# Gemini CLI 0.54.0: credential transport hardening and session-state fixes

> A stable release dominated by core fixes and two credential-handling hardening changes. Matters mainly to users hitting model fallback errors, stale-context bugs, or running the CLI against non-HTTPS credential endpoints.

| | |
|---|---|
| **Tool** | Gemini CLI |
| **Version** | v0.54.0 |
| **Kind** | release |
| **Published** | 2026-08-06 |
| **Observed** | 2026-08-11 |
| **Significance** | 2/5 |
| **Breaking** | no |
| **Categories** | fix, security |

## What changed


- Google credentials auth provider now requires HTTPS, closing a cleartext-leak path
- File keychain enforces an explicit tag length and validates it
- Session ID rotates on model fallback, avoiding stateful API errors afterwards
- Thought parts filtered out of history turns when context management is off
- Merged function-response turns skipped when locating the active loop
- a2a-server normalizes CRLF to LF in proposed content
- Issue titles sanitized and wrapped in untrusted context (caretaker automation)
- Remaining entries are release plumbing and an internal PR-generator service


## Sources

- [github_release](https://github.com/google-gemini/gemini-cli/releases/tag/v0.54.0) — retrieved 2026-08-11

## Community

_No curated reactions recorded. Facts and community takes are kept in separate layers
and never blended._

---
Canonical: https://changelogs.info/gemini-cli/v0-54-0
Entity: https://changelogs.info/gemini-cli
Event ID: `evt_2026-08-06_gemini-cli_v0-54-0`
Licence: event synthesis © changelogs.info, CC BY 4.0. Linked sources belong to their vendors.
