Zum Inhalt springen

Cloudflare Release Notes

Einträge
1.630
Quellen
14
Zuletzt aktualisiert

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Cloudflare One von Cloudflare

Email security: Mehr Details zu Post-Delivery-Aktionen

Das Action Log zeigt bei fehlgeschlagenen Post-Delivery-Aktionen nun den Ziel-Ordner und einen konkreten Fehlergrund im Feld Activity an, für Enterprise und Enterprise + PhishGuard.

The Action Log now provides enriched data for post-delivery actions to improve troubleshooting. In addition to success confirmations, failed actions now display the targeted Destination folder and a specific failure reason within the Activity field.

Note

Error messages will vary depending on whether you are using Google Workspace or Microsoft 365.

failure-log-example

This update allows you to see the full lifecycle of a failed action. For instance, if an administrator tries to move an email that has already been deleted or moved manually, the log will now show the multiple retry attempts and the specific destination error.

This applies to all Email Security packages:

  • Enterprise
  • Enterprise + PhishGuard

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Typen prüfen mit wrangler types --check

Wrangler unterstützt für wrangler types das neue Flag --check, das ohne Schreibzugriff prüft, ob die generierten Typen aktuell sind, und sich dank Exit-Code ungleich null für CI/CD-Pipelines eignet.

Wrangler now supports a --check flag for the wrangler types command. This flag validates that your generated types are up to date without writing any changes to disk.

This is useful in CI/CD pipelines where you want to ensure that developers have regenerated their types after making changes to their Wrangler configuration. If the types are out of date, the command will exit with a non-zero status code.

npx wrangler types --check

If your types are up to date, the command will succeed silently. If they are out of date, you'll see an error message indicating which files need to be regenerated.

For more information, see the Wrangler types documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Generierte Typen mit wrangler types --check prüfen

Das neue Flag --check für wrangler types prüft, ob die generierten Typen aktuell sind, ohne Dateien zu schreiben, und beendet sich bei veralteten Typen mit einem Fehlercode, was für CI/CD nützlich ist.

Wrangler now supports a --check flag for the wrangler types command. This flag validates that your generated types are up to date without writing any changes to disk.

This is useful in CI/CD pipelines where you want to ensure that developers have regenerated their types after making changes to their Wrangler configuration. If the types are out of date, the command will exit with a non-zero status code.

npx wrangler types --check

If your types are up to date, the command will succeed silently. If they are out of date, you'll see an error message indicating which files need to be regenerated.

For more information, see the Wrangler types documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

Cloudflare Threat Events unterstützen STIX2

Cloudflare Threat Events unterstützen nun das STIX2-Format für eine einfachere Integration in Threat-Intel-Plattformen.

We are excited to announce that Cloudflare Threat Events now supports the STIX2 (Structured Threat Information Expression) format. This was a highly requested feature designed to streamline how security teams consume and act upon our threat intelligence.

By adopting this industry-standard format, you can now integrate Cloudflare's threat events data more effectively into your existing security ecosystem.

Key benefits

  • Eliminate the need for custom parsers, as STIX2 allows for "out of the box" ingestion into major Threat Intel Platforms (TIPs), SIEMs, and SOAR tools.

  • STIX2 provides a standardized way to represent relationships between indicators, sightings, and threat actors, giving your analysts a clearer picture of the threat landscape.

For technical details on how to query events using this format, please refer to our Threat Events API Documentation ↗︎.


Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Verbesserungen gegen SQL-Injection

Zwei Beta-Regeln zur SQL-Injection-Erkennung wurden in die regulären Regeln integriert und blockieren jetzt Angriffe.

This week's release focuses on improvements to existing detections to enhance coverage.

Key Findings

  • Existing rule enhancements have been deployed to improve detection resilience against SQL Injection.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...48a1841a

N/A

SQLi - AND/OR MAKE_SET/ELT - Beta

Log

Block

This rule is merged into the original rule "SQLi - AND/OR MAKE_SET/ELT" (ID: ...252d3934)

Cloudflare Managed Ruleset

...9e553ad3

N/A

SQLi - Benchmark Function - Beta

Log

Block

This rule is merged into the original rule "SQLi - Benchmark Function" (ID: ...2ebc44ad)

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Rules: Metrocodes (DMA) als Feld verfügbar

Das Feld ip.src.metro_code ist im Ruleset Engine verfügbar und enthält DMA-Daten, sodass Regeln auf Basis geografischer Marktgebiete erstellt werden können.

