Your stack
Models
2 pickedAI coding tools
1 pickedAI frameworks
1 pickedAuth & data
1 pickedInfra & queues
1 pickedCloud platforms
4Frontend & UI
1 pickedLanguages & runtimes
7Observability & evals
2Section order
drag to arrange- OpenAI1
- Anthropic2
- Claude Code3
- Vercel AI SDK4
- Vercel5
- Next.js6
- Drizzle ORM7
Verbosity
How often
Your edition
56 items this week
28 Sept – 4 Oct
OpenAI
2 updates
29 Sept
Agents can control a browser to complete web tasks
Agents can now interact with websites by controlling a browser environment hosted by OpenAI, with your application handling access approvals and authentication.
Multi-agent support added to Responses API in beta
GPT-6.1 Sol supports multi-agent delegation in beta via the Responses API, letting the model spawn and coordinate subagents for complex tasks.
Anthropic
3 updates
30 Sept
Claude Sonnet 4.5 model deprecated, retiring November 30
Claude Sonnet 4.5 is deprecated and will be removed from the API on November 30, 2026. Migrate to Sonnet 5.5 before then.
28 Sept
Thinking blocks are now account-bound and cannot be shared
Sonnet 5.5 thinking blocks are account-bound for security. Sending one from another account silently drops it; the request still succeeds. Earlier models' blocks are unaffected.
Claude Sonnet 5.5 released with breaking API changes
Claude Sonnet 5.5 has breaking changes to thinking, tool use, and computer use APIs. Forced tool choice now errors; thinking syntax changed; older models can't be advisors. Migration guide available.
Claude Code
20 updates
3 Oct
Deny and ask rules now apply to files accessed through symlinks
Deny and ask rules now correctly apply when files are accessed through symlinks, or when nested parts of compound shell commands are restricted—even when a user-installed mod has already been approved on managed machines.
Agent can spawn sub-agents and track idle and waiting states
Plugins can now spawn sub-agents for teammates via `agent.spawn`, receive a consistent agent id across hook events, and query idle and waiting states through `$.agent.list()`.
Terminal no longer freezes on code blocks with many unclosed script tags
The terminal no longer freezes when displaying short code blocks containing many unclosed `<script>` tags or deeply nested variable substitutions.
Bash deny rules now catch commands hidden behind variable prefixes
Deny and ask rules now correctly match Bash commands even when they're preceded by environment variable assignments that expand at runtime, and when bare variable assignments come before the command.
2 Oct
Mid-response API timeouts no longer fail; sessions resume from partial response
When an API timeout happens mid-response, headless sessions and subagents now resume from what they received instead of failing the turn.
Code review findings limit is now configurable per run
The `/code-review` command now accepts `--max-findings` to report more or fewer findings than the default; your choice sticks until you reset it.
Selection API for mods returns fullscreen text and transcript context
Mods can now call `$.ui.selection()` to get the text you selected in fullscreen mode, plus the transcript row it came from if the selection spans one row.
Prompt recovery restores draft after Ctrl+C with pasted content intact
If you clear the prompt with Ctrl+C, you can now press Up to get your draft back, complete with any text or images you pasted.
1 Oct
Fixed dangerous rm commands losing safeguards with output redirection
A dangerous `rm` command (on `/` or home directory) was losing its safety prompt when the same command also redirected output to `~` or a wildcard. This is now fixed.
Claude Mods let plugins modify deeper agent behavior
Plugins can now modify deeper agent behavior, not just add tools. A built-in mod watches for things you or Claude might miss and flags them; enable with `/plugin enable cc-plugin-you-should-know@builtin` in first-party sessions with telemetry on.
Session name and task filter in agents view
The agents view now supports `n:<text>` to filter sessions by name or task; matches appear in collapsed sections and Enter opens the first one.
MCP servers can now send URL prompts for sign-in flows
MCP servers using the 2025-11-25 protocol can now send URL prompts for flows like sign-in. If a server no longer connects after this update, add `"bareElicitationCapability": true` to its MCP config entry.
