Upgrade Gemini CLI to v0.54.0 for session-ID rotation on model fallback
v0.54.0 rotates the session ID on model fallback, enforces HTTPS for GoogleCredentialsAuthProvider, filters thought parts when context management is disabled, skips merged function-response turns in the active loop, and tightens file keychain tag validation.Why this loop
Gemini CLI v0.54.0 changes session, auth, history, and keychain behavior. Model fallback now rotates the session ID so a failed stateful API session is not reused. GoogleCredentialsAuthProvider is forced to HTTPS to stop cleartext credential leakage. getHistoryTurns drops thought parts when context management is disabled. Active-loop detection skips merged function-response turns. File keychain tags require explicit length and validation. Caretaker/a2a also sanitize issue titles in untrusted_context, comment before auto-close, and normalize CRLF to LF in getProposedContent. Pin to 0.54.0 so wrappers pick up these fixes instead of compensating in app code.
Proposed actions
- Pin Gemini CLI to v0.54.0: npm install -g @google/gemini-cli@0.54.0 && gemini --version. Abort if the printed version is not 0.54.0.
- Reproduce model fallback (fail the primary model, then use a working fallback). Log the session ID on the failed turn and on the first successful fallback turn; assert the ID changed so the fallback request does not reuse the failed session.
- Search the repo for GoogleCredentialsAuthProvider and credential base URLs. Replace any http:// credential endpoints with https:// and throw if the URL protocol is not https, matching the v0.54.0 cleartext-leakage fix.
- With context management disabled, call getHistoryTurns and assert thought parts are omitted from the returned turns before they are sent on the next model request.
- When finding the active tool loop, skip merged function-response turns so they are not treated as the loop head. On file keychain writes, reject tags that fail explicit length checks or validation before persist.
Agent prompt
Paste into your agent or query via MCP (get_agent_prompt) — free, no extra AI costGoogle Antigravity / agent task
DevAgentRadar → Google Antigravity
Goal: turn this release signal into a safe pilot plan for my stack.
Context
Assistant: Gemini CLI Proposal: Upgrade Gemini CLI to v0.54.0 for session-ID rotation on model fallback Summary: v0.54.0 rotates the session ID on model fallback, enforces HTTPS for GoogleCredentialsAuthProvider, filters thought parts when context management is disabled, skips merged function-response turns in the active loop, and tightens file keychain tag validation. Primary source: https://github.com/google-gemini/gemini-cli/releases/tag/v0.54.0
Why it matters
Gemini CLI v0.54.0 changes session, auth, history, and keychain behavior. Model fallback now rotates the session ID so a failed stateful API session is not reused. GoogleCredentialsAuthProvider is forced to HTTPS to stop cleartext credential leakage. getHistoryTurns drops thought parts when context management is disabled. Active-loop detection skips merged function-response turns. File keychain tags require explicit length and validation. Caretaker/a2a also sanitize issue titles in untrusted_context, comment before auto-close, and normalize CRLF to LF in getProposedContent. Pin to 0.54.0 so wrappers pick up these fixes instead of compensating in app code.
Suggested actions
- Pin Gemini CLI to v0.54.0: npm install -g @google/gemini-cli@0.54.0 && gemini --version. Abort if the printed version is not 0.54.0.
- Reproduce model fallback (fail the primary model, then use a working fallback). Log the session ID on the failed turn and on the first successful fallback turn; assert the ID changed so the fallback request does not reuse the failed session.
- Search the repo for GoogleCredentialsAuthProvider and credential base URLs. Replace any http:// credential endpoints with https:// and throw if the URL protocol is not https, matching the v0.54.0 cleartext-leakage fix.
- With context management disabled, call getHistoryTurns and assert thought parts are omitted from the returned turns before they are sent on the next model request.
- When finding the active tool loop, skip merged function-response turns so they are not treated as the loop head. On file keychain writes, reject tags that fail explicit length checks or validation before persist.
After you finish
Do not report this as applied to DevAgentRadar. You cannot write the visitor's loop.
Tell the human: open https://devagentradar.com/proposals/gemini-cli-v0-54-0-upgrade-gemini-cli-to-v0-54-0-for-session-id-rotation and mark Applied, Skipped, or Failed. Proposal id: 6a7cc2ab-4b09-49b8-98e7-7840d3151166
Please:
- Map the change to concrete pilot steps
- Flag security / permission implications
- Keep the pilot reversible
Your loop
This browser · no sign-in · not shared as “you”After you run the prompt
Only you can mark this. Agents cannot write your loop.
Your decision stays on this device. A public tally appears after a few votes.