Excited to share that Gel Data has been acquired by Vercel!
We are joining a company that built what is arguably the best JavaScript platform in the world, and now our team, Yury and I get to help do the same for Python. Our team's expertise in DX, cloud platforms, and the Python runtime will combine with Vercel's relentless focus on shipping exceptional software to great effect, I am sure of it.
I'm incredibly grateful to our team, our community, our investors and everybody who supported Gel along the way!
More here: https://t.co/CjqOvuWuFk
Sandboxes are now persistent by default.
▪︎ Automatic, unlimited snapshots
▪︎ New APIs like 𝚐𝚎𝚝𝙾𝚛𝙲𝚛𝚎𝚊𝚝𝚎 & 𝚏𝚘𝚛𝚔
▪︎ Lifecycle hooks (𝚘𝚗𝙲𝚛𝚎𝚊𝚝𝚎 & 𝚘𝚗𝚁𝚎𝚜𝚞𝚖𝚎)
▪︎ Tags support for multi-tenant platforms
https://t.co/j3GkzmQV3g
Flat Rate CDN is in Limited Beta for Pro teams.
You pay a fixed monthly fee for Vercel CDN usage, with no overages for viral spikes, unfiltered bots, or misconfigured routes.
Join the waitlist ↓https://t.co/y50l3Exw4A
Introducing Zero
The programming language for agents.
I wanted a systems language that was faster, smaller, and easier for agents to use and repair.
Explicit capabilities. JSON diagnostics. Typed safe fixes.
Made for agents on day zero.
deepsec is quite possibly one of the best security tools I've tried so far
we get a ton of "security reports" @dubdotco and only a handful of those are actually actionable
with deepsec, we were able to detect several valuable issues from the get-go and secure our application for the long term
highly recommend trying it out – best part, you get to run in your own infra as well for full control
Today we're open-sourcing `deepsec`: a security harness powered by coding agents.
We've been testing it for a few months on our internal code bases as well as open-source applications from customers and partners. For the latter group we have privately shared the results, so issues can be fixed.
- It actually works. I recommend giving it a try. The dream of Mythos in CLI-form.
- You can run it on your laptop with your existing claude or codex subscription.
- For large repos it can take a very long time to run. For this it supports fanout to worker sandboxes. I've been running it on 1000 cores+ to get through a lot of code quickly
While a lot has already been said about the recent
@vercel incident, here’s what isn’t:
1) @rauchg and the Vercel team handled the disclosure well. They were clear about what happened, specific about the access path, and avoided speculation. Having this level of transparency is not easy in the middle of an incident, but we should hope it becomes the norm. Instead of a vague post or PR speak, Vercel gave details on exactly what happened, what steps to take, and what it was doing going forward. And they’ve been updating customers along the way. This kind of transparency helps the rest of the industry focus on the actual problem instead of reacting to incomplete narratives and jumping to conclusions.
2) This is about more than a single tool or decision, it is about how access works today. An employee connects a third-party application using OAuth. The permissions are granted through a standard flow. That connection persists. If at some later point, the external service is compromised, then the token becomes the access path. While nothing is “technically wrong,” this is where the identity model of security starts to break down. Identity systems were built around controlling access at login. That creates a gap between what is allowed and what should happen in context.
At @1Password, we are shifting from managing identity to governing how access is used in practice. We are co-building with our partners now, to help them secure their agents and their access.
Credit to the Vercel team for surfacing this issue 🙏
In collaboration with @github, @Microsoft, @npmjs, and @SocketSecurity, our security team has confirmed that no npm packages published by Vercel have been compromised.
There is no evidence of tampering, and we believe the supply chain remains safe.
https://t.co/0S939n3qHC
I’m so encouraged by the way our team and industry peers have shown up to protect the internet.
We’ve now shipped over 20 product improvements across Dashboard and CLI to help your security posture.
Easier to set up MFA, audit your Environment Variables, Activity logs and more
Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly.
A Vercel employee got compromised via the breach of an AI platform customer called https://t.co/7PY6gGtzgI that he was using. The details are being fully investigated.