30 Sept
API errors from non-text tool returns are now handled
Tools and hooks that return structured data (objects, numbers, booleans) instead of text no longer cause API errors. This fix applies to both fresh and resumed sessions.
Remote Control sessions now disconnect when policy is disabled
If your organization disables Remote Control, any active sessions (including `claude remote-control`) will now cleanly disconnect and notify you, rather than silently remaining connected.
Resume sessions now preserve turns after parallel tool calls crash
When you resume a crashed session after Claude Code ran multiple tools in parallel, all turns are now preserved instead of being lost. This restores the full context of what happened before the crash.
29 Sept
Subagent permission requests now route to prompt tool
Background subagents with `--permission-prompt-tool` now correctly route permission requests to the prompt tool instead of auto-denying them.
Disable WebFetch tool via environment variable
New environment variable `CLAUDE_CODE_DISABLE_WEB_FETCH` lets you disable the WebFetch tool, useful for restricted environments or when you want to limit agent capabilities.
Configure MCP server settings at install time
MCP server settings can now be configured during `claude plugin install` using `<server>.<key>=<value>` syntax, avoiding the need to visit the Configure UI afterward.
28 Sept
MCP tool calls now wait for servers to connect in resumed sessions
When you resume a session and call an MCP tool whose server is still connecting, Claude Code now waits up to 10 seconds instead of failing with 'No such tool available'.
Malformed images and documents no longer crash Agent SDK sessions
Agent SDK sessions no longer crash when a user message contains an image with malformed metadata or a malformed document block; they replace it with an explanatory note.
Vercel AI SDK
13 updates
1 Oct
Merged UI message streams now cancel on consumer disconnect
Fixed a resource leak where merged UI message streams continued running after the consumer disconnected.
Tool search results are now configurable with maxResults
Tool search now accepts a maxResults parameter to cap the number of tools returned to the model, letting you control inference cost and latency.
Tool search now supports ranking and filtering via callback
Tool search now accepts a search() callback that lets you rank and filter which deferred tools the model can choose from, giving you control over tool eligibility at inference time.
30 Sept
Tool approvals now clear when adding tool output
When you add tool output via `addToolOutput`, any prior tool approvals are now cleared, ensuring fresh approval state for subsequent tool invocations.
Speech generation and transcription now emit telemetry events
Speech generation and transcription now report telemetry including provider usage and experimental callbacks for streaming lifecycle events, letting you track and debug audio operations.
Streamed text parts now preserve partial reasoning tags
When streaming text with reasoning, partial tags that span chunk boundaries are now preserved instead of being lost, fixing output corruption.
Idle UI message streams stay open with optional SSE heartbeats
Server-sent event streams for UI messages can now send heartbeats during idle periods, preventing proxies and load balancers from closing long-lived connections.
28 Sept
Tool execution errors from providers skip the UI stream error callback
When a provider executes a tool and it fails, that error no longer fires the UI stream's `onError` callback—this preserves the provider's error context. Stream errors and malformed tool calls still use the callback as before.
UI message parts resume correctly after network disconnection
If a user's connection drops mid-stream, UI message parts that were being rendered will now properly resume instead of being lost or duplicated.
Tool metadata now preserved through streaming output chunks
When tools return data through streaming, their metadata (like names and descriptions) now persists through the output pipeline instead of being lost.
Prevent unhandled rejections from stream completion in non-Node runtimes
Fixed unhandled promise rejections from stream completion in non-Node environments like browsers and edge functions, improving stability.
Advertise image model capabilities with confirmed model IDs
The SDK now accurately advertises which image models support file inputs and masks, using verified model IDs. Adds support declarations for Together AI FLUX.2 Pro, Flex, and QuiverAI Arrow 2, while marking unsupported capabilities as unknown.
Cancel response streams when clients disconnect
Response streams are cancelled immediately when a client disconnects, reducing unnecessary compute and API costs.