The ip.src.metro_code field in the Ruleset Engine is now populated with DMA (Designated Market Area) data.

You can use this field to build rules that target traffic based on geographic market areas, enabling more granular location-based policies for your applications.

Field details

Field

Type

Description

ip.src.metro_code

String | null

The metro code (DMA) of the incoming request's IP address. Returns the designated market area code for the client's location.

Example filter expression:

ip.src.metro_code eq "501"

For more information, refer to the Fields reference.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Benachrichtigungen bei erfolgreichen oder fehlgeschlagenen Workers Builds

Über Event Subscriptions von Queues lassen sich jetzt Benachrichtigungen erhalten, wenn Workers Builds starten, erfolgreich sind, fehlschlagen oder abgebrochen werden, und ein Template sendet diese etwa an Slack.

You can now receive notifications when your Workers' builds start, succeed, fail, or get cancelled using Event Subscriptions.

Workers Builds publishes events to a Queue that your Worker can read messages from, and then send notifications wherever you need — Slack, Discord, email, or any webhook endpoint.

You can deploy this Worker ↗︎ to your own Cloudflare account to send build notifications to Slack:

Deploy to Cloudflare

The template includes:

  • Build status with Preview/Live URLs for successful deployments
  • Inline error messages for failed builds
  • Branch, commit hash, and author name

Slack notifications showing build events …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Shell-Tab-Completion für die Wrangler CLI

Wrangler bringt eingebaute Tab-Vervollständigung für Befehle, Unterbefehle, Flags und Optionswerte in Bash, Zsh, Fish und PowerShell mit, die per wrangler complete eingerichtet wird.

Wrangler now includes built-in shell tab completion support, making it faster and easier to navigate commands without memorizing every option. Press Tab as you type to autocomplete commands, subcommands, flags, and even option values like log levels.

Tab completions are supported for Bash, Zsh, Fish, and PowerShell.

Setup

Generate the completion script for your shell and add it to your configuration file:

# Bash
wrangler complete bash >> ~/.bashrc

# Zsh
wrangler complete zsh >> ~/.zshrc

# Fish
wrangler complete fish >> ~/.config/fish/config.fish

# PowerShell
wrangler complete powershell >> $PROFILE

After adding the script, restart your terminal or source your configuration file for the changes to take effect. Then you can simply press Tab to see available completions:

wrangler d<TAB>          # completes to 'deploy', 'dev', 'd1', etc.
wrangler kv <TAB>        # shows subcommands: namespace, key, bulk

Tab completions are dynamically generated from Wrangler's command registry, so they stay up-to-date as new commands and options are added. This feature is powered by @bomb.sh/tab ↗︎.

See the wrangler complete documentation for more details.

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Access: Admin-Aktivitätslogs erfassen Anlage von DoH-Nutzern

Die Cloudflare admin activity logs erfassen jetzt jedes Erstellen eines DNS-over-HTTP-(DoH-)Nutzers und lassen sich im Dashboard ansehen, per API abrufen und über Logpush exportieren.

Cloudflare admin activity logs now capture each time a DNS over HTTP (DoH) user is created.

These logs can be viewed from the Cloudflare One dashboard ↗︎, pulled via the Cloudflare API, and exported through Logpush.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Workers Analytics Engine SQL unterstützt HAVING und LIKE

Die SQL-API von Workers Analytics Engine unterstützt jetzt die HAVING-Klausel zum Filtern aggregierter Gruppen sowie die Operatoren LIKE, NOT LIKE, ILIKE und NOT ILIKE für Mustervergleiche.

You can now use the HAVING clause and LIKE pattern matching operators in Workers Analytics Engine ↗︎.

Workers Analytics Engine allows you to ingest and store high-cardinality data at scale and query your data through a simple SQL API.

