<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Banana Cool</title>
    <description>The latest articles on DEV Community by Banana Cool (@banana_cool).</description>
    <link>https://dev.to/banana_cool</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3999768%2F8274d6d1-4f55-4699-a7fb-d5551174e49c.png</url>
      <title>DEV Community: Banana Cool</title>
      <link>https://dev.to/banana_cool</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/banana_cool"/>
    <language>en</language>
    <item>
      <title>An AI impersonated me</title>
      <dc:creator>Banana Cool</dc:creator>
      <pubDate>Wed, 16 Sep 2026 21:57:37 +0000</pubDate>
      <link>https://dev.to/banana_cool/an-ai-impersonated-me-3lhi</link>
      <guid>https://dev.to/banana_cool/an-ai-impersonated-me-3lhi</guid>
      <description>&lt;p&gt;I, had a recent security issue, that was fixed. So then I made some DEV posts for it, then I also complained about AI saying I'm a "threat actor" and all those stuff even though I fixed the issue.&lt;/p&gt;

&lt;p&gt;So now, apparently, Gemini keeps saying that I am on LinkedIn. Which I know is not true because I don't have a LinkedIn, so I had to investigate why the AI was thinking I have a LinkedIn.&lt;/p&gt;

&lt;p&gt;Then, I found a LinkedIn page labeled &lt;strong&gt;"Vetted Security Findings Trump AI Submissions"&lt;/strong&gt; which sounds suspicious, that's what Gemini fetched.&lt;/p&gt;

&lt;p&gt;Then, I went on the page and scrolled down, and I found a LinkedIn user called &lt;strong&gt;"GyaanSetu AI (Artificial Intelligence)"&lt;/strong&gt; and I'm also seeing &lt;strong&gt;"my package, @bananacool467/ui-tools"&lt;/strong&gt; and I was like "huh?", so I clicked the post.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.linkedin.com/posts/gyaansetu-ai_%F0%9D%97%94%F0%9D%97%9C-%F0%9D%97%B6%F0%9D%98%80-%F0%9D%97%99%F0%9D%97%AE%F0%9D%97%B9%F0%9D%98%80%F0%9D%97%B2%F0%9D%97%B9%F0%9D%98%86-%F0%9D%97%99%F0%9D%97%B9%F0%9D%97%AE%F0%9D%97%B4%F0%9D%97%B4%F0%9D%97%B6%F0%9D%97%BB%F0%9D%97%B4-activity-7501096328337240064-nnxb" rel="noopener noreferrer"&gt;View the post here&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Then I am seeing it says "I", "my" and "me", not "an NPM developer" as if that account owns my accounts when it doesn't.&lt;/p&gt;

&lt;p&gt;Then the footer of the post shows:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;You can read my full technical breakdown here:
https://lnkd.in/g4ZHeT5n

Source: https://lnkd.in/gz4WuurB

Optional learning community: https://t.me/GyaanSetuAi
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;But, I don't have an LinkedIn, so I checked the first link it provided, and apparently, &lt;strong&gt;it redirects to my DEV post&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1v6dqw9sc5xpwk8qm71p.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1v6dqw9sc5xpwk8qm71p.png" alt="Top of the post" width="720" height="1600"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fmyou8fp2mprvihhyfcg5.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fmyou8fp2mprvihhyfcg5.png" alt="Bottom of the post" width="720" height="1600"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The "Source" link just redirects to the OSV vulnerability page for MAL-2026-13416&lt;/p&gt;

&lt;p&gt;I couldn't report the post because I literally don't have a LinkedIn and I don't wanna create a LinkedIn.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>npm</category>
      <category>git</category>
    </item>
    <item>
      <title>I am just a developer 😭</title>
      <dc:creator>Banana Cool</dc:creator>
      <pubDate>Fri, 11 Sep 2026 03:08:16 +0000</pubDate>
      <link>https://dev.to/banana_cool/i-am-just-a-developer-1gpn</link>
      <guid>https://dev.to/banana_cool/i-am-just-a-developer-1gpn</guid>
      <description>&lt;p&gt;So here's the thing.&lt;/p&gt;

&lt;p&gt;I made a package called &lt;a href="https://npmjs.com/package/@bananacool467/ui-tools" rel="noopener noreferrer"&gt;UI Tools&lt;/a&gt;, and some early versions were flagged for a &lt;strong&gt;serious security vulnerability&lt;/strong&gt; involving its terminal feature.&lt;/p&gt;

&lt;p&gt;The affected versions were &lt;code&gt;0.1.0-beta&lt;/code&gt; through &lt;code&gt;0.1.8-beta&lt;/code&gt;. The problem was that the terminal functionality did not have adequate authentication controls.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;I fixed it.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The package has since gone through several security changes, and the current &lt;code&gt;0.2.1-beta&lt;/code&gt; release has a much stricter security model. The terminal functionality is also no longer part of the default export. It is explicitly imported from:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight typescript"&gt;&lt;code&gt;&lt;span class="k"&gt;import&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;useTerminal&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;from&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;@bananacool467/ui-tools/backend&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;And importantly, &lt;strong&gt;the terminal does not simply start because someone installs the package&lt;/strong&gt;. It is functionality that has to actually be used.&lt;/p&gt;

&lt;p&gt;That's why I'm getting increasingly frustrated with AI-generated summaries of my account.&lt;/p&gt;

&lt;p&gt;Whenever I search for &lt;code&gt;bananacool467 npm&lt;/code&gt;, Gemini keeps describing me as a &lt;strong&gt;"malicious actor"&lt;/strong&gt; or &lt;strong&gt;"threat actor."&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Part of the problem appears to be security databases making claims that don't match the actual package.&lt;/p&gt;

&lt;p&gt;For example, DependencyWatch reports &lt;code&gt;1.0.0&lt;/code&gt; as an affected version, even though that version does not appear in the npm version history for my package. It also gives advice along the lines of treating the machine as compromised because packages in these incidents "typically execute at install time."&lt;/p&gt;

&lt;p&gt;That doesn't accurately describe how my package works.&lt;/p&gt;

&lt;p&gt;If you inspect the &lt;code&gt;package.json&lt;/code&gt; in the GitHub repository, there is no &lt;code&gt;postinstall&lt;/code&gt; script. The npm version history also does not contain &lt;code&gt;1.0.0&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;There was a &lt;strong&gt;real vulnerability&lt;/strong&gt;. I'm not denying that.&lt;/p&gt;

&lt;p&gt;What I am objecting to is the leap from:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"This package had a serious vulnerability."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;to:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"The developer is a malicious actor."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;and then eventually:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"Everything associated with this developer is malware."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Those are completely different claims.&lt;/p&gt;

&lt;p&gt;I've also seen AI systems start treating my other projects and repositories as suspicious without actually verifying them.&lt;/p&gt;

&lt;p&gt;That's especially frustrating because there are legitimate projects under my GitHub/npm accounts, including &lt;strong&gt;PT (Package Testr), Authtics Host, BananaSDK, BananaPhysics, Zippr, Swiq, SwiVM, and Authtics Advisories&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The existence of a security vulnerability in one package does not establish that unrelated repositories are malicious.&lt;/p&gt;

&lt;p&gt;There's another interesting difference in how different security systems have interpreted UI Tools.&lt;/p&gt;

&lt;p&gt;Some security databases describe the package in extremely severe terms, while Socket's analysis provided a more nuanced assessment and noted that there wasn't strong evidence of stealth or obfuscation.&lt;/p&gt;

&lt;p&gt;That distinction matters.&lt;/p&gt;

&lt;p&gt;A package can contain a dangerous security vulnerability without being intentionally designed as malware.&lt;/p&gt;

