$ the-wire · showcase
Claude Code ships Sonnet 5.5 as default, Goose patches a security advisory
By RepoJournal · Filed · About Agentic Coding · Composed from the cited sources · methodology
A model swap and pricing change lands in Claude Code, Goose routes a GHSA advisory to a fix, and Codex and Gemini CLI both ship fixes aimed at long-standing operational pain.
v2.1.284 anthropics/claude-code
Sonnet now defaults to claude-sonnet-5-5 with a 1M context window and $2/$10 per Mtok ($0.20/Mtok cache reads), and /usage plus the status line now show gateway spend in dollars instead of bare counts. Auto mode also gains a "Yes, but ask again next time" answer for one-off reads outside your working directories.
fix(security): remediate GHSA-6mg9-3cvh-9939 (#12537) aaif-goose/goose
The fix for GHSA-6mg9-3cvh-9939 has landed in the Goose tree. If you run Goose from a build older than this commit, you're running the vulnerable version; pull the fixed build before your next session.
fix(auth): prevent infinite auth loop from file contention, headless keyring, and supervisor state drops (#28341) google-gemini/gemini-cli
An infinite auth loop that hit Windows, WSL, and headless users is fixed: file contention with companion tools like the Gemini Code Assist VS Code extension, a headless or locked libsecret keyring now falling back to encrypted file storage, and security.auth.selectedType being dropped across supervisor relaunches (exit code 199) were all in the loop.
Reuse the HTTP connection pool for remote plugin requests openai/codex
Remote plugin requests now share one lazily initialized, route-aware HTTP connection pool instead of building a fresh client per service configuration, so plugin traffic reuses connections. Newly constructed inputs still get their own pool.
chore(llms): bump @ai-sdk/amazon-bedrock to ^5.0.96 so unclassified Bedrock models stop receiving reasoningConfig (#14602) cline/cline
Bumping @ai-sdk/amazon-bedrock to ^5.0.96 stops the adapter from sending reasoningConfig for models it can't classify as Anthropic or OpenAI; Bedrock rejects that field, so application inference-profile ARNs, Nova Micro and other unlisted families were failing outright. Upgrade if your Bedrock models error with "Model returned empty response"-adjacent symptoms after enabling reasoning.
fix(llms,agents): distinguish content-filtered turns from empty responses (#13302) cline/cline
Content-filtered turns are no longer reported as "Model returned empty response," a message that previously accounted for roughly 3.6k occurrences across about 1.1k users per week with no way to split them by cause. Zero-content stops and filtered turns now give you different signals.
fix(provider): passing thinking effort to ollama models aaif-goose/goose
Setting thinking effort to "none" now actually reaches Ollama: reasoning_effort was only sent for OpenAI and xAI model names, so Ollama kept thinking regardless. Off maps to none for all models, low/medium/high pass through for reasoning models only, and max maps to high.
Action items
- → Update Goose to a build containing the GHSA-6mg9-3cvh-9939 fix aaif-goose/goose [immediate]
- → Update cline to a build with @ai-sdk/amazon-bedrock ^5.0.96 if you use Bedrock inference profiles or Nova models cline/cline [plan]