release aidev SIG 2/5

Gemini CLI 0.54.0: credential transport hardening and session-state fixes

A stable release dominated by core fixes and two credential-handling hardening changes. Matters mainly to users hitting model fallback errors, stale-context bugs, or running the CLI against non-HTTPS credential endpoints.

PUBLISHED2026-08-06
OBSERVED2026-08-11
AGE5d
SOURCES1
  • Google credentials auth provider now requires HTTPS, closing a cleartext-leak path
  • File keychain enforces an explicit tag length and validates it
  • Session ID rotates on model fallback, avoiding stateful API errors afterwards
  • Thought parts filtered out of history turns when context management is off
  • Merged function-response turns skipped when locating the active loop
  • a2a-server normalizes CRLF to LF in proposed content
  • Issue titles sanitized and wrapped in untrusted context (caretaker automation)
  • Remaining entries are release plumbing and an internal PR-generator service

COMMUNITY

No curated reactions recorded for this event. Facts and takes are kept in separate layers — community context is added by hand, never blended into the record above.