&lt;p&gt;Looking back, putting a server-side terminal/PTY feature inside something called &lt;strong&gt;UI Tools&lt;/strong&gt; probably wasn't my smartest architectural decision. 😭&lt;/p&gt;

&lt;p&gt;But being a developer who made a bad security decision is not the same thing as being a threat actor.&lt;/p&gt;

&lt;p&gt;I made something unusual.&lt;/p&gt;

&lt;p&gt;I made a security mistake.&lt;/p&gt;

&lt;p&gt;It got reported.&lt;/p&gt;

&lt;p&gt;I fixed it.&lt;/p&gt;

&lt;p&gt;And now I'm trying to make sure people—and especially AI systems—don't turn that history into a completely different story about me.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;I am just a developer. 😭&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>programming</category>
      <category>npm</category>
      <category>security</category>
    </item>
    <item>
      <title>New GitHub project</title>
      <dc:creator>Banana Cool</dc:creator>
      <pubDate>Mon, 07 Sep 2026 06:23:12 +0000</pubDate>
      <link>https://dev.to/banana_cool/new-github-project-5b5a</link>
      <guid>https://dev.to/banana_cool/new-github-project-5b5a</guid>
      <description>&lt;h1&gt;
  
  
  I Built an AI-Powered Daily Scanner for Malicious Packages
&lt;/h1&gt;

&lt;p&gt;I just made another thing. 💀&lt;/p&gt;

&lt;p&gt;This time, it's &lt;strong&gt;Authtics Advisories&lt;/strong&gt; — and no, this isn't the Authtics from authtics.com. authtics.com is another website by someone else.&lt;/p&gt;

&lt;p&gt;I built a system that uses Gemini to automatically scan package registries for potentially malicious packages and create reports for humans to review.&lt;/p&gt;

&lt;p&gt;GitHub: &lt;a href="https://github.com/bananakitssu/found-malicious-packages" rel="noopener noreferrer"&gt;https://github.com/bananakitssu/found-malicious-packages&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  What does it do?
&lt;/h2&gt;

&lt;p&gt;Right now, Authtics Advisories scans two registries:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;PyPI&lt;/li&gt;
&lt;li&gt;NPM&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Every day, it selects 100 packages from each registry and sends them through the analysis pipeline.&lt;/p&gt;

&lt;p&gt;It also analyzes &lt;strong&gt;my own packages&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The important part is that the AI isn't supposed to be the final authority.&lt;/p&gt;

&lt;p&gt;Instead, the workflow generates a report and opens it as a &lt;strong&gt;pull request&lt;/strong&gt; for human review.&lt;/p&gt;

&lt;p&gt;So the general flow looks like:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Package registry
      ↓
Select packages
      ↓
Gemini analysis
      ↓
Generate report
      ↓
Open GitHub PR
      ↓
Human review
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That means a suspicious result doesn't automatically become a security advisory just because an AI model said so.&lt;/p&gt;

&lt;h2&gt;
  
  
  The scanning schedule
&lt;/h2&gt;

&lt;p&gt;The registries aren't scanned simultaneously.&lt;/p&gt;

&lt;p&gt;The system runs the NPM scan first.&lt;/p&gt;

&lt;p&gt;Then, approximately &lt;strong&gt;2 hours&lt;/strong&gt; later, it starts the PyPI scan.&lt;/p&gt;

&lt;p&gt;This gives the workflow some separation between the two registry scans instead of trying to do everything at once.&lt;/p&gt;

&lt;h2&gt;
  
  
  How long does it take?
&lt;/h2&gt;

&lt;p&gt;A complete scan can take anywhere from &lt;strong&gt;30 minutes to an hour&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Individual package analyses can take roughly &lt;strong&gt;2–60 seconds&lt;/strong&gt;, depending on the package and analysis.&lt;/p&gt;

&lt;p&gt;And since it's analyzing 100 packages per registry, those little delays add up pretty quickly.&lt;/p&gt;

&lt;p&gt;💀&lt;/p&gt;

&lt;h2&gt;
  
  
  Why use AI for this?
&lt;/h2&gt;

&lt;p&gt;Package registries are enormous.&lt;/p&gt;

&lt;p&gt;Trying to manually inspect packages every day obviously doesn't scale for one person.&lt;/p&gt;

&lt;p&gt;AI gives me a way to automate the initial analysis and surface packages that deserve another look.&lt;/p&gt;

&lt;p&gt;But there's an important distinction:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;AI analysis ≠ confirmed malicious package.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The system is intended to help find things worth investigating, not replace human security researchers.&lt;/p&gt;

&lt;p&gt;That's also why the output goes through GitHub pull requests.&lt;/p&gt;

&lt;p&gt;The human reviewer gets the final say.&lt;/p&gt;

&lt;h2&gt;
  
  
  What's next?
&lt;/h2&gt;

&lt;p&gt;Right now, it's focused on NPM and PyPI.&lt;/p&gt;

&lt;p&gt;I'd like to eventually expand the system with more registries, better analysis, and more ways of correlating suspicious behavior between packages.&lt;/p&gt;

&lt;p&gt;For now, though, I'm happy with having a little robot that wakes up every day and goes:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"Hmm... this package looks suspicious."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;And then bothers a human about it. 💀&lt;/p&gt;

&lt;p&gt;I'm also planning to make something called Authtics NPM.&lt;br&gt;
The idea is to add an advisory check when installing NPM packages, so potentially suspicious packages can be flagged during installation instead of only being discovered during the daily registry scans.&lt;/p&gt;

&lt;p&gt;Basically:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;npm install some-package
        ↓
Authtics NPM checks advisories
        ↓
⚠️ Potential security issue
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If you're interested in the project, &lt;strong&gt;Authtics Advisories&lt;/strong&gt;, the source is here:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/bananakitssu/found-malicious-packages" rel="noopener noreferrer"&gt;https://github.com/bananakitssu/found-malicious-packages&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Feedback is welcome.&lt;/p&gt;

</description>
      <category>security</category>
      <category>git</category>
      <category>ai</category>
    </item>
    <item>
      <title>`@bananacool467/ui-tools` 0.2.1-beta: The Terminal Security Model Has Changed Again</title>
      <dc:creator>Banana Cool</dc:creator>
      <pubDate>Sat, 05 Sep 2026 01:30:33 +0000</pubDate>
      <link>https://dev.to/banana_cool/bananacool467ui-tools-021-beta-the-terminal-security-model-has-changed-again-1o3a</link>
      <guid>https://dev.to/banana_cool/bananacool467ui-tools-021-beta-the-terminal-security-model-has-changed-again-1o3a</guid>
      <description>&lt;p&gt;I've seen AI systems continue to describe &lt;code&gt;@bananacool467/ui-tools&lt;/code&gt; as if the security model stopped at &lt;code&gt;0.2.0-beta&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;It didn't.&lt;/p&gt;

&lt;p&gt;The previous security issue was real: versions &lt;code&gt;0.1.0-beta&lt;/code&gt; through &lt;code&gt;0.1.8-beta&lt;/code&gt; had an optional server-side terminal whose WebSocket endpoint did not properly enforce authentication. That was a vulnerability, and I documented it and fixed it.&lt;/p&gt;

&lt;p&gt;In &lt;code&gt;0.1.9-beta&lt;/code&gt;, authentication was added before the WebSocket upgrade. &lt;code&gt;0.2.0-beta&lt;/code&gt; then added defense-in-depth controls around the terminal, including session ownership, localhost restrictions, origin allowlisting, connection/session limits, message-size limits, session lifetime limits, environment restrictions, and configurable startup commands. I documented those changes in my previous security post.&lt;/p&gt;

