---
title: Changelogs
image: https://edgetunnel-b2h.pages.dev/cf-twitter-card.png
---

> Documentation Index  
> Fetch the complete documentation index at: https://edgetunnel-b2h.pages.dev/changelog/llms.txt  
> Use this file to discover all available pages before exploring further. 

[Skip to content](#%5Ftop) 

# Changelog

New updates and improvements at Cloudflare.

[ Subscribe to RSS ](https://edgetunnel-b2h.pages.dev/changelog/rss/index.xml) [ View RSS feeds ](https://edgetunnel-b2h.pages.dev/fundamentals/new-features/available-rss-feeds/) 

All products

![hero image](https://edgetunnel-b2h.pages.dev/_astro/hero.CVYJHPAd_26AMqX.svg) 

Jul 17, 2026
1. ### [Preview sent emails in the Activity log](https://edgetunnel-b2h.pages.dev/changelog/post/2026-07-17-email-message-preview/)  
[ Email Service ](https://edgetunnel-b2h.pages.dev/email-service/)  
You can now preview the content of sent emails directly from the Email Service Activity log. Expand a sent email and open the new **Preview** section to inspect the message as it was sent, across tabs for the rendered **HTML** body, the **Text** body, the **Headers**, the **Attachments**, and the full **Raw** [RFC 5322 ↗](https://datatracker.ietf.org/doc/html/rfc5322) source.  
![The rendered HTML preview of a sent email in the Email Service Activity log](https://edgetunnel-b2h.pages.dev/_astro/email-message-preview.Bj6Lk8Y6_ZQJVjF.webp)  
Previously, the Activity log surfaced delivery and authentication metadata but not the message content, making rendering and content issues harder to debug. Message preview closes that gap.  
To make messages previewable, turn on **Email preview** in your sending domain's settings. Previews cover messages sent while the setting is turned on and are retained for about seven days. Sending domains onboarded on or after 2026-07-02 have **Email preview** turned on automatically.  
![The Email preview setting in a sending domain's settings](https://edgetunnel-b2h.pages.dev/_astro/email-preview-setting.XEd1WIiO_Z1Vc9Dv.webp)  
Refer to [Email logs](https://edgetunnel-b2h.pages.dev/email-service/observability/logs/#message-preview) for more information.

Jul 17, 2026
1. ### [WAF Release - 2026-07-17 - Emergency](https://edgetunnel-b2h.pages.dev/changelog/post/2026-07-17-emergency-waf-release/)  
[ WAF ](https://edgetunnel-b2h.pages.dev/waf/)  
This emergency release adds a new managed rule to block active exploitation of a critical remote code execution (RCE) and SQL injection (SQLi) vulnerability found in popular web frameworks.

**Key Findings**

  * Generic Frameworks - Unauthenticated RCE: Attackers can execute arbitrary system commands with web server privileges by sending malicious input containing invalid path sequences during request processing.
  * Generic Frameworks - SQLi: Attackers can execute unauthorized database queries due to a failure to sanitize input values within request parameters.

| Ruleset                    | Rule ID     | Legacy Rule ID | Description                         | Previous Action | New Action | Comments                 |
| -------------------------- | ----------- | -------------- | ----------------------------------- | --------------- | ---------- | ------------------------ |
| Cloudflare Managed Ruleset | ...550664b6 | N/A            | Generic Rules - Unauthenticated RCE | N/A             | Block      | This is a new detection. |
| Cloudflare Managed Ruleset | ...ed933fcc | N/A            | Generic Rules - SQLi                | N/A             | Block      | This is a new detection. |
| Cloudflare Free Ruleset    | ...b5ec246a | N/A            | Generic Rules - Unauthenticated RCE | N/A             | Block      | This is a new detection. |
| Cloudflare Free Ruleset    | ...33697a1a | N/A            | Generic Rules - SQLi                | N/A             | Block      | This is a new detection. |

Jul 16, 2026
1. ### [Bulk print PDFs for browser-based RDP](https://edgetunnel-b2h.pages.dev/changelog/post/2026-07-16-rdp-bulk-print/)  
[ Access ](https://edgetunnel-b2h.pages.dev/cloudflare-one/access-controls/policies/)[ Cloudflare One ](https://edgetunnel-b2h.pages.dev/cloudflare-one/)  
Users in browser-based RDP sessions can now print multiple PDF files as a single print job. Copy the files to your clipboard on the remote machine, then select **Print all PDFs** in the clipboard panel. The files are combined into one PDF and sent to your local printer.  
![The clipboard panel showing the Print all PDFs option for multiple selected PDF files.](https://edgetunnel-b2h.pages.dev/_astro/rdp-bulk-print.DT4sCcI-_Z1XuBEQ.webp)  
Bulk print is available in Chromium-based browsers and Firefox. For more information, refer to [Print PDFs for browser-based RDP](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-browser/#print-pdfs).

Jul 16, 2026
1. ### [Manage Flagship from the command line with Wrangler](https://edgetunnel-b2h.pages.dev/changelog/post/2026-07-16-wrangler-commands/)  
[ Flagship ](https://edgetunnel-b2h.pages.dev/flagship/)  

**[Wrangler](https://edgetunnel-b2h.pages.dev/workers/wrangler/)** now includes `wrangler flagship`, a command suite for managing [Flagship](https://edgetunnel-b2h.pages.dev/flagship/) apps and feature flags from your terminal.  
Create an app and, if you use it from a Worker, add it to your `wrangler.json` or `wrangler.jsonc` file as a binding:  
```bash  
wrangler flagship apps create "My Worker App" \
  --binding FLAGS \
  --update-config  
```  
Then create flags for the behavior you want to control. Flags can be booleans, strings, numbers, or JSON values:  
```bash  
wrangler flagship flags create <APP_ID> new-checkout  
wrangler flagship flags create <APP_ID> checkout-flow \
  --variation control=old-checkout \
  --variation treatment=new-checkout \
  --default control \
  --type string  
```  
After a flag exists, change its default variation or use enable and disable commands as kill switches. Existing targeting rules continue to apply unless you change or clear them explicitly:  
```bash  
wrangler flagship flags update <APP_ID> checkout-flow --default treatment  
wrangler flagship flags disable <APP_ID> checkout-flow  
wrangler flagship flags enable <APP_ID> checkout-flow  
```  
For release workflows, use `rollout`, `split`, and `rules` to change exposure without redeploying your Worker:  
```bash  
wrangler flagship flags rollout <APP_ID> new-checkout \
  --to on \
  --percentage 25 \
  --by user_id  
wrangler flagship flags split <APP_ID> checkout-flow \
  --weight control=80 \
  --weight treatment=20 \
  --by user_id  
wrangler flagship flags rules update <APP_ID> checkout-flow \
  --priority 1 \
  --when "country equals US"  
```  
These commands can also be used from CI/CD pipelines, scripts, and AI agents to inspect Flagship state, update flag behavior, or roll back changes through Wrangler.  
Refer to the [wrangler flagship command reference](https://edgetunnel-b2h.pages.dev/flagship/reference/wrangler-commands/) for the full command guide.

