# Changelog

## New project activity feed  
**September 24, 2026**  
As part of our ongoing work to simplify the [Netlify dashboard](https://app.netlify.com/), we’ve added an activity feed to the project overview page. It’s available on all plans and adapts to how your project is set up.

Now when you open a project, the activity feed gives you a snapshot of your project’s latest updates, with quick access to:

- Production versions of your project, including the version last published  
- Preview versions of your project  
- Agent runs, so you can see what agents are working on and what you and your teammates have prompted

This means that instead of tracking down Production deploy links, Deploy Preview links, branch deploy links, and your agent runs list separately, you can now see where your project stands at a glance in one single spot.

The feed also suggests next steps to help you get started. It’s one of several dashboard improvements we’re gradually rolling out to simplify the Netlify experience, so you may have spotted a few already, with more to come.

## Security Update: Critical Next.js vulnerability in ImageResponse  
**September 22, 2026**  
The Next.js team has disclosed a [critical severity vulnerability](https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j) in an upstream dependency that can lead to remote code execution when `ImageResponse` renders untrusted input. It is patched in **15.5.26** and **16.3.6**. Applications that do not pass untrusted input into `ImageResponse` are not expected to be affected. Here’s what Netlify customers need to know.

### Vulnerabilities

- [GHSA-vcvr-r3jv-pc5j](https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j) / CVE-2026-94545 — Remote Code Execution in `next/og``ImageResponse`. Critical. Patched in 15.5.26 and 16.3.6.

### Impact on Netlify  
Netlify sites are affected only if they use `ImageResponse` **and** the image it generates includes untrusted input — text, or an image loaded from the request. Sites that don’t use `ImageResponse`, or that only render trusted content through it, are **not affected**.

For sites that do, the impact is limited to a crashed function invocation, not code execution. **On Netlify, this has minimal impact**: our autoscaling serverless architecture means that a malicious request resulting in a crashed function does not affect other requests. However, active exploitation could increase your function costs.

### What should I do?  
We strongly recommend upgrading as soon as possible to patched releases:

- `next` 15.5.26 or later, or 16.3.6 or later, then redeploy.

Until you can upgrade, do not place untrusted input inside elements passed to `ImageResponse`. Escape it as XML before rendering, or keep it out of the generated image entirely.

Note that any publicly available deploy previews and branch deploys may remain vulnerable until they are [automatically deleted](https://docs.netlify.com/deploy/manage-deploys/manage-deploys-overview/#automatic-deploy-deletion). Consider [deleting these deploys manually](https://docs.netlify.com/deploy/manage-deploys/manage-deploys-overview/#manual-deploy-deletion-through-the-netlify-ui).

### Resources

- [Next.js security advisory (GHSA-vcvr-r3jv-pc5j)](https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j)  
- [Next.js Security Update for a Critical Upstream Issue](https://nextjs.org/blog/nextjs-security-update-september-22-2026)  
- [Next.js security advisories](https://github.com/vercel/next.js/security)

## Claude Opus 5.5 now available in AI Gateway and Agent Runners  
**September 22, 2026**  
Anthropic’s Claude Opus 5.5 model is now available through Netlify’s AI Gateway and Agent Runners with zero configuration required.

Use the Anthropic SDK directly in your Netlify Functions without managing API keys or authentication. AI Gateway handles everything automatically. Here’s an example using Claude Opus 5.5:

```javascript
import Anthropic from '@anthropic-ai/sdk';

export default async () => {

const anthropic = new Anthropic();

const response = await anthropic.messages.create({

model: 'claude-opus-5-5',

max_tokens: 4096,

output_config: { effort: 'medium' },

messages: [
      {
        role: 'user',
        content: 'How can AI improve my coding?',
      },
    ],
  });

return new Response(JSON.stringify(response), {
    headers: { 'Content-Type': 'application/json' },
  });
};
```

Claude Opus 5.5 is also available across Background Functions, Scheduled Functions, and Edge Functions. You get automatic access to Netlify’s caching, rate limiting, and authentication infrastructure.

Learn more in the [AI Gateway documentation](https://docs.netlify.com/build/ai-gateway/overview/) and [Agent Runners documentation](https://docs.netlify.com/build/build-with-ai/agent-runners/overview/).

## GPT-6 Sol and GPT-6 Luna now available in AI Gateway and Agent Runners  
**September 22, 2026**  
OpenAI’s GPT-6 Sol and GPT-6 Luna models are now available through Netlify’s AI Gateway and Agent Runners with zero configuration required.

Use the OpenAI SDK directly in your Netlify Functions without managing API keys or authentication. AI Gateway handles everything automatically. Here’s an example using GPT-6 Sol with the Responses API:

```javascript
import OpenAI from 'openai';

export default async () => {

const openai = new OpenAI();

const response = await openai.responses.create({

model: 'gpt-6-sol',

input: 'Give a concise explanation of how AI works.',
    });

return Response.json(response);
};
```

GPT-6 Sol and GPT-6 Luna are also available across Scheduled Functions, Background Functions, and Edge Functions. You get automatic access to Netlify’s caching, rate limiting, and authentication infrastructure.

## TypeSafe Jev now available in AI Gateway  
**September 17, 2026**  
TypeSafe’s Jev model is now available through Netlify’s AI Gateway with zero configuration required.

Install `@typesafe-ai/sdk` and use it directly in your Netlify Functions — no API keys to create, no provider config, no base URLs to wire up. AI Gateway handles credentials automatically, and usage is billed to your Netlify credits like every other model in the gateway.