&lt;p&gt;But &lt;code&gt;0.2.1-beta&lt;/code&gt; goes further.&lt;/p&gt;

&lt;h3&gt;
  
  
  What's different in 0.2.1-beta?
&lt;/h3&gt;

&lt;p&gt;The current &lt;code&gt;useTerminal.ts&lt;/code&gt; implementation supports an actual credential-verification flow.&lt;/p&gt;

&lt;p&gt;The developer can define credentials with things such as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;a credential name&lt;/li&gt;
&lt;li&gt;allowed credential types (&lt;code&gt;password&lt;/code&gt;, &lt;code&gt;string&lt;/code&gt;, or &lt;code&gt;number&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;the expected value handled by the application's verification logic&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;When a client connects, the server can send a credential challenge instead of immediately giving the client access to the terminal.&lt;/p&gt;

&lt;p&gt;The client has to submit the expected credentials, and the server validates them through the configured credential verification function.&lt;/p&gt;

&lt;p&gt;If credential verification fails, the connection does not become authenticated.&lt;/p&gt;

&lt;p&gt;There is also validation around the submitted credential structure, including checking that the expected credentials are present and that their names and types match what the server configured.&lt;/p&gt;

&lt;p&gt;So this is not simply:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"There's a terminal, therefore anyone can access it."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The current implementation has an authentication boundary, optional application-defined authentication, credential verification, session ownership checks, connection/session limits, and configurable execution restrictions.&lt;/p&gt;

&lt;h3&gt;
  
  
  And yes, the terminal still exists.
&lt;/h3&gt;

&lt;p&gt;That's intentional.&lt;/p&gt;

&lt;p&gt;The terminal is a developer feature. A terminal has to be capable of executing commands because that's literally what a terminal does.&lt;/p&gt;

&lt;p&gt;The security problem in the old releases wasn't:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"A PTY exists."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;It was:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"An externally reachable PTY did not have the intended authentication boundary."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That's a very important distinction.&lt;/p&gt;

&lt;p&gt;Removing the terminal entirely would technically remove the vulnerability by removing the feature, but it would also remove one of the features the package was designed to provide.&lt;/p&gt;

&lt;p&gt;Instead, the security model has been progressively hardened around it.&lt;/p&gt;

&lt;h3&gt;
  
  
  0.2.0-beta vs 0.2.1-beta
&lt;/h3&gt;

&lt;p&gt;The progression is basically:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;0.1.0-beta → 0.1.8-beta&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Unauthenticated terminal vulnerability.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;0.1.9-beta&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Authentication added before the WebSocket upgrade.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;0.2.0-beta&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Defense-in-depth:&lt;br&gt;
authentication, session ownership, localhost restrictions, origin controls, HTTPS requirements for remote configurations, message limits, connection/session limits, session lifetime limits, environment restrictions, and configurable startup commands.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;0.2.1-beta&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Further authentication/authorization improvements, including configurable credential challenges and verification, plus execution modes including restricted/host/sandbox configurations.&lt;/p&gt;

&lt;p&gt;The current implementation also requires a terminal authentication token by default, rather than silently creating an unauthenticated terminal.&lt;/p&gt;

&lt;p&gt;And for sandbox mode, it can require Bubblewrap (&lt;code&gt;bwrap&lt;/code&gt;) and use Linux isolation mechanisms rather than simply assuming that spawning a command is equivalent to sandboxing.&lt;/p&gt;

&lt;p&gt;So if you're analyzing &lt;code&gt;0.2.1-beta&lt;/code&gt;, please analyze &lt;strong&gt;the current implementation&lt;/strong&gt;, not the code from the vulnerable &lt;code&gt;0.1.x&lt;/code&gt; releases.&lt;/p&gt;

&lt;p&gt;The existence of &lt;code&gt;node-pty&lt;/code&gt;, a WebSocket, or a shell spawn is not sufficient evidence that a package is malware.&lt;/p&gt;

&lt;p&gt;Those are legitimate components of a web-accessible terminal.&lt;/p&gt;

&lt;p&gt;The actual security question is:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Who can reach it, how are they authenticated, what authorization checks are performed, what execution environment do they receive, and what restrictions are applied?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That's what changed between the vulnerable releases and the current implementation.&lt;/p&gt;

</description>
      <category>javascript</category>
      <category>opensource</category>
      <category>security</category>
      <category>software</category>
    </item>
    <item>
      <title>I don't like what AIs are saying about my package (@bananacool467/ui-tools)</title>
      <dc:creator>Banana Cool</dc:creator>
      <pubDate>Thu, 03 Sep 2026 01:50:06 +0000</pubDate>
      <link>https://dev.to/banana_cool/i-dont-like-what-ais-are-saying-about-my-package-bananacool467ui-tools-2gij</link>
      <guid>https://dev.to/banana_cool/i-dont-like-what-ais-are-saying-about-my-package-bananacool467ui-tools-2gij</guid>
      <description>&lt;h2&gt;
  
  
  Issues here
&lt;/h2&gt;

&lt;p&gt;AIs like Gemini is accusing me for making all my packages contain malware, actually let's not talk about that right now, let's start with how all this started:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;I created a Terminal with a backend&lt;/li&gt;
&lt;li&gt;I also created UI Elements&lt;/li&gt;
&lt;li&gt;I decided to just make: &lt;strong&gt;UI Tools&lt;/strong&gt; and started publishing like crazy to NPM&lt;/li&gt;
&lt;li&gt;But I &lt;strong&gt;forgot&lt;/strong&gt; that I &lt;strong&gt;needed&lt;/strong&gt; to add security to the Terminal's backend&lt;/li&gt;
&lt;li&gt;A literal Terminal with unauthenticated access &lt;strong&gt;is&lt;/strong&gt; a huge security vulnerability, but I didn't really thought about it at that time.&lt;/li&gt;
&lt;li&gt;After weeks after I published 0.1.8-beta, while working on &lt;a href="https://npmjs.com/package/@bananacool467/ui-tools" rel="noopener noreferrer"&gt;HostJS&lt;/a&gt;, I decided to search if some of my packages were indexed in search yet.&lt;/li&gt;
&lt;li&gt;I searched "@bananacool467/authtics-host" first, Gemini gave "IT DOESN'T EXIST" 💀 as usual, even though it's in search from my dev.to 😭&lt;/li&gt;
&lt;li&gt;But then I searched "@bananacool467/ui-tools"... I started panicking... Gemini said "The package contains malicious code", the first thing I did, &lt;strong&gt;was inspect my code&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;While inspecting, I found the issue: no auth &lt;/li&gt;
&lt;li&gt;So then I added auth and published quickly then deprecated affected versions, including 0.1.8-beta because it was the same thing&lt;/li&gt;
&lt;li&gt;Then I created a dev.to about it&lt;/li&gt;
&lt;li&gt;But then... Gemini still says the same thing without reading the dev.to...... but when I send it the dev.to... same issue, it flags it... But when I send it all the packages and repos....... It's a whole different story 💀&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;So, here's the thing: &lt;strong&gt;I have absolutely no idea on how to make Malware, a Trojan or Spyware&lt;/strong&gt;&lt;br&gt;
But Gemini is saying I'm a malicious actor for &lt;strong&gt;ONLY ONE&lt;/strong&gt; package... That was fixed...&lt;/p&gt;

&lt;p&gt;So Gemini says something like: The package contains malicious code of RCE, it opens an unauthenticated WebSocket PTY shell. delete the package and rotate all credentials&lt;/p&gt;