Jul 15, 2026
1. ### [Internal DNS is now generally available](https://edgetunnel-b2h.pages.dev/changelog/post/2026-07-15-internal-dns-ga/)  
[ Gateway ](https://edgetunnel-b2h.pages.dev/cloudflare-one/traffic-policies/)[ DNS ](https://edgetunnel-b2h.pages.dev/dns/)  
[Internal DNS](https://edgetunnel-b2h.pages.dev/dns/internal-dns/) is now generally available. Internal DNS provides authoritative and recursive DNS for private networks on the same global network and control plane you already use for public DNS, Zero Trust, and application services.  
#### Why it matters

  * **Consolidate DNS operations.** Public and private DNS run on one platform, with one API, one audit trail, and one place to set policy.
  * **Simplify split-horizon DNS.** Internal and external resolution are defined as separate [views](https://edgetunnel-b2h.pages.dev/dns/internal-dns/dns-views/) over shared zones, managed from a single control plane — so there is no drift to chase down.
  * **Extend Zero Trust to DNS.** Resolver policies decide which users and devices resolve against which view, enforced by the same [Gateway](https://edgetunnel-b2h.pages.dev/cloudflare-one/traffic-policies/) that already governs the rest of your traffic.  
Setting up Internal DNS takes three steps: create a zone, create a view, and define a resolver policy.  
```json  
POST /zones  
{  
  "account": {  
    "id": "<ACCOUNT_ID>"  
  },  
  "name": "corp.internal",  
  "type": "internal"  
}  
```  
Internal DNS is included with [Cloudflare Gateway](https://edgetunnel-b2h.pages.dev/cloudflare-one/traffic-policies/) for Enterprise customers. To get started, refer to the [Internal DNS documentation](https://edgetunnel-b2h.pages.dev/dns/internal-dns/).

Jul 15, 2026
1. ### [Subscribe to Email Sending events with Queues](https://edgetunnel-b2h.pages.dev/changelog/post/2026-07-15-event-subscriptions/)  
[ Email Service ](https://edgetunnel-b2h.pages.dev/email-service/)[ Queues ](https://edgetunnel-b2h.pages.dev/queues/)  
You can now subscribe to **[Email Sending](https://edgetunnel-b2h.pages.dev/email-service/api/send-emails/) events** through [Queues event subscriptions](https://edgetunnel-b2h.pages.dev/queues/event-subscriptions/) and receive outbound transactional email lifecycle events on a queue. Each subscription is scoped to one sending domain — either the zone apex, such as `example.com`, or a verified sending subdomain, such as `send.example.com`.  
Six event types are published: `message.delivered`, `message.deferred`, `message.bounced`, `message.failed`, `message.rejected`, and `message.complained`. Use them to track deliverability, react to bounces and complaints, and drive suppression or retry logic. Email Routing events are not published on this source.  
Each event includes the message details, delivery status, and SMTP response:  
```json  
{  
  "type": "cf.email.sending.message.delivered",  
  "source": {  
    "type": "email.sending",  
    "zoneId": "023e105f4ecef8ad9ca31a8372d0c353",  
    "domain": "example.com"  
  },  
  "payload": {  
    "messageId": "0101018f7d0c4d9a-msg-deadbeef",  
    "recipient": "user@example.net",  
    "terminal": true,  
    "delivery": {  
      "status": "delivered",  
      "smtpStatusCode": "250"  
    }  
  }  
}  
```  
Refer to [Event subscriptions](https://edgetunnel-b2h.pages.dev/email-service/platform/event-subscriptions/) to see all event types and example payloads.

Jul 15, 2026
1. ### [Deprecate legacy Workers KV namespace API routes](https://edgetunnel-b2h.pages.dev/changelog/post/2026-07-15-kv-legacy-namespace-routes-deprecation/)  
[ KV ](https://edgetunnel-b2h.pages.dev/kv/)  
The legacy Workers KV API routes under `/accounts/{account_id}/workers/namespaces/*` are deprecated as of July 15, 2026, and will stop working on October 15, 2026\. Migrate to the documented [Workers KV API](https://edgetunnel-b2h.pages.dev/api/resources/kv/) routes under `/accounts/{account_id}/storage/kv/namespaces/*` before that date.  
The legacy and replacement routes are interchangeable. They accept the same request parameters and return the same response payloads. To migrate, update the URL path from `/workers/namespaces/` to `/storage/kv/namespaces/`.  
#### What you need to do  
Update any integration that calls a route under `/accounts/{account_id}/workers/namespaces/` to use the equivalent route under `/accounts/{account_id}/storage/kv/namespaces/`. The migration is a direct URL path substitution — request parameters and response payloads are identical:

  * `GET` and `POST /accounts/{account_id}/workers/namespaces` → `GET` and `POST /accounts/{account_id}/storage/kv/namespaces`
  * `GET`, `PUT`, and `DELETE /accounts/{account_id}/workers/namespaces/{namespace_id}` → `GET`, `PUT`, and `DELETE /accounts/{account_id}/storage/kv/namespaces/{namespace_id}`
  * `GET /accounts/{account_id}/workers/namespaces/{namespace_id}/keys` → `GET /accounts/{account_id}/storage/kv/namespaces/{namespace_id}/keys`
  * `GET /accounts/{account_id}/workers/namespaces/{namespace_id}/metadata/{key_name}` → `GET /accounts/{account_id}/storage/kv/namespaces/{namespace_id}/metadata/{key_name}`
  * `GET`, `PUT`, and `DELETE /accounts/{account_id}/workers/namespaces/{namespace_id}/values/{key_name}` → `GET`, `PUT`, and `DELETE /accounts/{account_id}/storage/kv/namespaces/{namespace_id}/values/{key_name}`  
For more information about the deprecation timeline, refer to [API deprecations](https://edgetunnel-b2h.pages.dev/fundamentals/api/reference/deprecations/).

Jul 14, 2026
1. ### [WAF Release - 2026-07-14](https://edgetunnel-b2h.pages.dev/changelog/post/2026-07-14-waf-release/)  
[ WAF ](https://edgetunnel-b2h.pages.dev/waf/)  
This release introduces new rules targeting critical infrastructure vulnerabilities. These include an unauthenticated memory disclosure flaw in Citrix NetScaler ADC and Gateway (CVE-2026-8451) and a high-severity pre-authentication remote code execution (RCE) vulnerability in Progress Kemp LoadMaster (CVE-2026-8037).

