megachangelog
Feature

Introducing Conformance and Code Owners

Vercel is launching Conformance, a static analysis tool for catching critical issues before production, and Code Owners, an ownership system that ensures appropriate code reviews. Together, these features help teams maintain code quality and security while scaling velocity.

As organizations grow, it can become hard to sustain fast release cycles without diminishing code health and letting errors slip into production. It shouldn't be this way. We should be able to move fast  breaking things—making quick updates and innovating while retaining great performance, security, and accessibility.without

Today, we're releasing new features to Vercel's to help ship higher quality code, with the same velocity even as teams and codebases scale.Developer Experience PlatformEnterprise teams

Our Conformance tooling runs over your codebase to find critical issues before merging—allowing you to move quickly without compromising quality. It automatically checks for issues that may result in performance, security, or quality problems in your production applications.static analysis checks

Conformance rules span multiple files, instead of verifying each file individually, providing a holistic perspective on your codebase. It also adds frontend specific context to issues, classifies and tags issues, as well as assigns a severity with granular ownership of both rules and rule violation exceptions.

By providing a high-level score and tracking issues in the dashboard, you get a barometer for assessing accumulated technical debt. Much like a performance budget, this score becomes invaluable in understanding when and where to prioritize tasks. Specifically, you can before going to production, then track how you start unlisting them and burning down through the issues to improve code health. allowlist a specific number of issues

Conformance was built by the creators of and . By codifying decades of their combined experience crafting high performant web sites and deep knowledge of the framework ecosystem, we're able to go catching errors, towards actually optimizing your application.Next.jsTurborepobeyond

You can run Conformance within your CI/CD systems or locally to:

Deploying bad code has an outsized impact on a team's velocity.

Debugging alone can take away a year's worth of valuable developer time. Conformance strategically places guardrails to redirect brainpower towards creation, rather than time-consuming error detection. By proactively resolving potential issues, Conformance frees developers from unnecessary dependencies, leading to increased productivity and allowing them to channel their efforts into the projects and features that will improve end-customer experiences.

As your company grows, you need a code ownership system that grows with you.

Code Owners works with your , ensuring code reviews with smart reviewer assignments, and an escalation protocol that ensures appropriate individuals review your code and escalate concerns when needed.Git integration

Code Owners mirrors the structure of your organization. This means Code Owners who are higher up in the directory tree act as broader stewards over the codebase and are the fallback if owners files go out of date, such as when developers switch teams. And, with  your organization can tailor your code review process. For example, you can assign reviews in a round-robin style, based on who's on call, or to the whole team.Modifiers

Security remains at the forefront of every feature we release. Creating security rules with Conformance and Code Owners brings your security team into the development process. Conformance catches issues that could become security vulnerabilities, , before they make it to production. Similarly, Code Owners ensures no one on your team becomes a security vulnerability. like unsafe usage of cookies in your application

Using the features together, you can define an allowlist file for Security rules, and then assign your Security team as code owner of that file. So whenever someone tries to add something new to the list, the Security teams needs to approve it.

When you start using Conformance, you'll also see a within that gives developers and leadership team members an overall view of project health. At a glance, any team member can see global code health, Conformance scores, and the teams responsible for those repositories. This means, you can understand problem areas and investigate errors by seeing all of your allowlisted performance, security, or code-quality errors.redesigned dashboardvercel.com

and are a major step forward in providing developers with the tools and resources they need to build better, more efficient applications.ConformanceCode Owners

Today, Conformance and Code Owners are Generally Available on Vercel for Enterprise teams.

Read more

  • Automate detection of critical issues early in the development lifecycle and prevent them from reaching production.Conformance:

  • Find who is responsible for the code and make sure that code changes are reviewed by the right people, every time.Code Owners:

  • A workspace to surface code health insights, help with cross-team collaboration, and ensure a better onboarding experience for new team members.A reimagined dashboard experience:

  • Use guardrails crafted by the inventors of Next.js to catch common issues that can happen in Next.js applications. For example, detect when is not needed, as there's no use of the context parameter and it could be static generated.Next.js:getServerSideProps

  • Catch issues that negatively affect the performance of your website. For example, prevent blocking serial asynchronous calls in your applications. Performance:

  • Set general rules that can prevent things from negatively affecting your codebase or code health. For example, require that a workspace package that uses TypeScript files has configured TypeScript correctly for that workspace.Code health:

  • Act as a first layer of threat detection for security vulnerabilties. For example, require that important security headers are set correctly for Next.js apps and contain valid directives.Security:

Conformance: Out-of-the-box static analysis

Code Owners: Framework-defined ownership

A reimagined dashboard experience for monorepos

Move fast, don’t break things

Accelerate innovation, reduce time spent on bugs

All while elevating application security

conformancecode-ownerscode-qualitysecuritydeveloper-experienceenterprise

Source: original entry ↗

More from Vercel

Follow Vercel to get its new changes in your feed and email digest.

Feature

OpenAI Decisions API now available on AI Gateway

OpenAI's Decisions API is now accessible through Vercel's AI Gateway with an OpenAI-compatible endpoint, enabling decision models to answer typed questions and return probabilities, choices, and scores for routing, triage, and guardrails use cases. Support is available across the OpenAI SDK, AI SDK, HTTP API, and CLI with the latest versions.

ai-gatewayopenaiapidecisionssdks
Feature

Timestamp attributes now supported in Vercel Flags

Vercel Flags now supports timestamp attributes for entities, allowing you to create time-based targeting rules. Use this feature to run limited-time campaigns, show content between specific dates, or target users based on registration date.

flagstargetingfeaturetimestampscampaigns
Feature

Glyph Cluster now available in stealth on AI Gateway

Glyph Cluster, a reasoning model for coding and long-context analysis, is now available as a stealth model on Vercel's AI Gateway for Pro and Enterprise plan teams with purchased AI Gateway credits at no cost during the stealth period. The model supports function calling, streams responses, and can be accessed via AI SDK, OpenAI-compatible APIs, and coding agents.

ai-gatewaymodelscodingstealth
See all Vercel changes →