145205731+Rajeshpatel07@users.noreply.github.com>
Co-authored-by: Keith Schaab <keith.schaab@gmail.com>
Co-authored-by: Ramón Medrano Llamas <45878745+rmedranollamas@users.noreply.github.com>
Co-authored-by: Om Patel <ompatel.aiml@gmail.com>
Co-authored-by: ashishch432 <55024632+ashishch432@users.noreply.github.com>
Co-authored-by: Andrea Alberti <a.alberti82@gmail.com>
Co-authored-by: Ananth Kini <ananthkini1@gmail.com>
Co-authored-by: Yuvraj Angad Singh <36276913+yuvrajangadsingh@users.noreply.github.com>
Co-authored-by: Debasish <90102437+dibyx@users.noreply.github.com>
Co-authored-by: Hashaam Zahid <68606886+Hashaam101@users.noreply.github.com>
Co-authored-by: tison <wander4096@gmail.com>
Co-authored-by: adithya32 <163162210+KumarADITHYA123@users.noreply.github.com>
Co-authored-by: Syed Ayman Quadri <87442765+saymanq@users.noreply.github.com>
Co-authored-by: jvargassanchez-dot <jvargassanchez@google.com>
Co-authored-by: Billy Biggs <bbiggs@google.com>
Co-authored-by: Om Patel <ompatel@google.com>
Co-authored-by: Mukunda Rao Katta <mukunda.vjcs6@gmail.com>
Co-authored-by: nirali <124287834+Niralisj@users.noreply.github.com>
Co-authored-by: Sikandar <ma5161310@gmail.com>
Co-authored-by: Gaurav <39389231+gsquared94@users.noreply.github.com>
Co-authored-by: luisfelipe-alt <luisfelipe@google.com>
Co-authored-by: Cesar Sanchez Coraspe <sanchezcoraspe@google.com>
Co-authored-by: sidhantgoyal-droid <sidhantgoyal@google.com>
Co-authored-by: amelidev <ameliesther@google.com>
Co-authored-by: Vedant Mahajan <vedant.04.mahajan@gmail.com>
Co-authored-by: Jerry Lin <44830071+jerrylin3321@users.noreply.github.com>
Co-authored-by: Jerry Lin <jerrysf@google.com>
Co-authored-by: Chad <chaddiao0@gmail.com>
Co-authored-by: Chad <chaddiao@google.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/core Issues related to User Interface, OS Support, Core Functionality area/platform Issues related to Build infra, Release mgmt, Testing, Eval infra, Capacity, Quota mgmt priority/p1 Important and should be addressed in the near term. size/m A medium sized PR status/pr-nudge-sent

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Proxy defined in environment broken: "TypeError: HttpsProxyAgent is not a constructor" when using proxy options

4 participants