惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hacker News - Newest:
Hacker News - Newest: "LLM"
C
Cisco Blogs
L
LINUX DO - 热门话题
S
Schneier on Security
NISL@THU
NISL@THU
T
Threatpost
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Latest news
Latest news
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
量子位
Stack Overflow Blog
Stack Overflow Blog
The GitHub Blog
The GitHub Blog
月光博客
月光博客
Cyberwarzone
Cyberwarzone
B
Blog
G
GRAHAM CLULEY
L
Lohrmann on Cybersecurity
Microsoft Security Blog
Microsoft Security Blog
Vercel News
Vercel News
小众软件
小众软件
M
MIT News - Artificial intelligence
I
InfoQ
aimingoo的专栏
aimingoo的专栏
C
CXSECURITY Database RSS Feed - CXSecurity.com
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
美团技术团队
Google DeepMind News
Google DeepMind News
T
The Blog of Author Tim Ferriss
Help Net Security
Help Net Security
WordPress大学
WordPress大学
V
Vulnerabilities – Threatpost
T
Tenable Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
N
Netflix TechBlog - Medium
MyScale Blog
MyScale Blog
Blog — PlanetScale
Blog — PlanetScale
Y
Y Combinator Blog
Google DeepMind News
Google DeepMind News
D
Docker
MongoDB | Blog
MongoDB | Blog
Forbes - Security
Forbes - Security
H
Hacker News: Front Page
A
About on SuperTechFans
L
LINUX DO - 最新话题
B
Blog RSS Feed
D
DataBreaches.Net
博客园 - 司徒正美
Recorded Future
Recorded Future
G
Google Developers Blog
Hugging Face - Blog
Hugging Face - Blog

Netlify Changelog

Gemini 3.5 Flash now available in Agent Runners 4 Nuxt CVEs: what Netlify users need to know Gemini 3.5 Flash now available in AI Gateway Agent Runners workflow improvements Next.js & React security release (May 2026): what to know Block project transfers out of your team Gemini 3.1 Flash-Lite now available in AI Gateway OpenAI GPT-5.5 Instant now available in AI Gateway New `netlify logs` CLI command Deploy to Netlify with Stripe Projects Netlify Database is now generally available OpenAI GPT-5.5 and GPT-5.5 Pro in AI Gateway & Agent Runners Rename an agent run GPT Image 2 now available in AI Gateway New frontend-design skill for Agent Runners Claude Opus 4.7 now available in AI Gateway and Agent Runners Pricing updates for Credit-based plans New sorting and filter controls on the Members page Netlify Database GA coming soon, no new databases for now Deploy logs streaming is now faster Netlify CLI adds prompt-based creation and anonymous deploys Deploy from Codex with the Netlify Plugin Hydrogen with React Router 7 now supported on Netlify Monitor credit usage by day Invoices for Enterprise Available on the Billing Page AI app development on production infrastructure with Netlify Introducing Prompt Templates OpenAI GPT-5.4 Nano and GPT-5.4 Mini in AI Gateway Change your pricing plan Internal Builder Role & Project Access Controls See your available credits at a glance Astro 6 just works on Netlify Limit AI feature usage OpenAI GPT-5.4 and GPT-5.4 Pro in AI Gateway & Agent Runners Deploy Preview screenshots in agent runs Gemini 3.1 Flash-Lite Preview now available in AI Gateway GPT-5.3 Instant now available in AI Gateway Use Netlify Agent Runners from Linear Automatic PHP bot scan blocking now live on all plans Support for stale-while-revalidate in Cache API Gemini 3.1 Flash Image Preview now available in AI Gateway GPT-5.3-Codex now available in AI Gateway Gemini 3.1 Pro Preview now available in AI Gateway Claude Sonnet 4.6 now available in AI Gateway and Agent Runners Sync changes with Agent Runners without Git Claude Opus 4.6 now available in AI Gateway and Agent Runners Agent Runners improvements recap 6 new React Router & Remix CVEs: what you need to know Vulnerability in Node.js: what Netlify users need to know 5 SvelteKit security vulnerabilities: what Netlify users need to know GPT-5.2-Codex Now Available in AI Gateway and Agent Runners Play Games While Agent Runners Do the Work Prerender.io support updated as new extension Gemini 3 Flash Preview now available in AI Gateway GPT-image-1.5 now available in AI Gateway AI Gateway now Generally Available Observability release is here Prerender extension now generally available Action required: React/Next.js CVE-2025-55184 and CVE-2025-55183 GPT-5.2 and GPT-5.2-Pro now available in AI Gateway and Agent Runners GPT-5.1-Codex-Max now available in AI Gateway and Agent Runners Netlify’s response to the critical React security vulnerability Netlify Vite Plugin now supports AI Gateway locally Claude Opus 4.5 now available in AI Gateway Projects deployed using a zip file via API now support branch deploys Day one support for Angular v21 on Netlify Gemini 3 now available in AI Gateway and Agent Runners DNS record management simplified for teams in Netlify organizations Skew protection for CLI workflows Support for more domain TLDs GPT-5.1 model now available in AI Gateway React Router 7 apps can now be deployed to Edge Functions | Netlify Changelog Git SHA exposed for triggered deploys | Netlify Changelog Test scheduled functions in Netlify dashboard | Netlify Changelog Revert agent run in a task | Netlify Changelog Deletion improvements with Netlify Blobs | Netlify Changelog Preview Server restart for cross-functional collaborators | Netlify Changelog AI inference usage graphs | Netlify Changelog Buy credit packs on demand | Netlify Changelog React Router 7 middleware now supported | Netlify Changelog Skew protection now available | Netlify Changelog Next.js 16 is ready to deploy on Netlify | Netlify Changelog Enforce Git-based workflows for production deploys | Netlify Changelog Claude Haiku 4.5 is now available in the AI Gateway | Netlify Changelog GPT 5 Pro now available in the AI Gateway | Netlify Changelog Updates to credit-based Personal and Pro plans | Netlify Changelog New AI workflows: Agent Runners and AI Gateway (beta) | Netlify Changelog Netlify pricing update: Introducing credit-based plans | Netlify Changelog Security Update: Multiple vulnerabilities in Next.js | Netlify Changelog ChatGPT deep link for failed deploy analysis | Netlify Changelog Equinix IP address expiring for 4-year old sites | Netlify Changelog Nuxt 4 support + new @netlify/nuxt module for local dev | Netlify Changelog Smart Secret Scanning for AI-Generated Code | Netlify Netlify DB: Serverless PostgreSQL Database | Netlify One-click install Netlify MCP on Cursor | Netlify Changelog Netlify MCP Server: AI Agents Can Now Deploy Code Directly | Netlify Netlify Becomes Official Vite Deployment Partner + New Plugin | Netlify Angular 20 support | Netlify Changelog Netlify CLI 21.4.1 UI and workflow enhancements | Netlify Changelog Security Update: Next.js sites on Netlify not vulnerable to CVE-2025-32421 | Netlify Changelog
Introducing Advanced Web Security and Web Application Firewall
Nahrin Jalal · 2024-08-27 · via Netlify Changelog