Filtering using HAVING

The HAVING clause complements the WHERE clause by enabling you to filter groups based on aggregate values. While WHERE filters rows before aggregation, HAVING filters groups after aggregation is complete.

You can use HAVING to filter groups where the average exceeds a threshold:

SELECT
    blob1 AS probe_name,
    avg(double1) AS average_temp
FROM temperature_readings
GROUP BY probe_name
HAVING average_temp > 10

You can also filter groups based on aggregates such as the number of items in the group:

SELECT
    blob1 AS probe_name,
    count() AS num_readings
FROM temperature_readings
GROUP BY probe_name
HAVING num_readings > 100

Pattern matching using LIKE

The new pattern matching operators enable you to search for strings that match specific patterns using wildcard characters:

  • LIKE - case-sensitive pattern matching
  • NOT LIKE - case-sensitive pattern exclusion
  • ILIKE - case-insensitive pattern matching
  • NOT ILIKE - case-insensitive pattern exclusion …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Benutzerdefinierte Container-Instanztypen für alle Nutzer

Alle Cloudflare-Containers-Nutzer können nun eigene Instanztypen mit individuellen vCPU-, Speicher- und Disk-Werten festlegen, wobei mindestens 1 vCPU nötig ist und die Obergrenzen dem Typ standard-4 entsprechen.

Custom instance types are now enabled for all Cloudflare Containers users. You can now specify specific vCPU, memory, and disk amounts, rather than being limited to pre-defined instance types. Previously, only select Enterprise customers were able to customize their instance type.

To use a custom instance type, specify the instance_type property as an object with vcpu, memory_mib, and disk_mb fields in your Wrangler configuration:

[[containers]]
image = "./Dockerfile"
instance_type = { vcpu = 2, memory_mib = 6144, disk_mb = 12000 }

Individual limits for custom instance types are based on the standard-4 instance type (4 vCPU, 12 GiB memory, 20 GB disk). You must allocate at least 1 vCPU for custom instance types. For workloads requiring less than 1 vCPU, use the predefined instance types like lite or basic.

See the limits documentation for the full list of constraints on custom instance types. See the getting started guide to deploy your first Container,

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Microfrontend-Anwendungen auf Workers bauen

Microfrontends lassen sich nun auf Cloudflare bereitstellen, wobei ein Template einen Router-Worker mit vorkonfiguriertem Routing erstellt, der Anfragen per Service Bindings an unabhängig deploybare Microfrontends weiterleitet.

You can now deploy microfrontends to Cloudflare, splitting a single application into smaller, independently deployable units that render as one cohesive application. This lets different teams using different frameworks develop, test, and deploy each microfrontend without coordinating releases.

Microfrontends solve several challenges for large-scale applications:

  • Independent deployments: Teams deploy updates on their own schedule without redeploying the entire application
  • Framework flexibility: Build multi-framework applications (for example, Astro, Remix, and Next.js in one app)
  • Gradual migration: Migrate from a monolith to a distributed architecture incrementally

Create a microfrontend project:

Deploy to Cloudflare

This template automatically creates a router worker with pre-configured routing logic, and lets you configure Service bindings to Workers you have already deployed to your Cloudflare account. The router Worker analyzes incoming requests, matches them against configured routes, and forwards requests to the appropriate microfrontend via service bindings. The router automatically rewrites HTML, CSS, and headers to ensure assets load correctly from each microfrontend's mount path. The router includes advanced features like preloa…

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Magic WAN Connector: Breakout-Traffic per NetFlow sichtbar

Der Magic WAN Connector exportiert jetzt NetFlow-Daten für Breakout-Traffic an Magic Network Monitoring, sodass Traffic, der Cloudflares Sicherheitsfilter umgeht, im Dashboard sichtbar wird.

Magic WAN Connector now exports NetFlow data for breakout traffic to Magic Network Monitoring (MNM), providing visibility into traffic that bypasses Cloudflare's security filtering.

This feature allows you to:

  • Monitor breakout traffic statistics in the Cloudflare dashboard.
  • View traffic patterns for applications configured to bypass Cloudflare.
  • Maintain visibility across all traffic passing through your Magic WAN Connector.

