Skip to content
Proposals/Upgrade Goose to v1.53.0 and quote selected conv
proposalteamP5Worth a lookGoose

Upgrade Goose to v1.53.0 and quote selected conversation text into the composer

Goose v1.53.0 patches GHSA-6mg9-3cvh-9939 and MCP HTTP SSRF, renames deepseek-v4-flash to deepseek-flash, and adds composer quoting, resizable MCP App PiP, live models.dev metadata, Opus 5.5/GPT-6-sol/GPT-6-luna, CLI session rename, and auto-compact at tool boundaries.

Why this loop

v1.53.0 is a breaking, security-heavy Goose cut. Older builds still carry GHSA-6mg9-3cvh-9939 and unguarded MCP streamable-HTTP redirects. The deepseek-v4-flash to deepseek-flash rename will miss configured models until every provider config is updated. The quoting action appends selected conversation text to the composer so you stop restating context; resizable Picture-in-Picture keeps MCP Apps on screen while you keep prompting; CLI session rename plus working-directory display on session remove reduce deleting the wrong session. Auto-compact at tool boundaries in the unrolled agent loop, live models.dev metadata with bundled fallback, Opus 5.5, GPT-6-sol, GPT-6-luna, GPT-6.1-sol none reasoning effort, and thinking effort passed to Ollama change which model and effort you pick on long runs. Unattended ACP environments should use the lean ACP-only binary and treat the keyring-hang warning as a real failure mode.

Proposed actions

  1. Upgrade every workstation and CI image to Goose v1.53.0 from https://github.com/aaif-goose/goose/releases/tag/v1.53.0 so GHSA-6mg9-3cvh-9939 is remediating and MCP streamable-HTTP client redirects are SSRF-guarded.
  2. In Goose provider configs, replace model id deepseek-v4-flash with deepseek-flash; add Opus 5.5, GPT-6-sol, and GPT-6-luna; for GPT-6.1-sol set reasoning effort to none when you do not want extra reasoning tokens; pass thinking effort through to Ollama; prefer live models.dev metadata (bundled catalog is the fallback).
  3. In the Goose UI, select the conversation span you want to reuse and trigger the quoting action so that text is appended to the composer before you send the next prompt.
  4. Keep MCP Apps visible by resizing the Picture-in-Picture window instead of switching away, and let the unrolled agent loop auto-compact at tool boundaries on long sessions rather than restarting them.
  5. In Goose CLI, use the session rename command to give the current session a durable name and read the working directory shown by session remove before deleting; in unattended ACP, run the lean ACP-only Goose binary and treat the keyring hang warning as blocking.

Agent prompt

Paste into your agent or query via MCP (get_agent_prompt) — free, no extra AI cost

Goose session task

DevAgentRadar → Goose

You are helping me adopt a real coding-assistant change. Work only from the facts below. Do not invent features.

Context

Assistant: Goose Proposal: Upgrade Goose to v1.53.0 and quote selected conversation text into the composer Summary: Goose v1.53.0 patches GHSA-6mg9-3cvh-9939 and MCP HTTP SSRF, renames deepseek-v4-flash to deepseek-flash, and adds composer quoting, resizable MCP App PiP, live models.dev metadata, Opus 5.5/GPT-6-sol/GPT-6-luna, CLI session rename, and auto-compact at tool boundaries. Primary source: https://github.com/aaif-goose/goose/releases/tag/v1.53.0

Why it matters

v1.53.0 is a breaking, security-heavy Goose cut. Older builds still carry GHSA-6mg9-3cvh-9939 and unguarded MCP streamable-HTTP redirects. The deepseek-v4-flash to deepseek-flash rename will miss configured models until every provider config is updated. The quoting action appends selected conversation text to the composer so you stop restating context; resizable Picture-in-Picture keeps MCP Apps on screen while you keep prompting; CLI session rename plus working-directory display on session remove reduce deleting the wrong session. Auto-compact at tool boundaries in the unrolled agent loop, live models.dev metadata with bundled fallback, Opus 5.5, GPT-6-sol, GPT-6-luna, GPT-6.1-sol none reasoning effort, and thinking effort passed to Ollama change which model and effort you pick on long runs. Unattended ACP environments should use the lean ACP-only binary and treat the keyring-hang warning as a real failure mode.

Suggested actions

  1. Upgrade every workstation and CI image to Goose v1.53.0 from https://github.com/aaif-goose/goose/releases/tag/v1.53.0 so GHSA-6mg9-3cvh-9939 is remediating and MCP streamable-HTTP client redirects are SSRF-guarded.
  2. In Goose provider configs, replace model id deepseek-v4-flash with deepseek-flash; add Opus 5.5, GPT-6-sol, and GPT-6-luna; for GPT-6.1-sol set reasoning effort to none when you do not want extra reasoning tokens; pass thinking effort through to Ollama; prefer live models.dev metadata (bundled catalog is the fallback).
  3. In the Goose UI, select the conversation span you want to reuse and trigger the quoting action so that text is appended to the composer before you send the next prompt.
  4. Keep MCP Apps visible by resizing the Picture-in-Picture window instead of switching away, and let the unrolled agent loop auto-compact at tool boundaries on long sessions rather than restarting them.
  5. In Goose CLI, use the session rename command to give the current session a durable name and read the working directory shown by session remove before deleting; in unattended ACP, run the lean ACP-only Goose binary and treat the keyring hang warning as blocking.

Config surfaces this release may change

  • MCP servers (high confidence) — check your repo before applying
  • context and compaction settings — check your repo before applying

After you finish

Do not report this as applied to DevAgentRadar. You cannot write the visitor's loop.

Tell the human: open https://devagentradar.com/proposals/goose-v1-53-0-upgrade-goose-to-v1-53-0-and-quote-selected-conversation-t and mark Applied, Skipped, or Failed. Proposal id: 28950ed7-76b7-4454-96e8-13de4265f215

Your job

  1. Restate the change in one sentence.
  2. Propose a minimal plan for my repo (or a throwaway pilot).
  3. Implement only what I approve; prefer small diffs and tests.
  4. Call out risks (permissions, breaking APIs, cost).

Start by confirming you understood the proposal.

agentmcpmodelsecurityideRelease source ↗

Your loop

This browser · no sign-in · not shared as “you”

After you run the prompt

Only you can mark this. Agents cannot write your loop.

Your decision stays on this device. A public tally appears after a few votes.

Originating release signal

Goosev1.53.0Oct 2, 2026

v1.53.0

Resizable Picture-in-Picture window for MCP Apps #12417 · Fetch model metadata from models.dev live with bundled fallback #12560 · Quoting action to append selected conversation text to composer #12536 · Lean ACP-only Goose binary #11961 · Model discovery API for GDK Provider #12497 · +30 more changes
Verified excerpt — the source's own words

✨ Features

  • Resizable Picture-in-Picture window for MCP Apps #12417

  • Fetch model metadata from models.dev live with bundled fallback #12560

  • Quoting action to append selected conversation text to composer #12536

  • Lean ACP-only Goose binary #11961

  • Model discovery API for GDK Provider #12497

  • Meta Muse Code provider #11765

  • Support for Opus 5.5, GPT-6-sol, GPT-6-luna #12447

  • Session rename command in CLI #12236

  • Show working directory in session remove command #12232

  • GDK agent loop runs on wasm32 #12569

🐛 Bug Fixes

  • Session naming and "none" reasoning effort for GPT-6.1-sol #12605

Excerpt ends here — this release continues at the source ↗.

Primary source ↗