**Key Findings**

  * CVE-2026-8451: An insufficient input validation vulnerability affects Citrix NetScaler ADC and NetScaler Gateway appliances configured as a SAML Identity Provider (IdP). Remote, unauthenticated attackers can exploit this flaw by sending malformed requests to trigger a memory overread, allowing them to leak chunks of sensitive data from adjacent appliance memory.
  * CVE-2026-8037: A critical OS command injection vulnerability in Progress Kemp LoadMaster load balancers allows unauthenticated remote attackers to achieve remote code execution (RCE).

| Ruleset                    | Rule ID     | Legacy Rule ID | Description                                                              | Previous Action | New Action | Comments                 |
| -------------------------- | ----------- | -------------- | ------------------------------------------------------------------------ | --------------- | ---------- | ------------------------ |
| Cloudflare Managed Ruleset | ...76973ac4 | N/A            | Citrix Netscaler ADC - Insufficient Input Validation - CVE:CVE-2026-8451 | Log             | Block      | This is a new detection. |
| Cloudflare Managed Ruleset | ...10233f36 | N/A            | Progress Kemp LoadMaster - Remote Code Execution - CVE:CVE-2026-8037     | Log             | Block      | This is a new detection. |

Jul 14, 2026
1. ### [WAF Release - Scheduled changes for 2026-07-20](https://edgetunnel-b2h.pages.dev/changelog/post/scheduled-waf-release/)  
[ WAF ](https://edgetunnel-b2h.pages.dev/waf/)  

| Announcement Date | Release Date | Release Behavior | Legacy Rule ID | Rule ID     | Description                                                        | Comments                 |
| ----------------- | ------------ | ---------------- | -------------- | ----------- | ------------------------------------------------------------------ | ------------------------ |
| 2026-07-12        | 2026-07-20   | Log              | N/A            | ...215e7d31 | SSRF - Restricted Protocol                                         | This is a new detection. |
| 2026-07-12        | 2026-07-20   | Log              | N/A            | ...a935ee5d | SSRF - Obfuscated Host                                             | This is a new detection. |
| 2026-07-12        | 2026-07-20   | Log              | N/A            | ...1b0230ac | LFI - Path Traversal                                               | This is a new detection. |
| 2026-07-14        | 2026-07-20   | Log              | N/A            | ...61349c8b | Adobe ColdFusion - File Upload Path Traversal - CVE:CVE-2026-48276 | This is a new detection. |
| 2026-07-14        | 2026-07-20   | Log              | N/A            | ...9cb61eac | Adobe ColdFusion - Path Traversal - CVE:CVE-2026-48282             | This is a new detection. |
| 2026-07-14        | 2026-07-20   | Log              | N/A            | ...4ac5e21f | XSS — JS Bracket Concat Obfuscation - Body                         | This is a new detection. |
| 2026-07-14        | 2026-07-20   | Log              | N/A            | ...f31f5559 | XSS — JS Bracket Concat Obfuscation - Headers                      | This is a new detection. |
| 2026-07-14        | 2026-07-20   | Log              | N/A            | ...987984fd | XSS — JS Bracket Concat Obfuscation - URI                          | This is a new detection. |

Jul 14, 2026
1. ### [Improved reliability for account-wide Web Analytics dashboards](https://edgetunnel-b2h.pages.dev/changelog/post/2026-06-10-improved-reliability-for-web-analytics-dash/)  
[ Cloudflare Web Analytics ](https://edgetunnel-b2h.pages.dev/web-analytics/)  
Cloudflare Web Analytics (Real User Monitoring) has rolled out performance optimizations to significantly improve the stability and loading speed of account-wide dashboards.  
For larger accounts (with >100 Web Analytics sites), loading the aggregate account-wide view would often fail, running into timeouts or unexpected interface errors due to the massive scale of parallel query processing. This update optimizes how high-volume multi-site data is queried to reduce errors and provide a snappier dashboard experience.  
Accounts with up to 1,000 sites will now be able to load this account-wide aggregate view without experiencing misleading errors.  
If you have an account with over 1,000 sites, we cannot currently aggregate over this volume due to processing constraints but you will now be presented with a clear error and instruction to filter to the relevant site(s) you wish to see the data for.

Jul 14, 2026
1. ### [Platforms can now create Temporary Accounts via the Cloudflare API](https://edgetunnel-b2h.pages.dev/changelog/post/2026-07-14-temporary-accounts-api/)  
[ Workers ](https://edgetunnel-b2h.pages.dev/workers/)  
Platforms can now create temporary preview accounts through the Cloudflare REST API. This lets your platform deploy a live Worker before the user signs in to Cloudflare.  
With the Temporary Accounts API, coding agents, AI app builders, and other platforms can build a similar flow for generated Workers and supported resources.  
Your platform can keep users in its onboarding flow while they generate, deploy, and test an application. Users do not need an existing Cloudflare account, and your platform does not need write access to one.  
![Diagram showing an AI agent deploying, verifying, and redeploying a Worker in a temporary account, then a user authenticating and claiming the account to keep its resources](https://edgetunnel-b2h.pages.dev/_astro/claim-deployments-flow.Co0tUHG4_g1dGj.webp)  
The API returns a claim URL that lets the user make the temporary account and its resources permanent.  
[Cloudflare Drop ↗](https://www.cloudflare.com/drop/) demonstrates this preview-and-claim pattern for static sites. Someone can upload a site, test and share it for one hour, then sign in or create an account only when they want to keep it.  
This API expands the flow first introduced with [wrangler deploy --temporary](https://edgetunnel-b2h.pages.dev/changelog/post/2026-06-19-temporary-accounts-for-agents/). Your backend now controls the provisioning and deployment experience directly:

  1. Show Cloudflare's Terms of Service and Privacy Policy in your product, and require the user to accept them.
  2. Request and solve a proof-of-work challenge.
  3. Create a temporary preview account.
  4. Deploy with the returned temporary account ID and API token.
  5. Show the deployed Worker URL and claim URL to the user.  
```bash  
curl "https://api.cloudflare.com/client/v4/provisioning/previews/challenge" \
  -X POST \
  -H "Content-Type: application/json" \
  --data '{}'  
curl "https://api.cloudflare.com/client/v4/provisioning/previews" \
  -X POST \
  -H "Content-Type: application/json" \
  --data '{  
    "termsOfService": "https://www.cloudflare.com/terms/",  
    "privacyPolicy": "https://www.cloudflare.com/privacypolicy/",  
    "acceptTermsOfService": "yes",  
    "challengeToken": "<CHALLENGE_TOKEN>",  
    "solution": {  
      "checkpoints": "<BASE64_CHECKPOINTS>"  
    }  
  }'  
```  
For the complete API flow, proof-of-work requirements, supported products, and limits, refer to [Claim deployments (temporary accounts)](https://edgetunnel-b2h.pages.dev/workers/platform/claim-deployments/#integrate-with-the-rest-api). For the background and design goals behind this flow, refer to [Temporary Cloudflare Accounts for AI agents ↗](https://blog.cloudflare.com/temporary-accounts/).

