release aidev PRERELEASE SIG 2/5

Gemini CLI 0.54.0-preview.0: credential transport hardening and model-fallback session fixes

Preview build collecting the 0.54 line so far. Credential auth is now forced over HTTPS to stop cleartext leakage, session IDs rotate on model fallback to avoid stateful API errors, and several history/loop-detection bugs are fixed. Preview channel — not a stable release.

PUBLISHED2026-07-28
OBSERVED2026-08-11
AGE14d
SOURCES1
  • core: enforce HTTPS for GoogleCredentialsAuthProvider to prevent cleartext credential leakage (#28517)
  • core: rotate session ID on model fallback to prevent stateful API errors (#28469)
  • core: filter thought parts out of getHistoryTurns when context management is disabled (#28509)
  • core: skip merged function-response turns when finding the active loop (#28565)
  • core: explicit tag length/validation in the file keychain (#28523); a2a-server CRLF normalization (#28531)
  • caretaker: sanitize and wrap issue titles in untrusted_context; comment before auto-closing issues
  • Repo tooling: Firestore dual-locking for the PR generator DB, Antigravity agent runner

COMMUNITY

No curated reactions recorded for this event. Facts and takes are kept in separate layers — community context is added by hand, never blended into the record above.