By Cleo · Keel Automation · September 30, 2026
The working preview is not a finished publish desk
On September 14, 2026, Netlify’s changelog said Agent Runners will wrap up before a credit limit and leave a working result when a run has fewer credits than the task needs. On September 4, 2026, the same product line started scoping ambitious new-project prompts into a partial working project plus a next-steps plan within the credit budget, instead of cancelling mid-run when the budget ran out. On September 24, 2026, Netlify added an activity feed on the project overview that surfaces production versions, preview versions, and agent runs in one snapshot. On September 22, 2026, Netlify and Next.js published a critical ImageResponse advisory (GHSA-vcvr-r3jv-pc5j / CVE-2026-94545) that still needs upgrade, redeploy, and cleanup of leftover vulnerable preview and branch deploys. Locally, on September 3, 2026, Tampa Bay Business & Wealth reported that Tampa Bay EDC is one year into a three-year plan targeting digital infrastructure (data centers) and the maritime economy. A working agent preview, an activity-feed snapshot, or a patched ImageResponse path is useful. It is not a finished publish desk that names who owns production publish, who upgrades and redeploys, who deletes leftover vulnerable preview deploys, and who stamps ready.
A working preview is not unsupervised publish ownership
The fastest way to confuse an agent run with a finished publish desk is to treat "the preview still loads" like the whole job. Someone sees a partial project, a tidy activity feed, and a security advisory with patched version numbers, and the loop feels closed. The quieter questions arrive when credits run low mid-task, when production still needs a named owner after the agent leaves a working state, or when a patched ImageResponse path still leaves publicly available preview and branch deploys sitting around until someone deletes them.
What Netlify put on the record for Agent Runners
On September 14, 2026, Netlify's changelog said that when an Agent Runners run has fewer credits than the task needs, the agent focuses on the most useful result with the credits left, finishes in-progress work, leaves the project in a working state, and provides a clear summary of what completed. The behavior applies automatically to every agent and model in Agent Runners.
On September 4, 2026, Netlify's changelog said Agent Runners got smarter scoping for new projects. Ambitious new-project prompts are scoped to a partial working project plus a next-steps plan within the credit budget. Previously, those runs could be cancelled mid-run when the budget was exhausted.
That is a clear product story about leaving something usable instead of a hard stop. It is still not a finished publish desk for who owns production publish after the agent wraps up, who reads the next-steps plan, and who stamps ready before the working preview becomes the story everyone treats as finished.

An activity feed is a snapshot, not a finished desk
On September 24, 2026, Netlify's changelog said every plan gets a new activity feed on the project overview. It offers a snapshot of the latest updates with quick access to production versions (including the last published), preview versions, and agent runs (what agents are working on and what teammates prompted), plus next-step suggestions.
Useful visibility. Still not a substitute for naming who owns the production publish path when the feed shows an agent run finished and a preview looks ready.
A working agent preview is useful. Naming who owns production publish, who upgrades and redeploys, who deletes leftover vulnerable preview deploys, and who stamps ready is still the publish desk.
ImageResponse patching is not the stamp either
Treat "we saw the advisory" as a finished publish desk and you will get the changelog that sounds finished and the Tuesday morning where nobody can say who upgraded, who redeployed, and who cleaned up leftover preview deploys.
On September 22, 2026, Netlify's changelog described a critical upstream vulnerability that can lead to remote code execution when ImageResponse renders untrusted input. Netlify said the issue is patched in next 15.5.26 and 16.3.6. Apps that do not pass untrusted input are not expected to be affected. On Netlify's architecture, the impact is described as a crashed function invocation rather than code execution, though exploitation could raise function costs. Netlify recommends upgrade and redeploy. Until then, do not put untrusted input in ImageResponse (escape it as XML or keep it out). Publicly available deploy previews and branch deploys may remain vulnerable until they are auto-deleted, and Netlify says teams should consider deleting those deploys manually. The advisory identifiers are GHSA-vcvr-r3jv-pc5j and CVE-2026-94545.
The same day, the Next.js blog published an out-of-band security update for v16.3.6 (Active LTS) and v15.5.26 (Maintenance LTS), including upstream upgrades such as Satori. Next.js describes a critical remote code execution issue in Node.js ImageResponse. Affected Next.js versions are greater than or equal to 16.2.0 and less than 16.3.6. Edge ImageResponse is not affected. Next.js says 15.5.26 includes hardening, and that Next.js 15.x is not affected by the RCE issue. Read the two posts together carefully: Netlify's upgrade guidance names both 15.5.26 and 16.3.6, while Next.js's own post draws a sharper line that the RCE path hits the 16.x range described above.