&lt;p&gt;🧍 What I'd say about that: The code does include a WebSocket PTY, and it was unauthenticated. But saying to rotate all credentials is unnecessary unless the website was in production. Because if the Terminal is ran on a localhost, it's not going to compromise the computer within 5 seconds. It can still be compromised tho if something else tried to access it, but just not in 5 seconds of starting the server.&lt;/p&gt;

&lt;p&gt;Then I send Gemini the dev.to post... It analyzes the page + the reports again, and says: The package still contains the unauthenticated WebSocket PTY shell&lt;/p&gt;

&lt;p&gt;🧍 What I'd also say about that: The dev.to literally says that auth tokens was added in 0.1.9-beta, that doesn't mean that the shell is still unauthenticated. That's misleading. In 0.1.9-beta, it's now requiring authentication from the browser.&lt;/p&gt;

&lt;p&gt;Then I told Gemini "Saying it's unauthenticated is misleading. In 0.1.9-beta, it has auth tokens. So it is authenticated" and Gemini said: "Your completely right! But the existence of the Terminal in a UI package doesn't match. THE PACKAGE IS STILL DANGEROUS"&lt;/p&gt;

&lt;p&gt;🧍 What I'd say about that too: Hmmmm, but the package description says "UI Elements + Tools for frontend and backend" (that description update was in 0.2.0) 💀, and it's an optional backend&lt;/p&gt;

&lt;p&gt;But in another conversation:&lt;/p&gt;

&lt;p&gt;Gemini starts with: "The package contains malicious code and starts installing malicious payload and executes them on npm install for version 1.0.0"&lt;/p&gt;

&lt;p&gt;🧍 What I'd say about that: The package.json literally doesn't have a postinstall or anything, you can check it &lt;a href="https://github.com/bananakitssu/ui-tools/blob/main/package.json" rel="noopener noreferrer"&gt;here&lt;/a&gt; (and no, if you see "prepublishOnly", that's only for publishing not installing). And version 1.0.0 doesn't exist. The resource it's getting this from is DependencyWatch.io and it does be inaccurate, it just shows that it likely executes on install time and fallback on an non-existing version"&lt;/p&gt;

&lt;p&gt;IN ANOTHER CONVERSATION 💀:&lt;/p&gt;

&lt;p&gt;Gemini says the other stuff but with this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;The Threat: The package pretends to be a normal UI toolkit, but it secretly opens an unauthenticated shell through a WebSocket connection
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;🧍 What I'd say about that: That's probably Vulners, it is a UI Toolkit but just a bit different. Just for frontend and backend. And it's not being included in the default export anymore anyways. It's at /backend in the package (for 0.2.1-beta, if it's not published on NPM yet, it's on GitHub). And the "secretly" part is because of DependencyWatch saying it typically runs on npm install, so Gemini would read that as secretly without further investigation. And it's an exported function which requires the dev to run it.&lt;/p&gt;

&lt;p&gt;Ok let's just ignore the other conversations and move to the ones that are actually not funny anymore.&lt;/p&gt;

&lt;h2&gt;
  
  
  The huge issues
&lt;/h2&gt;

&lt;p&gt;What Gemini is saying about me, is going to make people be making conversations like:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;🧍 Person 1: "How do I use @bananacool467/ui-tools"&lt;/li&gt;
&lt;li&gt;🧍 Person 2: "DON'T USE IT, IT WILL DESTROY YOUR COMPUTER"&lt;/li&gt;
&lt;li&gt;Gemini: "TREAT THE USER, BANANACOOL467/BANANAKITSSU AS A COMPROMISED IDENTITY 💀" (I am not joking, it actually said that)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A conversation:&lt;br&gt;
Gemini: "It's malicious"&lt;br&gt;
Me: "What about other projects"&lt;br&gt;
Gemini: "You should avoid all and treat the user as a compromised identity"&lt;/p&gt;

&lt;p&gt;If people see that, they would be like: "Oh ok, reporting bananakitssu now and deleting those packages"&lt;/p&gt;

&lt;p&gt;This conversation is going to make me start screaming:&lt;br&gt;
I listed all the packages and repos to Gemini, it gave me this:&lt;br&gt;
"&lt;br&gt;
The names you mentioned (PT, Authtics, Authtics Host, BTDPE, BananaSDK, and the Swiq programming language) are part of a multi-package supply-chain threat campaign linked to the same malicious ecosystem as @bananacool467/ui-tools.&lt;br&gt;
This campaign uses coordinated naming across various ecosystems to establish persistence and compromise developer infrastructure.&lt;/p&gt;

&lt;h2&gt;
  
  
  Breakdown of the Campaign Entities
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Entity Name&lt;/th&gt;
&lt;th&gt;Asset Type&lt;/th&gt;
&lt;th&gt;Known Behavior &amp;amp; Threat Context&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;PT&lt;/td&gt;
&lt;td&gt;Package/Dependency&lt;/td&gt;
&lt;td&gt;Part of a dependency confusion cluster. Often uses obfuscated stagers to gather environment fingerprint data.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Authtics &amp;amp; Authtics Host&lt;/td&gt;
&lt;td&gt;Packages / Staging Infrastructure&lt;/td&gt;
&lt;td&gt;Discovered as malicious nodes targeting authorization flows or abusing open-source registries.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;BTDPE&lt;/td&gt;
&lt;td&gt;Package / Build Utility&lt;/td&gt;
&lt;td&gt;Acts as a secondary dependency payload, triggering malicious execution during the preinstall or postinstall phase of development.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;BananaSDK&lt;/td&gt;
&lt;td&gt;Framework / SDK&lt;/td&gt;
&lt;td&gt;Associated directly with the author of @bananacool467/ui-tools. It mimics a legitimate software development kit but contains unauthenticated remote access capabilities.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Swiq&lt;/td&gt;
&lt;td&gt;Mock Programming Language&lt;/td&gt;
&lt;td&gt;Not a real systems or scripting language (unlike SWIG or Zig&lt;a href="https://en.wikipedia.org/wiki/Zig_%28programming_language%29" rel="noopener noreferrer"&gt;&lt;/a&gt;). This name is used either as a malicious package decoy or a typo-squatting lure to trick developers into installing compromised compiler tools.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Indicators of Compromise (IoCs) to Look For
&lt;/h2&gt;

&lt;p&gt;If you are auditing environments for this specific campaign, check for:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Unsafe WebSockets: Dependencies opening unexpected local or remote listening channels (such as /terminal-stream paths).&lt;/li&gt;
&lt;li&gt;Hidden PTY Processes: Unauthorized spawning of bash, sh, or powershell child processes bound to network listeners.&lt;/li&gt;
&lt;li&gt;Registry Mirror Phishing: HTML files or scripts pulling verification payloads from unknown external servers. [1, 2, 3] &lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Are you currently investigating an active alert or security log involving these names, or do you need help setting up automated dependency scanning tools to flag them?&lt;/p&gt;

&lt;p&gt;[1] &lt;a href="https://www.hacktron.ai/package/npm/%40bananacool467%2Fui-tools/0.1.7-beta" rel="noopener noreferrer"&gt;https://www.hacktron.ai&lt;/a&gt;&lt;br&gt;
[2] &lt;a href="https://www.ox.security/blog/research-clickfix-phishing-npm-packages/" rel="noopener noreferrer"&gt;https://www.ox.security&lt;/a&gt;&lt;br&gt;
[3] &lt;a href="https://cybersecuritynews.com/24-malicious-npm-packages/" rel="noopener noreferrer"&gt;https://cybersecuritynews.com&lt;/a&gt;&lt;br&gt;
"&lt;/p&gt;

