# Gemini CLI nightly 20260726: HTTPS enforced for credential auth provider, session ID rotates on model fallback

> Nightly build carrying a credential-path hardening fix — GoogleCredentialsAuthProvider now enforces HTTPS to prevent cleartext leakage — plus a fix that rotates the session ID when the CLI falls back to another model, avoiding stateful API errors. Also filters thought parts from history when context management is off.

| | |
|---|---|
| **Tool** | Gemini CLI |
| **Version** | v0.54.0-nightly.20260726.g3818efbbf |
| **Kind** | release |
| **Published** | 2026-07-26 |
| **Observed** | 2026-08-11 |
| **Significance** | 3/5 |
| **Breaking** | no |
| **Categories** | security, fix |

## What changed


- `GoogleCredentialsAuthProvider` enforces HTTPS to prevent cleartext leakage (#28517)
- Session ID rotates on model fallback to prevent stateful API errors (#28469)
- Thought parts filtered out of `getHistoryTurns` when context management is disabled (#28509)
- Caretaker: issue titles sanitized and wrapped in untrusted context (#28352); comment posted before auto-closing issues (#28411)
- Tooling: vitest updated to 3.2.4, package-lock files added (#28409)


## Sources

- [github_release](https://github.com/google-gemini/gemini-cli/releases/tag/v0.54.0-nightly.20260726.g3818efbbf) — retrieved 2026-08-11

## Community

_No curated reactions recorded. Facts and community takes are kept in separate layers
and never blended._

---
Canonical: https://changelogs.info/gemini-cli/v0-54-0-nightly-20260726-g3818efbbf
Entity: https://changelogs.info/gemini-cli
Event ID: `evt_2026-07-26_gemini-cli_v0-54-0-nightly-20260726-g3818efbbf`
Licence: event synthesis © changelogs.info, CC BY 4.0. Linked sources belong to their vendors.