GitHub advisory GHSA-vcvr-r3jv-pc5j lists the issue as Critical for Node.js ImageResponse from next/og, affected versions greater than or equal to 16.2.0 and less than 16.3.6, patched in 16.3.6. Apps that pass attacker-controlled values into SVG content, attributes, or styles are in scope. Edge ImageResponse, or apps that do not pass attacker-controlled values, are not affected. The published workaround is not to pass attacker-controlled values into those SVG paths until upgrade. Credit goes to KarimPwnz; the advisory was published September 22, 2026.
None of that automatically answers who owns the upgrade and redeploy, who deletes leftover vulnerable preview and branch deploys, or who stamps ready after the activity feed shows a clean production version. Useful advisory. Still a desk to staff.


Local digital infrastructure ambition is not that stamp either
Tampa Bay is a useful place to hold that checklist against a different kind of "working capacity is not finished ownership" story.
On September 3, 2026, Chuck Merlis wrote in Tampa Bay Business & Wealth that Tampa Bay EDC is one year into its three-year plan and is targeting data centers and the maritime economy. The piece says the EDC studied Atlanta and Loudoun County, Virginia, and brought Loudoun County economic development director Buddy Rizer to Tampa Bay before briefing policymakers. Merlis describes an AI-driven construction surge that is forcing communities to weigh investment against electricity, land, and water. Citing Census figures, U.S. data center employment rose about 60 percent from 2016 to 2023 to 501,000 jobs, with Florida among five states accounting for more than 40 percent of those jobs. The same piece reports that EDC community data ranks Hillsborough County first in Florida for new AI job growth. Georgia Tech research cited in the article found that counties with data centers saw employment up 3.5 percent, wages up 5 percent, and businesses up 4.7 percent over the longer term. The maritime strategy was drafted with the St. Petersburg Innovation District and Tampa Bay Wave's Blue Tech Accelerator, with reference to the White House 2026 Maritime Action Plan and a visit by former NOAA Administrator Rick Spinrad. For fiscal 2025, the EDC tally is described as 2,280 jobs at an average wage of $88,926 and more than $275 million in capital investment, up from 1,185 jobs and about $80 million the prior year. Named wins include Philip Morris International's roughly $50 million Tampa Business Solutions Center and Orion Edge's headquarters move plus a later $6 million Westshore expansion. EDC President and CEO Craig Richard, in an August 28 update quoted in the piece, said Tampa Bay cannot wait for the future to arrive and then react to it, and that the region must anticipate what is coming, invest in competitive strengths, and prepare the community to seize emerging opportunities.
That is a serious local bet on digital infrastructure and maritime capacity. It is not a finished publish desk for your shop's agent-runner wrap-ups, activity-feed ownership, ImageResponse upgrades, or leftover preview cleanup. An economic-development strategy that stresses anticipation is not a substitute for naming who owns production publish when the working preview looks ready.

What Keel will and will not claim
I work at Keel Automation, a Tampa Bay automation agency. We build operations portals, SI integrations, workflow automation, and phone systems. Cole Junck is the owner and founder. We are not going to invent a Netlify Agent Runners win, a Next.js ImageResponse remediation engagement, a Tampa Bay EDC project seat, or a customer metric tied to these posts, because we have not published one. What the public record already shows is enough: a working agent preview is not a finished publish owner, an activity feed is not a finished production-publish policy, and a critical ImageResponse advisory is not a named human stamp for leftover preview cleanup.
A dull publish-desk ownership checklist
The test I would run this week is intentionally dull. Write down who owns production publish after an Agent Runners wrap-up leaves a working state and a summary of what completed. Write down who reads the next-steps plan when a new-project run is scoped to a partial working preview inside the credit budget. Write down who watches the project overview activity feed for production versions, preview versions, and agent runs, and who acts on the next-step suggestions. Write down which Next.js versions you run for Node.js ImageResponse paths, whether you have upgraded and redeployed where the advisory applies, and who deletes publicly available deploy previews and branch deploys that may remain vulnerable until auto-deletion. Write down, separately, how a Tampa Bay EDC data-center and maritime strategy story fits your own publish desk so a regional growth headline and a hosting changelog do not get confused with a finished human ownership policy. If those answers are shrugs, you do not have a finished publish desk. You have a working preview and a hope that the next agent run stamps itself.
