--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-cb99e9b2ac
2026-09-27 00:28:13.807491+00:00
--------------------------------------------------------------------------------

Name        : goose
Product     : Fedora 45
Version     : 1.45.0
Release     : 1.fc45
URL         : https://github.com/aaif-goose/goose
Summary     : Extensible AI agent client
Description :
Goose is your on-machine AI agent, capable of automating complex development
tasks from start to finish. More than just code suggestions, goose can build
entire projects from scratch, write and execute code, debug failures,
orchestrate workflows, and interact with external APIs - autonomously.

Whether you're prototyping an idea, refining existing code, or managing
intricate engineering pipelines, goose adapts to your workflow and executes
tasks with precision.

Designed for maximum flexibility, goose works with any LLM and supports
multi-model configuration to optimize performance and cost, seamlessly
integrates with MCP servers, and is available as both a desktop app as well as
CLI - making it the ultimate AI assistant for developers who want to move
faster and focus on innovation.

--------------------------------------------------------------------------------
Update Information:

Update to 1.45.0
--------------------------------------------------------------------------------
ChangeLog:

* Thu Aug 20 2026 thepetk <[email protected]> - 1.45.0-1
- Update to version 1.45.0
- Security fix: arbitrary command execution in goose CLI via `goose review` 
(GHSA-r5pp-p5r8-466r)
- /status slash command in CLI for session inspection
- /model slash command for session model switching, with tab completion and 
provider switching
- goose review local code review command
- tui command on goose-cli with diff viewer
- Hooks system for extensibility (PreToolUse denial, Stop hook context)
- Global hints loading from ~/.agents/AGENTS.md
- Structured summary output with template rendering for compaction
- Configurable GOOSE_DOCS_ROOT for air-gapped docs access
- Allow disabling built-in skills
- Option to disable automatic update downloads
- Track cache tokens and per-message usage/cost stats
- Unified thinking effort control across providers; Opus 5 adaptive thinking 
support
- Upgrade to rmcp 2.0
- New providers: Together AI, EmpirioLabs, OrcaRouter, NEAR AI Cloud, 
Perplexity, Alibaba (Qwen via DashScope), Databricks AI Gateway, Scaleway, 
Vercel AI Gateway, xAI SuperGrok, iFlytek Spark/Astron MaaS, Fireworks AI, 
OllamaCloudProvider, Sakana AI
- MLX support for local inference provider
- Nushell terminal and completion support
- Azure Entra ID bearer token auth via AZURE_OPENAI_AD_TOKEN
- Accept string values for GOOSE_CONTEXT_LIMIT
- Quarterly option for scheduler
- Worktree-aware directory switcher
- Restore dynamic model discovery and current Grok support
- Update DeepSeek model names to v4 API
- Gate rcgen aws_lc_rs feature behind rustls-tls
- Fail closed on unverifiable update provenance
- Bump nostr to 0.44.6 to clear RUSTSEC-2026-0216
- Numerous provider, ACP, local-inference, and session-handling bug fixes
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2514571 - CVE-2026-72718 goose: Goose: Arbitrary command execution 
via malicious Git configuration in `goose review` [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2514571
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-cb99e9b2ac' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

-- 
_______________________________________________
package-announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to