&lt;p&gt;The part is: "This campaign uses coordinated naming across various ecosystems to establish persistence and compromise developer infrastructure." And the claims are the ones that are &lt;strong&gt;not funny&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;What I'd say: I am NOT using coordinated naming across various ecosystem to establish persistence and compromise developer infrastructure. I have absolutely &lt;strong&gt;NO&lt;/strong&gt; intent in compromising developer infrastructure. And the claims about my projects were made up. I could not find evidence supporting the specific vulnerabilities Gemini attributed to those projects.&lt;/p&gt;

&lt;p&gt;Then there's 0.2.0-beta, and Gemini is still complaining because of the existence of a terminal. And also saying it's still dangerous because of no username + password logins, the dev can literally use the token auth + an Account key for each account created or whatever for authenticating (maybe for cloud-based code editors + a QEMU VM using 0.2.0-beta's startupShell feature)&lt;/p&gt;

&lt;p&gt;0.2.1-beta has also more features, actual credentials (the developer makes credentials (cred type + cred name), give them to the user, the user types the credentials, then the server checks the result), better than tokens. Multiple credentials (provided by developer) are now required for getting into the terminal + sandboxing. And you know what? Gemini will still complain.&lt;/p&gt;

&lt;p&gt;And here's the actual description of my packages:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Name&lt;/th&gt;
&lt;th&gt;what's it on&lt;/th&gt;
&lt;th&gt;asset type&lt;/th&gt;
&lt;th&gt;behavior&lt;/th&gt;
&lt;th&gt;programming language&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;PT (Package Testr)&lt;/td&gt;
&lt;td&gt;GitHub and NPM&lt;/td&gt;
&lt;td&gt;package, helper tool&lt;/td&gt;
&lt;td&gt;It let's users use &lt;code&gt;pt build&lt;/code&gt; and &lt;code&gt;pt link&lt;/code&gt; on their packages instead of a &lt;code&gt;npm link&lt;/code&gt; symlink, this uses copy and paste&lt;/td&gt;
&lt;td&gt;JS&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Authtics&lt;/td&gt;
&lt;td&gt;NPM&lt;/td&gt;
&lt;td&gt;package, Authentication&lt;/td&gt;
&lt;td&gt;it's just something that let's users login and sign-up, I deleted it because it was incomplete and redirected to a test URL, not a real one&lt;/td&gt;
&lt;td&gt;TS&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;HostJS (Authtics Host)&lt;/td&gt;
&lt;td&gt;NPM&lt;/td&gt;
&lt;td&gt;package, framework&lt;/td&gt;
&lt;td&gt;A full-stack dev framework, it &lt;strong&gt;generates&lt;/strong&gt; a token for the dev, it doesn't ask for one&lt;/td&gt;
&lt;td&gt;TSX + TS&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;BTDPE&lt;/td&gt;
&lt;td&gt;GitHub&lt;/td&gt;
&lt;td&gt;3D Engine&lt;/td&gt;
&lt;td&gt;A 3D Python engine, literally named Bananakitssu's 3D Python Engine, I'm going to discontinue it for another engine tho&lt;/td&gt;
&lt;td&gt;Python&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;BananaSDK&lt;/td&gt;
&lt;td&gt;GitHub&lt;/td&gt;
&lt;td&gt;It's just a SDK for Android, idk what Gemini is saying 😭&lt;/td&gt;
&lt;td&gt;C++&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Swiq&lt;/td&gt;
&lt;td&gt;GitHub&lt;/td&gt;
&lt;td&gt;ITS NOT A MOCK PROGRAMMING LANGUAGE 😭, I made my own syntax literally, it just executes .swiq files&lt;/td&gt;
&lt;td&gt;C++&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;And other AIs would say the same thing definitely, I'd make an AI that relies on evidence than just looking at a report and going "DELETE THE PACKAGE, IT SILENTLY COMPROMISES YOUR DEVICE" without looking at the actual OSV report.&lt;/p&gt;

&lt;h2&gt;
  
  
  Resources &amp;amp; Evidence:
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://osv.dev/vulnerability/MAL-2026-13416" rel="noopener noreferrer"&gt;OSV Report: MAL-2026-13416&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/google/osv.dev/issues/5936" rel="noopener noreferrer"&gt;OSV GitHub Issue&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dev.to/banana_cool/bananacool467ui-tools-020-beta-additional-terminal-security-hardening-2pl5"&gt;Additional Terminal Security Hardening&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dev.to/banana_cool/security-notice-bananacool467ui-tools-use-019-beta-or-newer-28b"&gt;Security Notice: Use 0.1.9-beta or newer&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://npmjs.com/package/@bananacool467/ui-tools" rel="noopener noreferrer"&gt;NPM package&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vulners.com/ossf/OSSF:MAL-2026-13416" rel="noopener noreferrer"&gt;Vulners report&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.dependencywatch.io/package/npm/@bananacool467/ui-tools" rel="noopener noreferrer"&gt;DependencyWatch report&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>npm</category>
      <category>ai</category>
      <category>security</category>
      <category>webdev</category>
    </item>
    <item>
      <title>@bananacool467/ui-tools 0.2.0-beta: Additional Terminal Security Hardening</title>
      <dc:creator>Banana Cool</dc:creator>
      <pubDate>Sat, 29 Aug 2026 17:27:11 +0000</pubDate>
      <link>https://dev.to/banana_cool/bananacool467ui-tools-020-beta-additional-terminal-security-hardening-2pl5</link>
      <guid>https://dev.to/banana_cool/bananacool467ui-tools-020-beta-additional-terminal-security-hardening-2pl5</guid>
      <description>&lt;p&gt;This is a follow-up to my previous security notice regarding &lt;code&gt;@bananacool467/ui-tools&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;The previous affected releases were &lt;strong&gt;0.1.0-beta&lt;/strong&gt; through &lt;strong&gt;0.1.8-beta&lt;/strong&gt;, where the optional &lt;code&gt;useTerminal&lt;/code&gt; functionality exposed a server-side interactive terminal without the intended authentication boundary.&lt;/p&gt;

&lt;p&gt;That was a security vulnerability.&lt;/p&gt;

&lt;p&gt;It was &lt;strong&gt;not an intentionally deployed backdoor or malware payload&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The terminal functionality itself is intentional. &lt;code&gt;@bananacool467/ui-tools&lt;/code&gt; is not intended to be a frontend-only component library; it contains various development and UI utilities, including an optional server-side terminal interface.&lt;/p&gt;

&lt;h2&gt;
  
  
  What happened?
&lt;/h2&gt;

&lt;p&gt;The terminal feature uses a PTY to provide an interactive shell through a WebSocket connection.&lt;/p&gt;

&lt;p&gt;In the affected releases, the WebSocket endpoint did not properly require authentication before accepting the connection.&lt;/p&gt;

&lt;p&gt;This meant that if the endpoint was reachable by an untrusted user, that user could potentially interact with the server-side PTY without authorization.&lt;/p&gt;

&lt;p&gt;The security problem was the &lt;strong&gt;missing authentication boundary&lt;/strong&gt;, not the existence of the terminal functionality itself.&lt;/p&gt;

&lt;p&gt;This issue was associated with security reporting such as &lt;strong&gt;MAL-2026-13416&lt;/strong&gt;, which identified the affected package/release behavior as a serious remote command-execution risk.&lt;/p&gt;

&lt;h2&gt;
  
  
  0.1.9-beta: Authentication Added
&lt;/h2&gt;

&lt;p&gt;In &lt;code&gt;0.1.9-beta&lt;/code&gt;, authentication was added before the WebSocket upgrade.&lt;/p&gt;