Jul 13, 2026
1. ### [Agents can respond to MCP elicitation requests](https://edgetunnel-b2h.pages.dev/changelog/post/2026-07-13-mcp-client-elicitation/)  
[ Agents ](https://edgetunnel-b2h.pages.dev/agents/)[ Workers ](https://edgetunnel-b2h.pages.dev/workers/)  
Agents connected to Model Context Protocol (MCP) servers with [addMcpServer](https://edgetunnel-b2h.pages.dev/agents/model-context-protocol/apis/client-api/) can now handle [elicitation ↗](https://modelcontextprotocol.io/specification/2025-11-25/client/elicitation) requests.  
Elicitation lets an MCP server request user input while it handles a tool call. Form mode collects structured, non-sensitive data. URL mode asks for consent before opening an out-of-band flow, such as third-party authorization or payment.  
sequenceDiagram  
    participant User  
    participant Agent as Agent (MCP client)  
    participant Server as MCP server  
    participant Browser  
    Server->>Agent: elicitation/create  
    Agent->>User: Show server, reason, and input or URL  
    User->>Agent: Submit, open, decline, or cancel  
    Agent->>Browser: Open URL after consent (URL mode)  
    Agent->>Server: accept, decline, or cancel  
    Server-->>Agent: Optional URL completion notification  
Register a handler for each mode your Agent supports in `onStart()`:

  * [  JavaScript ](#tab-panel-4944)
  * [  TypeScript ](#tab-panel-4945)

**JavaScript**  
```js  
import { Agent } from "agents";  
export class MyAgent extends Agent {  
  onStart() {  
    this.mcp.configureElicitationHandlers({  
      form: (request, serverId) => this.forwardToUser(request, serverId),  
      url: (request, serverId) => this.forwardToUser(request, serverId),  
    });  
  }  
  forwardToUser(request, serverId) {  
    // Show the request in your UI and resolve after the user responds.  
    throw new Error(  
      `Implement elicitation for ${serverId}: ${request.params.message}`,  
    );  
  }  
}  
```

**TypeScript**  
```ts  
import { Agent } from "agents";  
import type { ElicitRequest, ElicitResult } from "agents/mcp";  
export class MyAgent extends Agent<Env> {  
  onStart() {  
    this.mcp.configureElicitationHandlers({  
      form: (request, serverId) => this.forwardToUser(request, serverId),  
      url: (request, serverId) => this.forwardToUser(request, serverId),  
    });  
  }  
  private forwardToUser(  
    request: ElicitRequest,  
    serverId: string,  
  ): Promise<ElicitResult> {  
    // Show the request in your UI and resolve after the user responds.  
    throw new Error(  
      `Implement elicitation for ${serverId}: ${request.params.message}`,  
    );  
  }  
}  
```  
Connections advertise only the modes with configured handlers. An Agent without handlers advertises no elicitation capability, which lets the server use its fallback. The SDK stores the advertised modes with each MCP server registration so they survive Durable Object hibernation. Callback functions remain in memory and reattach when `onStart()` runs.  
For implementation details and a browser forwarding pattern, refer to [MCP client elicitation](https://edgetunnel-b2h.pages.dev/agents/model-context-protocol/apis/client-api/#elicitation). The [mcp-client ↗](https://github.com/cloudflare/agents/tree/main/examples/mcp-client) and [mcp-elicitation ↗](https://github.com/cloudflare/agents/tree/main/examples/mcp-elicitation) examples implement both sides.  
#### Upgrade  
To update to this release:  
 npm  yarn  pnpm  bun  
```  
npm i agents@latest  
```  
```  
yarn add agents@latest  
```  
```  
pnpm add agents@latest  
```  
```  
bun add agents@latest  
```

Jul 13, 2026
1. ### [Precursor introduces session-based bot detection](https://edgetunnel-b2h.pages.dev/changelog/post/2026-07-13-precursor-session-based-detection/)  
[ Challenges ](https://edgetunnel-b2h.pages.dev/cloudflare-challenges/)  
Precursor is rolling out to all customers starting today. Precursor is client-side JavaScript that enables session-based bot detection.  
You can [read the announcement blog ↗](https://blog.cloudflare.com/introducing-precursor) for background on why we built Precursor and how session-level behavioral detection works.  
With Precursor enabled, Cloudflare can:

  * Continuously evaluate behavioral signals across a session
  * Re-validate challenge clearance as behavior changes
  * Update bot scores with session context
  * Provide client-side visibility where none previously existed  
It integrates with existing protections, including Security Rules, and can be enabled directly from the Cloudflare dashboard with configurable modes to balance security and user experience.  
![Animated walkthrough of enabling Precursor in the Cloudflare dashboard](https://edgetunnel-b2h.pages.dev/images/precursor/enabling_precursor.gif)  
To learn more, refer to the [Precursor documentation](https://edgetunnel-b2h.pages.dev/cloudflare-challenges/precursor/).

Jul 13, 2026
1. ### [Origin Content Signals for Markdown for Agents](https://edgetunnel-b2h.pages.dev/changelog/post/2026-07-13-markdown-for-agents-header-preservation/)  
[ Cloudflare Fundamentals ](https://edgetunnel-b2h.pages.dev/fundamentals/)  
[Markdown for Agents](https://edgetunnel-b2h.pages.dev/fundamentals/reference/markdown-for-agents/) now preserves security- and cache-relevant response headers from your origin when converting HTML to Markdown:

  * Markdown for Agents preserves security headers such as `Strict-Transport-Security` (HSTS), `Content-Security-Policy` (CSP), `X-Frame-Options`, `Set-Cookie`, and CORS headers (for example, `Access-Control-Allow-Origin`) on the converted response.
  * Caching headers (`Cache-Control`, `Expires`, `Age`) continue to pass through.  
Your origin's [Content Signals ↗](https://contentsignals.org/) policy is now authoritative. If your origin sets a `content-signal` header, Markdown for Agents preserves it. When the origin does not send one, Cloudflare adds the default `Content-Signal: ai-train=yes, search=yes, ai-input=yes`.  
This release also fixes relative link resolution for directory-style base URLs (those ending in a trailing slash). Previously, relative links such as `../page/` could resolve one path segment too high and return a `404`. Links are now resolved correctly per [RFC 3986 ↗](https://www.rfc-editor.org/rfc/rfc3986#section-5.2.3).  
Refer to our [developer documentation](https://edgetunnel-b2h.pages.dev/fundamentals/reference/markdown-for-agents/) for more details.

