Fetching from the wire…
Public story · 2026-07-21 · high
Team Owners can wipe a team's entire Remote Cache the moment they suspect poisoned build artifacts, right from Build and Deployment settings.
Why now: Vercel's changelog names cache poisoning as the reason for the button, which is what turns a settings tweak into incident-response tooling worth flagging.
Vercel added a one-click way to purge a team's entire Remote Cache of build and CI artifacts, per its changelog.
The button lives in Build and Deployment settings and wipes every cached artifact across the whole team at once, not per project. Vercel's changelog names the reason plainly: "when you believe poisoned artifacts are in your cache." That's language built for incident response, not routine cache cleanup.
Nothing in the changelog describes how a team would detect a poisoned artifact in the first place. There's no mention of alerting or scanning, only the purge itself. Whoever holds Team Owner access is left to make that call and act on it.
Wiping the whole team's cache also means every project sharing it loses its build speedup at the same time, the tradeoff for a lever built for emergencies rather than routine use.
Putting the poisoning language directly in a changelog entry, instead of a separate security bulletin, means teams find out about the risk from a routine release note. Find the button before a CI run is already serving bad artifacts, not after.
Each link below shares sources, entities, or timing with this story.
npx deepsec init now sets up a repo and runs its first review in a single command: creates an isolated .deepsec/ workspace, configures model access via AI Gateway or custom keys, generates a codebase description and attack-surface map, runs pattern scans for coverage gaps, the...
Satya Nadella said companies routing everything through a single proprietary lab may not survive. His argument: you hand that lab your most sensitive business context, and the lab can turn it against you as a competitor. His prescription is an orchestration layer — keep the ha...
swyx's synthesis of the AI Engineer World's Fair 2026 is the clearest framing I've read of where this all goes. The discipline moved from building agents to engineering the harness around them. Lilian Weng (now at Thinking Machines Lab) reframed her whole practice as "harness...
Now on all plans and in v0. Instead of storing provider secrets in env vars, a deployment authenticates with its existing Vercel OIDC identity and calls getToken() for a task-scoped credential the platform refreshes and expires. Covers 100+ integrations including managed conne...
Two adapters on August 25: the Notion one lets an agent already running on Slack, Discord, GitHub, Teams or WhatsApp join comment discussions on Notion pages with no separate codebase, and the XChat one handles encryption, key management and signature verification for E2E-encr...
iad1 stays the default, joined by sfo1, cle1 and cdg1, with region choice on all plans and failover configuration limited to Pro and Enterprise. Set it in Settings, via vercel project update my-project --sandbox-region cdg1 --sandbox-failover-regions iad1,cle1, or by passing r...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.