# Changelog

## Changelog, page 102

3 April3 Apr

- [

    ## Vercel Secure Compute now supports multiple environments

    Users can now associate each project environment—Production, Preview, and custom—with a distinct Secure Compute network directly from the project settings

    Miroslav Simulcik, Meg Bird, and 1 other

    ](/changelog/vercel-secure-compute-now-supports-multiple-environments)

- [

    ## Two-Factor Authentication (2FA) is now available

    Two-Factor Authentication (2FA) is now available. You can now secure your personal account using Two-Factor Authentication (2FA) with Time-based One-Time Passwords (TOTP)

    Enric Pallerols, Meg Bird, and 1 other

    ](/changelog/2fa-is-now-available)

2 April2 Apr

- [

    ## CVE-2025-30218

    In the process of remediating CVE-2025-29927, we looked at other possible exploits of Middleware. We independently verified this low severity vulnerability at the same time as two further reports from independent researchers.

    Ty SbanoChief Information Security Officer

    ](/changelog/cve-2025-30218)

1 April1 Apr

- [

    ## Attack Challenge Mode now allows verified bots and Vercel cron jobs

    Vercel's Attack Challenge Mode blocks attacks while securely allowing verified webhooks, search engines, and analytics tools.

    Malavika Tadeusz, Sage Abraham, and 3 others

    ](/changelog/attack-challenge-mode-now-allows-verified-bots-and-vercel-cron-jobs)

31 March31 Mar

- [

    ## Yarn 2+ dependency caching now supported

    Vercel's build cache now supports Yarn 2+ dependencies. Previously, dependencies were only cached for npm, pnpm, and Yarn 1.

    Austin MerrickSoftware Engineer

    ](/changelog/yarn-2-dependency-caching-now-supported)

- [

    ## Flags SDK 3.2

    Flags SDK 3.2 now supports precomputing pattern in SvelteKit, making it possible to use feature flags on static pages without causing layout shift or jank.

    Simon Holthausen, Dominik Ferber

    ](/changelog/flags-sdk-3-2)

25 March25 Mar

- [

    ## Custom reporting now available on AI Gateway

    Track and analyze AI costs across models, providers, and users with Custom Reporting for Vercel AI Gateway. Tag requests, query spend by any dimension, and get full visibility into your AI usage, with no extra tools needed.

    Walter Korman, Matt Lenhard, and 2 others

    ](/changelog/custom-reporting-ai-gateway)

22 March22 Mar

- [

    ## Protection against Next.js CVE-2025-29927

    A security vulnerability in Next.js was responsibly disclosed, which allows malicious actors to bypass authorization in Middleware when targetting the x-middleware-subrequest header.

    Aaron BrownHead of Security

    ](/changelog/vercel-firewall-proactively-protects-against-vulnerability-with-middleware)