Jul 13, 2026
1. ### [R2 Data Catalog now supports read-only API tokens](https://edgetunnel-b2h.pages.dev/changelog/post/2026-07-09-r2-data-catalog-read-only-tokens/)  
[ R2 ](https://edgetunnel-b2h.pages.dev/r2/)  
[R2 Data Catalog](https://edgetunnel-b2h.pages.dev/r2/data-catalog/) now accepts read-only API tokens, so query engines and clients that only read data no longer need a read-write token. Previously, every catalog operation required an **Admin Read & Write** token, which meant read-only clients were granted more access than they needed.  
You can now authenticate your Iceberg engine based on your workload:

  * **Read-only** operations (such as listing namespaces, loading tables, and querying data) work with an **Admin Read only** token (R2 Data Catalog read and R2 storage read).
  * **Write** operations (such as creating or dropping tables and committing transactions) continue to require an **Admin Read & Write** token.  
This lets you follow the principle of least privilege — for example, using a read-write token for the pipeline that writes to your tables and read-only tokens for engines like [R2 SQL](https://edgetunnel-b2h.pages.dev/r2-sql/), [DuckDB](https://edgetunnel-b2h.pages.dev/r2/data-catalog/config-examples/duckdb/), or [PyIceberg](https://edgetunnel-b2h.pages.dev/r2/data-catalog/config-examples/pyiceberg/) that query them.  
Note that credentials vended by the catalog inherit the R2 storage permissions of the token used to authenticate. To ensure read-only access to your underlying data, scope the R2 storage permission to read-only as well.  
For details on choosing and creating the right token, refer to [Authenticate your Iceberg engine](https://edgetunnel-b2h.pages.dev/r2/data-catalog/manage-catalogs/#authenticate-your-iceberg-engine).

Jul 13, 2026
1. ### [R2 Data Catalog compaction now optimizes manifest files](https://edgetunnel-b2h.pages.dev/changelog/post/2026-07-13-r2-data-catalog-manifest-optimization/)  
[ R2 Data Catalog ](https://edgetunnel-b2h.pages.dev/r2/data-catalog/)[ R2 ](https://edgetunnel-b2h.pages.dev/r2/)  
[R2 Data Catalog](https://edgetunnel-b2h.pages.dev/r2/data-catalog/), a managed [Apache Iceberg ↗](https://iceberg.apache.org/) catalog built into R2, now automatically optimizes manifest files as part of [compaction](https://edgetunnel-b2h.pages.dev/r2/data-catalog/table-maintenance/).  
Manifest files track the data files that make up an Iceberg table. As a table accumulates many small or fragmented manifests, query engines must read more metadata during query planning, which slows down queries even before any data is scanned.  
When compaction runs, R2 Data Catalog now rewrites and clusters manifest files by partition as a best-effort pre-step. This consolidates fragmented manifests, reduces the number of manifests a query engine must open, and lowers metadata I/O overhead. Tables that are already well-clustered are skipped, so the operation only runs when it provides a benefit.  
This happens automatically for tables with compaction enabled — no configuration changes are required.  
For more information, refer to [Table maintenance](https://edgetunnel-b2h.pages.dev/r2/data-catalog/table-maintenance/).

Jul 10, 2026
1. ### [Source code detection improvements](https://edgetunnel-b2h.pages.dev/changelog/post/2026-07-10-source-code-detection-improvements/)  
[ Data Loss Prevention ](https://edgetunnel-b2h.pages.dev/cloudflare-one/data-loss-prevention/)  
Data Loss Prevention (DLP) source code detection now focuses on identifying whole source code file uploads and downloads. Previously, source code detection performed partial scans resulting in a higher rate of false positives. Since only whole source code files are evaluated, code embedded in other content — such as chat messages, documentation, or code samples — is no longer flagged as source code, removing a common source of false positives.  
Source code detection requires a minimum of 500 characters to evaluate a file. Files below this threshold are not flagged to reduce noise. This threshold filters out small fragments that lack enough context for reliable classification.  
Enable and set [confidence levels](https://edgetunnel-b2h.pages.dev/cloudflare-one/data-loss-prevention/dlp-profiles/advanced-settings/#confidence-thresholds) to tune match sensitivity. A higher confidence level reduces false positives by requiring stronger signals that the content is truly source code. A lower confidence level catches more files at the cost of additional noise.  
Source code detection applies to standalone source code files in [Gateway HTTP policies](https://edgetunnel-b2h.pages.dev/cloudflare-one/traffic-policies/http-policies/). It does not detect source code embedded within other file types or payloads, such as `.docx` files or chat messages.  
For more information, refer to [Source Code predefined profiles](https://edgetunnel-b2h.pages.dev/cloudflare-one/data-loss-prevention/dlp-profiles/predefined-profiles/#source-code).

Jul 10, 2026
1. ### [Plain text output for Markdown Conversion](https://edgetunnel-b2h.pages.dev/changelog/post/2026-07-13-markdown-conversion-text-output/)  
[ Workers AI ](https://edgetunnel-b2h.pages.dev/workers-ai/)  
The [Markdown Conversion](https://edgetunnel-b2h.pages.dev/workers-ai/features/markdown-conversion/) service now supports a new `output` conversion option that controls the format of the converted content.  
Set `output.format` to `text` to receive plain text with Markdown syntax removed. The default value is `markdown`, so existing conversions are unchanged.  
Use the [env.AI](https://edgetunnel-b2h.pages.dev/workers-ai/features/markdown-conversion/usage/binding/) binding:

  * [  JavaScript ](#tab-panel-4942)
  * [  TypeScript ](#tab-panel-4943)

**JavaScript**  
```js  
await env.AI.toMarkdown(  
  { name: "page.html", blob: new Blob([html]) },  
  {  
    conversionOptions: {  
      output: { format: "text" },  
    },  
  },  
);  
```

**TypeScript**  
```ts  
await env.AI.toMarkdown(  
  { name: "page.html", blob: new Blob([html]) },  
  {  
    conversionOptions: {  
      output: { format: "text" },  
    },  
  },  
);  
```  
Or call the REST API:  
```bash  
curl https://api.cloudflare.com/client/v4/accounts/{ACCOUNT_ID}/ai/tomarkdown \
  -H 'Authorization: Bearer {API_TOKEN}' \
  -F 'files=@index.html' \
  -F 'conversionOptions={"output": {"format": "text"}}'  
```  
When you request text output, the `format` field of each result is set to `text`. For more details, refer to [Conversion Options](https://edgetunnel-b2h.pages.dev/workers-ai/features/markdown-conversion/conversion-options/#output).

Jul 09, 2026
1. ### [Workflows now supports delay functions when retrying](https://edgetunnel-b2h.pages.dev/changelog/post/2026-07-09-dynamic-retry-delays/)  
[ Workflows ](https://edgetunnel-b2h.pages.dev/workflows/)  
With [Workflows](https://edgetunnel-b2h.pages.dev/workflows/), you can configure built-in retry behavior for each step. Previously, you could configure step retries with fixed delay durations, such as seconds, minutes, or hours, and backoff strategies such as `constant`, `linear`, or `exponential`.  
Step retries now support dynamic delay functions. Instead of choosing only a base delay and backoff strategy, pass a function to `retries.delay` and calculate the next delay from the failed attempt and thrown error.  
This is useful when retries should depend on the failure. Your Workflow may need to wait longer after a rate-limit error, but retry sooner after a short network failure. The delay function can also accommodate provider guidance if, for example, a downstream API returns a `Retry-After` value in its error messaging.

