This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+5 more
Affected surfaces
Summary
AI summaryFixed re_auth without show_browser:true which previously destroyed all concurrent session credentials.
Full changelog
Auth Stability Improvements
Changes
- Extended state file expiry from 24h to 7 days — Google cookies last 2-4 weeks so daily expiry was causing unnecessary auth prompts
- Touch state file on every successful
validateWithRetryso the 7-day clock resets on each use rather than from lastsetup_auth - Block headless
re_authwithoutshow_browser:true— calling it headlessly wiped credentials then failed to restore them, destroying auth for all concurrent sessions - Extended
retention-enginepolicy_sessionfrom 1 day to 14 days to match
Bug Fix
re_auth called without show_browser:true now returns a clear error instead of destroying credentials.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Pantheon-Security/notebooklm-mcp-secure
Security-hardened NotebookLM MCP with post-quantum encryption (ML-KEM-768), GDPR/SOC2/CSSF compliance, and 14 security layers. Query Google's Gemini-grounded research from Claude and AI agents.
Related context
Beta — feedback welcome: [email protected]