Gemini CLI 0.54.0: credential transport hardening and session-state fixes
A stable release dominated by core fixes and two credential-handling hardening changes. Matters mainly to users hitting model fallback errors, stale-context bugs, or running the CLI against non-HTTPS credential endpoints.
PUBLISHED2026-08-06
OBSERVED2026-08-11
AGE5d
SOURCES1
- Google credentials auth provider now requires HTTPS, closing a cleartext-leak path
- File keychain enforces an explicit tag length and validates it
- Session ID rotates on model fallback, avoiding stateful API errors afterwards
- Thought parts filtered out of history turns when context management is off
- Merged function-response turns skipped when locating the active loop
- a2a-server normalizes CRLF to LF in proposed content
- Issue titles sanitized and wrapped in untrusted context (caretaker automation)
- Remaining entries are release plumbing and an internal PR-generator service
COMMUNITY
No curated reactions recorded for this event. Facts and takes are kept in separate layers — community context is added by hand, never blended into the record above.