  * [  JavaScript ](#tab-panel-4946)
  * [  TypeScript ](#tab-panel-4947)

**JavaScript**  
```js  
await step.do(  
  "sync customer",  
  {  
    retries: {  
      limit: 5,  
      delay: ({ ctx, error }) => {  
        if (error.message.includes("rate limit")) {  
          return `${ctx.attempt * 30} seconds`;  
        }  
        return "10 seconds";  
      },  
    },  
  },  
  async () => {  
    await syncCustomer();  
  },  
);  
```

**TypeScript**  
```ts  
await step.do(  
  "sync customer",  
  {  
    retries: {  
      limit: 5,  
      delay: ({ ctx, error }) => {  
        if (error.message.includes("rate limit")) {  
          return `${ctx.attempt * 30} seconds`;  
        }  
        return "10 seconds";  
      },  
    },  
  },  
  async () => {  
    await syncCustomer();  
  },  
);  
```  
Dynamic delay functions can return a duration string, a number, or a promise that resolves to a duration. Use them to add adaptive retry behavior without writing separate queue or scheduling logic. For more information, refer to [Sleeping and retrying](https://edgetunnel-b2h.pages.dev/workflows/build/sleeping-and-retrying/).

Jul 09, 2026
1. ### [New DNS Firewall UX with more dashboard settings](https://edgetunnel-b2h.pages.dev/changelog/post/2026-07-09-new-dns-firewall-ux/)  
[ DNS ](https://edgetunnel-b2h.pages.dev/dns/)  
The DNS Firewall page in the Cloudflare dashboard has been refreshed, bringing several settings that were previously API-only into the UI and modernizing how you view and manage your DNS Firewall clusters.  
![New DNS Firewall UX](https://edgetunnel-b2h.pages.dev/_astro/dnsfw-new-ux.vHgdhBZD_10POx6.webp)  
#### What is new

  * **More settings in the dashboard**: cluster options that were previously only configurable through the API — such as attack mitigation, rate limiting, negative TTL, and resolver subnet — are now available directly in the dashboard.
  * **Better table experience**: the DNS Firewall cluster table has been revised to surface cluster details at a glance, with resizable columns and the option to show or hide columns to tailor the view to your workflow.
  * **New create and edit UX**: adding and editing clusters now uses a modernized form that groups related settings together, making configuration faster and clearer.  
#### Availability  
Available to all DNS Firewall customers as part of their existing subscription.  
#### Where to find it  
In the Cloudflare dashboard, go to the **DNS Firewall** page.  
[ Go to **Clusters** ](https://dash.cloudflare.com/?to=/:account/dns-firewall/clusters)  
For more information, refer to [DNS Firewall](https://edgetunnel-b2h.pages.dev/dns/dns-firewall/).

Jul 09, 2026
1. ### [New Durable Object namespaces must use the SQLite storage backend](https://edgetunnel-b2h.pages.dev/changelog/post/2026-07-09-restrict-new-kv-backed-namespaces/)  
[ Durable Objects ](https://edgetunnel-b2h.pages.dev/durable-objects/)[ Workers ](https://edgetunnel-b2h.pages.dev/workers/)  
If your account does not already have a key-value (KV) backed Durable Object namespace, you can no longer create new ones. New Durable Object namespaces must use the [SQLite storage backend](https://edgetunnel-b2h.pages.dev/durable-objects/best-practices/access-durable-objects-storage/#create-sqlite-backed-durable-object-class), which has been recommended for all new Durable Objects since it became [generally available ↗](https://blog.cloudflare.com/sqlite-in-durable-objects/) in 2024.  
Create a new class with a `new_sqlite_classes` migration:

  * [  wrangler.jsonc ](#tab-panel-4938)
  * [  wrangler.toml ](#tab-panel-4939)

**JSONC**  
```jsonc  
{  
  "$schema": "./node_modules/wrangler/config-schema.json",  
  "migrations": [  
    {  
      "tag": "v1",  
      "new_sqlite_classes": [  
        "MyDurableObject"  
      ]  
    }  
  ]  
}  
```

**TOML**  
```toml  
[[migrations]]  
tag = "v1"  
new_sqlite_classes = ["MyDurableObject"]  
```  
SQLite-backed Durable Objects have feature parity with the key-value backend — including the [key-value storage API](https://edgetunnel-b2h.pages.dev/durable-objects/api/sqlite-storage-api/#synchronous-kv-api) — and additionally support relational [SQL queries](https://edgetunnel-b2h.pages.dev/durable-objects/api/sqlite-storage-api/#sql-api) and [point-in-time recovery](https://edgetunnel-b2h.pages.dev/durable-objects/api/sqlite-storage-api/#pitr-point-in-time-recovery-api) to restore an object's storage to any point in the past 30 days.  
If you attempt to create a new key-value backed namespace (a `new_classes` migration) on an affected account, the deployment fails with the following error:  
```txt  
Creating new key-value backed Durable Object namespaces is no longer supported on this account. Please create a namespace using a `new_sqlite_classes` migration instead.  
```  
This change only affects accounts that are not already using the key-value storage backend. Accounts with at least one existing key-value backed namespace can still create new ones for now, and the Workers Free plan has only ever supported SQLite-backed Durable Objects. It is part of a broader move toward SQLite as the single storage backend for Durable Objects, ahead of a future migration path for existing key-value backed objects.  
For more information, refer to [Durable Objects migrations](https://edgetunnel-b2h.pages.dev/durable-objects/reference/durable-objects-migrations/).

Jul 09, 2026
1. ### [Zero Trust Networks route endpoints and Cloudflare Tunnel connections field retiring on October 5, 2026](https://edgetunnel-b2h.pages.dev/changelog/post/2026-07-09-tunnel-routes-and-connections-api-changes/)  
[ Cloudflare Tunnel ](https://edgetunnel-b2h.pages.dev/tunnel/)[ Cloudflare Tunnel for SASE ](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/connectors/cloudflare-tunnel/)[ Cloudflare Mesh ](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/connectors/cloudflare-mesh/)  
On **October 5, 2026**, two changes take effect across the [Zero Trust Networks API](https://edgetunnel-b2h.pages.dev/api/resources/zero%5Ftrust/subresources/networks/) and [Cloudflare Tunnel API](https://edgetunnel-b2h.pages.dev/api/resources/zero%5Ftrust/subresources/tunnels/): the CIDR-encoded route endpoints are removed, and tunnel list and get responses no longer include the `connections` field. If you manage private network routes or read tunnel connection details through the API, `cloudflared`, Terraform, or another integration, review the changes in the following sections and migrate before the removal date.  
#### Route endpoints  
The CIDR-encoded route endpoints are deprecated in favor of the standard, `route_id`\-based endpoints that already exist today. Both sets of endpoints route a private network through [Cloudflare Tunnel](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/connectors/cloudflare-tunnel/) or [Cloudflare Mesh](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/connectors/cloudflare-mesh/) (the API still refers to Mesh nodes as `warp_connector`) — only the request shape changes.