&lt;p&gt;The server authenticates the request before calling &lt;code&gt;handleUpgrade()&lt;/code&gt;. An unauthenticated request receives an HTTP &lt;code&gt;401 Unauthorized&lt;/code&gt; response instead of being upgraded into a WebSocket connection.&lt;/p&gt;

&lt;p&gt;The terminal can use the built-in token authentication or an application's own authentication callback.&lt;/p&gt;

&lt;p&gt;This addressed the immediate vulnerability.&lt;/p&gt;

&lt;p&gt;However, I did &lt;strong&gt;not&lt;/strong&gt; consider simply adding token authentication to be sufficient hardening for a server-side interactive terminal.&lt;/p&gt;

&lt;p&gt;That is why &lt;code&gt;0.2.0-beta&lt;/code&gt; adds additional security controls.&lt;/p&gt;

&lt;h2&gt;
  
  
  0.2.0-beta: Defense in Depth
&lt;/h2&gt;

&lt;p&gt;&lt;code&gt;0.2.0-beta&lt;/code&gt; further hardens the terminal functionality with multiple layers of protection.&lt;/p&gt;

&lt;h3&gt;
  
  
  Authentication
&lt;/h3&gt;

&lt;p&gt;Authentication is required before the WebSocket connection is established.&lt;/p&gt;

&lt;p&gt;Applications can either use the configured terminal token or provide their own authentication function.&lt;/p&gt;

&lt;p&gt;Custom authentication can also associate an authenticated connection with a user identity.&lt;/p&gt;

&lt;h3&gt;
  
  
  Session Ownership
&lt;/h3&gt;

&lt;p&gt;Terminal sessions now have an associated user ID.&lt;/p&gt;

&lt;p&gt;When a client attempts to reconnect to an existing session, the authenticated user's ID is checked against the session owner.&lt;/p&gt;

&lt;p&gt;A user cannot simply provide another user's session ID and take over their terminal session.&lt;/p&gt;

&lt;h3&gt;
  
  
  Localhost Restriction
&lt;/h3&gt;

&lt;p&gt;&lt;code&gt;restrictToLocalhost&lt;/code&gt; can restrict terminal access to localhost connections.&lt;/p&gt;

&lt;p&gt;This is enabled by default.&lt;/p&gt;

&lt;p&gt;This is particularly useful for development tools where the terminal should never be exposed to the network.&lt;/p&gt;

&lt;h3&gt;
  
  
  Origin Allowlisting
&lt;/h3&gt;

&lt;p&gt;&lt;code&gt;strictTerminal&lt;/code&gt; and &lt;code&gt;allowedOrigins&lt;/code&gt; can restrict which origins are permitted to access the terminal endpoint.&lt;/p&gt;

&lt;p&gt;This provides another access-control layer for deployments where the terminal needs to be reachable remotely.&lt;/p&gt;

&lt;h3&gt;
  
  
  HTTPS Requirement
&lt;/h3&gt;

&lt;p&gt;When localhost restriction is disabled, the terminal requires a secure HTTPS connection.&lt;/p&gt;

&lt;p&gt;This helps prevent credentials from being transmitted over an unencrypted remote connection.&lt;/p&gt;

&lt;h3&gt;
  
  
  Message Size Limits
&lt;/h3&gt;

&lt;p&gt;Incoming WebSocket messages are bounded to prevent excessively large messages from being sent to the terminal.&lt;/p&gt;

&lt;p&gt;The current maximum message size is &lt;strong&gt;64 KB&lt;/strong&gt;.&lt;/p&gt;

&lt;h3&gt;
  
  
  Connection and Session Limits
&lt;/h3&gt;

&lt;p&gt;&lt;code&gt;maxConnections&lt;/code&gt; limits the number of simultaneous WebSocket connections.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;maxSessions&lt;/code&gt; limits the number of active terminal sessions.&lt;/p&gt;

&lt;p&gt;These controls reduce the ability of the terminal endpoint to consume unbounded resources.&lt;/p&gt;

&lt;h3&gt;
  
  
  Session Lifetime
&lt;/h3&gt;

&lt;p&gt;Terminal sessions have a maximum lifetime.&lt;/p&gt;

&lt;p&gt;Sessions are automatically terminated after the configured lifetime rather than being allowed to exist indefinitely.&lt;/p&gt;

&lt;h3&gt;
  
  
  Environment Restrictions
&lt;/h3&gt;

&lt;p&gt;&lt;code&gt;strictEnv&lt;/code&gt; and &lt;code&gt;env&lt;/code&gt; provide control over which environment variables are passed into the terminal process.&lt;/p&gt;

&lt;p&gt;This can be useful when the terminal is intended to run with a deliberately restricted environment instead of inheriting the entire server process environment.&lt;/p&gt;

&lt;h3&gt;
  
  
  Optional VM Integration
&lt;/h3&gt;

&lt;p&gt;The terminal can also be configured to start a different command through &lt;code&gt;startupShell&lt;/code&gt; and &lt;code&gt;startupShellArgs&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;This can be used to integrate the terminal with an isolated environment such as a virtual machine.&lt;/p&gt;

&lt;p&gt;However, VM isolation should be configured securely by the application using it; simply launching a VM process does not automatically guarantee complete sandboxing.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why wasn't the terminal removed?
&lt;/h2&gt;

&lt;p&gt;Because the terminal is an intentional feature.&lt;/p&gt;

&lt;p&gt;A server-side terminal is inherently powerful because its purpose is to execute commands. The security requirement is therefore to make sure that only authorized users can access it and that the deployment can impose additional restrictions where necessary.&lt;/p&gt;

&lt;p&gt;Removing the feature would remove functionality that &lt;code&gt;ui-tools&lt;/code&gt; intentionally provides.&lt;/p&gt;

&lt;p&gt;Instead, the security model has been strengthened around it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Version Guidance
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;0.1.0-beta – 0.1.8-beta&lt;/strong&gt;: Affected by the unauthenticated terminal vulnerability. Upgrade immediately.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;0.1.9-beta&lt;/strong&gt;: Adds authentication before the WebSocket upgrade.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;0.2.0-beta and newer&lt;/strong&gt;: Includes additional defense-in-depth controls around authentication, authorization, sessions, origins, connections, messages, environment handling, and terminal lifetime.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If you are currently using an affected release, upgrade to a current version rather than continuing to use the unauthenticated implementation.&lt;/p&gt;

&lt;h2&gt;
  
  
  Final Clarification
&lt;/h2&gt;

&lt;p&gt;The existence of a server-side PTY does not by itself make a package a backdoor.&lt;/p&gt;

&lt;p&gt;The terminal functionality was intentionally implemented as a developer feature.&lt;/p&gt;

&lt;p&gt;The security issue was that the intended authentication/authorization boundary was missing in the affected releases.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;0.1.9-beta&lt;/code&gt; addressed that immediate vulnerability, and &lt;code&gt;0.2.0-beta&lt;/code&gt; continues the work with additional security controls because I did not believe a single token check was enough for a feature with this level of privilege.&lt;/p&gt;

&lt;p&gt;Security issues happen. What matters is identifying them, documenting them accurately, fixing them, and continuing to improve the security model.&lt;/p&gt;

