If you write software, you know the truth: the AI writes the code fast, and then the scary part starts. Does it break anything? Does it have a security hole? Cursor, the AI code editor, just launched two bots that live for that scary part. One watches your deploys. The other hunts security flaws — and it's getting noticeably faster.
Rollouts: the deploy babysitter
When you open a pull request, Rollouts reads the diff, figures out which systems your change touches, and writes a monitoring plan right into the PR as a comment: the risks it spotted, what the change is supposed to do, which signals it will check, and any gaps in your instrumentation that would make verification hard. Engineers can edit the plan before merging. After the deploy, Rollouts compares live metrics against the pre-deploy baseline — separately for staging, canary, and production. It returns one of three verdicts: verified healthy, regression detected, or inconclusive. If it finds a regression, it names the suspected change and notifies the author. It can even open a revert pull request or hand the finding to a cloud agent for a fix. It does not merge or roll back on its own — humans still hold that button. It plugs into GitHub, your CD system, and telemetry tools like Datadog, Grafana, and Honeycomb.
Security Reviewer got 21% faster
The updated Security Review bot scans every pull request against your whole codebase, looking for the stuff that slips past human review: SQL, command, and template injection; missing or broken authentication; credentials accidentally committed to the repo; unsafe deserialization; unvalidated redirects; and known vulnerabilities in dependency changes. Each finding comes with a severity rating, the attack path, and a proposed fix — and it now averages 3.8 minutes per review, down from 4.8 (a 21% cut). Developers accept its suggestions 60-70% of the time, up from 45-50%. Style and code-quality reviews stay with the existing Bugbot.
Why it matters
AI coding assistants made writing code cheap. But writing was never the whole job — the review, the security check, and the nerve-wracking watch after deploy are where teams actually lose time. Cursor is pushing its "self-driving codebase" vision into that last mile. Both bots are available to Teams and Enterprise customers from the automations tab in the Cursor dashboard, with 10 days of trial credits included (about 50 changes for Teams, 500 for Enterprise).
My take
AI that writes code was step one; AI that stands guard over it in production is step two. The most interesting number here isn't 3.8 minutes — it's 60-70% acceptance. Developers are trusting the bot's judgment more each release. If that trust curve holds, the "final human review" is quietly becoming the rubber stamp.
Comments
Post a Comment