{
  "schema_version": "1.1",
  "id": "s3:https://cursor.com/blog/rollouts-and-security-reviewer",
  "slug": "rollouts-and-security-reviewer-015uvdo",
  "url": "https://feed7.dev/p/rollouts-and-security-reviewer-015uvdo",
  "title": "Bots for the last mile: Rollouts, Security Review",
  "why_included": "Cursor added PR-to-production monitoring and codebase-aware security review, giving agent-driven teams automated checks after code generation but before and after deployment.",
  "summary": "Cursor released **Rollouts** to monitor changes from PR through production and **Security Reviewer** to inspect every PR in whole-codebase context. Rollouts establishes a pre-deploy baseline; Security Reviewer reports severity, attack path, and a proposed fix.",
  "practical_implication": "Connect deployment and telemetry systems, then review Rollouts’ monitoring plan before merge. Configure regression responses conservatively—notification, rollout pause, or approval-gated revert—and treat security fixes as reviewable patches rather than automatic truth.",
  "agent_context": "Cursor released **Rollouts** to monitor changes from PR through production and **Security Reviewer** to inspect every PR in whole-codebase context. Rollouts establishes a pre-deploy baseline; Security Reviewer reports severity, attack path, and a proposed fix.\n\nConnect deployment and telemetry systems, then review Rollouts’ monitoring plan before merge. Configure regression responses conservatively—notification, rollout pause, or approval-gated revert—and treat security fixes as reviewable patches rather than automatic truth.\n\nBoth bots are limited to **Teams and Enterprise** plans. Feature-flag traffic control, release-train awareness, and deploy-freeze awareness are still forthcoming, and the post provides no measured accuracy or false-positive rates.",
  "source": {
    "name": "Cursor",
    "url": "https://cursor.com/blog/rollouts-and-security-reviewer",
    "published_at": "2026-09-23T12:00:00.000Z"
  },
  "source_class": "blog_post",
  "content_type": "Engineering Post",
  "layer": "tools",
  "domains": [
    "coding",
    "security"
  ],
  "topics": [
    "coding-agents",
    "agent-reliability",
    "observability"
  ],
  "verification": {
    "status": "official_source",
    "label": "Official Source",
    "method": "source_feed",
    "verified_at": null
  },
  "uncertainty": [
    "Both bots are limited to **Teams and Enterprise** plans. Feature-flag traffic control, release-train awareness, and deploy-freeze awareness are still forthcoming, and the post provides no measured accuracy or false-positive rates."
  ],
  "connected_context": {
    "meaning": "This turns Cursor’s proposed production loop into two concrete, review-oriented controls spanning pre-merge security and post-merge behavior. It confirms telemetry-backed monitoring as part of coding-agent reliability, but keeps authority bounded through reviewable plans and conservative responses; missing accuracy data and forthcoming release controls prevent treating either bot as an autonomous gate.",
    "corpus_size": 875,
    "generated_at": "2026-09-25T09:06:52.652Z",
    "connections": [
      {
        "title": "Firetiger joins Cursor",
        "source_name": "Cursor",
        "source_url": "https://cursor.com/blog/firetiger",
        "feed7_url": "https://feed7.dev/p/firetiger-06hv2bc",
        "reason": "Rollouts is a concrete realization of the previously announced Firetiger direction, moving from an upcoming monitoring concept to a product with baseline creation, monitoring plans, and configurable regression responses."
      },
      {
        "title": "PostHog/posthog",
        "source_name": "GitHub",
        "source_url": "https://github.com/PostHog/posthog",
        "feed7_url": "https://feed7.dev/p/posthog-1dwbj56",
        "reason": "PostHog’s telemetry-to-diagnosis path provides the broader observability pattern that Rollouts operationalizes around individual changes from PR through production."
      },
      {
        "title": "Distributed Attacks in Persistent-State AI Control",
        "source_name": "arXiv",
        "source_url": "https://arxiv.org/abs/2607.02514v1",
        "feed7_url": "https://feed7.dev/p/2607-02514v1-02bqscm",
        "reason": "Distributed attacks across multiple PRs expose a limit of per-PR security review; whole-codebase context may broaden each inspection, but the supplied material does not show that Security Reviewer detects persistent multi-PR attacks."
      },
      {
        "title": "LLM Agents Can Easily Tamper With Their Own Traces",
        "source_name": "arXiv",
        "source_url": "https://arxiv.org/abs/2609.30266v1",
        "feed7_url": "https://feed7.dev/p/2609-30266v1-1kct4j7",
        "reason": "Because Rollouts depends on deployment and telemetry evidence, trace-tampering results make independently captured, agent-inaccessible monitoring data an important prerequisite for trustworthy automated responses."
      }
    ]
  },
  "lifecycle": "Current",
  "published_at": "2026-09-23T12:00:00.000Z",
  "modified_at": "2026-09-23T12:00:00.000Z",
  "supersedes": [],
  "expires_at": null,
  "formats": {
    "html": "https://feed7.dev/p/rollouts-and-security-reviewer-015uvdo",
    "json": "https://feed7.dev/p/rollouts-and-security-reviewer-015uvdo.json",
    "markdown": "https://feed7.dev/p/rollouts-and-security-reviewer-015uvdo.md"
  }
}