Tools
goose v1.47.0 is mostly a resource-bounding security pass, and quietly stops paying the prompt-cache write premium on one-shot fast-model calls
The AAIF goose project shipped v1.47.0 on 2026-08-21. The changelog reads as a deliberate hardening sweep: bounded XLSX range reads, bounded local image reads, bounded action-required stream admission, narrowed desktop file-read IPC, enforced secure token transport in OAuth, and SQLite bumped to 3.51.3. A separate fix stops paying the prompt-cache write premium on one-shot fast-model calls, which is a direct cost cut for anyone running goose in a loop, and the Gemini OAuth provider is now deprecated.
Source
↳ Follow the thread