Changelog

Subscribe to feed
  • SvelteKit 3 just works on Netlify

    SvelteKit 3 is out today, and it just works on Netlify on day one. To upgrade, run:

    npx sv migrate sveltekit-3

    The migration tool handles most of the mechanical changes for you, including moving your config and updating imports. You can also check out the official migration guide.

    What’s new

    Some highlights include:

    • Vite 8 — SvelteKit 3 requires Vite 8, bringing faster builds powered by Rolldown.
    • Config lives in vite.config.ts — SvelteKit configuration moves out of svelte.config.js and into your Vite config, so Vite plugins can read it right away.
    • Explicit environment variables are stable — Declare the environment variables your app depends on in src/env.ts, and specify whether each one is public and whether it’s resolved at build time or when the app boots. You get validation and type safety out of the box.
    • $lib is now #lib — The $lib alias is replaced by #lib, using Node’s subpath imports. Imports need to be unambiguous, so write #lib/foo.ts or #lib/foo/index.ts.
    • Shallow routing is built into goto — Use goto() with shallow: true instead of pushState and replaceState.
    • Consistent error handling — All errors, including ones you throw with error(...), now go through your handleError hook.
    • New service worker modules — $service-worker is replaced by imports from $app/env, $app/paths, and $app/manifest, with better type checking in service workers.
    • Tracing is stable — Tracing support has moved out of the experimental namespace.

    Check the full migration guide for all the details.

    Watch out for the #lib alias

    Nearly every SvelteKit project imports from $lib, so this is the change you’re most likely to run into. The migration tool rewrites these imports for you, but because #lib relies on Node’s subpath imports, directory imports without an explicit file no longer resolve:

    // Before
    import { formatDate } from '$lib/utils';
    // After
    import { formatDate } from '#lib/utils/index.ts';

    If a build fails after upgrading with a module resolution error, look for #lib imports that point to a directory or leave off the file extension.

    Deploy a SvelteKit 3 site on Netlify

    If you want to get started with a new site, start with the SvelteKit on Netlify doc, or just click this button:

    Deploy to Netlify

    Permalink to SvelteKit 3 just works on Netlify
  • Security Update: Multiple vulnerabilities in Next.js

    The Next.js team has disclosed seven security vulnerabilities in Next.js (one high, five medium, one low), patched on September 30, 2026 in 15.5.27 and 16.3.8. The issues span server-side request forgery (SSRF), cache poisoning, and information disclosure. Several of them do not affect apps hosted on Netlify. Here’s what Netlify customers need to know.

    Summary

    Some of these vulnerabilities affect Next.js sites hosted on Netlify (details in Impact on Netlify), so if you run Next.js on Netlify, we strongly recommend upgrading next to 15.5.27 or 16.3.8 and redeploying. The OpenNext Netlify Next.js adapter must also be updated to @netlify/plugin-nextjs 5.16.1; it’s auto-installed by default, so a redeploy picks it up (a manual upgrade is only needed if you pin the version). See What should I do? for full steps.

    Vulnerabilities

    All issues are patched in 15.5.27 and 16.3.8.

    VulnerabilitySeverityAffected
    GHSA-cjq9-62q9-8jv4 / CVE-2026-94483 — Image optimizer SSRFHigh16.x with an attacker-controlled remote host in images.remotePatterns
    GHSA-4jqv-mc3x-m676 / CVE-2026-94543 — Cache poisoning of SSG/ISR pages (cross-route)Medium15.x/16.x Pages Router apps with SSG/ISR and a root catch-all route
    GHSA-mcj8-r9mp-w47p / CVE-2026-94484 — Cache poisoning via encoded paths / /index (SSG/ISR)Medium15.x/16.x apps combining a root catch-all with SSG/ISR routes
    GHSA-f87g-xv8r-7p7x / CVE-2026-94485 — Metadata image dynamicParams bypass (information disclosure)Medium16.x App Router Webpack builds using metadata image routes
    GHSA-h694-7cp9-m8p3 — Cache leak across root param values in nested use cacheMedium16.3.x with Cache Components + nested use cache reading root params
    GHSA-3w37-wq28-93x7 / CVE-2026-94544 — Draft Mode use cache content leakMedium16.3.x with Cache Components / useCache, Draft Mode, and draft-dependent cached content
    GHSA-39w2-rjm5-chcv / CVE-2026-94486 — Development MCP information disclosureLow16.x development servers (next dev) with the MCP endpoint

    Impact on Netlify

    Not affected on Netlify

    • GHSA-cjq9-62q9-8jv4 (Image optimizer SSRF): Netlify projects are not affected. Image optimization on Netlify is handled by Netlify Image CDN — a separate service outside your project’s functions — so the vulnerable Next.js image-optimizer code path is not used, and the Image CDN has its own protections against this class of SSRF.
    • GHSA-3w37-wq28-93x7 (Draft Mode use cache content leak): Netlify projects are not affected. This leak requires two requests to share a single server process’s in-flight cache fill. On Netlify’s serverless architecture each request is served by its own isolated invocation, so the required overlap cannot occur.
    • GHSA-39w2-rjm5-chcv (Development MCP information disclosure): Netlify projects are not affected. This affects the next dev development server only; Netlify serves production builds, which do not expose the development MCP endpoint.