In an average week, Netlify blocks over half a billion malicious Layer 7 HTTP requests to our customer websites, with peaks totalling several times this amount.

Today Netlify is announcing our Advanced Web Security portfolio, which encompasses several of the security features that were previously available in our service. We are also introducing a new Web Application Firewall (WAF) capable of blocking OWASP-classified web attacks.

Looking back just a few years prior, composable applications mainly focused on the frontend web experience, pulling together content sources into Jamstack frameworks coupled with a lightning-quick Content Delivery Network (CDN).

Today, as more enterprises are embracing composable architecture solutions, the applications developed have become more complex and depend even more on backend systems—databases and APIs—to deliver a true enterprise-class experience to customers. These enterprise applications require greater levels of confidential data processing, compliance, and security.

Security at Netlify

Netlify is committed to providing a robust and comprehensive security framework designed to protect your web applications and dynamic websites. Our approach is to be secure by design and at scale, ensuring that security is woven into every aspect of our platform, from infrastructure to application security, and access control to compliance

1. Secure Access Control

Netlify ensures secure access control by implementing robust mechanisms that only allow authorized users to access your applications.

  • Through Single Sign-On (SSO), we support both Team SSO and Organization SSO, enabling strict policy enforcement by team and organization owners to minimize security risks.
  • For managing user access at scale, our SCIM Directory Sync integrates with supported identity providers, allowing seamless management of Netlify access across multiple teams directly from your identity provider.
  • Additionally, role-based access control (RBAC) offers fine-grained access control by restricting developers’ access to specific sites within a team.
  • We also make available a Security Scorecard to ensure your organization is configured to meet best practices.

2. Compliance and Certifications

Netlify is dedicated to meeting the complex security and compliance needs of enterprises. Netlify adheres to industry standards and frameworks such as SOC 2 Type 2, SOC 27001, PCI DSS, GDPR, and CCPA, and employs a variety of anti-fraud-and-abuse controls.

For the latest compliance information, visit Netlify’s trust center.

3. Advanced Web Security

This is the latest addition to our list of security features to protect your site from threats and unauthorized access. Netlify Advanced Web Security encompasses the following enterprise security features:

Netlify’s Web Application Firewall

To keep our customers safe, Netlify applies a variety of protections and filters globally to block a variety of common attacks on websites. These protections include tests for protocol and method enforcement, detection of path attacks, and the validation of request headers, user agents, and URIs, among other filters. These rules are in addition to our global IP bans, which block known malicious traffic, and the blocking of traffic associated with Distributed Denial of service (DDoS) attacks.

In an average week, Netlify blocks over half a billion malicious Layer 7 HTTP requests to our customer websites, with peaks totalling several times this amount.

This attack-blocking functionality is baked into our core service and is not customizable by users. Starting today, customers can apply and configure firewall rules compatible with the OWASP Core Rule Set (OWASP CRS), curated by Netlify to address the type of attack traffic we see targeting composable site architectures.

The OWASP CRS is one of the most respected sets of WAF rules available. It is specifically designed to detect some of the most exploited modern web attack signatures, including those in the OWASP Top 10.

The Netlify WAF also supports a passive mode, which coupled with log drains, enables site developers to observe the rules triggering on-site traffic, so ruleset tuning can be performed. Similar to the functionality of our custom rate limiting rules, our WAF also supports exclude paths.

Review our WAF documentation to learn more about how to enable and configure the Netlify Web Application Firewall for your sites.

One advantage of using a composable architecture is that you can piece together a custom application stack that’s the right solution for your site. If you want to bring your own WAF to your site, our customer success engineers can help you find a reference architecture that meets your needs.

Conclusion

The suite of security tools available in our Netlify Advanced Web Security portfolio provides site developers with the necessary tools to defend against modern web attacks. This suite is now more powerful with the introduction of the user-customizable Netlify Web Application Firewall.

WAF is currently available for all enterprise customers. If you’re interested in learning more about WAF and want to evaluate how to apply Netlify’s Advanced Web Security features to your sites, please get in touch with the Netlify Sales Team.