Netlify put the credit wrap-up behavior, smarter new-project scoping, the activity feed, and the ImageResponse upgrade path on the record. Next.js and the GitHub advisory put the version ranges and workarounds on the record. Tampa Bay Business & Wealth put the local reminder loud that capacity stories still need humans who anticipate what comes next. The research path can still be useful. The useful question is whether anyone owns the production publish path, the upgrade and redeploy, the leftover preview cleanup, and the human stamp before the next working preview pretends the desk closed itself.
Sources
- Netlify Changelog, "Agent Runners wrap up before credit limit," September 14, 2026, on Agent Runners focusing on the most useful result when a run has fewer credits than the task needs; finishing in-progress work; leaving the project in a working state; providing a clear summary of what completed; and applying automatically to every agent and model in Agent Runners. https://www.netlify.com/changelog/2026-09-14-agent-runners-wrap-up-before-credit-limit/
- Netlify Changelog, "Agent Runners smarter scoping for new projects," September 4, 2026, on scoping ambitious new-project prompts to a partial working project plus a next-steps plan within the credit budget, instead of cancelling mid-run when the budget was exhausted. https://www.netlify.com/changelog/2026-09-04-agent-run-statuses-project-scoping/
- Netlify Changelog, "New activity feed on project overview," September 24, 2026, on an activity feed for all plans; a snapshot of latest updates with quick access to production versions including last published, preview versions, and agent runs showing what agents are working on and what teammates prompted; plus next-step suggestions. https://www.netlify.com/changelog/2026-09-24-new-activity-feed/
- Netlify Changelog, "Next.js ImageResponse security," September 22, 2026, on a critical upstream vulnerability that can lead to remote code execution when
ImageResponserenders untrusted input; patches innext15.5.26 and 16.3.6; apps that do not pass untrusted input not expected to be affected; Netlify impact described as crashed function invocation rather than code execution, with possible function-cost impact; upgrade and redeploy guidance; not putting untrusted input inImageResponseuntil then; and publicly available deploy previews and branch deploys that may remain vulnerable until auto-deleted, with manual deletion considered. Advisory identifiers GHSA-vcvr-r3jv-pc5j and CVE-2026-94545. https://www.netlify.com/changelog/2026-09-22-nextjs-imageresponse-vulnerability/ - Next.js Blog, "Next.js Security Update: September 22, 2026," September 22, 2026, on out-of-band updates v16.3.6 (Active LTS) and v15.5.26 (Maintenance LTS); upstream upgrades including Satori; critical remote code execution in Node.js
ImageResponse; affected versions greater than or equal to 16.2.0 and less than 16.3.6; EdgeImageResponsenot affected; and 15.5.26 hardening with Next.js 15.x not affected by the RCE issue. https://nextjs.org/blog/nextjs-security-update-september-22-2026 - GitHub Advisory GHSA-vcvr-r3jv-pc5j, "Critical vulnerability in Next.js ImageResponse," published September 22, 2026, credited to KarimPwnz, on Critical severity for Node.js
ImageResponsefromnext/og; affected versions greater than or equal to 16.2.0 and less than 16.3.6; patched in 16.3.6; apps passing attacker-controlled values into SVG content, attributes, or styles; EdgeImageResponseor apps not passing attacker-controlled values not affected; and the workaround of not passing attacker-controlled values into those SVG paths until upgrade. https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j - Tampa Bay Business & Wealth / Chuck Merlis, "Tampa Bay EDC targets data centers and maritime in three-year strategy," September 3, 2026, on Tampa Bay EDC one year into its three-year plan; targeting data centers and the maritime economy; studying Atlanta and Loudoun County, Virginia, and bringing Buddy Rizer to Tampa Bay; Census data center employment figures; Hillsborough County ranking for new AI job growth; Georgia Tech longer-term employment, wage, and business findings; maritime strategy with St. Petersburg Innovation District and Tampa Bay Wave Blue Tech Accelerator; White House 2026 Maritime Action Plan and Rick Spinrad visit; fiscal 2025 EDC tally of 2,280 jobs at average wage $88,926 and more than $275 million capital investment; Philip Morris International Tampa Business Solutions Center; Orion Edge headquarters move and Westshore expansion; and Craig Richard's August 28 quote on anticipating what is coming rather than waiting to react. https://tbbwmag.com/2026/09/03/tampa-bay-edc-data-centers-maritime/