    Information disclosure

    GHSA-f87g-xv8r-7p7x (Metadata image dynamicParams bypass) can expose content from routes excluded via dynamicParams through metadata image routes. It only affects Webpack builds; Turbopack builds are not affected. On Netlify, apps that use a Webpack build are affected; upgrading Next.js resolves it.

    Cache poisoning and availability

    GHSA-4jqv-mc3x-m676 and GHSA-mcj8-r9mp-w47p affect apps with SSG/ISR routes behind a root catch-all.

    • GHSA-4jqv-mc3x-m676 (cross-route cache poisoning): Pages Router apps with SSG/ISR and a root catch-all route are affected on Netlify. Upgrading Next.js resolves the poisoning on its own. The fix also changes how cache entries are keyed, so you should update the Netlify adapter (5.16.1) as well — otherwise prerendered pages miss the cache and re-render (a serving/performance regression, not a security one). See What should I do?.
    • GHSA-mcj8-r9mp-w47p (encoded paths / /index): App Router apps with a prerendered catch-all route are affected by an availability issue — certain valid percent-encoded URLs can return an error (HTTP 500) instead of the page. Upgrading Next.js resolves it.
    • GHSA-h694-7cp9-m8p3 (cache leak across root param values): affects Next.js 16.x apps using Cache Components with a nested use cache that reads root params (e.g. locale or region segments) — an enclosing cache entry can be keyed without the root param and reused across values, so content produced for one value can be served for another. Upgrading Next.js resolves it.

    What should I do?

    We strongly recommend upgrading as soon as possible:

    • Upgrade next to 15.5.27 or 16.3.8 and redeploy.

    The OpenNext Netlify Next.js adapter that runs your app must also be updated to v5.16.1:

    • Auto-installed adapter (default): redeploy — the update is applied automatically.
    • Manually installed adapter: upgrade @netlify/plugin-nextjs to v5.16.1 and redeploy. We recommend not pinning the adapter version so future fixes ship automatically.

    Note that any publicly available deploy previews and branch deploys may remain vulnerable until they are automatically deleted. Consider deleting these deploys manually.

    Resources

    Permalink to Security Update: Multiple vulnerabilities in Next.js
  • Security Update: Cross-site scripting in TanStack Start

    The TanStack team has disclosed a critical cross-site scripting (XSS) vulnerability in TanStack Start. A crafted URL can cause an affected app to return attacker-controlled HTML from its own origin, which may run attacker-supplied JavaScript in a visitor’s browser. Here’s what Netlify customers need to know.

    Vulnerabilities

    GHSA-qx66-fv34-fjm8 (CVE-2026-102989): Unauthenticated reflected XSS in server-function responses.

    PackageAffected versionsFixed in
    @tanstack/react-start>= 1.143.12, < 1.168.601.168.60
    @tanstack/solid-start>= 1.143.12, < 1.168.571.168.57
    @tanstack/vue-start>= 1.143.12, < 1.168.561.168.56
    @tanstack/start-server-core>= 1.143.12, < 1.169.391.169.39

    Impact on Netlify

    This is a client-side cross-site scripting (XSS) vulnerability in TanStack Start’s server-function response handling. Because the malicious response is returned from the app’s own origin, an attacker who gets a victim to open a crafted link can run JavaScript in that visitor’s session — for example, to read their data or act as them on the site. All applications on an affected version should upgrade.

    What should I do?

    We strongly recommend upgrading as soon as possible to the patched releases:

    • @tanstack/react-start 1.168.60 or later
    • @tanstack/solid-start 1.168.57 or later
    • @tanstack/vue-start 1.168.56 or later
    • @tanstack/start-server-core 1.169.39 or later

    Not sure if you’re affected?

    Open your project in Agent Runners in ask mode and try this prompt:

    Does this project use TanStack Start? If so, which versions of `@tanstack/react-start`, `@tanstack/solid-start`, `@tanstack/vue-start`, and `@tanstack/start-server-core` are resolved in the lockfile? Is the resolved `@tanstack/start-server-core` version 1.169.39 or later? If not, what do I need to change to upgrade? (Advisory: GHSA-qx66-fv34-fjm8)

    Ask mode answers without changing your code. If an upgrade is needed, switch to Build mode to make the change, preview, and redeploy.

    Deploy previews and branch deploys

    Note that any publicly available deploy previews and branch deploys may remain vulnerable until they are automatically deleted. Consider deleting these deploys manually.

    Resources

    Permalink to Security Update: Cross-site scripting in TanStack Start
  • Trust Center is now in the Netlify Dashboard

    Netlify’s security and compliance document library has moved into the Netlify Dashboard. To request access and learn more about the certifications and documents available, go to https://www.netlify.com/trust-center/.

    Any signed-in user, on any plan, can view our certifications, subprocessor list, and available compliance documents from their user settings.

    More sensitive documents, such as our SOC 2 report, require an access request through the Trust Center in the Netlify dashboard. Once approved, the documents are available for download.