For more information, refer to NetFlow statistics.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Agents SDK v0.3.0 mit AI SDK v6-Unterstützung

Agents SDK v0.3.0 ist vollständig mit AI SDK v6 kompatibel und bringt das einheitliche Tool-Muster, dynamische Tool-Freigabe, erweiterte React-Hooks mit onToolCall sowie bessere Fehlerbehandlung beim Streaming, und workers-ai-provider sowie ai-gateway-provider erscheinen jeweils als v3.0.0.

We've shipped a new release for the Agents SDK ↗︎ v0.3.0 bringing full compatibility with AI SDK v6 ↗︎ and introducing the unified tool pattern, dynamic tool approval, and enhanced React hooks with improved tool handling.

This release includes improved streaming and tool support, dynamic tool approval (for "human in the loop" systems), enhanced React hooks with onToolCall callback, improved error handling for streaming responses, and seamless migration from v5 patterns.

This makes it ideal for building production AI chat interfaces with Cloudflare Workers AI models, agent workflows, human-in-the-loop systems, or any application requiring reliable tool execution and approval workflows.

Additionally, we've updated workers-ai-provider v3.0.0, the official provider for Cloudflare Workers AI models, and ai-gateway-provider v3.0.0, the provider for Cloudflare AI Gateway, to be compatible with AI SDK v6.

Agents SDK v0.3.0

Unified Tool Pattern

AI SDK v6 introduces a unified tool pattern where all tools are defined on the server using the tool() function. This replaces the previous client-side AITool pattern.

Server-Side Tool Definition

import { tool } from "ai";
import { z } from "zod";

// Server: Define ALL tools on the server
const tools = {
	// Server-executed tool …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Statisches Prerendering für TanStack Start

TanStack-Start-Apps können Routen nun zur Build-Zeit mit Zugriff auf Umgebungsvariablen und Bindings als statisches HTML prerendern und als Static Assets ausliefern, wofür @tanstack/react-start v1.138.0 oder neuer nötig ist.

TanStack Start ↗︎ apps can now prerender routes to static HTML at build time with access to build time environment variables and bindings, and serve them as static assets. To enable prerendering, configure the prerender option of the TanStack Start plugin in your Vite config:

vite.config.tsts

import { defineConfig } from "vite";
import { cloudflare } from "@cloudflare/vite-plugin";
import { tanstackStart } from "@tanstack/react-start/plugin/vite";

export default defineConfig({
  plugins: [
    cloudflare({ viteEnvironment: { name: "ssr" } }),
    tanstackStart({
      prerender: {
        enabled: true,
      },
    }),
  ],
});

This feature requires @tanstack/react-start v1.138.0 or later. See the TanStack Start framework guide for more details.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Terraform v5.15.0 verfügbar

Der Terraform-Provider für Cloudflare wurde in Version 5.15.0 veröffentlicht, mit Fehlerbehebungen, Stabilisierung weiterer Ressourcen und neuen AI-Search-Endpunkten.

Earlier this year, we announced the launch of the new Terraform v5 Provider. We are aware of the high number of issues reported by the Cloudflare community related to the v5 release. We have committed to releasing improvements on a 2-3 week cadence ↗︎ to ensure its stability and reliability, including the v5.15 release. We have also pivoted from an issue-to-issue approach to a resource-per-resource approach ↗︎ - we will be focusing on specific resources to not only stabilize the resource but also ensure it is migration-friendly for those migrating from v4 to v5.

Thank you for continuing to raise issues. They make our provider stronger and help us build products that reflect your needs.

This release includes bug fixes, the stabilization of even more popular resources, and more.

Features

  • ai_search: Add AI Search endpoints (6f02adb ↗︎)
  • certificate_pack: Ensure proper Terraform resource ID handling for path parameters in API calls (081f32a ↗︎) …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

R2 Data Catalog: automatisches Ablaufen von Snapshots

R2 Data Catalog entfernt für Apache-Iceberg-Tabellen jetzt automatisch alte Snapshots anhand einer konfigurierbaren Aufbewahrungsrichtlinie mit den Parametern --older-than-days und --retain-last, um Metadaten-Overhead und Speicherkosten zu senken.

