# Gemini CLI 0.54.0-preview.0: credential transport hardening and model-fallback session fixes

> Preview build collecting the 0.54 line so far. Credential auth is now forced over HTTPS to stop cleartext leakage, session IDs rotate on model fallback to avoid stateful API errors, and several history/loop-detection bugs are fixed. Preview channel — not a stable release.

| | |
|---|---|
| **Tool** | Gemini CLI |
| **Version** | v0.54.0-preview.0 |
| **Kind** | release |
| **Published** | 2026-07-28 |
| **Observed** | 2026-08-11 |
| **Significance** | 2/5 |
| **Breaking** | no |
| **Categories** | security, fix, feature |

## What changed


- core: enforce HTTPS for `GoogleCredentialsAuthProvider` to prevent cleartext credential leakage (#28517)
- core: rotate session ID on model fallback to prevent stateful API errors (#28469)
- core: filter thought parts out of `getHistoryTurns` when context management is disabled (#28509)
- core: skip merged function-response turns when finding the active loop (#28565)
- core: explicit tag length/validation in the file keychain (#28523); a2a-server CRLF normalization (#28531)
- caretaker: sanitize and wrap issue titles in untrusted_context; comment before auto-closing issues
- Repo tooling: Firestore dual-locking for the PR generator DB, Antigravity agent runner


## Sources

- [github_release](https://github.com/google-gemini/gemini-cli/releases/tag/v0.54.0-preview.0) — retrieved 2026-08-11

## Community

_No curated reactions recorded. Facts and community takes are kept in separate layers
and never blended._

---
Canonical: https://changelogs.info/gemini-cli/v0-54-0-preview-0
Entity: https://changelogs.info/gemini-cli
Event ID: `evt_2026-07-28_gemini-cli_v0-54-0-preview-0`
Licence: event synthesis © changelogs.info, CC BY 4.0. Linked sources belong to their vendors.
