Upgrade Goose to v1.53.0 and quote selected conversation text into the composer
Goose v1.53.0 patches GHSA-6mg9-3cvh-9939 and MCP HTTP SSRF, renames deepseek-v4-flash to deepseek-flash, and adds composer quoting, resizable MCP App PiP, live models.dev metadata, Opus 5.5/GPT-6-sol/GPT-6-luna, CLI session rename, and auto-compact at tool boundaries.Why this loop
v1.53.0 is a breaking, security-heavy Goose cut. Older builds still carry GHSA-6mg9-3cvh-9939 and unguarded MCP streamable-HTTP redirects. The deepseek-v4-flash to deepseek-flash rename will miss configured models until every provider config is updated. The quoting action appends selected conversation text to the composer so you stop restating context; resizable Picture-in-Picture keeps MCP Apps on screen while you keep prompting; CLI session rename plus working-directory display on session remove reduce deleting the wrong session. Auto-compact at tool boundaries in the unrolled agent loop, live models.dev metadata with bundled fallback, Opus 5.5, GPT-6-sol, GPT-6-luna, GPT-6.1-sol none reasoning effort, and thinking effort passed to Ollama change which model and effort you pick on long runs. Unattended ACP environments should use the lean ACP-only binary and treat the keyring-hang warning as a real failure mode.
Proposed actions
- Upgrade every workstation and CI image to Goose v1.53.0 from https://github.com/aaif-goose/goose/releases/tag/v1.53.0 so GHSA-6mg9-3cvh-9939 is remediating and MCP streamable-HTTP client redirects are SSRF-guarded.
- In Goose provider configs, replace model id deepseek-v4-flash with deepseek-flash; add Opus 5.5, GPT-6-sol, and GPT-6-luna; for GPT-6.1-sol set reasoning effort to none when you do not want extra reasoning tokens; pass thinking effort through to Ollama; prefer live models.dev metadata (bundled catalog is the fallback).
- In the Goose UI, select the conversation span you want to reuse and trigger the quoting action so that text is appended to the composer before you send the next prompt.
- Keep MCP Apps visible by resizing the Picture-in-Picture window instead of switching away, and let the unrolled agent loop auto-compact at tool boundaries on long sessions rather than restarting them.
- In Goose CLI, use the session rename command to give the current session a durable name and read the working directory shown by session remove before deleting; in unattended ACP, run the lean ACP-only Goose binary and treat the keyring hang warning as blocking.
Agent prompt
Paste into your agent or query via MCP (get_agent_prompt) — free, no extra AI costGoose session task
DevAgentRadar → Goose
You are helping me adopt a real coding-assistant change. Work only from the facts below. Do not invent features.
Context
Assistant: Goose Proposal: Upgrade Goose to v1.53.0 and quote selected conversation text into the composer Summary: Goose v1.53.0 patches GHSA-6mg9-3cvh-9939 and MCP HTTP SSRF, renames deepseek-v4-flash to deepseek-flash, and adds composer quoting, resizable MCP App PiP, live models.dev metadata, Opus 5.5/GPT-6-sol/GPT-6-luna, CLI session rename, and auto-compact at tool boundaries. Primary source: https://github.com/aaif-goose/goose/releases/tag/v1.53.0
Why it matters
v1.53.0 is a breaking, security-heavy Goose cut. Older builds still carry GHSA-6mg9-3cvh-9939 and unguarded MCP streamable-HTTP redirects. The deepseek-v4-flash to deepseek-flash rename will miss configured models until every provider config is updated. The quoting action appends selected conversation text to the composer so you stop restating context; resizable Picture-in-Picture keeps MCP Apps on screen while you keep prompting; CLI session rename plus working-directory display on session remove reduce deleting the wrong session. Auto-compact at tool boundaries in the unrolled agent loop, live models.dev metadata with bundled fallback, Opus 5.5, GPT-6-sol, GPT-6-luna, GPT-6.1-sol none reasoning effort, and thinking effort passed to Ollama change which model and effort you pick on long runs. Unattended ACP environments should use the lean ACP-only binary and treat the keyring-hang warning as a real failure mode.
Suggested actions
- Upgrade every workstation and CI image to Goose v1.53.0 from https://github.com/aaif-goose/goose/releases/tag/v1.53.0 so GHSA-6mg9-3cvh-9939 is remediating and MCP streamable-HTTP client redirects are SSRF-guarded.
- In Goose provider configs, replace model id deepseek-v4-flash with deepseek-flash; add Opus 5.5, GPT-6-sol, and GPT-6-luna; for GPT-6.1-sol set reasoning effort to none when you do not want extra reasoning tokens; pass thinking effort through to Ollama; prefer live models.dev metadata (bundled catalog is the fallback).
- In the Goose UI, select the conversation span you want to reuse and trigger the quoting action so that text is appended to the composer before you send the next prompt.
- Keep MCP Apps visible by resizing the Picture-in-Picture window instead of switching away, and let the unrolled agent loop auto-compact at tool boundaries on long sessions rather than restarting them.
- In Goose CLI, use the session rename command to give the current session a durable name and read the working directory shown by session remove before deleting; in unattended ACP, run the lean ACP-only Goose binary and treat the keyring hang warning as blocking.
Config surfaces this release may change
- MCP servers (high confidence) — check your repo before applying
- context and compaction settings — check your repo before applying
After you finish
Do not report this as applied to DevAgentRadar. You cannot write the visitor's loop.
Tell the human: open https://devagentradar.com/proposals/goose-v1-53-0-upgrade-goose-to-v1-53-0-and-quote-selected-conversation-t and mark Applied, Skipped, or Failed. Proposal id: 28950ed7-76b7-4454-96e8-13de4265f215
Your job
- Restate the change in one sentence.
- Propose a minimal plan for my repo (or a throwaway pilot).
- Implement only what I approve; prefer small diffs and tests.
- Call out risks (permissions, breaking APIs, cost).
Start by confirming you understood the proposal.
Your loop
This browser · no sign-in · not shared as “you”After you run the prompt
Only you can mark this. Agents cannot write your loop.
Your decision stays on this device. A public tally appears after a few votes.