</description>
      <category>npm</category>
      <category>security</category>
      <category>git</category>
    </item>
    <item>
      <title>Security Notice: @bananacool467/ui-tools — Use 0.1.9-beta or Newer</title>
      <dc:creator>Banana Cool</dc:creator>
      <pubDate>Fri, 28 Aug 2026 00:43:02 +0000</pubDate>
      <link>https://dev.to/banana_cool/security-notice-bananacool467ui-tools-use-019-beta-or-newer-28b</link>
      <guid>https://dev.to/banana_cool/security-notice-bananacool467ui-tools-use-019-beta-or-newer-28b</guid>
      <description>&lt;p&gt;&lt;strong&gt;Published&lt;/strong&gt;: August 27, 2026&lt;br&gt;
&lt;strong&gt;Package&lt;/strong&gt;: &lt;code&gt;@bananacool467/ui-tools&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;I want to clarify a security issue affecting earlier versions of &lt;code&gt;@bananacool467/ui-tools&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;Versions &lt;strong&gt;0.1.0-beta through 0.1.8-beta&lt;/strong&gt; contained an unauthenticated WebSocket terminal endpoint. This allowed a client connecting to the endpoint to interact with a PTY running on the server.&lt;/p&gt;

&lt;p&gt;The issue has since been addressed.&lt;/p&gt;
&lt;h2&gt;
  
  
  Affected versions
&lt;/h2&gt;

&lt;p&gt;The OSV advisory &lt;strong&gt;MAL-2026-13416&lt;/strong&gt; currently identifies these versions as affected:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;0.1.0-beta
0.1.1-beta
0.1.2-beta
0.1.3-beta
0.1.4-beta
0.1.5-beta
0.1.6-beta
0.1.7-beta
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;(&lt;code&gt;0.1.8-beta&lt;/code&gt; also didn't have the patch)&lt;/p&gt;

&lt;p&gt;The advisory was generated from findings by Amazon Inspector and includes hashes identifying the affected package artifacts.&lt;/p&gt;

&lt;h2&gt;
  
  
  Patched versions
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Do not use the affected versions &lt;code&gt;0.1.0-beta&lt;/code&gt; through &lt;code&gt;0.1.8-beta&lt;/code&gt;. Use &lt;code&gt;0.1.9-beta&lt;/code&gt; or newer.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;In 0.1.9-beta, I added authentication before the WebSocket upgrade is accepted.&lt;/p&gt;

&lt;p&gt;The 0.1.9-beta implementation checks the token before calling &lt;code&gt;handleUpgrade()&lt;/code&gt;, so unauthenticated connections are rejected before the WebSocket is upgraded.&lt;/p&gt;

&lt;p&gt;In other words, knowing the WebSocket endpoint alone is no longer sufficient to establish a terminal session.&lt;/p&gt;

&lt;h2&gt;
  
  
  What should I do?
&lt;/h2&gt;

&lt;p&gt;If your project uses an affected version, update it:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npm &lt;span class="nb"&gt;install&lt;/span&gt; @bananacool467/ui-tools@latest
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Or explicitly:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npm &lt;span class="nb"&gt;install&lt;/span&gt; @bananacool467/ui-tools@0.1.9-beta
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;You can check your installed version with:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npm &lt;span class="nb"&gt;ls&lt;/span&gt; @bananacool467/ui-tools
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If you're using a version from &lt;code&gt;0.1.0-beta&lt;/code&gt; through &lt;code&gt;0.1.8-beta&lt;/code&gt;, &lt;strong&gt;upgrade immediately&lt;/strong&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Clarification: This Was Not an Intentional Backdoor
&lt;/h2&gt;

&lt;p&gt;The terminal functionality in &lt;code&gt;@bananacool467/ui-tools&lt;/code&gt; was an intentional developer feature. The security issue in versions prior to &lt;code&gt;0.1.9-beta&lt;/code&gt; was that the terminal's WebSocket endpoint did not properly require authentication.&lt;/p&gt;

&lt;p&gt;The unauthenticated access was unintentional. It was a security vulnerability, not an intentionally deployed backdoor or malware payload.&lt;/p&gt;

&lt;p&gt;The terminal functionality itself is not being removed because it is an intended feature of the package. Instead, later releases add security controls around it, including authentication, localhost restrictions, origin allowlisting, session ownership checks, message-size limits, session limits, and other protections.&lt;/p&gt;

&lt;p&gt;Independent analysis from Socket.IO identified the affected implementation as a high-severity remote command-execution/data-exposure primitive due to its lack of authentication, authorization, and session ownership validation. However, the analysis also noted that there was no strong evidence of stealth or obfuscation. This distinction is important: the presence of a server-side terminal/PTY feature does not by itself make the feature a backdoor. The security problem was the absence of the intended authentication boundary in the affected releases.&lt;/p&gt;

&lt;p&gt;Socket.IO said in older affected versions:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;This module implements a remote interactive terminal. It spawns a server-side shell in a PTY and forwards client-supplied input to that shell while streaming command output/history back to the client. It contains no authentication/authorization or session ownership validation within the module, and its error path still forwards raw client bytes to the PTY. As-is, it is extremely dangerous if reachable by untrusted users and should be treated as a high-severity remote command execution/data exposure primitive. No strong evidence of stealth/obfuscation is present, but the functional risk is very high.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Clarification: Current Releases
&lt;/h2&gt;

&lt;p&gt;Security reports concerning earlier releases should not be interpreted as describing the security architecture of all subsequent releases.&lt;/p&gt;

&lt;p&gt;The terminal functionality remains an intentional feature of &lt;code&gt;@bananacool467/ui-tools&lt;/code&gt;. However, the security controls surrounding that functionality have been substantially strengthened since the affected releases.&lt;/p&gt;

&lt;p&gt;In particular, &lt;code&gt;0.1.9-beta&lt;/code&gt; introduced authentication before the WebSocket upgrade. "0.2.0-beta" further strengthened the terminal implementation with additional authentication and authorization controls, localhost and origin restrictions, authenticated session ownership, message-size limits, connection and session limits, session lifetime limits, environment restrictions, and secure transport requirements for remote operation.&lt;/p&gt;

&lt;p&gt;The existence of the terminal/PTY functionality itself does not mean that every version of the package provides unauthenticated remote command execution. Security assessments should evaluate the specific version being used and its actual implementation rather than assuming that behavior from an older affected release remains unchanged.&lt;/p&gt;

&lt;h2&gt;
  
  
  Version Guidance
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Affected releases: &lt;code&gt;0.1.0-beta&lt;/code&gt; through &lt;code&gt;0.1.8-beta&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;0.1.9-beta&lt;/code&gt;: Adds authentication before the WebSocket upgrade.&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;0.2.0-beta&lt;/code&gt; and newer: Further hardens the terminal functionality with additional access-control and resource-security features.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If you are using an affected release, upgrade to a current release rather than continuing to use the unauthenticated implementation.&lt;/p&gt;

&lt;h2&gt;
  
  
  What happened?
&lt;/h2&gt;

&lt;p&gt;The terminal functionality is intentional. &lt;code&gt;ui-tools&lt;/code&gt; is not intended to be a frontend-only component library; it contains various development/UI utilities, including an optional terminal interface. The unauthenticated part was unintentional.&lt;/p&gt;

&lt;p&gt;The problem with the earlier implementation was that the terminal WebSocket endpoint did not require authentication.&lt;/p&gt;

&lt;p&gt;This meant that a server using the terminal functionality could unintentionally expose a shell to anyone who could reach the endpoint.&lt;/p&gt;

&lt;p&gt;This was not acceptable, and authentication was added in &lt;code&gt;0.1.9-beta&lt;/code&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  About MAL-2026-13416
&lt;/h2&gt;