Through a series of maneuvers that escalated from our colleague’s compromised Vercel Google Workspace account, the attacker got further access to Vercel environments.
Vercel stores all customer environment variables fully encrypted at rest. We have numerous defense-in-depth mechanisms to protect core systems and customer data. We do have a capability however to designate environment variables as “non-sensitive”. Unfortunately, the attacker got further access through their enumeration.
We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI. They moved with surprising velocity and in-depth understanding of Vercel.
At the moment, we believe the number of customers with security impact to be quite limited. We’ve reached out with utmost priority to the ones we have concerns about. All of our focus right now is on investigation, communication to customers, enhancement of security measures, and sanitization of our environments. We’ve deployed extensive protection measures and monitoring. We’ve analyzed our supply chain, ensuring Next.js, Turbopack, and our many open source projects remain safe for our community.
The recommendation for all Vercel customers is to follow the Security Bulletin closely (https://t.co/BLVnic9fJC). My advice to everyone is to follow the best practices of security response: secret rotation, monitoring access to your Vercel environments and linked services, and ensuring the proper use of the sensitive env variables feature.
In response to this, and to aid in the improvement of all of our customers’ security postures, we’ve already rolled out new capabilities in the dashboard, including an overview page of environment variables, and a better user interface for sensitive env var creation and management. As always, I’m totally open to your feedback.
We’re working with elite cybersecurity firms, industry peers, and law enforcement. We’ve reached out to Context to assist in understanding the full scale of the incident, in an effort to protect other organizations and the broader internet. I also want to thank the Google Mandiant team for their active engagement and assistance.
It’s my mission to turn this attack into the most formidable security response imaginable. It’s always been a top priority for me. Vercel employs some of the most dedicated security researchers and security-minded engineers in the world. I commit to keeping you updated and rolling out extensive improvements and defenses so you, our customers and community, can have the peace of mind that Vercel always has your back.
Fwiw, I am impressed with how Vercel has handled this incident so far.
They’re taking it seriously. Notifying affected parties within minutes of identification. Being realistic about what they do and don’t know.
They’re clearly more worried about their customers than their reputation right now and I have a lot of respect for that.
Please welcome PEP 827 -- the result of a year-long research into what would it take to uplift Python's type checking to match its dynamism.
https://t.co/nLzVDS0kfB
Vercel will be officially sponsoring https://t.co/QF7eOed81b. That's a given. We as a community and industry owe @adamwathan and team a lot. Tailwind is foundational web infrastructure at this point (it fixed CSS 😉). I've also reached out to Adam to explore how we can make this a longer-term commitment.
We paid $1 million to hackers to harden our firewall defenses.
Today we're telling the story of how we strengthened our WAF, disclosing a runtime mitigation layer for the first time, and how we partnered with
@Hacker0x01 to defend against React2Shell.
https://t.co/O3DWCVnGU7
there aren't many products that people use every day that they *love*
astral builds several!
this is a unique role for someone looking to join a fast growing company - dm me or link is below!
If you have not upgraded yet, this makes it a one line invocation. Do not delay as exploitation is active in the wild.
You get to trade-off: Running a one-line-script vs. spending days rotating secrets
We’re bringing Vercel’s DX and self-driving infrastructure to Python, by teaming up with @1st1, @elprans & the Gel team.
I’m so excited to work with these guys. True missionaries that have lived and breathed Python their entire professional lives. I’m confident they’ll make Vercel the best Python cloud.
We’re also sponsoring the Python Software Foundation, core maintainer @SerhiyStorchaka, and are committed to the long-term strength of the open Python ecosystem.
Excited to share that Gel Data has been acquired by Vercel!
We are joining a company that built what is arguably the best JavaScript platform in the world, and now our team, Yury and I get to help do the same for Python. Our team's expertise in DX, cloud platforms, and the Python runtime will combine with Vercel's relentless focus on shipping exceptional software to great effect, I am sure of it.
I'm incredibly grateful to our team, our community, our investors and everybody who supported Gel along the way!
More here: https://t.co/CjqOvuWuFk