Jev is TypeSafe’s first “System One” model, and it works differently from the chat models you’re used to. Instead of generating prose, you send it your program state along with a set of typed questions, and it returns typed answers with calibrated probabilities. There are three question primitives: `choice` picks one option from a set, `score` rates against ordered levels, and `noul` returns a yes/no probability between 0 and 1. Answers are constrained to the options you declare, so there’s no JSON parsing or schema coercion on your end.

Every question in a request is evaluated in parallel against the same state, which means batching a dozen questions into one call costs little more than asking one. State and questions share a budget of roughly 32,000 tokens — about 150,000 characters of English text — and TypeSafe reports end-to-end response times of 70–500ms, making Jev a good fit for classification, routing, extraction, scoring, and guardrail checks on the request path. The SDK defaults to the `jev-latest` alias, currently `jev-1.13.0`, and requires Node.js 20 or newer.

Here’s a Function that routes an incoming contact form submission to sales, support, or spam:

```javascript
import type { Config, Context } from "@netlify/functions";
import { choice, TypeSafeClient } from "@typesafe-ai/sdk";

export default async (req: Request, context: Context) => {
  const client = new TypeSafeClient();

const { answers } = await client.systemOne({
    state: await req.json(),
    questions: {
      team: choice("Route this contact form submission", {
        sales: null,
        support: null,
        spam: null,
      }),
    },
  });

return Response.json({
    team: answers.team.choice,
    requestId: context.requestId,
  });
};

export const config: Config = { path: "/api/route", method: "POST" };
```

The `choice` helper declares the three possible destinations up front, so `answers.team.choice` comes back as one of them and nothing else, which makes the response safe to branch on directly. Each answer also carries a probability distribution and a confidence value, so you can act on high-confidence decisions and escalate the rest to a human.

Learn more in the [AI Gateway documentation](https://docs.netlify.com/build/ai-gateway/overview/) and the [TypeSafe documentation](https://docs.typesafe.ai/).

## DeepSeek V4.1 Flash now available in AI Gateway  
**September 15, 2026**  
DeepSeek V4.1 Flash is now available through OpenRouter on Netlify’s AI Gateway with zero configuration required.

Use the OpenRouter SDK directly in your Netlify Functions without managing API keys or authentication. AI Gateway handles everything automatically. Here’s an example using DeepSeek V4.1 Flash:

```javascript
import { OpenRouter } from '@openrouter/sdk';

export default async () => {
    const client = new OpenRouter();

const response = await client.chat.send({
        chatRequest: {
            model: 'deepseek/deepseek-v4.1-flash',
            messages: [{ role: 'user', content: 'How can AI improve my coding?' }],
            maxTokens: 400,
        },
    });

return Response.json(response);
};
```

DeepSeek V4.1 Flash is available across Background Functions, Scheduled Functions, and Edge Functions. You get automatic access to Netlify’s rate limiting and authentication infrastructure.

Learn more in the [AI Gateway documentation](https://docs.netlify.com/build/ai-gateway/overview/) and [OpenRouter documentation](https://openrouter.ai/docs/quickstart).

## Agent Runners: Get a working result when low on credits  
**September 14, 2026**  
Agent Runners are now better at completing their work when a run has less credits remaining than the task requires.

If you are close to running our of credits during a run, the agent will start focusing on delivering the most useful result it can with the credits it has left. It finishes work already in progress, leaves the project in a working state, and provides a clear summary of what it completed.

Previously, an ambitious task could end abruptly before the agent wrapped up, leaving partial changes and little explanation. Now, you’re more likely to get a working result you can use right away, or a solid, clearly documented starting point for your next run.

This improvement applies automatically to every agent and model available in Agent Runners. There’s nothing to enable or configure. Learn more in [Make changes with Agent Runners](https://docs.netlify.com/build/build-with-ai/agent-runners/make-changes-with-agent-runners/) and [how credits work](https://docs.netlify.com/manage/accounts-and-billing/billing/billing-for-credit-based-plans/how-credits-work/).

## Social media share buttons  
**September 11, 2026**  
Sharing your Netlify projects is now faster with built-in social media share buttons.

When you’re ready to show off what you’ve built, you can share your project directly to X, LinkedIn, Reddit, Facebook, or Bluesky. Choose your preferred platform and Netlify opens a ready-to-publish post with your project link, so you can reach your community with fewer steps.

## Cursor Origin now supported as a Git provider  
**September 10, 2026**  
You can now connect repositories hosted on [Cursor Origin](https://cursor.com/docs/origin) to Netlify, so every Git push deploys an updated version of your project at a preview URL or a production URL.

Netlify supports [Cursor Origin](https://cursor.com/docs/origin) with continuous deployment, meaning that once your codebase’s repo is connected, Netlify will automatically:

- Build and deploy your project with every git push  
- Build Deploy Previews for your pull requests  
- Send deploy notifications to your pull request comments on Cursor Origin so you can check preview URLs there

### Requirements
Cursor Origin uses OAuth authentication, so connecting a repo works much like our existing Azure DevOps support: the Cursor user who authenticates needs access to the Cursor Origin codebase that owns the repository.

To use Cursor Origin with Netlify, you do not need a specific pricing plan with Netlify.

### Support scope
Note that features outside of continuous deployment, such as Agent Runners and the Netlify Drawer, are not supported at this time.

### Get started
To learn more, check out these docs:

- [Get started Cursor Origin](https://docs.netlify.com/build/git-workflows/repo-permissions-linking#get-started-with-cursor-origin)  
- [Link your repo to your Netlify project](https://docs.netlify.com/manage/projects/connect-project-to-repo/)  
- [Deploy a new project to Netlify from your Cursor Origin repo](https://docs.netlify.com/start/quickstarts/deploy-from-repository/)
