-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-5c0d326b15 2026-09-27 01:11:44.345924+00:00 --------------------------------------------------------------------------------
Name : goose Product : Fedora 43 Version : 1.45.0 Release : 1.fc43 URL : https://github.com/aaif-goose/goose Summary : Extensible AI agent client Description : Goose is your on-machine AI agent, capable of automating complex development tasks from start to finish. More than just code suggestions, goose can build entire projects from scratch, write and execute code, debug failures, orchestrate workflows, and interact with external APIs - autonomously. Whether you're prototyping an idea, refining existing code, or managing intricate engineering pipelines, goose adapts to your workflow and executes tasks with precision. Designed for maximum flexibility, goose works with any LLM and supports multi-model configuration to optimize performance and cost, seamlessly integrates with MCP servers, and is available as both a desktop app as well as CLI - making it the ultimate AI assistant for developers who want to move faster and focus on innovation. -------------------------------------------------------------------------------- Update Information: Update to 1.45.0 -------------------------------------------------------------------------------- ChangeLog: * Thu Aug 20 2026 thepetk <[email protected]> - 1.45.0-1 - Update to version 1.45.0 - Security fix: arbitrary command execution in goose CLI via `goose review` (GHSA-r5pp-p5r8-466r) - /status slash command in CLI for session inspection - /model slash command for session model switching, with tab completion and provider switching - goose review local code review command - tui command on goose-cli with diff viewer - Hooks system for extensibility (PreToolUse denial, Stop hook context) - Global hints loading from ~/.agents/AGENTS.md - Structured summary output with template rendering for compaction - Configurable GOOSE_DOCS_ROOT for air-gapped docs access - Allow disabling built-in skills - Option to disable automatic update downloads - Track cache tokens and per-message usage/cost stats - Unified thinking effort control across providers; Opus 5 adaptive thinking support - Upgrade to rmcp 2.0 - New providers: Together AI, EmpirioLabs, OrcaRouter, NEAR AI Cloud, Perplexity, Alibaba (Qwen via DashScope), Databricks AI Gateway, Scaleway, Vercel AI Gateway, xAI SuperGrok, iFlytek Spark/Astron MaaS, Fireworks AI, OllamaCloudProvider, Sakana AI - MLX support for local inference provider - Nushell terminal and completion support - Azure Entra ID bearer token auth via AZURE_OPENAI_AD_TOKEN - Accept string values for GOOSE_CONTEXT_LIMIT - Quarterly option for scheduler - Worktree-aware directory switcher - Restore dynamic model discovery and current Grok support - Update DeepSeek model names to v4 API - Gate rcgen aws_lc_rs feature behind rustls-tls - Fail closed on unverifiable update provenance - Bump nostr to 0.44.6 to clear RUSTSEC-2026-0216 - Numerous provider, ACP, local-inference, and session-handling bug fixes * Thu Jun 25 2026 thepetk <[email protected]> - 1.39.0-1 - Update to version 1.39.0 - /status slash command in CLI for session inspection - ACP method for managing recipes and session extensions - Typed request/response for add/get session extensions in ACP - Load session using ACP - Elicitation method for ACP with improvements - Elicitation decline and cancel actions propagation - Recipe handling in new_session - Use ACP to manage global config and session extensions - Change working directory using ACP - ACP cancel race condition fix - Load global hints from ~/.agents/AGENTS.md - Azure Entra ID bearer token auth via AZURE_OPENAI_AD_TOKEN - Track cache tokens for accurate cost reporting - Quarterly option for scheduler - Option to disable automatic update downloads - Accept string values for GOOSE_CONTEXT_LIMIT - EmpirioLabs as a declarative OpenAI-compatible provider - OrcaRouter as a declarative OpenAI-compatible provider - Together AI declarative provider - Add option for overriding API URL for Moonshot provider - MCP extensions support in open plugins - Peek mode for async background tasks in summon - Context, working_dir, and metadata parameters for summon delegate tasks - Move OpenAI provider and API client into goose-providers crate - Delete embeddings support (unused) - Accept JSON-encoded string for autovisualiser data parameter - Send User-Agent on URL image fetches in developer/read_image - Allow unlisted models in search - Do not pass temperature to ChatGPT Codex provider - Sanitize extension environment maps - Refresh provider when session working directory changes - Use refreshed gcloud token after reauth (retry Vertex AI on 401/403) - Start a turn when /goal or /grind is set - Dedupe duplicate tool-call ids within a turn - Resolve bundled extensions from discovery - Custom OpenAI provider dropping port when URL scheme is omitted - Clear rejected OAuth credentials after refresh - Keep extended thinking within the Anthropic output cap - Preserve custom API path in OpenAI base_url derivation - Repair PATH for plugin hook commands - Fall back to default provider when resuming session with unavailable provider - Read meta.n_ctx from /v1/models to fix context limit for local OpenAI servers - Show resolved skill supporting file paths - Record OpenAI-native cached_tokens in usage metering - Detect image paths with spaces - Ensure tool request timestamp precedes tool response timestamp - Inherit login-shell PATH in spawned subagents - Skip non-recipe project config files in summon - Evict stale completed tasks to prevent unbounded memory growth in summon - Warn on unmatched extension names in summon delegate - Make context exceeded checker more precise - Include agentInfo in ACP initialize response - Check for responses API support in Databricks -------------------------------------------------------------------------------- References: [ 1 ] Bug #2514571 - CVE-2026-72718 goose: Goose: Arbitrary command execution via malicious Git configuration in `goose review` [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2514571 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5c0d326b15' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