**Deprecated endpoints (removed October 5, 2026):**

  * Create a tunnel route (CIDR Endpoint): [POST /accounts/{account\_id}/teamnet/routes/network/{ip\_network\_encoded}](https://edgetunnel-b2h.pages.dev/api/resources/zero%5Ftrust/subresources/networks/subresources/routes/subresources/networks/methods/create/)
  * Update a tunnel route (CIDR Endpoint): [PATCH /accounts/{account\_id}/teamnet/routes/network/{ip\_network\_encoded}](https://edgetunnel-b2h.pages.dev/api/resources/zero%5Ftrust/subresources/networks/subresources/routes/subresources/networks/methods/edit/)
  * Delete a tunnel route (CIDR Endpoint): [DELETE /accounts/{account\_id}/teamnet/routes/network/{ip\_network\_encoded}](https://edgetunnel-b2h.pages.dev/api/resources/zero%5Ftrust/subresources/networks/subresources/routes/subresources/networks/methods/delete/)

**Replacement endpoints:**

  * Create a tunnel route: [POST /accounts/{account\_id}/teamnet/routes](https://edgetunnel-b2h.pages.dev/api/resources/zero%5Ftrust/subresources/networks/subresources/routes/methods/create/)
  * Update a tunnel route: [PATCH /accounts/{account\_id}/teamnet/routes/{route\_id}](https://edgetunnel-b2h.pages.dev/api/resources/zero%5Ftrust/subresources/networks/subresources/routes/methods/edit/)
  * Delete a tunnel route: [DELETE /accounts/{account\_id}/teamnet/routes/{route\_id}](https://edgetunnel-b2h.pages.dev/api/resources/zero%5Ftrust/subresources/networks/subresources/routes/methods/delete/)  
#### What is changing

|                  | Deprecated (CIDR-encoded path)                                 | Replacement                                                         |
| ---------------- | -------------------------------------------------------------- | ------------------------------------------------------------------- |
| Route identifier | URL-encoded CIDR in the path (/network/{ip\_network\_encoded}) | route\_id in the path (network moves to the request body on create) |
| Create           | POST .../teamnet/routes/network/{ip\_network\_encoded}         | POST .../teamnet/routes with network and tunnel\_id in the body     |
| Update           | PATCH .../teamnet/routes/network/{ip\_network\_encoded}        | PATCH .../teamnet/routes/{route\_id}                                |
| Delete           | DELETE .../teamnet/routes/network/{ip\_network\_encoded}       | DELETE .../teamnet/routes/{route\_id}                               |  
#### Action required

  1. Capture each route's `route_id` by calling [List tunnel routes](https://edgetunnel-b2h.pages.dev/api/resources/zero%5Ftrust/subresources/networks/subresources/routes/methods/list/), or read it from the response the first time you create a route with the replacement endpoint.
  2. Update any scripts, backend services, or CI/CD pipelines that call the CIDR-encoded endpoints directly.
  3. If you manage routes with the `cloudflared tunnel route ip add | delete` commands, upgrade `cloudflared` to the [latest version ↗](https://github.com/cloudflare/cloudflared/releases).
  4. If you manage routes with Terraform, make sure you are on a current version of the [cloudflare\_zero\_trust\_tunnel\_cloudflared\_route ↗](https://registry.terraform.io/providers/cloudflare/cloudflare/latest/docs/resources/zero%5Ftrust%5Ftunnel%5Fcloudflared%5Froute) resource and the [Cloudflare Terraform provider ↗](https://registry.terraform.io/providers/cloudflare/cloudflare/latest/docs).  
```bash  
# Before: create a route by URL-encoding the CIDR into the path  
curl https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/teamnet/routes/network/172.16.0.0%2F16 \
     -H 'Content-Type: application/json' \
     -H "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
     -d '{"tunnel_id": "'$TUNNEL_ID'", "comment": "Example comment for this route."}'  
# After: create a route with the network in the request body  
curl https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/teamnet/routes \
     -H 'Content-Type: application/json' \
     -H "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
     -d '{"network": "172.16.0.0/16", "tunnel_id": "'$TUNNEL_ID'", "comment": "Example comment for this route."}'  
# After: update or delete a route using its route_id  
curl -X PATCH https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/teamnet/routes/$ROUTE_ID \
     -H 'Content-Type: application/json' \
     -H "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
     -d '{"comment": "Updated comment for this route."}'  
curl -X DELETE https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/teamnet/routes/$ROUTE_ID \
     -H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"  
```  
#### Cloudflare Tunnel and Cloudflare Mesh connections  
Starting the same day, the `connections` array is removed from list and get responses for [Cloudflare Tunnel](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/connectors/cloudflare-tunnel/) and [Cloudflare Mesh](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/connectors/cloudflare-mesh/) nodes (the `cfd_tunnel` and `warp_connector` API resources). Query the dedicated connections endpoint instead of reading the field off the tunnel or node object.  
This affects:

  * [GET /accounts/{account\_id}/cfd\_tunnel](https://edgetunnel-b2h.pages.dev/api/resources/zero%5Ftrust/subresources/tunnels/subresources/cloudflared/methods/list/) — `connections` removed from each item in `result`
  * [GET /accounts/{account\_id}/cfd\_tunnel/{tunnel\_id}](https://edgetunnel-b2h.pages.dev/api/resources/zero%5Ftrust/subresources/tunnels/subresources/cloudflared/methods/get/) — `connections` removed from `result`
  * [GET /accounts/{account\_id}/warp\_connector](https://edgetunnel-b2h.pages.dev/api/resources/zero%5Ftrust/subresources/tunnels/subresources/warp%5Fconnector/methods/list/) — `connections` removed from each item in `result`
  * [GET /accounts/{account\_id}/warp\_connector/{tunnel\_id}](https://edgetunnel-b2h.pages.dev/api/resources/zero%5Ftrust/subresources/tunnels/subresources/warp%5Fconnector/methods/get/) — `connections` removed from `result`  
#### Action required  
Fetch connection details from the tunnel-specific connections endpoint instead of parsing it off the list or get response. For Cloudflare Tunnel, call [GET /accounts/{account\_id}/cfd\_tunnel/{tunnel\_id}/connections](https://edgetunnel-b2h.pages.dev/api/resources/zero%5Ftrust/subresources/tunnels/subresources/cloudflared/subresources/connections/methods/get/). For Cloudflare Mesh, call [GET /accounts/{account\_id}/warp\_connector/{tunnel\_id}/connections](https://edgetunnel-b2h.pages.dev/api/resources/zero%5Ftrust/subresources/tunnels/subresources/warp%5Fconnector/subresources/connections/methods/get/).  
```bash  
# Before: read connections off the tunnel object  
curl https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/cfd_tunnel/$TUNNEL_ID \
     -H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"  
# After: query connections directly  
curl https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/cfd_tunnel/$TUNNEL_ID/connections \
     -H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"  
```  
Update any dashboards, monitoring scripts, or automation that parses `connections` from the tunnel list or get response. `cloudflared` and the Cloudflare Terraform provider do not read this field, so no changes are required on their side for this part of the update.  
#### Why we are making these changes