R2 Data Catalog now supports automatic snapshot expiration for Apache Iceberg tables.

In Apache Iceberg, a snapshot is metadata that represents the state of a table at a given point in time. Every mutation creates a new snapshot which enable powerful features like time travel queries and rollback capabilities but will accumulate over time.

Without regular cleanup, these accumulated snapshots can lead to:

  • Metadata overhead
  • Slower table operations
  • Increased storage costs.

Snapshot expiration in R2 Data Catalog automatically removes old table snapshots based on your configured retention policy, improving performance and storage costs.

# Enable catalog-level snapshot expiration
# Expire snapshots older than 7 days, always retain at least 10 recent snapshots
npx wrangler r2 bucket catalog snapshot-expiration enable my-bucket \
  --older-than-days 7 \
  --retain-last 10

Snapshot expiration uses two parameters to determine which snapshots to remove:

  • --older-than-days: age threshold in days
  • --retain-last: minimum snapshot count to retain

Both conditions must be met before a snapshot is expired, ensuring you always retain recent snapshots even if they exceed the age threshold. …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Workers for Platforms: Dashboard-Verbesserungen

Das Workers for Platforms Dashboard unterstützt jetzt das Anlegen von Namespaces, Dispatch-Worker-Templates und Tag-Verwaltung, sodass die Einrichtung nicht mehr nur per API erfolgen muss.

Workers for Platforms lets you build multi-tenant platforms on Cloudflare Workers, allowing your end users to deploy and run their own code on your platform. It's designed for anyone building an AI vibe coding platform, e-commerce platform, website builder, or any product that needs to securely execute user-generated code at scale.

Previously, setting up Workers for Platforms required using the API. Now, the Workers for Platforms UI supports namespace creation, dispatch worker templates, and tag management, making it easier for Workers for Platforms customers to build and manage multi-tenant platforms directly from the Cloudflare dashboard.

Workers for Platforms Dashboard Improvements

Key improvements

  • Namespace Management: You can now create and configure dispatch namespaces directly within the dashboard to start a new platform setup. …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Build-Image-Richtlinien für Workers Builds und Cloudflare Pages

Cloudflare hat Richtlinien für Build Images veröffentlicht, die Minor- und Major-Updates vorinstallierter Software sowie eine Vorankündigung von 3 bzw. 6 Monaten bei Einstellungen regeln.

We've published build image policies for Workers Builds and Cloudflare Pages, which establish:

  • Minor version updates: We typically update preinstalled software to the latest available minor version without notice. For tools that don't follow semantic versioning (e.g., Bun or Hugo), we provide 3 months’ notice.
  • Major version updates: Before preinstalled software reaches end-of-life, we update to the next stable LTS version with 3 months’ notice.
  • Build image version deprecation (Pages only): We provide 6 months’ notice before deprecation. Projects on v1 or v2 will be automatically moved to v3 on their specified deprecation dates.

To prepare for updates, monitor the Cloudflare Changelog ↗︎, dashboard notifications, and email. You can also override default versions to maintain specific versions.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Authentifizierungs-Token mit wrangler auth token abrufen

Der neue Befehl wrangler auth token gibt das aktuell konfigurierte Authentifizierungs-Token bzw. die Zugangsdaten aus, mit --json auch inklusive Token-Typ.

Wrangler now includes a new wrangler auth token command that retrieves your current authentication token or credentials for use with other tools and scripts.

wrangler auth token

The command returns whichever authentication method is currently configured, in priority order: API token from CLOUDFLARE_API_TOKEN, or OAuth token from wrangler login (automatically refreshed if expired).

Use the --json flag to get structured output including the token type:

wrangler auth token --json

The JSON output includes the authentication type:

// API token
{ "type": "api_token", "token": "..." }

// OAuth token
{ "type": "oauth", "token": "..." }

// API key/email (only available with --json)
{ "type": "api_key", "key": "...", "email": "..." }

API key/email credentials from CLOUDFLARE_API_KEY and CLOUDFLARE_EMAIL require the --json flag since this method uses two values instead of a single token.

Originalquelle(öffnet in neuem Tab)Problem melden