release aidev PRERELEASE SIG 3/5

Gemini CLI nightly 20260726: HTTPS enforced for credential auth provider, session ID rotates on model fallback

Nightly build carrying a credential-path hardening fix — GoogleCredentialsAuthProvider now enforces HTTPS to prevent cleartext leakage — plus a fix that rotates the session ID when the CLI falls back to another model, avoiding stateful API errors. Also filters thought parts from history when context management is off.

PUBLISHED2026-07-26
OBSERVED2026-08-11
AGE16d
SOURCES1
  • GoogleCredentialsAuthProvider enforces HTTPS to prevent cleartext leakage (#28517)
  • Session ID rotates on model fallback to prevent stateful API errors (#28469)
  • Thought parts filtered out of getHistoryTurns when context management is disabled (#28509)
  • Caretaker: issue titles sanitized and wrapped in untrusted context (#28352); comment posted before auto-closing issues (#28411)
  • Tooling: vitest updated to 3.2.4, package-lock files added (#28409)

COMMUNITY

No curated reactions recorded for this event. Facts and takes are kept in separate layers — community context is added by hand, never blended into the record above.