Vercel
14 updates
2 Oct
Python SDK adds evaluate() function for Jev classification model
Vercel's Python AI SDK now exposes Jev, a classifier model that answers multiple-choice questions over data without task-specific training. Use evaluate() with question types you define; get back structured JSON instead of text generation.
1 Oct
Speed Insights stops recording First Input Delay measurements
Speed Insights will stop collecting First Input Delay data on November 1st, replacing it with Interaction to Next Paint (INP), which is already your responsiveness metric. Your score and historical data are unaffected.
Microsoft AI audio models available on AI Gateway
Microsoft's speech generation and streaming transcription models are now available through Vercel's AI Gateway, billed at listed rates with no additional fees, enabling real-time voice agents and live captions.
Laya decision model available on AI Gateway
Laya is an evaluation model now accessible via AI Gateway alongside other models, letting you route decisions through a single API with unified cost tracking and failover.
30 Sept
Vercel Agent can install private npm packages using stored credentials
Vercel Agent can now install private dependencies from npm and custom registries by reading team-shared environment variables, the same way Vercel builds do. Credentials remain inaccessible to the agent itself.
AI Gateway adds Browserbase Search and Fetch tools
Browserbase Search and Fetch tools are now available through AI Gateway, letting you add web search and page retrieval to any model supporting tool calling without switching tools when you change models.
Vercel CDN stops caching responses with Vary: Cookie header
Responses with Vary: Cookie are no longer cached by Vercel's CDN because cookie-based variance creates low-reuse cache entries. Use Cache-Control: private for cookie-dependent responses, or remove Cookie from Vary if the response is identical regardless of cookies.
Vercel Sandbox can now connect to Secure Compute networks
Sandboxes now integrate with Secure Compute networks, letting you route outbound traffic through static IPs and access private resources in your VPC via peering. Attach at creation or update existing sandboxes; changes take effect on next session.
Ling 3.1 Flash model available on AI Gateway
InclusionAI's Ling 3.1 Flash, a hybrid reasoning model optimized for coding and tool use, is available on Vercel's AI Gateway with a 262K-token context window. Free during promotion, then metered billing.
29 Sept
Vercel Connect now accepts community service submissions
You can now submit services to Vercel Connect's directory instead of waiting for Vercel to build connectors. Submissions require OAuth or API key support and go through review.
Search trace spans from the CLI without opening the dashboard
You can now search request traces directly from the terminal instead of the dashboard, filtering by multiple fields and time range. Agents can parse structured JSON output to investigate errors and latency.
GPT-6.1 Sol model available on AI Gateway
GPT-6.1 Sol, OpenAI's latest model optimized for coding and multi-step workflows, is now accessible through Vercel's AI Gateway with improved factual accuracy and reduced token costs for cached contexts.
28 Sept
Search domain availability without authentication
You can discover and price domains through the CLI or API without signing in to Vercel. Authentication remains required only for purchase and management.
Claude Sonnet 5.5 available on AI Gateway
Anthropic's Claude Sonnet 5.5 is now available through Vercel's AI Gateway with zero data retention, supporting multiple API formats for inference in your product.
Next.js
4 updates
30 Sept
Patch Server-Side Request Forgery in image optimization
Image Optimization can be exploited to make requests to private IP ranges when `images.remotePatterns` is configured. Upgrade to v16.3.8 or v15.5.27.
Patch cache leak in nested 'use cache' functions
When Cache Components are enabled, nested `'use cache'` functions may cache incorrectly and serve one user's content for another's root param value.
Patch Draft Mode content leak via pending cache fills
Pending cache fills don't distinguish Draft Mode from regular requests, allowing unpublished content to be served and cached permanently if prerendered.
Patch cache poisoning in SSG and ISR pages
Self-hosted Next.js with static or incremental regeneration can have cache entries replaced with content from different routes. Vercel-hosted apps are not vulnerable.
A tool that ships more than twenty items in one edition has the rest follow in the next rather than being dropped.
This is what shipped each week, shaped by the same code that builds the email. A real edition also carries items an earlier one held back, skips anything you have already been sent, and never reaches back past the week you subscribed.