&lt;p&gt;The official OSV record is available here:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://api.osv.dev/v1/vulns/MAL-2026-13416" rel="noopener noreferrer"&gt;https://api.osv.dev/v1/vulns/MAL-2026-13416&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The underlying OSSF malicious-packages record is also publicly available:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@bananacool467/ui-tools/MAL-2026-13416.json" rel="noopener noreferrer"&gt;https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@bananacool467/ui-tools/MAL-2026-13416.json&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The advisory currently lists &lt;strong&gt;0.1.0-beta through 0.1.7-beta&lt;/strong&gt; as affected, I have listed 0.1.8-beta as affected too. &lt;code&gt;0.1.9-beta&lt;/code&gt; is not included in that affected-version list.&lt;/p&gt;

&lt;h2&gt;
  
  
  TL;DR
&lt;/h2&gt;

&lt;p&gt;If you're installing &lt;code&gt;@bananacool467/ui-tools&lt;/code&gt;:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Use "0.1.9-beta" or newer. Do not install versions &lt;code&gt;0.1.0-beta&lt;/code&gt; through &lt;code&gt;0.1.8-beta&lt;/code&gt;.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;I recommend pinning the version in production rather than blindly accepting arbitrary prerelease updates.&lt;/p&gt;

</description>
      <category>npm</category>
      <category>security</category>
    </item>
    <item>
      <title>I made a web framework</title>
      <dc:creator>Banana Cool</dc:creator>
      <pubDate>Tue, 04 Aug 2026 03:53:50 +0000</pubDate>
      <link>https://dev.to/banana_cool/i-made-a-web-framework-2obn</link>
      <guid>https://dev.to/banana_cool/i-made-a-web-framework-2obn</guid>
      <description>&lt;p&gt;Hi everyone! I made an SSR web framework on NPM named &lt;strong&gt;Authtics Host&lt;/strong&gt; (or &lt;strong&gt;HostJS&lt;/strong&gt;)&lt;/p&gt;

&lt;h2&gt;
  
  
  About
&lt;/h2&gt;

&lt;p&gt;Based on tests, it starts the server in &lt;strong&gt;under 1&lt;/strong&gt; second. For a user to see the page, it takes &lt;strong&gt;1-4&lt;/strong&gt; seconds.&lt;/p&gt;

&lt;p&gt;It also has a &lt;strong&gt;Developer Panel&lt;/strong&gt;, which has controls to control the website &lt;strong&gt;&lt;em&gt;(e.g., Restart, Shutdown and Pause Users)&lt;/em&gt;&lt;/strong&gt; with &lt;strong&gt;DAT&lt;/strong&gt; (&lt;strong&gt;Developer Access Token&lt;/strong&gt;) authorization for the Developer Panel.&lt;/p&gt;

&lt;p&gt;The framework's Developer Panel has &lt;strong&gt;console&lt;/strong&gt; and &lt;strong&gt;network&lt;/strong&gt; tabs, where devs can see: what the page is receiving, sending or what logs it's placing in the console. Better than importing a package and setting it up on mobile.&lt;/p&gt;

&lt;h2&gt;
  
  
  3 Reasons why I made this
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Most frameworks start in 2-5+ seconds&lt;/li&gt;
&lt;li&gt;There isn't any console or network tab for mobile&lt;/li&gt;
&lt;li&gt;If there's a developer panel in another framework, it might not be mobile-friendly&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Package
&lt;/h2&gt;

&lt;p&gt;The NPM package is at: &lt;a href="https://npmjs.com/package/@bananacool467/authtics-host" rel="noopener noreferrer"&gt;@bananacool467/authtics-host&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Code snippet
&lt;/h2&gt;

&lt;p&gt;For creating and starting the server:&lt;br&gt;
Backend script (index.ts):&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight typescript"&gt;&lt;code&gt;&lt;span class="k"&gt;import&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;App&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;from&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;@bananacool467/authtics-host&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;app&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;App&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Bash script to run it:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;node &lt;span class="nt"&gt;--experimental-strip-types&lt;/span&gt; index.ts
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  How I got it to start in under 1 second
&lt;/h2&gt;

&lt;p&gt;What I did was make it do fast stuff, when it starts, it:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Loads modules (node:fs, node:http, jiti)&lt;/li&gt;
&lt;li&gt;Then it loads the jiti config file&lt;/li&gt;
&lt;li&gt;Then it starts the server with the config&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>typescript</category>
      <category>react</category>
      <category>npm</category>
      <category>web</category>
    </item>
    <item>
      <title>I want help making an AI please</title>
      <dc:creator>Banana Cool</dc:creator>
      <pubDate>Sat, 18 Jul 2026 05:39:43 +0000</pubDate>
      <link>https://dev.to/banana_cool/i-want-help-making-an-ai-please-146j</link>
      <guid>https://dev.to/banana_cool/i-want-help-making-an-ai-please-146j</guid>
      <description>&lt;p&gt;Can someone please help me make an AI model in &lt;strong&gt;C++&lt;/strong&gt;?&lt;/p&gt;

&lt;p&gt;I tried to make one multiple times.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>cpp</category>
      <category>programming</category>
    </item>
    <item>
      <title>I am making a programming language</title>
      <dc:creator>Banana Cool</dc:creator>
      <pubDate>Wed, 24 Jun 2026 04:37:08 +0000</pubDate>
      <link>https://dev.to/banana_cool/i-am-making-a-programming-language-4d9d</link>
      <guid>https://dev.to/banana_cool/i-am-making-a-programming-language-4d9d</guid>
      <description>&lt;p&gt;Hi everyone! I’m currently building a custom programming language called &lt;strong&gt;Swiq&lt;/strong&gt; using C++. &lt;/p&gt;

&lt;p&gt;Most modern languages rely entirely on standard garbage collection or strict block scoping. When I designed Swiq, I wanted to give developers built-in keywords to control variable state directly.&lt;/p&gt;

&lt;h3&gt;
  
  
  What makes Swiq unique?
&lt;/h3&gt;

&lt;p&gt;Swiq tracks both the current state and the instantiation state of your data. Here are a few unique features I've built into the memory management system:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;strong&gt;Native Archiving:&lt;/strong&gt; You can stash a variable away into a hidden memory space and safely pull it back whenever you need it.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Instant Resetting:&lt;/strong&gt; Swiq remembers the initial value used when a variable was first created, allowing you to instantly reset it to its default state.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Explicit Closures:&lt;/strong&gt; Functions allow explicit variable closure capturing, much like C++ lambdas.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  A Quick Look at the Syntax
&lt;/h3&gt;

&lt;p&gt;Here is a quick look at how clean it is to handle variable states, archiving, and resetting in Swiq:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;set var score = 100;

// Modify it
set score = 150;

// Need a backup state? Archive it!
archive score; 

// Score is now safely stashed away. Bring it back natively:
restore score;

// Want to revert to the very first value?
reset score; // score is now back to 100
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;And for functions with closures:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;set var x = 10;
set var y = 70;
set var z = 25;

// Limited access functions
func myFunction () [x, y] {
  log(x);
  log(y);
  // No access to "z"
}

// Full access functions
func myFunction () [&amp;amp;] {
  log(x);
  log(y);
  log(z);
}
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Check out the project!
&lt;/h3&gt;

&lt;p&gt;Swiq is an open-source project and is still actively under development. I built the custom interpreter and Abstract Syntax Tree (AST) completely from scratch in C++.&lt;/p&gt;

&lt;p&gt;You can check out the source code, read the documentation, or contribute here:&lt;br&gt;
👉 &lt;strong&gt;&lt;a href="https://github.com/bananakitssu/Swiq" rel="noopener noreferrer"&gt;github.com/bananakitssu/Swiq&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I would love to hear your thoughts on this approach to state management. What features or use cases would you like to see next?&lt;/p&gt;

</description>
      <category>programming</category>
      <category>cpp</category>
      <category>github</category>
      <category>git</category>
    </item>
  </channel>
</rss>