  * **Smaller, faster responses.** Cloudflare Tunnel and Cloudflare Mesh nodes with many connections no longer inflate every list and get call — connection detail is only fetched when you need it.
  * **A single way to identify a route.** Consolidating on `route_id` removes the need to URL-encode CIDR ranges into the path and matches how every other resource in the Zero Trust Networks API is addressed.
  * **Consistency across the API.** Both changes align these endpoints with Cloudflare's standard REST conventions for resource identifiers and nested detail endpoints.  
To learn more, refer to the [Zero Trust Networks API](https://edgetunnel-b2h.pages.dev/api/resources/zero%5Ftrust/subresources/networks/), the [Cloudflare Tunnel API](https://edgetunnel-b2h.pages.dev/api/resources/zero%5Ftrust/subresources/tunnels/), and [Routes](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/routes/) documentation.

Jul 09, 2026
1. ### [Send npm package dependency metadata with Worker uploads](https://edgetunnel-b2h.pages.dev/changelog/post/2026-07-07-wrangler-deploy-upload-dependencies-metadata/)  
[ Workers ](https://edgetunnel-b2h.pages.dev/workers/)  
Wrangler now collects npm package dependency information from your project's `package.json` during [wrangler deploy](https://edgetunnel-b2h.pages.dev/workers/wrangler/commands/general/#deploy) and [wrangler versions upload](https://edgetunnel-b2h.pages.dev/workers/wrangler/commands/general/#upload), and includes it in the upload metadata sent to the Cloudflare API. This data, each dependency's name, declared version range, and exact installed version, enables dependency analytics and future supply chain security features such as vulnerability alerting.  
To opt out, set [dependencies\_instrumentation.enabled](https://edgetunnel-b2h.pages.dev/workers/wrangler/configuration/#top-level-only-keys) to `false` in your Wrangler configuration file:

  * [  wrangler.jsonc ](#tab-panel-4940)
  * [  wrangler.toml ](#tab-panel-4941)

**JSONC**  
```jsonc  
{  
  "dependencies_instrumentation": {  
    "enabled": false  
  }  
}  
```

**TOML**  
```toml  
[dependencies_instrumentation]  
enabled = false  
```  
For more details, refer to [Wrangler configuration](https://edgetunnel-b2h.pages.dev/workers/wrangler/configuration/#top-level-only-keys).

Jul 08, 2026
1. ### [Filter AI Search list items by exact object key](https://edgetunnel-b2h.pages.dev/changelog/post/2026-07-08-ai-search-list-items-key-filter/)  
[ AI Search ](https://edgetunnel-b2h.pages.dev/ai-search/)  
In [AI Search](https://edgetunnel-b2h.pages.dev/ai-search/), you can upload files to an instance, or connect a [data source](https://edgetunnel-b2h.pages.dev/ai-search/configuration/data-source/) such as an R2 bucket, to make your content searchable with natural language. Each file becomes an **item** identified by an object **key** (its filename or path). The [list items endpoint](https://edgetunnel-b2h.pages.dev/ai-search/api/items/rest-api/) returns the items in an instance.  
That endpoint now accepts a `key` query parameter, so you can look up a single item by its exact object key without paging through the full list. This complements the existing `item_id` filter for when you know the key but not the ID.  
```bash  
curl "https://api.cloudflare.com/client/v4/accounts/<ACCOUNT_ID>/ai-search/instances/<INSTANCE_NAME>/items?key=docs/readme.md" \
  -H "Authorization: Bearer <API_TOKEN>"  
```  
Keys are unique per data source, so combine `key` with `source` (for example, `source=builtin`) to disambiguate when the same key exists across multiple sources.  
For more information, refer to [managing items](https://edgetunnel-b2h.pages.dev/ai-search/api/items/rest-api/).

Jul 08, 2026
1. ### [Workers AI toMarkdown and AI Search now supports GIF and BMP image conversion](https://edgetunnel-b2h.pages.dev/changelog/post/2026-07-08-gif-bmp-image-support/)  
[ Workers AI ](https://edgetunnel-b2h.pages.dev/workers-ai/)[ AI Search ](https://edgetunnel-b2h.pages.dev/ai-search/)  
Workers AI [Markdown conversion](https://edgetunnel-b2h.pages.dev/workers-ai/features/markdown-conversion/) (`toMarkdown`) now supports `.gif` and `.bmp` image files, in addition to the JPEG, PNG, WebP, and SVG formats already supported.  
GIF and BMP files run through the same [image pipeline](https://edgetunnel-b2h.pages.dev/workers-ai/features/markdown-conversion/how-it-works/#images) as other formats. Each image is resized if needed (and for animated GIFs, only the first frame is used), then passed to an object-detection model to identify what it contains. Those detected objects prompt a vision model that writes a natural-language description of the image, which becomes searchable, machine-readable Markdown.  
[AI Search](https://edgetunnel-b2h.pages.dev/ai-search/) uses `toMarkdown` automatically to process the files it ingests, so any `.gif` and `.bmp` files are included the next time your index syncs, with no configuration changes required. This helps when your content mixes formats, for example a support knowledge base full of screenshots or an archive of BMP scans.  
Learn more about [Markdown conversion](https://edgetunnel-b2h.pages.dev/workers-ai/features/markdown-conversion/) and the full list of [AI Search's supported file types](https://edgetunnel-b2h.pages.dev/ai-search/configuration/data-source/#supported-file-types).

```json
{"@context":"https://schema.org","@type":"BlogPosting","@id":"https://edgetunnel-b2h.pages.dev/changelog/#page","headline":"Changelogs | Cloudflare Docs","url":"https://edgetunnel-b2h.pages.dev/changelog/","inLanguage":"en","image":"https://edgetunnel-b2h.pages.dev/cf-twitter-card.png","publisher":{"@type":"Organization","name":"Cloudflare","url":"https://www.cloudflare.com/"},"isPartOf":{"@type":"WebSite","@id":"https://edgetunnel-b2h.pages.dev/#website","name":"Cloudflare Docs","url":"https://edgetunnel-b2h.pages.dev/"}}
```
