Skip to content

Cursor ships Rollouts bot to watch deployments per PR and cuts Security Review scan time to 3.8 minutes

· by Pondero Newsdesk

The short version

Cursor launched two automated production-safety bots on September 23, 2026: Rollouts attaches a live deployment monitor to every pull request, and a faster Security Review now averages 3.8 minutes per PR scan, down from 4.8.

Cursor ships Rollouts bot to watch deployments per PR and cuts Security Review scan time to 3.8 minutes

Before this week, Cursor's code editor stopped at the PR merge button. On September 23, 2026, Anysphere added a bot that reads the diff, writes a monitoring plan into the PR as a comment, attaches to the deployment, and then reports per-environment health back to the team. That is Rollouts, and it launched alongside an updated Security Review bot now completing scans in 3.8 minutes on average.

What happened

Cursor published a blog post on September 23, 2026, announcing two automated bots for Teams and Enterprise customers, described as tools for "the last mile of shipping code."

Rollouts connects to source control, the team's continuous delivery system, and telemetry providers including Datadog, Grafana, and Honeycomb. When a PR opens, Rollouts reads the diff, identifies which systems the change touches, and writes a monitoring plan as a PR comment. The plan lists the risks it identified, the intended effect of the change, the signals it will check, and any instrumentation gaps that would make the change hard to verify. Engineers can edit the plan before merge; Rollouts uses the revised version.

After a deploy event, Rollouts compares live metrics against a pre-deploy baseline and tracks each environment separately. It reports three possible verdicts: verified healthy, regression detected, or inconclusive. When it detects a regression it names the suspected change and notifies the author. Per the Cursor changelog, depending on configuration it can open a revert PR for review or hand the finding to a cloud agent for a fix. It does not merge or roll back autonomously today.

Security Review runs on every pull request, reads the change in the context of the full codebase, and posts one review comment reporting exploitable bugs. Each finding carries a severity, the attack path, and a proposed fix. Per the Cursor blog post, the updated bot averages 3.8 minutes per review, down from 4.8 minutes, a 21% reduction. Engineer comment acceptance rose from 45-50% to 60-70%. Style and code quality reviews remain with the existing Bugbot.

For the next 10 days, Cursor is including free trial credits: roughly 50 changes for Teams and 500 for Enterprise plans, per the changelog. Both bots activate from the automations tab in the Cursor dashboard.

Cursor Teams plans get deployment monitoring without new tooling

Most engineering teams have some deployment monitoring, but the setup is typically manual: you pick what to watch after the first incident surfaces the gap. Rollouts shifts that work to pre-merge. A bot that writes and then enforces its own per-change monitoring plan targets the most common reason a bad deployment goes undetected: no one updated the dashboards.

For teams already on a Cursor Teams or Enterprise plan, both bots activate against the existing telemetry stack. No separate tooling purchase is required. The Security Review acceptance rate improvement carries more signal than the scan-time headline: jumping from 45-50% to 60-70% means engineers are acting on the findings at a meaningfully higher rate, the number that actually reduces shipped vulnerabilities, not just the time to flag them.

The free trial window closes roughly October 3, 2026, based on the 10-day window announced September 23.

What to watch next

Feature flag integration for Rollouts is listed as coming soon, which would let it ramp or unramp traffic directly rather than opening a revert PR. The bigger question is whether Cursor adds an autonomous rollback action. The changelog is clear that the bot does not roll back on its own today; that gap is the natural next capability, and it is the one competitors building in the same space will be watching.

Sources