    Learn more about how to access the Netlify Trust Center in our Security docs.

    Permalink to Trust Center is now in the Netlify Dashboard
  • Rich link previews for Agent Runners sites

    Every site created with Agent Runners now includes Open Graph tags. When you share a link to your site, it shows up as a proper preview instead of a bare URL.

    Social media sites and messaging apps read Open Graph tags to build link previews. Now, when you or your visitors share a site you created with Agent Runners, the preview includes a screenshot of the site, its title, and a description. That makes your site easier to recognize, more inviting to click, and look better than ever from the moment you share it.

    This is available on all public sites created with Agent Runners. You don’t need to do anything to turn it on.

    Learn more about Agent Runners in the Agent Runners docs.

    Permalink to Rich link previews for Agent Runners sites
  • GPT-6.1 Sol now available in AI Gateway and Agent Runners

    OpenAI’s GPT-6.1 Sol model is now available through Netlify’s AI Gateway and Agent Runners with zero configuration required.

    Use the OpenAI SDK directly in your Netlify Functions without managing API keys or authentication. AI Gateway handles everything automatically. Here’s an example using GPT-6.1 Sol with the Responses API:

    import OpenAI from 'openai';
    export default async () => {
    const openai = new OpenAI();
    const response = await openai.responses.create({
    model: 'gpt-6.1-sol',
    input: 'Give a concise explanation of how AI works.',
    });
    return Response.json(response);
    };

    GPT-6.1 Sol is also available across Scheduled Functions, Background Functions, and Edge Functions. You get automatic access to Netlify’s caching, rate limiting, and authentication infrastructure.

    Learn more in the AI Gateway documentation and Agent Runners documentation.

    Permalink to GPT-6.1 Sol now available in AI Gateway and Agent Runners
  • Prompt and preview in one view with Agent Runners

    Agent Runners now shows you a preview right next to your prompt.

    Previously, you’d get a link to the Deploy Preview and have to open it in a separate tab to see what the agent changed. Now the preview appears inline, so you can review the result and write your next prompt without switching back and forth. Plus, you can still access the Deploy Preview link if you need it.

    This makes iterating with an agent feel more like a conversation. See what changed, spot what’s off, and follow up with the next instruction, all in one view.

    Example flow

    For example, say you’re building a strategic task organizer and prompt your agent to add a button that generates a quarterly impact report. Now you can watch your agent’s updates in the side preview next to your prompt.

    Agent Runners side-by-side view showing a chat prompt to add a quarterly report button next to the live Deploy Preview of the resulting task organizer app

    In this example, your agent on Netlify will also let you know if your project cannot save your tasks across browser sessions yet, and you can approve adding a database in the same view.

    This is just one example of how Netlify gives you professional-grade capabilities, such as a real working database, with your agent of choice when you prompt with Agent Runners.

    Try it out

    See it in action when you start a new agent run or learn more about working with agents on Netlify.

    Permalink to Prompt and preview in one view with Agent Runners
  • Claude Sonnet 5.5 now available in AI Gateway and Agent Runners

    Anthropic’s Claude Sonnet 5.5 model is now available through Netlify’s AI Gateway and Agent Runners with zero configuration required.

    Use the Anthropic SDK directly in your Netlify Functions without managing API keys or authentication. AI Gateway handles everything automatically. Here’s an example using Claude Sonnet 5.5:

    import Anthropic from '@anthropic-ai/sdk';
    export default async () => {
    const anthropic = new Anthropic();
    const response = await anthropic.messages.create({
    model: 'claude-sonnet-5-5',
    max_tokens: 4096,
    messages: [
    {
    role: 'user',
    content: 'How can AI improve my coding?'
    }
    ]
    });
    return Response.json(response);
    };

    Claude Sonnet 5.5 is also available across Background Functions, Scheduled Functions, and Edge Functions. You get automatic access to Netlify’s caching, rate limiting, and authentication infrastructure.

    Learn more in the AI Gateway documentation and Agent Runners documentation.

    Permalink to Claude Sonnet 5.5 now available in AI Gateway and Agent Runners
  • New project activity feed

    As part of our ongoing work to simplify the Netlify dashboard, we’ve added an activity feed to the project overview page. It’s available on all plans and adapts to how your project is set up.

    Now when you open a project, the activity feed gives you a snapshot of your project’s latest updates, with quick access to:

    • Production versions of your project, including the version last published
    • Preview versions of your project
    • Agent runs, so you can see what agents are working on and what you and your teammates have prompted

    Project activity feed in the Netlify dashboard listing recent activity newest first, with filters for All, Production, Previews, and Agent runs. Entries include an in-progress agent run, a published production deploy, and two branch deploys with Preview links.

    This means that instead of tracking down Production deploy links, Deploy Preview links, branch deploy links, and your agent runs list separately, you can now see where your project stands at a glance in one single spot.

    The feed also suggests next steps to help you get started. It’s one of several dashboard improvements we’re gradually rolling out to simplify the Netlify experience, so you may have spotted a few already, with more to come.

    Permalink to New project activity feed
Next page